Lecture Notes in Computer Science vol:2513 pages:315-326
ICICS 2002 date:December 09-12, 2002
This paper presents a large collection of new weak-key classes for the IDEA cipher. The classes presented in this paper contain 2(53) -2(64) weak keys (as compared with 2(51) differential weak keys presented by Daemen at CRYPTO'93 and 2(63) differential-linear weak-keys presented by Hawkes at EUROCRYPT'98). The novelty of our approach is in the use of boomerang distinguishers for the weak-key class membership test. We also show large weak-key classes for reduced-round versions of IDEA.