AI & Computingarticle2026-08-07

Equivalence of XOR and XNOR in differential cryptanalysis: application to SCAN-C

Open access0 citations

Abstract

Abstract SCAN-C is a lightweight block cipher featuring a hybrid Feistel-SPN structure designed for Controller Area Network (CAN) security. This work presents the first full-round differential cryptanalysis of SCAN-C, demonstrating that its unique XNOR-based key mixing provides no additional security margin. We also prove that XNOR-based mixing is structurally equivalent to standard XOR mixing, as the corresponding difference distribution tables (DDTs) differ only by a permutation of indices. Utilizing an SMT-based automated search, we identify optimal differential clusters, including a 9-round distinguisher with a probability of $$2^{-51.30}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:msup> <mml:mn>2</mml:mn> <mml:mrow> <mml:mo>-</mml:mo> <mml:mn>51.30</mml:mn> </mml:mrow> </mml:msup> </mml:math> . By extending these results, we show that the complete internal key state can be recovered through the recovery of all 12 round keys, requiring around $$2^{55}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:msup> <mml:mn>2</mml:mn> <mml:mn>55</mml:mn> </mml:msup> </mml:math> chosen plaintexts and $$2^{69}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:msup> <mml:mn>2</mml:mn> <mml:mn>69</mml:mn> </mml:msup> </mml:math> encryptions. Our results confirm that the current 12-round specification is insufficient for security and is the first to show that differential cryptanalysis is equivalent under both XOR and XNOR difference definitions.

// Source

View paper (DOI)Open access versionOpenAlexCybersecurityPublished 2026-08-07

Authors: Vanshita Jha, Je Sen Teh, Aishwarya Thiruvengadam

Institutions: Deakin University, Indian Institute of Technology Madras