Biryukov, A.Nakahara, Jr. J.Yıldırım H. M.2016-02-082016-02-0820140377-0427http://hdl.handle.net/11693/26660This paper describes a new cryptanalytic technique that combines differential cryptanalysis with Shannon entropy. We call it differential entropy (DE). The objective is to exploit the non-uniform distribution of output differences from a given mapping as a distinguishing tool in cryptanalysis. Our preferred target is the IDEA block cipher, since we detected significantly low entropy at the output of its multiplication operation. We looked to further extend this entropy analysis to larger components and for a number of rounds. We present key-recovery attacks on up to 2.5-round IDEA in the single-key model and without weak-key assumptions. © 2013 Elsevier B.V. All rights reserved.EnglishDifferential cryptanalysisIDEA block cipherShannon entropyBlock ciphersCryptanalytic techniquesDifferential cryptanalysisDifferential entropyKey-recovery attacksMultiplication operationsNon-uniform distributionLyapunov methodsSecurity of dataCryptographyDifferential entropy analysis of the IDEA block cipherArticle10.1016/j.cam.2013.08.0021879-1778