Paper 2026/1402

On Extending Integral Distinguishers

Dachao Wang, Lund University, Lund, Sweden
Hosein Hadipour, Ruhr University Bochum, Bochum, Germany
Simon Gerhalter, TU Graz, Graz, Austria
Abstract

Integral cryptanalysis analyzes block ciphers using input structures for which the sum of a chosen function of the output bits becomes key-independent. However, most methods still test one output expression at a time, so they can miss distinguishers that emerge only when several outputs are combined, either linearly or nonlinearly. They are also not designed to capture key-dependent integral combinations, which may hold deterministically on part of the key space. In this work, we develop Split-and-Cancel, a method that combines exact expansion in a short final part with an oracle on the preceding rounds to determine which suffix monomials can survive from the chosen structure and records them in a binary matrix. Key-independent combinations are then extracted from the left kernel of this matrix. We first apply the method in a reduced model with omitted boundary key additions, where linear dependencies in this matrix yield certified key-independent sum combinations among output bits and higher-degree output products. When the omitted boundary key is restored, the same combinations yield deterministic weak-key distinguishers. We apply the method to SIMON, SIMECK, SPECK, PRESENT, and GIFT. Our strongest deterministic results improve the best integral distinguishers for SIMON, SIMECK, and SPECK by one round at every standard block size. For PRESENT and GIFT, we improve deterministic weak-key integral distinguishers by one round. In each case, the exact weak-key class covers at least a quarter of the key space: $2^{78}$ of $2^{80}$ keys for PRESENT-80, $2^{126}$ of $2^{128}$ keys for PRESENT-128, GIFT-64 and GIFT-128. These results show that exact modeling of a short final part can reveal key-independent and weak-key integral behavior missed by single-observable searches.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Symmetric-key cryptanalysisBoolean functionsIntegral cryptanalysisLinear algebraSAT
Contact author(s)
dachao wang @ eit lth se
hossein hadipour @ rub de
simon gerhalter @ tugraz at
History
2026-07-20: last of 2 revisions
2026-07-09: received
See all versions
Short URL
https://ia.cr/2026/1402
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1402,
      author = {Dachao Wang and Hosein Hadipour and Simon Gerhalter},
      title = {On Extending Integral Distinguishers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1402},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1402}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.