Advances in Cryptology — EUROCRYPT 2003: International by Antoine Joux (auth.), Eli Biham (eds.)

This ebook constitutes the refereed lawsuits of the overseas convention at the idea and purposes of Cryptographic options, EUROCRYPT 2003, held in Warsaw, Poland in could 2003.

The 37 revised complete papers awarded including invited papers have been conscientiously reviewed and chosen from 156 submissions. The papers are geared up in topical sections on cryptanalysis, safe multi-party communique, zero-knowledge protocols, foundations and complexity-theoretic protection, public key encryption, new primitives, elliptic curve cryptography, electronic signatures, information-theoretic cryptography, and crew signatures.

2 New Asymptotic Bounds (n) First, we note that if δlin is optimal, then Pe ≤ 12 for all n > 0 (otherwise, we could modify it such that it outputs the opposite decision as defined in Algorithm (n) 1 and get a smaller error probability). Thus, we have Advnδlin (C, C ∗ ) = 1−2Pe . As outlined before, the crucial part of δlin is the acceptance region A(n) . e. the region producing the smallest overall error probability. Without with > 0 loss of generality, we assume that E [PrX [a · X = b · C(X)]] 12 + where the expectation is taken over a uniformly distributed plaintext space X and the key space K.

2. The relations between the different sets for the AE algorithm. Sets DA and DB – values for which A or B are known respectively. As A is a linear mapping, any linear combination of points of DA will also reside in DA . The same is true for DB . Note that DA and DB always include 0. , S ◦ A (CA ) = B (CB ). For these values, RS and RS are known respectively. Sets NA and NB – remaining points of DA and DB . We have that S ◦A (NA )∩ B (NB ) = ∅. Sets UA and UB – values for which A and B can still be chosen.

Keywords: Distinguishers, Statistical Hypothesis Testing, Linear Cryptanalysis, Differential cryptanalysis 1 Introduction Historically, statistical procedures are indissociable of cryptanalytic attacks against block ciphers. One of the first attack exploiting statistical correlations in the core of DES [24] is Davies and Murphy’s attack [9]. Biham and Shamir’s differential cryptanalysis [1,2,3], Matsui’s attack against DES [17,18], Vaudenay’s statistical and χ2 cryptanalysis [29], Harpes and Massey’s partitioning cryptanalysis [13], and Gilbert-Minier stochastic cryptanalysis [21] are attacks using statistical procedures in their core.

