LiCi2 Squeezed Dry - Full Key Recovery in Practice
Cezary Pilaszewicz, Nina Matthias and Marian Margraf – 2026
We present a cryptanalysis of the lightweight block cipher LiCi2 and identify a fundamental flaw in its design. Due to an overlooked structural weakness, the right half of the ciphertext receives no effective mixing during encryption. Instead, it is obtained by XORing the plaintext with the aggregate sum of the round keys, which immediately yields a perfect distinguisher. Building on this observation, we develop a related-key attack that exploits the weak algebraic structure of the key schedule. Using a low-dimensional cube technique, we recover superpolies and derive relations that enable efficient computation of the secret key. Our results demonstrate that LiCi2 is vulnerable to both distinguishing and key-recovery attacks, rendering the cipher insecure for practical use.