Designing cryptographic permutations and block ciphers using a substitution-permutation network (SPN) approach where the nonlinear part does not cover the entire state has recently gained attention due to favorable implementation characteristics in …

We consider SPN schemes, i.e., schemes whose non-linear layer is defined as the parallel application of t=1 independent S-Boxes over GF(2^n) and whose linear layer is defined by the multiplication with a nt x nt matrix over GF(2). Even if the …

