2003
DOI: 10.1016/s0020-0190(03)00333-8
|View full text |Cite
|
Sign up to set email alerts
|

Differential and linear cryptanalysis for 2-round SPNs

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
13
0

Year Published

2005
2005
2023
2023

Publication Types

Select...
6
2
1

Relationship

0
9

Authors

Journals

citations
Cited by 15 publications
(13 citation statements)
references
References 1 publication
0
13
0
Order By: Relevance
“…This result has then been refined in [9,21,8]. The bounds in [15,9,21] are invariant under affine equivalence, i.e., their values are the same for two Sboxes S and S when there exist two affine permutations A 1 and A 2 such that S = A 1 •S•A 2 .…”
Section: Expected Probability Of a 2-round Differentialmentioning
confidence: 99%
See 1 more Smart Citation
“…This result has then been refined in [9,21,8]. The bounds in [15,9,21] are invariant under affine equivalence, i.e., their values are the same for two Sboxes S and S when there exist two affine permutations A 1 and A 2 such that S = A 1 •S•A 2 .…”
Section: Expected Probability Of a 2-round Differentialmentioning
confidence: 99%
“…The bounds in [15,9,21] are invariant under affine equivalence, i.e., their values are the same for two Sboxes S and S when there exist two affine permutations A 1 and A 2 such that S = A 1 •S•A 2 . However, the exact values of MEDP 2 may differ for Sboxes in the same equivalent class, and there can be a gap between these bounds and the exact value of MEDP 2 .…”
Section: Expected Probability Of a 2-round Differentialmentioning
confidence: 99%
“…From DDT table, when input difference is 1011(B), output difference 0010(2) occurs eight times with probability 8/16 as we have 16 possible combinations. So, we get probability 8/16 from round 1 [9]. Output of round 1 is fed as input to the round 2.…”
Section: Constructing Differential Characteristicsmentioning
confidence: 99%
“…[41,14] Let E be a block cipher of the form SPN(m, t, S, M ) where M is a linear permutation with differential (resp. linear) branch number d (resp.…”
Section: Theorem 1 (Fse 2003 Bounds)mentioning
confidence: 99%