Catching the Fastest Boomerangs Application to SKINNY

Stéphanie Delaune, Patrick Derbez, and Mathieu Vavrille. Catching the Fastest Boomerangs Application to SKINNY. IACR Trans. Symmetric Cryptol., 2020(4):104–129, 2020.

Download

[PDF] 

Abstract

In this paper we describe a new tool to search for boomerang distinguishers. One limitation of the MILP model of Liu et al. is that it handles only one round for the middle part while Song et al. have shown that dependencies could affect much more rounds, for instance up to 6 rounds for SKINNY. Thus we describe a new approach to turn an MILP model to search for truncated characteristics into an MILP model to search for truncated boomerang characteristics automatically handling the middle rounds. We then show a new CP model to search for the best possible instantiations to identify good boomerang distinguishers. Finally we systematized the method initiated by Song et al. to precisely compute the probability of a boomerang.As a result, we found many new boomerang distinguishers up to 24 rounds in the TK3 model. In particular, we improved by a factor 2^30 the probability of the best known distinguisher against 18-round SKINNY-128/256.

BibTeX

@article{DDV22,
  author    = {St{\'{e}}phanie Delaune and
               Patrick Derbez and
               Mathieu Vavrille},
abstract = {In this paper we describe a new tool to search for boomerang distinguishers. One limitation of the MILP model of Liu et al. 
is that it handles only one round for the middle part while Song et al. have shown that dependencies could affect much more rounds, for instance up to 
6 rounds for SKINNY. Thus we describe a new approach to turn an MILP model to search for truncated characteristics into an MILP model to search 
for truncated boomerang characteristics automatically handling the middle rounds. We then show a new CP model to search for the best possible 
instantiations to identify good boomerang distinguishers. Finally we systematized the method initiated by Song et al. to precisely compute the probability of a boomerang.
As a result, we found many new boomerang distinguishers up to 24 rounds in the TK3 model. In particular, we improved by a factor 2^30 
the probability of the best known distinguisher against 18-round SKINNY-128/256.
},
  title     = {Catching the Fastest Boomerangs Application to {SKINNY}},
  journal   = {{IACR} Trans. Symmetric Cryptol.},
  volume    = {2020},
  number    = {4},
  pages     = {104--129},
  year      = {2020},
  timestamp = {Fri, 29 Jan 2021 16:47:01 +0100},
  lsv-category =  {jour},
  wwwpublic =     {public and ccsb},
}