Research Article

Cryptanalysis of the Lightweight Block Cipher BORON

Table 5

Linear trails with the optimal bias.

RoundInput mask of S-boxOutput mask of S-box

3-round linear trail with bias
00x0D0000000006000B0x0800000000010008
10x00000000000010000x0000000000003000
20x00000000006000600x0000000000100060
4-round linear trail with bias
00xD0000000006000B00x8000000000100080
10x00000000000000010x0000000000000007
20x000000000E000E000x0000000001000800
30x00100010000000100x0030003000000070
5-round linear trail with bias
00x0000000D00F000000x0000000200100000
10x00010000000000010x0007000000000003
20x000E000E060006000x0008000401000100
30x00000002001000000x0000000E00700000
40x00070000000000070x000C00000000000C
6-round linear trail with bias
00x00000090060000000x0000002001000000
10x00100000000000100x0070000000000030
20x00E000E0600060000x0090004010001000
30x00200000010000000x0040000008000000
40x00000000008000000x0000000000500000
50x00050005000500000x0003000700030000
7-round linear trail with bias
00xD0000D00000D000D0x4000080000080002
10x00000400800000000x00000A0050000000
20x05000000000005000x0300000000000300
30x06000600000600060x0B000C0000010003
40x06000000100000000x06000000C0000000
50x000000000C0000000x0000000005000000
60x00500050005000000x0070007000300000
8-round linear trail with bias
00x00000D00F00000000x0000020010000000
10x01000000000001000x0700000000000300
20x0E000E00000600060x0800040000010001
30x00000200100000000x00000E0070000000
40x07000000000007000x0100000000000300
50x02000200000600060x0B000C0000010003
60x06000000100000000x06000000C0000000
70x000000000C0000000x0000000005000000
9-round linear trail with bias
00x0000000F000D00000x0000000100080000
10x80000000000080000x5000000000007000
20xA000A00000E000E00x8000400000100010
30x00002000000100000x0000E00000070000
40x70000000000070000x1000000000003000
50x20002000006000600xB000C00000100030
60x60000000000100000x60000000000C0000
70x00000000C00000000x0000000070000000
80x07000700070000000x010001000C000000