9.10 DIFFERENTIAL CRYPTANALYSIS
Suppose two plaintexts are enciphered by S-box S with the same key.
We conclude that
and write this last relationship as
How much of the 6-bit key is revealed by corresponding pairs of plain- and ciphertext (xi, yi) (i = 1, 2) enciphered by S-box S with the same unknown key? That is, how many solutions are there to
A pair (z1, z2) in (Δx, Δy) determines a possible unknown key by setting
If the size of (Δx, Δy) is much smaller ...