REVIEW 2 minor 31 references
Every non-MDS matrix admits related differentials, as do all odd-order symmetric MDS matrices and most circulant matrices.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
The paper proves that every non-MDS matrix admits related differentials, every odd-order symmetric MDS matrix admits them, most circulant matrices admit them, and gives an explicit 15-constraint criterion for 3x3 MDS matrices over finite fields.
T0 review reviewed 2026-06-29 challenge →
load-bearing objection Four algebraic necessity results on related differentials give concrete obstructions for MDS matrix classes that were previously treated as interchangeable.
Analyzing Linear Layers in Related-Differential Cryptanalysis
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
Core claim
The central claim is that related differentials are unavoidable outside narrow algebraic conditions: every non-MDS matrix admits a nontrivial pair, every odd-order symmetric MDS matrix admits them, and every circulant matrix of order n with n not congruent to plus or minus 2 modulo 12 admits them. For 3 by 3 MDS matrices over F_{2^m}, the absence of related differentials holds if and only if 15 explicit polynomial constraints are satisfied.
What carries the argument
Related differentials, pairs of input-output differences linked by the linear layer that enable chained differential trails beyond what branch number alone controls.
Load-bearing premise
The definition and attack model for related differentials match exactly those introduced in the cited prior references.
What would settle it
A single non-MDS matrix with no nontrivial related-differential pair, or a single odd-order symmetric MDS matrix with none, would disprove the necessity claims.
If this is right
- Any cipher whose linear layer is not MDS is immediately open to related-differential exploitation.
- Symmetric MDS matrices of odd order are ruled out for designs that must avoid related differentials.
- Circulant layers are restricted to orders satisfying the stated congruence to have any chance of avoiding the structure.
- The 15-constraint criterion gives a concrete, checkable test for all 3 by 3 MDS matrices over characteristic-2 fields.
- Cipher designers must now verify their chosen matrix against these classes rather than relying on the MDS property alone.
Where Pith is reading between the lines
- Existing ciphers that already use odd-order symmetric or non-conforming circulant layers may carry previously unrecognized attack surfaces.
- The results invite similar classification for other common matrix families such as Hadamard or Toeplitz forms.
- A natural next step is to lift the 15-constraint test to 4 by 4 or larger MDS matrices over the same fields.
- Lightweight ciphers that replace matrix diffusion with bit-permutation or other non-matrix layers may require an analogous analysis.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proves four main results on related differentials in linear layers: (1) every non-MDS matrix admits a nontrivial pair of related differentials, establishing necessity of the MDS property; (2) every odd-order symmetric MDS matrix admits related differentials; (3) related differentials are unavoidable for every circulant matrix of order n with n ≢ ±2 (mod 12); and (4) an explicit necessary-and-sufficient criterion consisting of 15 polynomial constraints characterizes 3×3 MDS matrices over F_{2^m} that avoid related differentials.
Significance. If the algebraic derivations hold, the results provide a rigorous classification of when the MDS property is necessary but not always sufficient to avoid related-differential structure, with explicit constructions for the symmetric and circulant cases and a concrete, checkable polynomial criterion for the 3×3 case. These strengthen resistance arguments in AES-like designs beyond the classical branch-number analysis and supply falsifiable algebraic tests that can be verified directly over finite fields.
minor comments (2)
- [Abstract] The abstract and introduction should explicitly reference the precise definition of 'related differential' from Bardeh-Rijmen 2022 (or the cited prior work) to ensure the necessity claims transfer unambiguously to the attack model used here.
- [Circulant case section] In the circulant-matrix theorem, the proof sketch for the n ≢ ±2 (mod 12) case would benefit from a short table or enumerated case breakdown showing how the exhaustive analysis covers the residue classes.
Simulated Author's Rebuttal
We thank the referee for the positive assessment of our work and the recommendation for minor revision. No specific major comments were raised in the report, so we have no points requiring point-by-point rebuttal at this stage. We remain available to incorporate any minor clarifications or corrections identified during the editorial process.
Circularity Check
No significant circularity; algebraic proofs are self-contained
full rationale
The paper derives its four main results (non-MDS matrices always admit related differentials; odd-order symmetric MDS matrices always admit them; circulant matrices avoid them only for n ≡ ±2 mod 12; and the 15-polynomial criterion for 3×3 MDS) directly from the algebraic definitions of MDS matrices and related differentials over finite fields, using explicit constructions, exhaustive case analysis, and polynomial derivations. These steps contain no self-definitional reductions, no fitted parameters renamed as predictions, and no load-bearing self-citations, as the foundational definition is taken from external prior work (Daemen-Rijmen 2009, Bardeh-Rijmen 2022) whose authors do not overlap with the present paper. The derivation chain is therefore independent of its own outputs and remains self-contained.
Axiom & Free-Parameter Ledger
axioms (2)
- standard math Finite fields F_{2^m} are fields with the usual addition and multiplication operations.
- domain assumption The definition of related differentials follows exactly the formulation in Daemen-Rijmen 2009 and Bardeh-Rijmen 2022.
Cite this review
Pith. "Pith review of Analyzing Linear Layers in Related-Differential Cryptanalysis." pith.science (2026). https://pith.science/paper/3KIP4KAF
@misc{pith2026260527535,
author = {Pith},
title = {Pith review of: Analyzing Linear Layers in Related-Differential Cryptanalysis},
year = {2026},
howpublished = {\url{https://pith.science/paper/3KIP4KAF}},
note = {Machine review of arXiv:2605.27535}
}
abstract
In AES-like ciphers, diffusion layers are commonly instantiated using MDS matrices, since their optimal branch number yields strong diffusion guarantees and underpins classical resistance arguments against differential and linear cryptanalysis. However, Daemen and Rijmen (2009) showed that linear layers may still exhibit related-differential structure beyond what the MDS criterion captures, and Bardeh and Rijmen (2022) demonstrated that this phenomenon can be exploited in attacks on reduced-round AES. In this work, we systematically investigate the conditions under which linear layers avoid or exhibit these differentials, identifying matrix classes for which such structure is unavoidable. We first prove that every non-MDS matrix admits a nontrivial pair of related differentials, showing that the MDS property is necessary for avoiding them. We then establish that every odd-order symmetric MDS matrix admits related differentials, which rules out broad families of Cauchy-based constructions. We also substantially strengthen the circulant case by proving that related differentials are unavoidable for every circulant matrix of order $n$ with $n \not\equiv \pm 2 \pmod{12}$. Finally, we revisit the characterization of $3 \times 3$ MDS matrices over $\mathbb{F}_{2^m}$ for the absence of related differentials, and derive an explicit necessary and sufficient criterion in terms of $15$ polynomial constraints.
Reference graph
Works this paper leans on
-
[1]
J. Daemen and V . Rijmen,The Design of Rijndael: AES - The Advanced Encryption Standard, ser. Information Security and Cryptography. Springer, 2002. [Online]. Available: https://doi.org/10.1007/978-3-662-04722-4
-
[2]
Daemen,Cipher and hash function design, strategies based on linear and differential cryptanalysis, PhD Thesis
J. Daemen,Cipher and hash function design, strategies based on linear and differential cryptanalysis, PhD Thesis. K.U.Leuven, 1995, http://jda.noekeon.org/
1995
-
[3]
The cipher SHARK,
V . Rijmen, J. Daemen, B. Preneel, A. Bosselaers, and E. De Win, “The cipher SHARK,” inFast Software Encryption, D. Gollmann, Ed. Berlin, Heidelberg: Springer Berlin Heidelberg, 1996, pp. 99–111
1996
-
[4]
The block cipher Square,
J. Daemen, L. Knudsen, and V . Rijmen, “The block cipher Square,” inFast Software Encryption, E. Biham, Ed. Berlin, Heidelberg: Springer Berlin Heidelberg, 1997, pp. 149–165
1997
-
[5]
A Construction of Matrices with No Singular Square Submatrices,
J. Lacan and J. Fimes, “A Construction of Matrices with No Singular Square Submatrices,” inFinite Fields and Applications, G. L. Mullen, A. Poli, and H. Stichtenoth, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2004, pp. 145–147
2004
-
[6]
On constructions of involutory MDS matrices,
K. C. Gupta and I. G. Ray, “On constructions of involutory MDS matrices,” inInternational Conference on Cryptology in Africa. Springer, 2013, pp. 43–60
2013
-
[7]
Cryptographically significant MDS matrices over finite fields: A brief survey and some generalized results,
K. C. Gupta, S. K. Pandey, I. G. Ray, and S. Samanta, “Cryptographically significant MDS matrices over finite fields: A brief survey and some generalized results,”Advances in Mathematics of Communications, vol. 13, no. 4, pp. 779–843, 2019
2019
-
[8]
On the Direct Construction of MDS and Near-MDS Matrices,
K. C. Gupta, S. K. Pandey, and S. Samanta, “On the Direct Construction of MDS and Near-MDS Matrices,”Advances in Mathematics of Communications, vol. 24, no. 0, pp. 110–135, 2026. [Online]. Available: https://www.aimsciences.org/article/id/69d772db64170a12e9eaafa3
2026
-
[9]
On construction of Involutory MDS Matrices from Vandermonde Matrices in GF(2 q),
M. Sajadieh, M. Dakhilalian, H. Mala, and B. Omoomi, “On construction of Involutory MDS Matrices from Vandermonde Matrices in GF(2 q),”Designs, Codes and Cryptography, vol. 64, no. 3, pp. 287–308, sep 2012
2012
-
[10]
Direct Construction of Recursive MDS Diffusion Layers Using Shortened BCH Codes,
D. Augot and M. Finiasz, “Direct Construction of Recursive MDS Diffusion Layers Using Shortened BCH Codes,” inFast Software Encryption – FSE 2014, ser. Lecture Notes in Computer Science, vol. 8540. London, UK: Springer, March 2014, pp. 3–17
2014
-
[11]
Towards a general construction of recursive MDS diffusion layers,
K. C. Gupta, S. K. Pandey, and A. Venkateswarlu, “Towards a general construction of recursive MDS diffusion layers,”Designs, Codes and Cryptography, vol. 82, no. 1-2, pp. 179–195, 2017
2017
-
[12]
On the direct construction of recursive MDS matrices,
——, “On the direct construction of recursive MDS matrices,”Designs, Codes and Cryptography, vol. 82, no. 1-2, pp. 77–94, 2017
2017
-
[13]
Exhaustive Search for Various Types of MDS Matrices,
A. Kesarwani, S. Sarkar, and A. Venkateswarlu, “Exhaustive Search for Various Types of MDS Matrices,”IACR Transactions on Symmetric Cryptology, vol. 2019, no. 3, pp. 231–256, Sep. 2019. [Online]. Available: https://tosc.iacr.org/index.php/ToSC/article/view/8364
2019
-
[14]
Lightweight MDS Involution Matrices,
S. M. Sim, K. Khoo, F. Oggier, and T. Peyrin, “Lightweight MDS Involution Matrices,” inFast Software Encryption – FSE 2015, ser. Lecture Notes in Computer Science, G. Leander, Ed., vol. 9054. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015, pp. 471–493. 24
2015
-
[15]
Lightweight MDS Generalized Circulant Matrices,
M. Liu and S. M. Sim, “Lightweight MDS Generalized Circulant Matrices,” inFast Software Encryption – FSE 2016, ser. Lecture Notes in Computer Science, T. Peyrin, Ed., vol. 9783. Bochum, Germany: Springer, March 2016, pp. 101–120
2016
-
[16]
On the construction of lightweight circulant involutory mds matrices,
Y . Li and M. Wang, “On the construction of lightweight circulant involutory mds matrices,” inFast Software Encryption – FSE 2016, ser. Lecture Notes in Computer Science, T. Peyrin, Ed., vol. 9783. Bochum, Germany: Springer, March 2016, pp. 121–139
2016
-
[17]
A new matrix form to generate all3×3involutory MDS matrices overF 2m ,
G. G. G ¨uzel, M. T. Sakalli, S. Akleylek, V . Rijmen, and Y . C ¸ engellenmis ¸, “A new matrix form to generate all3×3involutory MDS matrices overF 2m ,”Information Processing Letters, vol. 147, pp. 61–68, 2019
2019
-
[18]
Generalisation of Hadamard matrix to generate involutory MDS matrices for lightweight cryptography,
M. K. Pehlivano ˜glu, M. T. Sakalli, S. Akleylek, N. Duru, and V . Rijmen, “Generalisation of Hadamard matrix to generate involutory MDS matrices for lightweight cryptography,”IET Information Security, vol. 12, no. 4, pp. 348–355, 2018
2018
-
[19]
Construction of all MDS and involutory MDS matrices,
Y . Kumar, P. R. Mishra, S. Samanta, K. C. Gupta, and A. Gaur, “Construction of all MDS and involutory MDS matrices,”Advances in Mathematics of Communications, vol. 19, no. 3, pp. 922–941, 2025
2025
-
[20]
A systematic construction approach for all4×4involutory MDS matrices,
Y . Kumar, P. R. Mishra, S. Samanta, and A. Gaur, “A systematic construction approach for all4×4involutory MDS matrices,”Journal of Applied Mathematics and Computing, vol. 70, no. 5, pp. 4677–4697, 2024. [Online]. Available: https://doi.org/10.1007/s12190-024-02142-z
-
[21]
New criteria for linear maps in AES-like ciphers,
J. Daemen and V . Rijmen, “New criteria for linear maps in AES-like ciphers,”Cryptography and Communications, vol. 1, no. 1, pp. 47–69, 2009
2009
-
[22]
New key-recovery attack on reduced-round aes,
N. Ghaedi Bardeh and V . Rijmen, “New key-recovery attack on reduced-round aes,”IACR Transactions on Symmetric Cryptology, vol. 2022, no. 2, p. 43–62, Jun. 2022. [Online]. Available: https://tosc.iacr.org/index.php/ToSC/article/view/9713
2022
-
[23]
S. Rønjom, N. G. Bardeh, and T. Helleseth, “Yoyo Tricks with AES,” inAdvances in Cryptology - ASIACRYPT 2017 - 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3-7, 2017, Proceedings, Part I, ser. Lecture Notes in Computer Science, T. Takagi and T. Peyrin, Eds. Springer, 2017, ...
-
[24]
Construction of hadamard-based mixcolumns matrices resistant to related-differential cryptanalysis,
S. Jha, S. Li, and D. Gligoroski, “Construction of hadamard-based mixcolumns matrices resistant to related-differential cryptanalysis,” IACR Communications in Cryptology, vol. 2, no. 1, 2025
2025
-
[25]
On the Cryptographic Resilience of MDS Matrices,
K. Otal, A. M. S ¨ulc ¸e, and O. Yayla, “On the Cryptographic Resilience of MDS Matrices,”Cryptology ePrint Archive, 2025
2025
-
[26]
Block Ciphers – Focus on the Linear Layer (feat. PRIDE),
M. R. Albrecht, B. Driessen, E. B. Kavun, G. Leander, C. Paar, and T. Yalc ¸ın, “Block Ciphers – Focus on the Linear Layer (feat. PRIDE),” inAdvances in Cryptology – CRYPTO 2014, J. A. Garay and R. Gennaro, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2014, pp. 57–76
2014
-
[27]
Midori: A Block Cipher for Low Energy,
S. Banik, A. Bogdanov, T. Isobe, K. Shibutani, H. Hiwatari, T. Akishita, and F. Regazzoni, “Midori: A Block Cipher for Low Energy,” in Advances in Cryptology – ASIACRYPT 2015, T. Iwata and J. H. Cheon, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015, pp. 411–436
2015
-
[28]
The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS,
C. Beierle, J. Jean, S. K ¨olbl, G. Leander, A. Moradi, T. Peyrin, Y . Sasaki, P. Sasdrich, and S. M. Sim, “The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS,” inAdvances in Cryptology – CRYPTO 2016, M. Robshaw and J. Katz, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2016, pp. 123–153
2016
-
[29]
Fides: Lightweight Authenticated cipher with Side-Channel Resistance for Constrained Hardware,
B. Bilgin, A. Bogdanov, M. Kne ˇzevi´c, F. Mendel, and Q. Wang, “Fides: Lightweight Authenticated cipher with Side-Channel Resistance for Constrained Hardware,” inCryptographic Hardware and Embedded Systems - CHES 2013, G. Bertoni and J.-S. Coron, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2013, pp. 142–158
2013
-
[30]
PRINCE – A Low-Latency Block Cipher for Pervasive Computing Applications,
J. Borghoff, A. Canteaut, T. G ¨uneysu, E. B. Kavun, M. Knezevic, L. R. Knudsen, G. Leander, V . Nikov, C. Paar, C. Rechberger, P. Rombouts, S. S. Thomsen, and T. Yalc ¸ın, “PRINCE – A Low-Latency Block Cipher for Pervasive Computing Applications,” inAdvances in Cryptology – ASIACRYPT 2012, X. Wang and K. Sako, Eds. Berlin, Heidelberg: Springer Berlin Hei...
2012
-
[31]
MacWilliams and N
F. MacWilliams and N. Sloane,The Theory of Error Correcting Codes. North-Holland Publishing Co., Amsterdam-New York-Oxford, 1977. 25
1977
This paper was first reviewed by grok-4.3 on June 29, 2026.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.