Journal of Xidian University ›› 2023, Vol. 50 ›› Issue (4): 170-179.doi: 10.19665/j.issn1001-2400.2023.04.017

• Special Issue on Cyberspace Security • Previous Articles     Next Articles

The design and cryptanalysis of a large state lightweight cryptographic S-box

FAN Ting1(),FENG Wei2(),WEI Yongzhuang1()   

  1. 1. Guangxi Key Laboratory of Cryptography and Information Security,Guilin University of Electronic Technology,Guilin 541004,China
    2. Guangxi Wangxin Information Technology Co.,Ltd.,Nanning 530000,China
  • Received:2023-01-16 Online:2023-08-20 Published:2023-10-17
  • Contact: Wei FENG E-mail:fanting0801@163.com;77578790@163.com;walker_wyz@guet.edu.cn

Abstract:

Alzette is a 64 bit lightweight S-box based on the ARX structure proposed at the CRYPTO 2020.It has many advantages such as excellent hardware and software performance,strong diffusion and high security,so that it receives wide attention domestically and internationally.However,64-bit lightweight S-boxes with execllent performance and security are rare.Whether it is possible to design the large state lightweight S-box with better performance than Alzette is difficult in current research.In this paper,a large state lightweight cryptographic S-box based on the ARX structure with an excellent performance and security is designed.A “hierarchy filtering method” is proposed to determine the optimal rotation parameters by setting the best differential/linear characteristic bounds in advance,and the security evaluation for the new S-box is given.It is shown that the software and hardware implementation performance of the new S-box is equivalent to that of the Alzette.For the new S-box,the probability of 5-round best differential characteristic (linear approximation) up to 2-17(2-8),and the probability of 7-round best linear approximation reaches 2-17.But for the Alzette,the 5-round best differential characteristic (linear approximation) with probability of 2-10>2-17(2-5>2-8),and the 7-round best linear approximation with probability of 2-13>2-17.The new S-box shows a stronger resistance against differential cryptanalysis and linear cryptanalysis.

Key words: lightweight block cipher, cryptographic S-box, differential cryptanalysis, linear cryptanalysis

CLC Number: 

  • TN918.4