Searching linear structures of permutation groups with quantum computer
摘要
Linear structures of round functions of block ciphers is well-known weakness. Several attacks such as linear or differential cryptanalysis are based on existence of non-trivial linear structures. We also can formulate this problem over symmetric group