From: Multidimensional linear cryptanalysis with key difference invariant bias for block ciphers
k14:17 | S9(k18:21)3 | δ14:17 | k14:17 | S9(k18:21)3 | δ14:17 |
---|---|---|---|---|---|
0000 | 0 | 1100 | 0010 | 1 | 0100 |
0111 | 0 | 1100 | 1001 | 1 | 0100 |
1011 | 0 | 1100 | 1101 | 1 | 0100 |
1100 | 0 | 1100 | 0110 | 1 | 0100 |
0000 | 1 | 0111 | 0010 | 0 | 1111 |
0011 | 0 | 0111 | 1001 | 0 | 1111 |
1111 | 1 | 0111 | 1101 | 0 | 1111 |
0100 | 0 | 0111 | 0110 | 0 | 1111 |
0111 | 1 | 0111 | 0101 | 0 | 1011 |
1000 | 1 | 0111 | 1010 | 1 | 1011 |
1011 | 1 | 0111 | 1110 | 0 | 1011 |
1100 | 1 | 0111 | 0001 | 1 | 1011 |
0100 | 1 | 1010 | 0001 | 0 | 1001 |
1110 | 1 | 1010 | 1000 | 0 | 1001 |
0011 | 1 | 0110 | 1010 | 0 | 0101 |
0101 | 1 | 0110 | 1111 | 0 | 0101 |