Extended differential properties of cryptographic functions

Anne Canteaut, Joëlle Roué · Contemporary mathematics - American Mathematical Society · 2015

The resistance of a block cipher against differential cryptanalysis is usually quantified by the differential uniformity of the involved Sbox. However, this criterion is not very precise; for instance, it does not capture the different behaviors which may be observed for affinely equivalent Sboxes. A more precise quantity derived from the differential spectrum of the Sbox is introduced here and provides a better estimate of the maximum expected differential probability for any two-round Substitution-Permutation Network whose diffusion layer is linear over the field corresponding to the domain of the Sbox. In particular, this result shows that the inversion in the field with 2 m 2^m elements is the mapping in its equivalence class which leads to the highest two-round maximum expected differential probability, for any F 2 m \mathbf {F}_{2^m} -linear diffusion mapping.

Read the paper · More papers on PaperTik