Impossible Differential Cryptanalysis of Reduced-Round mCrypton-64

نویسندگان

1 Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran

2 Electronics Research Institute, Sharif University of Technology, Tehran, Iran

3 Electronics Research Institute, Sharif University of Technology, Tehran, Iran

4 Electronics Research Institute, Sharif University of Technology, Tehran, Iran

5 Faculty of Computer Science, Ruhr University Bochum, Bochum, Germany

doi
10.22042/isecure.2025.214371
چکیده

Impossible-differential cryptanalysis is one of the powerful methods utilized for evaluating the robustness of block ciphers; however, mCrypton is one of the block ciphers whose master key has not been recovered with this method in the single-key scenario. This paper first clarifies the branch number of the linear layer of mCrypton block ciphers with an observation. It has been shown that the branch number of the linear layer in mCrypton block cipher is four. Then, using this result, a 4-round impossible differential in a single-key scenario has been found. On the other hand, by exploiting the result of several observations, some vulnerabilities in the key-schedule algorithm were discovered and introduced. As a result, by exploiting the discovered vulnerabilities and 4-round property, impossible-differential cryptanalysis was successfully applied to seven rounds of mCrypton-64. To our knowledge, this is the first impossible differential cryptanalysis applied on mCrypton-64. In addition, this method requires 236.0 bytes of memory, 259.0 chosen plaintexts (with the corresponding ciphertexts), and 259.6 encryptions to recover the master key.