8 citations found. Retrieving documents...
L. R. Knudsen and D. Wagner. Integral cryptanalysis. These Proceedings.

 Home/Search   Document Details and Download   Summary   Related Articles   Check  

This paper is cited in the following contexts:
Impossible Differential Attacks on Reduced-Round SAFER.. - Nakahara, Jr.. (2002)   (Correct)

....128 down to 104 key bits. The data, memory and time complexities are the same as for the attack on SAFER 128. 6 Square Attacks on SAFER Ciphers In [4] Knudsen described Square attacks on 3.25 round SAFER ciphers. For SAFER K SK, using the modular addition in ZZ 256 as the notion of integral [5], a set pattern [3] consisting of the rst seven plaintext bytes constant, and the 8th byte assuming all possible 8 bit values (active) will cause the rst text byte after 2.75 rounds to be active, too. This property can be used to recover four key bytes K 6 , because the additive bytes can ....

L.R. Knudsen and D. Wagner. Integral Cryptanalysis. In J. Daemen and V. Rijmen, editors, 9th Fast Software Encryption Workshop, LNCS 2365, pages 112-127. SpringerVerlag, 2002.


Impossible Differential Attacks on Reduced-Round SAFER.. - Nakahara, Jr..   (Correct)

....128 down to 104 key bits. The data, memory and time complexities are the same as for the attack on SAFER 128. 6 Square Attacks on SAFER Ciphers In [5] Knudsen described a Square attack (although not with this name) on 3. 25 round SAFER K SK, using the addition in ZZ 256 as the notion of integral [6]. A # set pattern [4] consists of the first seven plaintext bytes fixed, and the 8th byte assuming all possible 8 bit values (active) It will cause the first text byte after 2.75 rounds to be active. This property can be used to recover four subkeys K 6 , because the additive subkeys can be ....

L.R. Knudsen and D. Wagner. Integral Cryptanalysis. In J. Daemen and V. Rijmen, editors, 9th Fast Software Encryption Workshop, LNCS 2365, pages 112--127. Springer-Verlag, 2002.


Integral Cryptanalysis on reduced-round Safer++ - A way to.. - Piret, Quisquater (2003)   (Correct)

....however, S. Lucks applied the square technique to a non square like cipher, namely Twofish[7] This way he managed to break up to eight rounds of Twofish, which is at present the best known attack on it. Since then, it was applied to many other algorithms: IDEA[5] Camellia[10] Skipjack[4] Misty[6], In this paper, we will apply the integral cryptanalysis technique to the Safer algorithm. Although the di#usion layer of this cipher is not very strong (more precisely, it has a small branch number) the best known attack on it is a linear cryptanalysis against weak key classes breaking 3 ....

L. Knudsen and D. Wagner. Integral cryptanalysis. In J. Daemen and V. Rijmen, editors, Fast Software Encryption (FSE '02), pages 112--127, Berlin, 2002. SpringerVerlag. Lecture Notes in Computer Science Volume 2365.


NESSIE D13 - Security Evaluation of NESSIE First Phase - Preneel, Van Rompay.. (2001)   (Correct)

....texts, where m is the block size. Integral Attacks This type of attack is sometimes referred to as the square attack , since it was first applied to the block cipher Square [32, 33] Slightly modified versions of the attack on Square also apply to the block ciphers Crypton and Rijndael [34] In [76], these attacks are generalised under the name integral cryptanalysis: in di#erential attacks one considers di#erences of texts, while in integral cryptanalysis one considers sums of texts. This attack is still currently the best attack reported on the AES block cipher Rijndael. The block cipher ....

L. R. Knudsen and D. Wagner. Integral cryptanalysis. In preparation, 2001.


Non-random properties of reduced-round Whirlpool - Knudsen (2002)   Self-citation (Knudsen)   (Correct)

....European Union fund IST 1999 12324 Nessie. The information in this document is provided as is, and no warranty is given or implied that the information is fit for any particular purpose. The user thereof uses the information at its sole risk and liability. structure has been called an integral [3]. Also, note that there are 63 other similar structures, since the position of non constant byte in the plaintexts can be in any of the 64 positions. Next we give some notation for integrals for Whirlpool. An integral with the terms is a collection of 2 texts. j means that in the ....

L.R. Knudsen and D. Wagner. Integral cryptanalysis. Proceedings from FSE 2002. LNCS 2365, Springer Verlag.


Improved Cryptanalysis of MISTY1 - Ulrich Kuhn Dresdner (2002)   (1 citation)  (Correct)

No context found.

L. R. Knudsen and D. Wagner. Integral cryptanalysis. These Proceedings.


Survey and Benchmark of Block Ciphers for Wireless Sensor.. - Law, Doumen, Hartel   (Correct)

No context found.

Knudsen, L., Wagner, D.: Integral cryptanalysis. In Daemen, J., Rijmen, V., eds.: Fast Software Encryption, 9th International Workshop, FSE 2002. Volume 2365 of LNCS., Springer-Verlag (2002) 112--127


The MESH Block Ciphers - Jorge Nakahara Jr (2002)   (Correct)

No context found.

Knudsen,L.R., Wagner,D.: Integral Cryptanalysis, In: Daemen, J., Rijmen,V. (eds): 9th Fast Software Encryption Workshop, LNCS, Vol. 2365. Springer-Verlag (2002), 112--127.

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC