MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers
Table 16
Eighteen-round DL distinguisher for SIMECK48 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.
Differential part
0
000000000000000000001000000000000000000000010100
1
000000000000000000000100000000000000000000001000
2
000000000000000000000000000000000000000000000100
3
000000000000000000000100000000000000000000000000
4
000000000000000000001000000000000000000000000100
5
000000000000000000010100000000000000000000001000
6
000000000000000000100000000000000000000000010100
DL part
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
1.0
−1.0
−1.0
7
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
1.0
0.0
1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
8
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−0.5
−1.0
−1.0
−1.0
0.0
−0.25
0.0
−1.0
0.0
0.0
−0.5
0.0
1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
1.0
0.0
1.0
−1.0
1.0
−1.0
−1.0
9
−1.0
−1.0
−1.0
−0.75
−1.0
−1.0
−1.0
−0.25
−0.4688
−0.5
−1.0
0.0
−0.0625
0.0
−0.25
0.0
0.0
0.25
0.0
−0.5
0.0
0.5
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−0.5
−1.0
−1.0
−1.0
0.0
−0.25
0.0
−1.0
0.0
0.0
−0.5
0.0
1.0
0.0
−1.0
−1.0
10
−1.0
−1.0
−0.4688
−0.6426
−0.75
−1.0
−0.1250
−0.1556
−0.0918
−0.4688
0.0
−0.0156
0.0
−0.0156
0.0
0.0
0.0
0.0
−0.1250
0.0
−0.25
0.0
−0.875
−1.0
−1.0
−1.0
−1.0
−0.75
−1.0
−1.0
−1.0
−0.25
−0.4688
−0.5
−1.0
0.0
−0.0625
0.0
−0.25
0.0
0.0
0.25
0.0
−0.5
0.0
0.5
−1.0
−1.0
11
−1.0
−0.2637
−0.2727
−0.2522
−0.6426
−0.0625
−0.0445
−0.0066
−0.0609
0.0
−0.0039
0.0
−0.0002
0.0
0.0
0.0
0.0
0.0146
0.0
−0.0625
0.0
0.1606
−0.77
−0.875
−1.0
−1.0
−0.4688
−0.6426
−0.75
−1.0
−0.1250
−0.1556
−0.0918
−0.4688
0.0
−0.0156
0.0
−0.0156
0.0
0.0
0.0
0.0
−0.1250
0.0
−0.25
0.0
−0.875
−1.0
12
−0.1401
−0.09
−0.0379
−0.1371
−0.0192
−0.0119
−0.0002
−0.0024
0.0
−0.0005
0.0
0.0
0.0
0.0
0.0
0.0
−0.0037
0.0
0.0127
0.0
−0.4242
−0.77
−1.0
−0.2637
−0.2727
−0.2522
−0.6426
−0.0625
−0.0445
−0.0066
−0.0609
0.0
−0.0039
0.0
−0.0002
0.0
0.0
0.0
0.0
0.0146
0.0
−0.0625
0.0
0.1606
−0.77
−0.875
Linear part
000000000000000000000001000000000000000000000010
13
000000000000000000000010000000000000000000000000
14
000000000000000000000000000000000000000000000010
15
000000000000000000000010000000000000000000000001
16
000000000000000000000001100000000000000000000010
17
100000000000000000000010010000000000000000000000
18
010000000000000000000000101000000000000000000010
Note: The experimental correlation of the first 12 () rounds is under sample sizes and 100 random keys, and the experimental correlation of the 6 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .