Even though SIMECK as a lightweight block cipher can be secure against differential cryptanalysis, the practical security of SIMECK implementation against differential cryptanalysis is not clear. In light of this, the security of three versions of SIMECK implementation against differential cryptanalysis is considered in a leakage profiling scenario. In a leakage profiling scenario, the leakages of three versions of SIMECK implementation can be characterized and template attack can be used to recover the eighth round output. Then, eight-round differential cryptanalysis based on some three-round differentials can be performed to recover the secret key used by SIMECK implementation. We evaluate the efficiency of this combinatorial analysis style in simulated scenario where the values of different parameters that can influence the efficiency of template attack are under full control. The evaluation results show that about 340, 720 and 1040 correct pairs of samples can be enough to recover the secret key of three versions of SIMECK implementation with at most \(2^{21}\) exhaustive search, and the success rate of key-recovery can be higher than 90%. Therefore, inner rounds of SIMECK implementation should also be protected to counteract side-channel attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Differential Cryptanalysis Against SIMECK Implementation in a Leakage Profiling Scenario

  • Hailong Zhang

摘要

Even though SIMECK as a lightweight block cipher can be secure against differential cryptanalysis, the practical security of SIMECK implementation against differential cryptanalysis is not clear. In light of this, the security of three versions of SIMECK implementation against differential cryptanalysis is considered in a leakage profiling scenario. In a leakage profiling scenario, the leakages of three versions of SIMECK implementation can be characterized and template attack can be used to recover the eighth round output. Then, eight-round differential cryptanalysis based on some three-round differentials can be performed to recover the secret key used by SIMECK implementation. We evaluate the efficiency of this combinatorial analysis style in simulated scenario where the values of different parameters that can influence the efficiency of template attack are under full control. The evaluation results show that about 340, 720 and 1040 correct pairs of samples can be enough to recover the secret key of three versions of SIMECK implementation with at most \(2^{21}\) exhaustive search, and the success rate of key-recovery can be higher than 90%. Therefore, inner rounds of SIMECK implementation should also be protected to counteract side-channel attacks.