Research Article

Rotational-XOR Rectangle Cryptanalysis on Round-Reduced Simon

Table 3

Combinations of trails for constructing the RX rectangle distinguisher.

Simon-Rounds ()Probability

32/648 + 8 = 16
48/727 + 9 = 16
48/969 + 9 = 18.
64/968 + 9 = 17
64/1289 + 10 = 19