<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>2008 Reports</title>
    <link>http://eprint.iacr.org/forum/list.php?8</link>
    <description><![CDATA[Discussion forum for Cryptology ePrint Archive reports posted in 2008.
Please put the report number in the subject.

]]></description>
    <language>EN</language>
    <pubDate>Fri, 18 Jul 2008 01:45:32 -0600</pubDate>
    <lastBuildDate>Fri, 18 Jul 2008 01:45:32 -0600</lastBuildDate>
    <category>2008 Reports</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>Birthday attack of DES: clearity of step 2 of 4</title>
      <link>http://eprint.iacr.org/forum/read.php?8,57,57#msg-57</link>
      <author>prasanth.thandra</author>
      <description><![CDATA[.. I hope you can help me in understanding your paper.

 

in the description of attack, in step 2 (of 4) computing the candidate for each K16[j],

 

 

S[j](EL16[j]XORa)=?S[j](EL'16[j]XORa) ---------(1)
                                                        has to be checked out forall j belongd to the set{1,2,3,4,5,6,7,8} and where &quot;a&quot; belongs to the set{0,1,2,3....63}

also, clearly EL16[ j ] NOT = EL'16[ j ]:

dose the above statement means

by changing the values of &quot;a&quot; for each S-box we have to check whether LHS of (1) are equal to RHS or not 

If LHS=RHS that particular choice of K16[j] is correct;

If such equality of LHS and RHS are not found with any possibility of &quot;a&quot;, then that choice of Ciphertext pairs has to be neglected and 

new pair of Cipher texts has to be chosen to implement.


is the above explenation to step2 of 4 is correct or not ???????????????

Thanking you.]]></description>
      <category>2008 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?8,57,57#msg-57</guid>
      <pubDate>Fri, 18 Jul 2008 01:45:32 -0600</pubDate>
    </item>
  </channel>
</rss>
