摘要 |
<p>To evaluate the randomness of an S-box, the indices of strength against the high-order differential attack method, interpolation attack method, division attack method, and differential linear attack method and the necessary conditions under which the indices have resistances to decoding methods are determined. Whether or not each of function candidates meets part or all of the conditions is checked, and candidates which meet the part or all of the conditions are selected, as necessary. For each selected candidate, the resistance to at least either the differential decoding method or the linear decoding method is evaluated, and function candidates having strong resistances to at least one of them can be selected, as necessary.</p> |