This invention intends to reduce the amount of calculation required by a
cipher strength estimating device for estimating a ciphertext in
collectively finding session keys for plural rounds of transformation.
The cipher strength estimating device is configured to: first calculate
one session key prospect presumed to be equivalent to a session key for
use at a certain round of transformation in encryption which is
calculated from a key; perform a decrypting operation with the session
key prospect presumed to be true; calculating a session key prospect for
the round immediately preceding the certain round based on the resulting
text thereby calculating session keys for different rounds. This device
enhances the possibility that plural true session keys are calculated
faster.