So far, low probability differentials for the key schedule of block ciphers have been used as a straightforward proof of security against related-key differential analysis. To achieve resistance, it is believed that for cipher with k-bit key it suffices the upper bound on the probability to be 2⁻k. Surprisingly, we show that this reasonable assumption is incorrect, and the probability should be (much) lower than 2⁻k. Our counter example is a related-key differential analysis of the well established block cipher CLEFIA-128. We show that although the key schedule of CLEFIA-128 prevents differentials with a probability higher than 2⁻¹²⁸, the linear part of the key schedule that produces the round keys, and the Feistel structure of the cipher, ...
Impossible differential cryptanalysis has shown to be a very powerful form of cryptanalysis against ...
CAST-128 is a block cipher used in a number of products, notably as the default cipher in some versi...
Recent iterated ciphers have been designed to be resistant to differential cryptanalysis. This impli...
So far, low probability differentials for the key schedule of block ciphers have been used as a stra...
Abstract. So far, low probability differentials for the key schedule of block ciphers have been used...
In this paper we present a new statistical cryptanalytic technique that we call improbable different...
Improbable differential cryptanalysis is a recent attack technique that generalizes impossible diffe...
Improbable differential cryptanalysis is a recent attack technique that generalizes impossible diffe...
Abstract. This paper reports impossible differential cryptanalysis on the 128-bit block cipher CLEFI...
We present a new statistical cryptanalytic technique that we call improbable differential cryptanaly...
Abstract. CLEFIA is a 128-bit block cipher proposed by Sony Corpo-ration in 2007. Our paper introduc...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
We examine the security of the 64-bit lightweight block cipher PRESENT-80 against related-key differ...
In this paper we propose a new differential fault analysis (DFA) on CLEFIA of 128-bit key. The propo...
Impossible differential cryptanalysis has shown to be a very powerful form of cryptanalysis against ...
CAST-128 is a block cipher used in a number of products, notably as the default cipher in some versi...
Recent iterated ciphers have been designed to be resistant to differential cryptanalysis. This impli...
So far, low probability differentials for the key schedule of block ciphers have been used as a stra...
Abstract. So far, low probability differentials for the key schedule of block ciphers have been used...
In this paper we present a new statistical cryptanalytic technique that we call improbable different...
Improbable differential cryptanalysis is a recent attack technique that generalizes impossible diffe...
Improbable differential cryptanalysis is a recent attack technique that generalizes impossible diffe...
Abstract. This paper reports impossible differential cryptanalysis on the 128-bit block cipher CLEFI...
We present a new statistical cryptanalytic technique that we call improbable differential cryptanaly...
Abstract. CLEFIA is a 128-bit block cipher proposed by Sony Corpo-ration in 2007. Our paper introduc...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
Resistance against differential cryptanalysis is an important design criteria for any modern block c...
We examine the security of the 64-bit lightweight block cipher PRESENT-80 against related-key differ...
In this paper we propose a new differential fault analysis (DFA) on CLEFIA of 128-bit key. The propo...
Impossible differential cryptanalysis has shown to be a very powerful form of cryptanalysis against ...
CAST-128 is a block cipher used in a number of products, notably as the default cipher in some versi...
Recent iterated ciphers have been designed to be resistant to differential cryptanalysis. This impli...