Paper 2025/2011
When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks
Abstract
An integral distinguisher for a block cipher is defined by a nontrivial subset of plaintexts for which the bitwise sum of (parts of) a certain internal state is independent of the secret key. Such a distinguishing property can be turned into a key-recovery procedure by partially decrypting the ciphertexts under all possible keys and then filtering the key candidates using the integral distinguisher. The behavior of this filter has never been analyzed in depth, and we show that the ubiquitous hypothesis about its behavior is incorrect. Fortunately, the deviation is either limited or can be lifted to improve the underlying attacks. By algorithmically determining the exact subspaces of key candidates to be guessed - whose dimensions are often lower than expected - we are able to improve upon the best known integral key-recovery attacks on various ciphers.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published by the IACR in EUROCRYPT 2026
- DOI
- 10.1007/978-3-032-25333-0_2
- Keywords
- Block cipherIntegral attackKey RecoveryWrong-Key RandomizationLinear Structure
- Contact author(s)
-
christof beierle @ rub de
gregor leander @ rub de
yevhen perehuda @ rub de - History
- 2026-05-06: revised
- 2025-10-28: received
- See all versions
- Short URL
- https://ia.cr/2025/2011
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2011,
author = {Christof Beierle and Gregor Leander and Yevhen Perehuda},
title = {When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2011},
year = {2025},
doi = {10.1007/978-3-032-25333-0_2},
url = {https://eprint.iacr.org/2025/2011}
}