Rotational-XOR cryptanalysis of reduced-round SPECK

Yunwen Liu, Glenn de Witte (Corresponding author), Adrián Ranea, Tomer Ashur

Research output: Contribution to journalArticleAcademicpeer-review

In this paper we formulate a SAT/SMT model for Rotational-XOR (RX) cryptanalysis in ARX primitives for the first time. The model is successfully applied to the block cipher family Speck, and distinguishers covering more rounds than previously are found, as well as RX-characteristics requiring less data to detect. In particular, we present distinguishers for 10, 11 and 12 rounds for Speck32/64 which have better probabilities than the previously known 9-round differential characteristic, for a certain weak key class. For versions of Speck48, we present several distinguishers, among which the longest one covering 15 rounds, while the previously best differential characteristic only covered 11.
Original languageEnglish
Pages (from-to)24-36
Number of pages13
JournalIACR Transactions on Symmetric Cryptology
Issue number3
Publication statusPublished - 19 Sep 2017
Externally publishedYes


  • Rotational-XOR cryptanalysis
  • ARX
  • Weak keys


