Experimentally Obtained Differential-Linear Distinguishers for Permutations of ASCON and DryGASCON


7th and 8th International Conferences on Information Systems Security and Privacy, ICISSP 2021 and ICISSP 2022, Virtual, Online, 9 - 11 February 2022, vol.1851 CCIS, pp.91-103 identifier

  • Publication Type: Conference Paper / Full Text
  • Volume: 1851 CCIS
  • Doi Number: 10.1007/978-3-031-37807-2_5
  • City: Virtual, Online
  • Page Numbers: pp.91-103
  • Keywords: Cryptanalysis, Differential-linear, Lightweight cryptography, NIST
  • Middle East Technical University Affiliated: Yes


DryGASCON and Ascon are two similar authenticated encryption algorithms submitted to NIST’s recently finalized lightweight cryptography competition. DryGASCON was eliminated after the second round, while Ascon won the competition and became the new lightweight cryptography standard. We analyze these two ciphers using differential-linear distinguishers to better understand their security. By using the parallel computing power of GPUs, we show that better distinguishers can be obtained experimentally in practice which cannot be obtained theoretically by known methods. We offer the best experimentally obtained 5-round differential-linear distinguishers for the permutations of Ascon and DryGASCON. We also provide related-key differential-linear attacks on 5-round Ascon.