Multiple Impossible Differentials Cryptanalysis on 7-Round ARIA-192

Table 3

Six 4-round impossible differential distinguishers of ARIA.

Number The positions of nonzero output difference Whitening key and 1-st round subkeys 7-th round subkeys

, are 14-byte whitening keys and 6-byte subkeys in the first round during an attack, respectively; are 4-byte subkeys which need to be guessed in the 7-th round when using the -th distinguisher.