Dierential cryptanalysis [2], pioneered by Biham and Shamir, has had
a quite revolutionary eect on the design and analysis of block ciphers.
The basic idea in this technique is the following: Two plaintexts are chosen
with a certain dierence" P 0 between them. Typically, the dierence" is
measured by exclusive-or , but for some ciphers an alternative measure can
be more useful. These two plaintexts are enciphered to give two ciphertexts
such that their dierence C0 has a specic value with better than average
probability. Such a pair (P 0; C0) is called a characteristic. Depending on the