By Alex Biryukov, Christophe De Cannière, Michaël Quisquater (auth.), Matt Franklin (eds.)

Crypto 2004, the twenty fourth Annual Crypto convention, was once subsidized by means of the Int- nationwide organization for Cryptologic study (IACR) in cooperation with the IEEE laptop Society Technical Committee on safeguard and privateness and the pc technology division of the collage of California at Santa Barbara. this system committee authorised 33 papers for presentation on the conf- ence. those have been chosen from a complete of 211 submissions. each one paper got at the very least 3 autonomous stories. the choice procedure integrated an online dialogue part, and a one-day software committee assembly at ny U- versity. those court cases comprise up-to-date types of the 33 accredited papers. The authors had a number of weeks to revise them, aided by means of reviews from the reviewers. even if, the revisions weren't subjected to any editorial overview. Theconferenceprogramincludedtwoinvitedlectures.VictorShoup’sinvited speak was once a survey on selected ciphertext protection in public-key encryption. Susan Landau’s invited speak used to be entitled “Security, Liberty, and digital Commu- cations”. Her prolonged summary is integrated in those lawsuits. We persevered the culture of a Rump consultation, chaired by way of Stuart Haber. these displays (always brief, frequently severe) will not be incorporated here.

If is sufficiently large, the gain derived in Theorem 1 can accurately be approximated by where is called the total capacity of the linear characteristics. Proof. In order to show how (11) is derived from (8), we just need to construct an approximation for the expression We first define the function Denoting the average value of a set of variables by we can reduce (12) to the compact expression with By expanding into a Taylor series around the average value we find Provided that the higher order moments of are sufficiently small, we can use the approximation Exploiting the fact that the jth coordinate of each vector is either or we can easily calculate the average value When is sufficiently large (say the right hand part can be approximated by (remember that and thus Substituting this into the relation we find By applying this approximation to the gain formula derived in Theorem 1, we directly obtain expression (11).

We will use this characteristic. Let KS5 denote the combination of the S-box S5 and the key bits XORed to its inputs. It is easy to see that for KS5, if we denote by K[sth] some constant linear combination of key bits, for any key, one of the following equations is always strongly biased: In our construction, we will use one of the above, and we will also use another, naturally biased equation, which will be one of the following: Now we are ready to construct characteristics for 3 rounds of DES.

