Paper 2026/1549

The Cross-ratio Property and Its Use for Cryptanalysis of Round-reduced AES

Zhenzhen Bao, Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing, China, Zhongguancun Laboratory, Beijing, China, State Key Laboratory of Cryptography and Digital Economy Security, Tsinghua University, Beijing, China
Jian Guo, Nanyang Technological University, Singapore, Singapore
Eik List, Nanyang Technological University, Singapore, Singapore
Haoyang Wang, School of Computer Science, Shanghai Jiao Tong University, Shanghai, China
Abstract

In this work, we propose three techniques for advancing cryptanalysis of round-reduced AES, two of which exploit the multiplicative inverse, and a third, structural, property that generalizes the S-box switch to multiple quartets. Firstly, we formalize the cross-ratio property for tracing a nonlinear equation over $F_{2^8}$ from the differences of four distinct inputs or their respective outputs through the key-wrapped multiplicative inverse. While the underlying properties of the multiplicative inverse have been well-studied, their usefulness for non-algebraic attacks has surprisingly remained unexamined. We demonstrate that it allows a more efficient matching between the sets of many related texts in a Demirci-Selçuk Meet-in-the-middle attack, leading to reductions in time and memory of both the online and offline phases for the seminal seven-round AES-128 by Derbez et al. from Eurocrypt 2013. Secondly, we show that the cross-ratio property gives rise to a relevant special case: when its inputs to the multiplicative inverse span a two-dimensional space, one can almost always recover the input differences of a quartet from only their output differences, or, in an alternative formulation, even the key applied before the outputs. We show how this can lead to new reduced-data three-round distinguishers. Thirdly, we define the mixture-quartet switch, an event that a mixture plaintext structure of 16 texts allows a partitioning into four quartets that all produce a related difference after two rounds. While most recent advances of the analysis of AES had focused on structural properties, we can trace partially active diagonals through a Super-S-box. Thus, by combining structural and algebraic properties, we describe a new distinguisher on four AES rounds with lower data complexity. Our applications do not threaten the security of the full AES, but advance the understanding of the building blocks of the AES further, and are likely applicable to similar settings and ciphers.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Secret-key cryptographyblock cipherAESdifferential cryptanalysismeet-in-the-middle attack
Contact author(s)
zzbao @ tsinghua edu cn
guojian @ ntu edu sg
eiklist @ ntu edu sg
haoyang wang @ sjtu edu cn
History
2026-08-03: approved
2026-07-29: received
See all versions
Short URL
https://ia.cr/2026/1549
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1549,
      author = {Zhenzhen Bao and Jian Guo and Eik List and Haoyang Wang},
      title = {The Cross-ratio Property and Its Use for Cryptanalysis of Round-reduced {AES}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1549},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1549}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.