Integral and multidimensional linear distinguishers with correlation zero

  • Authors:
  • Andrey Bogdanov;Gregor Leander;Kaisa Nyberg;Meiqin Wang

  • Affiliations:
  • ESAT/SCD/COSIC and IBBT, KU Leuven, Belgium;Technical University of Denmark, Denmark;Aalto University, Finland;Key Laboratory of Cryptologic Technology and Information Security, Ministry of Education, Shandong University, Jinan, China

  • Venue:
  • ASIACRYPT'12 Proceedings of the 18th international conference on The Theory and Application of Cryptology and Information Security
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Zero-correlation cryptanalysis uses linear approximations holding with probability exactly 1/2. In this paper, we reveal fundamental links of zero-correlation distinguishers to integral distinguishers and multidimensional linear distinguishers. We show that an integral implies zero-correlation linear approximations and that a zero-correlation linear distinguisher is actually a special case of multidimensional linear distinguishers. These observations provide new insight into zero-correlation cryptanalysis which is illustrated by attacking a Skipjack variant and round-reduced CAST-256 without weak key assumptions.