Paper 2024/1614
Related-Key Cryptanalysis of FUTURE
Abstract
At Africacrypt 2022, Gupta et al. introduced FUTURE, a 64-bit lightweight block cipher based on an MDS matrix and designed in an SPN structure, with a focus on achieving single-cycle encryption and low implementation cost, especially in unrolled architectures. While the designers evaluated its security under various attack models, they did not consider related-key cryptanalysis. In this work, we address this gap by analyzing the security of FUTURE in the related-key setting using techniques based on Mixed Integer Linear Programming (MILP). We first propose a simplified and generalizable approach for applying MILP to model any MDS or near-MDS-based cipher that follows the substitution-permutation paradigm. Using our MILP framework, we construct an 8-round related-key distinguisher on FUTURE, requiring $2^{58}$ plaintexts, $2^{58}$ \xor operations, and negligible memory. We further identify a full-round (i.e., 10 rounds) boomerang distinguisher with a probability of $2^{-45.8}$, enabling a distinguishing attack with $2^{48}$ data and time complexity. In addition, we develop a full-round key recovery attack on FUTURE with data, time, and memory complexities of $2^{18}$, $2^{70}$, and $2^{64}$, respectively. Although all known single-key attacks remain impractical (with time complexities of at least $2^{112}$), our results demonstrate a full-round cryptanalysis of FUTURE in the related-key setting, thereby challenging its claimed security guarantees.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Related key cryptanalysisBoomerang attack and FUTURE
- Contact author(s)
-
janaamit001 @ gmail com
smita1995star @ gmail com
cayantika @ gmail com
debdeep mukhopadhyay @ gmail com
yusasaki0930 @ gmail com - History
- 2025-05-16: revised
- 2024-10-10: received
- See all versions
- Short URL
- https://ia.cr/2024/1614
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1614,
author = {Amit Jana and Smita Das and Ayantika Chatterjee and Debdeep Mukhopadhyay and Yu Sasaki},
title = {Related-Key Cryptanalysis of {FUTURE}},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1614},
year = {2024},
url = {https://eprint.iacr.org/2024/1614}
}