Invariant Cryptanalysis
Christof Beierle · 2023
Compared to statistical cryptanalytic attacks such as differential and linear attacks, invariant attacks exploit an undesired, structural property of block ciphers and cryptographic permutations, namely, the property that a partition of the plaintext space into a set S and its complement is preserved under the application of the block cipher. This chapter presents the important concepts and ideas behind invariant subspace attacks and nonlinear invariant attacks. It discusses methods to spot potential vulnerabilities in cryptographic designs and also methods that allow designers to provide arguments on the security of their designs with respect to those attacks. The chapter presents a link between invariant attacks and linear approximations. Designers of block ciphers are expected to provide arguments on why their design is secure against attacks based on invariants. This especially holds if a block cipher uses round keys that only differ by the addition of round-dependent constants.