1

One Page 7, of Document Camellia Design and Analysis

The author says,

In the case of Camellia, the maximum diferential/linear probabilities of s-boxes are $2^{-6}$.

Since Camellia S-boxes are made up from Affine-Inverse-Affine Transformation in $GF(2^8)$ which has Linear Approximation Probability of $2^{-4}$, then why authors wrote it $2^{-6}$.

Does Camellia S-boxes have Linear Approximation probability of $2^{-6}$ or $2^{-4}$?

any body calculated it?

Biv
  • 9,879
  • 2
  • 37
  • 66
crypt
  • 2,291
  • 15
  • 31
  • it has been answered at https://crypto.stackexchange.com/questions/41702/linear-approximation-and-linear-probability-of-camellia-sbox – crypt Aug 22 '17 at 07:29
  • The same question is asked elsewhere , you can find the answer [here](https://crypto.stackexchange.com/questions/41702/linear-approximation-and-linear-probability-of-camellia-sbox/41725#41725) – hardyrama Nov 25 '17 at 12:50
  • @hardyrama your referred link is already mentioned in the above comment. – crypt Nov 26 '17 at 14:49

0 Answers0