Abstract:
In this work we present a differential attack on MARS which breaks 8 core and 8 mixing rounds with pre- and post-whitening. This attack is based on a new 8-core round differential characteristic with probability $2^{-98}$ and allows to recover more subkeys bits than previously published attacks (752 instead of 682) faster than exhaustive key search. The success probability of the attack is more than 0{,}99. The attack requires $2^{105}$ chosen plaintexts, $2^{109}$ bytes of memory and $2^{231}$ encryptions.