Cryptography Reference
In-Depth Information
Let's consider a simple example of using the piling-up lemma on the EASY1 cipher.
Although not shown in the
Table 6-4
diagram, one of the equations is
X
0
=
Y
4
, which has a bias of -4. If you
look at the diagram of the EASY1 cipher in
Figure 6-3
, there is one fairly easy pattern to follow using this bias:
In the second from the right S-box (second least significant), we have bit 4 of the S-box's output being mapped
to bit 0 of the same S-box's input for the next round.
Search WWH ::
Custom Search