Improved Integral Attacks on Reduced Round Camellia
In this paper a method is presented to extend the length of integral distinguisher of Feistel-SP structure, based on which a new 8-round distinguisher of Camellia is proposed. Moreover, the authors improve integral attacks on reduced round Camellia without FL/FL-1. They attack 11-round Camellia-128 with the data complexity of 2120 and the time complexity of 2125.5, and 12-round Camellia-256 with the data complexity of 2120 and the time complexity of 2214.3. The result is the best one of integral attacks on reduced round Camellia so far.