Paper 2026/1907

Higher-order differential attacks on the full DuX

Guoqiang Liu, College of Science, National University of Defense Technology
Bing Sun, College of Science, National University of Defense Technology
Abstract

DuX is a family of substitution-permutation block ciphers over $\mathbb{F}_q^{16}$ with $q\in\{2^{8},2^{16},65537\}$ and twelve rounds. For the two large-word instances its designers estimate that integral and higher-order differential distinguishers in the encryption direction reach at most six rounds, and fix the number of rounds accordingly. We bound the word-wise algebraic degree of DuX by exponent sets in the decryption direction, where the decryption S-box has coordinate degrees $(2,3,4,2)$ against the $(5,3,2,8)$ of the encryption S-box. Each row of the inverse diffusion matrix is supported on two residue classes of word indices modulo four. An active set equal to one class therefore keeps the vector of degree bounds constant within each class at every layer, and we prove that the four class-wise bounds then obey an exact recursion with base $2+\sqrt{3}$ instead of four. This yields higher-order differential distinguishers for eleven rounds of DuX($2^{16}$) and DuX($65537$) with $q^{4}$ chosen ciphertexts, and for seven rounds of DuX($2^{8}$) with $2^{88}$. Extending one round towards the plaintext gives three successive systems of equations. Every unknown there has a coefficient computed from the returned plaintext words, and the key words recovered at one stage are substituted into the next; for DuX($65537$) the last two systems are replaced by bivariate interpolation. Once each system attains the maximal rank that its structure permits, a condition that can be checked during the attack, solving the systems recovers all sixteen master-key words of the full twelve-round DuX($2^{16}$) and DuX($65537$). The data and time complexity is $2^{67.32}$ and $2^{67.58}$ with constant memory, and eight rounds of DuX($2^{8}$) are covered with $2^{91.32}$. The two diffusion layers differ by a rotation of four words, so the analysis is the same for each of the $2^{11}$ key-dependent choices of diffusion layers.

Note: Section 1 now contains a paragraph on the concurrent and independent work of Cryptology ePrint Archive, Paper 2026/2045, together with the corresponding bibliography entry. No result, table or figure is changed by this addition. This version also carries the revisions made before the manuscript was submitted to a journal on 11 September 2026. Theorem 3 is stated for both characteristics instead of even characteristic alone, and its third coefficient reads 2 Sigma(y_2 ybar_1) - Sigma P_0 in place of the even-characteristic form Sigma P_0. Proposition 4 carries the hypothesis that q is even, under which the entries of both diffusion matrices lie in {0,1}. The rank condition of Corollary 4 is stated in terms of the structure of each stage, and the rank counts are given per stage. The complexity of the full-round attack on DuX(65537) reads 2^67.59 in place of the truncated 2^67.58. Three entries of the degree table in Section 7 read 836, 1142 and 1560, the maxima over each class rather than the four words of the first block.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
DuXAlgebraic degreeHigher-order differential attackKey-recovery attack
Contact author(s)
liuguoqiang87 @ hotmail com
sunbing06 @ nudt edu cn
History
2026-09-17: revised
2026-09-07: received
See all versions
Short URL
https://ia.cr/2026/1907
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1907,
      author = {Guoqiang Liu and Bing Sun},
      title = {Higher-order differential attacks on the full {DuX}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1907},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1907}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.