Linear Analysis of reduced-round CAST-128 and CAST-256

  title={Linear Analysis of reduced-round CAST-128 and CAST-256},
  author={Jorge Nakahara and Mads Reinholdt Rasmussen}
This paper1 describes a linear analysis of reduced-round versions of the CAST-128 and CAST-256 block ciphers. CAST-256 was a former candidate to the AES Development Process. Both ciphers use the same nonlinear components (fixed 8×32-bit S-boxes, key-dependent bit-rotation, modular addition and subtraction on 32-bit words) and a Feistel Network structure. We exploit the fact that the S-boxes are non-surjective mappings to construct iterative linear distinguishers for both ciphers. As far as we… CONTINUE READING

Similar Papers

Loading similar papers…