2Knudsen L. Truncated and high order differentials[J]. LNCS, 1994, 1008: 196-211.
3Blondeau C, Gorard B, and Nyberg K. Multiple differential cryptanalysis using LLR and X2 statistics[J]. LNCS, 2012, 7485: 151-154.
4Blondeau C and Nyberg K. New Links between differential and linear cryptanalysis[J]. LNCS, 2013, 7881: 388-404.
5Albrecht M and Leander G. An all-in-one approach to differential cryptanalysis for small block ciphers[J]. LNCS, 2012, 7707: 1-15.
6Matsui M and Tokia T. Cryptanalysis of a reduced version of the block cipher E2[J]. LNCS, 1999, 1636: 71-80.
7Biryukov A, Canniere C, Lano J, et al.. Security and performance analysis of ARIA[OL]. http://cloud, ttongfly. net/t/attachment/1321529635.pdf. 2004, 07.
8Koyama T, Wang L, Sasaki Y, et al. New truncated differential cryptanalysis on 3D block cipher[J]. LNCS, 2012, 7232: 109-125.
9Sugita M, Kobara K, and Imai H. Pseudorandomness and maximum average of differential prabability of block ciphers with SPN-structures like E2[C]. In proceedings of the Second Advanced Encryption Standard Candidate Conference, New York, 1999: 200-214.
10Sugita M, Kobara K, Uehara K, et al.. Relationship among differential, truncated differential, impossible differential cryptanalysis against word-oriented block ciphers like Rijindael, E2[C]. Third AES Workshop, New York, 2000: 242-254.