{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T14:10:36Z","timestamp":1780668636316,"version":"3.54.1"},"reference-count":29,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T00:00:00Z","timestamp":1704758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,3,5]]},"abstract":"<jats:p>At CHES 2017, Banik et al. proposed a lightweight block cipher GIFT consisting of two versions GIFT-64 and GIFT-128. Recently, there are lots of authenticated encryption schemes that adopt GIFT-128 as their underlying primitive, such as GIFT-COFB and HyENA. To promote a comprehensive perception of the soundness of the designs, we evaluate their security against differential-linear cryptanalysis.<\/jats:p>\n          <jats:p>For this, automatic tools have been developed to search differential-linear approximation for the ciphers based on S-boxes. With the assistance of the automatic tools, we find 13-round differential-linear approximations for GIFT-COFB and HyENA. Based on the distinguishers, 18-round key-recovery attacks are given for the message processing phase and initialization phase of both ciphers. Moreover, the resistance of GIFT-64\/128 against differential-linear cryptanalysis is also evaluated. The 12-round and 17-round differential-linear approximations are found for GIFT-64 and GIFT-128 respectively, which lead to 18-round and 19-round key-recovery attacks respectively. Here, we stress that our attacks do not threaten the security of these ciphers. <\/jats:p>","DOI":"10.62056\/a6n5txol7","type":"journal-article","created":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T19:27:10Z","timestamp":1712690830000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":6,"title":["Differential-Linear Cryptanalysis of GIFT family and GIFT-based Ciphers"],"prefix":"10.62056","author":[{"given":"Shichang","family":"Wang","sequence":"first","affiliation":[{"name":"Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS","place":["Beijing, China"]},{"name":"School of Cyber Security, University of Chinese Academy of Sciences","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meicheng","family":"Liu","sequence":"additional","affiliation":[{"name":"Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS","place":["Beijing, China"]},{"name":"School of Cyber Security, University of Chinese Academy of Sciences","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiqi","family":"Hou","sequence":"additional","affiliation":[{"name":"Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS","place":["Beijing, China"]},{"name":"School of Cyber Security, University of Chinese Academy of Sciences","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongdai","family":"Lin","sequence":"additional","affiliation":[{"name":"Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS","place":["Beijing, China"]},{"name":"School of Cyber Security, University of Chinese Academy of Sciences","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"ref1:DBLP:conf\/ches\/BanikPPSST17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1007\/978-3-319-66787-4_16","article-title":"GIFT: A Small Present - Towards Reaching the Limit of\n  Lightweight Encryption","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2017 -\n  19th International Conference, Taipei, Taiwan, September 25-28, 2017,\n  Proceedings","volume":"10529","author":"Subhadeep Banik","year":"2017"},{"key":"ref2:gift_cofb","article-title":"GIFT-COFB","author":"Subhadeep Banik","year":"2021","journal-title":"NIST Lightweight Cryptography Project"},{"key":"ref3:hyena","article-title":"HyENA","author":"Avik Chakraborti","year":"2019","journal-title":"NIST Lightweight Cryptography Project"},{"key":"ref4:DBLP:conf\/crypto\/BihamS90","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/3-540-38424-3_1","article-title":"Differential Cryptanalysis of DES-like Cryptosystems","volume-title":"Advances in Cryptology - CRYPTO '90, 10th Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  11-15, 1990, Proceedings","volume":"537","author":"Eli Biham","year":"1990"},{"key":"ref5:DBLP:conf\/eurocrypt\/Matsui93","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1007\/3-540-48285-7_33","article-title":"Linear Cryptanalysis Method for DES Cipher","volume-title":"Advances in Cryptology - EUROCRYPT '93, Workshop on the\n  Theory and Application of of Cryptographic Techniques, Lofthus, Norway, May\n  23-27, 1993, Proceedings","volume":"765","author":"Mitsuru Matsui","year":"1993"},{"key":"ref6:DBLP:conf\/crypto\/LangfordH94","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/3-540-48658-5_3","article-title":"Differential-Linear Cryptanalysis","volume-title":"Advances in Cryptology - CRYPTO '94, 14th Annual\n  International Cryptology Conference, Santa Barbara, California, USA, August\n  21-25, 1994, Proceedings","volume":"839","author":"Susan K. Langford","year":"1994"},{"key":"ref7:DBLP:journals\/joc\/BlondeauLN17","doi-asserted-by":"publisher","first-page":"859","DOI":"10.1007\/s00145-016-9237-5","article-title":"Differential-Linear Cryptanalysis Revisited","volume":"30","author":"C\u00e9line Blondeau","year":"2017","journal-title":"J. Cryptol."},{"key":"ref8:DBLP:conf\/eurocrypt\/Bar-OnDKW19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/978-3-030-17653-2_11","article-title":"DLCT: A New Tool for Differential-Linear Cryptanalysis","volume-title":"Advances in Cryptology - EUROCRYPT 2019 - 38th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Darmstadt, Germany, May 19-23, 2019, Proceedings, Part I","volume":"11476","author":"Achiya Bar-On","year":"2019"},{"key":"ref9:DBLP:conf\/crypto\/BeierleLT20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56877-1_12","article-title":"Improved Differential-Linear Attacks with Applications to\n  ARX Ciphers","volume-title":"Advances in Cryptology - CRYPTO 2020 - 40th Annual\n  International Cryptology Conference, CRYPTO 2020, Santa Barbara, CA, USA,\n  August 17-21, 2020, Proceedings, Part III","volume":"12172","author":"Christof Beierle","year":"2020"},{"key":"ref10:DBLP:conf\/eurocrypt\/CoutinhoN21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1007\/978-3-030-77870-5_25","article-title":"Improved Linear Approximations to ARX Ciphers and Attacks\n  Against ChaCha","volume-title":"Advances in Cryptology - EUROCRYPT 2021 - 40th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Zagreb, Croatia, October 17-21, 2021, Proceedings, Part I","volume":"12696","author":"Murilo Coutinho","year":"2021"},{"key":"ref11:DBLP:conf\/crypto\/LiuLL21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1007\/978-3-030-84252-9_9","article-title":"Differential-Linear Cryptanalysis from an Algebraic\n  Perspective","volume-title":"Advances in Cryptology - CRYPTO 2021 - 41st Annual\n  International Cryptology Conference, CRYPTO 2021, Virtual Event, August\n  16-20, 2021, Proceedings, Part III","volume":"12827","author":"Meicheng Liu","year":"2021"},{"key":"ref12:DBLP:conf\/eurocrypt\/LiuSL21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"741","DOI":"10.1007\/978-3-030-77870-5_26","article-title":"Rotational Cryptanalysis from a Differential-Linear\n  Perspective - Practical Distinguishers for Round-Reduced FRIET, Xoodoo, and\n  Alzette","volume-title":"Advances in Cryptology - EUROCRYPT 2021 - 40th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Zagreb, Croatia, October 17-21, 2021, Proceedings, Part I","volume":"12696","author":"Yunwen Liu","year":"2021"},{"key":"ref13:DBLP:conf\/crypto\/NiuSLL22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-031-15802-5_1","article-title":"Rotational Differential-Linear Distinguishers of ARX\n  Ciphers with Arbitrary Output Linear Masks","volume-title":"Advances in Cryptology - CRYPTO 2022 - 42nd Annual\n  International Cryptology Conference, CRYPTO 2022, Santa Barbara, CA, USA,\n  August 15-18, 2022, Proceedings, Part I","volume":"13507","author":"Zhongfeng Niu","year":"2022"},{"key":"ref14:DBLP:conf\/ctrsa\/BelliniGGMP23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-031-30872-7_10","article-title":"Fully Automated Differential-Linear Attacks Against ARX\n  Ciphers","volume-title":"Topics in Cryptology - CT-RSA 2023 - Cryptographers' Track\n  at the RSA Conference 2023, San Francisco, CA, USA, April 24-27, 2023,\n  Proceedings","volume":"13871","author":"Emanuele Bellini","year":"2023"},{"key":"ref15:DBLP:journals\/iacr\/LvJC23","first-page":"259","article-title":"A MIQCP-Based Automatic Search Algorithm for\n  Differential-Linear Trails of ARX Ciphers(Long Paper)","author":"Guangqiu Lv","year":"2023","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref16:DBLP:conf\/asiacrypt\/HuPTY23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-981-99-8727-6_14","article-title":"Revisiting Higher-Order Differential-Linear Attacks from an\n  Algebraic Perspective","volume-title":"Advances in Cryptology - ASIACRYPT 2023 - 29th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Guangzhou, China, December 4-8, 2023, Proceedings, Part\n  III","volume":"14440","author":"Kai Hu","year":"2023"},{"key":"ref17:DBLP:journals\/tosc\/ZongDCLWL21","doi-asserted-by":"publisher","first-page":"156","DOI":"10.46586\/tosc.v2021.i1.156-184","article-title":"Towards Key-recovery-attack Friendly Distinguishers:\n  Application to GIFT-128","volume":"2021","author":"Rui Zong","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref18:DBLP:journals\/tosc\/SunWW21a","doi-asserted-by":"publisher","first-page":"199","DOI":"10.46586\/tosc.v2021.i2.199-221","article-title":"Linear Cryptanalyses of Three AEADs with GIFT-128 as\n  Underlying Primitives","volume":"2021","author":"Ling Sun","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref19:DBLP:conf\/sacrypt\/SunWW21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1007\/978-3-030-99277-4_12","article-title":"Improved Attacks on GIFT-64","volume-title":"Selected Areas in Cryptography - 28th International\n  Conference, SAC 2021, Virtual Event, September 29 - October 1, 2021,\n  Revised Selected Papers","volume":"13203","author":"Ling Sun","year":"2021"},{"key":"ref20:DBLP:conf\/icics\/ChenZD19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1007\/978-3-030-41579-2_26","article-title":"Improved Differential Attacks on GIFT-64","volume-title":"Information and Communications Security - 21st International\n  Conference, ICICS 2019, Beijing, China, December 15-17, 2019, Revised\n  Selected Papers","volume":"11999","author":"Huaifeng Chen","year":"2019"},{"key":"ref21:DBLP:journals\/iacr\/JiZZD20","first-page":"1242","article-title":"Improved (Related-key) Differential Cryptanalysis on\n  GIFT","author":"Fulei Ji","year":"2020","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref22:DBLP:conf\/ctrsa\/ZhuDY19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"372","DOI":"10.1007\/978-3-030-12612-4_19","article-title":"MILP-Based Differential Attack on Round-Reduced GIFT","volume-title":"Topics in Cryptology - CT-RSA 2019 - The Cryptographers'\n  Track at the RSA Conference 2019, San Francisco, CA, USA, March 4-8, 2019,\n  Proceedings","volume":"11405","author":"Baoyu Zhu","year":"2019"},{"key":"ref23:DBLP:conf\/sacrypt\/JiZZD20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/978-3-030-81652-0_8","article-title":"Improved (Related-key) Differential Cryptanalysis on\n  GIFT","volume-title":"Selected Areas in Cryptography - SAC 2020 - 27th\n  International Conference, Halifax, NS, Canada (Virtual Event), October 21-23,\n  2020, Revised Selected Papers","volume":"12804","author":"Fulei Ji","year":"2020"},{"key":"ref24:DBLP:journals\/tosc\/SunWW22","doi-asserted-by":"publisher","first-page":"212","DOI":"10.46586\/TOSC.V2022.I1.212-219","article-title":"Addendum to Linear Cryptanalyses of Three AEADs with\n  GIFT-128 as Underlying Primitives","volume":"2022","author":"Ling Sun","year":"2022","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref25:DBLP:conf\/cisc\/MouhaWGP11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/978-3-642-34704-7_5","article-title":"Differential and Linear Cryptanalysis Using Mixed-Integer\n  Linear Programming","volume-title":"Information Security and Cryptology - 7th International\n  Conference, Inscrypt 2011, Beijing, China, November 30 - December 3, 2011.\n  Revised Selected Papers","volume":"7537","author":"Nicky Mouha","year":"2011"},{"key":"ref26:DBLP:conf\/asiacrypt\/SunHWQMS14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/978-3-662-45611-8_9","article-title":"Automatic Security Evaluation and (Related-key) Differential\n  Characteristic Search: Application to SIMON, PRESENT, LBlock, DES(L) and\n  Other Bit-Oriented Block Ciphers","volume-title":"Advances in Cryptology - ASIACRYPT 2014 - 20th\n  International Conference on the Theory and Application of Cryptology and\n  Information Security, Kaoshiung, Taiwan, R.O.C., December 7-11, 2014.\n  Proceedings, Part I","volume":"8873","author":"Siwei Sun","year":"2014"},{"key":"ref27:cryptoeprint:2014:747","article-title":"Towards Finding the Best Characteristics of Some\n  Bit-oriented Block Ciphers and Automatic Enumeration of (Related-key)\n  Differential and Linear Characteristics with Predefined Properties","author":"Siwei Sun","year":"2014"},{"key":"ref28:DBLP:conf\/eurocrypt\/Leurent16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1007\/978-3-662-49890-3_14","article-title":"Improved Differential-Linear Cryptanalysis of 7-Round\n  Chaskey with Partitioning","volume-title":"Advances in Cryptology - EUROCRYPT 2016 - 35th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Vienna, Austria, May 8-12, 2016, Proceedings, Part I","volume":"9665","author":"Ga\u00ebtan Leurent","year":"2016"},{"key":"ref29:DBLP:journals\/joc\/Selcuk08","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s00145-007-9013-7","article-title":"On Probability of Success in Linear and Differential\n  Cryptanalysis","volume":"21","author":"Ali Aydin Sel\u00e7uk","year":"2008","journal-title":"J. Cryptol."}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T21:25:18Z","timestamp":1733865918000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/1\/13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,9]]},"references-count":29,"URL":"https:\/\/doi.org\/10.62056\/a6n5txol7","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,9]]},"assertion":[{"value":"2024-01-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-05","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-1-40"}}