Paper 2026/1848

A Quasidifferential Analysis of the Wrong-Key Randomization Hypothesis

Tim Beyne, KU Leuven
Gregor Leander, Ruhr University Bochum
Mariia Mutkovina, Ruhr University Bochum
Ricardo Rodriguez Reveco, Ruhr University Bochum
Abstract

The Wrong-Key Randomization (WKR) hypothesis governs data-complexity estimates in differential cryptanalysis: wrong-key guesses are assumed to behave as a random permutation would. Exact computation of fixed-key differential probabilities was, until recently, infeasible. We use quasidifferential trails to compute the exact wrong-key distribution for the key-recovery map \(G_{k,k'} = F_{k'}^{-1}\!\circ F_k\) in PRESENT-like SPNs. A mask-first reformulation exposes a Walsh--Hadamard structure; restricting the transform to the low-dimensional support, together with SMT-guided trail enumeration, reduces the cost: for a 16-bit toy cipher, from~\(2^{80}\) to~\(2^{13}\); for \presentCipher, from~\(2^{192}\) to~\(2^{30}\); and for GIFT, from~\(2^{192}\) to~\(2^{32}\). For the toy cipher, PRESENT and GIFT, the computed distribution is a structured mixture: a large zero-probability class coexists with bottleneck classes orders of magnitude above the random-permutation mean, and nothing lies between them. Such a distribution is not unimodal, so no Poisson or binomial law fits it for any parameter and the hypothesis is formally false for all three targets. For PRESENT, however, we show that this deviation does not affect the security of Wang's 14-round differential attack. We cast the computed distribution as a structured composite hypothesis---the differential counterpart of the random-permutation/composite-hypothesis model used for wrong keys in linear cryptanalysis--and show that the shape of the wrong-key distribution, not merely its mean, governs how many wrong keys survive the key-recovery filter. For PRESENT with Wang's distinguisher, the structural signal is carried only by the right pairs, whose weight is too small for the deviation to surface; the hypothesis remains a safe heuristic in this case despite being formally false. Our SMT-based enumeration tool is publicly available.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in TOSC 2026
DOI
10.46586/tosc.a39qdk-ib02a
Keywords
Differential cryptanalysisWrong-Key RandomizationQuasidifferential Trails
Contact author(s)
tim beyne @ esat kuleuven be
gregor leander @ rub de
mariia mutkovina @ rub de
ricardo rodriguezreveco @ rub de
History
2026-09-03: approved
2026-08-31: received
See all versions
Short URL
https://ia.cr/2026/1848
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1848,
      author = {Tim Beyne and Gregor Leander and Mariia Mutkovina and Ricardo Rodriguez Reveco},
      title = {A Quasidifferential Analysis of the Wrong-Key Randomization Hypothesis},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1848},
      year = {2026},
      doi = {10.46586/tosc.a39qdk-ib02a},
      url = {https://eprint.iacr.org/2026/1848}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.