MILP Based Differential Attack on Round Reduced WARP

Manoj Kumar,Tarun Yadav
DOI: https://doi.org/10.1007/978-3-030-95085-9_3
2022-01-01
Abstract:WARP is a 128-bit lightweight block cipher presented by S. Banik et al. at SAC 2020. It is based on 32-nibble type-2 Generalised Feistel Network (GFN) structure and uses a permutation over nibbles to optimize the security and efficiency. The designers provided a lower bound on the number of active S-boxes but they did not provide the differential characteristics against these bounds. In this paper, we model the MILP problem for WARP and present the 18-round and 19-round differential characteristics with the probability of 2-122$$2^{-122}$$ and 2-132$$2^{-132}$$ respectively. We also present a key recovery attack on 21 rounds with the data complexity of 2113$$2^{113}$$ chosen plaintexts. To the best of our knowledge, this is the first key recovery attack against 21-round WARP using differential cryptanalysis.
What problem does this paper attempt to address?