Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO
Abstract
1. Introduction
- We construct a PICO-specific MILP–SAT workflow. MILP supplies active-S-box lower bounds, while SAT tests disjoint exact-weight and active-count subinstances under the DDT constraints. With fixed endpoints, complete characteristics are blocked individually and their contributions are aggregated by weight. Our methodological contribution is the PICO-specific integration of these established components into a workflow that yields auditable characteristic searches and finite-window probability sums.
- For selected 21- and 22-round endpoint pairs, we extend the verified enumeration windows from the intermediate cutoffs and , respectively, to matched 14-layer windows ending at and . The resulting finite-window lower bounds increase from to and from to .
- We use the larger verified 21-round finite-window lower bound as the probability input for filtering-and-ranking equivalent-round-key candidates, following Ref. [20]. We prepend two rounds and append three rounds around the 21-round differential to form the procedure for a 108-bit equivalent-round-key tuple. For S plaintext structures, we derive the data amount , the normalized S-box filtering workload , and the plaintext–ciphertext-record storage . At the illustrative setting , these quantities are , , and , respectively. This setting is not tied to a demonstrated success probability. These values do not represent a comparison with Ref. [20] at the same success probability.
2. The PICO Cipher
2.1. Notation
2.2. Encryption Procedure
- (1)
- Round Key Addition
- (2)
- S-box Substitution
- (3)
- Permutation Layer
2.3. Key Schedule
3. PICO-Specific MILP–SAT Workflow for Differential Cryptanalysis
3.1. MILP Model for Active-S-Box Bounds
3.1.1. XOR Operation
3.1.2. S-Box Activity Constraints
3.1.3. The Inequality Description of the DDT
3.1.4. The Objective Function
3.2. SAT Model for Searching Valid Differential Characteristics
3.2.1. Variable Definitions
3.2.2. S-Box Constraints
3.2.3. Permutation Constraints
3.2.4. Weight and Cardinality Constraints
3.2.5. Matsui Pruning
3.2.6. Nonzero Constraint
3.2.7. Complete Model
3.3. PICO-Specific MILP–SAT Workflow
| Algorithm 1 MILP–SAT search for a minimum-weight differential characteristic | |
| Input: Number of rounds R; table of minimum active S-box counts for shorter rounds | |
| Output: First feasible weight and characteristic C | |
| 1: | ▹ minimum active S-box count from MILP |
| 2: | ▹ weight lower bound: each active S-box has weight |
| 3: while true do | |
| 4: for to do | |
| 5: | ▹ fix , , optional Matsui |
| 6: if returns a model then | |
| 7: return | ▹ feasible characteristic |
| 8: end if | |
| 9: end for | |
| 10: | |
| 11: end while | |
| Algorithm 2 The SAT-based enumeration of differential characteristics contributing to a differential | |
| Input: Number of rounds R; endpoints ; weight window ; minimum active S-box counts | |
| Output: Finite-window lower bound for the fixed endpoints | |
| 1: | |
| 2: for to do | |
| 3: | |
| 4: for to do | |
| 5: | ▹ fix endpoints, , ; optional Matsui |
| 6: while returns a model do | |
| 7: ; | |
| 8: add to a blocking clause on the characteristic variables of C | |
| 9: end while | |
| 10: end for | |
| 11: | ▹: number of weight-W characteristics |
| 12: end for | |
| 13: return P | |
4. Finite-Window Differential Analysis and Outer-Round Filtering for 26-Round PICO
4.1. Reported Differential-Characteristic Weights
4.2. The 21-Round and 22-Round Fixed-Endpoint Differentials
4.3. Analytical Equivalent-Round-Key Filtering and Ranking for 26-Round PICO
4.3.1. Differential Distinguisher Extension
4.3.2. Analytical Data Accounting
4.3.3. Equivalent-Round-Key Filtering Schedule
4.3.4. Analytical Workload, Signal-to-Noise Ratio, and Output Scope
5. Conclusions
Supplementary Materials
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| AI | Artificial Intelligence |
| SPN | Substitution–Permutation Network |
| S-box | Substitution Box |
| ARX | Addition–Rotation–XOR |
| XOR | Exclusive OR |
| MILP | Mixed-Integer Linear Programming |
| LP | Linear Programming |
| SAT | Boolean Satisfiability |
| SMT | Satisfiability Modulo Theories |
| CNF | Conjunctive Normal Form |
| DDT | Differential Distribution Table |
| UNSAT | Unsatisfiable |
| AK | Round Key Addition |
| SB | S-Box Substitution |
| Perm | Bit Permutation |
References
- Bogdanov, A.; Knudsen, L.R.; Leander, G.; Paar, C.; Poschmann, A.; Robshaw, M.J.B.; Seurin, Y.; Vikkelsoe, C. PRESENT: An ultra-lightweight block cipher. In Cryptographic Hardware and Embedded Systems—CHES 2007; Paillier, P., Verbauwhede, I., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2007; Volume 4727, pp. 450–466. [Google Scholar] [CrossRef] [Scilit]
- Banik, S.; Pandey, S.K.; Peyrin, T.; Sasaki, Y.; Sim, S.M.; Todo, Y. GIFT: A small present—Towards reaching the limit of lightweight encryption. In Cryptographic Hardware and Embedded Systems—CHES 2017; Fischer, W., Homma, N., Eds.; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2017; Volume 10529, pp. 321–345. [Google Scholar] [CrossRef] [Scilit]
- Beierle, C.; Jean, J.; Kölbl, S.; Leander, G.; Moradi, A.; Peyrin, T.; Sasaki, Y.; Sasdrich, P.; Sim, S.M. The SKINNY family of block ciphers and its low-latency variant MANTIS. In Advances in Cryptology—CRYPTO 2016; Robshaw, M., Katz, J., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2016; Volume 9815, pp. 123–153. [Google Scholar] [CrossRef] [Scilit]
- Wu, W.; Zhang, L. LBlock: A lightweight block cipher. In Applied Cryptography and Network Security; Lopez, J., Tsudik, G., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2011; Volume 6715, pp. 327–344. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Wei, Y.; Pasalic, E.; Li, L.; Fan, T. LLBC: A novel Feistel-based low-latency block cipher for IoT applications. IEEE Internet Things J. 2025, 12, 45583–45595. [Google Scholar] [CrossRef] [Scilit]
- Bansod, G.; Pisharoty, N.; Patil, A. PICO: An ultra lightweight and low power encryption design for ubiquitous computing. Def. Sci. J. 2016, 66, 259–265. [Google Scholar] [CrossRef] [Scilit]
- Biham, E.; Shamir, A. Differential cryptanalysis of DES-like cryptosystems. J. Cryptol. 1991, 4, 3–72. [Google Scholar] [CrossRef] [Scilit]
- Lai, X.; Massey, J.L.; Murphy, S. Markov ciphers and differential cryptanalysis. In Advances in Cryptology—EUROCRYPT ’91; Davies, D.W., Ed.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1991; Volume 547, pp. 17–38. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Leurent, G.; Pernot, C.; Schrottenloher, A. Clustering effect in Simon and Simeck. In Advances in Cryptology—ASIACRYPT 2021; Tibouchi, M., Wang, H., Eds.; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2021; Volume 13090, pp. 272–302. [Google Scholar] [CrossRef] [Scilit]
- Mouha, N.; Wang, Q.; Gu, D.; Preneel, B. Differential and linear cryptanalysis using mixed-integer linear programming. In Information Security and Cryptology; Wu, C.-K., Yung, M., Lin, D., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2012; Volume 7537, pp. 57–76. [Google Scholar] [CrossRef] [Scilit]
- Sun, S.; Hu, L.; Wang, P.; Qiao, K.; Ma, X.; Song, L. Automatic security evaluation and (related-key) differential characteristic search: Application to SIMON, PRESENT, LBlock, DES(L) and other bit-oriented block ciphers. In Advances in Cryptology—ASIACRYPT 2014; Sarkar, P., Iwata, T., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2014; Volume 8873, pp. 158–178. [Google Scholar] [CrossRef] [Scilit]
- Mouha, N.; Preneel, B. Towards Finding Optimal Differential Characteristics for ARX: Application to Salsa20. Cryptology ePrint Archive. Paper 2013/328. 2013. Available online: https://eprint.iacr.org/2013/328 (accessed on 18 July 2026).
- Kölbl, S.; Leander, G.; Tiessen, T. Observations on the SIMON block cipher family. In Advances in Cryptology—CRYPTO 2015; Gennaro, R., Robshaw, M., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2015; Volume 9215, pp. 161–185. [Google Scholar] [CrossRef] [Scilit]
- Sun, L.; Wang, W.; Wang, M. Accelerating the search of differential and linear characteristics with the SAT method. IACR Trans. Symmetric Cryptol. 2021, 2021, 269–315. [Google Scholar] [CrossRef] [Scilit]
- Taka, K.; Sakamoto, K.; Ito, R.; Shiba, R.; Utsumi, S.; Isobe, T. Divide-and-conquer SAT for exploring optimal differential and linear characteristics and its applications. IACR Trans. Symmetric Cryptol. 2025, 2025, 516–576. [Google Scholar] [CrossRef] [Scilit]
- Kim, I.; Kim, S.; Kim, S.; Kwon, D.; Shin, H.; Lee, D.; Hong, D.; Sung, J.; Hong, S. Towards Optimal Differential Attacks on FLY and PIPO. Cryptology ePrint Archive. Paper 2025/837. 2025. Available online: https://eprint.iacr.org/2025/837 (accessed on 18 July 2026).
- Kumar, M.; Suresh, T.S.; Pal, S.K.; Panigrahi, A. Optimal differential trails in lightweight block ciphers ANU and PICO. Cryptologia 2020, 44, 68–78. [Google Scholar] [CrossRef] [Scilit]
- Ma, C.-Y.; Liu, G.-Q.; Li, C. Zero-correlation linear cryptanalysis on PICO and RECTANGLE. J. Cryptologic Res. 2017, 4, 413–422. (In Chinese) [Google Scholar] [CrossRef]
- Shi, K.-K.; Ren, J.-J.; Chen, S.-Z. MILP-based search for differential and linear distinguishers of PICO algorithm. J. Cryptologic Res. 2023, 10, 910–921. (In Chinese) [Google Scholar] [CrossRef]
- Wang, C.-B.; Zhang, Z.-Y.; Hu, L. Differential cryptanalysis on ultra lightweight block cipher PICO. J. Cryptologic Res. 2023, 10, 685–701. (In Chinese) [Google Scholar] [CrossRef]
- Sasaki, Y.; Todo, Y. New algorithm for modeling S-box in MILP based differential and division trail search. In Innovative Security Solutions for Information Technology and Communications; Farshim, P., Simion, E., Eds.; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2017; Volume 10543, pp. 150–165. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Sinz, C. Towards an optimal CNF encoding of Boolean cardinality constraints. In Principles and Practice of Constraint Programming—CP 2005; van Beek, P., Ed.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2005; Volume 3709, pp. 827–831. [Google Scholar] [CrossRef] [Scilit]
- Selçuk, A.A. On probability of success in linear and differential cryptanalysis. J. Cryptol. 2008, 21, 131–147. [Google Scholar] [CrossRef] [Scilit]





| Notation | Description |
|---|---|
| P | The 64-bit input plaintext |
| C | The 64-bit output ciphertext |
| , | The 64-bit input and output of round r |
| r | The round index, |
| K | The 128-bit master key |
| The subkey used in round r | |
| The bit-permutation layer | |
| Δ | A difference (bit vector) |
| The probability of a differential characteristic | |
| W | The weight of a differential characteristic, |
| ⊕ | The bitwise exclusive OR (XOR) operation |
| ‖ | The concatenation of two binary strings |
| ⋘n | Left cyclic shift by n bits |
| ⋙n | Right cyclic shift by n bits |
| x | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | A | B | C | D | E | F |
| 1 | 2 | 4 | D | 6 | F | B | 8 | A | 5 | E | 3 | 9 | C | 7 | 0 |
| 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 0 | 0,10 | 1,5 | 1,12 | 2,6 | 2,12 | 3,0 | 3,11 | 0,1 | 3,3 | 0,15 | 2,9 | 0,2 | 3,12 | 2,2 | 1,8 | 1,4 |
| 1 | 3,8 | 0,6 | 1,1 | 1,15 | 2,4 | 3,5 | 0,12 | 2,14 | 1,14 | 3,4 | 0,11 | 0,4 | 1,7 | 2,3 | 2,8 | 3,15 |
| 2 | 0,8 | 2,7 | 0,3 | 2,11 | 3,9 | 3,1 | 1,0 | 1,9 | 2,5 | 2,10 | 3,13 | 3,2 | 0,0 | 0,9 | 1,2 | 1,10 |
| 3 | 3,10 | 3,7 | 0,7 | 1,3 | 1,13 | 0,14 | 2,15 | 2,0 | 2,1 | 0,5 | 3,14 | 2,13 | 0,13 | 3,6 | 1,6 | 1,11 |
| Rounds | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| −log2 p | 2 | 4 | 6 | 9 | 12 | 14 | 17 | 20 | 23 | 26 | 29 |
| Rounds | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| −log2 p | 33 | 38 | 41 | 44 | 47 | 51 | 54 | 58 | 60 | 63 | 66 |
| W | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 |
| 2 | 4 | 0 | 6 | 22 | 22 | 14 | 40 | 63 | 110 | 185 | 257 | 425 | 706 |
| W | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 |
| 4 | 8 | 0 | 12 | 44 | 44 | 28 | 80 | 126 | 220 | 370 | 514 | 850 | 1412 |
| Number of Layers | 21-Round Upper Bound | 22-Round Upper Bound | ||
|---|---|---|---|---|
| 4 | ||||
| 8 | ||||
| 10 | ||||
| 12 | ||||
| 14 |
| Step | Guessed Key Bits | Filtering Condition | Expected Remaining Pairs | Analytical S-Box Workload |
|---|---|---|---|---|
| 1 | ||||
| 2 | ||||
| 3 | ||||
| 4 | ||||
| 5 | ||||
| 6 | ||||
| 7 | ||||
| 8 | ||||
| 9 | ||||
| 10 | ||||
| 11 | ||||
| 12 | ||||
| 13 | ||||
| 14 | ||||
| 15 | ||||
| 16 | ||||
| 17 | ||||
| 18 | ||||
| 19 | ||||
| 20 | ||||
| 21 | ||||
| 22 | ||||
| 23 | ||||
| 24 | ||||
| 25 | ||||
| 26 | ||||
| 27 | ||||
| Total |
| 21-Round Distinguisher Probability | Data Amount D | Normalized Filtering Workload T | Record Storage M | Reference |
|---|---|---|---|---|
| [20] | ||||
| Ours |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Wang, Y.; Liang, Z.; Fan, T.; Zhou, T. Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO. Entropy 2026, 28, 1006. https://doi.org/10.3390/e28091006
Wang Y, Liang Z, Fan T, Zhou T. Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO. Entropy. 2026; 28(9):1006. https://doi.org/10.3390/e28091006
Chicago/Turabian StyleWang, Yu, Zhuofeng Liang, Ting Fan, and Tao Zhou. 2026. "Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO" Entropy 28, no. 9: 1006. https://doi.org/10.3390/e28091006
APA StyleWang, Y., Liang, Z., Fan, T., & Zhou, T. (2026). Improved Differential Cryptanalysis of the Ultra-Lightweight Block Cipher PICO. Entropy, 28(9), 1006. https://doi.org/10.3390/e28091006

