,,Cryptanalysis of Block Ciphers with Overdefined Systems of Equations''
Nicolas Courtois and Josef Pieprzyk
http://eprint.iacr.org/2002/044/
Abstract: Several recently proposed ciphers are built with layers of
small S-boxes, interconnected by linear key-dependent layers. Their
security relies
Pawe³ Krawczyk wrote:
In this paper we study the security of such ciphers under an
additional hypothesis: the S-box can be described by an overdefined
system of algebraic equations (true with probability 1). We show that
this hypothesis is true for both Serpent (due to a small size of