We shall consider the e ect of a change in block cipher mode on three forms of cryptanalysis; exhaustive search, di erential cryptanalysis and linear cryptanalysis. Exhaustive search In an exhaustive search attack, the cryptanalyst tries each key in turn. The only complicating issue in mounting an exhaustive key search is in being able to recognize the correct plaintext when it has been recovered. 3). If the CFB mode is used, then the previous ciphertext will also be required to recover a candidate pair of plaintext and ciphertext.

M. Adams. A Formal and Practical Design for Substitution - Permutation Network Cryptosystems. PhD thesis, Queen's University, Kingston, Canada, 1990. M. Adams. On Immunity against Biham and Shamir's \Di erential Cryptanalysis". Information Processing Letters, 41(2):77{80, 1992. M. E. Tavares. Designing S-boxes for ciphers resistant to di erential cryptanalysis. In W. Wolfowicz, editor, Proceedings of the 3rd symposium on State and Progress of Research in Cryptography, 1993, pages 181{190. Fondazione Ugo Bordoni, 1993.

While this an impractical attack, it is important as it represents the rst cryptanalytic breakthrough with regards to Khufu. Despite the nice features of these ciphers and what is, so far, fairly limited success in cryptanalysis, they have failed to capture much attention outside the research community. 7 MMB and 3-WAY In connection with his work in the analysis of IDEA, Daemen has made a proposal for a di erent block cipher based on the use of modular multiplication [35]. MMB (Modular Multiplication based Block cipher) is a 128-bit block cipher with a key of length 128 bits.

