Iterative Characteristics of DES and S^2-DES

Forfattere

  • Lars Ramkilde Knudsen

DOI:

https://doi.org/10.7146/dpb.v22i439.6756

Resumé

In this paper we show that we are close at the proof that the type of characteristics used by Biham and Shamir in their differential attack on DES are in fact the best characteristics we can find for DES. Furthermore we show that the criteria for the construction of DES-like S-boxes proposed by Kim are insufficient to assure resistance against differential attacks. We show several good iterative characteristics for these S-boxes to be used in differential attacks. Finally we examine the probabilities of the two characteristics used by Biham and Shamir. We found that for some keys we do not get the probabilities used in the attack. We suggest the use of 5 characteristics instead of two in the attack on DES.

Forfatterbiografi

Lars Ramkilde Knudsen

Downloads

Publiceret

1993-05-01

Citation/Eksport

Knudsen, L. R. (1993). Iterative Characteristics of DES and S^2-DES. DAIMI Report Series, 22(439). https://doi.org/10.7146/dpb.v22i439.6756