Research Article

MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like Ciphers

Table 8

Seventeen-round DL distinguisher for SIMON48 with theoretical correlation and experimental correlation , where the theoretical probability of the differential part, the theoretical correlation of the DL part, and the theoretical correlation of the linear part are , and , respectively.

Differential part

0000000100000000000000000000010001000100000000000
1000000001000100000000000000000100000000000000000
2000000000010000000000000000000001000100000000000
3000000000000100000000000000000000010000000000000
4000000000000000000000000000000000000100000000000
5000000000000100000000000000000000000000000000000
6000000000010000000000000000000000000100000000000
7000000001000100000000000000000000010000000000000

DL part

−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
1.0−1.0−1.0−1.01.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.01.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

80.0−1.0−1.0−1.00.0−1.00.99990.0
−1.0−1.0−1.00.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0
1.0−1.0−1.0−1.01.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

9−1.0−1.00.0−0.250.99990.0−0.5−1.0
1.00.0−0.5−1.01.0−1.0−1.0−1.0
−0.5−1.0−1.0−1.0−0.5−1.00.0−0.25
0.0−1.0−1.0−1.00.0−1.00.99990.0
−1.0−1.0−1.00.0−1.0−1.0−1.0−1.0
−1.0−1.0−1.0−1.0−1.0−1.0−1.0−1.0

100.0−0.06250.46880.00.0−0.75−0.9999
−0.1875−0.750.99990.0−0.75−1.0−0.25−0.4688
−1.0−1.0−0.25−0.46880.0−0.0625−0.4688−1.0
−1.0−1.00.0−0.250.99990.0−0.5−1.0
1.00.0−0.5−1.01.0−1.0−1.0−1.0
−0.5−1.0−1.0−1.0−0.5−1.00.0−0.25

110.14790.00.0−0.04690.76560.0−0.0293−0.3270
−0.87500.0−0.1172−0.64260.1250−0.1556−0.5393−1.0
−0.0625−0.15560.0−0.0156−0.0623−0.64260.0−0.0039
0.0−0.06250.46880.00.0−0.75−0.9999
−0.1875−0.750.99990.0−0.75−1.0−0.2500−0.4688
−1.0−1.0−0.2450−0.46880.0−0.0625−0.4688−1.0

120.0−0.0007−0.10490.0−0.0729−0.44680.0
−0.0058−0.1556−0.05130.0−0.1241−0.6321−0.0078−0.0195
−0.0−0.0039−0.0040−0.08370.0−0.000060.0179−0.0
0.14790.00.0−0.04690.76560.0−0.0293−0.3270
−0.87500.0−0.1172−0.64260.1250−0.1556−0.5393−1.0
−0.0625−0.15560.0−0.0156−0.0623−0.64260.0−0.0039

130.00390.00.0−0.00090.10320.0−0.00004−0.0130
−0.0130−0.0037−0.12370.0004−0.00080.0−0.0010
−0.00006−0.00330.00.00030.00.0
0.0−0.0007−0.10490.0−0.0729−0.44680.0
−0.0058−0.1556−0.05130.0−0.1241−0.6321−0.0078−0.0195
−0.0−0.0039−0.0040−0.08370.0−0.000060.0179−0.0

Linear part

000000000000000000000000000000000000010000000000
14000000000000010000000000000000000000000100000000
15000000000000000100000000000000000000010001000000
16000000000000010001000000000000000000000000010000
17000000000000000000010000000000000000010001000100

Note: The experimental correlation of the first 13 () rounds is under sample sizes and 100 random keys, the experimental correlation of the 4 rounds at the bottom is under sample sizes and 100 random keys. According to piling-up lemma, the experimental correlation is .