Research Article

MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers

Table 6

Fifteen-round DL distinguisher for SIMON48 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.

Differential part

0100000000000000000000000001000100000000000000010
1001000100000000000000000100000000000000000000000
2000010000000000000000000001000100000000000000000
3000000100000000000000000000010000000000000000000
4000000000000000000000000000000100000000000000000
5000000100000000000000000000000000000000000000000
6000010000000000000000000000000100000000000000000
7001000100000000000000000000010000000000000000000

DL part

−1.0−1.01.0−1.0−1.0−1.01.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.01.0−1.0−1.0−1.0
1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

81.00.0−1.0−1.0−1.00.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.00.0−1.0−1.0−1.00.0−1.0
−1.0−1.01.0−1.0−1.0−1.01.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

9−0.5−1.01.00.0−0.5−1.01.0−1.0
−1.0−1.0−0.50−1.0−1.0−1.0−0.5−1.0
0.0−0.25−1.0−1.00.0−0.251.00.0
1.00.0−1.0−1.0−1.00.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.00.0−1.0−1.0−1.00.0−1.0

10−1.00.0−0.1875−0.751.00.0−0.75−1.0
−0.2499−0.4687−1.0−0.9999−0.25−0.46870.0−0.0625
−0.4687−1.00.0−0.06250.46870.00.0−0.75
−0.5−1.01.00.0−0.5−1.01.0−1.0
−1.0−1.0−0.50−1.0−1.0−1.0−0.5−1.0
0.0−0.25−1.0−1.00.0−0.251.00.0

11−0.0292−0.3270−0.87500.0−0.1171−0.64250.1249−0.1556
−0.5393−0.9999−0.0625−0.15560.0−0.0156−0.0622−0.6425
0.0−0.00390.14780.00.0−0.04680.7656
−1.00.0−0.1875−0.751.00.0−0.75−1.0
−0.2499−0.4687−1.0−0.9999−0.25−0.46870.0−0.0625
−0.4687−1.00.0−0.06250.46870.00.0−0.75

Linear part

001000000000000000000000100000000000000000000000
12100000000000000000000000000000000000000000000000
13000000000000000000000000100000000000000000000000
14100000000000000000000000001000000000000000000000
15001000000000000000000000100010000000000000000000

Note: The experimental correlation of the first 11 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .