# Journal of Mathematical Cryptology

Managing Editor: Magliveras, Spyros S. / Steinwandt, Rainer / Trung, Tran

Editorial Board: Blackburn, Simon R. / Blundo, Carlo / Burmester, Mike / Cramer, Ronald / Gilman, Robert / Gonzalez Vasco, Maria Isabel / Grosek, Otokar / Helleseth, Tor / Kim, Kwangjo / Koblitz, Neal / Kurosawa, Kaoru / Lauter, Kristin / Lange, Tanja / Menezes, Alfred / Nguyen, Phong Q. / Pieprzyk, Josef / Rötteler, Martin / Safavi-Naini, Rei / Shparlinski, Igor E. / Stinson, Doug / Takagi, Tsuyoshi / Williams, Hugh C. / Yung, Moti

CiteScore 2017: 1.43

SCImago Journal Rank (SJR) 2017: 0.293
Source Normalized Impact per Paper (SNIP) 2017: 1.117

Mathematical Citation Quotient (MCQ) 2017: 0.51

Online
ISSN
1862-2984
Volume 11, Issue 2

# Multiple differential-zero correlation linear cryptanalysis of reduced-round CAST-256

• School of Mathematics, Iran University of Science and Technology, Narmak, Tehran 16844, Iran
Published Online: 2017-04-21 | DOI: https://doi.org/10.1515/jmc-2016-0054

## Abstract

CAST-256 (or CAST6) is a symmetric-key block cipher published in June 1998. It was submitted as a candidate for Advanced Encryption Standard (AES). In this paper, we will propose a new chosen text attack, the multiple differential-zero correlation linear attack, to analyze the CAST-256 block cipher. Our attack is the best-known attack on CAST-256 according to the number of rounds without the weak-key assumption. We first construct a 30-round differential-zero correlation linear distinguisher. Based on the distinguisher, we propose a first 33-round attack on CAST-256 with data complexity of ${2}^{115.63}$ and time complexity ${2}^{238.26}$. In the end, the 111-bit subkey is recovering.

MSC 2010: 94A60

Accepted: 2017-02-09

Published Online: 2017-04-21

Published in Print: 2017-06-01

Citation Information: Journal of Mathematical Cryptology, Volume 11, Issue 2, Pages 55–62, ISSN (Online) 1862-2984, ISSN (Print) 1862-2976,

