close

Paper 2025/1330

Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium

Jiahui He, Shandong University
Kai Hu, Shandong University
Guowei Liu, Shandong University
Abstract

The cube attack is one of the most powerful attacks on stream ciphers, with recovering the superpoly as its key step. The core monomial prediction is the state-of-the-art technique for superpoly recovery, which can reach 851 rounds for Trivium thus far (EUROCRYPT 2024). The core monomial prediction heavily relies on the trail enumeration which is the bottleneck for its efficiency. This paper further explores the potential of the core monomial prediction for Trivium by constructing a composite representation for the superpoly. This representation allows us to detect the algebraic structure of the superpoly under specific conditions on the intermediate variables, without the computational burden of trail enumerations. Leveraging these discovered conditions, we successfully recovered weak-key superpolies for 852-round Trivium, establishing the first cryptanalytic result against 852-round Trivium in the literature to date.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Cube AttackCore Monomial PredictionSuperpoly RecoveryTrivium
Contact author(s)
hejiahui2020 @ mail sdu edu cn
kai hu @ sdu edu cn
guoweiliu @ mail sdu edu cn
History
2025-07-22: approved
2025-07-21: received
See all versions
Short URL
https://ia.cr/2025/1330
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1330,
      author = {Jiahui He and Kai Hu and Guowei Liu},
      title = {Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1330},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1330}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.