Lǚ Shuwang, Zhang Ruwen. Linear cryptanalysis for a class of feistel ciphers[J]. Journal of Electronics & Information Technology, 2003, 25(9): 1237-1242.
Citation:
Lǚ Shuwang, Zhang Ruwen. Linear cryptanalysis for a class of feistel ciphers[J]. Journal of Electronics & Information Technology, 2003, 25(9): 1237-1242.
Lǚ Shuwang, Zhang Ruwen. Linear cryptanalysis for a class of feistel ciphers[J]. Journal of Electronics & Information Technology, 2003, 25(9): 1237-1242.
Citation:
Lǚ Shuwang, Zhang Ruwen. Linear cryptanalysis for a class of feistel ciphers[J]. Journal of Electronics & Information Technology, 2003, 25(9): 1237-1242.
In this paper, a new method is proposed for seeking the upper bounds of maximum linear bias for block ciphers, which is especially applicable to a class of Feistel ciphers that key is XORed with data. This technique consists of two steps. Firstly, the mathematical relationship between linear bias of ciphers and linear bias of round function F and S-box respectively is given by carrying out strictly mathematical expression of linear bias for ciphers. Next, the upper bounds of linear bias for ciphers are determined by seeking the solution with minimum weight for linear equation group. Using this method the upper bounds of linear bias within 32 rounds are given.
M. Matsui.[J].Linear cryptanalysis method for DES ciper, Advances in Cryptology-Eurocrypt93,Berlin: Springer- Verlag.1993,:-[2]M. Kanda, Y. Takashima, T. Matsumoto, A strategy for constructing fast round function with practical security against differential and linear cryptanalysis, Selected Areas in Cryptography,Lecture Notes of Computer Science 1556, Springer-Verlag, 1999, 264-279.[3]M. Kanda, Practical security evaluation against differential and linear attacks for Feistel ciphers with SPN round function, Selected Areas in Cryptography, Lecture Notes of Computer Science 2012, Springer-Verlag, 2000, 324-338.