## Unified Impossible Differential Cryptanalysis on Block Cipher Structures

In this paper, we propose a systematic search method for finding the impossible differential characteristic for block cipher structures, better than the U-method introduced by Kim et al [6]. This method is referred as unified impossible differential (UID) cryptanalysis. We give practical UID cryptanalysis on some popular block ciphers and give the detailed impossible differential characteristics. On the generalized CAST-256 and generalized MARS block cipher structure, our results are better than the U-method. On the Four-Cell, FOX64, our results are the same as previous best manual works. Thus UID method can be used as a tool for examining the security of a block cipher structure against impossible differential cryptanalysis. 1

Citation Context ...Gen RC6[8] 4 9 round {0, 0, x, 0} ↛9 {0, y, 0, 0} [6] SMS4[13] 4 11 round {x, x, x, 0} ↛11 {0, x, x, x} [7] FOX64[5] 8 4 round {0, x, 0, x, 0, x, 0, x} ↛4 {y1, y2, y1, y3, y1, y2, y1, y3} the same as =-=[11]-=- In Table 4, the UID result on Four-Cell is the same as [12] and the UID result on FOX64 is the same as [11]. In [6], Kim et al. present a 15-round impossible differential characteristics on Gen CAST-... |