Paper 2026/1563

A Generalized Framework for Conditional Linear Cryptanalysis and Its Application to AES-Like Ciphers

Cheng Che, Information Engineering University, Zhengzhou, China
Tian Tian, Information Engineering University, Zhengzhou, China
Jing Yang, Information Engineering University, Zhengzhou, China
Fan Yang, Information Engineering University, Zhengzhou, China
Abstract

Conditional linear cryptanalysis represents an extension of linear cryptanalysis and has been applied to DES and AES. Notably, it enables the construction of a linear distinguisher for 4-round AES, which is considered unattainable through standard linear cryptanalysis. The underlying principle is that the correlation of a linear approximation can be improved when the data is restricted to a specific subspace or subset, thereby allowing more effective linear cryptanalysis. The critical challenge in conditional linear cryptanalysis lies in identifying appropriate conditions to impose on the data; however, previous methods rely on ad hoc strategies that depend heavily on expert intuition, which limits their generalization and application. In this paper, we propose a generalized framework for conditional linear cryptanalysis. The core tool is the conditional linear approximation table (CLAT), which quantifies linear correlations within constrained data subspaces. We further define a metric termed conditional linear weight, which balances the gain in correlation against the overhead of data filtering, thereby offering a quantitative measure of resistance against conditional linear cryptanalysis. Based on the CLAT and conditional linear weight, we develop an MILP-based automatic search model for conditional linear trails and devise systematic approaches for mounting distinguishing and key recovery attacks using these trails. Applying our framework to AES, Rijndael-256, ARIA, LED, Midori-128, and SKINNY-128, we demonstrate that conventional full-space bounds do not guarantee resistance against conditional linear cryptanalysis, and we propose improved linear attacks. Our framework provides systematic approaches and automatic tools for conditional linear cryptanalysis. It enables cryptanalysts to gain deeper insights into the statistical linear properties of cryptographic primitives and serves as a useful evaluation technique for new designs.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Conditional Linear CryptanalysisCLATAESRijndael-256ARIALEDMidori-128SKINNY-128
Contact author(s)
tiantian_d @ 126 com
History
2026-08-03: approved
2026-07-30: received
See all versions
Short URL
https://ia.cr/2026/1563
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1563,
      author = {Cheng Che and Tian Tian and Jing Yang and Fan Yang},
      title = {A Generalized Framework for Conditional Linear Cryptanalysis and Its Application to {AES}-Like Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1563},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1563}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.