Paper 2026/1825

Enhanced Differential-linear Cryptanalysis of Forr\'{o} with MILP

Zhengting Li, Information Engineering University, Zhengzhou, China, 450001
Lin Ding, Information Engineering University, Zhengzhou, China, 450001
Xinhai Wang, Information Engineering University, Zhengzhou, China, 450001
Honglei Wang, Information Engineering University, Zhengzhou, China, 450001
Jiang Wan, Information Engineering University, Zhengzhou, China, 450001
Fan Zhang, Zhejiang University, Hangzhou, China, 310058
Abstract

ARX-based design is a major building block of modern cryptographic ciphers due to its efficiency in software. Forr\'{o} is an ARX-based stream cipher proposed by Coutinho et al. at ASIACRYPT 2022, which was designed to provide higher security margin than the ChaCha stream cipher. In this paper, we propose a full automated MILP model called \textit{MinForr\'{o}}, to derive linear approximations for the Forr\'{o} stream cipher. For the differential part, a two-stage strategy to search for single-bit differential trails with high differential correlations is presented, which helps us to find the first-ever 3-round differential trails for Forr\'{o}. By combining the linear approximations obtained by \textit{MinForr\'{o}} and 3-round differential trail for Forr\'{o}, we propose improved differential-linear distinguishers for 4-, 5-, 5.25-, 5.5-, 5.75-, 6-, 6.25- and 6.5-round Forr\'{o} with complexities ${2^{32.44}}$, ${2^{46}}$, ${2^{50}}$, ${2^{64.32}}$, ${2^{87.12}}$, ${2^{117.92}}$, ${2^{174.92}}$ and ${2^{226.88}}$, respectively. The proposed differential-linear distinguishers for 4-, 5-, 5.25- and 5.5-round Forr\'{o} significantly improve the existing distinguishers by factors of ${2^{4.11}}$, ${2^{83.68}}$, ${2^{127.64}}$ and ${2^{178.20}}$, respectively. To the best of our knowledge, this is the first differential-linear distinguisher for Forr\'{o} that reaches 6.5 rounds, which is a significant advancement over the existing record of 5.5 rounds. We have implemented the differential-linear distinguishers for 4- and 5-round Forr\'{o} on a common PC, and the experimental results confirm the correctness of these distinguishers. Furthermore, when combined with the \textit{Probabilistic Neutral Bits} (PNB) technique, we obtain key recovery attacks on 5.5-, 6-, 6.5- and 6.75-round Forr\'{o} with time complexities ${2^{149.20}}$, ${2^{151.84}}$, ${2^{213.49}}$ and ${2^{251.97}}$, respectively. The proposed key recovery attack on 5.5-round Forr\'{o} significantly improves the time complexity of the existing attack by a factor of ${2^{75.84}}$. To the best of our knowledge, this is the first key recovery attack on Forr\'{o} that reaches 6.75 rounds, which is a significant advancement over the existing record of 5.5 rounds.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. IEEE Transactions on Information Theory
DOI
10.1109/TIT.2026.3695599
Keywords
Differential-linear cryptanalysisMILPProbabilistic Neutral BitsForroStream cipher
Contact author(s)
dinglin_cipher @ 163 com
History
2026-08-30: approved
2026-08-28: received
See all versions
Short URL
https://ia.cr/2026/1825
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1825,
      author = {Zhengting Li and Lin Ding and Xinhai Wang and Honglei Wang and Jiang Wan and Fan Zhang},
      title = {Enhanced Differential-linear Cryptanalysis of Forr\'{o} with {MILP}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1825},
      year = {2026},
      doi = {10.1109/TIT.2026.3695599},
      url = {https://eprint.iacr.org/2026/1825}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.