Lecture Notes in Computer Science vol:2355 pages:165-173
FSE 2001 date:April 02-04, 2001
We present improved SQUARE attacks against the NESSIE and ECTP candidate block ciphers HIEROCRYPT-3 and HIEROCRYPT-L1, designed by Toshiba. We improve over the previous best known attack on five S-box layers of HIEROCRYPT-3 by a factor of 2(128) computational steps with an attack on six layers for 128-bit keys, and extend it to seven S-box layers for longer keys. For HIEROCRYPT-L1 we are able to improve previous attacks up to seven S-box layers (out of twelve).