Optimal differential trails in lightweight block ciphers ANU and PICO
Manoj Kumar, T. S. Suresh, Saibal Kumar Pal, Anupama Panigrahi · Cryptologia · 2019
ANU and PICO are two lightweight block ciphers published by Bansod et al. in 2016. For cryptanalysis, we apply a branch-and-bound based search algorithm to find the least number of active Substitution boxes (S-boxes) in differential trails of these ciphers. Designers provide a lower bound on the number of active S-boxes in any differential trail of ANU up to 4 rounds as 0, 2, 8, and 20. We improve this lower bound to 0, 2, 5, and 9. We present the optimal differential trails in ANU for 7 rounds with probability 2−62. The design specification of PICO claims to generate a large number of active S-boxes in a few rounds. We reduce the lower bound on the number of active S-boxes in any 6-round trail from 12 to 6. We also present the optimal differential trails in PICO for 21 rounds with probability 2−63. These are the best results reported in the literature for differential cryptanalysis of ANU and PICO.