In this paper, we study NIST lightweight 3rd round candidate [Formula: see text]. The core component of [Formula: see text] is the keyed permutation [Formula: see text], which is based on a non-linear feedback shift register. By analysing this permutation carefully, we are able to find good cubes that are used to build distinguishers in the weak-key setting.
View Article and Find Full Text PDF