On linear hulls in one round of DES

T Ashur, R Posteuca - Cryptology ePrint Archive, 2018 - eprint.iacr.org
… In this paper we extend the study regarding one-round linear hulls introduced in [7]. In the
first … In this section we prove the existence of one-round hulls in DES, which might impact the …

Linear (hull) and algebraic cryptanalysis of the block cipher PRESENT

J Nakahara, P Sepehrdad, B Zhang… - Cryptology and Network …, 2009 - Springer
… In this paper we deploy ElimLin algorithm proposed by Courtois against DES [9… round
linear hull to a 17-round linear hull with 93 17-round linear trails by choosing an additional 1-round

On linear hulls and trails

T Ashur, V Rijmen - Progress in Cryptology–INDOCRYPT 2016: 17th …, 2016 - Springer
… cryptanalysis is introduced by Matsui and applied to DES in [11]. The formalism of … We
prove the existence of one-round hulls, which impact the computation of correlations of multi-…

Cryptanalysis of the Full DES and the Full 3DES using a new linear property

T Ashur, R Posteuca - Cryptology ePrint Archive, 2018 - eprint.iacr.org
… label “poisonous round” for a one-round linear hull that leads, … A trail containing at least one
“poisonous” round is called a “… round, we used a 1-round linear hull for the ffunction of DES. …

Linear hulls with correlation zero and linear cryptanalysis of block ciphers

A Bogdanov, V Rijmen - Designs, codes and cryptography, 2014 - Springer
… key-recovery attacks based on Algorithm 1 and two of those zero-correlation linear hulls. …
In our attack, the 9-round zero-correlation linear hull covers rounds 3 to 11. The procedure …

Improved Linear Hull Attack on Round-Reduced Simon with Dynamic Key-Guessing Techniques

H Chen, X Wang - … Encryption: 23rd International Conference, FSE 2016 …, 2016 - Springer
… method proposed in 1993 to cryptanalysis DES. At first, … 13-round linear hull distinguisher,
we give the 21-round linear attack on Simon32 / 64. The estimated potential of the linear hull is …

New linear trails and linear hulls of CHAM

D Roh - IEEE Access, 2024 - ieeexplore.ieee.org
… -round linear hull with potential greater than 2−61.793 of CHAM with 64-bit blocks and a
54-round linear hull … To the best of our knowledge, they are the first known linear hulls of CHAM. …

Improved linear (hull) cryptanalysis of round-reduced versions of SIMON

D Shi, L Hu, S Sun, L Song, K Qiao, X Ma - Cryptology ePrint Archive, 2014 - eprint.iacr.org
… In this paper, we investigate linear characteristics with consideration of dependence of the
S-boxes of the bitwise AND operation with dependent input bits. By the methods of automatic …

More on linear hulls of PRESENT-like ciphers and a cryptanalysis of full-round EPCBC-96

S Bulygin - Cryptology ePrint Archive, 2013 - eprint.iacr.org
… ” is true for the case of DES [17]. The reason lies again in the structure of the key schedule
of DES: it is not only linear, but actually subkey bits of the round keys are always some master …

Linear (hull) cryptanalysis of round-reduced versions of KATAN

D Shi, L Hu, S Sun, L Song - International Conference on Information …, 2016 - scitepress.org
… ignoring the dependence of the S-box based on the Mixed-integer linear programming(…
round linear hulls on KATAN32/48/64 respectively are proposed. Moreover, 131/120/94-round