Research Article
SAT-Based Security Evaluation for WARP against Linear Cryptanalysis
Table 11
19-round linear trial with optimal correlation
.
| Round | Mask | |
| 0 | 0xa000 005a 00f0 00aa 0000 0000 5000 005f | 1 | 1 | 0x000f 0000 a0a5 0000 0000 0000 00f0 00a | | 2 | 0x5000 0005 0000 00f0 000f 0000 00aa 0500 | | 3 | 0x0000 0000 5f00 0500 a000 5a0f 0000 00f5 | | 4 | 0x00f0 5500 0000 000a 0000 0000 ff50 a000 | | 5 | 0x0f00 0000 0aa0 5000 00f5 000a 0000 0f00 | | 6 | 0x00aa 0af0 0f00 0000 0000 f000 a505 005f | | 7 | 0x05f0 0000 0000 a0a0 5f5a 0f00 00f5 0000 | | 8 | 0x0000 0050 0000 0f0a 5f00 00fa 0a00 ffaa | | 9 | 0x0000 f500 00aa 0000 00a0 f5f5 a5a0 0000 | | 10 | 0xa500 0000 0000 5a00 005a 0000 5000 5000 | | 11 | 0x0000 a050 0505 0000 0000 0000 0000 00a5 | | 12 | 0x5a5f 0000 0000 0000 0000 0500 005f 0000 | | 13 | 0x0000 00a0 0000 00f0 ff00 0000 0000 5a00 | | 14 | 0x0000 0000 0000 0000 0000 aaff 0000 0000 | | 15 | 0x0000 0000 0000 0000 0000 0000 f000 a000 | | 16 | 0x0000 0000 0a0f 0000 0000 0000 0000 0000 | | 17 | 0xf0a5 0000 0000 0000 0000 0000 000a 0000 | | 18 | 0x0000 0000 0000 0050 a00a 0000 0000 000f | | 19 | 0x0000 0005 0000 0a0a 0000 0005 00f0 00a0 | |
|
|