Research Article
Unveiling the Neutral Difference and Its Automated Search
Table 2
Key recovery attacks on round-reduced LEA.
| Cipher | Round | Type | Data (CP) | Time | Ref. |
| LEA192 | 14/28 | DC | | | [16] | 18/28 | DL | | | [6] | 18/28 | DL (ND) | | | This work |
| LEA256 | 15/32 | DC | | | [16] | 18/32 | DL | | | [6] | 18/32 | DL (ND) | | | This work |
|
|
DL = differential-linear distinguishers, DL (ND) = DL distinguishers combined with neutral difference technique, DC = differential cryptanalysis, CP = chosen-plaintexts.
|