2008
DOI: 10.1007/978-3-540-89754-5_24
|View full text |Cite
|
Sign up to set email alerts
|

A Differential-Linear Attack on 12-Round Serpent

Abstract: Serpent is an SP Network block cipher submitted to the AES competition and chosen as one of its five finalists. The security of Serpent is widely acknowledged, especially as the best known attack so far is a differential-linear attack on only 11 rounds out of the 32 rounds of the cipher. In this paper we introduce a more accurate analysis of the differentiallinear attack on 11-round Serpent. The analysis involves both theoretical aspects as well as experimental results which suggest that previous attacks had o… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
41
0

Year Published

2013
2013
2021
2021

Publication Types

Select...
7

Relationship

0
7

Authors

Journals

citations
Cited by 38 publications
(41 citation statements)
references
References 16 publications
0
41
0
Order By: Relevance
“…The various linear, differential-linear and multidimensional linear attacks on reduced-round Serpent fall into two categories; those based on Collard et al's approximations [11,12,13,30] and those based on the approximation of Dunkelman, Keller et al [2,4,20]. In Appendix A, we point out a few errors in the existing descriptions of Dunkelman et al's approximation.…”
Section: Survey Of Existing Attacksmentioning
confidence: 99%
See 3 more Smart Citations
“…The various linear, differential-linear and multidimensional linear attacks on reduced-round Serpent fall into two categories; those based on Collard et al's approximations [11,12,13,30] and those based on the approximation of Dunkelman, Keller et al [2,4,20]. In Appendix A, we point out a few errors in the existing descriptions of Dunkelman et al's approximation.…”
Section: Survey Of Existing Attacksmentioning
confidence: 99%
“…In Indesteege et al's chosen-ciphertext attack on 11-round Serpent [20], two active plaintext boxes (both Serpent S4) contribute bit y 4 to the attack. Since three input differences cause this bit to flip with bias ±0.5, the attack recovers 56 key bits instead of 60.…”
Section: Survey Of Existing Attacksmentioning
confidence: 99%
See 2 more Smart Citations
“…The data and time complexities of these attacks are reduced in [17] by using the following improvements:…”
Section: Differential-linear Attacks On Serpentmentioning
confidence: 99%