Paper 2026/567
Accurate Parameter Estimates for Punctured Key Recovery Linear Attacks
Abstract
At EUROCRYPT 2024, Flórez-Gutiérrez and Todo introduced the puncturing technique for linear key recovery attacks. Puncturing works by modifying the map which evaluates the linear approximation as a function of the plaintext, ciphertext and key by setting carefully chosen coordinates of its Fourier transform to zero. These modifications are intended to reduce the time complexity of the attack at the cost of an increase in data complexity. In this note, we revisit the model which is used to estimate the data complexity, clarify some of its underlying assumptions, and improve its accuracy. This leads to a revision of the cost estimates for several applications of puncturing in the literature, most notably for attacks whose data complexity is close to the full codebook.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- linear cryptanalysispuncturing
- Contact author(s)
-
tim beyne @ esat kuleuven be
antonio florez @ ntt com
yosuke todo @ ntt com - History
- 2026-03-22: approved
- 2026-03-21: received
- See all versions
- Short URL
- https://ia.cr/2026/567
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/567,
author = {TIm Beyne and Antonio Flórez-Gutiérrez and Yosuke Todo},
title = {Accurate Parameter Estimates for Punctured Key Recovery Linear Attacks},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/567},
year = {2026},
url = {https://eprint.iacr.org/2026/567}
}