In the past few years, research on lightweight block ciphers as security ciphers in the Internet of Things (IoT) has attracted considerable attention in cryptography. In this paper, we present an improved framework for neural distinguishers in lightweight SPN block ciphers suitable for IoT, focusing on two aspects: training data format and neural network structure. First, we analyze the nature of the SPN round function, then divide it into three cases to apply data augmentation. Second, we generate training data samples using three dimensions and construct neural networks using two-dimensional convolution. Finally, we validate the advantages of the improved framework on the SKINNY family and MIDORI family with higher accuracy and achieve a breakthrough in the number of rounds.
Encrypted traffic classification is crucial for critical network management tasks such as traffic type identification, resource allocation, and risk mitigation, especially given that encrypted traffic has become the dominant form of modern network communication. However, existing classification methods are typically confined to single-level feature extraction, failing to capture the multi-granularity information inherent in traffic and thus limiting their ability to characterize complex encrypted traffic patterns. To address this issue, this paper proposes BPF-GNN, a hierarchical graph feature extraction model for encrypted traffic classification. The model enables multi-granularity feature learning by constructing a three-tier graph structure (Byte-, Packet-, and Flow-level). It sequentially extracts discriminative information inherent in each granularity level and accumulates multi-dimensional traffic characteristics, significantly improving the classification accuracy of encrypted traffic. Experiments on the ISCX-VPN2016, ISCX-Tor2016, USTC-TFC2016, and MIRAGE-2024 datasets demonstrate that BPF-GNN outperforms existing methods, validating the effectiveness and superiority of the proposed hierarchical multi-granularity feature extraction approach.
In recent years, the integration of deep learning with differential cryptanalysis has led to differential neural cryptanalysis, enabling efficient data-driven security evaluation of modern cryptographic algorithms. Compared to traditional cryptanalysis, differential neural cryptanalysis enhances the efficiency and automation of the analysis by training neural networks to automatically extract statistical features from ciphertext pairs. As research advances, neural distinguisher construction faces challenges due to the absence of a unified framework capable of cross-algorithm generalization and feature optimization. There is no systematic way to build a framework from adapted data formats and network architectures, which limits their scalability across diverse ciphers and their suitability for combining different cryptanalysis methods. Besides, neural network training is data-driven; there is an urgent need to combine cryptographic theory with data analysis methods to systematically evaluate the quality of differentially generated datasets. To address these gaps, this article proposes a novel framework for constructing related-key neural differential distinguishers that integrates three core innovations: 1) multiciphertext multidifference formats to enhance dataset diversity and feature coverage; 2) structural filtering for prioritizing high-probability differential paths aligned with cryptographic architectures; and 3) deep residual shrinkage network (DRSN) with adaptive thresholding to suppress noise and amplify critical differential features. By applying this framework to two standardized algorithms, data encryption standard (DES) and PRESENT, our results demonstrate data-driven breakthroughs in standard ciphers. For DES, the framework achieves an eight-round related-key neural distinguisher and improves six/seven-round distinguisher accuracy by over 40%. For PRESENT, we construct the first nine-round related-key neural distinguisher, which outperforms existing neural distinguishers in both round coverage and accuracy. In addition, we systematically analyze dataset quality using kernel principal component analysis (KPCA) and K-means clustering, revealing a strong correlation between clustering compactness and distinguisher performance. Furthermore, we propose a validation algorithm to verify differential combinations with cryptographic advantages from a machine learning perspective, identifying "good" plaintext-key differential combinations. We apply this approach to the SIMECK algorithm, demonstrating its broad applicability.
With the widespread deployment of Internet of Things across various industries, the security of communications between different devices is one of the critical concerns to consider. The lightweight cryptography emerges as a specialized solution to address security requirements for resource-constrained environments. Consequently, the comprehensive security evaluation of the lightweight cryptographic primitives—from the structure of ciphers and cryptographic components—has become imperative. In this article, we focus on the security evaluation of rotation parameters in the Speck32-like lightweight cipher family. We establish a machine learning-driven security evaluation framework for the rotational parameter selection principles—the core of Speck32’s design architecture. To assess different parameters security, we develop neural-differential distinguishers with considering of two distinct input difference models: (1) the low-Hamming-weight input differences and (2) the input differences from optimal differential characteristics. Our methodology achieves the security evaluation of 256 rotation parameters using the accuracy of neural distinguishers as the evaluation criteria. Our results illustrate the parameter (7,3) has stronger ability to resist machine learning-aided distinguishing attack compared to the standard (7,2) configuration. To our knowledge, this represents the first comprehensive study applying machine learning techniques for security assessment of Speck32-like ciphers. Furthermore, we investigate the reason for the difference in the accuracy of neural distinguishers with different rotation parameters. Our experimental results demonstrate that the bit bias in output differences and truncated differences is the important factor affecting the accuracy of distinguishers.
In CRYPTO 2019, Gohr pioneered the integration of machine learning with differential cryptanalysis, demonstrating that differential-neural distinguishers can outperform classical techniques in distinguishing attacks. He also introduced a novel key-recovery strategy based on Bayesian optimization, termed BAYESIANKEY-SEARCH, enhancing key recovery for SPECK32/64. However, the impact of parameter selection on the complexity and success probability of key-recovery attack using BAYESIANKEYSEARCH remains underexplored. This paper investigates the impact of parameter selections on key-recovery effectiveness. Gohr's key-recovery attack involves two stages, each using a cutoff value to filter candidate guesses for the last subkey and second-to-last subkey. Previous works selected these cutoffs independently. We propose connecting these cutoff selections, enhancing coordination between stages and improving the attack's complexity and success probability. Applying our parameter optimization, we enhance the single-key recovery attacks on 16-round SIMoN32/64, 16-round and 17-round SIMECK32/64, achieving higher success rates and lower time complexities compared to previous works. Additionally, for related-key differential-neural attacks on SIMoN32/64, we exploit both single-key and related-key features from cross-paired ciphertexts, developing advanced neuraldistinguishers for up to 13 rounds. Using these neural-distinguishers combined with carefully selected classical differentials, we devise an 18-round related-key recovery attack on SIMoN32/64. Our results validate the practical effectiveness of the proposed strategies and are expected to contribute to the advancement of machine learning-aided cryptanalysis.
In CRYPTO 2019, Gohr introduced machine learning-aided differential cryptanalysis, demonstrating superior performance in key-recovery attacks compared to traditional methods. This advancement has sparked significant interest in exploring the potential of machine learning for enhancing the effectiveness and efficiency of cryptanalysis. To address these phenomena, we develop an innovative framework that integrates machine learning into differential-linear cryptanalysis and apply it to the 8-round Des, which achieves better performance than classical methods. Additionally, considering the existence of the non-trivial differentials in differential-linear distinguishers, we employ the generalized neutral bits during the generating training data phase and the key-guessing phase to improve the accuracy of neural-aided differential-linear distinguishers of Speck. For comparison, we further perform the traditional key-recovery attacks, whose results show that machine learning-aided cryptanalysis has considerable advantages in success rate over attacks devised using pure counterparts. As the first machine learning-aided differential-linear cryptanalysis, our works not only extends the application of machine learning in cryptanalysis but also provides valuable insights into the potential of integrating deep learning for enhancing cryptanalysis.
As a family of tweakable block ciphers, HALFLOOP is standardized in the interoperability and performance standards for medium and high-frequency radio systems published by the United States Department of Defense. Although HALFLOOP-24 has been destroyed in real-world practical attacks, seeking stronger attacks from the structure of ciphers against two larger variants of HALFLOOP is to be further explored. Since HALFLOOP has a property of smaller internal states compared to master keys, it leads to a low diffusion in the key schedule. Considering that related-key boomerang attacks have a significant effect on such ciphers and can even achieve full-round attacks, we evaluate the resistance of two larger variants of HALFLOOP against related-key boomerang attacks in the paper. First, we propose a more efficient model to search for sandwich distinguishers of ciphers with non-linear key schedules. Specifically, we derive more constraints rather than simple relationships in the internal linear layer to further restrict the appropriate distinguishers into a smaller space. In addition, we utilize the ladder switch effect in the related-key model to guarantee the differential transition with probability one among the master key quartet, thereby avoiding possible weak-key attacks or invalid trails. Second, applying the model to HALFLOOP, we propose a full-round related-key boomerang attack on HALFLOOP-48 and nearly full-round related-key attacks on HALFLOOP-96. The relevant results demonstrate that the security of two larger variants of HALFLOOP is weak in related-key scenario. Therefore, in addition to the serious flaw brought by the tweak, the low diffusion in the key schedule algorithm is also worthy of attention.
In CRYPTO 2019, Gohr built a bridge between machine learning and differential cryptanalysis, which show that machine learning-aided methods have advantages over classical differential cryptanalysis. Yet, for linear cryptanalysis, there is lack of effective works showing that machine learning-aided cryptanalysis can reach the benchmark of traditional counterparts and also lack of an effective universal framework using machine learning to assist linear cryptanalysis. In this paper, we mainly focus on machine learning-aided linear cryptanalysis and application to Des. First, we propose a machine learning-aided model to distinguish different Bernoulli distributions and demonstrate the validity of the model through experiments and theoretical analysis. Based on the model, we propose a new machine learning-aided linear cryptanalysis framework, which can be applied to one bit and multiple bits key-recovery attacks. As applications, we perform one bit attacks on 3-, 4-, 5-, 6-round Des and multiple bits attack on 8-round Des. Compared with the previous works about machine learning-aided linear cryptanalysis, the results improve the success rate and the complexity. Most importantly, more rounds are covered in our work. Besides, the work indicates that machine learning-aided cryptanalysis can achieve the same or marginally better performance than classical methods.
As one of the candidates for authenticated encryption in the second round of the CAESAR competition, Joltik has an internal lightweight tweakable block cipher Joltik-BC. In ASIACRYPT 2014, designers stated that the real threat to Joltik-BC comes from attacks that exploit the tweakey schedule, i.e. related-tweakey differential attacks. However, there has been no such attack against Joltik-BC currently. In the paper, we evaluate the resistance to Joltik-BC against boomerang attacks. Considering that not all distinguishers with high probability have a significant effect in key recovery attacks, we incorporate the complexity of key recovery into the search for distinguishers and turn to search for the entire truncated attack paths. Specifically, by considering truncated differential propagation, we control the number of active nibbles on the sides of plaintext and ciphertext to reduce key guessing. Then we apply it to search for appropriate distinguishers of Joltik-BC. Finally, we propose a 10-round related-tweakey boomerang attack for Joltik-BC-128 and a 14-round related-tweakey rectangle attack for Joltik-BC-192. To reduce the time complexity, we also utilize the property of components to guess partial key bits and deduce other key bits. This is the first work to evaluate the resistance of related-tweakey boomerang attack for Joltik-BC and both of them increase the round number of key recovery attacks.
At the Annual International Cryptology Conference in 2019, Gohr introduced a deep learning based cryptanalysis technique applicable to the reduced-round lightweight block ciphers with a short block of SPECK32/64. One significant challenge left unstudied by Gohr’s work is the implementation of key recovery attacks on large-state block ciphers based on deep learning. The purpose of this paper is to present an improved deep learning based framework for recovering keys for large-state block ciphers. First, we propose a key bit sensitivity test (KBST) based on deep learning to divide the key space objectively. Second, we propose a new method for constructing neural distinguisher combinations to improve a deep learning based key recovery framework for large-state block ciphers and demonstrate its rationality and effectiveness from the perspective of cryptanalysis. Under the improved key recovery framework, we train an efficient neural distinguisher combination for each large-state member of SIMON and SPECK and finally carry out a practical key recovery attack on the large-state members of SIMON and SPECK. Furthermore, we propose that the 13-round SIMON64 attack is the most effective approach for practical key recovery to date. Noteworthly, this is the first attempt to propose deep learning based practical key recovery attacks on 18-round SIMON128, 19-round SIMON128, 14-round SIMON96, and 14-round SIMON64. Additionally, we enhance the outcomes of the practical key recovery attack on SPECK large-state members, which amplifies the success rate of the key recovery attack in comparison to existing results.
The Joltik-BC,adopting the substitution-permutation network structure and Tweakey framework,was a lightweight tweakable block cipher published at ASIACRPYPT 2014.By researching the internal characteristic of the Joltik-BC,a 6-round meet-in-the-middle distinguisher against the Joltik-BC-128 was constructed by controlling the tweakey differentials and combining differential enumeration and differential characteristics of S-boxes.An im-proved meet-in-the-middle attack against the 9-round Joltik-BC-128 was developed using this distinguisher.The memory and time complexities of the improved 9-round Joltik-BC-128 were 244.91 64-bits blocks and 248 9-round Joltik-BC-128 encryptions.Compared with existing meet-in-the-middle attack results,the time complexity and memory complexity of this method were significantly reduced.
针对网络空间安全人才培养现状,结合密码学课程特点,从课程教材和内容选取、理论教学、实践和实训、课程思政教育方面,阐述密码学课程的教学方法,旨在培养学生密码创新应用能力,为其从事网络空间安全工作奠定基础.
分析密码学选修课程的教学现状和内容设置,在总结近几年教学存在问题的基础上,从授课内容、授课方法、考核方式、教材选取、兴趣培养、实际应用等方面进行探讨,提出一些行之有效的教学策略.
The neural distinguisher is a new tool widely used in crypto analysis of some ciphers.For SIMON-like block ciphers, there are multiple choices for their parameters, but the reasons for designer’s selection remain unexplained.Using neural distinguishers, the security of the parameters (a,b,c) of the SIMON-like with a block size of 32 bits was researched, and good choices of parameters were given.Firstly, using the idea of affine equivalence class proposed by K?lbl et al.in CRYPTO2015, these parameters can be divided into 509 classes.And 240 classes which satisfied gcd(a-b,2)=1 were mainly researched.Then a SAT/SMT model was built to help searching differential characteristics for each equivalent class.From these models, the optimal differential characteristics of SIMON-like was obtained.Using these input differences of optimal differential characteristics, the neural distinguishers were trained for the representative of each equivalence class, and the accuracy of the distinguishers was saved.It was found that 20 optimal parameters given by K?lbl et al.cannot make the neural distinguishers the lowest accuracy.On the contrary, there were 4 parameters, whose accuracy exceeds 80%.Furthermore, the 4 parameters were bad while facing neural distinguishers.Finally, comprehensively considering the choice of K?lbl et al.and the accuracy of different neural distinguishers, three good parameters, namely (6,11,1),(1,8,3), and(6,7,5) were given.
Cryptographic identification is a critical aspect of cryptanalysis and a fundamental premise for key recovery.With the advancement of artificial intelligence, cryptanalysis based on machine learning has become increasingly mature, providing more effective methods and valuable insights for cryptographic identification.The distinguishability experiments were performed based on the Machine Learning to identify the structures of block ciphers in conditions of random keys.The identification of two structures of block ciphers from theoretical and experimental angles was studied.The differences of features in two structures’ cipher texts have been deduced by introducing the runs distribution index, feature distribution functions, KL-divergence, etc.After completing the feasibility research, experiments to identify the structures of two block ciphers using two Machine Learning models and the runs distribution index were conducted.The experiments were divided into two groups: single algorithm group and mixture algorithms group.It is found that the accuracy of both groups are more than 80%, which is around 40% higher than former work.The problem of identifying the structures of Block Ciphers in the conditions of random keys is solved in detail.Meanwhile, differences between the two structures of block ciphers are verified, which can serve as a reference for the design of cryptography algorithms.
In CRYPTO 2019, Gohr opens up a new direction for cryptanalysis. He successfully applied deep learning to differential cryptanalysis against the NSA block cipher SPECK32/64, achieving higher accuracy than traditional differential distinguishers. Until now, one of the mainstream research directions is increasing the training sample size and utilizing different neural networks to improve the accuracy of neural distinguishers. This conversion mindset may lead to a huge number of parameters, heavy computing load, and a large number of memory in the distinguishers training process. However, in the practical application of cryptanalysis, the applicability of the attacks method in a resource-constrained environment is very important. Therefore, we focus on the cost optimization and aim to reduce network parameters for differential neural cryptanalysis.In this paper, we propose two cost-optimized neural distinguisher improvement methods from the aspect of data format and network structure, respectively. Firstly, we obtain a partial output difference neural distinguisher using only 4-bits training data format which is constructed with a new advantage bits search algorithm based on two key improvement conditions. In addition, we perform an interpretability analysis of the new neural distinguishers whose results are mainly reflected in the relationship between the neural distinguishers, truncated differential, and advantage bits. Secondly, we replace the traditional convolution with the depthwise separable convolution to reduce the training cost without affecting the accuracy as much as possible. Overall, the number of training parameters can be reduced by less than 50% by using our new network structure for training neural distinguishers. Finally, we apply the network structure to the partial output difference neural distinguishers. The combinatorial approach have led to a further reduction in the number of parameters (approximately 30% of Gohr’s distinguishers for SPECK).
In CRYPTO 2019, Gohr successfully applied deep learning to differential cryptanalysis against the NSA block cipher Speck32/64, achieving higher accuracy than traditional differential distinguishers. Until now, the improvement of neural differential distinguishers is a mainstream research direction in neural-aided cryptanalysis. But the current development of training data formats for neural distinguishers forms barriers: (1) The source of data features is limited to linear combinations of ciphertexts, which does not provide more learnable features to the training samples for improving the neural distinguishers. (2) Lacking breakthroughs in constructing data format for network training from the deep learning perspective. In this paper, considering both the domain knowledge about deep learning and information on differential cryptanalysis, we use the output features of the penultimate round to proposing a two-dimensional and non-realistic input data generation method of neural differential distinguishers. Then, we validate that the proposed new input data format has excellent features through experiments and theoretical analysis. Moreover, combining the idea of multiple ciphertext pairs, we generate two specific models for data input construction: MRMSP(Multiple Rounds Multiple Splicing Pairs) and MRMSD(Multiple Rounds Multiple Splicing Differences) and then build new neural distinguishers against Speck and Simon family, which effectively improve the performance compared with the previous works. To the best of our knowledge, our neural distinguishers achieve the longest rounds and the higher accuracy for NSA block ciphers Speck and Simon.
AbstractCRAFT is a lightweight block cipher designed by Beierle et al. to effectively resist differential fault attacks at fast software encryption 2019. In this article, Demirci‐Selçuk meet‐in‐the‐middle (DS‐MITM) attacks on round‐reduced CRAFT based on automatic search are proposed. A DS‐MITM automatic search model for CRAFT was constructed, and then, the automatic search model was used to detect a 9‐round DS‐MITM distinguisher. The strong relations between the round‐subtweakeys were observed and the key‐dependent sieve technique was adopted to reduce the memory complexity of the attack. Based on the 9‐round distinguisher, a 19‐round DS‐MITM attack can be presented. Due to the strong key relations, the time complexity can be reduced by the key‐bridging technique and the equivalent round‐subtweakey. The time complexity of the 19‐round DS‐MITM attack is 2114.68 19‐round CRAFT encryption, the data complexity is 256 chosen plaintexts, and the memory complexity is 2109 64‐bit blocks. Adding one round to the end of the 19‐round DS‐MITM attack, a 20‐round DS‐MITM attack can be proposed. The time complexity of the 20‐round attack is 2126.94 20‐round CRAFT encryption, the data complexity is 256 chosen plaintexts, and the memory complexity is 2109 64‐bit blocks.
Deoxys-BC is an internal tweakable block cipher of the authenticated encryption algorithm Deoxys, which is a third-round finalist in the CAESAR competition. In this paper, we study the property of Deoxys-BC, such as the subtweakey difference cancelation and the freedom of the tweak. Combining the differential enumeration technique with these properties, the authors achieve the key-recovery attacks on Deoxys-BC under the meet-in-the-middle attack. As a result, we get an attack on 9-round Deoxys-BC-128-128 by constructing a 6-round meet-in-the-middle distinguisher with $2^{113}$ plaintext–tweak combinations, $2^{97}$ Deoxys-BC blocks and $2^{121.6}$ 9-round Deoxys-BC-128-128 encryptions. We also present an attack on 11-round Deoxys-BC-256-128 for the first time by constructing a 7-round meet-in-the-middle distinguisher with $2^{113}$ plaintext-tweak combinations, $2^{226}$ Deoxys-BC blocks and $2^{251}$ 11-round Deoxys-BC-256-128 encryptions.