## On the complexity of Matsui’s attack (2001)

Venue: | in Selected Areas in Cryptography, SAC 2001 |

Citations: | 12 - 2 self |

### BibTeX

@INPROCEEDINGS{Junod01onthe,

author = {Pascal Junod},

title = {On the complexity of Matsui’s attack},

booktitle = {in Selected Areas in Cryptography, SAC 2001},

year = {2001},

pages = {199--211},

publisher = {Springer-Verlag}

}

### Years of Citing Articles

### Abstract

Abstract. Linear cryptanalysis remains the most powerful attack against DES at this time. Given 2 43 known plaintext-ciphertext pairs, Matsui expected a complexity of less than 2 43 DES evaluations in 85 % of the cases for recovering the key. In this paper, we present a theoretical and experimental complexity analysis of this attack, which has been simulated 21 times using the idle time of several computers. The experimental results suggest a complexity upper-bounded by 2 41 DES evaluations in 85 % of the case, while more than the half of the experiments needed less than 2 39 DES evaluations. In addition, we give a detailed theoretical analysis of the attack complexity.

