论文部分内容阅读
Dear editor,rnImpossible differential cryptanalysis and zero-correlation linear cryptanalysis are two powerful methods in the block cipher field.Herein,we present an automatic tool to find impossible differentials(IDs)and zero-correlation linear ap-proximations(ZCLAs)for both ARX and S-box-based ci-phers.Similar to the idea of using mixed-integer linear programming(MILP)models for differential cryptanalysis in[1],we first use linear inequalities to describe all the tar-get cipher's components exactly.However,we are indiffer-ent to the objective function and only interested in knowing whether a solution to the whole system of inequalities for given input and output differences(masks)is present.If not,these input and output differences can yield an ID(ZCLA),as expected.Herein,we describe the search process in detail for IDs,but the process for finding ZCLAs is similar.