A Generalization of linear cryptanalysis and the applicability of Matsui's piling-up Lemma

Carlo Harpes, Gerhard G. Kramer, James L. Massey

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

94 Scopus citations

Abstract

Matsui’s linear cryptanalysis for iterated block ciphers is generalized by replacing his linear expressions with 1/0 sums. For a single round, an 1/0 sum is the XOR of a balanced binary-valued function of the round input and a balanced binary-valued function of the round output. The basic attack is described and conditions for it to be successful are given. A procedure for finding effective 1/0 sums, i.e., 1/0 sums yielding successful attacks, is given. A cipher contrived to be secure against linear cryptanalysis but vulncrable to this generalization of linear cryptanalysis is given. Finally, it is argued that the ciphers IDEA and SAFER K-64 are secure against this generalization.

Original languageEnglish
Title of host publicationAdvances in Cryptology — EUROCRYPT 1995 - International Conference on the Theory and Application of Cryptographic Techniques, Proceedings
EditorsJean-Jacques Quisquater, Louis C. Guillou
PublisherSpringer Verlag
Pages24-38
Number of pages15
ISBN (Print)3540594094, 9783540594093
DOIs
StatePublished - 1995
Externally publishedYes
EventInternational Conference on theTheory and Applications of Cryptographic Techniques, EUROCRYPT 1995 - Saint-Malo, France
Duration: 21 May 199525 May 1995

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume921
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Conference on theTheory and Applications of Cryptographic Techniques, EUROCRYPT 1995
Country/TerritoryFrance
CitySaint-Malo
Period21/05/9525/05/95

Keywords

  • Differential cryptanalysis
  • IDEA
  • Linear cryptanalysis
  • Piling-up lemma
  • SAFER K-64

Fingerprint

Dive into the research topics of 'A Generalization of linear cryptanalysis and the applicability of Matsui's piling-up Lemma'. Together they form a unique fingerprint.

Cite this