Cryptanalysis of the Full DES and the Full 3DES Using a New Linear Property

Tomer Ashur and Raluca Posteuca


In this paper we extend the work presented by Ashur and Posteuca in BalkanCryptSec 2018, by designing 0-correlation key-dependent linear trails covering more than one round of DES. First, we design a 2-round 0-correlation key-dependent linear trail which we then connect to Matsui's original trail in order to obtain a linear approximation covering the full DES and 3DES. We show how this approximation can be used for a key recovery attack against both ciphers. To the best of our knowledge, this paper is the first to use this kind of property to attack a symmetric-key algorithm, and our linear attack against 3DES is the first statistical attack against this cipher.

linear cryptanalysisDES3DESpoisonous hull
raluca posteuca @ esat kuleuven be
2018-12-30: received
