Cryptanalysis of reduced-round RC6 without whitening

Atsuko Miyaji, Masao Nonaka · Institutional Repositories DataBase (IRDB) · 2003

We investigate the cryptanalysis of reduced-round RC6 without whitening. Up to now, key recovery algorithms against the reduced-round RC6 itself, the reduced-round RC6 without whitening, and even the simplified variants have been infeasible on a modern computer. In this paper, we propose an efficient and feasible key recovery algorithm against reduced-round RC6 without whitening. Our algorithm is very useful for analyzing the security of the round-function of RC6. Our attack applies to a rather large number of rounds. RC6 without whitening with r rounds can be broken with a success probability of 90% by using 2^ plaintexts. Therefore, our attack can break RC6 without whitening with 17 rounds by using 2^ plaintexts with a probability of 90%.

Read the paper · More papers on PaperTik