PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 14, 2026Cybersecurity0 citationsOpen Access

Improved search models of boomerang distinguishers and application to LILLIPUT

View Full Paper
YWYunong WuYZYanyan ZhouZZZongsheng Zhang

Key Points

  • This research aims to enhance the security analysis of block ciphers through improved boomerang distinguisher models.
  • Developed Mixed-Integer Linear Programming (MILP)-based search models for single and related-key boomerang distinguishers.
  • Introduced dynamic allocation of active S-boxes in single-key models for better probability characterization.
  • Created models for related-key scenarios ensuring boomerang switch probability of 1 using bit-level key schedule.
  • Achieved single-key distinguishers for 8 to 13 rounds and a 15-round related-key distinguisher for LILLIPUT.
  • Reduced data complexity for 13-round single-key distinguishing attack by approximately 9.7 times.
  • Established a 15-round related-key distinguisher with a probability of 2^{-58}, the longest for LILLIPUT.

Abstract

Abstract Boomerang attack serves as a potent cryptanalytic tool for assessing the security of block ciphers. Over the past few years, various automatic search models for boomerang distinguishers have been proposed for block ciphers with different structures. This paper presents improved Mixed-Integer Linear Programming (MILP) -based search models for both single-key and related-key boomerang distinguishers. In the single-key scenario, we propose a method for dynamic allocation of active S-boxes. Our search model for single-key boomerang distinguishers characterizes the distinguisher probability more accurately, addressing the suboptimality issue caused by non-fixed weight assignments in prior models. In the related-key scenario, a search model for related-key boomerang distinguisher is proposed for block ciphers with bit-level key schedule algorithms, where the probability of the boomerang switch is ensured to be 1. To validate the effectiveness of our models, we apply them to the lightweight block cipher LILLIPUT based on Extended Generalized Feistel Networks (EGFN), conducting a comprehensive security analysis against boomerang attacks. Using our models, we successfully derive single-key boomerang distinguishers for 8 to 13 rounds and a 15-round related-key boomerang distinguisher. Notably, the data complexity required for 13-round single-key distinguishing attack is reduced by 2^{ 3. 172} 2 3. 172, and the 15-round related-key boomerang distinguisher with a probability of 2^{ - 58} 2 - 58 is currently the longest-round distinguisher among all known distinguishers for LILLIPUT. The application results fully demonstrate the capability of our models in evaluating the security of block ciphers. This research not only provides new insights and methods for the design and analysis of lightweight block ciphers, but also deepens the understanding of the security characteristics for LILLIPUT.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Wu et al. (2026) studied this question.

synapsesocial.com/papers/6966f2e313bf7a6f02c001ebhttps://doi.org/10.1186/s42400-025-00540-9
Ask AI
Helpful
Bookmark
Share
View Full Paper