ACISP 2021, December 1-3, 2021. Distinguishing and Key Recovery Attacks on the Reduced-Round SNOW-V Experimental Results 25 Bit-wise Differential Distinguisher (9/9) Domain Single-bit differentials Dual-bit differentials ID OD bias ID OD bias V0 Δ!,,. , Δ,,, / -10.299 Δ/,! , Δ,,! / ⊕ Δ!,! / -9.432 V1 Δ0,! , Δ,,, / -10.114 Δ/,! , Δ,,! / ⊕ Δ!,! / -9.243 V2 Δ/,# , Δ,,, / -9.804 Δ/,# , Δ,,, / ⊕ Δ!,, / -9.069 V3 Δ,,1 , Δ#,/ / -9.121 Δ/,! , Δ,,! / ⊕ Δ!,! / -8.825 V4 Δ2,2 , Δ3,# / -8.975 Δ!/,. , Δ,,! / ⊕ Δ!,! / -7.343 V5 Δ!0,/ , Δ.,0 / -7.904 Δ2,. , Δ#,# / ⊕ Δ0,# / -5.675 V6 Δ!0,! , Δ1,/ / -6.197 Δ,,2 , Δ,,, / ⊕ Δ!,. / -3.725 V7 Δ!/,! , Δ!#,0 / -4.268 Δ4,, , Δ,,! / ⊕ Δ0,# / -1.733 Table. The best bit-wise differential biases (log2 ) for 4-round SNOW-V. n Chosen-IV technique is valid up to 4 rounds of SNOW-V u Bit-wise differential attack is valid up to 4 rounds of SNOW-V u 24.466 samples suffice to distinguish the 4-round SNOW-V from a TRNG