Paper 2018/635

On linear hulls in one round of DES

Tomer Ashur and Raluca Posteuca


At Indocrypt 2016, Ashur et al. showed that linear hulls are sometimes formed in a single round of a cipher (exemplifying on Simon ciphers) and showed that the success rate of an attack may be influenced by the quality of the estimation of one-round correlations. This paper improves the understanding regarding one-round linear hulls and trails, being dedicated to the study of one-round linear hulls of the DES cipher, more exactly of its $f$-function. It shows that, in the case of DES, the existence of one-round hulls is related to the number of active Sboxes and its correlation depends on a fixed set of key bits. All the ideas presented in this paper are followed by examples and are verified experimentally.

Available format(s)
Secret-key cryptography
Publication info
Preprint. MINOR revision.
DESLinear CryptanalysisLinear Hulls
Contact author(s)
raluca posteuca @ esat kuleuven be
2018-07-03: received
Short URL
Creative Commons Attribution


      author = {Tomer Ashur and Raluca Posteuca},
      title = {On linear hulls in one round of DES},
      howpublished = {Cryptology ePrint Archive, Paper 2018/635},
      year = {2018},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.