Paper 2026/1848
A Quasidifferential Analysis of the Wrong-Key Randomization Hypothesis
Abstract
The Wrong-Key Randomization (WKR) hypothesis governs data-complexity estimates in differential cryptanalysis: wrong-key guesses are assumed to behave as a random permutation would. Exact computation of fixed-key differential probabilities was, until recently, infeasible. We use quasidifferential trails to compute the exact wrong-key distribution for the key-recovery map \(G_{k,k'} = F_{k'}^{-1}\!\circ F_k\) in PRESENT-like SPNs. A mask-first reformulation exposes a Walsh--Hadamard structure; restricting the transform to the low-dimensional support, together with SMT-guided trail enumeration, reduces the cost: for a 16-bit toy cipher, from~\(2^{80}\) to~\(2^{13}\); for \presentCipher, from~\(2^{192}\) to~\(2^{30}\); and for GIFT, from~\(2^{192}\) to~\(2^{32}\). For the toy cipher, PRESENT and GIFT, the computed distribution is a structured mixture: a large zero-probability class coexists with bottleneck classes orders of magnitude above the random-permutation mean, and nothing lies between them. Such a distribution is not unimodal, so no Poisson or binomial law fits it for any parameter and the hypothesis is formally false for all three targets. For PRESENT, however, we show that this deviation does not affect the security of Wang's 14-round differential attack. We cast the computed distribution as a structured composite hypothesis---the differential counterpart of the random-permutation/composite-hypothesis model used for wrong keys in linear cryptanalysis--and show that the shape of the wrong-key distribution, not merely its mean, governs how many wrong keys survive the key-recovery filter. For PRESENT with Wang's distinguisher, the structural signal is carried only by the right pairs, whose weight is too small for the deviation to surface; the hypothesis remains a safe heuristic in this case despite being formally false. Our SMT-based enumeration tool is publicly available.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published by the IACR in TOSC 2026
- DOI
- 10.46586/tosc.a39qdk-ib02a
- Keywords
- Differential cryptanalysisWrong-Key RandomizationQuasidifferential Trails
- Contact author(s)
-
tim beyne @ esat kuleuven be
gregor leander @ rub de
mariia mutkovina @ rub de
ricardo rodriguezreveco @ rub de - History
- 2026-09-03: approved
- 2026-08-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1848
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1848,
author = {Tim Beyne and Gregor Leander and Mariia Mutkovina and Ricardo Rodriguez Reveco},
title = {A Quasidifferential Analysis of the Wrong-Key Randomization Hypothesis},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1848},
year = {2026},
doi = {10.46586/tosc.a39qdk-ib02a},
url = {https://eprint.iacr.org/2026/1848}
}