Cryptology ePrint Archive: Report 2020/290

Linear Cryptanalysis of Reduced-Round SIMON Using Super Rounds

Reham Almukhlifi and Poorvi Vora

Abstract: We present attacks on 21-rounds of SIMON 32/64, 21-rounds of SIMON 48/96, 25-rounds of SIMON 64/128, 35-rounds of SIMON 96/144 and 43-rounds of SIMON 128/256, often with direct recovery of the full master key without repeating the attack over multiple rounds. These attacks result from the observation that, after four rounds of encryption, one bit of the left half of the state of 32/64 SIMON depends on only 17 key bits (19 key bits for the other variants of SIMON). Further, linear cryptanalysis requires the guessing of only 16 bits, the size of a single round key of SIMON 32/64. We partition the key into smaller strings by focusing on one bit of state at a time, decreasing the cost of the exhaustive search of linear cryptanalysis to 16 bits at a time for SIMON 32/64. We also present other example linear cryptanalysis, experimentally verified on 8, 10 and 12 rounds for SIMON 32/64.

Category / Keywords: secret-key cryptography / linear cryptanalysis,SIMON , super rounds

Date: received 4 Mar 2020, last revised 7 Mar 2020

Contact author: rsa39 at gwu edu,poorvi@gwu edu

Available format(s): PDF | BibTeX Citation

Version: 20200307:235024 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]