Cryptanalysis of LOKI91

  • Lars Ramkilde Knudsen


In this paper we examine the redesign of LOKI, LOKI91 proposed by Brown et al. First it is shown that there is no characteristic with a probability high enough to do a successful differential attack on LOKI91. Secondly we show that the size of the image of the F-function in LOKI91 is 8\22*2^32. Finally we introduce a chosen plaintext attack that reduces an exhaustive key search on LOKI91 by almost a factor 4 using 2^33+2 chosen plaintexts.
How to Cite
Knudsen, L. (2003). Cryptanalysis of LOKI91. DAIMI Report Series, 22(440).