arrow
Return

Exponential Sums in Linear Cryptanalysis

delete2026-02-20
delete0
PRE
AI
T
Tim Beyne *
C
Clémence Bouvier
DOI:10.1007/s00145-026-09575-8delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
It is shown how bounds on exponential sums derived from modern algebraic geometry, and & ell;\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\ell $$\end{document}-adic cohomology specifically, can be used to upper bound the absolute correlations of linear approximations for cryptographic constructions of low algebraic degree. This is illustrated by applying results of Deligne, Denef and Loeser, and Rojas-Le & oacute;n, to obtain correlation bounds for a generalization of the Butterfly construction, three-round Feistel ciphers, and a generalization of the Flystel construction. For each of these constructions, bounds obtained using other methods are significantly weaker. In the case of the Flystel construction, our bounds resolve a conjecture by the designers. Correlation bounds of this type are relevant for the development of security arguments against linear cryptanalysis, especially in the weak-key setting or for primitives that do not involve a key. Since the methods used in this paper are applicable to constructions defined over arbitrary finite fields, the results are also relevant for arithmetization-oriented primitives such as Anemoi, which uses S-boxes based on the Flystel construction.
Keywords:
Linear cryptanalysis
Algebraic exponential sums
Butterfly
Feistel
Flystel

Journal

J
Journal of Cryptology
IF:
2.2
Papers:
29
Citations:
2.5K

Organization

K
ku leuven
Scholars:
6.9K
Papers: 3.0K
Citations: 1
R
ruhr university bochum
Scholars:
2.3W
Papers: 1.9W
Citations: 14