characteristics to retrieve a subkey material for the first or the last several rounds of block
ciphers. Thus, the security of a block cipher against IDC can be evaluated by impossible
differential characteristics. In this paper, we study impossible differential characteristics of
block cipher structures whose round functions are bijective. We introduce a widely
applicable method to find various impossible differential characteristics of block cipher …