Cryptanalysis of TFHE-Friendly Cipher FRAST

dc.contributor.authorBak, Antoine
dc.contributor.authorGhosh, Shibam
dc.contributor.authorLiu, Fukang
dc.contributor.authorMeier, Willi
dc.contributor.authorNi, Jianqiang
dc.contributor.authorPerrin, Léo
dc.date.accessioned2026-06-19T07:40:53Z
dc.date.issued2026
dc.description.abstractFRAST is a TFHE-friendly stream cipher that was published at FSE 2025. The cipher is defined over Z16, and makes extensive use of negacyclic S-boxes over Z16 as they are less costly in TFHE. Like many FHE-friendly ciphers, FRAST randomizes some of its components to increase its security against statistical attacks. In the case of FRAST, some S-boxes are randomized using an XOF that takes a nonce as input. In this work, we point out a strong structural property of the full FRAST permutation, which leads to a much simpler alternative representation of the primitive. We study the consequences of this representation and find a weak key space of non-negligible size (i.e., much larger than 2128) on which every ciphertext leaks one bit of plaintext. This corresponds to a distinguishing attack on the full FRAST in the weak-key setting. In particular, we emphasize that, apart from the structural property, the usage of negacyclic S-boxes further leads to a much larger weak-key space for our attack.Finally, we provide a general framework to mount a linear attack on FRAST in the average key setting. We briefly describe our approach in the end of the paper, and observe that standard assumptions expected to work in the context of linear cryptanalysis do not hold in the case of FRAST: our experiments indicate that a linear attack in the average key setting does not work as expected.
dc.identifier.doi10.46586/tosc.v2026.i1.119-147
dc.identifier.issn2519-173X
dc.identifier.issn2569-2925
dc.identifier.urihttps://irf.fhnw.ch/handle/11645/56994
dc.identifier.urihttps://doi.org/10.26041/fhnw-16459
dc.issue1
dc.language.isoen
dc.publisherRuhr-Universität Bochum
dc.relation.ispartofIACR Transactions on Symmetric Cryptology
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subject.ddc004 - Computer Wissenschaften, Internet
dc.titleCryptanalysis of TFHE-Friendly Cipher FRAST
dc.type01A - Beitrag in wissenschaftlicher Zeitschrift
dc.volume2026
dspace.entity.typePublication
fhnw.InventedHereYes
fhnw.ReviewTypepeer-reviewed
fhnw.affiliation.hochschuleHochschule für Technik und Umwelt FHNWde_CH
fhnw.affiliation.institutInstitut für Sensorik und Elektronikde_CH
fhnw.openAccessCategoryDiamond
fhnw.pagination119-147
fhnw.publicationStatePublished
fhnw.targetcollection73d37ef7-2159-47c7-8854-323781de95db
relation.isAuthorOfPublication3649d208-8491-4eca-bd4e-574d8c3ae4e1
relation.isAuthorOfPublication.latestForDiscovery3649d208-8491-4eca-bd4e-574d8c3ae4e1
Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
ToSC2026_1_05.pdf
Größe:
826.78 KB
Format:
Adobe Portable Document Format

Lizenzbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
license.txt
Größe:
2.66 KB
Format:
Item-specific license agreed upon to submission
Beschreibung: