Paper 2026/2013
Revisiting Differential-Linear Cryptanalysis via a Walsh-Transform Perspective
Abstract
Standard differential-linear (SDL) cryptanalysis has matured rapidly, now backed by the SDL connectivity table (SDLCT) framework, multi-round middle-part extensions, and automated CP-based search models. The rotational differential-linear (RDL) variant lacks even an SDLCT counterpart, and the analogous combination of internal differentials with linear approximations, which we call internal differential-linear (IDL) cryptanalysis, has never been formulated. We unify SDL, RDL, and IDL in a single Walsh-transform framework on the difference transition function (DTF). Existing SDL machinery, including recent multi-round middle-part search models, transfers to RDL and IDL, yielding efficient correlation computation and distinguisher search. For ARX primitives, we derive a $2\times 2$ matrix-product formula for the SDL and RDL correlations of a single modular addition. The formula exposes a rank-$1$ structure on the input-difference matrix that decouples the running product into independent factors, making a CP approximation with only linear inequalities and table lookups practical. This partially resolves the open problem of Niu et al. (CRYPTO 2022). We apply the framework to \xoodoo-$p$, \ascon-$p$, \alzette, \siphash, and \specksixtyfour. For \xoodoo-$p$, we obtain a 6-round RDL distinguisher and the first IDL distinguisher in the literature (both at 6 rounds). For \ascon-$p$, the first RDL distinguisher (6 rounds). For \alzette, an 8-round RDL distinguisher, doubling the previous 4-round best. For \siphash, the longest known distinguisher (5 rounds). For \specksixtyfour, the longest known SDL distinguisher (14 rounds).
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Differential-linearARXXoodooAsconSipHashSPECKChaskeyAlzette
- Contact author(s)
-
jhe @ esat kuleuven be
kai hu @ sdu edu cn
zhongfeng niu @ ntu edu sg
bart preneel @ esat kuleuven be
mqwang @ sdu edu cn - History
- 2026-09-14: approved
- 2026-09-14: received
- See all versions
- Short URL
- https://ia.cr/2026/2013
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2013,
author = {Jiahui He and Kai Hu and Zhongfeng Niu and Bart Preneel and Meiqin Wang},
title = {Revisiting Differential-Linear Cryptanalysis via a Walsh-Transform Perspective},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2013},
year = {2026},
url = {https://eprint.iacr.org/2026/2013}
}