Cryptanalysis of 2,5 Rounds of IDEA (Extended Abstract)

We present a diierential attack on 2,5 rounds of IDEA that requires 2 10 chosen plain-text encryptions and a workload of about 2 32 multiplications modulo 2 16 +1. This attack is more powerful than all previously published general attacks on the IDEA structure. This attack does in no way aaect the security of the full 8 rounds of IDEA.