Der Angriff wird als chosen plaintext attack ausgeführt.

Don Coppersmith, einer der DES-Entwickler bei IBM, gab im Jahr 1994 an, dass Sicherheit gegen diesen Angriff eines der Entwicklungsziele war.

Differential cryptanalysis seeks to find the difference between related plaintexts that are encrypted. Observing the desired output difference (between two chosen or known plaintext inputs) suggests possible key values. 2–21. I

{\displaystyle SX_{O}^{\prime }} This would have allowed room for a more efficient S-box, even if it is 16-uniform the probability of attack would have still been 2−200.

p 0 For example, with the current S-box AES emits no fixed differential with a probability higher than (4/256)50 or 2−300 which is far lower than the required threshold of 2−128 for a 128-bit block cipher.

