66
T. Ashur and A. Luykx
Table 4.2 Speck’s
parameters
Block size (2n) Key size (mn) (α, β) Rounds (T )
32
64
(7, 2) 22
48
72
(8, 3) 22
96
(8, 3) 23
64
96
(8, 3) 26
128
(8, 3) 27
96
96
(8, 3) 28
144
(8, 3) 29
128
128
(8, 3) 32
192
(8, 3) 33
256
(8, 3) 34
To reduce implementation size, the designers reuse Speck’s round function for
the key schedule, feeding in the round number as the round key and outputting one
subkey word in every round. Depicted in Fig. 4.2 are the round function and the key
schedule for Speck. The pairs of possible block- and key- sizes, and the rotation
constants α and β for each variant are listed in Table 4.2.
4.3 Simon and Speck’s “Design Rationale”
A standard practice in modern block cipher design is to provide a design rationale
explaining the design decisions (e.g., the choices of round constants, number of
rounds, rotation amounts, etc.), and the expected security of the new algorithm.
There is no particular structure to a design rationale, but it usually includes a
description of the attacks the designer attempted to apply against the algorithm, and
some reasoning about why the designer believes the algorithm to be secure (e.g.,
using the wide-trail strategy). If the cipher has additional features (such as being an
involution) they are also described and explained in the design rationale.
The purpose of the design rationale is twofold. First, it allows a cryptanalyst
to quickly discard attacks that have been attempted and ruled out by the designer.
Secondly, it provides a general idea about how secure the algorithm should be. Once
new attacks are found against an algorithm they can be compared with the expected
security reported by the designer to see how serious they are.
An important component to establishing confidence in a new algorithm’s security
is the teamwork between the designer and third party cryptanalysts. While the
designer has the “home advantage” of understanding the internals of their algorithm,
the cryptanalyst enjoys an unbiased view that allows them to see things that might
have been overlooked by the designer.
This is why it came as a surprise that the NSA chose not to provide any security
design rationale for their algorithms. The lure of analyzing newly released NSAciphers proved tempting for many, as the vacuum the NSA left behind was quickly
filled with third party analysis such as those in [5, 6, 18, 19, 183].
T. Ashur and A. Luykx
Table 4.2 Speck’s
parameters
Block size (2n) Key size (mn) (α, β) Rounds (T )
32
64
(7, 2) 22
48
72
(8, 3) 22
96
(8, 3) 23
64
96
(8, 3) 26
128
(8, 3) 27
96
96
(8, 3) 28
144
(8, 3) 29
128
128
(8, 3) 32
192
(8, 3) 33
256
(8, 3) 34
To reduce implementation size, the designers reuse Speck’s round function for
the key schedule, feeding in the round number as the round key and outputting one
subkey word in every round. Depicted in Fig. 4.2 are the round function and the key
schedule for Speck. The pairs of possible block- and key- sizes, and the rotation
constants α and β for each variant are listed in Table 4.2.
4.3 Simon and Speck’s “Design Rationale”
A standard practice in modern block cipher design is to provide a design rationale
explaining the design decisions (e.g., the choices of round constants, number of
rounds, rotation amounts, etc.), and the expected security of the new algorithm.
There is no particular structure to a design rationale, but it usually includes a
description of the attacks the designer attempted to apply against the algorithm, and
some reasoning about why the designer believes the algorithm to be secure (e.g.,
using the wide-trail strategy). If the cipher has additional features (such as being an
involution) they are also described and explained in the design rationale.
The purpose of the design rationale is twofold. First, it allows a cryptanalyst
to quickly discard attacks that have been attempted and ruled out by the designer.
Secondly, it provides a general idea about how secure the algorithm should be. Once
new attacks are found against an algorithm they can be compared with the expected
security reported by the designer to see how serious they are.
An important component to establishing confidence in a new algorithm’s security
is the teamwork between the designer and third party cryptanalysts. While the
designer has the “home advantage” of understanding the internals of their algorithm,
the cryptanalyst enjoys an unbiased view that allows them to see things that might
have been overlooked by the designer.
This is why it came as a surprise that the NSA chose not to provide any security
design rationale for their algorithms. The lure of analyzing newly released NSAciphers proved tempting for many, as the vacuum the NSA left behind was quickly
filled with third party analysis such as those in [5, 6, 18, 19, 183].
