New Linear Cryptanalytic Results of Reduced-Round of CAST-128 and CAST-256

Meiqin Wang,Xiaoyun Wang,Changhui Hu
DOI: https://doi.org/10.1007/978-3-642-04159-4_28
2008-01-01
Abstract:This paper presents a linear cryptanalysis for reduced round variants of CAST-128 and CAST-256 block ciphers. Compared with the linear relation of round function with the bias 2驴 17 by J. Nakahara et al., we found the more heavily biased linear approximations for 3 round functions and the highest one is 2驴 12.91. We can mount the known-plaintext attack on 6-round CAST-128 and the ciphertext-only attack on 4-round CAST-128. Moreover the known-plaintext attack on 24-round CAST-256 with key size 192 and 256 bits has been given, and the ciphertext-only attack on 21-round CAST-256 with key size 192 and 256 bits can be performed. At the same time, we also present the attack on 18-round CAST-256 with key size 128 bits.
What problem does this paper attempt to address?