Paper 2024/1801
Investigation of the Optimal Linear Characteristics of BAKSHEESH (Full Version)
Abstract
This paper aims to provide a more comprehensive understanding of the optimal linear characteristics of BAKSHEESH. Initially, an explicit formula for the absolute correlation of the $R$-round optimal linear characteristic of BAKSHEESH is proposed when $R \geqslant 12$. By examining the linear characteristics of BAKSHEESH with three active S-boxes per round, we derive some properties of the three active S-boxes in each round. Furthermore, we demonstrate that there is only one 1-round iterative linear characteristic with three active S-boxes. Since the 1-round linear characteristic is unique, it must be included in any $R$-round ($R \geqslant 12$) linear characteristics of BAKSHEESH with three active S-boxes per round. Finally, we confirm that BAKSHEESH's total number of $R$-round optimal linear characteristics is $3072$ for $R \geqslant 12$. All of these characteristics are generated by employing the 1-round iterative linear characteristic.
Metadata
- Available format(s)
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. Major revision. ICISC 2024
- Keywords
- Linear cryptanalysisLinear characteristicBAKSHEESH
- Contact author(s)
- lingsun @ sdu edu cn
- History
- 2024-11-08: approved
- 2024-11-04: received
- See all versions
- Short URL
- https://ia.cr/2024/1801
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1801, author = {Yuxuan Peng and Jinpeng Liu and Ling Sun}, title = {Investigation of the Optimal Linear Characteristics of {BAKSHEESH} (Full Version)}, howpublished = {Cryptology {ePrint} Archive, Paper 2024/1801}, year = {2024}, url = {https://eprint.iacr.org/2024/1801} }