Paper 2026/205

Differential-Linear Attacks from New Distinguishers: the case of SERPENT and PRESENT

Thierno Mamoudou Sabaly, Université de Lorraine, CNRS, Inria, LORIA, F-54000, Nancy, France
Marine Minier, Université de Lorraine, CNRS, Inria, LORIA, F-54000, Nancy, France
Abstract

Differential-linear distinguishers have been introduced by Langford and Hellman in 1994. They consist in combining, first, a differential distinguisher and second, a linear distinguisher and then study the bias between plaintexts with a difference and linear approximations of the two ciphertexts to create a differential-linear distinguisher. The original method has been improved by Bar-On et al. in 2019 where the table called the DLCT (Differential Linear Connectivity Table) has been introduced and more recently, in 2024 by Hadipour et al. where, as for the case of boomerang distinguishers, several intermediate tables are used to tune the computation of the middle part of the distinguisher. From a distinguisher, it is thus natural to try to mount some dedicated attacks. This step has been done by Broll et al. in 2021 and in 2022 for the case of SERPENT. In this paper, we propose a tool that directly searches for the best differential-linear attacks automating the work of Broll et al. using the differential-linear distinguishers proposed by Hadipour et al. More precisely, both searches (distinguishers and attacks) are done in the same step to improve the overall complexity of the differential-linear attack. We apply this tool to the case of SERPENT and PRESENT. The attack against SERPENT reaches 12 rounds with a time complexity equal to $2^{220.9}$ for a data/memory complexity equal to $2^{125.01}$. The attack against PRESENT-80 (PRESENT-128 respectively) reaches 16 (18 respectively) rounds with a time complexity equal to $2^{73.88}$ ($2^{124}$ respectively) for a data/memory complexity equal to $2^{57.88}$ ($2^{63.25}$ respectively).

Note: Add the reference to the linear attack on SERPENT prior to our work: This attack's starting point is the Sbox S2, while ours starts at the first round of the cipher.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published elsewhere. Minor revision. Journal Design, Codes and Cryptography
DOI
https://doi.org/10.1007/s10623-025-01790-x
Keywords
Block ciphersDifferential-Linear DistinguishersDifferential-Linear AttacksAutomatic Tools
Contact author(s)
thierno-mamoudou sabaly @ loria fr
marine minier @ loria fr
History
2026-04-13: last of 3 revisions
2026-02-09: received
See all versions
Short URL
https://ia.cr/2026/205
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/205,
      author = {Thierno Mamoudou Sabaly and Marine Minier},
      title = {Differential-Linear Attacks from New Distinguishers: the case of {SERPENT} and {PRESENT}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/205},
      year = {2026},
      doi = {https://doi.org/10.1007/s10623-025-01790-x},
      url = {https://eprint.iacr.org/2026/205}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.