Estimating the Probabilities of Low-Weight Differential and Linear Approximations on PRESENT-Like Ciphers

  • Mohamed Ahmed Abdelraheem
Part of the Lecture Notes in Computer Science book series (LNCS, volume 7839)


We use large but sparse correlation and transition-difference-probability submatrices to find the best linear and differential approximations respectively on PRESENT-like ciphers. This outperforms the branch and bound algorithm when the number of low-weight differential and linear characteristics grows exponentially which is the case in PRESENT-like ciphers. We found linear distinguishers on 23 rounds of the SPONGENT permutation. We also found better linear approximations on PRESENT using trails covering at most 4 active Sboxes which give us 24-round statistical saturation distinguishers which could be used to break 26 rounds of PRESENT.


block cipher differential difference matrix linear hull correlation matrix statistical saturation attack PRESENT SPONGENT 


Copyright information

© Springer-Verlag Berlin Heidelberg 2013

Authors and Affiliations

  • Mohamed Ahmed Abdelraheem
    • 1
  1. 1.Department of MathematicsTechnical University of DenmarkLyngbyDenmark

