MARS Attacks! Preliminary Cryptanalysis of Reduced-Round MARS Variants

J. Kelsey and B. Schneier

Third AES Candidate Conference, 2000, to appear

ABSTRACT: In this paper, we discuss ways to attack various reduced-round variants of MARS. We consider cryptanalysis of two reduced-round variants of MARS: MARS with the full mixing layers but fewer core rounds, and MARS with each of the four kinds of rounds reduced by the same amount. We develop some new techniques for attacking both of these MARS variants. Our best attacks break MARS with full mixing and five core rounds (21 rounds total), and MARS symmetrically reduced to twelve rounds (3 of each kind of round).

[full text - postscript] [full text - PDF (Acrobat)]

