A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis

A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
复制标题

DOI:
10.1007/s11432-022-3466-x
复制
发表时间:
2023-01
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Kai Zhang;Xuejia Lai;Lei Wang;Jie Guan;Bin Hu
Kai Zhang;Xuejia Lai;Lei Wang;Jie Guan;Bin Hu
中科院分区:
其他
文献类型:
--
作者:
Kai Zhang;Xuejia Lai;Lei Wang;Jie Guan;Bin Hu

文献摘要

被引文献

相似文献

Simeck是2015年CHES[1]提出的一类轻量级分组密码算法。Simeck的轮次功能和密钥时间表的灵感来自于美国国家安全局在2013年提出的Simon和SPECK。与这两种轻量级密码相比,Simeck的硬件实现更为紧凑。此外,2019年,美国国家标准与技术研究院提出了轻量级密码学标准化项目。在本项目中,一些方案采用了改进的Simeck作为基本模块,如ACE、SPIX和SPOC,这意味着Simeck具有更实用的潜力。不可能差分密码分析最初是由Knudsen[2]和Biham等人[3]提出的。这是迄今为止最有效的密码分析方法之一。不可能差分密码分析的基本思想是建立一个不可能差分鉴别器,然后用这个鉴别器过滤错误的候选密钥,直到恢复正确的密钥。在该规范中,基于不可能的差分密码分析,可以实现对Simeck32/48/[1]的20/24/25轮密钥恢复攻击。在这些攻击中,24/25轮攻击基于13/15轮区分。2018年,Sadeghi等人[4]提出了一种修改内部状态的某些比特差异的方法来获得更长的区分器,并为Simeck48/发现了15/17轮的区分器。在ICISC 2018上,Wang等人[5]提出了基于MILP优化的11/15/17轮Simeck32/48/的单比特不可能差分器。2021年,Wang等人[6]在《网络安全》杂志上提出了基于MILP优化的具有相同长度的多活动比特的不可能差分器。主要结果。(1)通过解除对有效位数的约束,得到新的最长区分符。在我们的实验中,活动比特的数量被限制为两个。对于Simeck48/Simeck64,多出了42/240个区分词,使所有已报道的最长区分词的比率分别提高了41.2%/300%。此外,还讨论了这些最长分布的结构性质。
Simeck is a family of lightweight block ciphers proposed at CHES 2015 [1]. The round function and key schedule of Simeck were inspired by SIMON and SPECK, which were proposed by the US National Security Agency in 2013. Compared with these two lightweight ciphers, Simeck has a more compact hardware implementation. In addition, in 2019, the US National Institute of Standards and Technology proposed a lightweight cryptography standardization project. In this project, some proposals have applied modified Simeck as a basic module, such as ACE, SPIX, and SPOC, which implies a more practical potential for Simeck. Impossible differential cryptanalysis was originally proposed by Knudsen [2] and Biham et al.[3], respectively. It is one of the most effective cryptanalytic methods to date. The basic idea of impossible differential cryptanalysis is to establish an impossible differential distinguisher, then filter the wrong key candidates with this distinguisher until the correct key is recovered.The security evaluation of Simeck against impossible differential cryptanalysis has lasted for years. In the specification, on the basis of impossible differential cryptanalysis, 20/24/25-round key recovery attacks can be achieved for Simeck32/48/64 [1]. In these attacks, the 24/25-round attacks are based on 13/15-round distinguishers. In 2018, Sadeghi et al.[4] proposed a method for modifying some bit differences of the internal state to derive longer distinguishers, and 15/17-round distinguishers were discovered for Simeck48/64. At ICISC 2018, Wang et al.[5] proposed single-bit impossible differential distinguishers for 11/15/17-round Simeck32/48/64 based on MILP optimization. In 2021, Wang et al.[6] presented impossible differential distinguishers with multi-active bits for the same length based on MILP optimization in the journal cybersecurity. Key results.(1) By releasing the constraints on the number of active bits, new longest distinguishers are derived. In our experiment, the number of active bits is limited to two. For Simeck48/Simeck64, 42/240 more distinguishers are derived, which improves the ratios of all the previously reported longest distinguishers by 41.2%/300%, respectively. Moreover, the structural property of these longest distin-