SIMON is a widely used block cipher family designed by the National Security Agency for lightweight applications and has attracted significant cryptanalytic scrutiny. One of its most robust variants is SIMON 64/128 (64-bit block, 128-bit key). To the best of our knowledge, previous linear hull approaches have successfully analyzed up to 31 out of 44 rounds, but with a high time complexity of 2120 and a memory requirement of c·231. In this work, we propose a novel hybrid cryptanalytic framework that integrates SMT-aided partial key recovery with a statistical distinguisher. By utilizing the Z₃ solver to prune the subkey search space through bit-vector equations and subsequently verifying candidates via a 22-round statistical distinguisher, we achieve a key recovery attack on 31 rounds. Our approach significantly reduces the time complexity to 282.39 and the data complexity to a full codebook of 264, while maintaining negligible memory complexity. Furthermore, we demonstrate the practicality of this hybrid framework through successful experimental verification on a 25-round version of the cipher.
Tentu et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: