Public Comments Regarding The Advanced Encryption Standard (AES) Development Effort Round 1 Comments [in response to a notice in the September 14, 1998 Federal Register (Volume 63, Number 177; pages 49091-49093)] From: "Yasuyoshi Kaneko" <
[email protected]> To: <
[email protected]> Subject: AES Candidate Comments Date: Tue, 25 Aug 1998 11:43:28 +0900 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 4.72.2106.4 X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4 Messrs. Information Technology Laboratory I am Y.Kaneko belonging Telecommunications Advancement Organization of Japan(TAO). I have found the specifications of all AES candidate Algolizums on web and begun to read. In my opinion, these 15 ciphers are classified to 4 groups. Namely 'DES-type' , 'IDEA-type' , 'SAFER-type' and 'other-type' are found out from these specifications. 'DES-type' ciphers are 'DEAL', 'DFC', 'E2' and 'LOKI97' , these ciphers have feistel structures with a F-function. 'IDEA-type' ciphers are 'CAST-256', 'MARS', 'RC6' and 'TWOFISH', these ciphers have paralell 4 inputs and 4 outputs with some (F-) functions. 'SAFER-type' ciphers are 'CRYPTON', 'MAGENTA', 'RIJENDA', 'SAFER+' and 'SERPENT', these ciphers have a kind of Pseude-Hadamard Transform structure with invertible functions per same bits-length input/output. 'other-type' ciphers are 'HPC' and 'FLOG' these ciphers have particular structures with original algolithms. The differences of the first three types are summarized as followings: 1) Differential and Linear cryptanalysis From the viewpoint of the differential and linear cryptanalysis, supposing that r-round cipher (which round numbers would be logically and experimentaly obtained) gives an enough strong ciphers for each types then 'DES-type' ciphers need r+3 or r+2 round to keep security, because (r-2)-round or (r-3)-round differential or linear attacks are possible for the feistel structure, 'IDEA-type' ciphers and 'SAFER-type' ciphers need r+1 round to keep security in general meaning.