Truncated differentials of SAFER

  • Lars R. Knudsen
  • Thomas A. Berson
Block Ciphers — Analysis
In this paper we do differential cryptanalysis of SAFER. We consider “truncated differentials” and apply them in an attack on 5-round SAFER, which finds the secret key in time much faster than by exhaustive search.


