文摘
By considering the number of independent variables, we present a new method for finding an upper bound on the maximum differential probability (MDP) for r(r ≥ 2)-round substitution-permutation networks (SPNs). It first finds an upper bound for 2-round SPNs and then uses a recursive technique for r(r ≥ 3)-round SPNs. Our result extends and sharpens known results in that it is more effective for calculating MDP for r(r ≥ 3)-round SPNs and applicable to all SPNs. By applying our method to ARIA, we get an estimated bound of 1.5 ¡Á 2− 98 on MDP for 6-round ARIA.