Paper 2026/1891

Improved Related-Key Boomerang Distinguisher for Full-Round FUTURE

Guoqiang Liu, College of Science, National University of Defense Technology
Suping Liu, College of Science, National University of Defense Technology
Wuyou Zhang, College of Science, National University of Defense Technology
Abstract

FUTURE is a lightweight block cipher with a 64-bit block, a 128-bit key and $10$ rounds, proposed at AFRICACRYPT 2022 for low-latency hardware. This study analyzes FUTURE in the related-key setting with a bit-level constraint model that carries the exact weights of the differential distribution table and the exact entries of the boomerang connectivity table, and whose objective function $2w_0 + 2w_1 + w_{\mathrm{bct}} = -\log_2(p^2q^2r)$ optimizes both sub-ciphers and the middle layer of the sandwich framework together. The model returns a full-round distinguisher whose objective function value $36$ is optimal over all switching rounds and whose probability is $P = \hat{p}^2\,\bar{r}\,\hat{q}^2 = 11\cdot 2^{-39} \approx 2^{-35.54}$, at a cost of $2^{37.54}$ queries under four related keys and $2^{37.54}$ XOR operations. Running it on the full cipher over $2^{44.34}$ quartets returns $341$ right quartets and an experimental probability of $2^{-35.92}$, in $63.9$ hours on an ordinary personal computer; at the previous full-round probability $2^{-45.8}$ the same computer would take about $6.8$ years. The distinguisher is therefore a practical one, and improves the best previously known full-round related-key boomerang distinguisher of FUTURE by a factor of $2^{10.26}$ in probability, in data and in time. An $8$-round distinguisher placed into the unified key recovery framework further gives a full-round attack with $2^{51.05}$ data, $2^{64}$ time and $2^{64}$ memory, whose time complexity attains the optimum of the framework at any memory within the codebook and improves the best previously known attack by a factor of $2^{6}$.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
block cipherFUTURErelated-key boomerang attackdifferential cluster
Contact author(s)
liuguoqiang87 @ hotmail com
liusuping24 @ 163 com
zhangwuyou @ nudt edu cn
History
2026-09-07: approved
2026-09-04: received
See all versions
Short URL
https://ia.cr/2026/1891
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1891,
      author = {Guoqiang Liu and Suping Liu and Wuyou Zhang},
      title = {Improved Related-Key Boomerang Distinguisher for Full-Round {FUTURE}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1891},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1891}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.