MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers
Table 14
Fourteen-round DL distinguisher for SIMECK32 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part is , and , respectively.
Differential part
0
00100000000000000111010000000000
1
00010100000000000010000000000000
2
00001000000000000001010000000000
3
00000100000000000000100000000000
4
00000000000000000000010000000000
5
000001000000000000000000000000000
DL part
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
6
0.0
−1.0
−1.0
−1.0
1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
7
−0.25
−1.0
−1.0
0.9999
0.0
0.50
−1.0
−1.0
−1.0
−1.0
−0.9999
−0.50
−1.0
−1.0
−1.0
0.0
0.0
−1.0
−1.0
−1.0
1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
8
0.0
−1.0
0.9999
0.0
−0.2450
0.0
−0.75
−1.0
−1.0
−0.9999
−0.2450
−0.4688
−1.0
−1.0
0.0
−0.0625
−0.25
−1.0
−1.0
0.9999
0.0
0.50
−1.0
−1.0
−1.0
−1.0
−0.9999
−0.50
−1.0
−1.0
−1.0
0.0
9
−0.0625
0.8750
0.0
0.1250
0.0
0.1172
−0.6426
−1.0
−0.9999
−0.1250
−0.1556
−0.1836
−1.0
0.0
−0.0156
0.0
0.0
−1.0
0.9999
0.0
−0.2450
0.0
−0.75
−1.0
−1.0
−0.9999
−0.2450
−0.4688
−1.0
−1.0
0.0
−0.0625
10
0.0
0.0
−0.0625
0.0
0.0082
0.0
−0.3645
−1.0
−0.0625
−0.0445
−0.0133
−0.1474
0.0
−0.0039
0.0
−0.0010
−0.0625
0.8750
0.0
0.1250
0.0
0.1172
−0.6426
−1.0
−0.9999
−0.1250
−0.1556
−0.1836
−1.0
0.0
−0.0156
0.0
Linear part
00000001000000000000001000000000
11
00000010000000000000000000000000
12
00000000000000000000001000000000
13
00000010000000000000000100000000
14
00000001000000000000001010001000
Note: The experimental correlation of the first 10 () rounds is under sample sizes and 100 random keys, and the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .