Skip to main content

Table 1 Comparison of key-recovery attacks on LBlock

From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers

Model Attack rounds Data per key Time Memory Ref.
RK Differential 22 264.1RKKP 267 N/A (Liu et al. 2012)
  Imp.Diff 22 247RKCP 270 N/A (Minier and Naya-Plasencia 2012)
  Imp.Diff 23 264.1RKKP 278.3 261.4 (Wen et al. 2014)
  Key Diff Inv Bias 24 262.95RKKP 270.67 261 (Bogdanov et al. 2013)
  Key Diff Inv Bias 24 262.83RKKP 268.08 261 this paper
  Key Diff Inv Bias 24 262.3RKDKP 268.07 261 this paper
  Key Diff Inv Bias 25 260.4RKDKP 278.85 261 this paper
SK Integral 20 263.6CP 239.6 235 (Sasaki and Wang 2013a)
  Integral 21 261.6CP 254.16 251.58 (Sasaki and Wang 2013b)
  Integral 22 261CP 270 263 (Sasaki and Wang 2013b)
  Zero-Correlation 22 262DKP 271.27 264 (Soleimany and Nyberg 2014)
  Zero-Correlation 22 260DKP 279 264 (Soleimany and Nyberg 2014)
  Zero-Correlation 23 262.1KP 276 260 (Wang and Wu 2014)
  Imp.Diff 24 259CP 277.5 275 (Wang et al. 2016)