IT lexicon Security Differential cryptanalysis

Differential cryptanalysis

Security På svenska → Updated: 2026-08-03

Breaks ciphers by feeding in pairs with a known difference and watching what the difference becomes on the far side.

Published in 1990 by Eli Biham and Adi Shamir. The attacker picks plaintext pairs with a chosen difference and studies how that difference propagates through the cipher's rounds. If some pattern holds more often than chance allows, candidates for the round keys can be sifted out.

The attack needs large quantities of chosen plaintexts and is rarely practical against a deployed system, but it changed how ciphers are built: resistance to differential cryptanalysis now has to be demonstrated rather than assumed. Remarkably, DES was already immune. IBM and the NSA knew the technique in 1974 and classified it — something Don Coppersmith only confirmed publicly in 1994.

← Back to the lexicon