what is linear cryptanalysis?
a category of attack launched against block ciphers
powerful attack, aims to approximate block ciphers by means of linear expressions
these expressions are true or false with some bias
we can use this bias to discover key bits
how can bias in S-boxes be used to “guess” keys?
key points from linear relations table for S-boxes:
what is Matsui’s Piling Up Lemma?
what happens with Matsui’s Piling Up Lemma if one of the variables is genuinely unbiased?
what type of attack is linear cryptanalysis?
known plaintext attack (KPA)