Research Article

Improved Conditional Differential Analysis on NLFSR-Based Block Cipher KATAN32 with MILP

Table 9

Five key-recovery attack experiments on 81-round KATAN32.

No.80-bit keyEquivalent key bits with the maximum bias

11110
21010
31011
41010
50000