A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
复制标题
DOI:
10.1007/s11432-022-3466-x
复制
发表时间:
2023-01
期刊:
影响因子:
--
通讯作者:
Kai Zhang;Xuejia Lai;Lei Wang;Jie Guan;Bin Hu
中科院分区:
文献类型:
--
作者:
Kai Zhang;Xuejia Lai;Lei Wang;Jie Guan;Bin Hu
Simeck is a family of lightweight block ciphers proposed at CHES 2015 [1]. The round function and key schedule of Simeck were inspired by SIMON and SPECK, which were proposed by the US National Security Agency in 2013. Compared with these two lightweight ciphers, Simeck has a more compact hardware implementation. In addition, in 2019, the US National Institute of Standards and Technology proposed a lightweight cryptography standardization project. In this project, some proposals have applied modified Simeck as a basic module, such as ACE, SPIX, and SPOC, which implies a more practical potential for Simeck. Impossible differential cryptanalysis was originally proposed by Knudsen [2] and Biham et al.[3], respectively. It is one of the most effective cryptanalytic methods to date. The basic idea of impossible differential cryptanalysis is to establish an impossible differential distinguisher, then filter the wrong key candidates with this distinguisher until the correct key is recovered.The security evaluation of Simeck against impossible differential cryptanalysis has lasted for years. In the specification, on the basis of impossible differential cryptanalysis, 20/24/25-round key recovery attacks can be achieved for Simeck32/48/64 [1]. In these attacks, the 24/25-round attacks are based on 13/15-round distinguishers. In 2018, Sadeghi et al.[4] proposed a method for modifying some bit differences of the internal state to derive longer distinguishers, and 15/17-round distinguishers were discovered for Simeck48/64. At ICISC 2018, Wang et al.[5] proposed single-bit impossible differential distinguishers for 11/15/17-round Simeck32/48/64 based on MILP optimization. In 2021, Wang et al.[6] presented impossible differential distinguishers with multi-active bits for the same length based on MILP optimization in the journal cybersecurity. Key results.(1) By releasing the constraints on the number of active bits, new longest distinguishers are derived. In our experiment, the number of active bits is limited to two. For Simeck48/Simeck64, 42/240 more distinguishers are derived, which improves the ratios of all the previously reported longest distinguishers by 41.2%/300%, respectively. Moreover, the structural property of these longest distin-