Cryptanalysis of Gleeok-128
Siwei Chen, Peipei Xie, Shengyuan Xu, Xiutao Feng, Zejun Xiang, Xiangyong Zeng

TL;DR
This paper presents the first comprehensive cryptanalysis of Gleeok-128, introducing new differential linear distinguishers, integral distinguishers, and key recovery attacks, thereby advancing understanding of its security properties.
Contribution
It develops a novel MILP framework for analyzing multi-branch ciphers and extends security bounds, providing new insights into Gleeok-128's vulnerabilities.
Findings
Identified 7-8 round differential linear distinguishers for Gleeok-128
Extended integral distinguishers by 2-3 rounds, enabling key recovery attacks
Discovered a flaw in the original linear security evaluation of Branch 3
Abstract
Gleeok is a family of low latency keyed pseudorandom functions (PRFs) consisting of three parallel SPN based permutations whose outputs are XORed to form the final value. Both Gleeok-128 and Gleeok-256 use a 256 bit key, with block sizes of 128 and 256 bits, respectively. Owing to its multi branch structure, evaluating security margins and mounting effective key recovery attacks present nontrivial challenges. This paper provides the first comprehensive third party cryptanalysis of Gleeok-128. We introduce a two stage MILP based framework for constructing branch wise and full cipher differential linear (DL) distinguishers, together with an integral based key recovery framework tailored to multi branch designs. Our DL analysis yields 7, 7, 8, and 4 round distinguishers for Branch 1, Branch 2, Branch 3, and Gleeok-128, respectively, with squared correlations approximately 2 to the power…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptographic Implementations and Security · Coding theory and cryptography · Cryptography and Residue Arithmetic
