Abstract:
Arbitrary block iterative cipher scheme with random independent binary input and output vectors is considered. A matrix formula for the spectrum of the scheme output distribution is obtained by means of the pseudo-Boolean linear representation of the iterative vector-function. Based on this formula, a statistical criterion of the hypothesis testing that binary vectors are obtained as an output of the scheme against the hypothesis of their uniform distribution is given. Asymptotic type I and type II errors are calculated. An experimental comparison of the criterion with the “Bookstack” test (and its proposed modification) is done during the construction of a distinguishing attack on the mini-models of the block cipher PRESENT (with block size 12 bits and the number of rounds $R\le10$).
Keywords:binary vector-function, block iterative cipher scheme, spectrum of distribution, distinguishing attack, the “Bookstack” test.