Cryptanalysis of Five Rounds of CRYPTON Using Impossible Differentials

An block cipher CRYPTON based on the structure of SQUARE is a candidate algorithm for the AES. Recently Lim changes the S-box construction and key scheduling, and suggested modified version(version 1.0) in FSE'99. In this paper we present an attack on CRYPTON reduced to 5 rounds. This attack is based on impossible differentials[7]. 4 rounds of CRYPTON has impossible differential, we use this to show that CRYPTON version 1.0 reduced to 5 rounds can be attacked using 2 83.4 chosen plaintext and ciphertext pairs. This attack can be also applied to CRYPTON version 0.5 using less chosen plaintext and ciphertext pairs.