Netinfo Security ›› 2022, Vol. 22 ›› Issue (9): 63-75.doi: 10.3969/j.issn.1671-1122.2022.09.008

Previous Articles     Next Articles

Differential-Linear Cryptanalysis of the SIMON Algorithm

HU Yujia1(), DAI Zhengyi2, SUN Bing1,3   

  1. 1. College of Science, National University of Defense Technology, Changsha 410073, China
    2. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China
    3. Hunan Engineering Research Center of Commercial Cryptography Theory and Technology Innovation, Changsha 410000, China
  • Received:2022-06-15 Online:2022-09-10 Published:2022-11-14
  • Contact: HU Yujia E-mail:1654606492@qq.com

Abstract:

Differential cryptanalysis and linear cryptanalysis are currently the two most common methods to evaluate the security of block ciphers. Differential-linear cryptanalysis is an analysis method based on these two methods, which has been widely studied by the cryptography community in recent years. SIMON algorithm is an important lightweight block cipher, this paper mainly performed differential-linear attacks on SIMON 32/64 and SIMON 48, constructed 13 rounds differential-linear distinguishers respectively, made 16 rounds of key recovery attacks, whose data complexities are 226 and 242, and time complexities are 240.59 and 261.59 respectively, thereby increased the security evaluation dimension of the SIMON algorithm and enriched the actual cases of differential-linear cryptanalysis.

Key words: lightweight block ciphers, differential-linear cryptanalysis, SIMON algorithm

CLC Number: