Lecture Notes in Computer Science vol:1636 pages:46-59
FSE 1999 date:March 24-26, 1999
In this paper we present an attack on a reduced round version of CRYPTON. The attack is based on the dedicated SQUARE attack. We explain why the attack also works on CRYPTON and prove that the entire 256-bit user key for 6 rounds of CRYPTON can be recovered with a complexity of 2(56) encryptions, whereas for SQUARE 2(72) encryptions are required to recover the 128-bit user key.