Paper 2025/1931

Differential-Linear Cryptanalysis of GIFT family and GIFT-based Ciphers

Shichang Wang, Nanyang Technological University
Meicheng Liu, Institute of Information Engineering, CAS
Shiqi Hou, Tsinghua University
Dongdai Lin, Institute of Information Engineering, CAS
Abstract

At CHES 2017, Banik et al. proposed a lightweight block cipher GIFT consisting of two versions GIFT-64 and GIFT-128. Recently, there are lots of authenticated encryption schemes that adopt GIFT-128 as their underlying primitive, such as GIFT-COFB and HyENA. To promote a comprehensive perception of the soundness of the designs, we evaluate their security against differential-linear cryptanalysis. For this, automatic tools have been developed to search differential-linear approximation for the ciphers based on S-boxes. With the assistance of the automatic tools, we find 13-round differential-linear approximations for GIFT-COFB and HyENA. Based on the distinguishers, 18-round key-recovery attacks are given for the message processing phase and initialization phase of both ciphers. Moreover, the resistance of GIFT-64/128 against differential-linear cryptanalysis is also evaluated. The 12-round and 17-round differential-linear approximations are found for GIFT-64 and GIFT-128 respectively, which lead to 18-round and 19-round key-recovery attacks respectively. Here, we stress that our attacks do not threaten the security of these ciphers.

Note: This is the full version of the paper that appeared in IACR Communications in Cryptology, vol. 1, no. 1, April 9, 2024. DOI: https://doi.org/10.62056/a6n5txol7

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A major revision of an IACR publication in CIC 2024
DOI
10.62056/a3n59qgxq
Keywords
Differential-linear attackGIFTGIFT-COFBHyENA
Contact author(s)
shichang wang @ ntu edu sg
liumeicheng @ iie ac cn
seventeenhsq @ gmail com
ddlin @ iie ac cn
History
2025-10-20: approved
2025-10-16: received
See all versions
Short URL
https://ia.cr/2025/1931
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1931,
      author = {Shichang Wang and Meicheng Liu and Shiqi Hou and Dongdai Lin},
      title = {Differential-Linear Cryptanalysis of {GIFT} family and {GIFT}-based Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1931},
      year = {2025},
      doi = {10.62056/a3n59qgxq},
      url = {https://eprint.iacr.org/2025/1931}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.