Sciact
  • EN
  • RU

Maximums of the additive differential probability of exclusive-or Научная публикация

Журнал IACR Transactions on Symmetric Cryptology
, E-ISSN: 2519-173X
Вых. Данные Год: 2021, Том: 2021, Номер: 2, Страницы: 292-313 Страниц : 22 DOI: 10.46586/tosc.v2021.i2.292-313
Ключевые слова ARX; Differential cryptanalysis; Modular addition; XOR
Авторы Mouha N. 1 , Kolomeec N. 2 , Akhtiamov D. 3 , Sutormin I. 2 , Panferov M. 4 , Titova K. 4 , Bonich T. 4 , Ishchukova E. 5 , Tokareva N. 2 , Zhantulikov B. 4
Организации
1 Strativia, LargoMD, United States
2 Sobolev Institute of Mathematics, Novosibirsk, Russian Federation
3 The Hebrew University of Jerusalem, Jerusalem, Israel
4 Novosibirsk State University, Novosibirsk, Russian Federation
5 Southern Federal University, Taganrog, Russian Federation

Реферат: At FSE 2004, Lipmaa et al. studied the additive differential probability adp⊕ (α, β → γ) of exclusive-or where differences α, β, γ ∈ Fn2 are expressed using addition modulo 2n . This probability is used in the analysis of symmetric-key primitives that combine XOR and modular addition, such as the increas-ingly popular Addition-Rotation-XOR (ARX) constructions. The focus of this paper is on maximal differentials, which are helpful when constructing differential trails. We provide the missing proof for Theorem 3 of the FSE 2004 paper, which states that maxα,β adp⊕ (α, β → γ) = adp⊕ (0, γ → γ) for all γ. Furthermore, we prove that there always exist either two or eight distinct pairs α, β such that adp⊕ (α, β → γ) = adp⊕ (0, γ → γ), and we obtain recurrence formulas for calculating adp⊕ . To gain insight into the range of possible differential probabilities, we also study other properties such as the minimum value of adp⊕ (0, γ → γ), and we find all γ that satisfy this minimum value.
Библиографическая ссылка: Mouha N. , Kolomeec N. , Akhtiamov D. , Sutormin I. , Panferov M. , Titova K. , Bonich T. , Ishchukova E. , Tokareva N. , Zhantulikov B.
Maximums of the additive differential probability of exclusive-or
IACR Transactions on Symmetric Cryptology. 2021. V.2021. N2. P.292-313. DOI: 10.46586/tosc.v2021.i2.292-313 WOS Scopus OpenAlex
Идентификаторы БД:
Web of science: WOS:000661483500009
Scopus: 2-s2.0-85108784834
OpenAlex: W3167606741
Цитирование в БД:
БД Цитирований
Scopus 4
OpenAlex 3
Web of science 3
Альметрики: