<p>Properties of the additive differential probability <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq1.gif" Format="GIF" Height="21" Rendition="HTML" Resolution="72" Type="Linedraw" Width="45" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textrm{adp}^{\textrm{XR}}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>adp</mtext> <mtext>XR</mtext> </msup> </math></EquationSource> </InlineEquation> of the composition of bitwise XOR and a bit rotation are investigated, where the differences are expressed using addition modulo <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="18" /> </InlineMediaObject> <EquationSource Format="TEX">\(2^n\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mi>n</mi> </msup> </math></EquationSource> </InlineEquation>. This composition is widely used in ARX constructions consisting of additions modulo <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq3.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="18" /> </InlineMediaObject> <EquationSource Format="TEX">\(2^n\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mi>n</mi> </msup> </math></EquationSource> </InlineEquation>, bit rotations and bitwise XORs. Differential cryptanalysis of such primitives may involve maximums of <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq4.gif" Format="GIF" Height="21" Rendition="HTML" Resolution="72" Type="Linedraw" Width="45" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textrm{adp}^{\textrm{XR}}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>adp</mtext> <mtext>XR</mtext> </msup> </math></EquationSource> </InlineEquation>, where some of its input or output differences are fixed. Although there is an efficient way to calculate this probability (Velichkov et al, 2011), many of its properties are still unknown. In this work, we find maximums of <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq5.gif" Format="GIF" Height="21" Rendition="HTML" Resolution="72" Type="Linedraw" Width="45" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textrm{adp}^{\textrm{XR}}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>adp</mtext> <mtext>XR</mtext> </msup> </math></EquationSource> </InlineEquation>, where the rotation is one bit left/right and one of its input differences is fixed. Some symmetries of <InlineEquation ID="IEq6"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_773_Article_IEq6.gif" Format="GIF" Height="21" Rendition="HTML" Resolution="72" Type="Linedraw" Width="45" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textrm{adp}^{\textrm{XR}}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mtext>adp</mtext> <mtext>XR</mtext> </msup> </math></EquationSource> </InlineEquation> are obtained as well. We provide all its impossible differentials in terms of regular expression patterns and estimate the number of them. This number turns out to be maximal for the one bit left rotation and noticeably less than the number of impossible differentials of bitwise XOR.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On additive differential probabilities of the composition of bitwise exclusive-or and a bit rotation

  • Nikolay Kolomeec,
  • Ivan Sutormin,
  • Denis Bykov,
  • Matvey Panferov,
  • Tatyana Bonich

摘要

Properties of the additive differential probability \(\textrm{adp}^{\textrm{XR}}\) adp XR of the composition of bitwise XOR and a bit rotation are investigated, where the differences are expressed using addition modulo \(2^n\) 2 n . This composition is widely used in ARX constructions consisting of additions modulo \(2^n\) 2 n , bit rotations and bitwise XORs. Differential cryptanalysis of such primitives may involve maximums of \(\textrm{adp}^{\textrm{XR}}\) adp XR , where some of its input or output differences are fixed. Although there is an efficient way to calculate this probability (Velichkov et al, 2011), many of its properties are still unknown. In this work, we find maximums of \(\textrm{adp}^{\textrm{XR}}\) adp XR , where the rotation is one bit left/right and one of its input differences is fixed. Some symmetries of \(\textrm{adp}^{\textrm{XR}}\) adp XR are obtained as well. We provide all its impossible differentials in terms of regular expression patterns and estimate the number of them. This number turns out to be maximal for the one bit left rotation and noticeably less than the number of impossible differentials of bitwise XOR.