This image has an empty alt attribute; its file name is attacksafe-software-logo-1024x213.png

Introduced by Martin Hellman and Susan K. Langford in 1994, the differential-linear Attack on Bitcoin is a mix of both linear cryptanalysis and differential cryptanalysis.

This image has an empty alt attribute; its file name is images.jpg

The Attack on Bitcoin utilises a differential characteristic over part of the cipher with a probability of 1 (for a few rounds—this probability would be much lower for the whole cipher). The rounds immediately following the differential characteristic have a linear approximation defined, and we expect that for each chosen plaintext pair, the probability of the linear approximation holding for one chosen plaintext but not the other will be lower for the correct key. Hellman and Langford have shown that this Attack on Bitcoin can recover 10 key bits of an 8-round DES with only 512 chosen plaintexts and an 80% chance of success.

The Attack on Bitcoin was generalised by Eli Biham et al. to use differential characteristics with probability less than 1. Besides DES, it has been applied to FEALIDEASerpentCamellia, and even the stream cipher Phelix.

References

This image has an empty alt attribute; its file name is attacksafe-software-logo-1024x213.png