76
T. Ashur and A. Luykx
to second working draft or to the ballot stage. All experts in attendance were asked and the
result was 16 to 8 in favor of a second working draft with 8 abstentions.
Such numbers, especially in a preliminary stage, show that the algorithms did
not enjoy the wide support required for standardization. Nevertheless, since it was
the editors’ responsibility to implement the decisions, they concluded the meeting,
writing:
The Editor will now draft a new Call for Contributions which will make three requests.
First, a request to outline security concerns with the use of a 48-bit block cipher. Secondly,
a request for potential use cases for a 48-bit block cipher. Finally, a request for any updates
on the ongoing security evaluation of SIMON and SPECK.
Abu Dhabi, UAE (October 2016)
Indeed, another Working Draft was circulated on June 2016 with a commenting
period of 15 weeks (until September 2016). Surprisingly, the Working Draft only
included questions about the block size, and about new cryptanalytic results,
completely ignoring the mistrust expressed by the majority of experts. As a result,
comments about this working draft were limited to the questions asked and referred
only to the block size.
In their Disposition of Comments, the editors resolved to remove the 48-bit
variants of Simon and Speck and leave the other block sizes. 10 They also resolved
all editorial comments and declared that a consensus has been reached and that the
draft was ready to progress to Committee Stage.
Hamilton, New Zealand (April 2017)
Simon and Speck’s 1st PDAM was circulated on December 2016 requesting that
votes and comments be sent until February 2017. The result of this ballot showed
that 15 NBs voted to approve the proposal (some with comments), 8 voted to
disapprove, and 26 abstained. This result showed not only that the algorithms do
not enjoy consensus, but also even the 66% minimal threshold was not met.
Many of the comments from the National Bodies listed the absence of a design
rationale as a factor in their disapproving vote. Other comments also mentioned that
64-bit block ciphers were inherently insecure against generic attacks. 11 In their
preliminary Disposition of Comment the editors announced that they would provide
a design rationale for the algorithms:
The editors will provide documentation that discusses the design rationale and the design
team’s security analysis for SIMON and SPECK.
10 Since the efficiency of the two algorithms, which was its main selling point, was always presented
with respect to the smaller variants of the algorithms, it is interesting how the smaller variants have
been slowly phased out of the proposed standard, leaving only the larger variants whose efficiency
was never thoroughly discussed and that do not fare as well as the alternatives.
11 The Sweet32 attack [86] was published around this time and was a factor in many of the decisions
of the NBs.
Précédent

- 89/268

Suivant