The Complete Distribution of Linear Probabilities of MARS' s-box

Kazumaro Aoki

Abstract: This paper shows the complete linear probability distribution of MARS' s-box. The best bias is $\dfrac{84}{2^9}$ ($=2^{-2.61}$), while the designers' estimation is $\dfrac{64}{2^9}$ and the best previously known bias is $\dfrac{82}{2^9}$.

Category / Keywords: secret-key cryptography / AES, block ciphers, linear cryptanalysis, MARS

Date: received 29 Jun 2000, last revised 4 Mar 2009

Contact author: maro at isl ntt co jp

Version: 20090305:060109 (All versions of this report)

