Paper 2023/398
A New Linear Distinguisher for Four-Round AES
Abstract
In SAC'14, Biham and Carmeli presented a novel attack on DES, involving a variation of Partitioning Cryptanalysis. This was further extended in ToSC'18 by Biham and Perle into the Conditional Linear Cryptanalysis in the context of Feistel ciphers. In this work, we formalize this cryptanalytic technique for Substitution-Permutation Networks and derive several properties. A conditional approximation is then used to approximate the $inv: GF(2^8) \to GF(2^8) : x \to x^{254}$ function, which forms the only source of non-linearity in the AES. By extending the approximation to encompass the full AES round function, a linear distinguisher for 4-round AES using $2^{125.72}$ known-plaintexts is constructed; the existence of which is often understood to be impossible. We furthermore demonstrate how to recover 32 key bits directly from this distinguisher with no data or time overhead. In addition to suggesting a new approach to advancing the cryptanalysis of the AES, this result moreover demonstrates a caveat in the standard interpretation of the Wide Trail Strategy — the design framework underlying many SPN-based ciphers published in recent years.
Note: Most significantly, we updated Section 5.3 to leverage Blondeau and Nyberg's data complexity formula, achieving a slightly more accurate bound for the distinguishing attack. Moreover, we expanded the related works section, rewrote and reorganized several sections to improve the readability and flow of the paper, and updated the discussion and conclusion.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published by the IACR in JOC 2025
- DOI
- 10.1007/s00145-025-09550-9
- Keywords
- Conditional Linear CryptanalysisAESStatistical Distinguisher
- Contact author(s)
-
tomer @ 3milabs tech
erik takke @ 3milabs tech - History
- 2025-10-27: last of 2 revisions
- 2023-03-20: received
- See all versions
- Short URL
- https://ia.cr/2023/398
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2023/398,
author = {Tomer Ashur and Erik Takke},
title = {A New Linear Distinguisher for Four-Round {AES}},
howpublished = {Cryptology {ePrint} Archive, Paper 2023/398},
year = {2023},
doi = {10.1007/s00145-025-09550-9},
url = {https://eprint.iacr.org/2023/398}
}