Paper 2025/2297

Cryptanalysis of Full BEANIE

Xavier Bonnetain, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Sébastien Duval, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Virginie Lallemand, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Thierno Mamoudou Sabaly, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Thomas Sagot, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Thibault Sanvoisin, Université de Lorraine, CNRS, Inria, LORIA, Nancy, France
Abstract

Beanie is a tweakable block cipher recently published at ToSC aiming for memory encryption of microcontroller units. In line with this goal, it handles small plaintexts of only 32 bits and has a low latency. In this paper, we propose the first third-party analysis of the two variants of Beanie. By carefully leveraging structural properties of the cipher and taking advantage of its distinctive attack model, we manage to mount several key-recovery attacks against both the 5+5-round version and the 7+7-round version.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
BEANIECryptanalysisYoyoTruncated differential
Contact author(s)
xavier bonnetain @ inria fr
History
2026-09-15: last of 3 revisions
2025-12-20: received
See all versions
Short URL
https://ia.cr/2025/2297
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2297,
      author = {Xavier Bonnetain and Sébastien Duval and Virginie Lallemand and Thierno Mamoudou Sabaly and Thomas Sagot and Thibault Sanvoisin},
      title = {Cryptanalysis of Full {BEANIE}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2297},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2297}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.