Differential cryptanalysis of Q

Eli Biham, Vladimir Furman, Michał Misztal, Vincent Rijmen · 2002

Q is a block cipher submitted as a cmdidate to the NESSIE project by Leslie McBride. The submission document of Q describes 12 one-round iterative chm'acteristics with probability 2-18 each. On 7 rounds these chm'acteristics have probability 2-12e md the author of Q claims that they m'e the best 7-round chm'acteristics. We find additional one-round chm'acteristics that cm be extended to more rounds. We also combine the chm'acteristics into differentials. We present several differential attacks on the full cipher. Our best attack on the full Q with 128-bit keys uses 215 chosen plaintexts md has a complexity of 277 encryptions. Our best attack on the full Q with lm'ger key sizes uses 2125 chosen ciphertexts, md has a complexity of 29e for 192-bit keys md 2128 for 256-bit keys.

Read the paper · More papers on PaperTik