Saturation cryptanalysis of CLEFIA

The saturation attack on a novel block cipher CLEFIA,which was proposed in FSE 2007,was reevaluated.The flaws in Shirai et al’s 8 round distinguishers were pointed out and corrected.In order to reduce the number of guessed subkeys,the attack utilized the movement of the whitening key to combine it with subkey,and explored a di-vide-and-conquer strategy.The partial sum technique was adopted to reduce the time complexity.As a result,the satura-tion attack can be extended from 10 round variant without key whitenings to 11 round CLEFIA-128/192/256,and is ap-plicable to 12 round CLEFIA-192/256 and 13 round CLEFIA-256.