MILP-Based Differential Attack on Round-Reduced GIFT

Baoyu Zhu,Xiaoyang Dong,Hongbo Yu
DOI: https://doi.org/10.1007/978-3-030-12612-4_19
2019-01-01
Abstract:At Asiacrypt 2014, Sun et al. proposed a MILP model [20] to search for differential characteristics of bit-oriented block ciphers. In this paper, we improve this model to search for differential characteristics of GIFT [2], a new lightweight block cipher proposed at CHES 2017. GIFT has two versions, namely GIFT-64 and GIFT-128. For GIFT-64, we find the best 12-round differential characteristic and a number of iterative 4-round differential characteristics with our MILP-based model. We give a key-recovery attack on 19-round GIFT-64. For GIFT-128, we find a 18-round differential characteristic and give the first attack on 23-round GIFT-128.
What problem does this paper attempt to address?