IACR Transactions on Symmetric Cryptology 2017
DOI: 10.13154/tosc.v2017.i4.99-129
|View full text |Cite
|
Sign up to set email alerts
|

MILP Modeling for (Large) S-boxes to Optimize Probability of Differential Characteristics

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
5
1

Relationship

1
5

Authors

Journals

citations
Cited by 13 publications
(3 citation statements)
references
References 0 publications
0
3
0
Order By: Relevance
“…1 As S-boxes diffuse each active bit to multiple rows, each S D i should not have the common efficient trails. Criterion 2 For any (i, j) with i = j and any (α, β) ∈ {1, 2, 3, 6} × {1, 2, 3, 6} except for (2,6) and (6, 2),…”
Section: Choice Of the Subblockdiffusion Layermentioning
confidence: 99%
See 2 more Smart Citations
“…1 As S-boxes diffuse each active bit to multiple rows, each S D i should not have the common efficient trails. Criterion 2 For any (i, j) with i = j and any (α, β) ∈ {1, 2, 3, 6} × {1, 2, 3, 6} except for (2,6) and (6, 2),…”
Section: Choice Of the Subblockdiffusion Layermentioning
confidence: 99%
“…Differential and linear cryptanalyses. We estimated the minimum number of differentially and linearly active S-boxes by using MILP [2,39]. Both numbers of differentially and linearly active S-boxes are 16 in 3 rounds.…”
Section: Security Analysismentioning
confidence: 99%
See 1 more Smart Citation