DC/LC analysis of Keccak-f[200]
Differential cryptanalysis

1 trails of length 2 read and checked.
1 trails of length 3 read and checked.
1 trails of length 4 read and checked.
Minimum weight: 8
       1 trails of weight  8
       1 trails of weight 20
       1 trails of weight 46

Showing the trails up to weight 46 (in no particular order).

2-round differential trail of total weight 8
* Profile related to χ:
Propagation weights:    4   4
Active rows:            2   2
* Profile related to θ:
Gaps:     12   0
Kernel:    N   k
Previous round would have weight at least 99
Round 0 (weight 4, θ-gap 12) after previous χ, then before χ (2 active rows):
..XXX   XX.XX   ..X.X   X..XX   X.X.X   .XX..   .XXXX   .X.XX  |  .....    
..XXX   XX.XX   ..X.X   X..XX   X.X.X   .XX..   .XXXX   .X.XX  |  ..X..    
..+XX   XX.XX   ..X.X   X..XX   ..X.X   .XX..   .XXXX   .X.XX  |  ..X.. z^7
..XXX   XX.XX   ..X.X   X..XX   X.X.X   .XX..   .XXXX   .X.XX  |  .....    
..XXX   XX.XX   ..X.X   X..XX   X.X.X   .XX..   .XXXX   .X.XX  |  .....    
---OO   OO-OO   --O-O   O--OO   --O-O   -OO--   -OOOO   -O-OO
Round 1 (weight 4, θ-gap 0) after previous χ, then before χ (2 active rows):
.....      |  .....     .....    
..X..      |  .....     .....    
..X.. z^7  |  ..X.. z^3 ..... z^3
.....      |  .....     .....    
.....      |  .....     ...X.    
-----    

3-round differential trail of total weight 20
* Profile related to χ:
Propagation weights:    4   8   8
Active rows:            2   4   4
* Profile related to θ:
Gaps:     10   0   0
Kernel:    N   k   k
Previous round would have weight at least 90
Round 0 (weight 4, θ-gap 10) after previous χ, then before χ (2 active rows):
X.X..   .XXX.   X....   XXXX.   .X..X   ...XX   ..X..   XXXXX  |      .....  
X.X..   .XXX.   XX...   XXXX.   .X..X   ...XX   ..X..   .XXXX  |      ...X.  
X.X..   .XXX.   X....   XXXX.   .X..X   ...XX   ..X..   XXXXX  |  z^6 ..... z
X.X..   .XXX.   X....   XXXX.   .X..X   ...XX   ..X..   XXXXX  |      ...X.  
X.X..   .XXX.   X....   XXXX.   .X..X   ...XX   ..X..   XXXXX  |      .....  
O-O--   -OOO-   OO---   OOOO-   -O--O   ---OO   --O--   -OOOO
Round 1 (weight 8, θ-gap 0) after previous χ, then before χ (4 active rows):
    .....    |  .X...   .....    
    ..XX.    |  .....   .....    
z^6 ..... z  |  ..+.. z ...X. z^5
    ..XX.    |  .X...   .....    
    .....    |  .....   ...X.    
    -----  
Round 2 (weight 8, θ-gap 0) after previous χ, then before χ (4 active rows):
.X...   .....      |      ..X..    .....   .....
.....   .....      |      .....    .....   X....
..+.. z ...X. z^5  |  z^3 ..... zz .X...   .....
.X...   .....      |      .....    .....   ....X
.....   ...X.      |      .....    .....   .....
-----   -----    

4-round differential trail of total weight 46
* Profile related to χ:
Propagation weights:   21   9   8   8
Active rows:           10   4   4   4
* Profile related to θ:
Gaps:     11   3   0   0
Kernel:    N   N   k   k
Previous round would have weight at least 88
Round 0 (weight 21, θ-gap 11) after previous χ, then before χ (10 active rows):
XX..X   X..XX   XXX.X   XX.X.   XX.XX   .XX.X   X..XX  |      ....X   ...X.
XX..X   X..X.   X..XX   XX.X.   .X.XX   .XX.X   X..XX  |      X....   ...X.
XX+.X   X..XX z X.X.X   XX.X.   .X.XX   .XX.X   X..XX  |  z^6 X....   ...X.
XX..X   X..XX   XXX.X   XX.X.   .X..X   .XX.X   X..XX  |      X....   .X...
XX..X   ....X   XXX.X   XX.X.   .XXXX   .XX.X   X..X.  |      X.X..   ...X.
OO--O   -----   OO-OO   OO-O-   OOO-O   -OO-O   O--O-
Round 1 (weight 9, θ-gap 3) after previous χ, then before χ (4 active rows):
    ...XX   .XXX.  |    .X...     X...X
    X..XX   .XXX.  |    .....     .....
z^6 X..XX   .XXX.  |  z ..... z^5 .....
    X..XX   .X...  |    .X...     X....
    X.XXX   ..XX.  |    .....     .....
    --OOO   -----
Round 2 (weight 8, θ-gap 0) after previous χ, then before χ (4 active rows):
  .X...     X....  |  ....X     .....
  .....     .....  |  .....     .....
z ..... z^5 .....  |  ..+.. z^6 .X...
  .X...     X....  |  ....X     .....
  .....     .....  |  .....     .X...
  -----     -----
Round 3 (weight 8, θ-gap 0) after previous χ, then before χ (4 active rows):
....X     .....  |     .....   .....   .....   X....
.....     .....  |     .....   .....   .X...   .....
..+.. z^6 .X...  |  zz .....   ....X z ..... z .....
....X     .....  |     .....   .....   .....   .....
.....     .X...  |     ..X..   .....   .....   .....
-----     -----

