1

One Page 7, of Document Camellia Design and Analysis

The author says,

In the case of Camellia, the maximum diferential/linear probabilities of s-boxes are $2^{-6}$.

Since Camellia S-boxes are made up from Affine-Inverse-Affine Transformation in $GF(2^8)$ which has Linear Approximation Probability of $2^{-4}$, then why authors wrote it $2^{-6}$.

Does Camellia S-boxes have Linear Approximation probability of $2^{-6}$ or $2^{-4}$?

any body calculated it?

Biv
  • 10,088
  • 2
  • 42
  • 68
crypt
  • 2,522
  • 22
  • 33

0 Answers0