The Best Differential Characteristics and Subtleties of the Biham-Shamir Attacks on DES.
Nicolas T. Courtois · 2005
In about every book about cryptography, we learn that the plaintext complexity of differential cryptanalysis on DES is 2^47, as reported by Biham and Shamir in [2]. Yet few people realise that in a typical setting this estimation is not exact and too optimistic. In this note we show...