This publication constitutes the refereed court cases of the overseas convention at the conception and purposes of Cryptographic suggestions, EUROCRYPT 2003, held in Warsaw, Poland in may perhaps 2003.

The 37 revised complete papers awarded including invited papers have been rigorously reviewed and chosen from 156 submissions. The papers are geared up in topical sections on cryptanalysis, safe multi-party conversation, zero-knowledge protocols, foundations and complexity-theoretic protection, public key encryption, new primitives, elliptic curve cryptography, electronic signatures, information-theoretic cryptography, and workforce signatures.

Meier, Correlations in RC6 with a reduced number of rounds, Fast Software Encryption FSE’00, LNCS, vol. 1978, Springer-Verlag, 2000, pp. 94– 108. 16. M. Luby and C. Rackoff, How to construct pseudorandom permutations from pseudorandom functions, SIAM Journal on Computing 17 (1988), no. 2, 373–386. 17. M. Matsui, Linear cryptanalysis method for DES cipher, Advances in Cryptology – EUROCRYPT’93, LNCS, vol. 765, Springer-Verlag, 1993, pp. 386–397. 18. , The first experimental cryptanalysis of the Data Encryption Standard, Advances in Cryptology – CRYPTO’94, LNCS, vol.

Let be a sequential likelihood-ratio test with stopping bounds τup and τdown , with τup > τdown and error probabilities 0 < α < 1 and 0 < β < 1, β then τdown ≥ 1−α and τup ≤ 1−β α . β 1−β The approximation τdown 1−α and τup α is known as “Wald’s approximation”. The following theorem gives some credit to this approximation. Theorem 9. Let us assume we select for given α, β ∈]0, 1[, where α+β ≤ 1, the β 1−β stopping bounds τdown 1−α and τup α . Then it holds that the sequential likelihood-ratio test with stopping bounds τdown and τup has error probabilities α β α and β where α ≤ 1−β , β ≤ 1−α and α + β ≤ α + β.

Ch Abstract. In this paper, we consider the statistical decision processes behind a linear and a differential cryptanalysis. By applying techniques and concepts of statistical hypothesis testing, we describe precisely the shape of optimal linear and differential distinguishers and we improve known results of Vaudenay concerning their asymptotic behaviour. Furthermore, we formalize the concept of “sequential distinguisher” and we illustrate potential applications of such tools in various statistical attacks.

