Paper 2026/1193
Cryptanalytic Properties of Mealy Machines
Abstract
This paper proposes a systematic approach to compute cryptanalytic properties of arbitrary Mealy machines or S-functions. Based on the geometric approach to cryptanalysis, we provide a uniform formula for any cryptanalytic property of such a function, as long as the property is compatible with the way its input and output are split into chunks. Examples include linear, (quasi) differential, (ultrametric) integral, differential-linear, and boomerang properties. To illustrate our results, we compute these properties for several important examples, including modular additions, the Chi- and ChiChi-functions, and the SHA-1 step function. As proof-of-concept applications, we construct a boomerang distinguisher for the Subterranean permutation, and show how to compute the correlations of conditional linear approximations in partitioning-based differential-linear attacks more accurately. Our results also lead to a new approach to compute the algebraic normal form of the inverse of the Chi-function.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A minor revision of an IACR publication in CRYPTO 2026
- Keywords
- S-functionsCryptanalysisGeometric approach
- Contact author(s)
-
zhongfeng niu @ ntu edu sg
tim beyne @ esat kuleuven be
kai hu @ sdu edu cn
mqwang @ sdu edu cn - History
- 2026-07-27: last of 2 revisions
- 2026-06-07: received
- See all versions
- Short URL
- https://ia.cr/2026/1193
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1193,
author = {Zhongfeng Niu and Tim Beyne and Kai Hu and Meiqin Wang},
title = {Cryptanalytic Properties of Mealy Machines},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1193},
year = {2026},
url = {https://eprint.iacr.org/2026/1193}
}