International Association for Cryptologic Research

International Association
for Cryptologic Research

Eurocrypt 2026

When the Wrong Key Lives On:

The Key-Recovery Procedure in Integral Attacks


Christof Beierle
Ruhr University Bochum

Gregor Leander
Ruhr University Bochum

Yevhen Perehuda
Ruhr University Bochum


Keywords: block ciphers, integral attacks, key recovery, wrong-key randomization, linear structures


Abstract

An integral distinguisher for a block cipher is defined by a nontrivial subset of plaintexts for which the bitwise sum of (parts of) a certain internal state is independent of the secret key. Such a distinguishing property can be turned into a key-recovery procedure by partially decrypting the ciphertexts under all possible keys and then filtering the key candidates using the integral distinguisher. The behavior of this filter has never been analyzed in depth, and we show that the ubiquitous hypothesis about its behavior is incorrect.

Fortunately, the deviation is either limited or can be lifted to improve the underlying attacks. By algorithmically determining the exact subspaces of key candidates to be guessed -- whose dimensions are often lower than expected -- we are able to improve upon the best known integral key-recovery attacks on various ciphers.

Publication

EUROCRYPT 2026, LNCS 16546

Paper

Artifact

Artifact number
eurocrypt/2026/a16

Artifact published
July 25, 2026

Badge
IACR EUROCRYPT Artifacts Functional

README

ZIP (24.6 KB)  

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Christof Beierle, Gregor Leander, and Yevhen Perehuda. (2026). When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16546, pp. 33–62, Springer. https://doi.org/10.1007/978-3-032-25333-0_2. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a16.