Paper 2026/2013

Revisiting Differential-Linear Cryptanalysis via a Walsh-Transform Perspective

Jiahui He, KU Leuven
Kai Hu, Shandong University
Zhongfeng Niu, Nanyang Technological University
Bart Preneel, KU Leuven
Meiqin Wang, Shandong University
Abstract

Standard differential-linear (SDL) cryptanalysis has matured rapidly, now backed by the SDL connectivity table (SDLCT) framework, multi-round middle-part extensions, and automated CP-based search models. The rotational differential-linear (RDL) variant lacks even an SDLCT counterpart, and the analogous combination of internal differentials with linear approximations, which we call internal differential-linear (IDL) cryptanalysis, has never been formulated. We unify SDL, RDL, and IDL in a single Walsh-transform framework on the difference transition function (DTF). Existing SDL machinery, including recent multi-round middle-part search models, transfers to RDL and IDL, yielding efficient correlation computation and distinguisher search. For ARX primitives, we derive a $2\times 2$ matrix-product formula for the SDL and RDL correlations of a single modular addition. The formula exposes a rank-$1$ structure on the input-difference matrix that decouples the running product into independent factors, making a CP approximation with only linear inequalities and table lookups practical. This partially resolves the open problem of Niu et al. (CRYPTO 2022). We apply the framework to \xoodoo-$p$, \ascon-$p$, \alzette, \siphash, and \specksixtyfour. For \xoodoo-$p$, we obtain a 6-round RDL distinguisher and the first IDL distinguisher in the literature (both at 6 rounds). For \ascon-$p$, the first RDL distinguisher (6 rounds). For \alzette, an 8-round RDL distinguisher, doubling the previous 4-round best. For \siphash, the longest known distinguisher (5 rounds). For \specksixtyfour, the longest known SDL distinguisher (14 rounds).

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
Differential-linearARXXoodooAsconSipHashSPECKChaskeyAlzette
Contact author(s)
jhe @ esat kuleuven be
kai hu @ sdu edu cn
zhongfeng niu @ ntu edu sg
bart preneel @ esat kuleuven be
mqwang @ sdu edu cn
History
2026-09-14: approved
2026-09-14: received
See all versions
Short URL
https://ia.cr/2026/2013
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2013,
      author = {Jiahui He and Kai Hu and Zhongfeng Niu and Bart Preneel and Meiqin Wang},
      title = {Revisiting Differential-Linear Cryptanalysis via a Walsh-Transform Perspective},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2013},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2013}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.