The results of this paper give the theoretical fundaments on which Matsui’s linear cryptanalysis of the DES is based. As a result we obtain precise information on the assumptions explicitely or implicitely stated in [2] and show that the success of Algorithm 2 is underestimated in [2]. We also derive a formula for the strength of Algorithm 2 for DES-like ciphers and see what is its dependence on the plaintext distribution. Finally, it is shown how to achieve proven resistance against linear cryptanalysis.
CITATION STYLE
Nyberg, K. (1995). Linear approximation of block ciphers. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 950, pp. 439–444). Springer Verlag. https://doi.org/10.1007/bfb0053460
Mendeley helps you to discover research relevant for your work.