Paper 2025/1495

Pairwise independence of AES-like block ciphers

Tim Beyne, KU Leuven
Gregor Leander, Ruhr University Bochum
Immo Schütt, Ruhr University Bochum
Abstract

We prove that $4r + 4$ rounds of an AES variant with independent and uniform random round keys are $\varepsilon$-close to pairwise independent with $\varepsilon = 2^{14}\, 2^{-40r}$. This result follows from a near-optimal bound for a two-norm version of pairwise independence for the Shark construction, depending on the third singular value of the difference-distribution table of the S-boxes. Our analysis combines insights from cryptanalysis — in particular, truncated differentials — and linear algebra over the reals.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in EUROCRYPT 2026
Keywords
Pairwise independenceAESSHARKTruncated differentials
Contact author(s)
tim beyne @ esat kuleuven be
gregor leander @ rub de
immo schuett @ ruhr-uni-bochum de
History
2026-02-01: last of 4 revisions
2025-08-19: received
See all versions
Short URL
https://ia.cr/2025/1495
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1495,
      author = {Tim Beyne and Gregor Leander and Immo Schütt},
      title = {Pairwise independence of {AES}-like block ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1495},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1495}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.