Abstract
In this paper we introduce the mini-square propagation: four ciphertexts corresponding to four plaintexts with some specific differences summing to zero after several rounds. We then extend this propagation by appending a linear propagation to the mini-square propagation and by preceding it with differential propagations. We apply this approach to block ciphers AES and Camellia.