Page 395 - 《软件学报》2026年第5期
P. 395
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(5):2274−2285 [doi: 10.13328/j.cnki.jos.007457] [CSTR: 32375.14.jos.007457] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
对缩减轮 SPECK 改进的差分-线性分析
张语晗 1,2 , 张 蕾 1,2 , 吴文玲 1,2
1
(中国科学院 软件研究所 可信计算与信息保障实验室, 北京 100190)
2
(中国科学院大学, 北京 100049)
通信作者: 吴文玲, E-mail: wenling@iscas.ac.cn
摘 要: 差分-线性分析是一种组合类分析方法, 已经被应用于许多对称密码的分析中. 特别地, 对于 ARX 类分组
密码算法 SPECK, 差分-线性分析是评估其安全性的一种强有力的方式. 在最新的差分-线性分析框架中, 密码算法
被分解为 3 部分: 差分部分、中间部分和线性部分, 其中差分部分、中间部分和线性部分分别包含高概率的差分
特征, 高相关性的差分-线性逼近和高相关性的线性逼近, 组合 3 部分特征可以得到一个完整的差分-线性区分器.
对于 ARX 类对称密码算法, 在传统的差分-线性区分器的搜索过程中, 通常是首先借助实验方法来计算得到中间
部分一个高相关性的差分-线性逼近, 然后再分别向前向后搜索线性特征和差分特征, 但是该策略容易忽视掉一些
好的差分-线性区分器. 区别于传统的搜索算法, 该算法结合高相关性的差分-线性逼近中差分部分和线性部分的特
点, 从高概率的差分特征和线性特征出发, 给出一个差分-线性区分器搜索算法. 将所提搜索算法应用于 SPECK 中,
得到 SPECK32 的 11 轮差分-线性区分器和 SPECK48 的 12 轮差分-线性区分器. 所提区分器都优于 SPECK32/48
目前已知最好的差分-线性区分器.
关键词: 密码分析; 对称密码; 差分-线性分析; SPECK; 分组密码
中图法分类号: TP309
中文引用格式: 张语晗, 张蕾, 吴文玲. 对缩减轮SPECK改进的差分-线性分析. 软件学报, 2026, 37(5): 2274–2285. http://www.jos.
org.cn/1000-9825/7457.htm
英文引用格式: Zhang YH, Zhang L, Wu WL. Improved Differential-linear Analysis on Round-reduced SPECK. Ruan Jian Xue
Bao/Journal of Software, 2026, 37(5): 2274–2285 (in Chinese). http://www.jos.org.cn/1000-9825/7457.htm
Improved Differential-linear Analysis on Round-reduced SPECK
1,2
1,2
ZHANG Yu-Han , ZHANG Lei , WU Wen-Ling 1,2
1
(Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China)
2
(University of Chinese Academy of Sciences, Beijing 100049, China)
Abstract: Differential-linear cryptanalysis, a combined cryptanalysis method, has been applied to the analysis of many symmetric ciphers.
Specifically, for the ARX block cipher SPECK, differential-linear cryptanalysis is an effective technique for evaluating its security. In the
latest framework of differential-linear cryptanalysis, the cipher is divided into three components: the differential part, the middle part, and
the linear part. These parts contain high-probability differential characteristics, high-correlation differential-linear approximations, and high-
correlation linear approximations, respectively. For ARX ciphers, the traditional search process for differential-linear distinguishers typically
involves first using experimental methods to obtain a high-correlation differential-linear approximation in the middle part. Subsequently,
linear and differential characteristics are searched for forward and backward. However, this strategy may overlook some effective
differential-linear distinguishers. This study proposes a search method for differential-linear distinguishers, which integrates the
characteristics of the differential and linear parts in high-correlation differential-linear approximations and leverages high-probability
differential and linear characteristics. The proposed search algorithm is applied to SPECK, yielding an 11-round differential-linear
* 基金项目: 国家自然科学基金 (62072445)
收稿时间: 2024-09-05; 修改时间: 2024-10-29; 采用时间: 2025-04-25; jos 在线出版时间: 2025-10-29
CNKI 网络首发时间: 2025-10-30

