Abstract:
Round functions in XSL block ciphers consist of three layers. The first is a key addition layer; the second is a nonlinear s-box layer; the third is a linear layer. Here, for a Markov XSL block cipher with a reducible linear transformation, instead of “classical” $r$-round differential characteristic used in differential technique, a $r$-round differential characteristic defined by the sequence of invariant subspace cosets of the linear transformation is considered.
Keywords:Markov cipher, invariant set, reducible linear transformation, differential characteristic.