Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability
Prikladnaâ diskretnaâ matematika, no. 4 (2022), pp. 40-56.

Voir la notice de l'article provenant de la source Math-Net.Ru

In this paper, we describe a “differential meet-in-the-middle” method for obtaining differences for $64$-bit ARX permutation Alzette with maximum or close to maximum differential characteristic probability (DCP). The method is based on testing the high-probability differences in the middle rounds of Alzette and extending them to the previous and following rounds. Using this method, we obtain $7$ differences for $4$-rounds Alzette with DCP $2^{-6}$, $1$ difference for $5$-rounds Alzette with DCP $2^{-10}$, and $1$ difference for $6$-rounds Alzette with DCP $2^{-18}$. Same differences for $4$ and $5$ rounds were obtained by the developers of Alzette as the differences with maximum DCP, but our method has lower complexity: taking the calculation of probability for a round difference as a single operation, it's $36$ operations ($4$ rounds), $135$ operations ($5$ rounds) and $486$ operations ($6$ rounds) for our method and more than $1.29\cdot 10^8$ operations ($4$ rounds), $2\cdot 1.29\cdot 10^8$ operations ($5$ rounds) and $1.03\cdot 10^{14}$ operations ($6$ rounds) for Alzette developers’ method. Also, we obtain $6$ differences for $7$-rounds Alzette with DCP $2^{-27}$ and $11$ differences for $8$-rounds Alzette with DCP $2^{-35}$ with complexity $\le 5\cdot 10^{13}$ operations for both cases. For these number of rounds by the developers of Alzette were obtained only the higher bounds for maximum DCP: $2^{-24}$ ($7$ rounds) and $2^{-32}$ ($8$ rounds). Our estimations of Alzette developers’ method complexity is $\ge2.97\cdot 10^{16}$ operations for $7$-rounds Alzette and $\ge2.97\cdot 10^{16} + 4.75\cdot 10^{12}$ operations for $8$-rounds Alzette.
Mots-clés : permutation, Alzette
Keywords: differential characteristic, differential method.
@article{PDM_2022_4_a4,
     author = {A. A. Dmukh and D. O. Pasko},
     title = {Search for differences for {Alzette} {S-Box} with maximum or close to maximum differential characteristic probability},
     journal = {Prikladna\^a diskretna\^a matematika},
     pages = {40--56},
     publisher = {mathdoc},
     number = {4},
     year = {2022},
     language = {ru},
     url = {http://geodesic.mathdoc.fr/item/PDM_2022_4_a4/}
}
TY  - JOUR
AU  - A. A. Dmukh
AU  - D. O. Pasko
TI  - Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability
JO  - Prikladnaâ diskretnaâ matematika
PY  - 2022
SP  - 40
EP  - 56
IS  - 4
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/PDM_2022_4_a4/
LA  - ru
ID  - PDM_2022_4_a4
ER  - 
%0 Journal Article
%A A. A. Dmukh
%A D. O. Pasko
%T Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability
%J Prikladnaâ diskretnaâ matematika
%D 2022
%P 40-56
%N 4
%I mathdoc
%U http://geodesic.mathdoc.fr/item/PDM_2022_4_a4/
%G ru
%F PDM_2022_4_a4
A. A. Dmukh; D. O. Pasko. Search for differences for Alzette S-Box with maximum or close to maximum differential characteristic probability. Prikladnaâ diskretnaâ matematika, no. 4 (2022), pp. 40-56. http://geodesic.mathdoc.fr/item/PDM_2022_4_a4/

[1] Beierle C., Biryukov A., Cardoso dos Santos L., et al., Alzette: A 64-bit ARX-box, Cryptology Archive. Report 2019/1378, , 2019 https://eprint.iacr.org/2019/1378

[2] Canteaut A., Duval S., Leurent G., et al., Saturnin: a suite of lightweight symmetric algorithms for post-quantum security https://csrc.nist.gov/CSRC/media/Projects/lightweight-cryptography/documents/round-2/spec-doc-rnd2/saturnin-spec-round2.pdf

[3] Dinu D., Perrin L., Udovenko A., et al., “Design strategies for ARX with provable bounds: Sparx and LAX”, LNCS, 10031, 2016, 484–513 | MR

[4] Biryukov A., Velichkov V., and Corre Y. L., “Automatic search for the best trails in ARX: Application to block cipher Speck”, LNCS, 9783, 2016, 289–310 | MR

[5] Malyshev F. M., “Probabilistic characteristics of differential and linear relations for nonhomogeneous linear medium”, Matematicheskie Voprosy Kriptografii, 10:1 (2019), 41–72 (in Russian) | MR

[6] Wallèn J., On the differential and linear properties of addition, Research Report A84, Helsinki University of Technology, Laboratory for Theoretical Computer Science, Espoo, Finland, 2003, 58 pp.

[7] Malyshev F. M. and Trifonov D. I., “Diffusion properties of XSLP-ciphers”, Matematicheskie Voprosy Kriptografii, 7:3 (2016), 47–60 (in Russian) | MR

[8] https://github.com/cryptolu/sparkle