On additive differential probabilities of the composition of bitwise exclusive-or and a bit rotation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kolomeec, Nikolay, Sutormin, Ivan, Bykov, Denis, Panferov, Matvey, Bonich, Tatyana
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910369523433472
author Kolomeec, Nikolay
Sutormin, Ivan
Bykov, Denis
Panferov, Matvey
Bonich, Tatyana
author_facet Kolomeec, Nikolay
Sutormin, Ivan
Bykov, Denis
Panferov, Matvey
Bonich, Tatyana
contents Properties of the additive differential probability $\mathrm{adp}^{\mathrm{XR}}$ of the composition of bitwise XOR and a bit rotation are investigated, where the differences are expressed using addition modulo $2^n$. This composition is widely used in ARX constructions consisting of additions modulo $2^n$, bit rotations and bitwise XORs. Differential cryptanalysis of such primitives may involve maximums of $\mathrm{adp}^{\mathrm{XR}}$, where some of its input or output differences are fixed. Although there is an efficient way to calculate this probability (Velichkov et al, 2011), many of its properties are still unknown. In this work, we find maximums of $\mathrm{adp}^{\mathrm{XR}}$, where the rotation is one bit left/right and one of its input differences is fixed. Some symmetries of $\mathrm{adp}^{\mathrm{XR}}$ are obtained as well. We provide all its impossible differentials in terms of regular expression patterns and estimate the number of them. This number turns out to be maximal for the one bit left rotation and noticeably less than the number of impossible differentials of bitwise XOR.
format Preprint
id arxiv_https___arxiv_org_abs_2303_04097
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle On additive differential probabilities of the composition of bitwise exclusive-or and a bit rotation
Kolomeec, Nikolay
Sutormin, Ivan
Bykov, Denis
Panferov, Matvey
Bonich, Tatyana
Cryptography and Security
94A60
G.2.3
Properties of the additive differential probability $\mathrm{adp}^{\mathrm{XR}}$ of the composition of bitwise XOR and a bit rotation are investigated, where the differences are expressed using addition modulo $2^n$. This composition is widely used in ARX constructions consisting of additions modulo $2^n$, bit rotations and bitwise XORs. Differential cryptanalysis of such primitives may involve maximums of $\mathrm{adp}^{\mathrm{XR}}$, where some of its input or output differences are fixed. Although there is an efficient way to calculate this probability (Velichkov et al, 2011), many of its properties are still unknown. In this work, we find maximums of $\mathrm{adp}^{\mathrm{XR}}$, where the rotation is one bit left/right and one of its input differences is fixed. Some symmetries of $\mathrm{adp}^{\mathrm{XR}}$ are obtained as well. We provide all its impossible differentials in terms of regular expression patterns and estimate the number of them. This number turns out to be maximal for the one bit left rotation and noticeably less than the number of impossible differentials of bitwise XOR.
title On additive differential probabilities of the composition of bitwise exclusive-or and a bit rotation
topic Cryptography and Security
94A60
G.2.3
url https://arxiv.org/abs/2303.04097