Higher-Order Differential Cryptanalysis

Influence of the Linear Layer on the Algebraic Degree in SP-Networks

We consider SPN schemes, i.e., schemes whose non-linear layer is defined as the parallel application of t=1 independent S-Boxes over GF(2^n) and whose linear layer is defined by the multiplication with a nt x nt matrix over GF(2). Even if the …