4 The ISO/IEC Standardization of Simon and Speck
71
Even under these generous assumptions the security margins seem slightly on
the unsafe side. Surprisingly, it appears that the security margin decreases with
the block size and that for about half of the variants the security margin is below
(sometimes well below) the claimed 25%. In particular, by the time this so-called
design rationale was finally released, only the 128-bit variants of Simon and Speck
were considered for standardization in ISO with their extremely small security
margins.
After facing these comments, the designers updated [66] and changed the 50%
figure for the multipath effect to 25% adding a footnote which reads:
The original version of this paper said 50% here, but noted that this was “very conservative.”
This led to confusion by some, who interpreted 50% as an exact value, rather than the very
conservative upper bound we intended it to be. This is supported by the literature (see,
e.g., [138]) and by our internal analysis. Indeed 50% is a significant overestimate; 25%
appears to be a more accurate estimate. We apologize for the lack of clarity here, and note
that even if future advances increased the 25–50% Simon would still be secure.
In fact, this footnote is liberal with the facts. In a private correspondence between
the design team and one of the ISO experts, the former writes:
Interestingly, for 18 rounds, it appears that there *is* likely a distinguisher. However, it’s
not a slam dunk . . . However, I think the existence of such a distinguisher could likely be
supported by analytic arguments. . .
4.3.3 Misquoting Existing Work
Following an extended discussion about differential and linear paths the designers
proceed to briefly discuss other, less notable attacks. When reading this section
with an expert’s eye it becomes clear that some of the claims are outdated, either
intentionally or unintentionally. One claim stands out in particular in the paragraph
discussing slide and rotational attacks. The designers write:
Both Simon and Speck employ round counters to block slide and rotational properties . . .
We note that, as with many block ciphers, the counters are essential elements of the
designs; without them there are rotational attacks. In fact a very early analysis paper
described a rotational attack on Speck, but it only worked because the authors of that paper
mistakenly omitted the counter (see [6] (20130909 version)). Also see [28].
The uninformed reader may understand this paragraph to mean that rotational
attacks are avoided by injecting round constants into the state and that this approach
is supported by Ashur and Liu [28]. While adding round constants is indeed
a common countermeasure against rotational attacks, the aforementioned [28]
actually presents a novel method for building rotational distinguishers despite the
algorithm’s use of round constants. To drive the point home [28] exemplified the
new method by building a rotational property for Speck. It is therefore not surprising
that [376], a follow-up work to [28] used this method to build the longest distinguisher against certain variants of Speck using rotational cryptanalysis (surpassing
71
Even under these generous assumptions the security margins seem slightly on
the unsafe side. Surprisingly, it appears that the security margin decreases with
the block size and that for about half of the variants the security margin is below
(sometimes well below) the claimed 25%. In particular, by the time this so-called
design rationale was finally released, only the 128-bit variants of Simon and Speck
were considered for standardization in ISO with their extremely small security
margins.
After facing these comments, the designers updated [66] and changed the 50%
figure for the multipath effect to 25% adding a footnote which reads:
The original version of this paper said 50% here, but noted that this was “very conservative.”
This led to confusion by some, who interpreted 50% as an exact value, rather than the very
conservative upper bound we intended it to be. This is supported by the literature (see,
e.g., [138]) and by our internal analysis. Indeed 50% is a significant overestimate; 25%
appears to be a more accurate estimate. We apologize for the lack of clarity here, and note
that even if future advances increased the 25–50% Simon would still be secure.
In fact, this footnote is liberal with the facts. In a private correspondence between
the design team and one of the ISO experts, the former writes:
Interestingly, for 18 rounds, it appears that there *is* likely a distinguisher. However, it’s
not a slam dunk . . . However, I think the existence of such a distinguisher could likely be
supported by analytic arguments. . .
4.3.3 Misquoting Existing Work
Following an extended discussion about differential and linear paths the designers
proceed to briefly discuss other, less notable attacks. When reading this section
with an expert’s eye it becomes clear that some of the claims are outdated, either
intentionally or unintentionally. One claim stands out in particular in the paragraph
discussing slide and rotational attacks. The designers write:
Both Simon and Speck employ round counters to block slide and rotational properties . . .
We note that, as with many block ciphers, the counters are essential elements of the
designs; without them there are rotational attacks. In fact a very early analysis paper
described a rotational attack on Speck, but it only worked because the authors of that paper
mistakenly omitted the counter (see [6] (20130909 version)). Also see [28].
The uninformed reader may understand this paragraph to mean that rotational
attacks are avoided by injecting round constants into the state and that this approach
is supported by Ashur and Liu [28]. While adding round constants is indeed
a common countermeasure against rotational attacks, the aforementioned [28]
actually presents a novel method for building rotational distinguishers despite the
algorithm’s use of round constants. To drive the point home [28] exemplified the
new method by building a rotational property for Speck. It is therefore not surprising
that [376], a follow-up work to [28] used this method to build the longest distinguisher against certain variants of Speck using rotational cryptanalysis (surpassing
