29.01.2013 Views

On Probability of Success in Linear and ... - Bilkent University

On Probability of Success in Linear and ... - Bilkent University

On Probability of Success in Linear and ... - Bilkent University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

P(rank(k 0 ) ≤ r)<br />

P(rank(k 0 ) ≤ r)<br />

1<br />

0.8<br />

0.6<br />

0.4<br />

0.2<br />

0<br />

1<br />

0.8<br />

0.6<br />

0.4<br />

0.2<br />

0<br />

Equation (19), μ = 16<br />

μ = 8<br />

μ = 4<br />

Experimental, μ = 16<br />

μ = 8<br />

μ = 4<br />

5 10 15 20 25 30<br />

r<br />

(a) Attack on s-box 5; SN = 2.<br />

Equation (19), μ = 12<br />

μ = 6<br />

μ = 2<br />

Experimental, μ = 12<br />

μ = 6<br />

μ = 2<br />

10 20 30 40 50<br />

r<br />

60 70 80 90 100<br />

(b) Attack on s-boxes 2, 5, 6, 7, 8; SN = 2 16 .<br />

Fig. 2. A comparison <strong>of</strong> equation (19) <strong>and</strong> the experimental success rates <strong>of</strong> the 6round<br />

DES attacks tested. The results show a considerable difference for the lower<br />

values <strong>of</strong> µ.<br />

To trace the source <strong>of</strong> this error, we first looked <strong>in</strong>to the normal approximation<br />

for the b<strong>in</strong>omial distribution. Recall that <strong>in</strong> formulation <strong>of</strong> the success<br />

probability,<br />

PS = P (T0 > W¯r)<br />

=<br />

� ∞ � x<br />

0<br />

−∞<br />

fq(y) dy f0(x) dx . (23)<br />

14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!