Skip to main content

Table 2 Comparison of key-recovery attacks on TWINE-128

From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers

Model Attack rounds Data per key Time Memory Ref.
RK Key Diff Inv Bias 27 262.95RKKP 2119.5 261 (Bogdanov et al. 2013)
  Key Diff Inv Bias 27 262.3RKDKP 2119.5 261 this paper
  Key Diff Inv Bias 27 260.44RKDKP 2119.5 15·261 this paper
  Key Diff Inv Bias 28 261.5RKDKP 2126.15 261 this paper
SK Saturation 23 262.81CP 2106.14 2103 (Suzaki et al. 2012)
  Imp.Diff 24 252.21CP 2115.10 2118 (Suzaki et al. 2012)
  Meet-in-the-Middle 25 248CP 2122 2125 (Boztas et al. 2013)
  Zero-Correlation 25 262.1KP 2122.12 260 (Wang and Wu 2014)