## Cryptanalysis of LOKI 91 (1993)

Venue: | Advances in Cryptology, AusCrypt 92, LNCS 718 |

Citations: | 34 - 8 self |

### BibTeX

@INPROCEEDINGS{Knudsen93cryptanalysisof,

author = {Lars Ramkilde Knudsen and Comp Science Dept and Dk- Arhus C},

title = {Cryptanalysis of LOKI 91},

booktitle = {Advances in Cryptology, AusCrypt 92, LNCS 718},

year = {1993},

pages = {196--208},

publisher = {Springer-Verlag}

}

### Abstract

. In this paper we examine the redesign of LOKI, LOKI 91 proposed in [5]. First it is shown that there is no characteristic with a probability high enough to do a successful differential attack on LOKI 91. Secondly we show that the size of the image of the F-function in LOKI 91 is 8 13 \Theta 2 32 . Finally we introduce a chosen plaintext attack that reduces an exhaustive key search on LOKI 91 by almost a factor 4 using 2 33 + 2 chosen plaintexts. 1 Introduction In 1990 Brown et al [4] proposed a new encryption primitive, called LOKI, later renamed LOKI 89, as an alternative to the Data Encryption Standard (DES), with which it is interface compatible. Cryptanalysis showed weaknesses in LOKI 89 [2, 5, 8] and a redesign, LOKI 91 was proposed in [5]. The ciphers from the LOKI family are DES-like iterated block ciphers based on iterating a function, called the F-function, sixteen times. The block and key size is 64 bits. Each iteration is called a round. The input to each round is d...

