“…In this paper we consider the same cipher but with a round function of more general form and we determine the correlation distribution in dependence of the key for arbitrary input and output masks (σ, ω), where σ, ω ∈ F n 2 , n odd. Our methods are based on finite-field theory, see, e.g., [3,10,11,13] and some general results on correlation analysis and linear cryptanalysis [5,8,12].…”