MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers
Table 8
Seventeen-round DL distinguisher for SIMON48 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.
Differential part
0
000000100000000000000000000010001000100000000000
1
000000001000100000000000000000100000000000000000
2
000000000010000000000000000000001000100000000000
3
000000000000100000000000000000000010000000000000
4
000000000000000000000000000000000000100000000000
5
000000000000100000000000000000000000000000000000
6
000000000010000000000000000000000000100000000000
7
000000001000100000000000000000000010000000000000
DL part
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
8
0.0
−1.0
−1.0
−1.0
0.0
−1.0
0.9999
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
9
−1.0
−1.0
0.0
−0.25
0.9999
0.0
−0.5
−1.0
1.0
0.0
−0.5
−1.0
1.0
−1.0
−1.0
−1.0
−0.5
−1.0
−1.0
−1.0
−0.5
−1.0
0.0
−0.25
0.0
−1.0
−1.0
−1.0
0.0
−1.0
0.9999
0.0
−1.0
−1.0
−1.0
0.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
−1.0
10
0.0
−0.0625
0.4688
0.0
0.0
−0.75
−0.9999
−0.1875
−0.75
0.9999
0.0
−0.75
−1.0
−0.25
−0.4688
−1.0
−1.0
−0.25
−0.4688
0.0
−0.0625
−0.4688
−1.0
−1.0
−1.0
0.0
−0.25
0.9999
0.0
−0.5
−1.0
1.0
0.0
−0.5
−1.0
1.0
−1.0
−1.0
−1.0
−0.5
−1.0
−1.0
−1.0
−0.5
−1.0
0.0
−0.25
11
0.1479
0.0
0.0
−0.0469
0.7656
0.0
−0.0293
−0.3270
−0.8750
0.0
−0.1172
−0.6426
0.1250
−0.1556
−0.5393
−1.0
−0.0625
−0.1556
0.0
−0.0156
−0.0623
−0.6426
0.0
−0.0039
0.0
−0.0625
0.4688
0.0
0.0
−0.75
−0.9999
−0.1875
−0.75
0.9999
0.0
−0.75
−1.0
−0.2500
−0.4688
−1.0
−1.0
−0.2450
−0.4688
0.0
−0.0625
−0.4688
−1.0
12
0.0
−0.0007
−0.1049
0.0
−0.0729
−0.4468
0.0
−0.0058
−0.1556
−0.0513
0.0
−0.1241
−0.6321
−0.0078
−0.0195
−0.0
−0.0039
−0.0040
−0.0837
0.0
−0.00006
0.0179
−0.0
0.1479
0.0
0.0
−0.0469
0.7656
0.0
−0.0293
−0.3270
−0.8750
0.0
−0.1172
−0.6426
0.1250
−0.1556
−0.5393
−1.0
−0.0625
−0.1556
0.0
−0.0156
−0.0623
−0.6426
0.0
−0.0039
13
0.0039
0.0
0.0
−0.0009
0.1032
0.0
−0.00004
−0.0130
−0.0130
−0.0037
−0.1237
0.0004
−0.0008
0.0
−0.0010
−0.00006
−0.0033
0.0
0.0003
0.0
0.0
0.0
−0.0007
−0.1049
0.0
−0.0729
−0.4468
0.0
−0.0058
−0.1556
−0.0513
0.0
−0.1241
−0.6321
−0.0078
−0.0195
−0.0
−0.0039
−0.0040
−0.0837
0.0
−0.00006
0.0179
−0.0
Linear part
000000000000000000000000000000000000010000000000
14
000000000000010000000000000000000000000100000000
15
000000000000000100000000000000000000010001000000
16
000000000000010001000000000000000000000000010000
17
000000000000000000010000000000000000010001000100
Note: The experimental correlation of the first 13 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .