2 Catalog and Illustrative Examples of Lightweight Cryptographic Primitives
29
Table 2.2 (continued)
Best known attack: data complexity/memory/time
Name
Ref
complexity
Noekeon
[165]
Many related keys (weakness) [334]
PICARO
[485]
Related-key attack [129]: 2 99 /2 22 B /2 107.4
Piccolo
[526]
Biclique cryptanalysis [15]: 2 4 /− /(2 79.07 , 2 127.12 )
PRESENT
[101]
Biclique cryptanalysis (PRESENT-80) [15]: 2 22 /− /2 79.37
PRIDE
[17]
Multiple related-key differential attack [167]: 2 41.6 /−
/2 42.7
PRINCE
[105]
Multiple differential attack [128]: 2 57.94 /2 61.52 /2 60.62 on
10 rounds
PRINTcipher
[333]
Invariance subspace attack [359] applicable to 2 52 / 2 102
weak keys:
5 CPs/ −/ negligible
PUFFIN2
[569]
Differential attack [95]: 2 52.3 CPs/− /2 74.78
RC5-12
[502]
Differential attack [88]: 2 44 CPs
RECTANGLE
[598]
Related-key differential attack [521]: 2 62 /2 72 B/2 67.42 on
19 rounds
RoadRunneR
[63]
−
Robin
[247]
Key-recovery attack for the weak key set of density
2 −32 [360]: 1 CP/− /2 64
SEA
[542]
−
SKINNY
[68]
Related-tweakey impossible differential attacks [23]:
2 71.4 /2 64 /2 79 up to 23 rounds
Simeck
[588]
Linear hull attack with dynamic key-guessing
techniques [491]:
(2 31.91 , 2 47.66 , 2 63.09 )/ −/(2 61.78 , 2 92.2 , 2 111.44 ) add. and
(2 56.41 , 2 88.04 , 2 121.25 ) enc.
SIMON
[65]
Differential cryptanalysis on 12/16/19/28/37
reduced-round
SIMON-32/48/64/96/128
SPARX
[181]
Truncated-differential attack [24]: 2 32 /2 61 /2 93 on 16
rounds ( SPARX-64/128)
SPECK
[65]
Differential cryptanalysis [537]:
2 125.35 /2 22 /2 125.35 on 23 rounds of the SPECK-128/128
TWINE
[544]
Impossible differential and multidimensional zero
correlation linear attack [373]:
2 62.1 KPs/ 2 60 B / 2 73 (TWINE-80)
QARMA
[39]
−
XTEA
[436]
Related-key rectangle attack [380]: 2 63.83 / − / 2 104.33 on
36 rounds
Zorro
[227]
Differential attack [55]: 2 41.5 / 2 10 / 2 45
KP—Known Plaintext
CP—Chosen Plaintext
Précédent

- 43/268

Suivant