the strength of LBlock against related-key impossible differential attack is examined.Based on the differential information leakages in sub-key schedule
several sub-key differentials in low weight are constructed
and a 15-round related-key impossible differential distinguisher of LBlock is presented.By extending the distinguisher
related-key impossible differential attacks on 23-round LBlock and 24-round LBlock are presented.The data complexities of the attacks are 2
65.2
and 2
65.6
chosen-plain-text
respectively;the computing complexities of the attacks are 2
66.2
23-round LBlock encryptions and 2
66.6
24-round LBlock encryptions
respectively;the storage complexities of the attacks are 2
61.2
and 2
77.2
bytes of memory space
respectively.The cryptanalysis of reduced-round LBlock are first extended to 23-round and 24-round in this paper.