, about the branch number ?

I. Let,

?. , } ? P 2 (M I + a) has information set K , p 0 + p 1 ? C K and then R(p 0 ) + R(p 1 )

?. If-|k-|-<-b, M. |j|, and R. ,

S. Banik, A. Bogdanov, T. Isobe, K. Shibutani, H. Hiwatari et al., Midori: A block cipher for low energy, ASIACRYPT 2015, pp.411-436, 2015.

J. Daemen and V. Rijmen,

, The Design of Rijndael: AES-The Advanced Encryption Standard, 2002.

L. Grassi, C. Rechberger, and S. Rønjom, Subspace trail cryptanalysis and its applications to AES, IACR Trans. Symmetric Cryptol, vol.2016, issue.2, pp.192-225, 2016.

L. Grassi, C. Rechberger, and S. Rønjom, A new structural-differential property of 5-round AES, EUROCRYPT 2017, Part II, vol.10211, pp.289-317, 2017.

G. Leander, C. Tezcan, and F. Wiemer, Searching for subspace trails and truncated differentials, vol.30, p.30