Paper 2026/567

Accurate Parameter Estimates for Punctured Key Recovery Linear Attacks

TIm Beyne, KU Leuven
Antonio Flórez-Gutiérrez, NTT (Japan)
Yosuke Todo, NTT (Japan)
Abstract

At EUROCRYPT 2024, Flórez-Gutiérrez and Todo introduced the puncturing technique for linear key recovery attacks. Puncturing works by modifying the map which evaluates the linear approximation as a function of the plaintext, ciphertext and key by setting carefully chosen coordinates of its Fourier transform to zero. These modifications are intended to reduce the time complexity of the attack at the cost of an increase in data complexity. In this note, we revisit the model which is used to estimate the data complexity, clarify some of its underlying assumptions, and improve its accuracy. This leads to a revision of the cost estimates for several applications of puncturing in the literature, most notably for attacks whose data complexity is close to the full codebook.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
linear cryptanalysispuncturing
Contact author(s)
tim beyne @ esat kuleuven be
antonio florez @ ntt com
yosuke todo @ ntt com
History
2026-03-22: approved
2026-03-21: received
See all versions
Short URL
https://ia.cr/2026/567
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/567,
      author = {TIm Beyne and Antonio Flórez-Gutiérrez and Yosuke Todo},
      title = {Accurate Parameter Estimates for Punctured Key Recovery Linear Attacks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/567},
      year = {2026},
      url = {https://eprint.iacr.org/2026/567}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.