[Resource Topic] 2025/1330: Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium

Welcome to the resource topic for 2025/1330

Title:
Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium

Authors: Jiahui He, Kai Hu, Guowei Liu

Abstract:

The cube attack is one of the most powerful attacks on stream ciphers, with recovering the superpoly as its key step. The core monomial prediction is the state-of-the-art technique for superpoly recovery, which can reach 851 rounds for Trivium thus far (EUROCRYPT 2024). The core monomial prediction heavily relies on the trail enumeration which is the bottleneck for its efficiency.

This paper further explores the potential of the core monomial prediction for Trivium by constructing a composite representation for the superpoly. This representation allows us to detect the algebraic structure of the superpoly under specific conditions on the intermediate variables, without the computational burden of trail enumerations. Leveraging these discovered conditions, we successfully recovered weak-key superpolies for 852-round Trivium, establishing the first cryptanalytic result against 852-round Trivium in the literature to date.

ePrint: https://eprint.iacr.org/2025/1330

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .