Linear cryptanalysis

In cryptography, linear cryptanalysis is a general form of cryptanalysis based on finding affine approximations to the action of a cipher. Attacks have been developed for block ciphers and stream ciphers. Linear cryptanalysis is one of the two most widely used attacks on block ciphers; the other being differential cryptanalysis.

The discovery is attributed to Mitsuru Matsui, who first applied the technique to the FEAL cipher (Matsui and Yamagishi, 1992).[1] Subsequently, Matsui published an attack on the Data Encryption Standard (DES), eventually leading to the first experimental cryptanalysis of the cipher reported in the open community (Matsui, 1993; 1994).[2][3] The attack on DES is not generally practical, requiring 247 known plaintexts.[3]

A variety of refinements to the attack have been suggested, including using multiple linear approximations or incorporating non-linear expressions, leading to a generalized partitioning cryptanalysis. Evidence of security against linear cryptanalysis is usually expected of new cipher designs.

Overview

There are two parts to linear cryptanalysis. The first is to construct linear equations relating plaintext, ciphertext and key bits that have a high bias; that is, whose probabilities of holding (over the space of all possible values of their variables) are as close as possible to 0 or 1. The second is to use these linear equations in conjunction with known plaintext-ciphertext pairs to derive key bits.

Constructing linear equations

For the purposes of linear cryptanalysis, a linear equation expresses the equality of two expressions which consist of binary variables combined with the exclusive-or (XOR) operation. For example, the following equation, from a hypothetical cipher, states the XOR sum of the first and third plaintext bits (as in a block cipher's block) and the first ciphertext bit is equal to the second bit of the key:

In an ideal cipher, any linear equation relating plaintext, ciphertext and key bits would hold with probability 1/2. Since the equations dealt with in linear cryptanalysis will vary in probability, they are more accurately referred to as linear approximations.

The procedure for constructing approximations is different for each cipher. In the most basic type of block cipher, a substitution–permutation network, analysis is concentrated primarily on the S-boxes, the only nonlinear part of the cipher (i.e. the operation of an S-box cannot be encoded in a linear equation). For small enough S-boxes, it is possible to enumerate every possible linear equation relating the S-box's input and output bits, calculate their biases and choose the best ones. Linear approximations for S-boxes then must be combined with the cipher's other actions, such as permutation and key mixing, to arrive at linear approximations for the entire cipher. The piling-up lemma is a useful tool for this combination step. There are also techniques for iteratively improving linear approximations (Matsui 1994).

Deriving key bits

Having obtained a linear approximation of the form:

we can then apply a straightforward algorithm (Matsui's Algorithm 2), using known plaintext-ciphertext pairs, to guess at the values of the key bits involved in the approximation.

For each set of values of the key bits on the right-hand side (referred to as a partial key), count how many times the approximation holds true over all the known plaintext-ciphertext pairs; call this count T. The partial key whose T has the greatest absolute difference from half the number of plaintext-ciphertext pairs is designated as the most likely set of values for those key bits. This is because it is assumed that the correct partial key will cause the approximation to hold with a high bias. The magnitude of the bias is significant here, as opposed to the magnitude of the probability itself.

This procedure can be repeated with other linear approximations, obtaining guesses at values of key bits, until the number of unknown key bits is low enough that they can be attacked with brute force.

See also

References

  1. ^ Matsui, M. & Yamagishi, A. "A new method for known plaintext attack of FEAL cipher". Advances in Cryptology – EUROCRYPT 1992.
  2. ^ Matsui, M. "The first experimental cryptanalysis of the data encryption standard". Advances in Cryptology – CRYPTO 1994.
  3. ^ a b Matsui, M. "Linear cryptanalysis method for DES cipher" (PDF). Advances in Cryptology – EUROCRYPT 1993. Archived from the original (PDF) on 2007-09-26. Retrieved 2007-02-22.

Read other articles:

Ini adalah nama Korea; marganya adalah Seo. Seo In-youngSeo In-young di konferensi pers MasterChef Korea pada April 2012Nama asal서인영LahirSeo In-young3 September 1984 (umur 39)Nama lainEllyPekerjaanPenyanyipenaripemeranperaga busanapemandu acara televisiKarier musikGenreK-popR&BHip HopTahun aktif2002–sekarangLabel Star Empire (2002–2012) IY Company/EB Entertainment (2012–2015) Playtone Entertainment(2015–2016) Star Empire (2016–2017) Soribada (2018-sekarang)&...

Vũ Thu MinhThu MinhInformasi latar belakangNama lahirVũ Thu MinhNama lain Thu Minh Lahir22 September 1977 (umur 46)[1]Hanoi, VietnamAsalHanoiGenrePop, dance, electronicPekerjaanPenyanyi, penari, aktris, pengusahaInstrumenVocalsTahun aktif1993–sekarangLabelTM Solutions (Thu Minh Solutions Company)Situs webwww.thuminh.com Vũ Thu Minh (lahir 22 September 1977)[1] often dikenal sebagai Thu Minh, adalah penyanyi pop asal Vietnam. Dia terkenal dengan musik pop ballads dan ...

November 1996 mid-air plane collision in northern India Saudia Flight 763Kazakhstan Airlines Flight 1907AccidentDate12 November 1996SummaryMid-air collisionSiteCharkhi Dadri, Haryana, India 28°33′38″N 76°18′15″E / 28.56056°N 76.30417°E / 28.56056; 76.30417Total fatalities349Total survivors0First aircraft HZ-AIH, the 747 involved, at London Heathrow, in 1986TypeBoeing 747-168BOperatorSaudi Arabian AirlinesIATA flight No.SV763ICAO flight No.SVA763Call signSAU...

Giải vô địch bóng đá thế giới các câu lạc bộ 2013Giải vô địch bóng đá thế giới các câu lạc bộ 20132013 FIFA Club World Cup LogoChi tiết giải đấuNước chủ nhà MarocThời gian11 tháng 12 – 21 tháng 12Số đội7 (từ 6 liên đoàn)Địa điểm thi đấu2 (tại 2 thành phố chủ nhà)Vị trí chung cuộcVô địch Munich (lần thứ 1)Á quân Hanoi FCHạng ba Atlético MineiroHạng tư...

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (أغسطس 2021) كيبلر 442معلومات عامةالكتلة 0٫61 كتلة شمسية[1] رمز الفهرس KIC 4138008[2]2MASS J19012797+3916482[2]Gaia DR2 2100258047339711488[2] الكوكبة القيثارة الكوكب التابع كيبلر-442b المس...

Carmelitas Descalzas de Nogoyá, en Argentina, que siguen las constituciones de 1990 La Orden de Carmelitas Descalzos fue creada por Santa Teresa en el siglo XVI, con una rama femenina-contemplativa -que viven en monasterios llamados “carmelos”, y una masculina-activa, de los cuales las monjas dependían. En la actualidad hay unos 850 monasterios de carmelitas descalzas en todo el mundo, con 12 mil monjas aproximadamente.[1]​ Luego del Concilio Vaticano II la rama femenina de l...

PT Asuransi Jiwa IFGNama dagangIFG LifeJenisPerseroan terbatasIndustriAsuransiPendahuluAsuransi Jiwasraya (de facto)Didirikan22 Oktober 2020; 3 tahun lalu (2020-10-22)KantorpusatJakarta, IndonesiaWilayah operasiIndonesiaTokohkunciHarjanto Tanuwidjaja[1](Direktur Utama)Rianto Ahmadi[1](Komisaris Utama)ProdukAsuransi jiwaPendapatanRp 28,454 milyar (2021)[2]Laba bersihRp -94,442 milyar (2021)[2]Total asetRp 21,046 triliun (2021)[2]Total ekuitasRp 985,...

Elena Poniatowska 2012 Elena Poniatowska (eigentlich Hélène Elizabeth Louise Amélie Paula Dolores Poniatowska Amor; * 19. Mai 1932 in Paris) ist eine der renommiertesten Schriftstellerinnen und Journalistinnen in Mexiko. Inhaltsverzeichnis 1 Leben 2 Privatleben 3 Preise 4 Werk 4.1 Titel 5 Weiterführende Literatur 5.1 Bücher 5.2 Aufsätze 6 Siehe auch 7 Weblinks 8 Anmerkungen Leben Als Tochter der Mexikanerin Paulette Dolores Amor (deren Familie nach der Enteignung ihrer Ländereien im Zu...

Gerhard Wolf im Jahr 1974 Gerhard Wolf (* 16. Oktober 1928 in Bad Frankenhausen (Kyffh.); † 7. Februar 2023 in Berlin[1][2][3]) war ein deutscher Schriftsteller, Verlagslektor und Verleger. Inhaltsverzeichnis 1 Leben 2 Werke 3 Herausgeberschaft 4 Literatur 5 Weblinks 6 Einzelnachweise Leben Gerhard Wolf war der Sohn eines Buchhalters. Seine Mutter starb, als er zehn Jahre alt war. Er besuchte das Gymnasium in seiner Heimatstadt Bad Frankenhausen. 1944/1945 wurde er a...

2004 film directed by Claire Denis The IntruderFrenchL'intrus Directed byClaire DenisWritten by Claire Denis Jean-Pol Fargeau Based onL'intrusby Jean-Luc NancyProduced byHumbert BalsanStarring Michel Subor Béatrice Dalle Alex Descas CinematographyAgnès GodardEdited byNelly QuettierMusic byStuart A. StaplesRelease dates 9 September 2004 (2004-09-09) (Venice) 4 May 2005 (2005-05-04) (France) Running time130 minutesCountryFranceLanguages French English Kor...

Bagian dari seri tentangGereja KatolikBasilika Santo Petrus, Kota Vatikan Ikhtisar Paus (Fransiskus) Hierarki Sejarah (Lini Masa) Teologi Liturgi Sakramen Maria Latar Belakang Yesus Penyaliban Kebangkitan Kenaikan Gereja Perdana Petrus Paulus Bapa-Bapa Gereja Sejarah Gereja Katolik Sejarah Lembaga Kepausan Konsili Ekumene Magisterium Empat Ciri Gereja Satu Gereja Sejati Suksesi Apostolik Organisasi Takhta Suci Kuria Romawi Dewan Kardinal Konsili Ekumene Lembaga Keuskupan Gereja Latin Gereja-G...

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Februari 2023. Danau UlungurSatellite viewDanau UlungurLetakKabupaten Fuhai, XinjiangKoordinat47°15′00″N 87°15′00″E / 47.25000°N 87.25000°E / 47.25000; 87.25000Koordinat: 47°15′00″N 87°15′00″E / 47.25000...

artikel ini perlu dirapikan agar memenuhi standar Wikipedia. Tidak ada alasan yang diberikan. Silakan kembangkan artikel ini semampu Anda. Merapikan artikel dapat dilakukan dengan wikifikasi atau membagi artikel ke paragraf-paragraf. Jika sudah dirapikan, silakan hapus templat ini. (Pelajari cara dan kapan saatnya untuk menghapus pesan templat ini) Selamat Pagi, MalamPoster film 'Selamat Pagi, Malam'Sutradara Lucky Kuswandi Produser Sharon Simanjuntak Sammaria Simanjuntak Ditulis oleh Lucky K...

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (يوليو 2019) مقياس غلاسكو للنتائج (بالإنجليزية: Glasgow Outcome Scale)‏ هو مقياس للمرضى الذين يعانون من إصابات في المخ، مثل الصدمات الدماغية التي تجمع مجموعة من الضحايا حسب درجة ا...

156 Light Air Defence Missile Regiment (Self Propelled)Active1982 – presentCountry IndiaAllegianceIndiaBranch Indian ArmyTypeCorps of Army Air DefenceSizeRegimentNickname(s)“The Only Ones”Motto(s)Nulli Secundus (Latin for Second to None)ColorsSky Blue and RedEquipmentStrela-10MInsigniaAbbreviation156 Lt AD Msl Regt (SP)Military unit 156 Light Air Defence Missile Regiment (Self Propelled) is an Air Defence regiment of the Indian Army. Formation The regiment was raised at Kamptee on 01 Ma...

2014 film by Vamshi Paidipally YevaduTheatrical release posterDirected byVamshi PaidipallyScreenplay byVamshi Paidipally Dialogues byAbburi Ravi Story byVakkantham VamsiVamshi PaidipallyProduced byDil RajuStarringRam CharanAllu ArjunShruti HaasanAmy JacksonKajal AggarwalCinematographyC. RamprasadEdited byMarthand K. VenkateshMusic byDevi Sri PrasadProductioncompanySri Venkateswara CreationsRelease date 12 January 2014 (2014-01-12)[1] Running time166 minutesCountryIndiaL...

County in Markazi province, Iran For the city, see Shazand. County in Markazi, IranShazand County Persian: شهرستان شازندCountyShazandLocation of Shazand County in Markazi province (bottom left, purple)Location of Markazi province in IranCoordinates: 33°54′N 49°20′E / 33.900°N 49.333°E / 33.900; 49.333[1]Country IranProvinceMarkaziCapitalShazandDistrictsCentral, Qarah Kahriz, Sarband, ZalianPopulation (2016)[2]...

British playwright and pageant maker Mary Elfreda Kelly OBE (25 March 1888 – 5 November 1951) was a British playwright, pageant maker and founder of the Village Drama Society in 1919. Her family home was Kelly House in the village of Kelly, Devon. Early life Kelly House and church, Kelly, Devon. Home of Mary Kelly Mary Kelly was born at Salcombe vicarage in Devon on 25 March 1888 to the Reverend Maitland Kelly and his second wife Elfreda Blanche Carey. She was educated at home by a governes...

612

612 ← 611 612 613 → 数表 — 整数 <<  610 611 612  613‍  614‍  615‍ 616  617‍ 618  619‍ >> <<  600 610 620 630  640‍ 650  660‍  670‍  680‍  690‍ >> 命名數字612小寫六百一十二大寫陸佰壹拾貳序數詞第六百一十二six hundred and twelfth識別種類整數性質質因數分解 {\...

Indian television actor This biography of a living person needs additional citations for verification. Please help by adding reliable sources. Contentious material about living persons that is unsourced or poorly sourced must be removed immediately from the article and its talk page, especially if potentially libelous.Find sources: Pankit Thakker – news · newspapers · books · scholar · JSTOR (July 2010) (Learn how and when to remove this template messa...