Serge Vaudenay

dblp:v/SergeVaudenay · DBLP profile ↗
← Back
124ranked-venue papers
24as first author
16since 2021 · last 2026
0000-0001-9185-1449ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 118 · 23 first-author · 15 since 2021Theory of computation · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Computer networks · 1
YearPublicationVenuePosition
2026 The Cryptographic Layer of Biometric Authentication
Keng-Yu Chen, Serge Vaudenay
ACNS (2)2
2024 Non-Transferable Anonymous Tokens by Secret Binding
abstract
Non-transferability (NT) is a security notion which ensures that credentials are only used by their intended owners. Despite its importance, it has not been formally treated in the context of anonymous tokens (AT) which are lightweight anonymous credentials. In this work, we consider a client who "buys" access tokens which are forbidden to be transferred although anonymously redeemed. We extensively study the trade-offs between privacy (obtained through anonymity) and security in AT through the notion of non-transferability. We formalise new security notions, design a suite of protocols with various flavors of NT, prove their security, and implement the protocols to assess their efficiency. Finally, we study the existing anonymous credentials which offer NT, and show that they cannot automatically be used as AT without security and complexity implications.
F. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge Vaudenay
CCS4
2024 SILBE: An Updatable Public Key Encryption Scheme from Lollipop Attacks
Max Duparc, Tako Boris Fouotsa, Serge Vaudenay
SAC (1)3
2024 K-Waay: Fast and Deniable Post-Quantum X3DH without Ring Signatures
Daniel Collins 0001, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen 0001, Nicolas Rolin, Serge Vaudenay
USENIX Security Symposium5
2023 A Gapless Post-quantum Hash Proof System in the Hamming Metric
Bénédikt Tran, Serge Vaudenay
ACNS (1)2
2023 On Active Attack Detection in Messaging with Immediate Decryption
Khashayar Barooti, Daniel Collins 0001, Simone Colombo 0002, Loïs Huguenin-Dumittan, Serge Vaudenay
CRYPTO (4)5
2023 Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACs
Melissa Chase, F. Betül Durak, Serge Vaudenay
CRYPTO (2)3
2023 Private Message Franking with After Opening Privacy
Iraklis Leontiadis, Serge Vaudenay
ICICS2
2023 Cryptographic Administration for Secure Group Messaging
David Balbás, Daniel Collins 0001, Serge Vaudenay
USENIX Security Symposium3
2023 Optimal Symmetric Ratcheting for Secure Communication
abstract
Abstract To mitigate state exposure threats to long-lived instant messaging sessions, ratcheting was introduced, which is used in practice in protocols like Signal. However, existing ratcheting protocols generally come with a high cost. Recently, Caforio et al. proposed pragmatic constructions, which compose a weakly secure ‘light’ protocol and a strongly secure ‘heavy’ protocol, in order to achieve so-called ratcheting on-demand. The light protocol they proposed has still a high complexity. In this paper, we propose the lightest possible protocol we could imagine, which essentially encrypts and then hashes the secret key. We prove it secure in the standard model by introducing a new security notion, which relates symmetric encryption with key updates by hashing. Our protocol composes well with the generic transformation techniques by Caforio et al. to offer high security and performance at the same time. In a second step, we propose another protocol based on a newly defined integrated primitive, extending standard one-time authenticated encryption with an additional output block used as a secret key for the next message. We instantiate this primitive firstly from any authenticated encryption with associated data, and then we propose an efficient instantiation using advanced encryption standard (AES) encryption to update the key and AES-Galois/Counter mode of operation to encrypt and decrypt messages.
Hailun Yan, Serge Vaudenay, Daniel Collins 0001, Andrea Caforio
Comput. J.2
2022 On IND-qCCA Security in the ROM and Its Applications - CPA Security Is Sufficient for TLS 1.3
Loïs Huguenin-Dumittan, Serge Vaudenay
EUROCRYPT (3)2
2021 Towards Efficient LPN-Based Symmetric Encryption
Sonia Bogos, Dario Korolija, Thomas Locher, Serge Vaudenay
ACNS (2)4
2021 New Attacks on LowMC Instances with a Single Plaintext/Ciphertext Pair
Subhadeep Banik, Khashayar Barooti, Serge Vaudenay, Hailun Yan
ASIACRYPT (1)3
2021 FAST: Secure and High Performance Format-Preserving Encryption and Tokenization
F. Betül Durak, Henning Horst, Michael Horst, Serge Vaudenay
ASIACRYPT (3)4
2021 FO-like Combiners and Hybrid Post-Quantum Cryptography
Loïs Huguenin-Dumittan, Serge Vaudenay
CANS2
2021 On the Effectiveness of Time Travel to Inject COVID-19 Alerts
Vincenzo Iovino, Serge Vaudenay, Martin Vuagnoux
CT-RSA2
2020 \(\mathsf {BioLocker}\): A Practical Biometric Authentication Mechanism Based on 3D Fingervein
F. Betül Durak, Loïs Huguenin-Dumittan, Serge Vaudenay
ACNS (2)3
2020 Classical Misuse Attacks on NIST Round 2 PQC - The Power of Rank-Based Schemes
Loïs Huguenin-Dumittan, Serge Vaudenay
ACNS (1)2
2020 Determining the Core Primitive for Optimally Secure Ratcheting
Fatih Balli, Paul Rösler, Serge Vaudenay
ASIACRYPT (3)3
2019 Misuse Attacks on Post-quantum Cryptosystems
Ciprian Baetu, F. Betül Durak, Loïs Huguenin-Dumittan, Abdullah Talayhan, Serge Vaudenay
EUROCRYPT (2)5
2018 Secure Contactless Payment
Handan Kilinç Alper, Serge Vaudenay
ACISP2
2018 Generic Round-Function-Recovery Attacks for Feistel Networks over Small Domains
F. Betül Durak, Serge Vaudenay
ACNS2
2018 Formal Analysis of Distance Bounding with Secure Hardware
Handan Kilinç Alper, Serge Vaudenay
ACNS2
2018 Can Caesar Beat Galois? - Robustness of CAESAR Candidates Against Nonce Reusing and High Data Complexity Attacks
Serge Vaudenay, Damian Vizár
ACNS1
2017 Breaking the FF3 Format-Preserving Encryption Standard over Small Domains
F. Betül Durak, Serge Vaudenay
CRYPTO (2)2
2017 Contactless Access Control Based on Distance Bounding
Handan Kilinç Alper, Serge Vaudenay
ISC2
2016 Optimization of \mathsf LPN Solving Algorithms
Sonia Bogos, Serge Vaudenay
ASIACRYPT (1)2
2016 Efficient Public-Key Distance Bounding Protocol
Handan Kilinç Alper, Serge Vaudenay
ASIACRYPT (2)2
2016 Authenticated Encryption with Variable Stretch
Reza Reyhanitabar, Serge Vaudenay, Damian Vizár
ASIACRYPT (1)2
2016 Distance Bounding Based on PUF
Mathilde Igier, Serge Vaudenay
CANS2
2016 When Constant-Time Source Yields Variable-Time Binary: Exploiting Curve25519-donna Built with MSVC 2015
Thierry Kaufmann, Hervé Pelletier, Serge Vaudenay, Karine Villegas
CANS3
2016 Side-Channel Attacks on Threshold Implementations Using a Glitch Algebra
Serge Vaudenay
CANS1
2016 Privacy failure in the public-key distance-bounding protocols
abstract
Public‐key distance bounding protocols are well suited to defeat relay attacks in proximity access control systems when the author assume no prior shared key. At AsiaCCS 2014, Gambs, Onete, and Robert designed such a protocol with privacy protection for the prover. That is, the protocol hides the identity of the prover to active adversaries and the prover remains anonymous. In this study the author contradicts the result on this protocol by proving that an active adversary can easily identify one prover out of two possible ones. At WISEC 2013, Hermans, Peeters, and Onete proposed another protocol which is proven to protect the privacy of the prover. In this study the author complete their results and show that the protocol does not protect it in a strong sense. That is, if the adversary can corrupt the provers, then privacy is not guaranteed any more.
Serge Vaudenay
IET Inf. Secur.1
2015 Optimal Proximity Proofs Revisited
Handan Kilinç Alper, Serge Vaudenay
ACNS2
2015 How to Sequentialize Independent Parallel Attacks? - Biased Distributions Have a Phase Transition
Sonia Bogos, Serge Vaudenay
ASIACRYPT (2)2
2015 The Limits of Composable Crypto with Transferable Setup Devices
abstract
UC security realized with setup devices imposes that single instances of these setups are used. In most cases, UC-realization relies further on other properties of the setups devices, like tamper-resistance. But what happens in stronger versions of the UC framework, like EUC or JUC, where multiple instances of these setups are allowed? Can we formalise what it is about setups like these which makes them sometimes hinder UC, JUC, EUC realizability?
Ioana Boureanu, Miyako Ohkubo, Serge Vaudenay
AsiaCCS3
2015 Capacity and Data Complexity in Multidimensional Linear Attack
Jialin Huang, Serge Vaudenay, Xuejia Lai, Kaisa Nyberg
CRYPTO (1)2
2015 Better Algorithms for LWE and LWR
Alexandre Duc, Florian Tramèr, Serge Vaudenay
EUROCRYPT (1)3
2015 Protecting Against Multidimensional Linear and Truncated Differential Cryptanalysis by Decorrelation
Céline Blondeau, Aslí Bay, Serge Vaudenay
FSE3
2015 Boosting OMD for Almost Free Authentication of Associated Data
Reza Reyhanitabar, Serge Vaudenay, Damian Vizár
FSE2
2015 On Privacy for RFID
Serge Vaudenay
ProvSec1
2015 Sound Proof of Proximity of Knowledge
Serge Vaudenay
ProvSec1
2015 Practical and provably secure distance-bounding
abstract
Abstract From contactless payments to remote car unlocking, many applications are vulnerable to relay attacks. Distance bounding protocols are the main practical countermeasure against these attacks. In this paper, we present a formal analysis of SKI, which recently emerged as the first family of lightweight and provably secure distance bounding protocols. More precisely, we explicate a general formalism for distance-bounding protocols, which lead to this practical and provably secure class of protocols (and it could lead to others). We prove that SKI and its variants are provably secure, even under the real-life setting of noisy communications, against the main types of relay attacks: distance-fraud and generalised versions of mafia- and terrorist-fraud. To attain resistance to terrorist-fraud, we reinforce the idea of using secret sharing, combined with the new notion of a leakage scheme. In view of resistance to generalised mafia-frauds (and terrorist-frauds), we present the notion of circular-keying for pseudorandom functions (PRFs); this notion models the employment of a PRF, with possible linear reuse of the key. We also identify the need of PRF masking to fix common mistakes in existing security proofs/claims. Finally, we enhance our design to guarantee resistance to terrorist-fraud in the presence of noise.
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
J. Comput. Secur.3
2015 Expected loss analysis for authentication in constrained channels
abstract
Abstract We derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay
J. Comput. Secur.3
2014 On Selection of Samples in Algebraic Attacks and a New Technique to Find Hidden Low Degree Equations
Petr Susil, Pouyan Sepehrdad, Serge Vaudenay
ACISP3
2014 Optimal Proximity Proofs
Ioana Boureanu, Serge Vaudenay
Inscrypt2
2014 Misuse-Resistant Variants of the OMD Authenticated Encryption Mode
Reza Reyhanitabar, Serge Vaudenay, Damian Vizár
ProvSec2
2014 OMD: A Compression Function Mode of Operation for Authenticated Encryption
Simon Cogliani, Diana Maimut, David Naccache, Rodrigo Portella do Canto, Reza Reyhanitabar, Serge Vaudenay, Damian Vizár
Selected Areas in Cryptography6
2014 Location leakage in distance bounding: Why location privacy does not work
Aikaterini Mitrokotsa, Cristina Onete, Serge Vaudenay
Comput. Secur.3
2013 Primeless Factoring-Based Cryptography - -Solving the Complexity Bottleneck of Public-Key Generation-
Sonia Bogos, Ioana Boureanu, Serge Vaudenay
ACNS3
2013 Towards Secure Distance Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
FSE3
2013 Smashing WEP in a Passive Attack
Pouyan Sepehrdad, Petr Susil, Serge Vaudenay, Martin Vuagnoux
FSE3
2013 Practical and Provably Secure Distance-Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
ISC3
2013 Input-Aware Equivocable Commitments and UC-secure Commitments with Atomic Exchanges
Ioana Boureanu, Serge Vaudenay
ProvSec2
2013 On Modeling Terrorist Frauds - Addressing Collusion in Distance Bounding Protocols
Serge Vaudenay
ProvSec1
2013 On Selecting the Nonce Length in Distance-Bounding Protocols
abstract
Distance-bounding protocols form a family of challenge–response authentication protocols that have been introduced to thwart relay attacks. They enable a verifier to authenticate and to establish an upper bound on the physical distance to an untrusted prover. We provide a detailed security analysis of a family of such protocols. More precisely, we show that the secret key shared between the verifier and the prover can be leaked after a number of nonce repetitions. The leakage probability, while exponentially decreasing with the nonce length, is only weakly dependent on the key length. Our main contribution is a high probability bound on the number of sessions required for the attacker to discover the secret, and an experimental analysis of the attack under noisy conditions. Both of these show that the attack's success probability mainly depends on the length of the used nonces rather than the length of the shared secret key. The theoretical bound could be used by practitioners to appropriately select their security parameters. While longer nonces can guard against this type of attack, we provide a possible countermeasure which successfully combats these attacks even when short nonces are used.
Aikaterini Mitrokotsa, Pedro Peris-Lopez, Christos Dimitrakakis, Serge Vaudenay
Comput. J.4
2012 Strong Privacy for RFID Systems from Plaintext-Aware Encryption
Khaled Ouafi, Serge Vaudenay
CANS2
2012 Multipurpose Cryptographic Primitive ARMADILLO3
Petr Susil, Serge Vaudenay
CARDIS2
2012 The Bussard-Bagga and Other Distance-Bounding Protocols under Attacks
Aslí Bay, Ioana Boureanu, Aikaterini Mitrokotsa, Iosif Spulber, Serge Vaudenay
Inscrypt5
2012 Resistance against Iterated Attacks by Decorrelation Revisited,
Aslí Bay, Atefeh Mashatan, Serge Vaudenay
CRYPTO3
2012 ElimLin Algorithm Revisited
Nicolas T. Courtois, Pouyan Sepehrdad, Petr Susil, Serge Vaudenay
FSE4
2012 Expected loss bounds for authentication in constrained channels
abstract
We derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay
INFOCOM3
2012 Several Weak Bit-Commitments Using Seal-Once Tamper-Evident Devices
Ioana Boureanu, Serge Vaudenay
ProvSec2
2011 On Hiding a Plaintext Length by Preencryption
Cihangir Tezcan, Serge Vaudenay
ACNS2
2011 Fast Key Recovery Attack on ARMADILLO1 and Variants
Pouyan Sepehrdad, Petr Susil, Serge Vaudenay
CARDIS3
2011 Statistical Attack on RC4 - Distinguishing WPA
Pouyan Sepehrdad, Serge Vaudenay, Martin Vuagnoux
EUROCRYPT2
2011 Related-key Attack against Triple Encryption based on Fixed Points
Serge Vaudenay
SECRYPT1
2011 Short Undeniable Signatures Based on Group Homomorphisms
Jean Monnerat, Serge Vaudenay
J. Cryptol.2
2010 A Message Recognition Protocol Based on Standard Assumptions
Atefeh Mashatan, Serge Vaudenay
ACNS2
2010 Cryptanalysis of Reduced-Round MIBS Block Cipher
Aslí Bay, Jorge Nakahara Jr., Serge Vaudenay
CANS3
2010 ARMADILLO: A Multi-purpose Cryptographic Primitive Dedicated to Hardware
Stéphane Badel, Nilay Dagtekin, Jorge Nakahara Jr., Khaled Ouafi, Nicolas Reffé, Pouyan Sepehrdad, Petr Susil, Serge Vaudenay
CHES8
2010 Distinguishing Distributions Using Chernoff Information
Thomas Baignères, Pouyan Sepehrdad, Serge Vaudenay
ProvSec3
2009 Efficient Deniable Authentication for Signatures
Jean Monnerat, Sylvain Pasini, Serge Vaudenay
ACNS3
2009 On Tamper-Resistance from a Theoretical Viewpoint
Paulo Mateus, Serge Vaudenay
CHES2
2009 Smashing SQUASH-0
Khaled Ouafi, Serge Vaudenay
EUROCRYPT2
2008 On the Security of HB# against a Man-in-the-Middle Attack
Khaled Ouafi, Raphael Overbeck, Serge Vaudenay
ASIACRYPT3
2008 Mutual authentication in RFID: security and privacy
abstract
In RFID protocols, tags identify and authenticate themselves to readers. At Asiacrypt 2007, Vaudenay studied security and privacy models for these protocols. We extend this model to protocols which offer reader authentication to tags. Whenever corruption is allowed, we prove that secure protocols cannot protect privacy unless we assume tags have a temporary memory which vanishes by itself. Under this assumption, we study several protocols. We enrich a few basic protocols to get secure mutual authentication RFID protocols which achieve weak privacy based on pseudorandom functions only, narrow-destructive privacy based on random oracles, and narrow-strong and forward privacy based on public-key cryptography.
Radu-Ioan Paise, Serge Vaudenay
AsiaCCS2
2008 Cryptanalysis of an E0-like Combiner with Memory
Yi Lu 0002, Serge Vaudenay
J. Cryptol.2
2007 TCHo: A Hardware-Oriented Trapdoor Cipher
Jean-Philippe Aumasson, Matthieu Finiasz, Willi Meier, Serge Vaudenay
ACISP4
2007 Hash-and-Sign with Weak Hashing Made Secure
Sylvain Pasini, Serge Vaudenay
ACISP2
2007 On Privacy Models for RFID
Serge Vaudenay
ASIACRYPT1
2007 How to safely close a discussion
Gildas Avoine, Serge Vaudenay
Inf. Process. Lett.2
2006 An Optimal Non-interactive Message Authentication Protocol
Sylvain Pasini, Serge Vaudenay
CT-RSA2
2005 The Conditional Correlation Attack: A Practical Attack on Bluetooth Encryption
Yi Lu 0002, Willi Meier, Serge Vaudenay
CRYPTO3
2005 Secure Communications over Insecure Channels Based on Short Authenticated Strings
Serge Vaudenay
CRYPTO1
2005 Chaum's Designated Confirmer Signature Revisited
Jean Monnerat, Serge Vaudenay
ISC2
2005 The Pairing Problem with User Interaction
Thomas Peyrin, Serge Vaudenay
SEC2
2005 Generating anomalous elliptic curves
Franck Leprévost, Jean Monnerat, Sébastien Varrette, Serge Vaudenay
Inf. Process. Lett.4
2004 Optimistic Fair Exchange Based on Publicly Verifiable Secret Sharing
Gildas Avoine, Serge Vaudenay
ACISP2
2004 Digital Signature Schemes with Domain Parameters: Yet Another Parameter Issue in ECDSA
Serge Vaudenay
ACISP1
2004 How Far Can We Go Beyond Linear Cryptanalysis?
Thomas Baignères, Pascal Junod, Serge Vaudenay
ASIACRYPT3
2004 Cryptanalysis of Bluetooth Keystream Generator Two-Level E0
Yi Lu 0002, Serge Vaudenay
ASIACRYPT2
2004 Generic Homomorphic Undeniable Signatures
Jean Monnerat, Serge Vaudenay
ASIACRYPT2
2004 Faster Correlation Attack on Bluetooth Keystream Generator E0
Yi Lu 0002, Serge Vaudenay
CRYPTO2
2004 On Some Weak Extensions of AES and BES
Jean Monnerat, Serge Vaudenay
ICICS2
2003 Password Interception in a SSL/TLS Channel
Brice Canvel, Alain P. Hiltgen, Serge Vaudenay, Martin Vuagnoux
CRYPTO3
2003 Optimal Key Ranking Procedures in a Statistical Cryptanalysis
Pascal Junod, Serge Vaudenay
FSE2
2003 Decorrelation: A Theory for Block Cipher Security
Serge Vaudenay
J. Cryptol.1
2002 Security Flaws Induced by CBC Padding - Applications to SSL, IPSEC, WTLS
Serge Vaudenay
EUROCRYPT1
2001 Cryptanalysis of the Chor - Rivest Cryptosystem
Serge Vaudenay
J. Cryptol.1
2000 On the Pseudorandomness of Top-Level Schemes of Block Ciphers
Shiho Moriai, Serge Vaudenay
ASIACRYPT2
2000 Efficient Generation of Prime Numbers
Marc Joye, Pascal Paillier, Serge Vaudenay
CHES3
2000 A Statistical Attack on RC6
Henri Gilbert, Helena Handschuh, Antoine Joux, Serge Vaudenay
FSE4
1999 On the Lai-Massey Scheme
Serge Vaudenay
ASIACRYPT1
1999 Resistance Against General Iterated Attacks
Serge Vaudenay
EUROCRYPT1
1999 On the Security of CS-Cipher
Serge Vaudenay
FSE1
1998 Decorrelated Fast Cipher: An AES Candidate Well Suited for Low Cost Smart Card Applications
Guillaume Poupard, Serge Vaudenay
CARDIS2
1998 Cryptanalysis of the Chor-Rivest Cryptosystem
Serge Vaudenay
CRYPTO1
1998 CS-Cipher
Jacques Stern, Serge Vaudenay
FSE2
1998 Computational Alternatives to Random Number Generators
David M'Raïhi, David Naccache, David Pointcheval, Serge Vaudenay
Selected Areas in Cryptography4
1998 Feistel Ciphers with L2-Decorrelation
Serge Vaudenay
Selected Areas in Cryptography1
1998 Provable Security for Block Ciphers by Decorrelation
Serge Vaudenay
STACS1
1998 The Black-Box Model for Cryptographic Primitives
Claus-Peter Schnorr, Serge Vaudenay
J. Cryptol.2
1997 XMX: A Firmware-Oriented Block Cipher Based on Modular Multiplications
David M'Raïhi, David Naccache, Jacques Stern, Serge Vaudenay
FSE4
1997 The Security of the Birational Permutation Signature Schemes
Don Coppersmith, Jacques Stern, Serge Vaudenay
J. Cryptol.3
1996 Minding your p's and q's
Ross J. Anderson, Serge Vaudenay
ASIACRYPT2
1996 Authenticated Multi-Party Key Agreement
Mike Just, Serge Vaudenay
ASIACRYPT2
1996 An Experiment on DES Statistical Cryptanalysis
abstract
Linear cryptanalysis and differential cryptanalysis are the most important methods of attack against block ciphers.Their efficiency have been demonstrated against several ciphers, including the Data Encryption Standard.We prove that both of them can be considered, improved and joined in a more general statistical framework.We also show that the very same results as those obtained in the case of DES can be found without any linear analysis and we slightly improve them into an attack with theoretical complexity 2 42 • 9 .We can apply another statistical attack -the x 2 - cryptanalysis -on the same characteristics without a definite idea of what happens in the encryption process.It appears to be roughly as efficient as both differential and linear cryptanalysis.We propose a new heuristic method to find good characteristics.It has found an attack against DES absolutely equivalent to Matsui's one by following a distinct path.
Serge Vaudenay
CCS1
1996 Hidden Collisions on DSS
Serge Vaudenay
CRYPTO1
1996 On the Weak Keys of Blowfish
Serge Vaudenay
FSE1
1994 On the Need for Multipermutations: Cryptanalysis of MD4 and SAFER
Serge Vaudenay
FSE1
1993 Attacks on the Birational Permutation Signature Schemes
Don Coppersmith, Jacques Stern, Serge Vaudenay
CRYPTO3
1993 Parallel FFT-Hashing
Claus-Peter Schnorr, Serge Vaudenay
FSE2
1992 FFT-Hash-II is not yet Collision-free
Serge Vaudenay
CRYPTO1