Page 405 - 《软件学报》2026年第5期
P. 405
2284 软件学报 2026 年第 37 卷第 5 期
r 0 = 4, r m = 5, r 1 = 3
∆ m = [18,21,42], λ m = [5]
r 0 =4
−9
p = Pr(∆ in −−−→ ∆ m ) = 2
r m =5 .
r = Cor(∆ m −−−→ λ m ) = 2 −7.96
r 1 =3
q = Cor(λ m −−−→ λ out ) = 2
−3
r DL =12
−22.96
Cor(∆ in −−−−→ λ out ) = 2
最终我们得到了如下 8 个 SPECK48 的 12 轮区分器:
r DL =12 r DL =12
D 11 : (028210,000212) −−−−→ (65400c,6c4000), D 12 : (028210,000212) −−−−→ (41400c,4c4000)
r DL =12 r DL =12
D 13 : (028210,000212) −−−−→ (45c00c,484000), D 14 : (028210,000212) −−−−→ (61c00c,684000)
.
r DL =12 r DL =12
D 15 : (028210,000212) −−−−→ (61c028,684020), D 16 : (028210,000212) −−−−→ (45c028,484020)
r DL =12 r DL =12
D 17 : (028210,000212) −−−−→ (414028,4c4020), D 18 : (028210,000212) −−−−→ (654028,6c4020)
● SPECK48/96 的 14 轮密钥恢复: 我们以区分器 D 12 下的密钥恢复攻击为例进行介绍, 其他区分器下的攻击
过程是类似的. 在 SPECK48 的 12 轮差分-线性区分器 D 12 后添加 2 轮, 我们给出了 SPECK48/96 的 14 轮密钥恢复
攻击. 类似 SPECK32/64 x , 可知对 SPECK48/96 实施 14 轮的密钥恢
13
的密钥恢复过程, 将
i = 2, 3, 14, 16, 22 代入
i
13
13
13
复攻击需要猜测 (k ,k ,...,k ), k 14 共 44 个密钥比特. 此时攻击需要的数据复杂度为 2 22.96×2 = 2 45.92 , 需要的时间复
19 18 0
杂度为 2 45.92+44 = 2 91.92 .
4 总 结
在本文中, 我们对 ARX 类密码算法的差分-线性区分器搜索算法进行研究. 首先, 通过遍历 SPECK32/64 的
32 比特明文空间, 测试不同随机密钥下的差分-线性逼近的相关性, 进一步展示了样本量的大小与实验测量的相关
性的准确性之间的关系. 然后, 研究高相关性的差分-线性逼近差分部分和线性部分的特点, 进而基于这些特点给
出了一个 ARX 类对称密码算法差分-线性区分器的搜索算法; 基于所提搜索算法, 我们得到了 SPECK32 的 11 轮
差分-线性区分器和 SPECK48 的 12 轮差分-线性区分器.
References
[1] Wheeler DJ, Needham RM. TEA, a tiny encryption algorithm. In: Proc. of the 2nd Int’l Workshop on Fast Software Encryption. Leuven,
Belgium: Springer, 1994. 363–366. [doi: 10.1007/3-540-60590-8_29]
[2] Beaulieu R, Shors D, Smith J, Treatman-Clark S, Weeks B, Wingers L. The SIMON and speck block ciphers on AVR 8-bit
microcontrollers. In: Proc. of the 3rd Int’l Workshop on Lightweight Cryptography for Security and Privacy. Istanbul: Springer, 2014.
3–20. [doi: 10.1007/978-3-319-16363-5_1]
[3] Hong D, Sung J, Hong S, Lim J, Lee S, Koo BS, Lee C, Chang D, Lee J, Jeong K, Kim H, Kim J, Chee S. HIGHT: A new block cipher
suitable for low-resource device. In: Proc. of the 8th Int’l Workshop on Cryptographic Hardware and Embedded Systems. Yokohama:
Springer, 2006. 46–59. [doi: 10.1007/11894063_4]
[4] Hong D, Lee J, Kim DC, Kwon D, Ryu KH, Lee DG. LEA: A 128-bit block cipher for fast encryption on common processors. In: Proc. of
the 14th Int’l Workshop on Information Security Applications. Jeju Island: Springer, 2013. 3–27. [doi: 10.1007/978-3-319-05149-9_1]
[5] Koo B, Roh D, Kim H, Jung Y, Lee DG, Kwon D. CHAM: A family of lightweight block ciphers for resource-constrained devices. In:
Proc. of the 20th Int’l Conf. on Information Security and Cryptology. Seoul: Springer, 2017. 3–25. [doi: 10.1007/978-3-319-78556-1_1]
[6] Dinu D, Perrin L, Udovenko A, Velichkov V, Großschädl J, Biryukov A. Design strategies for ARX with provable bounds: SPARX and
LAX. In: Proc. of the 22nd Int’l Conf. on the Theory and Application of Cryptology and Information Security on Advances in
Cryptology. Hanoi: Springer, 2016. 484–513. [doi: 10.1007/978-3-662-53887-6_18]
[7] Langford SK, Hellman ME. Differential-linear cryptanalysis. In: Proc. of the 14th Annual Int’l Cryptology Conf. on Advances in
Cryptology. Santa Barbara: Springer, 1994. 17–25. [doi: 10.1007/3-540-48658-5_3]
[8] Biham E, Dunkelman O, Keller N. Enhancing differential-linear cryptanalysis. In: Proc. of the 2002 Int’l Conf. on the Theory and

