Paper 2025/1498
One More Pair, More Information Gained: Improved Attacks on LowMC with Full S-box Layers Using Two Plaintext/Ciphertext Pairs
Abstract
Motivated by LowMC cryptanalysis challenge, research in recent years focuses more on attacking LowMC in \PICNIC application setting, \ie an attacker can see only a single plaintext/ciphertext pair. It can be noted that in the security proof of \PICNIC, LowMC is required to be secure under two plaintexts, it is thus meaningful to investigate the security of LowMC in this direction. Pioneered by Liu, Isobe and Meier at Crypto 2021, they combined algebraic techniques with difference enumeration attack, which could attack all three 4-round LowMC instances adopting full S-Box layers in \PICNIC with only two chosen plaintexts. However, the research on cryptanalysis of LowMC using two plaintext/ciphertext pairs is yet far from complete. Previous works using a single known plaintext are better than those with two plaintexts in terms of attack complexity or attacked rounds when considering a comparable success probability. In this paper, to address such counter-intuitive gaps between existing attacks on LowMC with full S-box layers using a single and two plaintext/ciphertext pairs, we first develop an algebraic key-derived attack framework, where an algebraic property of the key-derived difference is utilized to build an equation system with lower algebraic degree. This directly contributes to less cost for solving equation system and naturally works under known-plaintext setting, which can be further enhanced with chosen-plaintext attack setting. We then present an improved difference enumeration attack framework. Instead of enumerating all possible differences in the second round, variables for part of S-boxes in the second and third rounds are introduced to derive cubic equations, which will lead to fewer variables for the last round. Finally, applying our new attack frameworks to LowMC, we propose \text{8-round} attacks on LowMC for the very first time, which remain under known-plaintext setting. Moreover, we give the first attacks on three LowMC instances, \ie 129-bit block size of 6 rounds and 129-/192-bit block size of 7 rounds, which cannot be obtained using previous attacking methods. Also, previous attacks on LowMC from 4 to 7 rounds could be improved for almost all three LowMC instances in this paper. All these results, we believe, could be a positive answer that given one more pair, more information indeed can be gained to improve attacks on LowMC when compared to those using only a single plaintext. As well as our newly proposed algebraic key-derived attack framework, we hope that, could provide more insights into the cryptanalysis of LowMC with low allowable data complexity.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- LowMCPICNIClinearizationalgebraic attackkey recoverypolynomial method
- Contact author(s)
-
sunyimeng @ mail sdu edu cn
cuijiamin @ sdu edu cn
shiyao chen @ ntu edu sg
mqwang @ sdu edu cn
202321179 @ mail sdu edu cn
niuchao niu @ antgroup com - History
- 2025-08-28: approved
- 2025-08-20: received
- See all versions
- Short URL
- https://ia.cr/2025/1498
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1498,
author = {Yimeng Sun and Jiamin Cui and Shiyao Chen and Meiqin Wang and Longzheng Cui and Chao Niu},
title = {One More Pair, More Information Gained: Improved Attacks on {LowMC} with Full S-box Layers Using Two Plaintext/Ciphertext Pairs},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1498},
year = {2025},
url = {https://eprint.iacr.org/2025/1498}
}