On the additive differential probability of exclusive-or

28Citations
Citations of this article
39Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

We study the differential probability adp⊕ of exclusive-or when differences are expressed using addition modulo 2N. This function is important when analysing symmetric primitives that mix exclusive-or and addition - especially when addition is used to add in the round keys. (Such primitives include IDEA, Mars, RC6 and Twofish.) We show that adp⊕ can be viewed as a formal rational series with a linear representation in base 8. This gives a linear-time algorithm for computing adp⊕, and enables us to compute several interesting properties like the fraction of impossible differentials, and the maximal differential probability for any given output difference. Finally, we compare our results with the dual results of Lipmaa and Moriai on the differential probability of addition modulo 2N when differences are expressed using exclusive-or. © International Association for Cryptologic Research 2004.

Cite

CITATION STYLE

APA

Lipmaa, H., Wallén, J., & Dumas, P. (2004). On the additive differential probability of exclusive-or. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 3017, 317–331. https://doi.org/10.1007/978-3-540-25937-4_20

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free