Paper 2026/2045

Practical Key Recovery Attacks on Full DuX and Reduced-Round YuX

Xingwei Ren, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Bo Xu, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Zhenyu Xiong, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Yongqiang Li, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Mingsheng Wang, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Abstract

DuX and YuX are recent block cipher families designed for efficient evaluation under fully homomorphic encryption. Both keep sixteen words of a large finite field in four blocks, with a low-degree block-wise S-box and a circulant linear layer. We show that, in the chosen-ciphertext model, the algebraic degree of their decryption functions grows far more slowly than the designers' encryption-side evaluation suggests, and we turn this into practical key-recovery attacks. Our starting point is a sufficient criterion for zero sums. It treats affine subspaces in characteristic 2, full prime fields, and multiplicative cosets uniformly, then over prime fields it is tight on every cell we could compute exactly. To turn it into attacks, we add full-block structures, cheap-coordinate elimination, and weighted moments. The first makes the initial S-box layer free, the second extracts equations from states that are only partially balanced, and the third yields thousands of equations from a single structure. We recover the master key of the full twelve-round DuX over $\mathbb{F}_{65537}$ from $2^{32}$ chosen ciphertexts in 45 core-hours, executed on random keys. For YuX, we recover the key of eleven of the fourteen rounds of both YupX-65537 and Yu2X-16 from $2^{32}$ chosen ciphertexts, with both attacks experimentally executed, reducing the data complexity for Yu2X-16 from the previously reported $2^{96}$ to $2^{32}$. Our distinguishers on DuX coincide with those of independent concurrent work by Liu and Sun (eprint 2026/1907). Furthermore, our key recovery attack lowers the data complexity of their full-round attack from $2^{67.58}$ to $2^{32}$.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
DuXYuXhigher-order differential attackzero-sum distinguisherkey recovery
Contact author(s)
renxingwei @ iie ac cn
xubo2024 @ iie ac cn
xiongzhenyu @ iie ac cn
liyongqiang @ iie ac cn
wangmingsheng @ iie ac cn
History
2026-09-17: last of 5 revisions
2026-09-15: received
See all versions
Short URL
https://ia.cr/2026/2045
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2045,
      author = {Xingwei Ren and Bo Xu and Zhenyu Xiong and Yongqiang Li and Mingsheng Wang},
      title = {Practical Key Recovery Attacks on Full {DuX} and Reduced-Round {YuX}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2045},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2045}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.