Cryptanalysis of Reduced-Round SIMON32 and SIMON48

Cryptanalysis of Reduced-Round SIMON32 and SIMON48
复制标题

DOI:
10.1007/978-3-319-13039-2_9
复制
发表时间:
2014-12
期刊:
--
影响因子:
--
通讯作者:
Qingju Wang;Zhiqiang Liu;Kerem Varici;Yu Sasaki;V. Rijmen;Yosuke Todo
Qingju Wang;Zhiqiang Liu;Kerem Varici;Yu Sasaki;V. Rijmen;Yosuke Todo
中科院分区:
其他
文献类型:
--
作者:
Qingju Wang;Zhiqiang Liu;Kerem Varici;Yu Sasaki;V. Rijmen;Yosuke Todo

文献摘要

被引文献

相似文献

SIMON家族是NSA最近推出的轻量级分组密码设计之一。迄今为止,人们已经用差分分析、线性分析和不可能差分分析等方法对该密码进行了分析。本文利用整数、零相关线性和不可能差分密码分析方法研究了SIMON 32、SIMON 48/72和SIMON 48/96的安全性。首先,我们提出了一种新的实验方法来构建SIMON 32的最知名的积分算子。SIMON 32的小块大小,32位,使我们能够通过实验找到一个15轮的整数倍,在此基础上,我们提出了一个21轮的SIMON 32的密钥恢复攻击,而以前的最好的结果只实现了19轮。此外,我们分别基于SIMON 32和SIMON 48的11轮和12轮零相关线性壳攻击20轮SIMON 32、20轮SIMON 48/72和21轮SIMON 48/96。最后,我们提出了新的不可能差分攻击,改进了以前的不可能差分攻击。我们的分析表明,SIMON保持了足够的安全裕度。
SIMON family is one of the recent lightweight block cipher designs introduced by NSA. So far there have been several cryptanalytic results on this cipher by means of differential, linear and impossible differential cryptanalysis. In this paper, we study the security of SIMON32, SIMON48/72 and SIMON48/96 by using integral, zero-correlation linear and impossible differential cryptanalysis. Firstly, we present a novel experimental approach to construct the best known integral distinguishers of SIMON32. The small block size, 32 bits, of SIMON32 enables us to experimentally find a 15-round integral distinguisher, based on which we present a key recovery attack on 21-round SIMON32, while previous best results only achieved 19 rounds. Moreover, we attack 20-round SIMON32, 20-round SIMON48/72 and 21-round SIMON48/96 based on 11 and 12-round zero-correlation linear hulls of SIMON32 and SIMON48 respectively. Finally, we propose new impossible differential attacks which improve the previous impossible differential attacks. Our analysis shows that SIMON maintains enough security margin.