The r-rounds Evenâ€“Mansour block cipher is a generalization of the well known Evenâ€“Mansour block cipher to r iterations. Attacks on this construction were described by NikoliÄ‡ et al. and Dinur et al.â€¦ (More)

An oracle chooses a function f from the set of n bits strings to itself, which is either a randomly chosen permutation or a randomly chosen function. When queried by an n-bit string w, the oracleâ€¦ (More)

We show that a differential version of the classical Chebyshevâ€“Markovâ€“Stieltjes inequalities holds for a broad family of weight functions. Such a differential version appears to be new. Our resultsâ€¦ (More)

An oracle chooses a function f from the set of n bits strings to itself, which is either a randomly chosen permutation or a randomly chosen function. When queried by an n-bit string w, the oracleâ€¦ (More)

We show that for every > 0 there is an absolute constant c( ) > 0 such that the following is true: The union of any n arithmetic progressions, each of length n, with pairwise distinct differencesâ€¦ (More)

A family of sets is called r-cover free if it does not contain 2 â‰¤ ` + 1 â‰¤ r + 1 distinct sets A0, A1, . . . , A` such that A0 âŠ† A1 âˆª Â· Â· Â· âˆªA`. In particular, a 1-cover free family of sets is simplyâ€¦ (More)

Thedegree anti-RamseynumberARd(H)of a graphH is the smallest integer k for which there exists a graph Gwithmaximum degree at most k such that any proper edge colouring of G yields a rainbow copy of Hâ€¦ (More)

Let m < n be non-negative integers. An oracle chooses a permutation Ï€ of {0, 1}n uniformly at random. When queried with an n-bit string w, it truncates the lastm bits of Ï€(w), and returns theâ€¦ (More)