Problems with the linear cryptanalysis of DES using more than one active S-box per round (1994)

by U Blocher, M Dichtl
Venue:Fast Software Encryption: Second International Workshop