eprint.iacr.org will be offline for approximately an hour for routine maintenance at 11pm UTC on Tuesday, April 16. We lost some data between April 12 and April 14, and some authors have been notified that they need to resubmit their papers.

Paper 2022/243

A Greater GIFT: Strengthening GIFT against Statistical Cryptanalysis

Ling Sun, Bart Preneel, Wei Wang, and Meiqin Wang


GIFT-64 is a 64-bit block cipher with a 128-bit key that is more lightweight than PRESENT. This paper provides a detailed analysis of GIFT-64 against differential and linear attacks. Our work complements automatic search methods for the best differential and linear characteristics with a careful manual analysis. This hybrid approach leads to new insights. In the differential setting, we theoretically explain the existence of differential characteristics with two active S-boxes per round and derive some novel properties of these characteristics. Furthermore, we prove that all optimal differential characteristics of GIFT-64 covering more than seven rounds must activate two S-boxes per round. We can construct all optimal characteristics by hand. In parallel to the work in the differential setting, we conduct a similar analysis in the linear setting. However, unlike the clear view in differential setting, the optimal linear characteristics of GIFT-64 must have at least one round activating only one S-box. Moreover, with the assistance of automatic searching methods, we identify 24 GIFT-64 variants achieving better resistance against differential attack while maintaining a similar security level against a linear attack. Since the new variants strengthen GIFT-64 against statistical cryptanalysis, we claim that the number of rounds could be reduced from 28 to 26 for the variants. This observation enables us to create a cipher with lower energy consumption than GIFT-64. Similarly to the case in GIFT-64, we do not claim any related-key security for the round-reduced variant as this is not relevant for most applications.

Available format(s)
Secret-key cryptography
Publication info
A minor revision of an IACR publication in EUROCRYPT 2022
Contact author(s)
lingsun @ sdu edu cn
bart preneel @ kuleuven be
weiwangsdu @ sdu edu cn
mqwang @ sdu edu cn
2022-03-02: received
Short URL
Creative Commons Attribution


      author = {Ling Sun and Bart Preneel and Wei Wang and Meiqin Wang},
      title = {A Greater GIFT: Strengthening GIFT against Statistical Cryptanalysis},
      howpublished = {Cryptology ePrint Archive, Paper 2022/243},
      year = {2022},
      note = {\url{https://eprint.iacr.org/2022/243}},
      url = {https://eprint.iacr.org/2022/243}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.