A tutorial on linear and differential cryptanalysis

HM Heys - Cryptologia, 2002 - Taylor & Francis
In this paper, we present a detailed tutorial on linear cryptanalysis and differential
cryptanalysis, the two most significant attacks applicable to symmetric-key block ciphers. The …

Constructing symmetric ciphers using the CAST design procedure

CM Adams - Designs, Codes and cryptography, 1997 - Springer
This paper describes the CAST design procedure for constructing a family of DES-like
Substitution-Permutation Network (SPN) cryptosystems which appear to have good …

Automatic search of meet-in-the-middle and impossible differential attacks

P Derbez, PA Fouque - Annual International Cryptology Conference, 2016 - Springer
Tracking bits through block ciphers and optimizing attacks at hand is one of the tedious task
symmetric cryptanalysts have to deal with. It would be nice if a program will automatically …

On probability of success in linear and differential cryptanalysis

AA Selçuk - Journal of Cryptology, 2008 - Springer
Despite their widespread usage in block cipher security, linear and differential cryptanalysis
still lack a robust treatment of their success probability, and the success chances of these …

Provable security against differential and linear cryptanalysis for the SPN structure

S Hong, S Lee, J Lim, J Sung, D Cheon… - … York, NY, USA, April 10–12 …, 2001 - Springer
Abstract In the SPN (Substitution-Permutation Network) structure, it is very important to
design a diffusion layer to construct a secure block cipher against differential cryptanalysis …

Improving the time complexity of Matsui's linear cryptanalysis

B Collard, FX Standaert, JJ Quisquater - Information Security and …, 2007 - Springer
This paper reports on an improvement of Matsui's linear cryptanalysis that reduces the
complexity of an attack with algorithm 2, by taking advantage of the Fast Fourier Transform …

[PDF][PDF] An experiment on DES statistical cryptanalysis

S Vaudenay - Proceedings of the 3rd ACM Conference on Computer …, 1996 - dl.acm.org
Linear cryptanalysis and differential cryptanalysis are the most important methods of attack
against block ciphers. Their efficiency have been demonstrated against several ciphers …

On Matsui's linear cryptanalysis

E Biham - Advances in Cryptology—EUROCRYPT'94: Workshop …, 1995 - Springer
In [9] Matsui introduced a new method of cryptanalysis, called Linear Cryptanalysis. This
method was used to attack DES using 2 47 known plaintexts. In this paper we formalize this …

Linear hulls with correlation zero and linear cryptanalysis of block ciphers

A Bogdanov, V Rijmen - Designs, codes and cryptography, 2014 - Springer
Linear cryptanalysis, along with differential cryptanalysis, is an important tool to evaluate the
security of block ciphers. This work introduces a novel extension of linear cryptanalysis: zero …

Enhancing differential-linear cryptanalysis

E Biham, O Dunkelman, N Keller - … on the Theory and Application of …, 2002 - Springer
Differential cryptanalysis analyzes ciphers by studying the development of differences
during encryption. Linear cryptanalysis is similar but is based on studying approximate …