SLIDE 11 Description of PRINTCIPHER Differential Cryptanalysis Computing roots of permutations Summary
Differential trail on one round of PRINTCIPHER
wt(∆X) = 1, ∆X3 = 1
P k2
wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1 wt(∆Y) = 1, ∆Y8 = 1
Pk2(3) = 8. By trying all the 48 1-bit input differences: we learn Pk2 .
11 / 21