MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers
Table 6
Fifteen-round DL distinguisher for SIMON48 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.
Differential part
0
100000000000000000000000001000100000000000000010
1
001000100000000000000000100000000000000000000000
2
000010000000000000000000001000100000000000000000
3
000000100000000000000000000010000000000000000000
4
000000000000000000000000000000100000000000000000
5
000000100000000000000000000000000000000000000000
6
000010000000000000000000000000100000000000000000
7
001000100000000000000000000010000000000000000000
DL part
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
8
1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
9
−0.5
−1.0
1.0
0.0
−0.5
−1.0
1.0
−1.0
−1.0
−1.0
−0.50
−1.0
−1.0
−1.0
−0.5
−1.0
0.0
−0.25
−1.0
−1.0
0.0
−0.25
1.0
0.0
1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
0.0
−1.0
10
−1.0
0.0
−0.1875
−0.75
1.0
0.0
−0.75
−1.0
−0.2499
−0.4687
−1.0
−0.9999
−0.25
−0.4687
0.0
−0.0625
−0.4687
−1.0
0.0
−0.0625
0.4687
0.0
0.0
−0.75
−0.5
−1.0
1.0
0.0
−0.5
−1.0
1.0
−1.0
−1.0
−1.0
−0.50
−1.0
−1.0
−1.0
−0.5
−1.0
0.0
−0.25
−1.0
−1.0
0.0
−0.25
1.0
0.0
11
−0.0292
−0.3270
−0.8750
0.0
−0.1171
−0.6425
0.1249
−0.1556
−0.5393
−0.9999
−0.0625
−0.1556
0.0
−0.0156
−0.0622
−0.6425
0.0
−0.0039
0.1478
0.0
0.0
−0.0468
0.7656
−1.0
0.0
−0.1875
−0.75
1.0
0.0
−0.75
−1.0
−0.2499
−0.4687
−1.0
−0.9999
−0.25
−0.4687
0.0
−0.0625
−0.4687
−1.0
0.0
−0.0625
0.4687
0.0
0.0
−0.75
Linear part
001000000000000000000000100000000000000000000000
12
100000000000000000000000000000000000000000000000
13
000000000000000000000000100000000000000000000000
14
100000000000000000000000001000000000000000000000
15
001000000000000000000000100010000000000000000000
Note: The experimental correlation of the first 11 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .