Paper 2018/1219

Cryptanalysis of the Full DES and the Full 3DES Using a New Linear Property

Tomer Ashur and Raluca Posteuca


In this paper we extend the work presented by Ashur and Posteuca in BalkanCryptSec 2018, by designing 0-correlation key-dependent linear trails covering more than one round of DES. First, we design a 2-round 0-correlation key-dependent linear trail which we then connect to Matsui's original trail in order to obtain a linear approximation covering the full DES and 3DES. We show how this approximation can be used for a key recovery attack against both ciphers. To the best of our knowledge, this paper is the first to use this kind of property to attack a symmetric-key algorithm, and our linear attack against 3DES is the first statistical attack against this cipher.

Available format(s)
Secret-key cryptography
Publication info
Preprint. MINOR revision.
linear cryptanalysisDES3DESpoisonous hull
Contact author(s)
raluca posteuca @ esat kuleuven be
2018-12-30: received
Short URL
Creative Commons Attribution


      author = {Tomer Ashur and Raluca Posteuca},
      title = {Cryptanalysis of the Full DES and the Full 3DES Using a New Linear Property},
      howpublished = {Cryptology ePrint Archive, Paper 2018/1219},
      year = {2018},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.