Paper 2024/802

On Maximum Size Simultaneous Linear Approximations in Ascon and Keccak and Related Translation and Differential Properties

Nicolas T. Courtois, Qualcomm (France)
Frédéric Amiel, Qualcomm (France)
Alexandre Bonnard de Fonvillars, Qualcomm (France)

In this paper we study the S-box known as Chi or \chi initially proposed by Daemen in 1995 and very widely used ever since in Keccak, Ascon, and many other. This type of ciphers is typically analyzed [in recent research] in terms of subspace trail attacks [TeDi19] and vector space invariants. An interesting question is then, when different spaces are mapped to each other by translations with a constant. In this paper we relax this fundamental question and we consider arbitrary sets of points and their translations. We generalize previous S-box partial linearization results on Keccak and Ascon from Eurocrypt 2017. We basically introduce new ways to linearize the Ascon S-box to the maximum possible extent. On this basis we show further remarkable properties and some surprising connections between [simultaneous] linear and [prominent] differential properties. We exhibit a new family of maximum size and optimal approximation properties with 11 points, beyond the maximum size of any set in the DDT table. We prove a theorem which guarantees that this type of properties are stable by arbitrary input-side translations which holds for all quadratic permutations. All this will be placed in the context of previous work on classification of 5-bit quadratic permutations.

Available format(s)
Secret-key cryptography
Publication info
AsconKeccakSimultaneous Linear ApproximationsLATDDTMIrotation invariantsaffine space trailscryptanalysis
Contact author(s)
ncourtois427 @ gmail com
famiel @ qti qualcomm com
adefonvi @ qti qualcomm com
2024-06-25: last of 4 revisions
2024-05-23: received
See all versions
Short URL
Creative Commons Attribution-NonCommercial


      author = {Nicolas T. Courtois and Frédéric Amiel and Alexandre Bonnard de Fonvillars},
      title = {On Maximum Size Simultaneous Linear Approximations in Ascon and Keccak and Related Translation and Differential Properties},
      howpublished = {Cryptology ePrint Archive, Paper 2024/802},
      year = {2024},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.