Reconstructing an S-box from its Difference Distribution Table

In this paper we study the problem of recovering a secret S-box from its difference distribution table (DDT). While being an interesting theoretical problem on its own, the ability to recover the S-box from the DDT of a secret S-box can be used in cryptanalytic attacks where the attacker can obtain...

Full description

Bibliographic Details
Main Authors: Orr Dunkelman, Senyang Huang
Format: Article
Language:English
Published: Ruhr-Universität Bochum 2019-06-01
Series:IACR Transactions on Symmetric Cryptology
Subjects:
DDT
LAT
Online Access:https://ojs-speed.ub.rub.de/index.php/ToSC/article/view/8319