From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
Model | Attack | rounds | Data per key | Time | Memory | Ref. |
---|---|---|---|---|---|---|
RK | Differential | 22 | 264.1RKKP | 267 | N/A | |
 | Imp.Diff | 22 | 247RKCP | 270 | N/A | |
 | Imp.Diff | 23 | 264.1RKKP | 278.3 | 261.4 | |
 | Key Diff Inv Bias | 24 | 262.95RKKP | 270.67 | 261 | |
 | Key Diff Inv Bias | 24 | 262.83RKKP | 268.08 | 261 | this paper |
 | Key Diff Inv Bias | 24 | 262.3RKDKP | 268.07 | 261 | this paper |
 | Key Diff Inv Bias | 25 | 260.4RKDKP | 278.85 | 261 | this paper |
SK | Integral | 20 | 263.6CP | 239.6 | 235 | |
 | Integral | 21 | 261.6CP | 254.16 | 251.58 | |
 | Integral | 22 | 261CP | 270 | 263 | |
 | Zero-Correlation | 22 | 262DKP | 271.27 | 264 | |
 | Zero-Correlation | 22 | 260DKP | 279 | 264 | |
 | Zero-Correlation | 23 | 262.1KP | 276 | 260 | |
 | Imp.Diff | 24 | 259CP | 277.5 | 275 |