Paper 2025/1925
Improved Modeling for Substitution Boxes with Negative Samples and Beyond (Extended Version)
Abstract
It is a common practice for symmetric-key ciphers is to encode a cryptanalysis problem as an instance of the Mixed Integer Linear Programming (MILP) and then run the instance with an efficient solver. For this purpose, it is essential to model the components in a way that is compatible with the MILP formulation while preserving the characteristics of the cipher. In this work, we look at the problem of efficiently encoding a substitution box (SBox for short). More specifically, we take the evaluation tables, namely, the Difference Distribution Table (DDT), the Linear Approximation Table (LAT), the Division Property Table (DPT) and the Boomerang Connectivity Table (BCT). In the current stage, the only model proposed/used in the literature is to look for the positive samples (i.e., non-zero) entries in the evaluation table and encode for that (this ultimately leads to the minimum number of active SBoxes for the target cipher). In our first contribution, we experiment with the complementary concept of using the negative samples (i.e., treating the zero entries as non-zero entries and vice versa), finally a proper recovery procedure is performed to get back to the original problem. In our second contribution, we observe that the top row and column of each table (which are always taken into consideration by the past researchers) are actually redundant, as those are inherently taken care of through additional constraints at another level. We thus propose a simplified model that removes those row and column. We show the efficacy of our proposals by furnishing results on the evaluation tables on multiple SBoxes. Our proposals often reduce the number of constraints for certain SBox evaluation tables (depending on the properties of the table) from the state-of-the-art results.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published elsewhere. Minor revision. Indocrypt 2025
- Keywords
- Block CipherSBoxSBox Evaluation TableZero EncodingLinear ConstraintsMILP
- Contact author(s)
-
debranjan crl @ gmail com
anubhab baksi @ eit lth se
surajit1810 @ gmail com
sarkar santanu bir1 @ gmail com - History
- 2025-10-23: last of 4 revisions
- 2025-10-15: received
- See all versions
- Short URL
- https://ia.cr/2025/1925
- License
-
CC BY-NC-SA
BibTeX
@misc{cryptoeprint:2025/1925,
author = {Debranjan Pal and Anubhab Baksi and Surajit Mandal and Santanu Sarkar},
title = {Improved Modeling for Substitution Boxes with Negative Samples and Beyond (Extended Version)},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1925},
year = {2025},
url = {https://eprint.iacr.org/2025/1925}
}