Research Article

MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers

Table 2

The DL distinguishers of reduced-round SIMON.

CipherRoundConfigurationCorrelationReferences
TheoryExperiment

SIMON3213[24]
13This work
14This work
SIMON4813-[24]
15This work
16This work
17This work
SIMON6420This work
SIMON9625This work
26This work
SIMON12831This work
32This work

Note: aPractical correlation. The sample size for 13-round SIMON32 is , where we randomly chose 100 master keys. bSegmented experimental validation of theoretical correlation. Specifically, regarding the top and middle parts as a DL distinguisher, we obtain an experimental DL correlation with sample sizes and 100 random master keys. For the bottom linear part, we obtain an experimental linear correlation. Finally, the experimental correlations are obtained based on piling-up lemma. cSegmented experimental validation of theoretical correlation. Specifically, for the top, middle and bottom parts, we obtain an experimental differential probability, an experimental DL correlation, and an experimental linear correlation, respectively. Finally, the experimental correlations are obtained based on piling-up lemma. dSegmented experimental validation of theoretical correlation. Specifically, for the top and middle parts, we obtain an experimental differential probability and an experimental DL correlation, respectively. Finally, the experimental correlations are obtained based on piling-up lemma.