Abstract:
We study how difference propagation probability depends on its Hamming weight. The difference of two values is XOR, an operation usual for differential cryptanalysis. We prove that the difference preserves with probability $2^{-h}$ if the most significant bit is 0, and with probability $2^{-(h-1)}$ if this bit is 1, where $h$ is the difference's Hamming weight. Theoretical results are confirmed experimentally. Bibliogr. 13.