@misc{13576, author = {H{\r a}vard Raddum and Lars Knudsen}, title = {A Differential Attack on Reduced-Round SC2000}, abstract = {SC2000 is a 128-bit block cipher with key length of 128, 192 or 256 bits, developed by Fujitsu Laboratories LTD. For 128-bit keys, SC2000 consists of 6.5 rounds, and for 192- and 256-bit keys it consists of 7.5 rounds. In this paper we demonstrate two different 3.5-round differential characteristics that hold with probabilities 2-106 and 2-107. These characteristics can be used to extract up to 32 bits of the first and last round keys in a 4.5-round variant of SC2000.}, year = {2001}, journal = {Selected Areas in Cryptography 2001}, volume = {2259}, pages = {190 - 198}, month = {12/2001}, publisher = {Lecture Notes in Computer Science, Springer Verlag}, issn = {0302-9743}, isbn = {978-3-540-43066-7}, doi = {10.1007/3-540-45537-X_15}, }