Improved rotational‐XOR cryptanalysis of Simon‐like block ciphers

Improved rotational‐XOR cryptanalysis of Simon‐like block ciphers
复制标题

改进了 Simon 类分组密码的旋转 XOR 密码分析

DOI:
10.1049/ise2.12061
复制
发表时间:
2022
影响因子:
1.4
通讯作者:
Chao Li
Chao Li
中科院分区:
计算机科学4区
文献类型:
--
作者:
Jinyu Lu;Yunwen Liu;Tomer Ashur;Bing Sun;Chao Li

文献摘要

被引文献

相似文献

旋转-异或(RX)密码分析是一种密码分析方法,旨在发现加法-旋转-异或-C密码中可区分的统计特性,即只能通过使用模加法,循环旋转,异或和常数注入来描述的密码。在这项研究中,我们将RX-密码分析扩展到AND-RX密码,这是一种类似的设计范式,其中模加法被矢量逐位AND取代;这样的密码包括分组密码家族Simon和Simeck。我们分析了RX-差异通过AND-RX轮的传播,并为它们的预期概率开发了一个封闭形式的公式。受Sadeghi等人提出的MILP验证模型的启发,我们开发了一个SAT/SMT模型,用于在Simon类密码中搜索兼容的RX-特征,即至少有一对正确的消息/密钥满足RK-特征。据我们所知,这是第一个在类西蒙密码中同时考虑RX差分转换和值转换的模型。同时,我们研究了循环常数的选择如何影响Simon-like密码抵抗RX-密码分析的能力。最后,我们将展示如何使用RX‐解密器进行密钥恢复攻击。评估我们的模型,我们发现兼容的RX特性高达20,27和34轮,对于相关密钥模型中的大类弱密钥,对于32,48和64位的Simeck版本,其概率分别为2−26,2− 44和2− 56。在大多数情况下,这些是Simeck各自变体的最长出版物。就Simon而言,我们为所有10个实例的舍入版本提供了兼容的RX特征。我们观察到,对于相同的块和密钥大小,RX-加密器在Simon中覆盖的轮次比Simeck少。最后,我们提出了一个对Simeck 64的密钥恢复攻击,使用23轮RX特征减少到28轮。
Rotational‐XOR (RX) cryptanalysis is a cryptanalytic method aimed at finding distinguishable statistical properties in Addition‐Rotation‐XOR‐C ciphers, that is, ciphers that can be described only by using modular addition, cyclic rotation, XOR and the injection of constants. In this study, we extend RX‐cryptanalysis to AND‐RX ciphers, a similar design paradigm where the modular addition is replaced by vectorial bitwise AND; such ciphers include the block cipher families Simon and Simeck. We analyse the propagation of RX‐differences through AND‐RX rounds and develop a closed form formula for their expected probability. Inspired by the MILP verification model proposed by Sadeghi et al., we develop a SAT/SMT model for searching compatible RX‐characteristics in Simon‐like ciphers, that is, that there is at least one right pair of messages/keys to satisfy the RK‐characteristics. To the best of our knowledge, this is the first model that takes the RX‐difference transitions and value transitions simultaneously into account in Simon‐like ciphers. Meanwhile, we investigate how the choice of the round constants affects the resistance of Simon‐like ciphers against RX‐cryptanalysis. Finally, we show how to use an RX‐distinguisher for a key recovery attack. Evaluating our model we find compatible RX‐characteristics of up to 20, 27 and 34 rounds with respective probabilities of 2−26, 2−44and 2−56for versions of Simeck with block sizes of 32, 48 and 64 bits, respectively, for large classes of weak keys in the related‐key model. In most cases, these are the longest published distinguishers for the respective variants of Simeck. In the case of Simon, we present compatible RX‐characteristics for round‐reduced versions of all 10 instances. We observe that for equal block and key sizes, the RX‐distinguishers cover fewer rounds in Simon than in Simeck. Concluding the paper, we present a key recovery attack on Simeck 64 reduced to 28 rounds using a 23‐round RX‐characteristic.