Skip to main content

Table 5 Partial encryption and decryption on 24-round LBlock

From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers

Step Guess Time Obtained States Size
1 \(K_{24}^{7}\) N·24·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{24}^{13} |\) 260·2
    \(X_{22}^{7}\left |X_{24}^{2}\right | X_{24}^{8}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\)  
2 \(K_{24}^{0}\) 260·28·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{24}^{13} |\) 256·2
    \(X_{22}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\)  
3 \(K_{23}^{7}[0]\) 256·28+1·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{21}^{7} |\) 252·2
    \(X_{22}^{4}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\)  
4 \(K_{1}^{4}\) 252·29+4·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{1}\left |X_{1}^{6}\right | X_{21}^{7}\left |X_{22}^{4}\right |\) 248·2
    \(X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\)  
5 \(K_{2}^{6}\) 248·213+4·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{2}^{7}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11} |\) 244·2
    \(X_{24}^{0} | X_{24}^{9}\)  
6 \(K_{1}^{6}\) 244·217+4·2 \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{1}^{7}\right | X_{2}^{7}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right |\) 240·2
    \(X_{24}^{0} | X_{24}^{9}\)  
7 \(K_{1}^{5}\) 240·221+4·2 \(X_{0}^{0}\left |X_{1}^{4}\right | X_{1}^{7}\left |X_{2}^{7}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) 236·2
8 \(K_{2}^{4}\) 236·225+4·2 \(X_{3}^{14}\left |X_{1}^{7}\right | X_{2}^{7}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\) 232·2
9 \(K_{3}^{7}\) 232·229+4·2 \(X_{3}^{14}\left |X_{3}^{5}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) 228·2
10 \(K_{24}^{1}, K_{4}^{5}[1]\) 228·233+5·4 \(X_{4}^{4}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right | X_{22}^{2}\) 220·2
11 \(K_{23}^{2}\) 220·238+4·2 \(X_{4}^{4}\left |X_{21}^{7}\right | X_{22}^{4} | X_{21}^{5}\) 216·2
12 \(K_{22}^{5}\) 216·242+4·2 \(X_{4}^{4}\left |X_{21}^{7}\right | X_{20}^{6}\) 212·2
13 \(K_{21}^{6}\) 212·246+4·2 \(X_{4}^{4} | X_{20}^{9}\) 28·2