In this paper, we will propose a new chosen text attack, the multiple differential-zero correlation linear attack, to analyze the CAST block cipher.

## Variants of Differential and Linear Cryptanalysis

In cryptography , linear cryptanalysis is a general form of cryptanalysis based on finding affine approximations to the action of a cipher. Attacks have been developed for block ciphers and stream ciphers. Linear cryptanalysis is one of the two most widely used attacks on block ciphers; the other being differential cryptanalysis. A variety of refinements to the attack have been suggested, including using multiple linear approximations or incorporating non-linear expressions, leading to a generalized partitioning cryptanalysis. Evidence of security against linear cryptanalysis is usually expected of new cipher designs. There are two parts to linear cryptanalysis.

Show all documents In Boomerang attack was developed by Wagner [7] which states, attack is possible even if no differentials with high or low probability is present for whole cipher. This attack was modified and named as Rectangle attack [8] in Related Key attack can be combined with other variants of differential cryptanalysis where knowledge of difference in keys may allow to attack more number of rounds [9]. One of the most popular impossible differentials is called a truncated impossible differential. It is independent of the choices of the S-boxes. Integral cryptanalysis [3], also known as square attack[8], saturation attack [9], multi-set attack [10], higher-order differential attack [11, 12], was first proposed by Knudsen and Wagner.

## Variants of Differential and Linear Cryptanalysis

Introduced by Martin Hellman and Susan K. Langford in , the differential-linear attack is a mix of both linear cryptanalysis and differential cryptanalysis. The attack utilises a differential characteristic over part of the cipher with a probability of 1 for a few rounds—this probability would be much lower for the whole cipher. The rounds immediately following the differential characteristic have a linear approximation defined, and we expect that for each chosen plaintext pair, the probability of the linear approximation holding for one chosen plaintext but not the other will be lower for the correct key. The attack was generalised by Eli Biham et al. From Wikipedia, the free encyclopedia.

## Multiple differential-zero correlation linear cryptanalysis of reduced-round CAST-256

#### 2 Description of CAST-256

