๐”– Bobbio Scriptorium
โœฆ   LIBER   โœฆ

Differential cryptanalysis of RC5

โœ Scribed by Knudsen, Lars R. ;Meier, Willi


Publisher
John Wiley and Sons
Year
1997
Tongue
English
Weight
1001 KB
Volume
8
Category
Article
ISSN
1124-318X

No coin nor oath required. For personal study only.

โœฆ Synopsis


In this paper we investigate the strength of the secret-key algorithm RC5 proposed by Ron Rivest. The target version of RC5 works on words of 32 bits, has 12 rounds and a user-selected key of 128 bits. Kaliski and Yin estimated the strength of RC5 by differential and linear cryptanalysis. They conjectured that their linear analysis is optimal and that the use of 12 rounds for RC5 is sufficient to make both differential and linear cryptanalysis impractical. In this paper we show that the differential analysis made by Kaliski and Yin is not optimal. We give differential attacks better by up to a factor of 512. Also we show that RC5 has many weak keys with respect to differential attacks. This weakness relies on the structure of the cipher and not on the key schedule. Finally we discuss some possible extensions of our attacks and some modifications of RC5 in order to improve the resistance against our differential attacks Vol. X. No.


๐Ÿ“œ SIMILAR VOLUMES


Linear and Differential Cryptanalysis of
โœ Vitaly V. Shorin; Vadim V. Jelezniakov; Ernst M. Gabidulin ๐Ÿ“‚ Article ๐Ÿ“… 2001 ๐Ÿ› Elsevier Science ๐ŸŒ English โš– 470 KB

In this paper the linear cryptanalysis and the di erential cryptanalysis of the Russian GOST encryption algorithm are carried out. It is shown that GOST is secure against the linear cryptanalysis after ve rounds and against the di erential cryptanalysis after seven rounds. The di erential analysis a

Bovine RC5 effort
โœ Barbara Gengler ๐Ÿ“‚ Article ๐Ÿ“… 1997 ๐Ÿ› Elsevier Science ๐ŸŒ English โš– 248 KB