@article{Sun_Wang_Wang_2021, title={Linear Cryptanalyses of Three AEADs with GIFT-128 as Underlying Primitives}, volume={2021}, url={https://tosc.iacr.org/index.php/ToSC/article/view/8909}, DOI={10.46586/tosc.v2021.i2.199-221}, abstractNote={<p>This paper considers the linear cryptanalyses of Authenticated Encryptions with Associated Data (AEADs) GIFT-COFB, SUNDAE-GIFT, and HyENA. All of these proposals take GIFT-128 as underlying primitives. The automatic search with the Boolean satisfiability problem (SAT) method is implemented to search for linear approximations that match the attack settings concerning these primitives. With the newly identified approximations, we launch key-recovery attacks on GIFT-COFB, SUNDAE-GIFT, and HyENA when the underlying primitives are replaced with 16-round, 17-round, and 16-round versions of GIFT-128. The resistance of GIFT-128 against linear cryptanalysis is also evaluated. We present a 24-round key-recovery attack on GIFT-128 with a newly obtained 19-round linear approximation. We note that the attack results in this paper are far from threatening the security of GIFT-COFB, SUNDAE-GIFT, HyENA, and GIFT-128.</p>}, number={2}, journal={IACR Transactions on Symmetric Cryptology}, author={Sun, Ling and Wang, Wei and Wang, Meiqin}, year={2021}, month={Jun.}, pages={199–221} }