Linear Cryptanalysis of Simplified AES Under Change of S-Box

Samantha Campbell, Max Grinchenko, William Paul Smith · Cryptologia · 2013

The Simplified Advanced Encryption Standard, or S-AES, was introduced by Musa, Schaefer, and Wedig [10], in part, to show how to find linear equations for use in linear cryptanalysis. We review their methods and then consider how the choice of S-box affects the success of a greedy linear cryptanalysis algorithm devised for one-round S-AES. We characterize a class of highly non-linear S-boxes for which our algorithm is always successful; we analyze the strange phenomena that occur when S-boxes with linear features are considered; and we show how to construct S-boxes that foil our linear cryptanalysis algorithm completely.

Read the paper · More papers on PaperTik