Remarks on Mixture and Yoyo Distinguishers for Reduced-Round AES
Chunhui Duan, Lin Tan, Wen‐Feng Qi · 2020 5th International Conference on Computer and Communication Systems (ICCCS) · 2020
Reduced-round AES has been the popular building block to design new cryptographic schemes. The key-independent distinguishers were known up to 4 rounds of AES until Grassi et al. proposed the multiple-of-8 distinguisher on 5-round AES in Eurocrypt 2017. Later Grassi translated it into a simpler one and proposed the mixture differential distinguisher on 4-round AES. In Asiacrypt 2017, Rønjom et al. proposed the yoyo distinguishers on reduced-round AES, and gave the first key-independent distinguisher on 6-round AES in the adaptively chosen plaintexts/ciphertexts setting. In this paper, we study the relationship between yoyo distinguisher and mixture differential distinguisher for 4-round AES. It is shown that yoyo distinguisher on complete 4-round AES can be understood as a generalized mixture differential distinguisher. The second work of this paper is to improve the yoyo distinguisher on 6-round AES. Instead of finding good pair randomly, we find good pairs by fixing plantexts in some coset of some subspace. Making use of the properties of mixture and good pairs, the number of yoyo needed to do for distinguishing random permutation from 6-round AES can be reduced. We slightly improve the yoyo distinguisher on 6-round AES, reducing the required plaintext/ciphertext pairs from 2122.83to 2121.39.