{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T12:59:12Z","timestamp":1740142752408,"version":"3.37.3"},"reference-count":26,"publisher":"Oxford University Press (OUP)","issue":"9","license":[{"start":{"date-parts":[[2021,5,22]],"date-time":"2021-05-22T00:00:00Z","timestamp":1621641600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772517","61772516"],"award-info":[{"award-number":["61772517","61772516"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association CAS","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,9,16]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>This paper investigates the security of counter mode encryption with authentication tag (COMET), one of the 32 second-round candidates in National Institute of Standards and Technology\u2019s lightweight cryptography standardization process, against differential cryptanalysis. CHAM-64\/128 is a block cipher chosen as one of the underlying block ciphers in COMET for hardware-oriented applications, and a differential characteristic with a high probability for CHAM-64\/128 is useful for forgery attacks on COMET. However, we find that the optimal $\\mathbf{39}$-round differential characteristic for CHAM-64\/128 proposed by Roh et al., which is the longest differential characteristic of CHAM-64\/128, is invalid. Then, we propose a new method of distinguishing an $\\mathbf{m}$-bit block cipher from an $\\mathbf{m}$-bit random permutation using a differential characteristic with a probability not higher than $\\mathbf{2^{-m}}$. Using our method, we use two $\\mathbf{39}$-round differential characteristics with a probability of $\\mathbf{2^{-64}}$ for CHAM-64\/128 to distinguish $\\mathbf{39}$-round-reduced CHAM-64\/128 from a $\\mathbf{64}$-bit random permutation, respectively. Furthermore, we refine the probabilities of two differentials with the same input and output differential masks as the two $\\mathbf{39}$-round differential characteristics, respectively. Finally, we present the first forgery attacks on COMET with the two differentials without using weak keys. Our forgery attacks follow the nonce-misuse scenario. It should be noticed that this attack does not invalidate the security claims of the designers.<\/jats:p>","DOI":"10.1093\/comjnl\/bxab061","type":"journal-article","created":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T11:22:09Z","timestamp":1619176929000},"page":"2247-2261","source":"Crossref","is-referenced-by-count":0,"title":["Observations on the Security of COMET"],"prefix":"10.1093","volume":"65","author":[{"given":"Zheng","family":"Xu","sequence":"first","affiliation":[{"name":"State Key Laboratory of Information Security , Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100089, China"},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongqiang","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security , Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100089, China"},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingsheng","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security , Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100089, China"},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2021,5,22]]},"reference":[{"volume-title":"Lightweight cryptography standardization project","year":"2019","author":"NIST","key":"2022091610474837400_ref1"},{"volume-title":"Status Report on the First Round of the NIST Lightweight Cryptography Standardization Process","year":"2019","author":"NIST.IR.8268","key":"2022091610474837400_ref2"},{"volume-title":"COMET: counter mode encryption with authentication tag. Submission to NIST lightweight cryptography project","year":"2019","author":"Gueron","key":"2022091610474837400_ref3"},{"volume-title":"Recommendation for Block Cipher Modes of Operation: Methods and Techniques","year":"2001","author":"NIST Special Publication 800-38A","key":"2022091610474837400_ref4"},{"key":"2022091610474837400_ref5","doi-asserted-by":"crossref","first-page":"218","DOI":"10.46586\/tches.v2018.i2.218-241","article-title":"Beetle family of lightweight and secure authenticated encryption ciphers","volume":"2018","author":"Chakraborti","year":"2018","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"2022091610474837400_ref6","first-page":"1","article-title":"Revised Version of Block Cipher CHAM","volume-title":"ICISC 2019","author":"Roh","year":"2019"},{"key":"2022091610474837400_ref7","first-page":"404","article-title":"The SIMON and SPECK families of lightweight block ciphers","volume":"2013","author":"Beaulieu","year":"2013","journal-title":"IACR Cryptol. ePrint Arch."},{"volume-title":"Advanced Encryption Standard (AES)","year":"2001","author":"FIPS PUB 197","key":"2022091610474837400_ref8"},{"key":"2022091610474837400_ref9","first-page":"3","article-title":"CHAM: A Family of Lightweight Block Ciphers for Resource-Constrained Devices","volume-title":"Information Security and Cryptology\u2014ICISC 2017\u201420th Int. Conf.","author":"Koo","year":"2017"},{"key":"2022091610474837400_ref10","first-page":"272","article-title":"Weak keys in the rekeying paradigm: application to COMET and mixfeed","volume":"2019","author":"Khairallah","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"volume-title":"On the security of comet authenticated encryption scheme. NIST lightweight cryptography workshop 2019, Maryland, USA, November 4\u20136, 2019","year":"2019","author":"Gueron","key":"2022091610474837400_ref11"},{"key":"2022091610474837400_ref12","first-page":"1445","article-title":"Observations on COMET","volume":"2020","author":"Bernstein","year":"2020","journal-title":"IACR Cryptol. ePrint Arch."},{"volume-title":"Updates on COMET. Submission to NIST lightweight cryptography project","year":"2020","author":"Gueron","key":"2022091610474837400_ref13"},{"key":"2022091610474837400_ref14","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/BF00630563","article-title":"Differential cryptanalysis of des-like cryptosystems","volume":"4","author":"Biham","year":"1991","journal-title":"J. Cryptology"},{"key":"2022091610474837400_ref15","first-page":"366","article-title":"On Correlation Between the Order of S-Boxes and the Strength of DES","volume-title":"EUROCRYPT \u201894","author":"Matsui","year":"1994"},{"key":"2022091610474837400_ref16","doi-asserted-by":"crossref","first-page":"1054","DOI":"10.1109\/TIT.2020.3040543","article-title":"A new method for searching optimal differential and linear trails in ARX ciphers","volume":"67","author":"Liu","year":"2021","journal-title":"IEEE Trans. Inf. Theory"},{"key":"2022091610474837400_ref17","first-page":"546","article-title":"Differential Analysis of Block Ciphers SIMON and SPECK","volume-title":"FSE 2014","author":"Biryukov","year":"2014"},{"key":"2022091610474837400_ref18","first-page":"268","article-title":"Milp-based Automatic Search Algorithms for Differential and Linear Trails for Speck","volume-title":"FSE 2016","author":"Fu","year":"2016"},{"key":"2022091610474837400_ref19","first-page":"101","article-title":"Speeding up MILP Aided Differential Characteristic Search with Matsui\u2019s Strategy","volume-title":"ISC 2018","author":"Zhang","year":"2018"},{"key":"2022091610474837400_ref20","first-page":"19","article-title":"Improving the milp-based security evaluation algorithms against differential cryptanalysis using divide-and-conquer approach","volume":"2019","author":"Zhou","year":"2019","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2022091610474837400_ref21","first-page":"163","article-title":"Mind the Gap\u2014A Closer Look at the Security of Block Ciphers Against Differential Cryptanalysis","volume-title":"SAC 2018","author":"Ankele","year":"2018"},{"key":"2022091610474837400_ref22","first-page":"459","article-title":"Differential Cryptanalysis of Round-reduced Sparx-64\/128","volume-title":"ACNS 2018","author":"Ankele","year":"2018"},{"key":"2022091610474837400_ref23","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1007\/978-3-662-47989-6_8","article-title":"Observations on the SIMON Block Cipher Family","volume-title":"CRYPTO 2015","author":"K\u00f6lbl","year":"2015"},{"key":"2022091610474837400_ref24","first-page":"328","article-title":"Towards finding optimal differential characteristics for arx: application to salsa20","volume":"2013","author":"Mouha","year":"2013","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2022091610474837400_ref25","first-page":"336","article-title":"Efficient Algorithms for Computing Differential Properties of Addition","volume-title":"FSE 2001","author":"Lipmaa","year":"2001"},{"key":"2022091610474837400_ref26","first-page":"519","article-title":"A Decision Procedure for Bit-Vectors and Arrays","volume-title":"CAV 2007","author":"Ganesh","year":"2007"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/9\/2247\/45882235\/bxab061.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/9\/2247\/45882235\/bxab061.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,16]],"date-time":"2022-09-16T10:49:49Z","timestamp":1663325389000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/65\/9\/2247\/6280578"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,22]]},"references-count":26,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2021,5,22]]},"published-print":{"date-parts":[[2022,9,16]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxab061","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"type":"print","value":"0010-4620"},{"type":"electronic","value":"1460-2067"}],"subject":[],"published-other":{"date-parts":[[2022,9]]},"published":{"date-parts":[[2021,5,22]]}}}