MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers
Table 5
Fourteen-round DL distinguisher for SIMON32 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.
Differential part
0
00000000000010000000000000100010
1
00000000000000100000000000001000
2
00000000000000000000000000000010
3
00000000000000100000000000000000
4
00000000000010000000000000000010
5
00000000001000100000000000001000
DL part
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
6
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
7
0.0
−0.25
−1.0
−1.0
0.0
−0.25
1.0
0.0
−0.5
−1.0
0.5
0.0
−0.5
−1.0
0.5
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
8
−0.4687
−1.0
0.0
−0.0625
0.4687
0.0
−0.75
−0.25
0.0
−0.25
−0.75
0.25
0.0
0.0
−0.0625
0.0
−0.25
−1.0
−1.0
0.0
−0.25
1.0
0.0
−0.5
−1.0
0.5
0.0
−0.5
−1.0
0.5
−1.0
9
0.0
−0.0039
0.1556
0.0
−0.0468
0.1093
0.0
−0.0458
−0.4687
−0.0546
0.0
−0.0156
0.0622
−0.6425
−0.4687
−1.0
0.0
−0.0625
0.4687
0.0
−0.75
−0.25
0.0
−0.25
−0.75
0.25
0.0
0.0
−0.0625
10
0.0191
0.0
−0.0007
−0.0134
0.0
0.0
−0.1509
−0.0050
0.0
0.0
−0.0029
−0.0039
0.0
0.0
0.00006
0.0
−0.0039
0.1556
0.0
−0.0468
0.1093
0.0
−0.0458
−0.4687
−0.05468
0.0
−0.0156
0.0622
−0.6425
Linear part
00000000000000000000000000000001
11
00000000000000010100000000000000
12
01000000000000000001000000000001
13
00010000000000010000010000000000
14
00000100000000000001000100000001
Note: The experimental correlation of the first 10 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .