# Recursive Diffusion Layers for (Lightweight) Block Ciphers and Hash Functions

### Cites methods from "Recursive Diffusion Layers for (Lig..."

...Then the work is improved by using linear transformations with fewer XORs in [23], where some extreme lightweight MDS matrices are given....

...In previous constructions, the entries used to construct MDS matrices are pairwise commutative, such as MDS matrices over finite fields, or assumed pairwise commutative, such as recursive MDS matrices with elements being linear transformations [20,23]....

...We use the method in [20,23] to characterize whether L is MDS....

### Cites background or methods from "Recursive Diffusion Layers for (Lig..."

...[30], we consider a generalization to additive MDS codes in order to improve efficiency....

...In [24] and [30] the authors focus on even more efficient choices for A by considering additive, i....

...3 This is also true for the constructions given in [30], but does not hold for the subfield (or code-interleaving) construction....

...This is also the case when considering an unrolled implementation of the serial implementations in [30]....

