Skip to contentScholarGate
LibraryBookshelfDeskReview StudioAssistant
Sign in
On this page
IntuitionHow it worksWhen to use itStrengths & limitationsCommon pitfallsApplicationsFrequently asked🔒 Read the full methodSourcesRelated methods
Cite this pageSpotted an issue on this page? Report or suggest a fix →
Home›Cryptography›Linear Cryptanalysis
Machine learningCryptanalytic technique

Linear Cryptanalysis

Also known as: linear attack, linear approximation, piling-up lemma

Linear cryptanalysis is a known-plaintext attack that exploits linear approximations of a cipher's non-linear transformations to recover secret key bits. Introduced by Mitsuru Matsui in 1993, linear cryptanalysis provides practical attacks on ciphers like DES with computational complexity less than brute force. The technique analyzes statistical biases in how linear combinations of plaintext and ciphertext bits relate to key bits, enabling key recovery with reduced data requirements.

ScholarGate
  1. Machine learning
  2. v1
  3. 2 Sources
  4. PUBLISHED
Cite this page →
Tools & resources
Download slides
Learn & explore

Read the full method

Members only

Sign in with a free account to read this section.

Sign in

Method map

The neighbourhood of related methods — select a node to explore.

Linear Cryptanalysis
AES (Rijndael)Differential Cryptanalys…Side-Channel Analysis

When to use it

Linear cryptanalysis is used in cryptanalysis research and cipher design evaluation. It guides cipher designers in selecting S-boxes and transformations that resist linear approximations. Modern ciphers are designed with proven bounds on linear approximation strength.

Strengths & limitations

Strengths
  • Practical attack on DES requiring 2^43 plaintext-ciphertext pairs and 2^39 operations
  • Well-formalized mathematical framework (piling-up lemma) for analyzing approximation biases
  • Complements differential cryptanalysis, finding weaknesses differential analysis might miss
  • Shapes cipher design requirements for S-box selection and round transformation
Limitations
  • Modern ciphers (AES) are carefully designed to resist linear cryptanalysis with provable bounds
  • Requires known plaintext-ciphertext pairs, which may not be available in all scenarios
  • Computational and data requirements can exceed practical feasibility for well-designed ciphers
  • Discovering strong linear approximations for modern ciphers is extremely difficult

Frequently asked

What is the piling-up lemma?

The piling-up lemma provides a method for computing the bias of linear approximations across multiple rounds by combining biases of individual round approximations. It is foundational to linear cryptanalysis.

How does AES resist linear cryptanalysis?

AES uses S-boxes chosen to minimize maximum linear approximation probability and a diffusion layer ensuring fast diffusion of linear biases across rounds. Proven bounds guarantee no practical linear approximations.

What is the difference between linear and differential cryptanalysis?

Differential analysis studies input-output differences, while linear analysis studies linear approximations (XOR of plaintext and ciphertext bits). Both exploit structural weaknesses in ciphers.

Can linear cryptanalysis break modern ciphers?

Not practically. Modern ciphers like AES have provable bounds on linear approximations making attacks computationally infeasible.

How do I evaluate linear resistance in my cipher design?

Analyze S-box linear approximation tables and compute maximum bias through rounds using the piling-up lemma. Ensure maximum bias is negligible across all possible linear approximations.

Sources

  1. Matsui, M. (1993). Linear cryptanalysis method for DES cipher. In Advances in Cryptology - EUROCRYPT 1993, LNCS 765, pp. 386-397. DOI: 10.1007/3-540-48285-7_33 ↗
  2. Matsui, M. (1994). The first experimental cryptanalysis of the Data Encryption Standard. In Advances in Cryptology - CRYPTO 1994, LNCS 839, pp. 1-11. DOI: 10.1007/3-540-48658-5_1 ↗

How to cite this page

ScholarGate. (2026, June 3). Linear Cryptanalysis. ScholarGate. https://scholargate.app/en/cryptography/linear-cryptanalysis

Related methods

AES (Rijndael)Differential CryptanalysisSide-Channel Analysis

Which method?

Set this method beside its closest kin and read them side by side — the library lays the books on the table; the choice is yours.

  • AES (Rijndael)Cryptography↔ compare
  • Differential CryptanalysisCryptography↔ compare
  • Side-Channel AnalysisCryptography↔ compare
Compare side by side →

Referenced by

AES (Rijndael)Differential Cryptanalysis

Similar methods

Symmetric Key CryptanalysisDifferential CryptanalysisSide-Channel AnalysisAES (Rijndael)Lattice-Based CryptographyPost-Quantum Cryptography (Kyber)RSA Cryptosystem AnalysisRSA Cryptosystem

Related reference concepts

Block Ciphers and AESSymmetric CryptographyStream CiphersSecurity and CryptographyPost-Quantum CryptographyRandomness and Pseudorandomness

Spotted an issue on this page? Report or suggest a fix →

ScholarGate — Linear Cryptanalysis (Linear Cryptanalysis). Retrieved 2026-07-21 from https://scholargate.app/en/cryptography/linear-cryptanalysis · Dataset: https://doi.org/10.5281/zenodo.20539026
Quick facts
Originator
Mitsuru Matsui
Subfamily
Cryptanalytic technique
Year
1993
Type
linear approximation attack
Related methods
AES (Rijndael)Differential CryptanalysisSide-Channel Analysis
ScholarGate

A content-first reference library for research methods — what each one is, how it works, and where it comes from.

Open data (CC-BY)

Explore

  • Library
  • Search the library…
  • Browse by field
  • Fields
  • Journey
  • Compare
  • Which method?

Reference

  • Subjects
  • Atlas
  • Glossary
  • Methodology
  • Philosophy

Your tools

  • Bookshelf
  • Desk
  • Chat

Company

  • About
  • Pricing
  • Contact
  • Suggest a method

Entries are compiled from published sources for reference. Verifying the accuracy and suitability of any information for your own use remains your responsibility.

© 2026 ScholarGate · A research-method reference library
  • Privacy
  • Cookies
  • Terms
  • Delete account