Fast Software Encryption: 18th International Workshop, FSE by Mohamed Ahmed Abdelraheem, Gregor Leander, Erik Zenner

By Mohamed Ahmed Abdelraheem, Gregor Leander, Erik Zenner (auth.), Antoine Joux (eds.)

This ebook constitutes the completely refereed post-conference lawsuits of the 18th overseas Workshop on speedy software program Encryption, held in Lyngby, Denmark, in February 2011. The 22 revised complete papers awarded including 1 invited lecture have been conscientiously reviewed and chosen from 106 preliminary submissions. The papers are prepared in topical sections on differential cryptanalysis, hash capabilities, safety and types, move ciphers, block ciphers and modes, in addition to linear and differential cryptanalysis.

8. If exists, fix the output differences for the S-boxes of round 3 (it is not necessary to fix the outputs of S-boxes of round 1). Although we cannot give a precise estimate for the complexity of creating all 3round characteristics, we can give such estimates for some particular fixed values of Pn∗ ,Pn−1 ,Pn−2 , and Pn−2 . 3 times, respectively, leading to a total complexity of around 235 . 6 (step 8) good 3-round related-key characteristics. 3 The Split Approach To build the best n-round characteristic Matsui’s approach requires first to build the best characteristics on 1, 2, .

In: Biham, E. ) FSE 1997. LNCS, vol. 1267, pp. 41–53. Springer, Heidelberg (1997) 2. : Differential cryptanalysis of DES-like cryptosystems. J. Cryptology 4(1), 3–72 (1991) 3. : Differential cryptanalysis of the full 16-round DES. F. ) CRYPTO 1992. LNCS, vol. 740, pp. 487–496. Springer, Heidelberg (1993) 4. : Automatic Search for Related-Key Differential Characteristics in Byte-Oriented Block Ciphers: Application to AES, Camellia, Khazad and Others. In: Gilbert, H. ) EUROCRYPT 2010. LNCS, vol. 6110, pp.

Biryukov and I. Nikoli´c Table 2. 95 ≤ P7 < 2−30 < 2−31 ≤ P10 < 2−40 < 2−41 ≤ P13 < 2−50 < 2−51 The Case of s2 DES Another variant of DES called s2 DES was proposed in [5]. The search for the best single-key differential characteristics in s2 DES was performed in [10]. For this purpose the authors used Matsui’s tool. This analysis showed that the best round-reduced differential characteristics in s2 DES have higher probabilities than in DES. We ran our search for related-key characteristics using only our related-key approached based on Matsui’s algorithm.

