Skip to main content

Table 2 Comparison of key-recovery attacks on TWINE-128

From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers

Model

Attack

rounds

Data per key

Time

Memory

Ref.

RK

Key Diff Inv Bias

27

262.95RKKP

2119.5

261

(Bogdanov et al. 2013)

 

Key Diff Inv Bias

27

262.3RKDKP

2119.5

261

this paper

 

Key Diff Inv Bias

27

260.44RKDKP

2119.5

15·261

this paper

 

Key Diff Inv Bias

28

261.5RKDKP

2126.15

261

this paper

SK

Saturation

23

262.81CP

2106.14

2103

(Suzaki et al. 2012)

 

Imp.Diff

24

252.21CP

2115.10

2118

(Suzaki et al. 2012)

 

Meet-in-the-Middle

25

248CP

2122

2125

(Boztas et al. 2013)

 

Zero-Correlation

25

262.1KP

2122.12

260

(Wang and Wu 2014)