Paper 2025/1601

Meet-in-the-Middle Attacks on Full ChiLow

Eran Lambooij, INRIA
Patrick Neumann, INRIA
Michiel Verbauwhede, KU Leuven
Shichang Wang, Nanyang Technological University
Tianyu Zhang, Nanyang Technological University
Abstract

This work presents the first full-round attacks on ChiLow-32 and ChiLow-40, two tweakable low-latency block ciphers presented at Eurocrypt 2025. We first describe a straightforward Meet-in-the-Middle attack on full ChiLow-32 with multiple known plaintext-ciphertext pairs. To improve this attack, we carefully reduce the number of guesses required by (1) tracing differences in order to remove linear key dependencies and (2) moving from key guesses to state guesses. Using a novel method that is based on the propagation of differences and linear masks, we are able to map out the state dependencies for computing the difference at the matching point. This results in an attack on ChiLow-32 with time complexity $2^{120.34}$ using $160$ known plaintext-ciphertext pairs, and an attack with time complexity $2^{102.09}$ using $64$ chosen ciphertexts. Using these techniques, and an additional trick to better balance the complexities of the meet-in-the-middle branches, we propose an attack on ChiLow-40 with time complexity $2^{122.32}$ and $2^8$ chosen plaintexts. All of our attacks are within ChiLow's security model, and are currently the best and only known key recovery attacks on full-round ChiLow-32 and ChiLow-40.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in CRYPTO 2026
Keywords
Meet-in-the-MiddleKey-recovery attackFull RoundChiLowKey DependenciesState Dependencies
Contact author(s)
eran lambooij @ inria fr
patrick neumann @ inria fr
michiel verbauwhede @ esat kuleuven be
shichang wang @ ntu edu sg
tianyu005 @ e ntu edu sg
History
2026-06-08: last of 4 revisions
2025-09-05: received
See all versions
Short URL
https://ia.cr/2025/1601
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1601,
      author = {Eran Lambooij and Patrick Neumann and Michiel Verbauwhede and Shichang Wang and Tianyu Zhang},
      title = {Meet-in-the-Middle Attacks on Full {ChiLow}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1601},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1601}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.