From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
Step | Guess | Time | Obtained States | Size |
---|---|---|---|---|
1 | \(K_{24}^{7}\) | N·24·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{24}^{13} |\) | 260·2 |
 |  |  | \(X_{22}^{7}\left |X_{24}^{2}\right | X_{24}^{8}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\) |  |
2 | \(K_{24}^{0}\) | 260·28·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{24}^{13} |\) | 256·2 |
 |  |  | \(X_{22}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) |  |
3 | \(K_{23}^{7}[0]\) | 256·28+1·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{8}\left |X_{0}^{4}\right | X_{21}^{7} |\) | 252·2 |
 |  |  | \(X_{22}^{4}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\) |  |
4 | \(K_{1}^{4}\) | 252·29+4·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{0}^{1}\right | X_{0}^{1}\left |X_{1}^{6}\right | X_{21}^{7}\left |X_{22}^{4}\right |\) | 248·2 |
 |  |  | \(X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) |  |
5 | \(K_{2}^{6}\) | 248·213+4·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{0}^{9}\right | X_{0}^{6}\left |X_{2}^{7}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11} |\) | 244·2 |
 |  |  | \(X_{24}^{0} | X_{24}^{9}\) |  |
6 | \(K_{1}^{6}\) | 244·217+4·2 | \(X_{0}^{0}\left |X_{0}^{14}\right | X_{0}^{5}\left |X_{1}^{7}\right | X_{2}^{7}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right |\) | 240·2 |
 |  |  | \(X_{24}^{0} | X_{24}^{9}\) |  |
7 | \(K_{1}^{5}\) | 240·221+4·2 | \(X_{0}^{0}\left |X_{1}^{4}\right | X_{1}^{7}\left |X_{2}^{7}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) | 236·2 |
8 | \(K_{2}^{4}\) | 236·225+4·2 | \(X_{3}^{14}\left |X_{1}^{7}\right | X_{2}^{7}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right | X_{24}^{0} | X_{24}^{9}\) | 232·2 |
9 | \(K_{3}^{7}\) | 232·229+4·2 | \(X_{3}^{14}\left |X_{3}^{5}\right | X_{21}^{7}\left |X_{22}^{4}\right | X_{24}^{11}\left |X_{24}^{0}\right | X_{24}^{9}\) | 228·2 |
10 | \(K_{24}^{1}, K_{4}^{5}[1]\) | 228·233+5·4 | \(X_{4}^{4}\left |X_{21}^{7}\right | X_{22}^{4}\left |X_{24}^{11}\right | X_{22}^{2}\) | 220·2 |
11 | \(K_{23}^{2}\) | 220·238+4·2 | \(X_{4}^{4}\left |X_{21}^{7}\right | X_{22}^{4} | X_{21}^{5}\) | 216·2 |
12 | \(K_{22}^{5}\) | 216·242+4·2 | \(X_{4}^{4}\left |X_{21}^{7}\right | X_{20}^{6}\) | 212·2 |
13 | \(K_{21}^{6}\) | 212·246+4·2 | \(X_{4}^{4} | X_{20}^{9}\) | 28·2 |