Research Article
Cryptanalysis of the Lightweight Block Cipher BORON
Table 6
Related-key differential trails with the optimal probability.
| Round | Subkey difference | Input difference of S-box | Output difference of S-box |
| 4-round related-key differential trail with probability | 0 | 0x0020000000000000 | 0x0000000000000000 | 0x0000000000000000 | 1 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 2 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000001000 | 0x0000000000001000 | 0x000000000000F000 | 5-round related-key differential trail with probability | 0 | 0x0000004000000000 | 0x000A000000F00000 | 0x0004000000800000 | 1 | 0x0008000000000000 | 0x0000000000000000 | 0x0000000000000000 | 2 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000000400 | 0x0000000000000400 | 0x0000000000000900 | 6-round related-key differential trail with probability | 0 | 0x0000004000000000 | 0x000A000000600000 | 0x0004000000800000 | 1 | 0x0008000000000000 | 0x0000000000000000 | 0x0000000000000000 | 2 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000000400 | 0x0000000000000400 | 0x0000000000000500 | 5 | 0x0000000000800000 | 0x000A000A0080000A | 0x0004000F00C00004 | 7-round related-key differential trail with probability | 0 | 0x0000000002000000 | 0x003200A003102000 | 0x0025004002A03000 | 1 | 0x0000004000000000 | 0x000A000000600000 | 0x0004000000800000 | 2 | 0x0008000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 5 | 0x0000000000000400 | 0x0000000000000400 | 0x0000000000000500 | 6 | 0x0000000000800000 | 0x000A000A0080000A | 0x000F000400C0000F | 8-round related-key differential trail with probability | 0 | 0x0000000002000000 | 0x003200A003102000 | 0x0025004002A03000 | 1 | 0x0000004000000000 | 0x000A000000600000 | 0x0004000000800000 | 2 | 0x0008000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 5 | 0x0000000000000400 | 0x0000000000000400 | 0x0000000000000700 | 6 | 0x0000000000800000 | 0x000E000E0080000E | 0x0003000D00600008 | 7 | 0x0000001000000000 | 0x9000901600001000 | 0x100090F80000F000 | 9-round related-key differential trail with probability | 0 | 0x0000010000000000 | 0x00B0000003000000 | 0x0010000002000000 | 1 | 0x0020000000000000 | 0x0000000000000000 | 0x0000000000000000 | 2 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000001000 | 0x0000000000001000 | 0x0000000000006000 | 5 | 0x0000000002000000 | 0x00C000C0020000C0 | 0x0050008003000070 | 6 | 0x0000004000000000 | 0xE0E0E0000090E090 | 0x8030400000103010 | 7 | 0x0008000000000000 | 0x0009006000602000 | 0x000400C000803000 | 8 | 0x0000000000000000 | 0x0008000000000060 | 0x000F0000000000E0 | 10-round related-key differential trail with probability | 0 | 0x0000010000000000 | 0x00B0000003000000 | 0x0010000002000000 | 1 | 0x0020000000000000 | 0x0000000000000000 | 0x0000000000000000 | 2 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 3 | 0x0000000000000000 | 0x0000000000000000 | 0x0000000000000000 | 4 | 0x0000000000001000 | 0x0000000000001000 | 0x0000000000006000 | 5 | 0x0000000002000000 | 0x00C000C0020000C0 | 0x0050008003000070 | 6 | 0x0000004000000000 | 0xE0E0E0000090E090 | 0x8070400000107010 | 7 | 0x0008000000000000 | 0x000900E000E02000 | 0x000400D000803000 | 8 | 0x0000000000000000 | 0x0000000800000060 | 0x00000003000000C0 | 9 | 0x0000000000000000 | 0x0000000000008001 | 0x000000000000C00F |
|
|