A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2015; you can also visit the original URL.
The file type is application/pdf
.
Cryptanalysis of Iterated Even-Mansour Schemes with Two Keys
[chapter]
2014
Lecture Notes in Computer Science
The iterated Even-Mansour (EM) scheme is a generalization of the original 1-round construction proposed in 1991, and can use one key, two keys, or completely independent keys. In this paper, we methodically analyze the security of all the possible iterated Even-Mansour schemes with two n-bit keys and up to four rounds, and show that none of them provides more than n-bit security. Our attacks are based on a new cryptanalytic technique called multibridge which splits the cipher to different parts
doi:10.1007/978-3-662-45611-8_23
fatcat:ho5gkcthjjbm3fzfga5kgyiemq