Partly-Pseudo-Linear Cryptanalysis of Lightweight ARX Block Ciphers SPECK and SPARX
Open AccessARX (Addition-Rotation-XOR) block ciphers are useful in applications where lightweight cryptography is necessary. These designs are not vulnerable to traditional linear cryptanalysis. We propose a new cryptanalytic technique and key recovery attack for lightweight ARX ciphers with large words and illustrate it on SPECK and SPARX.We apply McKay’s pseudo-linear approximation of addition modular 2^n to SPECK 32/64. We observe that the attack complexity gets large rapidly, and the attack cannot go deeper than 6 rounds. This observation motivates our main original contribution: the Partly-Pseudo-Linear Attack, which combines the pseudo-linear approximation with a linear approximation using the meet-in-the-middle attack, resulting in deeper key-recovery attacks. We illustrate our attack on the SPECK and SPARX ciphers, showing that linear distinguishers that are based solely on Cho-Pieprzyk approximations of addition modulo 2^n are improved by combination with the pseudo-linear approximation. We describe the corresponding key recovery attacks. We are able to attack more than one-third of the rounds for all variants of SPECK (more than half for a couple of the variants) and guess more than one half of the key bits in all except one variant. More specifically, we are able to attack 9 rounds for SPECK 32/64 guessing 36 of 64 bits, 11 rounds for SPECK 48/96 guessing 45 of 96 key bits, 14 rounds for SPECK 64/128 guessing 49 of 128 key bits, 12 rounds for SPECK 96/144 guessing 76 of 144 bits and 14 rounds for SPECK 128/256 guessing 173 of 256 bits. We are able to recover 93 encryption key bits for 9 rounds of SPARX 64/128, 98 key bits for 9 rounds of SPARX 128/128 and 195 key bits for 11 rounds of SPARX 128/256. For comparison, we implement fully linear attacks using the Cho-Pieprzyk property and find that, for all variants of the SPARX family, we are able to recover more encryption key bits with better bias and lower data complexity using the Partly-Pseudo-Linear attack.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Alzakari_gwu_0075A_15342.pdf | 2020-12-03 | Open Access |
|