## On the Optimality of Linear, Differential, and Sequential Distinguishers

In this paper, we consider the statistical decision processes behind a linear and a differential cryptanalysis. By applying techniques and concepts of statistical hypothesis testing, we describe precisely the shape of optimal linear and differential distinguishers and we improve known results of Vaudenay concerning their asymptotic behaviour. Furthermore, we formalize the concept of sequential distinguisher'' and we illustrate potential applications of such tools in various statistical attacks.

Published in:
The International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2003, 2656, 17-32
Presented at:
The International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2003, Warsaw, Poland, May 4-8, 2003
Year:
2003
Keywords:
Laboratories: