The First Biclique Cryptanalysis of Serpent-256
Gabriel C. de Carvalho, Luis Antônio Brasil Kowada · 2020
The Serpent cipher was one of the finalists of the AES process and as of today there is no method for finding the key with fewer attempts than that of an exhaustive search of all possible keys, even when using known or chosen plaintexts for an attack. This work presents the first two biclique attacks for the full-round Serpent-256. The first uses a dimension 4 biclique while the second uses a dimension 8 biclique. The one with lower dimension covers nearly 4 complete rounds of the cipher, which is the reason for the lower time complexity when compared with the other attack (which covers nearly 3 rounds of the cipher). On the other hand, the second attack needs a lot less pairs of plaintexts for it to be done. The attacks require 2255.21 and 2255.45 full computations of Serpent-256 using 288 and 260 chosen ciphertexts respectively with negligible memory.