, about the branch number ?

,

, } ? P 2 (M I + a) has information set K , p 0 + p 1 ? C K and then R(p 0 ) + R(p 1 )

,

Midori: A block cipher for low energy, ASIACRYPT 2015, pp.411-436, 2015. ,

,

, The Design of Rijndael: AES-The Advanced Encryption Standard, 2002.

Subspace trail cryptanalysis and its applications to AES, IACR Trans. Symmetric Cryptol, vol.2016, issue.2, pp.192-225, 2016. ,

A new structural-differential property of 5-round AES, EUROCRYPT 2017, Part II, vol.10211, pp.289-317, 2017. ,

Searching for subspace trails and truncated differentials, vol.30, p.30 ,