Affine linear cryptanalysis

Kaisa Nyberg*

*Corresponding author for this work

Research output: Contribution to journalArticleScientificpeer-review

3 Citations (Scopus)
150 Downloads (Pure)


In this paper a new variant of the linear cryptanalysis method for block ciphers is proposed. It is based on the existing method of multidimensional linear cryptanalysis, but offers the option of discarding a whole half-space of linear approximations that do not contribute to statistical nonrandomness of the multidimensional linear cryptanalysis, and keep only the information extracted from an affine subspace for statistical inference. Also the connections of the new affine cryptanalysis with conditional linear cryptanalysis and multiple linear cryptanalysis are described and demonstrated in the context of state-of-the-art ciphers.

Original languageEnglish
Pages (from-to)367-377
Number of pages11
JournalCryptography and Communications
Issue number3
Publication statusPublished - 15 May 2019
MoE publication typeA1 Journal article-refereed


  • Block cipher
  • Conditional linear cryptanalysis
  • Linear approximation
  • Linear cryptanalysis
  • Multidimensional linear cryptanalysis
  • Multiple linear cryptanalysis


Dive into the research topics of 'Affine linear cryptanalysis'. Together they form a unique fingerprint.

Cite this