Further Observations on SIMON and SPECK Block Cipher Families

SIMON and SPECK families of block ciphers are well-known lightweight ciphers designed by the NSA. In this note, based on the previous investigations on SIMON, a closed formula for the squared correlations and differential probabilities of the mapping <inline-formula> <math display="inl...

Full description

Bibliographic Details
Main Author: Seyed Mojtaba Dehnavi
Format: Article
Language:English
Published: MDPI AG 2018-12-01
Series:Cryptography
Subjects:
Online Access:https://www.mdpi.com/2410-387X/3/1/1
Description
Summary:SIMON and SPECK families of block ciphers are well-known lightweight ciphers designed by the NSA. In this note, based on the previous investigations on SIMON, a closed formula for the squared correlations and differential probabilities of the mapping <inline-formula> <math display="inline"> <semantics> <mrow> <mi>ϕ</mi> <mrow> <mo>(</mo> <mi>x</mi> <mo>)</mo> </mrow> <mo>=</mo> <mi>x</mi> <mo>⊙</mo> <msup> <mi>S</mi> <mn>1</mn> </msup> <mrow> <mo>(</mo> <mi>x</mi> <mo>)</mo> </mrow> </mrow> </semantics> </math> </inline-formula> on <inline-formula> <math display="inline"> <semantics> <msubsup> <mi mathvariant="double-struck">F</mi> <mn>2</mn> <mi>n</mi> </msubsup> </semantics> </math> </inline-formula> is given. From the aspects of linear and differential cryptanalysis, this mapping is equivalent to the core quadratic mapping of SIMON via rearrangement of coordinates and EA -equivalence. Based on the proposed explicit formula, a full description of DDT and LAT of <inline-formula> <math display="inline"> <semantics> <mi>ϕ</mi> </semantics> </math> </inline-formula> is provided. In the case of SPECK, as the only nonlinear operation in this family of ciphers is addition mod <inline-formula> <math display="inline"> <semantics> <msup> <mn>2</mn> <mi>n</mi> </msup> </semantics> </math> </inline-formula>, after reformulating the formula for linear and differential probabilities of addition mod <inline-formula> <math display="inline"> <semantics> <msup> <mn>2</mn> <mi>n</mi> </msup> </semantics> </math> </inline-formula>, straightforward algorithms for finding the output masks with maximum squared correlation, given the input masks, as well as the output differences with maximum differential probability, given the input differences, are presented. By the aid of the tools given in this paper, the process of the search for linear and differential characteristics of SIMON and SPECK families of block ciphers could be sped up, and the complexity of linear and differential attacks against these ciphers could be reduced.
ISSN:2410-387X