Problems with the Linear Cryptanalysis of DES Using more than one Active S-Box per Round”, Fast Software Encryption (1994)

by U Blöcher, M Dichtl