## Truncated Differentials and Skipjack (1999)

Venue: | Advances in Cryptology: CRYPTO’99, LNCS 1666 |

Citations: | 11 - 4 self |

@INPROCEEDINGS{Knudsen99truncateddifferentials,

author = {Lars R. Knudsen and M. J. B. Robshaw and David Wagner},

title = {Truncated Differentials and Skipjack},

booktitle = {Advances in Cryptology: CRYPTO’99, LNCS 1666},

year = {1999},

pages = {165--180},

publisher = {Springer Verlag}

}

### Abstract

Abstract. We consider a range of attacks on reduced-round variants of the block cipher Skipjack. In particular we concentrate on the role of truncated differentials and consider what insight they give us into the design and long-term security of Skipjack. An attack on the full 32 rounds of Skipjack remains elusive. However we give attacks on the first 16 rounds of Skipjack that can efficiently recover the key with about 2 17 chosen plaintexts and an attack on the middle sixteen rounds of Skipjack which recovers the secret key using only two chosen plaintexts. Several highprobability truncated differentials are presented the existence of which might best be described as surprising. Most notably, we show that the techniques used by Biham et al. can be presented in terms of truncated differentials and that there exists a 24-round truncated differential that holds with probability one. 1

