Security of Loki97
- Knudsen and Rijmen, Jan. 1999, present weakness in the round function that allow differential and linear attacks
- Linear Attacks
- They claim that the f -function is imbalanced
- Part of the 2nd S-boxes’ inputs are determined by the round key alone (the output bits may not be balanced)
- Differential Attacks
- 1-bit input differences have a relatively large probability to generate 1-bit output differences