Page 405 - 《软件学报》2026年第5期
P. 405

2284                                                       软件学报  2026  年第  37  卷第  5  期


                                                 
                                                 r 0 = 4, r m = 5, r 1 = 3
                                                 
                                                 
                                                 
                                                 
                                                  ∆ m = [18,21,42], λ m = [5]
                                                 
                                                 
                                                 
                                                 
                                                 
                                                 
                                                         r 0 =4
                                                                  −9
                                                  p = Pr(∆ in −−−→ ∆ m ) = 2
                                                 
                                                 
                                                 
                                                 
                                                           r m =5      .
                                                 
                                                  r = Cor(∆ m −−−→ λ m ) = 2 −7.96
                                                 
                                                 
                                                 
                                                 
                                                 
                                                 
                                                          r 1 =3
                                                 q = Cor(λ m −−−→ λ out ) = 2
                                                                   −3
                                                 
                                                 
                                                 
                                                 
                                                 
                                                        r DL =12
                                                                  −22.96
                                                  Cor(∆ in −−−−→ λ out ) = 2
                                                 
                    最终我们得到了如下        8  个  SPECK48  的  12  轮区分器:

                                          r DL =12                           r DL =12
                          D 11 : (028210,000212) −−−−→ (65400c,6c4000), D 12 : (028210,000212) −−−−→ (41400c,4c4000)
                         
                         
                         
                         
                         
                         
                                          r DL =12                           r DL =12
                         
                         D 13 : (028210,000212) −−−−→ (45c00c,484000), D 14 : (028210,000212) −−−−→ (61c00c,684000)
                         
                         
                                                                                               .
                         
                                          r DL =12                           r DL =12
                         
                          D 15 : (028210,000212) −−−−→ (61c028,684020), D 16 : (028210,000212) −−−−→ (45c028,484020)
                         
                         
                         
                         
                         
                                          r DL =12                           r DL =12
                         
                          D 17 : (028210,000212) −−−−→ (414028,4c4020), D 18 : (028210,000212) −−−−→ (654028,6c4020)
                         
                    ● SPECK48/96  的  14  轮密钥恢复: 我们以区分器    D 12  下的密钥恢复攻击为例进行介绍, 其他区分器下的攻击
                 过程是类似的. 在     SPECK48  的  12  轮差分-线性区分器  D 12  后添加  2  轮, 我们给出了  SPECK48/96  的  14  轮密钥恢复
                 攻击. 类似  SPECK32/64                                   x , 可知对  SPECK48/96  实施  14  轮的密钥恢
                                                                      13
                                    的密钥恢复过程, 将
                                                   i = 2, 3, 14, 16, 22 代入
                                                                      i
                                       13
                                  13
                               13
                 复攻击需要猜测      (k ,k ,...,k ), k 14  共  44  个密钥比特. 此时攻击需要的数据复杂度为    2 22.96×2  = 2 45.92 , 需要的时间复
                               19  18  0
                 杂度为  2 45.92+44  = 2 91.92 .
                  4   总 结
                    在本文中, 我们对      ARX  类密码算法的差分-线性区分器搜索算法进行研究. 首先, 通过遍历                    SPECK32/64  的
                 32  比特明文空间, 测试不同随机密钥下的差分-线性逼近的相关性, 进一步展示了样本量的大小与实验测量的相关
                 性的准确性之间的关系. 然后, 研究高相关性的差分-线性逼近差分部分和线性部分的特点, 进而基于这些特点给
                 出了一个   ARX  类对称密码算法差分-线性区分器的搜索算法; 基于所提搜索算法, 我们得到了                        SPECK32  的  11  轮
                 差分-线性区分器和 SPECK48      的  12  轮差分-线性区分器.
                 References
                  [1]   Wheeler DJ, Needham RM. TEA, a tiny encryption algorithm. In: Proc. of the 2nd Int’l Workshop on Fast Software Encryption. Leuven,
                     Belgium: Springer, 1994. 363–366. [doi: 10.1007/3-540-60590-8_29]
                  [2]   Beaulieu  R,  Shors  D,  Smith  J,  Treatman-Clark  S,  Weeks  B,  Wingers  L.  The  SIMON  and  speck  block  ciphers  on  AVR  8-bit
                     microcontrollers. In: Proc. of the 3rd Int’l Workshop on Lightweight Cryptography for Security and Privacy. Istanbul: Springer, 2014.
                     3–20. [doi: 10.1007/978-3-319-16363-5_1]
                  [3]   Hong D, Sung J, Hong S, Lim J, Lee S, Koo BS, Lee C, Chang D, Lee J, Jeong K, Kim H, Kim J, Chee S. HIGHT: A new block cipher
                     suitable for low-resource device. In: Proc. of the 8th Int’l Workshop on Cryptographic Hardware and Embedded Systems. Yokohama:
                     Springer, 2006. 46–59. [doi: 10.1007/11894063_4]
                  [4]   Hong D, Lee J, Kim DC, Kwon D, Ryu KH, Lee DG. LEA: A 128-bit block cipher for fast encryption on common processors. In: Proc. of
                     the 14th Int’l Workshop on Information Security Applications. Jeju Island: Springer, 2013. 3–27. [doi: 10.1007/978-3-319-05149-9_1]
                  [5]   Koo B, Roh D, Kim H, Jung Y, Lee DG, Kwon D. CHAM: A family of lightweight block ciphers for resource-constrained devices. In:
                     Proc. of the 20th Int’l Conf. on Information Security and Cryptology. Seoul: Springer, 2017. 3–25. [doi: 10.1007/978-3-319-78556-1_1]
                  [6]   Dinu D, Perrin L, Udovenko A, Velichkov V, Großschädl J, Biryukov A. Design strategies for ARX with provable bounds: SPARX and
                     LAX.  In:  Proc.  of  the  22nd  Int’l  Conf.  on  the  Theory  and  Application  of  Cryptology  and  Information  Security  on  Advances  in
                     Cryptology. Hanoi: Springer, 2016. 484–513. [doi: 10.1007/978-3-662-53887-6_18]
                  [7]   Langford  SK,  Hellman  ME.  Differential-linear  cryptanalysis.  In:  Proc.  of  the  14th  Annual  Int’l  Cryptology  Conf.  on  Advances  in
                     Cryptology. Santa Barbara: Springer, 1994. 17–25. [doi: 10.1007/3-540-48658-5_3]
                  [8]   Biham  E,  Dunkelman  O,  Keller  N.  Enhancing  differential-linear  cryptanalysis.  In:  Proc.  of  the  2002  Int’l  Conf.  on  the  Theory  and
   400   401   402   403   404   405   406   407   408   409   410