Abstract In lightweight block cipher designs, involutory components are often employed to minimize circuit area. However, these components can also introduce security vulnerabilities. Loong is a family of lightweight block ciphers based on the Substitution-Permutation Network (SPN) structure. Each round of Loong incorporates two involutory MDS matrices and two involutory S-boxes, resulting in a fully involutory round function. While these operations provide high diffusion and a substantial algebraic degree, the involutory nature of the design makes Loong vulnerable to weak-key attacks. In this paper, we present several notable observations regarding the round function of Loong. By exploiting the unique properties of its involutory round function, we identify weak-key differential characteristics for all three full-round variants of Loong. Specifically, the probabilities of weak-key differential characteristics for Loong-64, Loong-80, and Loong-128 are 2^-26. 83 2 - 26. 83, 2^-37. 42 2 - 37. 42 and 2^-46. 66 2 - 46. 66, respectively. The corresponding weak-key spaces are of sizes 2^36 2 36, 2^52 2 52 and 2^96 2 96. These findings effectively compromise the security of Loong. Furthermore, we conducted experiments on a personal computer and identified practical differential characteristics for Loong-64. Additionally, we analyze the security of block ciphers with involutory round functions in general. Our findings indicate that such designs are more prone to weak-key attacks and are even more vulnerable to general differential cryptanalysis. While the use of involutory round functions reduces circuit area and improves cipher efficiency, it also introduces significant security weaknesses.
Guo et al. (Tue,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: