Paper 2025/1238

Extended $c$-differential distinguishers of full $9$ and reduced-round Kuznyechik cipher, no pre-whitening

Pantelimon Stanica, Naval Postgraduate School
Ranit Dutta, Indian Institute of Technology Jodhpur
Bimal Mandal, Indian Institute of Technology Jodhpur
Abstract

This paper introduces {\em truncated inner $c$-differential cryptanalysis}, a novel technique that for the first time enables the practical application of $c$-differential uniformity to block ciphers. While Ellingsen et al. (IEEE Trans. Inf. Theory, 2020) established the notion of $c$-differential uniformity by analyzing the equation $F(x\oplus a) \oplus cF(x) = b$, a key challenge remained: the outer multiplication by $c$ disrupts the structural properties essential for block cipher analysis, particularly key addition. We resolve this challenge by developing an \emph{inner} $c$-differential approach where multiplication by $c$ affects the input: $(F(cx\oplus a), F(x))$, thereby going back to the original idea of Borisov et al. (FSE, 2002). We prove that the inner $c$-differential uniformity of a function $F$ equals the outer $c$-differential uniformity of $F^{-1}$, establishing a fundamental duality. This modification preserves cipher structure while enabling practical cryptanalytic applications. Our main contribution is a comprehensive multi-faceted statistical-computational methodology, implementing truncated $c$-differential analysis against a 9-round Kuznyechik variant without initial key whitening (which preserves the essential $(cx \oplus a, x)$ differential structure required for our analysis). Through extensive computational analysis involving millions of differential pairs, we demonstrate statistically significant non-randomness across all tested round counts. For the full 9-round cipher, we identify multiple configurations triggering critical security alerts, with bias ratios reaching $1.7\times$ and corrected p-values as low as $1.85 \times 10^{-3}$, suggesting insufficient security margin against this new attack vector. The data complexity of our attack is about $2^{33}$ chosen plaintext pairs, time complexity $2^{34}$ and (negligible) memory complexity $2^{16}$. This represents the first practical distinguisher against a full 9-round (and reduced rounds) Kuznyechik variant.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
$(nm)$-functionblock cipherdifferential distinguishertruncated differential distinguisher$c$-differential
Contact author(s)
pstanica @ nps edu
duttaranit628 @ gmail com
bimalmandal @ iitj ac in
History
2026-02-21: last of 2 revisions
2025-07-03: received
See all versions
Short URL
https://ia.cr/2025/1238
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1238,
      author = {Pantelimon Stanica and Ranit Dutta and Bimal Mandal},
      title = {Extended $c$-differential distinguishers of full $9$ and reduced-round Kuznyechik cipher, no pre-whitening},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1238},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1238}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.