Paper 2026/1866

Peeling Nonlinear Layers: Algebraic Cryptanalysis of Full-Round Iasta

Chandan Dey, Indian Statistical Institute
Abul Kalam, Indian Institute of Technology Madras
Santanu Sarkar, Indian Institute of Technology Madras
Abstract

Iasta is a stream cipher designed for hybrid homomorphic encryption (HHE), with claimed $128$-bit security for its Iasta-3 and Iasta-4 instances. In this work, we present the first third-party cryptanalysis of the full-round Iasta-3 and Iasta-4 instances and further extend our approach to Iasta-5. Our cryptanalysis exploits the restricted randomness and structured construction of the nonce-dependent affine-layer matrices. We show that the matrix space contains only $2^{31.30}$ and $2^{19.62}$ distinct matrices for Iasta-3 and Iasta-4/5, respectively, compared with the $2^{29}$ and $2^{22}$ matrix randomness claimed by the designers. This restricted matrix space enables us to construct weak nonces that induce an identical matrix in the final affine layer. For such nonces, we peel off the final Cube transformation, yielding polynomial equations of degree at most $2^{d-1}$ in the secret-key coefficients, which we solve using linearization. We further consider the more restrictive class of nonces that induce identical matrices in both the initial and final affine layers. This allows us to additionally peel off the first non-linear layer, reducing the degree of the resulting equations to at most $2^{d-2}$ at the cost of introducing additional linearization variables. This extended attack substantially improves the attack complexity for Iasta-4 and Iasta-5. For Iasta-3 and Iasta-4, our best estimated attack complexities are $2^{59}$ and $2^{67}$ operations, respectively, under $\omega=2$, reducing the claimed $128$-bit security level to an almost square-root security level. Even under the conservative setting $\omega=3$, the attack requires approximately $2^{80}$ and $2^{82}$ operations against Iasta-3 and Iasta-4, respectively, both below $2^{128}$. For Iasta-5, the extended attack achieves an estimated complexity of $2^{99}$ operations under $\omega=2$. Although no overall security level is explicitly specified for Iasta-5, this result demonstrates that our attack can also reach a complexity below $2^{128}$ for this instance. In all three instances, our attacks reveal a structural weakness in Iasta arising from the restricted space of nonce-dependent affine-layer matrices.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
HE-friendly cipherstream cipherIastalinearization attackweak nonce
Contact author(s)
c dey math95 @ gmail com
abulkalam sunny @ gmail com
sarkar santanu bir1 @ gmail com
History
2026-09-06: approved
2026-09-02: received
See all versions
Short URL
https://ia.cr/2026/1866
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1866,
      author = {Chandan Dey and Abul Kalam and Santanu Sarkar},
      title = {Peeling Nonlinear Layers: Algebraic Cryptanalysis of Full-Round Iasta},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1866},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1866}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.