Preliminary Cryptanalysis of Reduced-Round Serpent
Tadayoshi Kohno, John M. Kelsey, Bruce Schneier · 2000
Abstract. Serpent is a 32-round AES block cipher finalist. In this paper we present several attacks on reduced-round variants of Serpent that require less work than exhaustive search. We attack six-round 256-bit Serpent using the meet-in-the-middle technique, 512 known plaintexts, 2 246 bytes of memory, and approximately 2 247 trial encryptions. For all key sizes, we attack six-round Serpent using standard differential cryptanalysis, 2 83 chosen plaintexts, 2 40 bytes of memory, and 2 90 trial encryptions. We present boomerang and amplified boomerang attacks on seven- and eight-round Serpent, and show how to break nine-round 256-bit Serpent using the amplified boomerang technique, 2 110 chosen plaintexts, 2 212 bytes of memory, and approximately 2 252 trial encryptions. 1