We answer a question of Paterson, showing that all block systems for thegroup generated by the round functions of a key-alternating block cipher arethe translates of a linear subspace. Following up remarks of Paterson andShamir, we exhibit a connection to truncated differential cryptanalysis. We also give a condition that guarantees that the group generated by theround functions of a key-alternating block cipher is primitive. This applies inparticular to AES.
展开▼