Advances in Cryptology — EUROCRYPT ’95: International by C. P. Schnorr, H. H. Hörner (auth.), Louis C. Guillou,

By C. P. Schnorr, H. H. Hörner (auth.), Louis C. Guillou, Jean-Jacques Quisquater (eds.)

This quantity constitutes the court cases of EUROCRYPT '95, the 1995 foreign Workshop at the idea and alertness of Cryptographic concepts, held in Saint-Malo, France in may possibly 1995 below the sponsorship of the foreign organization for Cryptologic study (IACR).
The quantity includes revised types of the 33 papers chosen from a complete of 113 submissions. All present facets of cryptologic study and complicated functions are addressed; there are sections on cryptanalysis, signatures, computational quantity conception, cryptographic protocols, mystery sharing, digital funds, shift registers and Boolean features, authentication codes, new schemes, complexity facets, and implementation points.

For + 37 the mini-cipher IDEA(8), the average-key imbalance of all one-round homomorphic 1/0 sums are zero. 00122, and all other 1/0 sum average-key imbalances are zero. Moreover, the number of p/c-pairs that must be analyzed in the generalization of linear cryptanalysis is about the square of the key-dependent imbalance and is here far larger than the total number of p/c-pairs. We conclude that the procedure for finding effective homomorphic threefold sums does not find any effective threefold sum for IDEA(8) and IDEA( 16).

As this is only slightly larger than the maximum I/O sum average-key imbalance, there are no weak keys for the MA-box with respect to our attack. These conclusions doubtlessly hold true for (full-sized) IDEA as well. Thus IDEA seems secure against the generalization of linear cryptanalysis. 3 C r y p t a n a l y s i s of SAFER K-64 SAFER K-64 is an iterated block-cipher, presented by Massey in [4]. The round function of SAFER K-64 consists of two half-rounds, each consisting of a keyed group operation and an unkeyed bijection either consisting of exponential and logarithm functions modulo 257 or a “Pseudo-Hadamard Transform”.

11 no repeated edges. ch vertex pair 7;ir u j in Gnf. th set. will exist since P . l(P), is irreducible. he length of the path 6 ( P,. nd d ( e ) = d i j . s 19 where the maximum is taken over all directed edges in the graph and the sum is over all paths that traverse the edge e. Note that K is essentially a measure of 'bottlenecks'. A bottleneck S in a graph G is a set of vertices for which there are relatively few edges directed in or out of S as compared to \S\. Intuitively, if the chain enters a state corresponding to a vertex in S then the process gets 'stuck' in S and does not mix rapidly.

