Return
Differential-Linear Cryptanalysis and Cube Attacks on ChiLow
DOI:10.46586/tosc.v2026.11.293-317.png)
Abstract
En 中文
CHILOW is a family of tweakable block ciphers specifically designed for embedded code encryption, proposed at EUROCRYPT 2025. Its novel nested tweak-key schedule and a variant of the x function significantly enhance latency and energy efficiency. This paper presents a security analysis of CHILOW from the perspectives of differential-fincar cryptanalysis alid cube attacks, filling Sofie gaps in the initial security analysis made by the designers. Our main contributions are threefold: (1) Distinguishing attacks based on differential-linear cryptanalysis that can distinguish full-round CHILOW from random permutations. For CHILOW-(32+tau), both the time complexity and data complexity of the attack are 281.03; for CHILOW-40, both complexities are 2(88.91). We note that the data complexities of these distinguishing attacks are valid since an adversary could query multiple devices. (2) Key recovery attacks on full-round CHILOW based on differential-linear cryptanalysis with the time complexity better than the exhaustive key search. These attacks achieve a time complexity of 2(121), with data complexities of 2(79.5 )for CHILOW-(32+tau) and 2(88.42) for CHILOW-40 exceeding the data limit for one key. (3) A key recovery attack on 6-round CHILOw based on cube attacks, with a time complexity of 2(68) and a data complexity of 2(33) respecting the limit of the total number of queries. These results shed some new light on the security boundaries of CHILOW and provide valuable insights for designing low-latency ciphers in embedded systems.
Keywords:
CHILOW
Differential-Linear Cryptanalysis
Cube Attack
MILP
Journal
I
IF:
2.2
Papers:
21
Citations:
1.1K

