Paper 2026/1818

Blood MERIDIAN: a blockcipher that is not a blockcipher

JP Aumasson
Abstract

MERIDIAN is a 128-bit blockcipher proposed as a lightweight AES alternative. We show that its “Directional Substitution” layer is not injective by giving an explicit collision. This yields a full 12-round collision for every key. Consequently, no keyed instance of MERIDIAN is a permutation, so no decryption function can invert encryption on all plaintexts, and its blockcipher and PRP security claims fail. We additionally identify a one-round differential that exceeds the claimed bound by a factor 13.37.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Contact author(s)
jeanphilippe aumasson @ gmail com
History
2026-08-28: approved
2026-08-27: received
See all versions
Short URL
https://ia.cr/2026/1818
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/1818,
      author = {JP Aumasson},
      title = {Blood {MERIDIAN}: a blockcipher that is not a blockcipher},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1818},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1818}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.