Paper 2020/632

Proposing an MILP-based Method for the Experimental Verification of Difference Trails

Sadegh Sadeghi, Vincent Rijmen, and Nasour Bagheri


Search for the right pairs of inputs in difference-based distinguishers is an important task for the experimental verification of the distinguishers in symmetric-key ciphers. In this paper, we develop an MILP-based approach to verify the possibility of difference-based distinguishers and extract the right pairs. We apply the proposed method to some presented difference-based trails (Related-Key Differentials (RKD), Rotational-XOR (RX)) of block ciphers \texttt{SIMECK}, and \texttt{SPECK}. As a result, we show that some of the reported RX-trails of \texttt{SIMECK} and \texttt{SPECK} are incompatible, i.e. there are no right pairs that follow the expected propagation of the differences for the trail. Also, for compatible trails, the proposed approach can efficiently speed up the search process of finding the exact value of a weak-key from the target weak-key space. For example, in one of the reported 14-round RX trails of \texttt{SPECK}, the probability of a key pair to be a weak-key is $2^{-94.91}$ when the whole key space is $2^{96}$; our method can find a key pair for it in a comparatively short time. It is worth noting that it was impossible to find this key pair using a traditional search. As another result, we apply the proposed method %and consider a search strategy for the framework of to \texttt{SPECK} block cipher, to construct longer related-key differential trails of \texttt{SPECK} which we could reach 15, 16, 17, and 19 rounds for \texttt{SPECK32/64}, \texttt{SPECK48/96}, \texttt{SPECK64/128}, and \texttt{SPECK128/256}, respectively. It should be compared with the best previous results which are 12, 15, 15, and 20 rounds, respectively, that both attacks work for a certain weak key class. It should be also considered as an improvement over the reported result of rotational XOR cryptanalysis on \texttt{SPECK}.

Available format(s)
Secret-key cryptography
Publication info
Preprint. MINOR revision.
Experimental verificationWeak-keysRelated-KeyMILPSPECKSIMECK
Contact author(s)
s sadeghi khu @ gmail com
na bagheri @ gmail com
vincent rijmen @ kuleuven be
2020-06-03: received
Short URL
Creative Commons Attribution


      author = {Sadegh Sadeghi and Vincent Rijmen and Nasour Bagheri},
      title = {Proposing an MILP-based Method for the  Experimental Verification of Difference Trails},
      howpublished = {Cryptology ePrint Archive, Paper 2020/632},
      year = {2020},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.