This paper describes a new differential-style attack, which we call the boomerang attack. This attack has several interesting applications. First, we disprove the oft-repeated claim that eliminating all high-probability differentials for the whole cipher is sufficient to guarantee security against differential attacks. Second, we show how to break COCONUT98, a cipher designed using decorrelation techniques to ensure provable security against differential attacks, with an advanced differential-style attack that needs just 2^16 adaptively chosen texts. Also, to illustrate the power of boomerag techniques, we give new attacks on Khufu-16 and on 16 rounds of CAST-256.
Click Here to download this article