Paper 2026/1402
On Extending Integral Distinguishers
Abstract
Integral cryptanalysis analyzes block ciphers using input structures for which the sum of a chosen function of the output bits becomes key-independent. However, most methods still test one output expression at a time, so they can miss distinguishers that emerge only when several outputs are combined, either linearly or nonlinearly. They are also not designed to capture key-dependent integral combinations, which may hold deterministically on part of the key space. In this work, we develop Split-and-Cancel, a method that combines exact expansion in a short final part with an oracle on the preceding rounds to determine which suffix monomials can survive from the chosen structure and records them in a binary matrix. Key-independent combinations are then extracted from the left kernel of this matrix. We first apply the method in a reduced model with omitted boundary key additions, where linear dependencies in this matrix yield certified key-independent sum combinations among output bits and higher-degree output products. When the omitted boundary key is restored, the same combinations yield deterministic weak-key distinguishers. We apply the method to SIMON, SIMECK, SPECK, PRESENT, and GIFT. Our strongest deterministic results improve the best integral distinguishers for SIMON, SIMECK, and SPECK by one round at every standard block size. For PRESENT and GIFT, we improve deterministic weak-key integral distinguishers by one round. In each case, the exact weak-key class covers at least a quarter of the key space: $2^{78}$ of $2^{80}$ keys for PRESENT-80, $2^{126}$ of $2^{128}$ keys for PRESENT-128, GIFT-64 and GIFT-128. These results show that exact modeling of a short final part can reveal key-independent and weak-key integral behavior missed by single-observable searches.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- Symmetric-key cryptanalysisBoolean functionsIntegral cryptanalysisLinear algebraSAT
- Contact author(s)
-
dachao wang @ eit lth se
hossein hadipour @ rub de
simon gerhalter @ tugraz at - History
- 2026-07-20: last of 2 revisions
- 2026-07-09: received
- See all versions
- Short URL
- https://ia.cr/2026/1402
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1402,
author = {Dachao Wang and Hosein Hadipour and Simon Gerhalter},
title = {On Extending Integral Distinguishers},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1402},
year = {2026},
url = {https://eprint.iacr.org/2026/1402}
}