Paper 2022/997

Key-Recovery Attacks on CRAFT and WARP (Full Version)

Ling Sun, Shandong University
Wei Wang, Shandong University
Meiqin Wang, Shandong University

This paper considers the security of CRAFT and WARP. We present a practical key-recovery attack on full-round CRAFT in the related-key setting with only one differential characteristic, and the theoretical time complexity of the attack is $2^{36.09}$ full-round encryptions. The attack is verified in practice. The test result indicates that the theoretical analysis is valid, and it takes about $15.69$ hours to retrieve the key. A full-round key-recovery attack on WARP in the related-key setting is proposed, and the time complexity is $2^{44.58}$ full-round encryptions. The theoretical attack is implemented on a round-reduced version of WARP, which guarantees validity. Besides, we give a 33-round multiple zero-correlation linear attack on WARP, which is the longest attack on the cipher in the single-key attack setting. We note that the attack results in this paper do not threaten the security of CRAFT and WARP as the designers do not claim security under the related-key attack setting.

Available format(s)
Attacks and cryptanalysis
Publication info
Published elsewhere. SAC 2022
Differential attack Zero-correlation linear attack Related-key CRAFT WARP
Contact author(s)
lingsun @ sdu edu cn
weiwangsdu @ sdu edu cn
mqwang @ sdu edu cn
2022-08-03: approved
2022-08-03: received
See all versions
Short URL
Creative Commons Attribution


      author = {Ling Sun and Wei Wang and Meiqin Wang},
      title = {Key-Recovery Attacks on CRAFT and WARP (Full Version)},
      howpublished = {Cryptology ePrint Archive, Paper 2022/997},
      year = {2022},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.