Cryptography and Communications

, Volume 1, Issue 1, pp 47–69

New criteria for linear maps in AES-like ciphers


DOI: 10.1007/s12095-008-0003-x

Cite this article as:
Daemen, J. & Rijmen, V. Cryptogr. Commun. (2009) 1: 47. doi:10.1007/s12095-008-0003-x


In this paper, we study a class of linear transformations that are used as mixing maps in block ciphers. We address the question which properties of the linear transformation affect the probability of differentials and characteristics over Super boxes. Besides the expected differential probability (EDP), we also study the fixed-key probability of characteristics, denoted by DP[k]. We define plateau characteristics, where the dependency on the value of the key is very structured. Our results show that the distribution of the key-dependent probability is not narrow for characteristics in the AES Super box and hence the widely made assumption that it can be approximated by the EDP, is not justified. Finally, we introduce a property of linear maps which hasn’t been studied before. We call this property related differentials. Related differentials don’t influence the EDP of characteristics, but instead they affect the distribution of their DP[k] values.


AES-like ciphers Linear maps EDP 

Copyright information

© Springer Science + Business Media, LLC 2008

Authors and Affiliations

  1. 1.STMicroelectronicsZaventemBelgium
  2. 2.IAIKGraz University of TechnologyGrazAustria
  3. 3.ESAT/COSICK.U.LeuvenBelgium