Linear and differential cryptanalysis

The table below contains links to slides and exercise sheets for my lecture about linear and differential cryptanalysis at the spring school on symmetric cryptography, on March 11th 2025. The lecture material and exercises for linear cryptanalysis are based on the first two chapters of the book Linear Cryptanalysis, to appear in winter 2025 with Cambridge University Press.

Time Description Resources
09:00-10:30 Linear cryptanalysis — lecture Slides
11:00-12:30 Linear cryptanalysis — exercises Exercise sheet
14:30-16:00 Differential cryptanalysis — lecture Slides
16:30-18:00 Differential cryptanalysis — exercises Exercise sheet