Abstract :
Plateau characteristics are a special type of characteristics whose probability depends on the key and can have only two values. For a (usually small) subset of the keys it has a non-zero probability and for all other keys its probability is zero. For a large group of ciphers, including the AES, all two-round characteristics are plateau characteristics. For the AES and other ciphers with a similar structure, the vast majority of characteristics over four or more rounds are plateau characteristics. In the case of the AES, for most keys, there are two-round characteristics with fixed-key probability equal to 32/2 32, whereas the maximum expected differential probability of two-round differentials is at most 13.25/232