Improving Linear Key Recovery Attacks using Walsh Spectrum Puncturing
摘要
In most linear key recovery attacks on block ciphers, the value of the target linear approximation is determined from the plaintext, ciphertext and key by a function. In some existing attacks, this map is replaced by a similar one in order to improve the time or memory complexity at the cost of a data complexity penalty. This paper proposes a general framework for key recovery map substitution, and introduces Walsh spectrum, which removes carefully-chosen coefficients from the Fourier transform of the key recovery map. The capabilities of this technique are illustrated by describing improved attacks on reduced-round Serpent (including the first 12-round attack on the 192-bit key variant), GIFT-128 and Noekeon, as well as the full DES.