{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T20:24:40Z","timestamp":1770236680789,"version":"3.49.0"},"reference-count":32,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2023,1,10]],"date-time":"2023-01-10T00:00:00Z","timestamp":1673308800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61379138"],"award-info":[{"award-number":["61379138"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,1,17]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>In recent years, Mixed-Integer Linear Programming (MILP)-based automatic tools have played a significant role in providing security evaluations of symmetric-key primitives. Differential and linear cryptanalysis are the two most important cryptographic techniques. Although some methods have conducted a great effort in exploiting MILP-aided tools in searching for differential (linear) characteristics, traditional methods still suffer from primitives with strong diffusion layers and large sizes, such as NOEKEON. Typically, searching for differential (linear) characteristics of such primitives is difficult, and the corresponding MILP models are too heavy to be solved efficiently. To this end, we propose a simple yet efficient approach to employ MILP to evaluate the security against differential and linear cryptanalysis of such primitives. The core of our approach is to reduce the complex problem to a set of simpler subproblems and obtain the optimal solution of the complex problem by combining all the subproblems. A subproblem is equivalent to searching for all differential (linear) characteristics with a fixed number of active S-boxes in each round. Furthermore, we design an elaborate algorithm consisting of three MILP-aided methods to solve various subproblems and adopt some techniques to improve efficiency further. Applying our new algorithm to three SPN primitives Serpent, NOEKEON and ASCON, we obtain the tightest security bounds against differential and linear cryptanalysis for all three primitives so far and find improved differential and linear characteristics for Serpent and NOEKEON. For Serpent, we improve the upper bound of the maximum probability of 7-round differential characteristics from $2^{-71}$ to $2^{-76}$ and find for the first time 7-round differential characteristics. For NOEKEON, our results show that there is no 9-round (10-round) differential (linear) characteristic with a probability (correlation) higher than $2^{-128}$ ($2^{-64}$), whereas it needs 10 rounds (11 rounds) according to the previous results. In addition, we find an 8-round (9-round) differential (linear) characteristic with a probability (correlation) of $2^{-127}$ ($2^{-60}$). For ASCON permutation, we provide for the first time an upper bound of the maximum probability (correlation) of 5-round differential (linear) characteristics as $2^{-70}$ ($2^{-33}$).<\/jats:p>","DOI":"10.1093\/comjnl\/bxac173","type":"journal-article","created":{"date-parts":[[2023,1,10]],"date-time":"2023-01-10T09:16:23Z","timestamp":1673342183000},"page":"274-291","source":"Crossref","is-referenced-by-count":2,"title":["A New Approach of Evaluating the Security Against Differential and Linear Cryptanalysis and Its Applications to Serpent, NOEKEON and ASCON"],"prefix":"10.1093","volume":"67","author":[{"given":"Chunning","family":"Zhou","sequence":"first","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences , Beijing 100085 , China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences , Beijing 100049 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wentao","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences , Beijing 100085 , China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences , Beijing 100049 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiwei","family":"Cao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences , Beijing 100085 , China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences , Beijing 100049 , China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2023,1,10]]},"reference":[{"key":"2024012011462630400_ref1","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/BF00630563","article-title":"Differential cryptanalysis of DES-like cryptosystems","volume":"4","author":"Biham","year":"1991","journal-title":"J. Cryptol."},{"key":"2024012011462630400_ref2","first-page":"386","volume-title":"Advances in Cryptology - EUROCRYPT \u201893, Workshop on the Theory and Application of Cryptographic Techniques, Lofthus, Norway, May 23\u201327, 1993, Proc.","author":"Matsui","year":"1993"},{"key":"2024012011462630400_ref4","first-page":"57","volume-title":"Information Security and Cryptology - 7th International Conference, Inscrypt 2011, Beijing, China, November 30\u2013December 3, 2011. Revised Selected Papers","author":"Mouha","year":"2011"},{"key":"2024012011462630400_ref5","first-page":"39","volume-title":"Information Security and Cryptology - 9th International Conference, Inscrypt 2013, Guangzhou, China, November 27\u201330, 2013, Revised Selected Papers","author":"Sun","year":"2013"},{"key":"2024012011462630400_ref6","first-page":"158","volume-title":"Advances in Cryptology - ASIACRYPT 2014 - 20th International Conference on the Theory and Application of Cryptology and Information Security, Kaoshiung, Taiwan, R.O.C., December 7\u201311, 2014. Proc., Part I","author":"Sun","year":"2014"},{"key":"2024012011462630400_ref7","article-title":"Towards finding the best characteristics of some bit-oriented block ciphers and automatic enumeration of (related-key) differential and linear characteristics with predefined properties","author":"Sun","year":"2014","journal-title":"Cryptol. ePrint Arch."},{"key":"2024012011462630400_ref8","first-page":"101","volume-title":"Information Security - 21st International Conference, ISC 2018, Guildford, UK, September 9\u201312, 2018, Proc.","author":"Zhang","year":"2018"},{"key":"2024012011462630400_ref9","first-page":"366","volume-title":"Advances in Cryptology - EUROCRYPT \u201894, Workshop on the Theory and Application of Cryptographic Techniques, Perugia, Italy, May 9\u201312, 1994, Proc.","author":"Matsui","year":"1994"},{"key":"2024012011462630400_ref10","doi-asserted-by":"crossref","first-page":"450","DOI":"10.1007\/978-3-540-74735-2_31","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2007, 9th International Workshop, Vienna, Austria, September 10\u201313, 2007, Proc.","author":"Bogdanov","year":"2007"},{"key":"2024012011462630400_ref11","first-page":"404","article-title":"The SIMON and SPECK families of lightweight block ciphers","volume":"2013","author":"Beaulieu","year":"2013","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"2024012011462630400_ref12","first-page":"372","volume-title":"Topics in Cryptology - CT-RSA 2019 - The Cryptographers\u2019 Track at the RSA Conference 2019, San Francisco, CA, USA, March 4\u20138, 2019, Proc.","author":"Zhu","year":"2019"},{"key":"2024012011462630400_ref13","first-page":"321","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2017 - 19th International Conference, Taipei, Taiwan, September 25\u201328, 2017, Proc.","author":"Banik","year":"2017"},{"key":"2024012011462630400_ref14","first-page":"49","article-title":"The relationship between the construction and solution of the MILP models and applications","volume":"2019","author":"Li","year":"2019","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"2024012011462630400_ref15","first-page":"438","article-title":"Improving the milp-based security evaluation algorithm against differential\/linear cryptanalysis using A divide-and-conquer approach","volume":"2019","author":"Zhou","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2024012011462630400_ref16","first-page":"1","article-title":"RECTANGLE: a bit-slice lightweight block cipher suitable for multiple platforms","volume":"58","author":"Zhang","year":"2015","journal-title":"Sci. China Inform. Sci."},{"key":"2024012011462630400_ref17","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1007\/978-3-642-21554-4_19","volume-title":"Applied Cryptography and Network Security - 9th International Conference, ACNS 2011, Nerja, Spain, June 7\u201310, 2011. Proc.","author":"Wu","year":"2011"},{"key":"2024012011462630400_ref18","first-page":"339","volume-title":"Selected Areas in Cryptography, 19th International Conference, SAC 2012, Windsor, ON, Canada, August 15\u201316, 2012, Revised Selected Papers","author":"Suzaki","year":"2012"},{"key":"2024012011462630400_ref19","doi-asserted-by":"crossref","first-page":"327","DOI":"10.46586\/tosc.v2020.i3.327-361","article-title":"Efficient MILP modelings for sboxes and linear layers of SPN ciphers","volume":"2020","author":"Boura","year":"2020","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2024012011462630400_ref20","volume-title":"Information Security and Cryptography","author":"Daemen","year":"2002"},{"key":"2024012011462630400_ref21","doi-asserted-by":"crossref","first-page":"156","DOI":"10.46586\/tosc.v2021.i1.156-184","article-title":"Towards key-recovery-attack friendly distinguishers: application to GIFT-128","volume":"2021","author":"Zong","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2024012011462630400_ref22","doi-asserted-by":"crossref","first-page":"222","DOI":"10.1007\/3-540-69710-1_15","volume-title":"Fast Software Encryption, 5th International Workshop, FSE \u201898, Paris, France, March 23\u201325, 1998, Proc.","author":"Biham","year":"1998"},{"key":"2024012011462630400_ref23","article-title":"Nessie Proposal: NOEKEON","author":"Daemen","year":"2000"},{"key":"2024012011462630400_ref24","article-title":"Ascon v1.2. submission to round 1 of the NIST lightweight cryptography project","author":"Dobraunig","year":"2019"},{"key":"2024012011462630400_ref25","first-page":"371","volume-title":"Topics in Cryptology - CT-RSA 2015, The Cryptographer\u2019s Track at the RSA Conference 2015, San Francisco, CA, USA, April 20\u201324, 2015. Proc.","author":"Dobraunig","year":"2015"},{"key":"2024012011462630400_ref26","first-page":"259","volume-title":"Information Security and Cryptology - 10th International Conference, Inscrypt 2014, Beijing, China, December 13-15, 2014, Revised Selected Papers","author":"Bao","year":"2014"},{"key":"2024012011462630400_ref27","first-page":"340","volume-title":"Advances in Cryptology - EUROCRYPT 2001, International Conference on the Theory and Application of Cryptographic Techniques, Innsbruck, Austria, May 6\u201310, 2001, Proc.","author":"Biham","year":"2001"},{"key":"2024012011462630400_ref29","first-page":"157","volume-title":"Advances in Cryptology - CRYPTO \u201895, 15th Annual International Cryptology Conference, Santa Barbara, California, USA, August 27\u201331, 1995, Proc.","author":"Ohta","year":"1995"},{"key":"2024012011462630400_ref30","first-page":"41","volume-title":"Fast Software Encryption, 4th International Workshop, FSE \u201897, Haifa, Israel, January 20\u201322, 1997, Proc.","author":"Aoki","year":"1997"},{"key":"2024012011462630400_ref31","first-page":"195","volume-title":"The Third Advanced Encryption Standard Candidate Conference, April 13\u201314, 2000, New York, NY, USA","author":"Kohno","year":"2000"},{"key":"2024012011462630400_ref32","first-page":"490","volume-title":"Advances in Cryptology - ASIACRYPT 2015 - 21st International Conference on the Theory and Application of Cryptology and Information Security, Auckland, New Zealand, November 29 - December 3, 2015, Proc., Part II","author":"Dobraunig","year":"2015"},{"key":"2024012011462630400_ref33","doi-asserted-by":"crossref","first-page":"102","DOI":"10.46586\/tosc.v2021.i3.102-136","article-title":"Exploring differential-based distinguishers and forgeries for ASCON","volume":"2021","author":"G\u00e9rault","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2024012011462630400_ref34","doi-asserted-by":"crossref","first-page":"546","DOI":"10.1007\/s11432-010-0048-2","article-title":"Differential-algebraic cryptanalysis of reduced-round of serpent-256","volume":"53","author":"Wang","year":"2010","journal-title":"Sci. China Inf. Sci."}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/1\/274\/56167714\/bxac173.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/1\/274\/56167714\/bxac173.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,20]],"date-time":"2024-01-20T11:46:50Z","timestamp":1705751210000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/67\/1\/274\/6862009"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,10]]},"references-count":32,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,1,10]]},"published-print":{"date-parts":[[2024,1,17]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxac173","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2024,1]]},"published":{"date-parts":[[2023,1,10]]}}}