A Cryptanalysis of HummingBird-2: The Differential Sequence Analysis.
Qi Chai, Guang Gong · 2012
Abstract. Hummingbird-2 is one recent design of lightweight block ciphers that enables compact hardware implementations, ultra-low power consumption and stringent response time as specified in ISO18000-6C. In this paper, we present cryptanalytic results on the full version of this cipher using two pairs of related keys. We discover that the differential sequences for the last invocation of the round function can be computed by running the full cipher, due to which the search space for the key can be reduced. Base upon this observation, we propose a probabilistic attack encompassing two phases, preparation phase and key recovery phase. The preparation phase, requiring 2 80 effort in time, reaches the internal states satisfying particular conditions with 0.5 probability. In the key recovery phase, by using the proposed differential sequence analysis (DSA) against the encryption (decryption resp.), 36-bit (another 44-bit resp.) of the 128-bit key could be recovered. Additionally, the rest 48-bit of the key can be exhaustively searched and the overall time complexity of this phase is 2 48.14. Note that the proposed attack, though exhibiting an interesting tradeoff between success probability and time complexity, is only of a theoretical interest at the moment and does not affect the practical security of the Hummingbird-2.