Paper 2019/750

A Short Note on a Weight Probability Distribution Related to SPNs

Sondre Rønjom


We report on a simple technique that supports some recent developments on AES by Grassi and Rechberger and Bao, Guo and List. We construct a weight transition probability matrix related to AES that characterises fixed configurations of active bytes in differences of ciphertexts when plaintext differences are fixed to some (possibly other) configuration of active bytes. The construction is very simple and requires only a little bit of linear algebra. The derived probabilities are essentially identical to recent results on 5- and 6-rounds AES derived through more sophisticated means, indicating that it might be worth a further investigation.

Note: Minor editing and comment from other authors that probabilities are in fact essentially identical

Available format(s)
Secret-key cryptography
Publication info
Preprint. MINOR revision.
Block CiphersSPNsAESProbability
Contact author(s)
Sondre Ronjom @ uib no
2019-07-04: last of 2 revisions
2019-06-25: received
See all versions
Short URL
Creative Commons Attribution


      author = {Sondre Rønjom},
      title = {A Short Note on a Weight Probability Distribution Related to SPNs},
      howpublished = {Cryptology ePrint Archive, Paper 2019/750},
      year = {2019},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.