“…Depending on the starting round and on the differential being used ((a, 0, a, 0) or (0, a, 0, a)), there is a varying amount of overlap between the subkey bits. In the case of our choice (from second to the fifth round, with the first differential), we will work with subkeys: 5 5 , Z 5 6 : a) Decrypt the last half round of all the structures, using the guessed subkeys. b) For each structure find all pairs with zero differences in the third and fourth words, leaving about 2 31 pairs per structure.…”