4 The ISO/IEC Standardization of Simon and Speck
65
≪ 1
≪ 8
≪ 2
&
?
6
-
-
-
-
-
?
?
?
X i
Y i
k i
Y i+1
X i+1
Fig. 4.1 One round of Simon (without the final swap operation)
l i+m−2
· · ·
l i
k i
R i
i
X i
Y i
≫ α
≪ β
X i+1
Y i+1
Fig. 4.2 One round of Speck and its key schedule
4.2.2 Speck
Similar to Simon the Speck family includes ten variants, differing in their block- and
key- sizes. A member is denoted Speck2n/mn where 2n is the block size and mn is
the key size. Speck builds on the ARX design paradigm and the cipher is composed
of three operations: modular Addition, Rotation, and XOR (hence the name ARX).
While efficient in software, ARX operations are known to have slow diffusion.
Usually, this slow diffusion mandates employing a large number of rounds (see
e.g., [214]) to be secure. However, as discussed in the sequel, the designers argued
that they have a good understanding of the cipher’s diffusion and settled for a
relatively small number of rounds.
65
≪ 1
≪ 8
≪ 2
&
?
6
-
-
-
-
-
?
?
?
X i
Y i
k i
Y i+1
X i+1
Fig. 4.1 One round of Simon (without the final swap operation)
l i+m−2
· · ·
l i
k i
R i
i
X i
Y i
≫ α
≪ β
X i+1
Y i+1
Fig. 4.2 One round of Speck and its key schedule
4.2.2 Speck
Similar to Simon the Speck family includes ten variants, differing in their block- and
key- sizes. A member is denoted Speck2n/mn where 2n is the block size and mn is
the key size. Speck builds on the ARX design paradigm and the cipher is composed
of three operations: modular Addition, Rotation, and XOR (hence the name ARX).
While efficient in software, ARX operations are known to have slow diffusion.
Usually, this slow diffusion mandates employing a large number of rounds (see
e.g., [214]) to be secure. However, as discussed in the sequel, the designers argued
that they have a good understanding of the cipher’s diffusion and settled for a
relatively small number of rounds.
