Research on the Security Level of Μ2 Against Impossible Differential Cryptanalysis.

Kai Zhang,Xuejia Lai,Jie Guan,Bin Hu
DOI: https://doi.org/10.3837/tiis.2022.03.012
2022-01-01
KSII Transactions on Internet and Information Systems
Abstract:In the year 2020, a new lightweight block cipher mu(2) is proposed. It has both good software and hardware performance, and it is especially suitable for constrained resource environment. However, the security evaluation on mu(2) against impossible differential cryptanalysis seems missing from the specification. To fill this gap, an impossible differential cryptanalysis on mu(2) is proposed. In this paper, firstly, some cryptographic properties on mu(2) are proposed. Then several longest 7-round impossible differential distinguishers are constructed. Finally, an impossible differential cryptanalysis on mu(2) reduced to 10 rounds is proposed based on the constructed distinguishers. The time complexity for the attack is about 2(69.63) 10-round mu(2) encryptions, the data complexity is O(2(48)), and the memory complexity is 2(63.57) Bytes. The reported result indicates that mu(2) reduced to 10 rounds can't resist against impossible differential cryptanalysis.
What problem does this paper attempt to address?