A Linear Annihilator Property and Strong Biases with Original DES S-boxes
In 2004 I have published a paper [Crypto 2004, Santa Barbara] in which I explain the concept of the so called Bi-Linear attack on DES. The old attack was not extremely strong. It is possible to see that two conditions would be necessary for such an attack to somewhat work well in cryptanalysis of DES: There …
Continue reading ‘A Linear Annihilator Property and Strong Biases with Original DES S-boxes’ »