On Probability of Success in Linear and ... - Bilkent University
On Probability of Success in Linear and ... - Bilkent University
On Probability of Success in Linear and ... - Bilkent University
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
P(rank(k 0 ) ≤ r)<br />
P(rank(k 0 ) ≤ r)<br />
1<br />
0.8<br />
0.6<br />
0.4<br />
0.2<br />
0<br />
1<br />
0.8<br />
0.6<br />
0.4<br />
0.2<br />
0<br />
Equation (19), μ = 16<br />
μ = 8<br />
μ = 4<br />
Experimental, μ = 16<br />
μ = 8<br />
μ = 4<br />
5 10 15 20 25 30<br />
r<br />
(a) Attack on s-box 5; SN = 2.<br />
Equation (19), μ = 12<br />
μ = 6<br />
μ = 2<br />
Experimental, μ = 12<br />
μ = 6<br />
μ = 2<br />
10 20 30 40 50<br />
r<br />
60 70 80 90 100<br />
(b) Attack on s-boxes 2, 5, 6, 7, 8; SN = 2 16 .<br />
Fig. 2. A comparison <strong>of</strong> equation (19) <strong>and</strong> the experimental success rates <strong>of</strong> the 6round<br />
DES attacks tested. The results show a considerable difference for the lower<br />
values <strong>of</strong> µ.<br />
To trace the source <strong>of</strong> this error, we first looked <strong>in</strong>to the normal approximation<br />
for the b<strong>in</strong>omial distribution. Recall that <strong>in</strong> formulation <strong>of</strong> the success<br />
probability,<br />
PS = P (T0 > W¯r)<br />
=<br />
� ∞ � x<br />
0<br />
−∞<br />
fq(y) dy f0(x) dx . (23)<br />
14