MILP-Aided Cryptanalysis of the FUTURE Block Cipher

İlter M. B., Selçuk A. A.

15th International Conference on Security for Information Technology and Communications, SECITC 2022, Virtual, Online, 8 - 09 December 2022, vol.13809 LNCS, pp.153-167 identifier

  • Publication Type: Conference Paper / Full Text
  • Volume: 13809 LNCS
  • Doi Number: 10.1007/978-3-031-32636-3_9
  • City: Virtual, Online
  • Page Numbers: pp.153-167
  • Keywords: differential cryptanalysis, FUTURE, linear cryptanalysis, MILP
  • Middle East Technical University Affiliated: No


FUTURE is a recently proposed, lightweight block cipher. It has an AES-like, SP-based, 10-round encryption function, where, unlike most other lightweight constructions, the diffusion layer is based on an MDS matrix. Despite its relative complexity, it has a remarkable hardware performance due to careful design decisions. In this paper, we conducted a MILP-based analysis of the cipher, where we incorporated exact probabilities rather than just the number of active S-boxes into the model. Through the MILP analysis, we were able to find differential and linear distinguishers for up to 5 rounds of FUTURE, extending the known distinguishers of the cipher by one round.