International Conference on the Theory and Application of Cryptology and Information Security

ASIACRYPT 2008: Advances in Cryptology - ASIACRYPT 2008 pp 441-454

An Improved Impossible Differential Attack on MISTY1

  • Orr Dunkelman
  • Nathan Keller
Conference paper

DOI: 10.1007/978-3-540-89255-7_27

Volume 5350 of the book series Lecture Notes in Computer Science (LNCS)


MISTY1 is a Feistel block cipher that received a great deal of cryptographic attention. Its recursive structure, as well as the added FL layers, have been successful in thwarting various cryptanalytic techniques. The best known attacks on reduced variants of the cipher are on either a 4-round variant with the FL functions, or a 6-round variant without the FL functions (out of the 8 rounds of the cipher).

In this paper we combine the generic impossible differential attack against 5-round Feistel ciphers with the dedicated Slicing attack to mount an attack on 5-round MISTY1 with all the FL functions with time complexity of 246.45 simple operations. We then extend the attack to 6-round MISTY1 with the FL functions present, leading to the best known cryptanalytic result on the cipher. We also present an attack on 7-round MISTY1 without the FL layers.

Download to read the full conference paper text

Copyright information

© Springer-Verlag Berlin Heidelberg 2008

Authors and Affiliations

  • Orr Dunkelman
    • 1
  • Nathan Keller
    • 2
  1. 1.Département d’Informatique, CNRS, INRIA’Ecole Normale SupérieureParisFrance
  2. 2.Einstein Institute of MathematicsHebrew UniversityJerusalemIsrael