Research Article

Cryptanalysis of the Lightweight Block Cipher BORON

Table 4

Differential trails with the optimal probability.

RoundInput difference of S-boxOutput difference of S-box

3-round differential trail with probability
00x00000008000002000x0000000C00000300
10x00000000000000060x0000000000000008
20x10001000000010000xA000A0000000A000
30x1141514040014141
4-round differential trail with probability
00xA0000009000F00000x4000000100080000
10x00008000000000000x0000C00000000000
20x60006000000000000x2000800000000000
30x00004000400040000x0000900090007000
40x48E048E0090009E0
5-round differential trail with probability
00x0000002009000F000x0000003001000800
10x00080008001000000x0003000C00600000
20x00000006000000000x0000000E00000000
30x00070007000000000x0001000400000000
40x00000002000200020x00000003000B0005
50x8A018A01B000BA00
6-round differential trail with probability
00x09000A00300800000x01000400200C0000
10x00000200C000C0000x0000030010008000
20x00800080010000000x003000C006000000
30x00000060000000000x000000C000000000
40x00600060000000000x0020008000000000
50x00000040004000400x0000009000700090
60x2049204900072006
7-round differential trail with probability
00xB000A000002300000x1000400000520000
10x00002000000500050x0000300000010008
20x08000800100000000x03000C0060000000
30x00000600000000000x00000A0000000000
40x05000500000000000x03000C0000000000
50x00000600060006000x0000080008000800
60x04100410008000900x07A007A000F00010
70x2C9023D00F4F2F4F
8-round differential trail with probability
00x00000800001000000x00000C0000F00000
10x06000600000F000F0x08000E00000E0008
20x07001700F000E0000x0400F10080004000
30x70007800000000800x60001C0000000060
40x0E00CE00C00000000x06001800C0000000
50x00000C00000000000x0000010000000000
60x00800080000000000x003000C000000000
70x00000060006000600x0000008000800080
80x0041004100080009