@inbook{35d1a8325a574947b7587e1f628d2924,
title = "Differential-Linear Cryptanalysis of Serpent",
abstract = "Serpent is a 128-bit SP-Network block cipher consisting of 32 rounds with variable key length (up to 256 bits long). It was selected as one of the 5 AES finalists. The best known attack so far is a linear attack on an 11-round reduced variant. In this paper we apply the enhanced differential-linear cryptanalysis to Serpent. The resulting attack is the best known attack on 11-round Serpent. It requires 2125.3 chosen plaintexts and has time complexity of 2139.2. We also present the first known attack on 10-round 128-bit key Serpent. These attacks demonstrate the strength of the enhanced differential-linear cryptanalysis technique.",
author = "Eli Biham and Orr Dunkelman and N. Keller",
year = "2003",
language = "American English",
volume = "2887",
series = "Lecture Notes in Computer Science",
publisher = "Springer",
pages = "9--21",
editor = "Thomas Johansson",
booktitle = "Fast Software Encryption",
}