Boomeyong Cryptanalysis of Reduced-Round mCrypton

Document Type : Research Article

Authors

1 Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran.

2 Information Systems and Security Lab (ISSL), Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran.

3 Electronics Research Institute, Sharif University of Technology, Tehran, Iran.

Abstract

Given the growing demand for secure yet lightweight encryption in constrained environments such as RFID tags and wireless sensor networks, resource-constrained devices are increasingly relying on lightweight block ciphers to protect sensitive data while meeting strict power, area, and latency requirements. In response to the challenge of designing such block ciphers, several lightweight block ciphers, such as the mCrypton, have been proposed. However, a thorough security evaluation of such ciphers is crucial, since their vulnerabilities can threaten the entire security architecture of systems. In this paper, we present the first application of the boomeyong attack—a hybrid technique combining boomerang and yoyo frameworks—on the reduced-round mCrypton block cipher. We formulate a novel 5-round distinguisher and demonstrate a key recovery attack that improves upon all previously known results. By refining structural definitions and adapting the boomeyong framework to the SPN-based design of mCrypton, our attack achieves a data complexity of 226, a time complexity of 223.02En. +225XOR, and a memory complexity of 212 blocks.

Keywords

Main Subjects


[1] Lim, Chae Hoon and Korkishko, Tymur. mCrypton--a lightweight block cipher for security of low-cost RFID tags and sensors. International workshop on information security applications. 243--258, 2005. [DOI ]
[2] Wagner, David. The boomerang attack. International Workshop on Fast Software Encryption. 156--170, 1999. [DOI ]
[3] Biryukov, Alex and Khovratovich, Dmitry and Nikolic, Ivica. Distinguisher and related-key attack on the full AES-256. Annual International Cryptology Conference. 231--249, 2009. [DOI ]
[4] Biham, Eli and Biryukov, Alex and Dunkelman, Orr and Richardson, Eran and Shamir, Adi. Initial observations on skipjack: Cryptanalysis of skipjack-3xor. International Workshop on Selected Areas in Cryptography. 362--375, 1998. [DOI ]
[5] R{\o}njom, Sondre and Bardeh, Navid Ghaedi and Helleseth, Tor. Yoyo tricks with AES. International Conference on the Theory and Application of Cryptology and Information Security. 217--243, 2017. [DOI ]
[6] Rahman, Mostafizar and Saha, Dhiman and Paul, Goutam. Boomeyong: Embedding yoyo within boomerang and its applications to key recovery attacks on AES and pholkos. IACR Transactions on Symmetric Cryptology. 137--169, 2021. [DOI ]
[7] Li, Bin and Lu, Jianhua and Wang, Yingjiu and Youssef, Amr M.. Improved meet-in-the-middle attacks on Crypton and mCrypton. IET Information Security. 11(1): 23--31, IET. 2017. [DOI ]
[8] Murphy, Sean and Robshaw, Matt. Return of the cryptanalysts: Ciphers, side channels, and fault attacks. International Workshop on Fast Software Encryption. 1--15, 2011. [DOI ]
[9] Dunkelman, Orr and Keller, Nathan and Shamir, Adi. A practical-time related-key attack on the KASUMI cryptosystem used in GSM and 3G telephony. Annual cryptology conference. 393--410, 2010. [DOI ]
[10] Dunkelman, Orr and Keller, Nathan and Shamir, Adi. A practical-time related-key attack on the KASUMI cryptosystem used in GSM and 3G telephony. Journal of cryptology. 27(4): 824--849, Springer. 2014. [DOI ]
[11] Cid, Claude and Huang, Yosuke and Peyrin, Thomas and Sasaki, Yu and Song, Ling. Boomerang Connectivity Table: A New Cryptanalysis Tool. EUROCRYPT. 683--714, 2018. [DOI ]
[12] Boura, Christina and Canteaut, Anne. On the boomerang uniformity of cryptographic sboxes. IACR Transactions on Symmetric Cryptology. 290--310, 2018. [DOI ]
[13] Hu, Lei and Song, Ling and Qin, Xianrui. Boomerang connectivity table revisited. application to SKINNY and AES. IACR Transactions on Symmetric Cryptology. 118--141, 2019. [DOI ]
[14] Wang, Haoyang and Peyrin, Thomas. Boomerang switch in multiple rounds. application to AES variants and Deoxys. IACR Transactions on Symmetric Cryptology. 142--169, 2019. [DOI ]
[15] Dunkelman, Orr and Keller, Nathan and Ronen, Eyal and Shamir, Adi. The retracing boomerang attack. Annual International Conference on the Theory and Applications of Cryptographic Techniques. 280--309, 2020. [DOI ]
[16] Boukerrou, Hamid and Huynh, Paul and Lallemand, Virginie and Mandal, Bimal and Minier, Marine. On the Feistel counterpart of the boomerang connectivity table. IACR Transactions on Symmetric Cryptology. 2020(1): 331--362, 2020. [DOI ]
[17] Delaune, Stephanie and Derbez, Patrick and Vavrille, Mathieu. Catching the fastest boomerangs: Application to SKINNY. IACR Transactions on Symmetric Cryptology. 104--129, 2020. [DOI ]
[18] Qin, Lingyue and Dong, Xiaoyang and Wang, Xiaoyun and Jia, Keting and Liu, Yunwen. Automated search oriented to key recovery on ciphers with linear key schedule: applications to boomerangs in SKINNY and ForkSkinny. IACR Transactions on Symmetric Cryptology. 2021(2): 249--291, 2021. [DOI ]
[19] Hadipour, Hosein and Bagheri, Nasour and Song, Ling. Improved rectangle attacks on SKINNY and CRAFT. IACR Transactions on Symmetric Cryptology. 140--198, 2021. [DOI ]