Sciweavers

EUROCRYPT
1995
Springer

A Generalization of Linear Cryptanalysis and the Applicability of Matsui's Piling-Up Lemma

14 years 4 months ago
A Generalization of Linear Cryptanalysis and the Applicability of Matsui's Piling-Up Lemma
Matsui's linear cryptanalysis for iterated block ciphers is generalized by replacing his linear expressions with I O sums. For a single round, an I O sum is the XOR of a balanced binary-valued function of the round input and a balanced binary-valued function of the round output. The basic attack is described and conditions for it to be successful are given. A procedure for nding e ective I O sums, i.e., I O sums yielding successful attacks, is given. A cipher contrived to be secure against linear cryptanalysis but vulnerable to this generalization of linear cryptanalysis is given. Finally, it is argued that the ciphers IDEA and SAFER K-64 are secure against this generalization. Keywords. Linear cryptanalysis, di erential cryptanalysis, piling-up lemma, IDEA, SAFER.
Carlo Harpes, Gerhard G. Kramer, James L. Massey
Added 26 Aug 2010
Updated 26 Aug 2010
Type Conference
Year 1995
Where EUROCRYPT
Authors Carlo Harpes, Gerhard G. Kramer, James L. Massey
Comments (0)