Research Article

Multiple Impossible Differential Attacks for ForkAES

Table 2

Six 5-round truncated impossible differential distinguishers of ForkAES.

TypeNumberZero input differenceNonzero middle state differenceNonzero tweak and output difference

First1(3, 6, 9, 12)(0, 5, 10, 15)(0)
2(2, 5, 8, 15)
3(1, 4, 11, 14)

Second4(3, 6, 9, 12)(3, 4, 9, 14)(4)
5(2, 5, 8, 15)
6(0, 5, 10, 15)

Note: the input difference propagates to the internal state with probability 0 and the output difference propagates to the internal state with probability 1.