Lagrange Interpolation Attack against 6 Rounds of Rijndael-128

Jingmei Liu, Shaopeng Chen, Linsen Zhao · 2013

By chosing all the 232 plaintexts of the four bytes in the first round, it can generate 224 Λ1sets. Each Λ1set will make all the input bytes balanced in the fifth round, so all the 232 input plaintexts will be balanced before the fifth round. If we combine partial sum technique, the Lagrange interpolation attack can be completed. The research results show that the attacking complexity can be decreased to 250, and it is better than the best of the existing result which is 272.

Read the paper · More papers on PaperTik