Sung, JaechulKim, JongsungLee, ChanghoonHong, SeokhieWulf, ChristopherLucks, StefanYau, Po-Wah2019-08-262019-08-2620053-88579-403-9https://dl.gi.de/handle/20.500.12116/24851Related-cipher attack was introduced by Hongjun Wu in 2002 [25]. We can consider related ciphers as block ciphers with the same round function but different number of rounds. This attack can be applied to related ciphers by using the fact that their key schedules do not depend on the total number of rounds. In this paper we introduce differential related-cipher attack on block ciphers, which combine related- cipher attack with differential cryptanalysis. We apply this attack to the block ciphers ARIA [15] and SC2000 [24]. Furthermore, related-cipher attack can be combined with other block cipher attacks such as linear cryptanalysis, higher-order differential crypt- analysis, and so on. With these combined attacks we also analyze some other block ciphers which use flexible number of rounds, SAFER++, CAST-128 and DEAL.enBlock CipherRelated-Cipher AttackRelated-Key AttackSlide AttackDifferential CryptanalysisARIASC2000SAFER++CAST-128DEALRelated-cipher attacks on block ciphers with flexible number of roundsText/Conference Paper1617-5468