ABSTRACT Since the proposal of the Grover algorithm in 1996, which first combined quantum algorithms with symmetric cryptanalysis, significant progress has been made in the quantization of classical cryptanalysis methods. Differential‐linear cryptanalysis is a hybrid technique combining differential and linear cryptanalysis; however, there has been no prior work on its quantization. This paper presents a quantum differential‐linear key recovery attack framework. We apply this framework to Simon32/64 and Simeck32/64. Considering that the experimental correlation distribution of the differential‐linear distinguisher significantly affects the complexity of quantum attacks, we measure the experimental correlation distributions of Simon32/64 and Simeck32/64. We conduct a quantum differential‐linear key recovery attack on 19‐round Simon32/64. Under the Q1 model, the time complexity of the attack is , the data complexity is , the memory complexity is and the success rate is 60.96%, which achieves the lowest time, memory, and data complexities among all existing 19‐round quantum attacks. In the Q2 model, the time complexity reduces to , with negligible memory complexity. For Simeck32/64, we present a 20‐round quantum key recovery attack under the Q2 model, which is the first quantum key recovery attack on this block cipher.
Z et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: