@article{Mouha_Kolomeec_Akhtiamov_Sutormin_Panferov_Titova_Bonich_Ishchukova_Tokareva_Zhantulikov_2021, title={Maximums of the Additive Differential Probability of Exclusive-Or}, volume={2021}, url={https://tosc.iacr.org/index.php/ToSC/article/view/8912}, DOI={10.46586/tosc.v2021.i2.292-313}, abstractNote={<p>At FSE 2004, Lipmaa et al. studied the additive differential probability adp<sup>⊕</sup>(α,β → γ) of exclusive-or where differences α,β,γ ∈ F<sup>n</sup><sub>2</sub> are expressed using addition modulo 2<sup>n</sup>. This probability is used in the analysis of symmetric-key primitives that combine XOR and modular addition, such as the increasingly popular Addition-Rotation-XOR (ARX) constructions. The focus of this paper is on maximal differentials, which are helpful when constructing differential trails. We provide the missing proof for Theorem 3 of the FSE 2004 paper, which states that max<sub>α</sub>,<sub>β</sub>adp<sup>⊕</sup>(α,β → γ) = adp<sup>⊕</sup>(0,γ → γ) for all γ. Furthermore, we prove that there always exist either two or eight distinct pairs α,β such that adp<sup>⊕</sup>( α,β → γ) = adp<sup>⊕</sup>(0,γ → γ), and we obtain recurrence formulas for calculating adp<sup>⊕</sup>. To gain insight into the range of possible differential probabilities, we also study other properties such as the minimum value of adp<sup>⊕</sup>(0,γ → γ), and we find all γ that satisfy this minimum value.</p>}, number={2}, journal={IACR Transactions on Symmetric Cryptology}, author={Mouha, Nicky and Kolomeec, Nikolay and Akhtiamov, Danil and Sutormin, Ivan and Panferov, Matvey and Titova, Kseniya and Bonich, Tatiana and Ishchukova, Evgeniya and Tokareva, Natalia and Zhantulikov, Bulat}, year={2021}, month={Jun.}, pages={292–313} }