There are several (five, that I've found) linear approximations of the
*entire* S-box that hold with probability 7/256.  Is that useful?
-- 
Mike Stay
Programmer / Crypto guy
AccessData Corp.
mailto:[EMAIL PROTECTED]

Reply via email to