on data-dependent operations, respectively. They are also fast hardware-oriented ciphers
and improvements of block cipher CIKS-1 introduced in [14]. This paper presents related-key
differential attacks on full-round CIKS-128 and CIKS-128H. In result, using full-round related-
key differential characteristics with probability 2−− 36 and 2−− 35.4, these attacks can
recover the partial subkey bits for CIKS-128 and CIKS-128H with about 2 40 plaintexts …