Paper 2024/1801

Investigation of the Optimal Linear Characteristics of BAKSHEESH (Full Version)

Yuxuan Peng, Shandong University
Jinpeng Liu, Shandong University
Ling Sun, Shandong University
Abstract

This paper aims to provide a more comprehensive understanding of the optimal linear characteristics of BAKSHEESH. Initially, an explicit formula for the absolute correlation of the $R$-round optimal linear characteristic of BAKSHEESH is proposed when $R \geqslant 12$. By examining the linear characteristics of BAKSHEESH with three active S-boxes per round, we derive some properties of the three active S-boxes in each round. Furthermore, we demonstrate that there is only one 1-round iterative linear characteristic with three active S-boxes. Since the 1-round linear characteristic is unique, it must be included in any $R$-round ($R \geqslant 12$) linear characteristics of BAKSHEESH with three active S-boxes per round. Finally, we confirm that BAKSHEESH's total number of $R$-round optimal linear characteristics is $3072$ for $R \geqslant 12$. All of these characteristics are generated by employing the 1-round iterative linear characteristic.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Major revision. ICISC 2024
Keywords
Linear cryptanalysisLinear characteristicBAKSHEESH
Contact author(s)
lingsun @ sdu edu cn
History
2024-11-08: approved
2024-11-04: received
See all versions
Short URL
https://ia.cr/2024/1801
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/1801,
      author = {Yuxuan Peng and Jinpeng Liu and Ling Sun},
      title = {Investigation of the Optimal Linear Characteristics of {BAKSHEESH} (Full Version)},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1801},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1801}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.