Research Article

MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers

Table 14

Fourteen-round DL distinguisher for SIMECK32 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part is , and , respectively.

Differential part

000100000000000000111010000000000
100010100000000000010000000000000
200001000000000000001010000000000
300000100000000000000100000000000
400000000000000000000010000000000
5000001000000000000000000000000000

DL part

−1.0−1.0−1.0−1.0−1.01.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

60.0−1.0−1.0−1.01.00.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.01.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

7−0.25−1.0−1.00.99990.00.50−1.0−1.0
−1.0−1.0−0.9999−0.50−1.0−1.0−1.00.0
0.0−1.0−1.0−1.01.00.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

80.0−1.00.99990.0−0.24500.0−0.75−1.0
−1.0−0.9999−0.2450−0.4688−1.0−1.00.0−0.0625
−0.25−1.0−1.00.99990.00.50−1.0−1.0
−1.0−1.0−0.9999−0.50−1.0−1.0−1.00.0

9−0.06250.87500.00.12500.00.1172−0.6426−1.0
−0.9999−0.1250−0.1556−0.1836−1.00.0−0.01560.0
0.0−1.00.99990.0−0.24500.0−0.75−1.0
−1.0−0.9999−0.2450−0.4688−1.0−1.00.0−0.0625

100.00.0−0.06250.00.00820.0−0.3645−1.0
−0.0625−0.0445−0.0133−0.14740.0−0.00390.0−0.0010
−0.06250.87500.00.12500.00.1172−0.6426−1.0
−0.9999−0.1250−0.1556−0.1836−1.00.0−0.01560.0

Linear part

00000001000000000000001000000000
1100000010000000000000000000000000
1200000000000000000000001000000000
1300000010000000000000000100000000
1400000001000000000000001010001000

Note: The experimental correlation of the first 10 () rounds is under sample sizes and 100 random keys, and the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .