Schwaemm is a member of the Sparkle-suite, a family of lightweight symmetric cryptographic algorithms that advanced to finalist status in the NIST lightweight cryptography standardization process. In 2023, using differential-linear cryptanalysis, Xiong and Liu presented a practical 4-round distinguisher and a theoretical 4.5-round key-recovery attack on a variant of Schwaemm128-128 that did not adhere to the original round constants. Recently, Niu et al. introduced a dedicated time-memory trade-off framework to achieve key-recovery attacks on 4.5-round Schwaemm using 2.5-round differential-linear distinguishers. This paper revisits the differential-linear cryptanalysis of round-reduced Schwaemm, focusing on the original, round-constant-respecting versions. We identify effective 4-round differential-linear trails and establish practical 4-round distinguishers with complexity below 2^13.1 . Experimental results demonstrate 100 2^9.58 and 2^15.73 ) and memory footprints (constrained between 2^27 and 2^55 ), significantly outperforming prior works. Furthermore, by extracting bit-level algebraic equations, we demonstrate that partial key information can be directly recovered with extremely low time complexities. For the respective versions, we establish a total of 36, 29, 29, and 9 equations, with time complexities of only 2^15.73 , 2^14.94 , 2^14.94 , and 2^9.58 . Among these, 9, 7, 7, and 3 are strictly linear equations, allowing for the direct recovery of an equal number of key bits, which drastically prunes the search space and reduces the time complexity of the full key-recovery process. Also, we emphasize that these attacks in this paper do not compromise the security of full Schwaemm.
更多