RUS  ENG
Full version
JOURNALS // Diskretnyi Analiz i Issledovanie Operatsii // Archive

Diskretn. Anal. Issled. Oper., 2024 Volume 31, Issue 2, Pages 108–135 (Mi da1348)

Additive differentials for ARX mappings with probability exceeding $1/4$

A. S. Mokrousov, N. A. Kolomeec

Novosibirsk State University, 2 Pirogov Street, 630090 Novosibirsk, Russia

Abstract: We consider the additive differential probabilities of functions $x \oplus y$ and $(x \oplus y) \lll r,$ where $x, y \in \mathbb{Z}_2^n$ and $1 \leq r < n.$ The probabilities are used for the differential cryptanalysis of ARX ciphers that operate only with addition modulo $2^n,$ bitwise XOR ($\oplus$) and bit rotations ($\lll r$). A complete characterization of differentials whose probability exceeds $1/4$ is obtained. All possible values of their probabilities are $1/3 + 4^{2 - i} / 6$ for $i \in \{1, \dots, n\}.$ We describe differentials with each of these probabilities and calculate the number of these values. We also calculate the number of all considered differentials. It is $48n - 68$ for $x \oplus y$ and $24n - 30$ for $(x \oplus y) \lll r,$ where $n \geq 2.$ We compare differentials of both mappings under the given constraint. Tab. 6, bibliogr. 23.

Keywords: ARX scheme, differential probabilities, modulo addition, XOR, bit rotation.

UDC: 519.7

Received: 03.05.2023
Revised: 16.10.2023
Accepted: 22.12.2023

DOI: 10.33048/daio.2024.31.769


 English version:
Journal of Applied and Industrial Mathematics, 2024, 18:2, 294–311


© Steklov Math. Inst. of RAS, 2025