Ciphertext-Only Attack on HALFLOOP-24


Dansarie M., Leander G., Rasoolzadeh S., Stennes L., TEZCAN C.

17th International Conference on Cryptology in Africa, AFRICACRYPT 2026, Hammamet, Tunus, 8 - 10 Temmuz 2026, cilt.16832 LNCS, ss.187-209, (Tam Metin Bildiri)

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Cilt numarası: 16832 LNCS
  • Doi Numarası: 10.1007/978-3-032-31130-6_8
  • Basıldığı Şehir: Hammamet
  • Basıldığı Ülke: Tunus
  • Sayfa Sayıları: ss.187-209
  • Anahtar Kelimeler: ALE, Differential Cryptanalysis, Halfloop-24, HF Radio
  • Orta Doğu Teknik Üniversitesi Adresli: Evet

Özet

We present a full key-recovery ciphertext-only attack on the tweakable block cipher Halfloop-24 which is standardized by the US military and NATO for use in the Automatic Link Establishment protocol for high-frequency radio. Our attack is based on the observation that the probability-one differential, which was used for known- and chosen-plaintext attacks in prior works, can be viewed as a probability-p differential when the plaintexts are unknown, where p is the network-dependent probability that plaintext differences line up with tweak differences. Further, due to the fact that the tweak is publicly known, the specific values of the plaintexts are not necessary to identify the correct key. Our attack has a theoretical complexity of roughly 265 encryptions, given a favorable ALE network setup that allows us to collect enough suitable ciphertexts. To give a hardware-grounded estimate of the cost of the whole attack, we provide optimized CPU and GPU implementations.