Linear cryptanalysis of NUSH block cipher
Wenling Wu, Dengguo Feng · Science in China Series F Information Sciences · 2002
NUSH is a block cipher as a candidate for NESSIE. NUSH is analyzed by linear crypt-analysis. The complexity δ=(ε, η) of the attack consists of data complexity ε and time complexity η. Three linear approximations are used to analyze NUSH with 64-bit block. When | K |=128 bits, the complexities of three attacks are (2 58 , 2 124 ), (2 60 , 2 78 ) and (2 62 , 2 55 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 58 , 2 157 ) (2 60 , 2 96 ) and (2 62 , 2 58 ) respectively. When | K | =256 bits, the complexities of three attacks are (2 58 , 2 125 ), (2 60 , 2 78 ) and (2 62 , 2 53 ) respectively. Three linear approximations are used to analyze NUSH with 128-bit block. When | K |=128 bits, the complexities of three attacks are (2 122 , 2 95 ), (2 124 , 2 57 ) and (2 126 , 2 52 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 122 , 2 142 ), (2 124 , 2 75 ) and (2 126 , 2 58 ) respectively. When | K |=256 bits, the complexities of three attacks are (2 122 , 2 168 ), (2 124 , 2 81 ) and (2 126 , 2 64 ) respectively. Two linear approximations are used to analyze NUSH with 256-bit block. When | K |=128 bits, the complexities of two attacks are (2 252 , 2 122 ) and (2 254 , 2 119 ) respectively. When | K |=192 bits, the complexities of two attacks are (2 252 , 2 181 ) and (2 254 , 2 177 ) respectively. When | K |=256 bits, the complexities of two attacks are (2 252 , 2 240 ) and (2 254 , 2 219 ) respectively. These results show that NUSH is not immune to linear cryptanalysis, and longer key cannot enhance the security of NUSH.