xii
Contents
2.3 Illustrative Issues in Security Evaluation of Certain
Encryption Schemes.. . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 38
2.3.1 Reconsidering TMD Tradeoff Attacks for
Lightweight Stream Cipher Designs . . .. . . . . . . . . . . . . . . . . . . . 40
2.3.2 Guess-and-Determine Based Cryptanalysis
Employing Dedicated TMD-TO . . . . . . .. . . . . . . . . . . . . . . . . . . . 44
3 Selected Design and Analysis Techniques for Contemporary
Symmetric Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 49
Vasily Mikhalev, Miodrag J. Mihaljevi´ c, Orhun Kara,
and Frederik Armknecht
3.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 49
3.2 Keystream Generators with Keyed Update Functions .. . . . . . . . . . . . . 50
3.2.1 Design Approach . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 50
3.2.2 On Continuously Accessing the Key . .. . . . . . . . . . . . . . . . . . . . 52
3.2.3 The Stream Ciphers Sprout and Plantlet. . . . . . . . . . . . . . . . . . . 53
3.3 A Generic Attack Against Certain Keystream Generators
with Keyed Update Functions . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 54
3.4 Randomized Encryption Employing Homophonic Coding . . . . . . . . 58
3.4.1 Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 58
3.4.2 Encryption and Decryption.. . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 58
3.4.3 Security Evaluation .. . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 61
3.5 Conclusion and Future Directions .. . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 62
4 An Account of the ISO/IEC Standardization of the Simon
and Speck Block Cipher Families . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 63
Tomer Ashur and Atul Luykx
4.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 63
4.2 Simon and Speck .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 64
4.2.1 Simon . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 64
4.2.2 Speck .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 65
4.3 Simon and Speck’s “Design Rationale” . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 66
4.3.1 Lack of New Information . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 67
4.3.2 Choice of the Number of Rounds .. . . . .. . . . . . . . . . . . . . . . . . . . 68
4.3.3 Misquoting Existing Work . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 71
4.4 The ISO/IEC JTC 1 Standardization Process . . .. . . . . . . . . . . . . . . . . . . . 72
4.5 The Standardization Process of Simon and Speck
in ISO/IEC 29192-2 .. . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 73
Part III Authentication Protocols
5 ePassport and eID Technologies . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
Lucjan Hanzlik and Mirosław Kutyłowski
5.1 Application Scenarios .. . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
5.1.1 Remote vs. Local Use . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
5.1.2 Actors and Scenarios . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 83
5.1.3 Goals of Protocol Execution . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 84
Contents
2.3 Illustrative Issues in Security Evaluation of Certain
Encryption Schemes.. . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 38
2.3.1 Reconsidering TMD Tradeoff Attacks for
Lightweight Stream Cipher Designs . . .. . . . . . . . . . . . . . . . . . . . 40
2.3.2 Guess-and-Determine Based Cryptanalysis
Employing Dedicated TMD-TO . . . . . . .. . . . . . . . . . . . . . . . . . . . 44
3 Selected Design and Analysis Techniques for Contemporary
Symmetric Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 49
Vasily Mikhalev, Miodrag J. Mihaljevi´ c, Orhun Kara,
and Frederik Armknecht
3.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 49
3.2 Keystream Generators with Keyed Update Functions .. . . . . . . . . . . . . 50
3.2.1 Design Approach . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 50
3.2.2 On Continuously Accessing the Key . .. . . . . . . . . . . . . . . . . . . . 52
3.2.3 The Stream Ciphers Sprout and Plantlet. . . . . . . . . . . . . . . . . . . 53
3.3 A Generic Attack Against Certain Keystream Generators
with Keyed Update Functions . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 54
3.4 Randomized Encryption Employing Homophonic Coding . . . . . . . . 58
3.4.1 Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 58
3.4.2 Encryption and Decryption.. . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 58
3.4.3 Security Evaluation .. . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 61
3.5 Conclusion and Future Directions .. . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 62
4 An Account of the ISO/IEC Standardization of the Simon
and Speck Block Cipher Families . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 63
Tomer Ashur and Atul Luykx
4.1 Introduction .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 63
4.2 Simon and Speck .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 64
4.2.1 Simon . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 64
4.2.2 Speck .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 65
4.3 Simon and Speck’s “Design Rationale” . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 66
4.3.1 Lack of New Information . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 67
4.3.2 Choice of the Number of Rounds .. . . . .. . . . . . . . . . . . . . . . . . . . 68
4.3.3 Misquoting Existing Work . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 71
4.4 The ISO/IEC JTC 1 Standardization Process . . .. . . . . . . . . . . . . . . . . . . . 72
4.5 The Standardization Process of Simon and Speck
in ISO/IEC 29192-2 .. . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 73
Part III Authentication Protocols
5 ePassport and eID Technologies . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
Lucjan Hanzlik and Mirosław Kutyłowski
5.1 Application Scenarios .. . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
5.1.1 Remote vs. Local Use . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 81
5.1.2 Actors and Scenarios . . . . . . . . . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 83
5.1.3 Goals of Protocol Execution . . . . . . . . . . .. . . . . . . . . . . . . . . . . . . . 84
