In this paper, we find linear equations of SPECTR-H64 using the property of controlled permutation boxes. Also, we construct the fourth-order differential structure using the property that the algebraic degree of the function G is 3, which is the only non-linear part of SPECTR-H64. These linear equations and structures enable us to attack the reduced 6 round SPECTR-H64. So, we can recover the 6-th round subkey with about 244 chosen plaintexts and 2229.6 steps which are lower than the exhaustive search 2256. © Springer-Verlag Berlin Heidelberg 2003.
CITATION STYLE
Ko, Y., Hong, D., Hong, S., Lee, S., & Lim, J. (2003). Linear cryptanalysis on SPECTR-H64 with higher order differential property. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2776, 298–307. https://doi.org/10.1007/978-3-540-45215-7_25
Mendeley helps you to discover research relevant for your work.