Differential Cryptanalysis of Optimal 4-bit S-Boxes Against Alternative Operations
This work characterizes diffusion layers that are linear with respect to both the standard XOR operation and a parallel alternative operation, enabling differential attacks that simultaneously target all s-boxes within a block. The authors also investigate the differential properties of all classes of optimal 4-bit s-boxes with respect to alternative operations, identifying certain classes that contain weak permutations vulnerable to such attacks.