{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T13:01:21Z","timestamp":1772283681179,"version":"3.50.1"},"reference-count":37,"publisher":"Walter de Gruyter GmbH","issue":"2","license":[{"start":{"date-parts":[[2016,5,18]],"date-time":"2016-05-18T00:00:00Z","timestamp":1463529600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,6,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Statistical analysis of attacks on symmetric ciphers often requires assuming the normal behaviour of a test statistic. Typically such an assumption is made in an asymptotic sense. In this work, we consider concrete versions of some important\nnormal approximations that have been made in the literature. To do this, we use the Berry\u2013Ess\u00e9en theorem to derive explicit bounds on the approximation errors. A basic mathematical requirement is that such approximation errors\nshould be within reasonable bounds, a point which appears to have been overlooked in many of the earlier works on statistical\naspects of cryptanalysis. Interpreting the error bounds in the cryptanalytic context yields several\nsurprising results. One important implication is that this puts in doubt the applicability of the order statistics\nbased approach for analysing key recovery attacks on block ciphers. This approach has been earlier used to obtain several\nresults on the data complexities of (multiple) linear and differential cryptanalysis. The non-applicability of the order\nstatistics based approach puts a question mark on the data complexities obtained using this approach. Fortunately, we\nare able to recover all of these results by utilising the hypothesis testing framework.\nThis, however, necessitates using normal approximations for the\n                    <jats:inline-formula id=\"eq1_w2aab3b7b9b1b6b1aab1c13b1b1Aa\">\n                      <jats:alternatives>\n                        <m:math xmlns:m=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                          <m:msup>\n                            <m:mi>\u03c7<\/m:mi>\n                            <m:mn>2<\/m:mn>\n                          <\/m:msup>\n                        <\/m:math>\n                        <jats:tex-math>${\\chi ^2}$<\/jats:tex-math>\n                      <\/jats:alternatives>\n                    <\/jats:inline-formula>\n                    and the LLR test statistics considered in earlier works.\nThese approximations themselves have issues which seem to be difficult to resolve satisfactorily. More generally, the message of\nour work is that all cryptanalytic attacks should properly derive and interpret the error bounds for any (normal) approximation that is made.\n                  <\/jats:p>","DOI":"10.1515\/jmc-2016-0006","type":"journal-article","created":{"date-parts":[[2016,5,18]],"date-time":"2016-05-18T06:11:36Z","timestamp":1463551896000},"page":"69-99","source":"Crossref","is-referenced-by-count":7,"title":["Another look at normal approximations in cryptanalysis"],"prefix":"10.1515","volume":"10","author":[{"given":"Subhabrata","family":"Samajder","sequence":"first","affiliation":[{"name":"Applied Statistics Unit, Indian Statistical Institute, B. T. Road 203, Kolkata 700108, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Palash","family":"Sarkar","sequence":"additional","affiliation":[{"name":"Applied Statistics Unit, Indian Statistical Institute, B. T. Road 203, Kolkata 700108, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"374","published-online":{"date-parts":[[2016,5,18]]},"reference":[{"key":"2025120600240360585_j_jmc-2016-0006_ref_000_w2aab3b7b9b1b6b1ab1ab1Aa","doi-asserted-by":"crossref","unstructured":"M. A. Abdelraheem, M. \u00c5gren, P. Beelen and G. Leander,\nOn the distribution of linear biases: Three instructive examples,\nAdvances in Cryptology (CRYPTO 2012),\nLecture Notes in Comput. Sci. 7417,\nSpringer, Berlin (2012), 50\u201367.","DOI":"10.1007\/978-3-642-32009-5_4"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_001_w2aab3b7b9b1b6b1ab1ab2Aa","doi-asserted-by":"crossref","unstructured":"T. Baign\u00e8res, P. Junod and S. Vaudenay,\nHow far can we go beyond linear cryptanalysis?,\nAdvances in Cryptology (ASIACRYPT 2004),\nLecture Notes in Comput. Sci. 3329,\nSpringer, Berlin (2004), 432\u2013450.","DOI":"10.1007\/978-3-540-30539-2_31"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_002_w2aab3b7b9b1b6b1ab1ab3Aa","doi-asserted-by":"crossref","unstructured":"T. Baign\u00e8res, P. Sepehrdad and S. Vaudenay,\nDistinguishing distributions using Chernoff information,\nProvable Security,\nLecture Notes in Comput. Sci. 6402,\nSpringer, Berlin (2010), 144\u2013165.","DOI":"10.1007\/978-3-642-16280-0_10"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_003_w2aab3b7b9b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"V. Bentkus,\nDependence of the Berry\u2013Ess\u00e9en estimate on the dimension,\nLithuanian Math. J. 26 (1986), 110\u2013114.","DOI":"10.1007\/BF00966143"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_004_w2aab3b7b9b1b6b1ab1ab5Aa","doi-asserted-by":"crossref","unstructured":"A. C. Berry,\nThe accuracy of the Gaussian approximation to the sum of independent variates,\nTrans. Amer. Math. Soc. 49 (1941), 122\u2013136.","DOI":"10.1090\/S0002-9947-1941-0003498-3"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_005_w2aab3b7b9b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"E. Biham and A. Shamir,\nDifferential cryptanalysis of DES-like cryptosystems,\nAdvances in Cryptology (CRYPTO'90),\nLecture Notes in Comput. Sci. 537,\nSpringer, Berlin (1990), 2\u201321.","DOI":"10.1007\/3-540-38424-3_1"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_006_w2aab3b7b9b1b6b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"E. Biham and A. Shamir,\nDifferential cryptanalysis of DES-like cryptosystems,\nJ. Cryptology 4 (1991), 3\u201372.","DOI":"10.1007\/BF00630563"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_007_w2aab3b7b9b1b6b1ab1ab8Aa","doi-asserted-by":"crossref","unstructured":"A. Biryukov, C. De Canni\u00e8re and M. Quisquater,\nOn multiple linear approximations,\nAdvances in Cryptology (CRYPTO 2004),\nLecture Notes in Comput. Sci. 3152,\nSpringer, Berlin (2004), 1\u201322.","DOI":"10.1007\/978-3-540-28628-8_1"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_008_w2aab3b7b9b1b6b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"C. Blondeau, A. Bogdanov and G. Leander,\nBounds in shallows and in miseries,\nAdvances in Cryptology (CRYPTO 2013),\nLecture Notes in Comput. Sci. 8042,\nSpringer, Berlin (2013), 204\u2013221.","DOI":"10.1007\/978-3-642-40041-4_12"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_009_w2aab3b7b9b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"C. Blondeau and B. G\u00e9rard,\nMultiple differential cryptanalysis: Theory and practice,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 6733,\nSpringer, Berlin (2011), 35\u201354.","DOI":"10.1007\/978-3-642-21702-9_3"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_010_w2aab3b7b9b1b6b1ab1ac11Aa","doi-asserted-by":"crossref","unstructured":"C. Blondeau, B. G\u00e9rard and K. Nyberg,\nMultiple differential cryptanalysis using LLR and \u03c72${\\chi ^{2}}$ statistics,\nSecurity and Cryptography for Networks,\nLecture Notes in Comput. Sci. 7485,\nSpringer, Berlin (2012), 343\u2013360.","DOI":"10.1007\/978-3-642-32928-9_19"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_011_w2aab3b7b9b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"C. Blondeau, B. G\u00e9rard and J.-P. Tillich,\nAccurate estimates of the data complexity and success probability for various cryptanalyses,\nDes. Codes Cryptogr. 59 (2011), 3\u201334.","DOI":"10.1007\/s10623-010-9452-2"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_012_w2aab3b7b9b1b6b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"A. Bogdanov and E. Tischhauser,\nOn the wrong key randomisation and key equivalence hypotheses in Matsui's algorithm 2,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 8424,\nSpringer, Berlin (2014), 19\u201338.","DOI":"10.1007\/978-3-662-43933-3_2"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_013_w2aab3b7b9b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"J. Daemen and V. Rijmen,\nProbability distributions of correlation and differentials in block ciphers,\nJ. Math. Crypt. 1 (2007), 221\u2013242.","DOI":"10.1515\/JMC.2007.011"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_014_w2aab3b7b9b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"F. C. Drost, W. C. M. Kallenberg, D. S. Moore and J. Oosterhoff,\nPower approximations to multinomial tests of fit,\nJ. Amer. Statist. Assoc. 84 (1989), 130\u2013141.","DOI":"10.1080\/01621459.1989.10478748"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_015_w2aab3b7b9b1b6b1ab1ac16Aa","unstructured":"C.-G. Ess\u00e9en,\nOn the Liapounoff limit of error in the theory of probability,\nArk. Mat. Astron. Fys. A28 (1942), 1\u201319."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_016_w2aab3b7b9b1b6b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"C.-G. Ess\u00e9en,\nA moment inequality with an application to the central limit theorem,\nScand. Actuar. J. 1956 (1956), 160\u2013170.","DOI":"10.1080\/03461238.1956.10414946"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_017_w2aab3b7b9b1b6b1ab1ac18Aa","unstructured":"W. Feller,\nAn Introduction to Probability Theory and Its Applications, Vol. 2,\nJohn Wiley & Sons, New York, 2008."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_018_w2aab3b7b9b1b6b1ab1ac19Aa","doi-asserted-by":"crossref","unstructured":"C. Harpes, G. G. Kramer and J. L. Massey,\nA generalization of linear cryptanalysis and the applicability of Matsui's piling-up lemma,\nAdvances in Cryptology (EUROCRYPT'95),\nLecture Notes in Comput. Sci. 921,\nSpringer, Berlin (1995), 24\u201338.","DOI":"10.1007\/3-540-49264-X_3"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_019_w2aab3b7b9b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"M. Hermelin, J. Y. Cho and K. Nyberg,\nMultidimensional extension of Matsui's algorithm 2,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 5665,\nSpringer, Berlin (2009), 209\u2013227.","DOI":"10.1007\/978-3-642-03317-9_13"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_020_w2aab3b7b9b1b6b1ab1ac21Aa","unstructured":"N. L. Johnson, S. Kotz and N. Balakrishnan,\nContinuous Univariate Distributions, Vol. 1, 2nd ed.,\nJohn Wiley & Sons, New York, 1994."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_021_w2aab3b7b9b1b6b1ab1ac22Aa","unstructured":"N. L. Johnson, S. Kotz and N. Balakrishnan,\nContinuous Univariate Distributions, Vol. 2, 2nd ed.,\nJohn Wiley & Sons, New York, 1995."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_022_w2aab3b7b9b1b6b1ab1ac23Aa","doi-asserted-by":"crossref","unstructured":"P. Junod,\nOn the optimality of linear, differential, and sequential distinguishers,\nAdvances in Cryptology (EUROCRYPT 2003),\nLecture Notes in Comput. Sci. 2656,\nSpringer, Berlin (2003), 17\u201332.","DOI":"10.1007\/3-540-39200-9_2"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_023_w2aab3b7b9b1b6b1ab1ac24Aa","doi-asserted-by":"crossref","unstructured":"P. Junod and S. Vaudenay,\nOptimal key ranking procedures in a statistical cryptanalysis,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 2887,\nSpringer, Berlin (2003), 235\u2013246.","DOI":"10.1007\/978-3-540-39887-5_18"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_024_w2aab3b7b9b1b6b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"B. S. Kaliski Jr and M. J. B. Robshaw,\nLinear cryptanalysis using multiple approximations,\nAdvances in Cryptology (Crypto'94),\nLecture Notes in Comput. Sci. 839,\nSpringer, Berlin (1994), 26\u201339.","DOI":"10.1007\/3-540-48658-5_4"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_025_w2aab3b7b9b1b6b1ab1ac26Aa","doi-asserted-by":"crossref","unstructured":"L. R. Knudsen,\nTruncated and higher order differentials,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 1008,\nSpringer, Berlin (1995), 196\u2013211.","DOI":"10.1007\/3-540-60590-8_16"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_026_w2aab3b7b9b1b6b1ab1ac27Aa","doi-asserted-by":"crossref","unstructured":"G. Leander,\nOn linear hulls, statistical saturation attacks, PRESENT and a cryptanalysis of PUFFIN,\nAdvances in Cryptology (EUROCRYPT 2011),\nLecture Notes in Comput. Sci. 6632,\nSpringer, Berlin (2011), 303\u2013322.","DOI":"10.1007\/978-3-642-20465-4_18"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_027_w2aab3b7b9b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"I. Mantin and A. Shamir,\nA practical attack on broadcast RC4,\nFast Software Encryption,\nLecture Notes in Comput. Sci. 2355,\nSpringer, Berlin (2002), 152\u2013164.","DOI":"10.1007\/3-540-45473-X_13"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_028_w2aab3b7b9b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"M. Matsui,\nLinear cryptanalysis method for DES cipher,\nAdvances in Cryptology (EUROCRYPT'93),\nLecture Notes in Comput. Sci. 765,\nSpringer, Berlin (1993), 386\u2013397.","DOI":"10.1007\/3-540-48285-7_33"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_029_w2aab3b7b9b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"M. Matsui,\nThe first experimental cryptanalysis of the data encryption standard,\nAdvances in Cryptology (CRYPTO'94),\nLecture Notes in Comput. Sci. 839,\nSpringer, Berlin (1994), 1\u201311.","DOI":"10.1007\/3-540-48658-5_1"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_030_w2aab3b7b9b1b6b1ab1ac31Aa","doi-asserted-by":"crossref","unstructured":"S. Murphy,\nThe independence of linear approximations in symmetric cryptanalysis,\nIEEE Trans. Inform. Theory 52 (2006), 5510\u20135518.","DOI":"10.1109\/TIT.2006.885528"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_031_w2aab3b7b9b1b6b1ab1ac32Aa","unstructured":"S. Murphy, F. Piper, M. Walker and P. Wild,\nLikelihood estimation for block cipher keys,\nTechnical Report RHUL-MA-2006-3, Royal Holloway, University of London, 1995."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_032_w2aab3b7b9b1b6b1ab1ac33Aa","unstructured":"V. V. Sazonov,\nOn the multi-dimensional central limit theorem,\nSankhya A 30 (1968), 181\u2013204."},{"key":"2025120600240360585_j_jmc-2016-0006_ref_033_w2aab3b7b9b1b6b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"A. A. Sel\u00e7uk,\nOn probability of success in linear and differential cryptanalysis,\nJ. Cryptology 21 (2008), 131\u2013147.","DOI":"10.1007\/s00145-007-9013-7"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_034_w2aab3b7b9b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"A. Tardy-Corfdir and H. Gilbert,\nA known plaintext attack of FEAL-4 and FEAL-6,\nAdvances in Cryptology (CRYPTO'91),\nLecture Notes in Comput. Sci. 576,\nSpringer, Berlin (1991), 172\u2013181.","DOI":"10.1007\/3-540-46766-1_12"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_035_w2aab3b7b9b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"I. S. Tyurin,\nAn improvement of upper estimates of the constants in the Lyapunov theorem,\nRussian Math. Surveys 65 (2010), 201\u2013202.","DOI":"10.1070\/RM2010v065n03ABEH004688"},{"key":"2025120600240360585_j_jmc-2016-0006_ref_036_w2aab3b7b9b1b6b1ab1ac37Aa","doi-asserted-by":"crossref","unstructured":"A. M. Walker,\nA note on the asymptotic distribution of sample quantiles,\nJ. R. Stat. Soc. Ser. B. Stat. Methodol. 30 (1968), 570\u2013575.","DOI":"10.1111\/j.2517-6161.1968.tb00757.x"}],"container-title":["Journal of Mathematical Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0006\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0006\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T00:24:08Z","timestamp":1764980648000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0006\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5,18]]},"references-count":37,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2016,6,1]]},"published-print":{"date-parts":[[2016,6,1]]}},"alternative-id":["10.1515\/jmc-2016-0006"],"URL":"https:\/\/doi.org\/10.1515\/jmc-2016-0006","relation":{},"ISSN":["1862-2984","1862-2976"],"issn-type":[{"value":"1862-2984","type":"electronic"},{"value":"1862-2976","type":"print"}],"subject":[],"published":{"date-parts":[[2016,5,18]]}}}