Pith. sign in

REVIEW 2 minor 31 references

Every non-MDS matrix admits related differentials, as do all odd-order symmetric MDS matrices and most circulant matrices.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

The paper proves that every non-MDS matrix admits related differentials, every odd-order symmetric MDS matrix admits them, most circulant matrices admit them, and gives an explicit 15-constraint criterion for 3x3 MDS matrices over finite fields.

T0 review reviewed 2026-06-29 challenge →

load-bearing objection Four algebraic necessity results on related differentials give concrete obstructions for MDS matrix classes that were previously treated as interchangeable.

arxiv 2605.27535 v1 pith:3KIP4KAF submitted 2026-05-26 cs.CR

Analyzing Linear Layers in Related-Differential Cryptanalysis

classification cs.CR
keywords related differentialsMDS matriceslinear layersdifferential cryptanalysisAES-like cipherscirculant matricessymmetric matricesfinite fields
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper proves that the MDS property is necessary but not sufficient to prevent related differentials in linear layers of AES-like ciphers. Any matrix that is not MDS has a nontrivial related-differential pair. Symmetric MDS matrices of odd order always exhibit them, which eliminates many Cauchy constructions. Circulant matrices of order n also always have them unless n is congruent to plus or minus 2 modulo 12. For the special case of 3 by 3 MDS matrices over fields of characteristic 2, absence of related differentials is equivalent to satisfying a fixed list of 15 polynomial constraints.

Core claim

The central claim is that related differentials are unavoidable outside narrow algebraic conditions: every non-MDS matrix admits a nontrivial pair, every odd-order symmetric MDS matrix admits them, and every circulant matrix of order n with n not congruent to plus or minus 2 modulo 12 admits them. For 3 by 3 MDS matrices over F_{2^m}, the absence of related differentials holds if and only if 15 explicit polynomial constraints are satisfied.

What carries the argument

Related differentials, pairs of input-output differences linked by the linear layer that enable chained differential trails beyond what branch number alone controls.

Load-bearing premise

The definition and attack model for related differentials match exactly those introduced in the cited prior references.

What would settle it

A single non-MDS matrix with no nontrivial related-differential pair, or a single odd-order symmetric MDS matrix with none, would disprove the necessity claims.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

If this is right

  • Any cipher whose linear layer is not MDS is immediately open to related-differential exploitation.
  • Symmetric MDS matrices of odd order are ruled out for designs that must avoid related differentials.
  • Circulant layers are restricted to orders satisfying the stated congruence to have any chance of avoiding the structure.
  • The 15-constraint criterion gives a concrete, checkable test for all 3 by 3 MDS matrices over characteristic-2 fields.
  • Cipher designers must now verify their chosen matrix against these classes rather than relying on the MDS property alone.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Existing ciphers that already use odd-order symmetric or non-conforming circulant layers may carry previously unrecognized attack surfaces.
  • The results invite similar classification for other common matrix families such as Hadamard or Toeplitz forms.
  • A natural next step is to lift the 15-constraint test to 4 by 4 or larger MDS matrices over the same fields.
  • Lightweight ciphers that replace matrix diffusion with bit-permutation or other non-matrix layers may require an analogous analysis.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

0 major / 2 minor

Summary. The paper proves four main results on related differentials in linear layers: (1) every non-MDS matrix admits a nontrivial pair of related differentials, establishing necessity of the MDS property; (2) every odd-order symmetric MDS matrix admits related differentials; (3) related differentials are unavoidable for every circulant matrix of order n with n ≢ ±2 (mod 12); and (4) an explicit necessary-and-sufficient criterion consisting of 15 polynomial constraints characterizes 3×3 MDS matrices over F_{2^m} that avoid related differentials.

Significance. If the algebraic derivations hold, the results provide a rigorous classification of when the MDS property is necessary but not always sufficient to avoid related-differential structure, with explicit constructions for the symmetric and circulant cases and a concrete, checkable polynomial criterion for the 3×3 case. These strengthen resistance arguments in AES-like designs beyond the classical branch-number analysis and supply falsifiable algebraic tests that can be verified directly over finite fields.

minor comments (2)
  1. [Abstract] The abstract and introduction should explicitly reference the precise definition of 'related differential' from Bardeh-Rijmen 2022 (or the cited prior work) to ensure the necessity claims transfer unambiguously to the attack model used here.
  2. [Circulant case section] In the circulant-matrix theorem, the proof sketch for the n ≢ ±2 (mod 12) case would benefit from a short table or enumerated case breakdown showing how the exhaustive analysis covers the residue classes.

Simulated Author's Rebuttal

0 responses · 0 unresolved

We thank the referee for the positive assessment of our work and the recommendation for minor revision. No specific major comments were raised in the report, so we have no points requiring point-by-point rebuttal at this stage. We remain available to incorporate any minor clarifications or corrections identified during the editorial process.

Circularity Check

0 steps flagged

No significant circularity; algebraic proofs are self-contained

full rationale

The paper derives its four main results (non-MDS matrices always admit related differentials; odd-order symmetric MDS matrices always admit them; circulant matrices avoid them only for n ≡ ±2 mod 12; and the 15-polynomial criterion for 3×3 MDS) directly from the algebraic definitions of MDS matrices and related differentials over finite fields, using explicit constructions, exhaustive case analysis, and polynomial derivations. These steps contain no self-definitional reductions, no fitted parameters renamed as predictions, and no load-bearing self-citations, as the foundational definition is taken from external prior work (Daemen-Rijmen 2009, Bardeh-Rijmen 2022) whose authors do not overlap with the present paper. The derivation chain is therefore independent of its own outputs and remains self-contained.

Axiom & Free-Parameter Ledger

0 free parameters · 2 axioms · 0 invented entities

The work rests on standard finite-field arithmetic and the definition of related differentials from prior literature; no free parameters are introduced, no new entities are postulated, and the axioms invoked are the usual properties of vector spaces over finite fields.

axioms (2)
  • standard math Finite fields F_{2^m} are fields with the usual addition and multiplication operations.
    Invoked throughout the matrix constructions and polynomial constraints.
  • domain assumption The definition of related differentials follows exactly the formulation in Daemen-Rijmen 2009 and Bardeh-Rijmen 2022.
    The necessity claims are relative to that attack model.

reviewed 2026-06-29 · how reviews work

0 comments
Cite this review

Pith. "Pith review of Analyzing Linear Layers in Related-Differential Cryptanalysis." pith.science (2026). https://pith.science/paper/3KIP4KAF

@misc{pith2026260527535,
  author       = {Pith},
  title        = {Pith review of: Analyzing Linear Layers in Related-Differential Cryptanalysis},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/3KIP4KAF}},
  note         = {Machine review of arXiv:2605.27535}
}
Share X Bluesky LinkedIn Reddit HN
abstract

In AES-like ciphers, diffusion layers are commonly instantiated using MDS matrices, since their optimal branch number yields strong diffusion guarantees and underpins classical resistance arguments against differential and linear cryptanalysis. However, Daemen and Rijmen (2009) showed that linear layers may still exhibit related-differential structure beyond what the MDS criterion captures, and Bardeh and Rijmen (2022) demonstrated that this phenomenon can be exploited in attacks on reduced-round AES. In this work, we systematically investigate the conditions under which linear layers avoid or exhibit these differentials, identifying matrix classes for which such structure is unavoidable. We first prove that every non-MDS matrix admits a nontrivial pair of related differentials, showing that the MDS property is necessary for avoiding them. We then establish that every odd-order symmetric MDS matrix admits related differentials, which rules out broad families of Cauchy-based constructions. We also substantially strengthen the circulant case by proving that related differentials are unavoidable for every circulant matrix of order $n$ with $n \not\equiv \pm 2 \pmod{12}$. Finally, we revisit the characterization of $3 \times 3$ MDS matrices over $\mathbb{F}_{2^m}$ for the absence of related differentials, and derive an explicit necessary and sufficient criterion in terms of $15$ polynomial constraints.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

31 extracted references · 3 canonical work pages

  1. [1]

    Daemen and V

    J. Daemen and V . Rijmen,The Design of Rijndael: AES - The Advanced Encryption Standard, ser. Information Security and Cryptography. Springer, 2002. [Online]. Available: https://doi.org/10.1007/978-3-662-04722-4

  2. [2]

    Daemen,Cipher and hash function design, strategies based on linear and differential cryptanalysis, PhD Thesis

    J. Daemen,Cipher and hash function design, strategies based on linear and differential cryptanalysis, PhD Thesis. K.U.Leuven, 1995, http://jda.noekeon.org/

  3. [3]

    The cipher SHARK,

    V . Rijmen, J. Daemen, B. Preneel, A. Bosselaers, and E. De Win, “The cipher SHARK,” inFast Software Encryption, D. Gollmann, Ed. Berlin, Heidelberg: Springer Berlin Heidelberg, 1996, pp. 99–111

  4. [4]

    The block cipher Square,

    J. Daemen, L. Knudsen, and V . Rijmen, “The block cipher Square,” inFast Software Encryption, E. Biham, Ed. Berlin, Heidelberg: Springer Berlin Heidelberg, 1997, pp. 149–165

  5. [5]

    A Construction of Matrices with No Singular Square Submatrices,

    J. Lacan and J. Fimes, “A Construction of Matrices with No Singular Square Submatrices,” inFinite Fields and Applications, G. L. Mullen, A. Poli, and H. Stichtenoth, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2004, pp. 145–147

  6. [6]

    On constructions of involutory MDS matrices,

    K. C. Gupta and I. G. Ray, “On constructions of involutory MDS matrices,” inInternational Conference on Cryptology in Africa. Springer, 2013, pp. 43–60

  7. [7]

    Cryptographically significant MDS matrices over finite fields: A brief survey and some generalized results,

    K. C. Gupta, S. K. Pandey, I. G. Ray, and S. Samanta, “Cryptographically significant MDS matrices over finite fields: A brief survey and some generalized results,”Advances in Mathematics of Communications, vol. 13, no. 4, pp. 779–843, 2019

  8. [8]

    On the Direct Construction of MDS and Near-MDS Matrices,

    K. C. Gupta, S. K. Pandey, and S. Samanta, “On the Direct Construction of MDS and Near-MDS Matrices,”Advances in Mathematics of Communications, vol. 24, no. 0, pp. 110–135, 2026. [Online]. Available: https://www.aimsciences.org/article/id/69d772db64170a12e9eaafa3

  9. [9]

    On construction of Involutory MDS Matrices from Vandermonde Matrices in GF(2 q),

    M. Sajadieh, M. Dakhilalian, H. Mala, and B. Omoomi, “On construction of Involutory MDS Matrices from Vandermonde Matrices in GF(2 q),”Designs, Codes and Cryptography, vol. 64, no. 3, pp. 287–308, sep 2012

  10. [10]

    Direct Construction of Recursive MDS Diffusion Layers Using Shortened BCH Codes,

    D. Augot and M. Finiasz, “Direct Construction of Recursive MDS Diffusion Layers Using Shortened BCH Codes,” inFast Software Encryption – FSE 2014, ser. Lecture Notes in Computer Science, vol. 8540. London, UK: Springer, March 2014, pp. 3–17

  11. [11]

    Towards a general construction of recursive MDS diffusion layers,

    K. C. Gupta, S. K. Pandey, and A. Venkateswarlu, “Towards a general construction of recursive MDS diffusion layers,”Designs, Codes and Cryptography, vol. 82, no. 1-2, pp. 179–195, 2017

  12. [12]

    On the direct construction of recursive MDS matrices,

    ——, “On the direct construction of recursive MDS matrices,”Designs, Codes and Cryptography, vol. 82, no. 1-2, pp. 77–94, 2017

  13. [13]

    Exhaustive Search for Various Types of MDS Matrices,

    A. Kesarwani, S. Sarkar, and A. Venkateswarlu, “Exhaustive Search for Various Types of MDS Matrices,”IACR Transactions on Symmetric Cryptology, vol. 2019, no. 3, pp. 231–256, Sep. 2019. [Online]. Available: https://tosc.iacr.org/index.php/ToSC/article/view/8364

  14. [14]

    Lightweight MDS Involution Matrices,

    S. M. Sim, K. Khoo, F. Oggier, and T. Peyrin, “Lightweight MDS Involution Matrices,” inFast Software Encryption – FSE 2015, ser. Lecture Notes in Computer Science, G. Leander, Ed., vol. 9054. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015, pp. 471–493. 24

  15. [15]

    Lightweight MDS Generalized Circulant Matrices,

    M. Liu and S. M. Sim, “Lightweight MDS Generalized Circulant Matrices,” inFast Software Encryption – FSE 2016, ser. Lecture Notes in Computer Science, T. Peyrin, Ed., vol. 9783. Bochum, Germany: Springer, March 2016, pp. 101–120

  16. [16]

    On the construction of lightweight circulant involutory mds matrices,

    Y . Li and M. Wang, “On the construction of lightweight circulant involutory mds matrices,” inFast Software Encryption – FSE 2016, ser. Lecture Notes in Computer Science, T. Peyrin, Ed., vol. 9783. Bochum, Germany: Springer, March 2016, pp. 121–139

  17. [17]

    A new matrix form to generate all3×3involutory MDS matrices overF 2m ,

    G. G. G ¨uzel, M. T. Sakalli, S. Akleylek, V . Rijmen, and Y . C ¸ engellenmis ¸, “A new matrix form to generate all3×3involutory MDS matrices overF 2m ,”Information Processing Letters, vol. 147, pp. 61–68, 2019

  18. [18]

    Generalisation of Hadamard matrix to generate involutory MDS matrices for lightweight cryptography,

    M. K. Pehlivano ˜glu, M. T. Sakalli, S. Akleylek, N. Duru, and V . Rijmen, “Generalisation of Hadamard matrix to generate involutory MDS matrices for lightweight cryptography,”IET Information Security, vol. 12, no. 4, pp. 348–355, 2018

  19. [19]

    Construction of all MDS and involutory MDS matrices,

    Y . Kumar, P. R. Mishra, S. Samanta, K. C. Gupta, and A. Gaur, “Construction of all MDS and involutory MDS matrices,”Advances in Mathematics of Communications, vol. 19, no. 3, pp. 922–941, 2025

  20. [20]

    A systematic construction approach for all4×4involutory MDS matrices,

    Y . Kumar, P. R. Mishra, S. Samanta, and A. Gaur, “A systematic construction approach for all4×4involutory MDS matrices,”Journal of Applied Mathematics and Computing, vol. 70, no. 5, pp. 4677–4697, 2024. [Online]. Available: https://doi.org/10.1007/s12190-024-02142-z

  21. [21]

    New criteria for linear maps in AES-like ciphers,

    J. Daemen and V . Rijmen, “New criteria for linear maps in AES-like ciphers,”Cryptography and Communications, vol. 1, no. 1, pp. 47–69, 2009

  22. [22]

    New key-recovery attack on reduced-round aes,

    N. Ghaedi Bardeh and V . Rijmen, “New key-recovery attack on reduced-round aes,”IACR Transactions on Symmetric Cryptology, vol. 2022, no. 2, p. 43–62, Jun. 2022. [Online]. Available: https://tosc.iacr.org/index.php/ToSC/article/view/9713

  23. [23]

    Yoyo Tricks with AES,

    S. Rønjom, N. G. Bardeh, and T. Helleseth, “Yoyo Tricks with AES,” inAdvances in Cryptology - ASIACRYPT 2017 - 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3-7, 2017, Proceedings, Part I, ser. Lecture Notes in Computer Science, T. Takagi and T. Peyrin, Eds. Springer, 2017, ...

  24. [24]

    Construction of hadamard-based mixcolumns matrices resistant to related-differential cryptanalysis,

    S. Jha, S. Li, and D. Gligoroski, “Construction of hadamard-based mixcolumns matrices resistant to related-differential cryptanalysis,” IACR Communications in Cryptology, vol. 2, no. 1, 2025

  25. [25]

    On the Cryptographic Resilience of MDS Matrices,

    K. Otal, A. M. S ¨ulc ¸e, and O. Yayla, “On the Cryptographic Resilience of MDS Matrices,”Cryptology ePrint Archive, 2025

  26. [26]

    Block Ciphers – Focus on the Linear Layer (feat. PRIDE),

    M. R. Albrecht, B. Driessen, E. B. Kavun, G. Leander, C. Paar, and T. Yalc ¸ın, “Block Ciphers – Focus on the Linear Layer (feat. PRIDE),” inAdvances in Cryptology – CRYPTO 2014, J. A. Garay and R. Gennaro, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2014, pp. 57–76

  27. [27]

    Midori: A Block Cipher for Low Energy,

    S. Banik, A. Bogdanov, T. Isobe, K. Shibutani, H. Hiwatari, T. Akishita, and F. Regazzoni, “Midori: A Block Cipher for Low Energy,” in Advances in Cryptology – ASIACRYPT 2015, T. Iwata and J. H. Cheon, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015, pp. 411–436

  28. [28]

    The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS,

    C. Beierle, J. Jean, S. K ¨olbl, G. Leander, A. Moradi, T. Peyrin, Y . Sasaki, P. Sasdrich, and S. M. Sim, “The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS,” inAdvances in Cryptology – CRYPTO 2016, M. Robshaw and J. Katz, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2016, pp. 123–153

  29. [29]

    Fides: Lightweight Authenticated cipher with Side-Channel Resistance for Constrained Hardware,

    B. Bilgin, A. Bogdanov, M. Kne ˇzevi´c, F. Mendel, and Q. Wang, “Fides: Lightweight Authenticated cipher with Side-Channel Resistance for Constrained Hardware,” inCryptographic Hardware and Embedded Systems - CHES 2013, G. Bertoni and J.-S. Coron, Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2013, pp. 142–158

  30. [30]

    PRINCE – A Low-Latency Block Cipher for Pervasive Computing Applications,

    J. Borghoff, A. Canteaut, T. G ¨uneysu, E. B. Kavun, M. Knezevic, L. R. Knudsen, G. Leander, V . Nikov, C. Paar, C. Rechberger, P. Rombouts, S. S. Thomsen, and T. Yalc ¸ın, “PRINCE – A Low-Latency Block Cipher for Pervasive Computing Applications,” inAdvances in Cryptology – ASIACRYPT 2012, X. Wang and K. Sako, Eds. Berlin, Heidelberg: Springer Berlin Hei...

  31. [31]

    MacWilliams and N

    F. MacWilliams and N. Sloane,The Theory of Error Correcting Codes. North-Holland Publishing Co., Amsterdam-New York-Oxford, 1977. 25

This paper was first reviewed by grok-4.3 on June 29, 2026.