Journal of Computer Applications ›› 2026, Vol. 46 ›› Issue (7): 2208-2215.DOI: 10.11772/j.issn.1001-9081.2025060713

• Cyber security • Previous Articles    

Differential-linear analysis method for data encryption algorithm LiCi

Yanjun LI1,2, Dingyun HUANG1, Zhong WANG3, Xin CHEN4(), Yuan GAO5   

  1. 1.Department of Cryptography Science and Technology,Beijing Electronic Science and Technology Institute,Beijing 100070,China
    2.The 15th Research Institute of China Electronics Technology Group Corporation,Beijing 100083,China
    3.China National Accreditation Center for Conformity Assessment,Beijing 100062,China
    4.China Cybersecurity Review,Certification and Market Regulation Big Data Center,Beijing 100045,China
    5.Department of Electronic and Communication Engineering,Beijing Electronic Science and Technology Institute,Beijing 100070,China
  • Received:2025-06-27 Revised:2025-10-20 Accepted:2025-10-22 Online:2025-11-05 Published:2026-07-10
  • Contact: Xin CHEN
  • About author:LI Yanjun, born in 1979, Ph. D., associate professor. Her research interests include information security, block cipher design and analysis.
    HUANG Dingyun, born in 2000, M. S. candidate. His research interests include block cipher design and analysis.
    WANG Zhong, born in 1974, M. S. His research interests include data security.
    GAO Yuan, born in 1979, Ph. D., lecturer. Her research interests include information security strategy, multimedia digital security.
  • Supported by:
    Science and Technology Program of State Administration for Market Regulation of China(2023MK213);Equipment Data Security and Guarantee Technology Key Laboratory of Ministry of Education(2024010102)

数据加密算法LiCi的差分-线性分析方法

李艳俊1,2, 黄丁韫1, 王忠3, 陈鑫4(), 高原5   

  1. 1.北京电子科技学院 密码科学与技术系,北京 100070
    2.中国电子科技集团公司 第十五研究所,北京 100083
    3.中国合格评定国家认可中心,北京 100062
    4.中国网络安全审查认证和市场监管大数据中心,北京 100045
    5.北京电子科技学院 电子与通信工程系,北京 100070
  • 通讯作者: 陈鑫
  • 作者简介:李艳俊(1979—),女,山西晋城人,副教授,博士,主要研究方向:信息安全、分组密码设计与分析
    黄丁韫(2000—),男,江西宜春人,硕士研究生,主要研究方向:分组密码设计与分析
    王忠(1974—),男,北京人,硕士,主要研究方向:数据安全
    高原(1979—),女,辽宁沈阳人,讲师,博士,主要研究方向:信息安全战略、多媒体数字安全。
  • 基金资助:
    国家市场监督管理总局科技计划项目(2023MK213);装备数据安全与保障技术教育部重点实验室资助项目(2024010102)

Abstract:

Currently, differential-linear security analysis of the LiCi block cipher is still missing. To fill this gap, this paper proposed a differential-linear analysis method for LiCi based on constraint programming (CP) modeling and key recovery. First, the LiCi algorithm was decomposed into three layers: a differential layer, a middle layer, and a linear layer. For each layer, constraints on the propagation of differential and linear masks were established, including inequality constraints for the S-box, branch propagation, and XOR operations of the differential and linear masks, as well as constraints for the objective function. Then, the Gurobi solver was used to perform the search. Experimental results show that a 13-round differential-linear distinguisher for LiCi with a probability of 2-27.4 exists. By appending 4 rounds before and extending 3 rounds after this distinguisher, a 20-round key-recovery attack can be mounted, recovering 91 bits of key information with a time complexity of 2114.3 20-round encryptions and a data complexity of 248 plaintexts. This result advances the number of breakable rounds of LiCi from 17 to 20, and for the first time provides a remaining security margin of 11 rounds out of the full 31 rounds.

Key words: LiCi algorithm, differential-linear analysis, key recovery attack, lightweight block cipher, distinguisher

摘要:

目前还缺少针对数据加密算法LiCi的差分-线性安全性分析,因此,本文基于约束规划(CP)建模和密钥恢复提出一种适用于LiCi算法的差分-线性分析方法。首先,将LiCi算法拆分为差分层、中间层与线性层3层,并对每一层分别建立差分与线性掩码传播的约束,包括对LiCi算法差分与线性掩码的S盒、分支传播以及异或过程中的不等式约束以及目标函数的约束;其次,使用Gurobi求解器进行搜索。实验结果表明:对于LiCi算法存在概率为2-27.4的13轮差分-线性区分器,在此基础上分别向前添加4轮,并向后扩展3轮,可以实现20轮的密钥恢复攻击,并可恢复91 bit的密钥信息,其中时间复杂度为2114.3次20轮加密,数据复杂度为248个明文。该结果将LiCi算法的可攻破轮数从17轮推进到20轮,并首次给出31轮总轮数下剩余11轮的安全冗余量。

关键词: LiCi算法, 差分-线性分析, 密钥恢复攻击, 轻量级分组密码, 区分器

CLC Number: