Revisiting Truncated Differential Attack from the Perspective of Equivalent Propagation Equations
摘要
Truncated differential attacks have been proven to be a powerful tool in the security analysis of block ciphers, but evaluating the exact distinguishing properties of truncated differentials for specific ciphers is still a challenging task. This paper revisits the truncated differential attack by introducing a new theoretical framework, that allows to calculate the probability of a truncated differential based on a system of equations, called Equivalent Propagation Equations (EPEs). By identifying special types of EPEs, the probability for specific S-boxes can be estimated intuitively and quickly while taking into account the dependence across two S-box layers. Furthermore, a grouping-and-sampling strategy is presented to address the impact of dependencies. Moreover, an automated model is developed to search for truncated differentials with EPEs. We apply the proposed framework to TWINE and LBlock, and search for novel truncated differentials to launch key recovery attacks. When evaluating the obtained distinguishers with our strategy, we conclude that it narrows the gap between the exact and estimated probabilities. Moreover, we perform key recovery attacks on 24 rounds of LBlock and 26 rounds of TWINE-128, both extending the previous best truncated differential attacks by three rounds.