Paper 2026/1162

Finer-Grained Fixed-Key Differential Probability Distributions via Quasidifferential Decoupling

Kai Hu, Shandong University
Thomas Peyrin, Nanyang Technological University
Quan Quan Tan, Centre Inria de Paris
Hongyi Zhang, Nanyang Technological University
Chunning Zhou, Nanyang Technological University
Abstract

The recent study of fixed-key differential probabilities mainly follows two complementary approaches. The first derives key-dependent constraints from the internal structure of the primitive. This approach is intuitive, but a complete theory is difficult to build. The second approach is based on quasidifferentials. It is complete in theory when all quasidifferentials are considered, but exhaustive enumeration is usually infeasible in practice. In this paper, we relate quasidifferentials to concrete key-dependent constraints. This gives new insights into quasidifferentials. Each quasidifferential with a nonzero mask carries one relation, equating a linear parity of the involved key bits to a generally nonlinear Boolean function of the intermediate-state bits, and the relations that share these bits together constrain the key. Under the common threshold-based treatment, where only quasidifferential trails with sufficiently large absolute correlation are kept, some constraints on intermediate-state bits may be lost. This can produce an incomplete quasidifferential trail set with respect to the induced intermediate-state constraints. This, for example, can result in the fixed-key differential probabilities computed by quasidifferential aggregation to become negative on some key subspaces. To obtain a more precise distribution of fixed-key differential probabilities over the key space, we decouple quasidifferential trails according to their induced constraints. After decoupling, each resulting quasidifferential trail set is locally complete, so the derived probability distribution for the particular subspace is always valid. The decoupling also reduces the number of trails in each set, improving the efficiency of the quasidifferential method. As a result, our method yields a finer-grained key-space partition that could allow us to better approximate the true distribution under the quasidifferential framework. We instantiate this decoupling strategy in the threshold-based setting and apply it to differential trails of GIFT-64, GIFT-128, SKINNY-64, SKINNY-128, and RECTANGLE. The resulting locally complete trail sets always give valid fixed-key differential probability distributions and are no coarser than direct threshold-based quasidifferential aggregation. They coincide with direct aggregation when the retained trails are already locally complete. In our experiments, using our decoupling method is actually better for many evaluated trails and refines the key-space restrictions reported by prior constraint-detection frameworks. As each quasidifferential is a constraint, the same insight also let us write the induced linear and nonlinear key constraints explicitly for the bit-wise ciphers GIFT-64, GIFT-128, and RECTANGLE, addressing a limitation of the Trail-Estimator constraint detector described in Peyrin, Tan, Zhang and Zhou at FSE, 2025.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
QuasidifferentialDifferential cryptanalysisConstraint detectionProbability estimation
Contact author(s)
kai hu @ sdu edu cn
thomas peyrin @ ntu edu sg
quan-quan tan @ inria fr
hongyi003 @ e ntu edu sg
chunning zhou @ ntu edu sg
History
2026-06-08: approved
2026-06-03: received
See all versions
Short URL
https://ia.cr/2026/1162
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1162,
      author = {Kai Hu and Thomas Peyrin and Quan Quan Tan and Hongyi Zhang and Chunning Zhou},
      title = {Finer-Grained Fixed-Key Differential Probability Distributions via Quasidifferential Decoupling},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1162},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1162}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.