Abstract
Orientation scheduling varies linear coefficients across rounds while preserving byte locality, invertibility, the branch-number floor, and the surrounding substitution-permutation network. For independently applied invertible maps over , active-byte support is invariant at the matrix step; this elementary block-diagonal fact is used here as a screening invariant rather than as a new algebraic theorem. The restriction does not extend to linear layers whose coefficients couple byte positions. Under the standard Markov-cipher model, a 128-state transfer computation over a deterministic panel of 256 matrix contexts finds a small separation between temporally constant and round-dependent schedules. At 16 rounds, the oracle-maximized geometric-mean class probabilities are about to , and the rotor-minus-static periodic-rate contrast is bits/round on the primary panel. Prefix and independently labeled panel checks give contrasts of the same order. The one-step ordering reverses under the periodic operator, an observation consistent with temporal-alignment effects but not sufficient to identify a unique mechanism. Reduced-round fixed-key calibration also shows that deviations from the Markov surrogate can be much larger than the schedule separation. The numerical difference is therefore resolvable but numerically small within the transfer model and is not presented as a fixed-key security advantage. The aggregate weight-one class exceeds the best individual trail by about in mean log-domain gap. The resulting design lesson is structural: coefficient diversity can change local transition quality and ordering, but within a byte-local layer it cannot substitute for diffusion width.
Keywords:
orientation scheduling; diffusion layers; differential cryptanalysis; linear cryptanalysis; Markov-cipher model; matched controls MSC:
94A60; 94B05; 15B33; 11T71
1. Introduction
Substitution-permutation networks (SPNs) obtain security from repeated interaction between nonlinear substitution and linear or permutation-based diffusion [1,2,3,4]. The present study examines one narrowly defined diffusion-layer question arising from earlier Hill-matrix work: whether publicly changing the orientation of a binary matrix across rounds and byte positions contributes meaningful diffusion when that matrix is applied independently to each byte [5,6].
1.1. Research Question and Structural Hypothesis
- Research question. Holding the seed matrices, round keys, nonlinear layer, whole-state rotation, and routing permutation fixed, does changing only the public orientation schedule of byte-local invertible matrices over improve differential diffusion relative to a static orientation?
Orientation scheduling is a plausible intervention because it preserves invertibility and the imposed branch-number floor while changing coefficient placement inside a byte. Across rounds, those changes can alter the difference patterns presented to subsequent S-boxes. The structural screening question is whether that variation also changes the number of active byte positions. For independently applied byte-local maps, it cannot: there is no coefficient path from one byte to another at the matrix step. The contribution is therefore not the algebraic difficulty of that observation but its use to separate coefficient diversity from diffusion width and to define the minimum-support class in which any residual scheduling effect must be transition-level rather than support-growth-level.
The restriction is essential. Nothing in the support-invariance statement applies to a linear layer whose coefficients couple distinct byte positions. Such cross-byte layers are discussed only as a boundary to the present result.
1.2. Why the Structural Limitation Matters
Wide-trail reasoning links resistance to differential and linear propagation to the number of nonlinear components forced active by the linear layer [4,7]. A design may vary matrices, coefficients, or orientations from round to round without increasing that active-component count. For a byte-local layer, coefficient changes can affect local differential probabilities and correlations, but they do not themselves enlarge byte support. The engineering screen suggested by this paper is therefore simple: before paying implementation or analysis cost for a varying linear rule, determine whether the variation changes support geometry at the symbol width feeding the nonlinear layer. If it does not, any benefit must come from coefficient-sensitive transition ordering rather than from a stronger active-S-box bound.
1.3. Main Findings
The byte-local support statement is an elementary consequence of block-diagonal structure and is used as a causal screening invariant. The new analysis is the finite-state weight-one transfer model built around that invariant, its schedule comparison over deterministic matrix contexts, and the separation of aggregate class probability from best-trail probability.
Within the Markov-cipher transfer model, the periodic rotor-minus-static decay-rate contrast is bits/round on the 256-context primary panel. Prefix checks give , , , and bits/round for the first 64, 128, 256, and 512 contexts, while an independently domain-separated 256-context panel gives bits/round. The paired context-level distributions are broad, so these values are presented as model-internal panel summaries rather than universal parameters.
At 16 rounds, the per-context oracle maximum over the 128 starting weight-one differences has mean probability for static and for rotor. These are log-domain summaries, equivalently geometric-mean probabilities, not arithmetic probability means. The corresponding arithmetic-mean probability exponents are and . The oracle maximum is a conservative structural diagnostic because the matrices are secret functions of the master key; it is not an operational attacker-selected differential. A fixed preselected start (bit 0) gives arithmetic-mean exponents and for static and rotor, respectively.
The one-step ordering reverses under the periodic operator: static has a slightly larger phase-averaged one-step decay than rotor but a smaller periodic decay. This rules out a simple explanation based on uniformly better one-step transitions. Temporal alignment is a natural interpretation, especially because static and position-only schedules are temporally constant at a fixed byte position, but the four-schedule comparison does not identify a unique noncommutative mechanism.
The model result is numerically stable but model-dependent. An independent direct-eigenvalue and long-horizon dynamic check agrees with the implemented power iteration to below bits/round on a validation subset, including reducible period products. By contrast, a reduced-round fixed-key calibration shows context/start deviations from the Markov predictions that are much larger than the -bit/round schedule separation. The schedule separation is therefore resolvable but numerically small within the surrogate model and is not interpreted as a fixed-key security gain.
1.4. Scope, Claim Status, and Adversary Model
The historical Hill-Enigma-SPN construction is retained only as a fully specified 128-bit experimental harness. It is not proposed as a deployment-ready cipher or as a replacement for AES. The orientation rule is public and contains no entropy. The sixteen accepted seed matrices are deterministic functions of the master key and are treated as secret internal components of the harness. Consequently, a per-context maximum over starting differences assumes knowledge not available to an attacker who does not know the key; throughout this paper, it is labeled an oracle-maximized structural diagnostic, not an attack probability.
The status of the principal claims is deliberately separated. Byte-local support invariance, invertibility preservation under orientation, the DDT column-sum identity, and the Parseval identity are elementary or standard facts specialized to this setting. The 128-state scheduled transfer system, its 256-context numerical evaluation, the one-step/periodic ordering reversal, the panel sensitivity checks, and the class-versus-single-trail gap are analyses or numerical findings reported here. All reported rate magnitudes are harness-specific and must be recomputed for another S-box, matrix family, routing rule, or state-motion schedule.
Relative to earlier Hill-derived work [5,6,8], the present paper uses the orientation operation as a public ablation variable rather than as secret transformation material, introduces the weight-one finite-state transfer analysis, and studies aggregate low-support differential recurrence. The earlier multidimensional Hill SPN [8] uses fixed cross-byte MDS mixing and contains no orientation-schedule comparison.
The contributions are therefore as follows: (i) formalizing the byte-local support screen in the specific context of orientation scheduling; (ii) connecting that screen to the weight-one recurrence class; (iii) specifying and evaluating the resulting Markov transfer system, including selection and averaging conventions; (iv) separating aggregate class mass from best individual trails; and (v) delimiting what the model result does and does not imply for a fixed keyed permutation.
1.5. Organization
Section 2 places the question in the Hill-matrix and SPN diffusion literature. Section 3 develops the byte-local support result, motivates the weight-one minimum-support class, and gives the differential and linear transfer analysis. Section 4 specifies the experimental harness. Section 5 gives the compressed matched corroboration and exploratory cross-byte boundary conclusion, with detailed diagnostics moved to the supplement. Section 6 discusses the design implications, limitations, and open questions.
2. Related Work and Structural Context
2.1. Hill-Matrix Variation and Orientation
The classical Hill cipher uses invertible matrix multiplication as a linear transformation [9,10]. Its linearity motivated variants that change the key matrix between messages, combine Hill multiplication with additional transformations, or alter matrix structure; representative examples include Saeednia [11], Ismail et al. [12], and Toorani and Falahati [13]. Coggins and Glatzer [5] and Coggins [6] used matrix-element rotations explicitly to vary Hill-derived transformations. Those two citations are the direct source of the orientation operation studied here. The present paper does not treat orientation as secret key material; it asks whether using the orientations as a public schedule changes diffusion when embedded in an otherwise fixed SPN.
A closer architectural predecessor is the multidimensional Hill SPN of Coggins [8], which uses global MDS matrices over . That construction and the present harness differ in the property under investigation: the former uses fixed cross-byte mixing, whereas the present experiment deliberately uses byte-local binary maps so that orientation scheduling can be isolated as an experimental variable.
2.2. SPN Diffusion and Branch Number
The wide-trail strategy relates linear-layer diffusion to lower bounds on active nonlinear components across rounds [4]. Branch number is therefore useful only at the algebraic granularity at which the linear map operates. AES MixColumns, for example, is an MDS map across four bytes over with branch number five [7,14]; SHARK similarly uses an MDS layer over byte symbols [15]. By contrast, the byte-local test layer applies independent maps to individual bytes over . Its branch-number floor constrains bit spreading inside a byte and is not a cross-byte wide-trail guarantee. Differential and linear branch numbers of binary matrices are treated in the terminology of Sarkar and Syed [16].
The distinction is summarized in Table 1. It is central to the research question: if an orientation schedule is to affect spatial diffusion, the linear layer must expose positional structure that can actually be changed by orientation.
Table 1.
Structural context for the diffusion layers discussed in this study. The comparison is algebraic, not a security or performance ranking.
2.3. Round-Varying and Structurally Diverse Layers
Round-varying public linear layers are an established design choice, but variation itself is not a security argument. LowMC uses independently generated dense binary matrices across rounds [17], and its cryptanalysis treats those matrices as fixed public instance data whose interaction with the nonlinear layer must be analyzed [18]. Rasta instead uses pseudorandomly generated affine layers, while Dasta studies a fixed-linear-layer alternative and thereby isolates the cost and role of that variation [19,20]. These constructions are not matched controls for the present harness because their linear layers span the full state, but they illustrate the relevant design distinction: changing a linear rule over time and increasing the support width of that rule are separate choices.
Structural diversity also arises outside matrix scheduling. Cellular-automata-based S-box constructions, for example, vary local update structure rather than merely permuting coefficients inside a fixed byte-local support [21]. Such work is relevant here because it changes the locality mechanism itself, which is precisely the variable held fixed in the present orientation experiment.
2.4. Differential Aggregation and Persistent Low-Support Structure
Differential cryptanalysis distinguishes individual characteristics from aggregate differentials, and the probability mass of many trails can differ substantially from that of the best single trail [22,23]. Ankele and Kölbl emphasize the gap between active-S-box bounds and achievable differential behavior in concrete block ciphers [24]. Persistent structural subsets are also central to invariant-subspace attacks, although the mechanisms differ from the substochastic recurrence class considered here [25]. These lines of work motivate reporting both the best single trail and the aggregate weight-one class rather than treating one characteristic as a complete description of low-support behavior.
2.5. Gap Addressed
Existing work shows that round-varying linear maps, global diffusion, and structural diversity can be useful ingredients, but it does not answer the narrower causal question posed here: what remains when only the orientation of a byte-local binary map is varied while support width is held fixed? The present experiment therefore compares schedule variants over identical components and explicitly separates an elementary support invariant from the coefficient-sensitive transfer quantities that remain. A separate cross-byte MDS experiment is retained only as an exploratory boundary example because it changes width, field, and matrix family simultaneously.
3. Byte-Local Orientation Scheduling: Structural Analysis and Transfer Model
This section defines the scheduled binary layer and isolates the structural property relevant to the research question. The central distinction is between intra-byte bit spreading, which the matrices can provide, and cross-byte support growth, which they cannot provide on their own. A finite-state transition computation then quantifies the resulting weight-one differential class under an explicitly stated Markov-cipher model.
3.1. Bit-Ordering Conventions (MSB-First)
The reference implementation uses one MSB-first convention throughout. A byte x is represented by ; each matrix row is stored as a byte with the same bit order, and matrix-vector multiplication computes the parity of the row/input bitwise intersection. A 128-bit state is the big-endian sequence of 16 bytes, so rotl128 rotates the corresponding big-endian integer and then repacks it as 16 bytes. Round indices in the key schedule are encoded as two-byte big-endian integers. These conventions are normative for reproducing the test vector; the supplementary implementation provides worked byte-level checks.
3.2. Linear Maps and 8 × 8 Binary Matrices
An matrix defines a linear map . Invertibility is equivalent to full rank over and is verified by Gaussian elimination with MSB-first pivot selection.
The admissible seeds form a branch-number-filtered subset of ; approximately 29% of all binary matrices are invertible [26]. The 16 seeds are deterministic functions of the master key and add no independent entropy. Their role in this study is to provide matched local linear maps whose orientations can be scheduled without changing the underlying seed family.
Granularity of the guarantee. The branch-number condition used below is defined over eight bits within one byte. It must not be interpreted as the four-byte MDS branch-number guarantee of AES MixColumns.
3.3. Branch Number as a Diffusion Metric
Definition 1
(branch number). For a linear map , [7]. Since this depends only on Hamming weights, it is independent of MSB/LSB convention. A lower bound on forces nontrivial spreading of any input difference. In the terminology of Sarkar & Syed [16], is the differential branch number; the linear branch number is , and the two need not coincide.
3.4. Clockwise 90° Rotation: Algebra and Consequences
For , define by . This permutes the 64 entries via the index map and satisfies .
Proposition 1
(Invertibility preservation). With J the reversal (antidiagonal identity) permutation matrix, . Hence, R preserves invertibility over : transpose preserves invertibility and right-multiplication by a permutation matrix preserves invertibility. Therefore, implies automatically.
Proposition 2
(Branch numbers of the four orientations). Because with J weight-preserving, the four orientations realize only the two branch numbers and . Thus, and are sufficient to guarantee the same floor for all four orientations.
Definition 2
(admissible seed). A seed S is admissible when it is invertible and satisfies and . By Proposition 2, every orientation is then invertible and has branch number at least four. The implementation checks all four orientations defensively, but this repeated check is not an additional mathematical condition.
3.5. Rotor Scheduling
Let be the 16 admissible seed matrices derived from master key K. In round and byte position , the active matrix is
Across 16 rounds, this yields 256 matrix applications in which the 64 labeled (seed, orientation) pairs each appear exactly four times. The rule is public, adds no key entropy, and was selected as the minimum balanced schedule that cycles every seed through all four orientations while phase-offsetting adjacent byte positions.
The motivation for that temporal variation is specific and testable. Cycling orientations changes which admissible linear coefficient pattern is presented in each round while preserving invertibility, the branch-number floor, the byte-local width, and the surrounding SPN. Such variation could plausibly disrupt repeatedly favorable differential transitions even if it cannot create cross-byte support directly. Section 3.7 tests that hypothesis within the stated Markov-cipher model for the weight-one class.
3.6. Diffusion Properties of the Rotor Layer
Proposition 3.
If M is invertible with , then for any nonzero x, and . In particular, a single-bit input produces .
Proof.
Invertibility implies trivial kernel, so for all nonzero x. The bound follows directly from . Setting gives . □
Intuitively, the proposition says that no nonzero input can collapse to a near-empty output: flipping a single input bit always activates at least three output bits within the affected byte, so a difference cannot vanish as it passes through the matrix layer.
The condition ensures that any single active bit entering byte j in round r produces at least three active output bits locally. Together with whole-state rotation and routing, this was intended to promote multiround diffusion, although Section 3.6.2 shows that the condition is not sufficient to preclude weight-one recurrence. Empirical saturation statements are secondary diagnostics and are summarized only briefly in Section 5.
3.6.1. Difference Distribution Table (DDT)
For an n-bit S-box S, the Difference Distribution Table (DDT) records for each input difference and output difference the number of inputs producing that transition:
Dividing an entry by gives the corresponding differential transition probability. This tabulation formalizes the input-pair/output-difference counting used in differential cryptanalysis of S-boxes and the difference-propagation probabilities used in differential and wide-trail analysis [4,27,28]. The abbreviation DDT is used in the remainder of this manuscript.
3.6.2. Why Weight-One Recurrence Is the Critical Test Class
A weight-one recurrence is not studied merely because its state space is finite and tractable. It represents the minimum-support propagation regime of the byte-local construction. If the round-boundary difference has Hamming weight one, then exactly one byte is active and only one S-box receives a nonzero input difference. Persistence in this class therefore means that the construction has repeatedly failed to force support growth, even if typical ciphertext statistics already appear close to random.
The local branch-number floor does not preclude this regime. For a weight-one input to a byte-local matrix, Proposition 3 guarantees at least three active output bits within the byte, but the AES S-box does not preserve Hamming weight. Its DDT contains transitions from multibit input differences back to weight-one output differences. After such a transition, whole-state rotation and routing move the surviving bit without splitting it. One active S-box per round is therefore structurally possible.
This is why the class is more informative for the present question than a finite-sample randomness battery. Randomness and avalanche tests characterize typical outputs at a resolution set by their sample size. The weight-one transfer model instead measures an adversarially relevant low-support propagation mode whose probability can be far below any feasible sampling resolution. Definition 3 formalizes the class, and Section 3.7 evaluates it without transition sampling under the stated model assumption. The result is not a complete differential hull, but it directly tests whether orientation scheduling eliminates the minimum-support recurrence that the byte-local geometry permits.
3.6.3. Claim Boundary
The condition is per byte over and supplies no nontrivial cross-byte active-S-box bound. The present study therefore does not derive a full-cipher upper bound on maximum differential probability or maximum linear correlation. Finite-sample avalanche, collision, linear-mask, and randomness tests cannot substitute for such bounds; they are retained later only as secondary diagnostics. The security of the complete experimental permutation is not claimed.
This limitation is also the mechanism under test. Because the scheduled map is byte-local, matrix orientation can change the intra-byte difference delivered to the S-box but cannot directly increase active-byte support. Theorem 1 states this support limitation formally. The transfer enumeration and matched controls then test whether orientation-dependent coefficient changes nevertheless produce a meaningful multiround advantage.
3.6.4. Routing Geometry and Four-Round Composition
The routing modes are strongly restricted: mode 0 is the identity, while modes 1, 2, and 3 swap byte-index bit pairs , , and . Thus, every nonidentity mode involves index bit 0; bits 1, 2, and 3 are never swapped directly with one another.
Proposition 4
(Four-round routing composition). Let a byte index be written with the least significant index bit, and let be the isolated routing composition for rounds 0 through 3. Then
Its cycle structure is
so Π has order four and the routing-only composition over 16 rounds is the identity.
Proof.
Applying the three index-bit transpositions in source-to-destination order moves into the least significant position and shifts one position toward the most significant end. Direct iteration gives the stated cycles and . □
The whole-state rotation schedule adds 16 bits in each block of 4 rounds and 64 bits over all 16 rounds. Because routing permutes whole bytes, the within-byte bit offset is therefore realigned at every four-round boundary. The routing and rotation operations are interleaved, so this fact does not imply that their combined state-motion map is a pure rotation or that routing makes no contribution to intermediate transport. It does establish a small-order, four-round periodic geometry. The structured-counter experiment in Section 5.1 tests the prediction that a deficit tied to this geometry should have the same stride signature in all four matrix-schedule arms.
3.7. Weight-One Trail-Class Transition Analysis
At a round boundary there are only 128 possible one-bit state differences, so the recurrent class can be represented by a finite transition system.
Definition 3
(weight-one iterative class). The round boundary is the state immediately after routing: rotate → key XOR → scheduled matrix → S-box → routing ∥ boundary. For a fixed weight-one boundary input difference, the r-round weight-one iterative class consists of all differential trails whose difference has Hamming weight one at every such boundary through round r. Its class probability is the sum of the transition-model probabilities of those trails. A trail that leaves the class can later return to weight one, so this is a lower bound on the broader modeled endpoint event.
Remark 1
(Modeling assumption). The transition computation is exact within the Markov-cipher DDT model [22]. A DDT probability averages a byte transition over a uniform S-box input value, equivalently over an independent uniform pre-S-box subkey. In the harness, however, the round keys and accepted seed matrices are correlated deterministic functions of the same master key. The transfer calculation therefore removes transition-sampling error inside the surrogate process but does not establish stochastic equivalence to a fixed keyed permutation. Reduced-round calibration in Section 3.8 quantifies this distinction directly. All uses of “model-exact” refer only to this stated surrogate.
3.7.1. Construction of the Transfer Operator
Let boundary state denote a single active bit before round r. After the whole-state left rotation by , define
under the MSB-first bit convention, and let . The matrix-layer input difference to the S-box is
For output bit index , let and let the routed successor boundary index be
The round transfer matrix is the substochastic matrix
with zero entries for states not obtained by this construction. Probability row vectors multiply on the right, so and the ordered 16-round period is . For fixed start u and prefix length R,
The oracle statistic used in the principal table is . For each context, this maximization is performed first; context summaries are taken only afterward. The code uses the algebraically equivalent backward survival recursion to evaluate Equation (4).
3.7.2. Byte-Local Support Invariance as a Screening Invariant
Theorem 1
(Byte-local support invariance). Let a nonzero state difference entering the scheduled matrix layer be confined to byte j. For every seed matrix and orientation exponent, the matrix-layer output remains confined to byte j. If the input has Hamming weight one, the output has Hamming weight at least three. Hence, changing matrix orientation cannot directly enlarge the number of active bytes at that layer.
Proof.
The scheduled map at position j is an linear transformation applied only to byte j; no coefficient connects that byte to any other state byte. Thus, support outside byte j remains zero. The weight-one lower bound follows from Proposition 3. □
Remark 2
(Role and scope of the invariant). Theorem 1 is an elementary consequence of block-diagonal byte locality; no claim of mathematical difficulty or novelty is attached to that algebraic fact. Its function here is causal screening: any schedule effect observed while the map remains byte-local must arise through coefficient-sensitive transition weights and their ordering, not through direct enlargement of byte support. The hypothesis fails immediately for a linear layer with coefficients connecting two byte positions.
3.7.3. Estimands, Selection, and Context Averaging
Four aggregation levels are kept distinct. First, within one context and start state, trail probabilities are summed arithmetically to obtain . Second, the primary structural diagnostic takes the maximum over 128 starts; fixed-start summaries are also reported to expose the selection effect. Third, the principal log-domain table averages over contexts, so exponentiating that mean gives a geometric-mean probability. Arithmetic probability means are reported separately. Fourth, finite decay rates are fitted within each context and only then averaged over contexts. Oracle maxima are nonzero in every reported context. Fixed-start cells can be zero; probability-domain averages retain those zeros, while log-domain distributions report the zero count separately and summarize only positive cells.
3.7.4. Enumerated Values
Table 2 reports the per-context oracle maximum of Equation (4). The entries are arithmetic means of across the deterministic context panel; parentheses give the corresponding across-context standard deviations. Thus, the displayed exponent describes a geometric-mean probability, not the arithmetic mean probability. The latter is given for in the text below.
Table 2.
Model-exact oracle-maximized weight-one class under Remark 1. Each cell is mean probability across 256 deterministic contexts, with across-context SD in parentheses. The final column averages the per-context least-squares decay rate fitted at . These are surrogate-model diagnostics, not fixed-key attack probabilities.
At 16 rounds, the arithmetic-mean probability exponents for static, position-only, rotor, and round-only are, respectively, , , , and . The distinction from the mean log probabilities in Table 2 is small but material at the scale of the schedule comparison. Under a single preselected starting difference (boundary bit 0), the corresponding arithmetic-mean exponents are , , , and ; zero-probability cells occur for this fixed start and are retained in those probability-domain means.
The maximizing start state is not stable enough to be interpreted as an attacker-selectable difference when the matrix context is secret. Across 256 contexts, the modal maximizing bit occurs only 8 times for static and 6 times for rotor, with 106 and 112 distinct maximizing bit positions, respectively. Full start-state quantiles and zero counts are given in the Supplementary Material. This is why the main table is described as an oracle-maximized structural diagnostic rather than as an operational differential probability.
The ideal-random-permutation value is used only as a fixed-input endpoint reference. It is not the same event as remaining weight one at every intermediate boundary, and it does not incorporate the per-context oracle selection. The comparison is therefore contextual rather than a like-for-like null. A trajectory-matched ideal-round reference is supplied in the Supplementary Material. Any conversion of the endpoint exponent gap into an equivalent number of rounds is explicitly an extrapolation inside the transfer model.
3.7.5. Why the Rate Is Approximately 4.99 Bits per Round
The observed rate has a simple analytic null. Let S be any bijective 8-bit S-box and let be its difference distribution table. For every fixed nonzero output difference ,
To see this, fix x and . Bijectivity gives a unique and hence a unique nonzero contributing that x to exactly one entry in column . Summing over all 256 values of x proves Equation (5).
There are eight weight-one output differences. Consequently,
If the nonzero difference entering the S-box were uniform over its 255 possible values, the mean probability of returning to a weight-one difference in one round would be
This is a null prediction, not an additional independence assumption imposed on the transition calculation. All quoted decay rates in this paper use of a mean probability, never the mean of probability. The distinction is material: for the AES S-box, bits, while bits when the single nonzero input difference with zero weight-one output mass is excluded. The latter average is undefined if that zero-mass input is retained. Accordingly, the mean-probability convention is used consistently in the null, the one-step column, and the transfer comparisons.
The ordered period operator is nonnegative and substochastic. Perron–Frobenius theory ensures that its spectral radius is nonnegative, and Gelfand’s formula gives the asymptotic norm growth even when P is reducible [29]. The model-periodic decay rate is therefore
Table 3 compares the bijective-S-box null, the scheduled one-step mean, Equation (8), and the finite four-point fit. Every entry is computed per context first and then summarized across the same context panel, except the one-step column, which applies after the phase-and-state mean retention probability as specified in the caption.
Table 3.
Model-internal decomposition of weight-one decay. “One-step” is of the mean row-sum retention probability over all 128 boundary states and 16 phases within a context, followed by context averaging. “Periodic” is Equation (8), computed per context and then averaged. is one-step minus periodic; it is a descriptive decomposition and not a uniquely identified causal effect. “Finite fit” is fitted per context at and then averaged.
The periodic rotor-minus-static contrast is bits/round on the primary 256-context panel. Prefix sensitivity gives , , , and bits/round for , and an independently domain-separated 256-context panel gives . The primary-panel paired differences have median , 5th and 95th percentiles and bits/round, and are positive in contexts. The replication panel is similarly centered but broader in sign balance ( positive). These distributions are reported descriptively; the small positive mean is reproducible within the stated context-generation model but is not asserted as a universal population parameter.
- Numerical validation.
The transfer implementation uses IEEE-754 binary64 arithmetic and power iteration with a log-factor convergence tolerance of and a 250-iteration cap. Reducibility is common rather than exceptional: 720 of the 1024 primary schedule-context period products have more than one strongly connected component. On a validation subset containing all four schedules for eight contexts, the power-iteration rate agrees with both a direct dense spectral-radius calculation and a 100-period dynamic-propagation estimate to a maximum absolute difference below bits/round; convergence required at most 14 iterations. Numerical error at this scale is therefore far below the panel dispersion and the reported -bit/round mean contrast.
Proposition 5
(Rotor and round-only one-step multiset equality). For every byte position j, the 16-round orientation multiset under rotor scheduling is identical to that under round-only scheduling:
with each orientation appearing exactly four times. Consequently, any one-step statistic that averages over all 16 phases and all boundary bit positions without regard to phase order is identical for the two schedules.
Proof.
Adding the fixed offset j modulo four only permutes the sequence within each four-round block. Averaging over all 128 boundary bit positions ensures that each input bit of each byte is represented at each phase, so phase order does not affect the one-step average. □
Proposition 5 explains the identical rotor and round-only one-step means. Table 3 nevertheless shows an ordering reversal: static decays slightly faster than rotor in the phase-averaged one-step statistic but more slowly under the ordered period product. This establishes that the multiround ordering is not explained by uniformly better one-step transitions.
A temporal-alignment or “phase-locking” account is consistent with the observation but is not uniquely identified by it. Static and position-only schedules are temporally constant at each fixed byte position, whereas rotor and round-only vary with round index. From the viewpoint of a surviving weight-one path, position-only scheduling therefore resembles static scheduling: revisiting byte j presents the same oriented map again even though other byte positions use different orientations. A returning path can repeatedly encounter a favorable phase-conditioned local transition. Under a round-dependent schedule, the same revisit encounters a different orientation. State-dependent row sums, spectral localization, and other noncommutative effects can contribute as well; no unique causal decomposition is claimed.
3.7.6. Linear Squared-Correlation Analogue
The mean-field identity has a linear analogue. Let
be the normalized correlation of an 8-bit bijective S-box in the standard linear-cryptanalysis convention of Matsui and correlation-matrix treatments [7,30]. For every fixed nonzero output mask , Parseval’s identity gives
because for a bijection and nonzero . Summing over the eight weight-one output masks therefore gives
Thus, a uniform nonzero input mask has mean squared-correlation retention , exactly the same null value as the differential mean-probability calculation, and
The supplementary checker verifies both identities directly for the AES S-box. This is a structural null for linear potential, not a complete linear-hull analysis of the harness; no model-exact multiround linear transfer claim is made here.
3.7.7. Class Probability Versus Best Single Trail
The 256-context enumeration also separates the maximum aggregate weight-one class probability from the maximum individual trail probability. At 16 rounds, the mean best single-trail log probabilities are (static), (position-only), (rotor), and (round-only), whereas the corresponding mean class values are , , , and . The corresponding class-minus-single gap is computed separately for each context and then averaged over the panel, giving means of , , , and bits, respectively.
This has a methodological consequence beyond the present harness. Bounding the construction by its best individual differential trail would understate the attainable weight-one recurrence by a factor of approximately on average. The schedule can redistribute probability among many individual paths without removing the aggregate class. Analyses of this family should therefore aggregate over trail classes rather than infer recurrence probability from the single best trail alone.
3.8. Reduced-Round Fixed-Key Calibration
The Markov transfer model is a surrogate for the fixed-key harness, so the revision includes a direct reduced-round calibration rather than relying on the modeling caveat alone. For four fixed key contexts and eight preselected starting bit differences, matched plaintext pairs were evaluated per context/start cell at two rounds under each schedule. The aggregate measured versus model-predicted weight-one probabilities were versus (static), versus (position-only), versus (rotor), and versus (round-only). Aggregation therefore looks broadly comparable at this coarse level.
Cell-level behavior is less benign. After the initial calibration had been inspected, four zero-hit cells were selected post hoc for higher-resolution discrepancy checks, with one cell chosen from each schedule arm. They were not a prospectively specified or randomly sampled confirmation set. Their model probabilities range from to . Each selected cell was rerun with pairs and again produced zero fixed-key weight-one outcomes. Their one-sided 95% binomial upper bound is per cell, far below the corresponding Markov predictions. These selected reruns therefore demonstrate that large cellwise surrogate-to-harness discrepancies can persist at higher sampling resolution, but they do not estimate how frequently such discrepancies occur across the full context/start grid. The Supplementary Material identifies the context, schedule, starting state, model probability, and observed counts for all four rerun cells. Fixed-key modeling error can thus be much larger than the approximately -bit/round schedule separation resolved by the surrogate transfer operator. The model rates are interpreted only as properties of the stated Markov process. The exact support-invariance result does not depend on this calibration.
4. Experimental SPN Harness and Round Function
The historical HESPN construction is used only as an instrumented 128-bit SPN harness for schedule ablation. Every matched arm uses the same accepted seed matrices, SHA-256-derived round keys, AES S-box, whole-state rotation schedule, routing permutation, and input panels; only the orientation exponent changes. Figure 1 summarizes the control structure. The complete byte ordering, matrix packing, key setup, encryption and decryption procedures, and reference test vectors are moved to the Supplementary Material.
Figure 1.
Matched primary design. All components are held fixed except the public orientation exponent. The separate cross-byte MDS example is exploratory, changes several variables simultaneously, and is documented in the Supplementary Material.
4.1. State Motion and Orientation Schedules
The state is 16 bytes in big-endian, MSB-first order. The fixed whole-state rotation schedule is
Each four-round block sums to 16 bits and the full schedule to 64 bits, so the within-byte offset realigns at four-round boundaries. Routing mode is the identity for mode 0 and swaps byte-index bits , , or in modes 1, 2, and 3. Theorem 1 concerns only the byte-local matrix step; Proposition 4 and the state-motion audit quantify the separate routing geometry.
For byte position j, the four schedule arms are static , position-only , round-only , and rotor . All accepted seeds satisfy the common invertibility and branch-number conditions of Section 3.4. Thus, the experiment changes temporal orientation only, not the seed family or any other round component.
4.2. Round Summary and Deterministic Context Panel
A round performs whole-state rotation, round-key XOR, the scheduled byte-local matrix on each byte, AES S-box substitution, and routing, in that order. Round-key XOR is difference-transparent for the transfer analysis. The primary panel uses . These master keys are treated as a deterministic pseudorandom panel for reproducibility, not as a distribution-free sample of all admissible matrices. Candidate byte matrices are derived from each key and rejected until the documented invertibility and branch conditions hold; this rejection rule defines the effective matrix ensemble.
Across the 256 primary contexts, 4096 accepted byte seeds required 465,673 candidate draws, for an empirical acceptance fraction of . Contexts required a mean of 1819 candidate draws (median 1798.5; range 667–3225). Per accepted seed, the median draw count was 80, the 95th percentile 335.25, and the maximum 843. Panel-prefix and independent-label sensitivity results are reported with the transfer results above and in full in the Supplementary Material. No claim that SHA-256 output constitutes a formal random sample is required for the structural theorem; the panel analysis is conditional on the stated deterministic generation procedure.
4.3. Evaluation Scope
Round counts 4, 8, 12, and 16 span early structured propagation through later empirical saturation and are observation points, not a proposed security parameter. The harness is not proposed with a deployment mode or authenticated-encryption construction. Its only role is to make the orientation mechanism reproducible and experimentally separable. Full implementation detail is retained in the supplement and repository rather than repeated in the main article.
5. Matched Evaluation and Boundary Setting
The exact structural and transfer analyses are primary. The finite empirical instruments are retained only to detect gross behavior that would contradict the structural interpretation; they are not used to estimate the approximately -bit/round transfer-model separation.
5.1. Matched Finite-Resolution Corroboration
All four schedules share the same key contexts, accepted matrices, round keys, S-box, state motion, and input panels. The original paired avalanche screen gives a rotor-minus-static mean of bits at eight rounds with 95% interval , and the twelve-round counter-distance means differ by only bits across schedules with broadly overlapping intervals. These instruments can exclude only much larger effects than the transfer-model separation. The common counter-stride signature also appears in all schedule arms, supporting the conclusion that this reduced-round geometric feature is not created by the orientation rule. Full avalanche, collision, counter, NIST SP 800-22, and other secondary diagnostic outputs remain in the Supplementary Material; none is used as cryptanalytic security evidence.
5.2. Exploratory Cross-Byte Boundary Example
A separate Cauchy MDS experiment over is retained only to mark where the byte-local support theorem ceases to apply. It changes mixing width, field, and matrix family simultaneously, and its pruned searches remain far from the certified activity floor. It therefore supports no schedule ranking and no causal attribution to width. Detailed candidate tables and audit outputs are confined to the Supplementary Material. A same-field binary layer spanning adjacent bytes would be a cleaner future ablation, but designing and validating that construction is outside the scope of this revision.
6. Discussion and Conclusions
6.1. Answer to the Research Question and Design Implication
For independently applied byte-local linear maps, changing orientation cannot enlarge active-byte support at the matrix step. That statement is a screening invariant, not a general theorem about cross-byte diffusion layers. The weight-one transfer analysis quantifies what remains after support width is held fixed: coefficient and phase changes can alter the surrogate transition process, but the observed schedule separation is small.
Within the Markov model, the rotor-minus-static periodic-rate difference is about bits/round on the primary panel and remains of the same order under panel-size and independent-label sensitivity checks. If one nevertheless extrapolates the 16-round class to the fixed-input endpoint reference at the asymptotic rates, the rotor shortens the remaining model distance by about of one round. Approximately of that difference is the level gap already present at round 16 and about is attributable to the asymptotic rate difference. This is a model-only extrapolation, not a security gain.
The reduced-round fixed-key calibration sharpens the limitation. Individual context/start cells can depart from the Markov prediction by far more than the transfer-model schedule separation. The numerical result is therefore best read as evidence about the surrogate process and about how coefficient ordering behaves under that model, not as an operational fixed-key differential advantage.
The portable design implication is structural. If a designer wants stronger active-S-box growth, resources should be directed toward a layer or state-motion mechanism that actually couples symbol supports. A public schedule that refreshes coefficients only inside an already active byte may change local transition quality, but it adds no entropy and does not enter a byte-level wide-trail bound. This does not make coefficient variation useless; it places its possible benefit in the narrower category of coefficient-sensitive ordering effects.
The one-step/periodic reversal is consistent with temporal-alignment effects, but the present four-schedule study does not establish phase locking as the unique cause. State-dependent row sums, localization, and other noncommutative effects remain possible explanations. Figure 2 is therefore conceptual rather than causal evidence.
Figure 2.
Conceptual illustration of the temporal-alignment interpretation. A temporally constant schedule can present the same oriented byte-local map when a low-support path revisits a position, while a round-dependent schedule changes the map with phase. The schematic is explanatory only: the measured ordering reversal establishes sensitivity to ordered composition, not a unique causal mechanism.
6.2. Generality Beyond the AES S-Box
The byte-local support invariant is independent of the S-box: it is a support statement about any independently applied byte-local linear map. The minimum-support interpretation likewise extends to SPNs with one bytewise S-box per active byte. The differential mean-field identity is also broader than AES. For every bijective 8-bit S-box, each nonzero DDT output column has total mass 256 across nonzero input differences, so the average probability of landing in one of eight weight-one outputs is exactly . The Parseval argument gives the same mean squared-correlation null for any bijective 8-bit S-box.
What is S-box-specific is the distribution around those means and therefore the actual finite and periodic rates induced by the scheduled matrix images. The magnitude of the phase-ordering effect reported here should not be transferred numerically to another S-box, matrix family, routing rule, or state-motion schedule without recomputation. The general claim is narrower and stronger: coefficient variation within fixed byte-local support cannot directly create diffusion width, while the average differential and linear nulls arise from bijectivity rather than from an AES-specific coincidence.
6.3. Why Trail-Class Aggregation Matters
The mean per-context log-domain gap between the aggregate weight-one class and the best single trail is about 28 bits across the deterministic panel. This is a methodological observation rather than a probability ratio formed from arithmetic means. In designs that admit recurrent low-support behavior, bounding only the most probable trail can substantially understate the probability mass accumulated across many related trails. The present finite-state class is narrow and does not replace a full hull computation, but it demonstrates why class aggregation should accompany single-trail bounds when the geometry permits repeated return to a low-support state set.
6.4. Routing Localization
The twelve-round counter-distance deficit provides an independent localization result. Proposition 4 proves that the isolated routing sequence has an order-four four-round composition, while the rotation schedule realigns within-byte bit offsets after each four-round block. The counter experiment confirms the same stride signature in all four matrix-schedule arms. A separate state-motion-only checker shows that composing the actual whole-state rotations with routing has order 504 over four rounds and over sixteen, under either rotation-direction convention. Thus, the small order is a routing-layer property that rotation destroys; it should not be interpreted as a short period of the complete state motion. The common stride signature remains independent of matrix orientation.
6.5. Cross-Byte Boundary and Open Questions
The cross-byte MDS experiment marks the boundary of Theorem 1: once the linear map connects several byte positions, the byte-local support proof no longer applies. The current beam searches are too far from the certified activity floor to establish a schedule ranking, and the intervention also confounds width, field, and matrix family. The useful conclusion is therefore prospective. A same-field binary map spanning two adjacent bytes is the natural next control because it changes support geometry while preserving more of the original algebraic setting.
Other structural questions follow directly: examine routing families whose four-round composition does not have small order; extend the transfer analysis beyond the weight-one differential class and toward linear hulls; characterize how periodic schedule phases couple to S-box transition structure; and design schedule objectives aligned with cryptanalytic quantities rather than generic diffusion surrogates. These questions test mechanisms that can alter support growth rather than merely adding coefficient diversity.
6.6. Limitations
The transition enumeration is exact only within Remark 1; it covers the weight-one iterative class, not the complete differential or linear hull of a fixed keyed permutation. The 256-context panel is deterministic and its population interpretation depends on treating the SHA-256-derived keys as a pseudorandom panel under the documented rejection rule. The independent-label replication tests sensitivity to that label but does not convert the study into a distribution-free proof. Fixed-key calibration shows that modeling error can exceed the schedule separation. The empirical diagnostics are intentionally secondary, and the cross-byte search is exploratory and pruned. None of these results constitutes a security proof for the complete experimental permutation.
6.7. Reproducibility
The primary byte-local matched-control results are reproduced by matched_orientation_schedule_experiment.py. The runner verifies the rotor arm against the supplementary reference vector before running. The cross-byte boundary study is provided under src/cross_byte/ in the public repository snapshot. Its unit tests verify all four MDS orientations, encryption/decryption round trips, schedule periods, and structural audits. The validated standard-profile outputs include the MILP activity bounds, capped minimum-support counts, differential and linear candidate tables, captured low-active mass, schedule-optimizer record, and compact slide/reflection summary. Full pair lists remain available in the archival audit JSON.
Supplementary Materials
The following supporting information can be downloaded at: https://www.mdpi.com/article/10.3390/cryptography10050071/s1, Supplementary Technical Material; Supplementary Code and Results. The files contain the validated byte-local matched-control implementation, the 256-context transition and periodic-transfer analysis with machine-readable outputs, matched statistical diagnostics, cross-byte MDS candidate and audit tables, trail-search code, sensitivity analysis, reference implementation, test vectors, and a reproducibility manifest.
Funding
This research received no external funding.
Data Availability Statement
The source code and machine-readable outputs supporting the transfer analysis, panel-sensitivity and starting-state checks, numerical validation, reduced-round fixed-key calibration, matched empirical controls, and exploratory cross-byte boundary experiment are included in the supplementary submission package and maintained in the public GitHub repository at https://github.com/ja9925ydbsu/structural-limits-orientation-scheduling (accessed on 18 September 2026). The supplementary manifest maps manuscript tables to scripts and output files. No third-party datasets were used.
Acknowledgments
During the preparation of this manuscript, the author used Anthropic Claude (Fable 5.1, medium) and OpenAI ChatGPT (High setting; no more specific model/version displayed) to assist with Python 3.13.5 refinement, copy editing, manuscript review, table and figure assembly, and reference formatting. The author independently verified the code and all reported measurements, reviewed and edited the outputs, and takes full responsibility for the content of this publication.
Conflicts of Interest
The author declares no conflicts of interest.
Abbreviations
The following abbreviations are used in this manuscript:
| AES | Advanced Encryption Standard |
| DDT | Difference Distribution Table |
| GF | Galois field |
| MDS | Maximum distance separable |
| SPN | Substitution-permutation network |
References
- Paar, C.; Pelzl, J. Understanding Cryptography: A Textbook for Students and Practitioners; Springer: Berlin/Heidelberg, Germany, 2010. [Google Scholar]
- Shannon, C.E. Communication Theory of Secrecy Systems. Bell Syst. Tech. J. 1949, 28, 656–715. [Google Scholar] [CrossRef] [Scilit]
- Kam, J.B.; Davida, G.I. Structured Design of Substitution-Permutation Encryption Networks. IEEE Trans. Comput. 1979, 28, 747–753. [Google Scholar] [CrossRef]
- Daemen, J.; Rijmen, V. The Wide Trail Design Strategy. In Proceedings of the Cryptography and Coding; Honary, B., Ed.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2001; Volume 2260, pp. 222–238. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Coggins, P.E.; Glatzer, T. An Algorithm for a Matrix-Based Enigma Encoder from a Variation of the Hill Cipher as an Application of 2 × 2 Matrices. PRIMUS 2020, 30, 1–18. [Google Scholar] [CrossRef] [Scilit]
- Coggins, P.E. Two Novel Multidimensional Affine Variations of the Hill Cipher. Math. Comput. Sci. 2024, 9, 46–56. [Google Scholar] [CrossRef] [Scilit]
- Daemen, J.; Rijmen, V. The Design of Rijndael: AES: The Advanced Encryption Standard; Springer: Berlin/Heidelberg, Germany, 2002. [Google Scholar] [CrossRef] [Scilit]
- Coggins, P.E. Multidimensional Hill Cipher Substitution-Permutation Network. J. Cybersecur. Priv. 2026, 6, 104. [Google Scholar] [CrossRef] [Scilit]
- Hill, L.S. Cryptography in an Algebraic Alphabet. Am. Math. Mon. 1929, 36, 306–312. [Google Scholar] [CrossRef] [Scilit]
- Hill, L.S. Concerning Certain Linear Transformation Apparatus of Cryptography. Am. Math. Mon. 1931, 38, 135–154. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Saeednia, S. How to Make the Hill Cipher Secure. Cryptologia 2000, 24, 353–360. [Google Scholar] [CrossRef] [Scilit]
- Ismail, I.A.; Amin, M.; Diab, H. How to Repair the Hill Cipher. J. Zhejiang Univ. Sci. A 2006, 7, 2022–2030. [Google Scholar] [CrossRef] [Scilit]
- Toorani, M.; Falahati, A. A Secure Variant of the Hill Cipher. In Proceedings of the 2009 IEEE Symposium on Computers and Communications; IEEE: Piscataway, NJ, USA, 2009; pp. 313–316. [Google Scholar] [CrossRef] [Scilit]
- Daemen, J.; Rijmen, V. AES Proposal: Rijndael, Version 2; Technical Report; National Institute of Standards and Technology: Gaithersburg, MD, USA, 1999. [Google Scholar]
- Rijmen, V.; Daemen, J.; Preneel, B.; Bosselaers, A.; De Win, E. The Cipher SHARK. In Proceedings of the Fast Software Encryption; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1996; Volume 1039, pp. 99–111. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Sarkar, S.; Syed, H. Bounds on Differential and Linear Branch Number of Permutations. In Proceedings of the Information Security and Privacy: ACISP 2018; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2018; Volume 10946, pp. 207–224. [Google Scholar] [CrossRef] [Scilit]
- Albrecht, M.R.; Rechberger, C.; Schneider, T.; Tiessen, T.; Zohner, M. Ciphers for MPC and FHE. In Proceedings of the Advances in Cryptology: EUROCRYPT 2015; Lecture Notes in Computer Science; Oswald, E., Fischlin, M., Eds.; Springer: Berlin/Heidelberg, Germany, 2015; Volume 9056, pp. 430–454. [Google Scholar] [CrossRef] [Scilit]
- Dobraunig, C.; Eichlseder, M.; Mendel, F. Higher-Order Cryptanalysis of LowMC. In Proceedings of the Information Security and Cryptology: ICISC 2015; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2016; Volume 9558, pp. 87–101. [Google Scholar] [CrossRef] [Scilit]
- Dobraunig, C.; Eichlseder, M.; Grassi, L.; Lallemand, V.; Leander, G.; List, E.; Mendel, F.; Rechberger, C. Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit. In Proceedings of the Advances in Cryptology: CRYPTO 2018; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2018; Volume 10991, pp. 662–692. [Google Scholar] [CrossRef] [Scilit]
- Hebborn, P.; Leander, G. Dasta: Alternative Linear Layer for Rasta. IACR Trans. Symmetric Cryptol. 2020, 2020, 46–86. [Google Scholar] [CrossRef]
- Mariot, L.; Picek, S.; Leporati, A.; Jakobovic, D. Cellular Automata Based S-Boxes. Cryptogr. Commun. 2019, 11, 41–62. [Google Scholar] [CrossRef] [Scilit]
- Lai, X.; Massey, J.L.; Murphy, S. Markov Ciphers and Differential Cryptanalysis. In Proceedings of the Advances in Cryptology: EUROCRYPT ’91; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1991; Volume 547, pp. 17–38. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Daemen, J.; Rijmen, V. Probability Distributions of Correlation and Differentials in Block Ciphers. J. Math. Cryptol. 2007, 1, 221–242. [Google Scholar] [CrossRef] [Scilit]
- Ankele, R.; Kölbl, S. Mind the Gap: A Closer Look at the Security of Block Ciphers against Differential Cryptanalysis. In Proceedings of the Selected Areas in Cryptography: SAC 2018; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2019; Volume 11349, pp. 163–190. [Google Scholar] [CrossRef] [Scilit]
- Leander, G.; Abdelraheem, M.A.; AlKhzaimi, H.; Zenner, E. A Cryptanalysis of PRINTcipher: The Invariant Subspace Attack. In Proceedings of the Advances in Cryptology: CRYPTO 2011; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2011; Volume 6841, pp. 206–221. [Google Scholar] [CrossRef] [Scilit]
- Overbey, J.; Traves, W.; Wojdylo, J. On the Keyspace of the Hill Cipher. Cryptologia 2005, 29, 59–72. [Google Scholar] [CrossRef] [Scilit]
- Biham, E.; Shamir, A. Differential Cryptanalysis of DES-Like Cryptosystems. J. Cryptol. 1991, 4, 3–72. [Google Scholar] [CrossRef] [Scilit]
- Coppersmith, D. The Data Encryption Standard (DES) and Its Strength against Attacks. IBM J. Res. Dev. 1994, 38, 243–250. [Google Scholar] [CrossRef] [Scilit]
- Horn, R.A.; Johnson, C.R. Matrix Analysis, 2nd ed.; Cambridge University Press: Cambridge, UK, 2013. [Google Scholar] [CrossRef] [Scilit]
- Matsui, M. Linear Cryptanalysis Method for DES Cipher. In Proceedings of the Advances in Cryptology: EUROCRYPT ’93; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1994; Volume 765, pp. 386–397. [Google Scholar] [CrossRef] [Scilit] [PubMed]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.

