We present improved Square attacks against the NESSIE and ECTP candidate block ciphers Hierocrypt-3 and Hierocrypt-L1, designed by Toshiba. We improve over the previous best known attack on five S-box layers of Hierocrypt-3 by a factor of 2128 computational steps with an attack on six layers for 128-bit keys, and extend it to seven S-box layers for longer keys. For
Hierocrypt-L1 we are able to improve previous attacks up to seven S-box layers (out of twelve).
F.W.O. Postdoctoral Researcher, sponsored by the Fund for Scientific Research -Flanders (Belgium)
sponsored in part by GOA project Mefisto 2000/06