| |
| | Towards the 128-bit Era: AES Candidates |
 | | However, while it seems that the series of byte substitutions, followed by a Pseudo-Hadamard Transform, mixes together the two halves of the block well enough, attacks are possible against this type of construction that make it not much stronger than normal DES, at least in theory. |
 | | This design is not perfect: since the expression for one of the outputs of a PHT has a factor of two in it, one can, using chosen plaintexts where only the least significant byte of one particular half is varied, uncover some facts about the S-boxes used, for example. |
 | | Thus, something that is designed for fast software encryption, with the required security, will be more optimal if it comes from a fresh design process. |
| friedo.szm.sk /krypto/JS/co0408.htm |
|