Unlike the situation with dierential cryptanalysis in which we have seen
big improvements over the rst attack, RC5 has appeared to be extremely
resistant to linear cryptanalysis. Moriai, Aoki, and Ohta [15] investigated
the strength of RC5 against linear cryptanalysis by focusing on the bias of
linear approximations for xed keys, rather than the average bias (see x9.1)
over al l keys. They also considered a mini-version of RC5 with much reduced
word size and computed the percentage of keys that yield ciphers less
resistant to linear cryptanalysis than the average case analysis might suggest.
Selcuk [21] implemented the rst linear attack [7] and showed that the
success rate of the attack is much less than the early theoretical estimates
due to some hidden assumptions