Paper 2025/056

A Unified Key Recovery Framework for Impossible Boomerang Attacks: Applications to Full-Round-ARADI and SKINNYe v2

Xichao Hu, State Key Laboratory of Cryptology, Beijing, China
Lin Jiao, State Key Laboratory of Cryptology, Beijing, China
Dengguo Feng
Yongqiang Li
Senpeng Wang
Yonglin Hao
Xinxin Gong
Abstract

The impossible boomerang attack is a powerful cryptanalytic technique, but existing key recovery methods face several limitations that restrict its applicability. Specifically, the key pre-guessing is coarse-grained, S-box details are ignored in the differential propagation, the complexity estimation and the key guessing order determination remain rudimentary. To overcome these issues, we introduce three key improvement measures. First, we propose a flexible partial key and difference pre-guessing technique based on directed graphs, enabling selective identification of required keys and differences for generating partial pairs and quartets. Second, we propose a pre-sieving technique to early eliminate invalid quartets by exploiting cipher-specific details. Third, we introduce an automatic key-guessing strategy based on the same directed graphs to efficiently determine valid guessing orders. We integrate these techniques to develop a unified key recovery framework for impossible boomerang attacks, accompanied by a formal and precise characterization of the overall complexity. This is the first framework to support flexible key and difference pre-guessing while incorporating block cipher details during key recovery for impossible boomerang attacks. Crucially, it enables the automatic generation of detailed recovery steps, a capability missing in prior work. As applications, under the four related-key/tweakey setting, we apply the framework to \ARADI{}, a low-latency cipher proposed by the National Security Agency (NSA), and \SKV{}, a threshold-implementation-friendly cipher proposed at EUROCRYPT 2020. For \ARADI{}, we achieve the first full-round attack with $2^{130}$ data, $2^{253.78}$ time, and $2^{235.75}$ memory complexity. For \SKV{}, we present the first 34-round impossible boomerang attack with $2^{66}$ data, $2^{253.75}$ time, and $2^{239.75}$ memory complexity. These results demonstrate the framework’s significance and its substantial improvement in advancing the impossible boomerang attack.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
ARADISKINNYe v2Impossible boomerang attackKey recoveryBlock cipher
Contact author(s)
xchao_h @ 163 com
jiaolin_jl @ 126 com
History
2025-12-20: last of 4 revisions
2025-01-14: received
See all versions
Short URL
https://ia.cr/2025/056
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/056,
      author = {Xichao Hu and Lin Jiao and Dengguo Feng and Yongqiang Li and Senpeng Wang and Yonglin Hao and Xinxin Gong},
      title = {A Unified Key Recovery Framework for Impossible Boomerang Attacks: Applications to Full-Round-{ARADI} and {SKINNYe} v2},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/056},
      year = {2025},
      url = {https://eprint.iacr.org/2025/056}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.