## CryptoDB

### Paper: Results from a Search for the Best Linear Approximation of a Block Cipher

Authors: Kashif Ali Howard M. Heys URL: http://eprint.iacr.org/2008/076 Search ePrint Search Google In this paper, we investigate the application of an algorithm to find the best linear approximation of a basic Substitution-Permutation Network block cipher. The results imply that, while it is well known that the S-box used for the Advanced Encryption Standard has good nonlinear properties, it is straightforward to randomly select other S-boxes which are able to provide a similar level of security, as indicated by the exact bias of the best linear approximation found by the algorithm, rather than a simple upper bound on the maximum bias.
