Equivalence of XOR and XNOR in differential cryptanalysis: application to SCAN-C
SCAN-C is a lightweight block cipher featuring a hybrid Feistel-SPN structure designed for Controller Area Network (CAN) security. This work presents the first full-round differential cryptanalysis of SCAN-C, demonstrating that its unique XNOR-based key mixing provides no additional security margin. We also prove that XNOR-based mixing is structurally equivalent to standard XOR mixing, as the corresponding difference distribution tables (DDTs) differ only by a permutation of indices. Utilizing an SMT-based automated search, we identify optimal differential clusters, including a 9-round distinguisher with a probability of 2-51.30\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$2^{-51.30}$$\end{document}. By extending these results, we show that the complete internal key state can be recovered through the recovery of all 12 round keys, requiring around 255\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$2^{55}$$\end{document} chosen plaintexts and 269\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$2^{69}$$\end{document} encryptions. Our results confirm that the current 12-round specification is insufficient for security and is the first to show that differential cryptanalysis is equivalent under both XOR and XNOR difference definitions.