Research Article

MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers

Table 5

Fourteen-round DL distinguisher for SIMON32 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.

Differential part

000000000000010000000000000100010
100000000000000100000000000001000
200000000000000000000000000000010
300000000000000100000000000000000
400000000000010000000000000000010
500000000001000100000000000001000

DL part

−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.01.0−1.0−1.0−1.01.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.01.0−1.0−1.0−1.0

6−1.0−1.00.0−1.0−1.0−1.00.0−1.0
1.00.0−1.0−1.0−1.00.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.01.0−1.0−1.0−1.01.0−1.0

70.0−0.25−1.0−1.00.0−0.251.00.0
−0.5−1.00.50.0−0.5−1.00.5−1.0
−1.0−1.00.0−1.0−1.0−1.00.0−1.0
1.00.0−1.0−1.0−1.00.0−1.0−1.0

8−0.4687−1.00.0−0.06250.46870.0−0.75
−0.250.0−0.25−0.750.250.00.0−0.0625
0.0−0.25−1.0−1.00.0−0.251.00.0
−0.5−1.00.50.0−0.5−1.00.5−1.0

90.0−0.00390.15560.0−0.04680.10930.0
−0.0458−0.4687−0.05460.0−0.01560.0622−0.6425
−0.4687−1.00.0−0.06250.46870.0−0.75
−0.250.0−0.25−0.750.250.00.0−0.0625

100.01910.0−0.0007−0.01340.00.0−0.1509
−0.00500.00.0−0.0029−0.00390.00.00.00006
0.0−0.00390.15560.0−0.04680.10930.0
−0.0458−0.4687−0.054680.0−0.01560.0622−0.6425

Linear part

00000000000000000000000000000001
1100000000000000010100000000000000
1201000000000000000001000000000001
1300010000000000010000010000000000
1400000100000000000001000100000001

Note: The experimental correlation of the first 10 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .