Improved cryptanalysis of RC5

  • Alex Biryukov
  • Eyal Kushilevitz
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 1403)


RC5 is a fast block cipher designed by Ron Rivest in 1994. Since then several attempts of cryptanalysis of this cipher were published. The best previously known attack requires 254 chosen plaintexts in order to derive the full set of 25 subkeys for the 12 round RC5 with 32 bit words. In this paper we show a drastic improvement of these results due to a novel partial differential approach. Our attack requires 244 chosen plaintexts. We show that the 64 bit word version of RC5 is also much weaker than it was expected.


block ciphers RC5 differential cryptanalysis 


Authors and Affiliations

  • Alex Biryukov
    • 1
  • Eyal Kushilevitz
    • 1
  1. 1.Applied Mathematics Department, Computer Science DepartmentTechnion - Israel Institute of TechnologyHaifaIsrael

