MSX: Lightweight Block Ciphers for Microcontrollers with High-assurance against Differential and Linear Attacks
Kazuhiko Minematsu, Tomoyasu Suzaki, Mostafizar Rahman, Sahiba Suryawanshi, Takanori Isobe · IACR Communications in Cryptology · 2026
We present MSX, a new family of 64/128-bit block ciphers. It aims to provide fast execution on microcontrollers and comes with a highly reliable argument on the resistance against basic differential/linear attacks, backed by the classical differential/linear probability analysis on Feistel ciphers and Vaudenay's decorrelation theory. MSX are classical (generalized) Feistel ciphers with a round function. Similar to many existing ARX ciphers, its round function uses arithmetic operations and does not have an S-box. A unique feature of MSX is its use of 32-bit integer multiplication, which enables proving an ideally strong differential/linear property by design. It could be interpreted as an application of Vaudenay's decorrelation theory. We provide a detailed security analysis on attacks beyond differential and linear ones and conduct a benchmark on a range of popular microcontrollers with a comparison to Speck, a top performer on microcontrollers. The results show MSX's good performance on 32-bit microcontrollers, maintaining a sufficiently large security margin. MSX aims at security under single key, and related-key security is not the focus.