A Short Note on a Weight Probability Distribution Related to SPNs

We report on a simple technique that supports some recent developments on AES by Grassi and Rechberger and Bao, Guo and List. We construct a weight transition probability matrix related to AES that characterises fixed configurations of active bytes in di↵erences of ciphertexts when plaintext di↵erences are fixed to some (possibly other) configuration of active bytes. The construction is very simple and requires only a little bit of linear algebra. The derived probabilities are essentially identical to recent results on 5and 6-rounds AES derived through more sophisticated means, indicating that it might be worth a further investigation.