1995-09-01 - Re: Cryptanalysis of S-1

From: “David A. Wagner” <dawagner@phoenix.Princeton.EDU>
To: Ted_Anderson@transarc.com
UTC Datetime: 1995-09-01 23:10:20 UTC
Raw Date: Fri, 1 Sep 95 16:10:20 PDT

From: "David A. Wagner" <dawagner@phoenix.Princeton.EDU>
Date: Fri, 1 Sep 95 16:10:20 PDT
To: Ted_Anderson@transarc.com
Subject: Re: Cryptanalysis of S-1
Ted_Anderson@transarc.com writes:
> Further we have a concrete design principle: the per-round sub-keys
> should not repeat.

Right.  In fact, this design principle has been known for a long time:
the earliest reference I know of is

        author = {Edna K. Grossman and Bryant Tuckerman},
        title = {Analysis of a Weakened {Feistel}-like Cipher},
        booktitle = {1978 International Conference on Communications},
        pages = {46.3.1--46.3.5},
        publisher = {Alger Press Limited},
        year = {1978},
        annote = {Feistel ciphers with identical subkeys in each round
                        are very weak}

David Wagner                                             dawagner@princeton.edu