Paper 2025/1330
Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium
Abstract
The cube attack is one of the most powerful attacks on stream ciphers, with recovering the superpoly as its key step. The core monomial prediction is the state-of-the-art technique for superpoly recovery, which can reach 851 rounds for Trivium thus far (EUROCRYPT 2024). The core monomial prediction heavily relies on the trail enumeration which is the bottleneck for its efficiency. This paper further explores the potential of the core monomial prediction for Trivium by constructing a composite representation for the superpoly. This representation allows us to detect the algebraic structure of the superpoly under specific conditions on the intermediate variables, without the computational burden of trail enumerations. Leveraging these discovered conditions, we successfully recovered weak-key superpolies for 852-round Trivium, establishing the first cryptanalytic result against 852-round Trivium in the literature to date.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Cube AttackCore Monomial PredictionSuperpoly RecoveryTrivium
- Contact author(s)
-
hejiahui2020 @ mail sdu edu cn
kai hu @ sdu edu cn
guoweiliu @ mail sdu edu cn - History
- 2025-07-22: approved
- 2025-07-21: received
- See all versions
- Short URL
- https://ia.cr/2025/1330
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1330,
author = {Jiahui He and Kai Hu and Guowei Liu},
title = {Exploring Core Monomial Prediction Further: Weak-Key Superpoly Recovery for 852-Round Trivium},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1330},
year = {2025},
url = {https://eprint.iacr.org/2025/1330}
}