Clustering Effect in Simon and Simeck - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

Clustering Effect in Simon and Simeck

Résumé

Simon and Simeck are two lightweight block ciphers with a simple round function using only word rotations and a bit-wise AND operation. Previous work has shown a strong clustering effect for differential and linear cryptanalysis, due to the existence of many trails with the same inputs and outputs. In this paper, we explore this clustering effect by exhibiting a class of high probability differential and linear trails where the active bits stay in a fixed window of w bits. Instead of enumerating a set of good trails contributing to a differential or a linear approximation, we compute the probability distribution over this space, including all trails in the class. This results in stronger distinguishers than previously proposed, and we describe key recovery attacks against Simon and Simeck improving the previous results by up to 7 rounds. In particular, we obtain an attack against 42-round Simeck64, leaving only two rounds of security margin, and an attack against 45-round Simon96/144, reducing the security margin from 16 rounds to 9 rounds.
Fichier principal
Vignette du fichier
2021-1198.pdf (797.32 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03529507 , version 1 (17-01-2022)

Identifiants

Citer

Gaëtan Leurent, Clara Pernot, André Schrottenloher. Clustering Effect in Simon and Simeck. ASIACRYPT 2021 - 27th International Conference on the Theory and Application of Cryptology and Information Security, Dec 2021, Virtual, Singapore. pp.272-302, ⟨10.1007/978-3-030-92062-3_10⟩. ⟨hal-03529507⟩

Collections

INRIA INRIA2 ANR
42 Consultations
119 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More