Research Article

On the Construction of and Binary Matrices with Good Implementation Properties for Lightweight Block Ciphers and Hash Functions

Table 1

The lower bounds for the number of active S-boxes and the upper bounds for the linear and differential probabilities for the assumed block cipher of 80-bit and 96-bit block size.

Round The lower bounds for the number of active S-boxes The upper bounds for the linear and differential probabilities
80-bit block cipher 96-bit block cipher 80-bit block cipher 96-bit block cipher

2 8 10
3 9 11
4 16 20
5 17 21
6 24 30
7 25 31
8 32 40
9 33 41
10 40 50
11 41 51
12 48 60