Search papers, labs, and topics across Lattice.
This paper employs Local Inversion via Black Box computations to successfully recover up to 80 bits of the AES128 key under Known Plaintext Attack (KPA) conditions, demonstrating that complete key recovery is feasible with known bits. The authors extrapolate results from smaller key sizes to predict the iterative sequence's period for the full 128-bit key case, proposing a brute-force parallel search strategy for the remaining bits. Their findings indicate that AES128's key recovery can be accomplished in a practically feasible timeframe, suggesting broader implications for the cryptanalysis of similarly strong ciphers.
Recovering up to 80 bits of the AES128 key under KPA is now feasible in practical timeframes, challenging assumptions about AES's security.
This paper presents computational results of cryptanalysis of AES using the Local Inversion by Black Box computations of the forward encryption and utilizes these results to develop a practically feasible approach for the key recovery of the full scale AES128 under Known Plaintext Attack (KPA). It is shown that complete recovery of unknown key bits is possible upto $80$ bits in a practically feasible time and memory in random KPA situation by sequential computation when remaining $48$ bits are known. The results of key recovery in $64$, $72$ and $80$ bit unknown cases are extrapolated to predict the period of the iterative sequence generated in the local inversion approach for the full $128$ bit unknown key case and a strategy is proposed to search the actual period by brute force parallel search of the sequence period with $10$ free bits defining the search space. Then it is shown that the actual key can be verified in polynomial time by fast powering of the forward encryption map. Hence this strategy shows that the key recovery problem for AES128 under KPA has a high chance of success in practically feasible time. Local inversion approach to cryptanalysis using black box computations is a universal method applicable to a vast variety of key recovery and map inversion problems. Hence the results presented in this paper are representative of estimates of cryptanalysis of other ciphers which can be considered almost as strong as AES128 as encryption functions.