{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:30:02Z","timestamp":1782977402012,"version":"3.54.5"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"1","license":[{"start":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T00:00:00Z","timestamp":1773619200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ToSC"],"abstract":"<jats:p>Linear cryptanalysis has long served as a cornerstone in the security analysis of symmetric-key cryptanalytic primitives. Through more than 30 years of community efforts, it has become routine to use automated tools to search for the optimal linear approximations. In stark contrast, the key recovery part is still far from automation and optimization. The situation became even more challenging after the work of Fl\u00f3rez-Guti\u00e9rrez and Todo [FT24], where the newly introduced Walsh Spectrum Puncturing (WSP) technique brought a large number of candidate key recovery map approximations. In this paper, we formally prove that the approximate key recovery map proposed by [FT24] is the optimal strategy for Bit Puncturing and LAT Subspace Puncturing. We then propose an MILP model to automatically search for the optimal approximate key recovery map for WSP. The automated model is used to improve the linear key recovery attack on the AES finalist Serpent and the ISO standard PRESENT. We reduce the time complexity of the 12-round Serpent key recovery attack to 2184.8 (from 2189.7) for Serpent-192 and to 2200.4 (from 2210.4) for Serpent-256. For PRESENT-128, we update the key recovery attack on its 29-round variant, and extend the attack to 30 rounds for the first time.<\/jats:p>","DOI":"10.46586\/tosc.v2026.i1.318-344","type":"journal-article","created":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:22:01Z","timestamp":1773670921000},"page":"318-344","source":"Crossref","is-referenced-by-count":1,"title":["Walsh Spectrum Puncturing Revisited: Toward Automated Linear Key Recovery Attacks"],"prefix":"10.46586","volume":"2026","author":[{"given":"Chengan","family":"Hou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuyi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meicheng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"25480","published-online":{"date-parts":[[2026,3,16]]},"container-title":["IACR Transactions on Symmetric Cryptology"],"original-title":[],"link":[{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/download\/12788\/12477","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/download\/12788\/12477","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:22:01Z","timestamp":1773670921000},"score":1,"resource":{"primary":{"URL":"https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/view\/12788"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,16]]},"references-count":0,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,3,16]]}},"URL":"https:\/\/doi.org\/10.46586\/tosc.v2026.i1.318-344","relation":{},"ISSN":["2519-173X"],"issn-type":[{"value":"2519-173X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,16]]}}}