Upper Bounds on Differential Characteristics in Twofish

N. Ferguson

August 17, 1998

ABSTRACT: In our original paper, the Twofish block cipher was introduced, and initial estimates of an upper bounds on the probability of a 12-round differential were given. These results used an imperfect model of Twofish. We present an improved model, and show that any 12-round differential characteristic has a probability of at most 2-102.8.

[full text - PDF (Acrobat)] [full text - Postscript]

Photo of Bruce Schneier by Per Ervland.

Schneier on Security is a personal website. Opinions expressed are not necessarily those of Co3 Systems, Inc..