Camellia is a 128-bit block cipher, proposed by NTT and Mitsubishi in 2000. It has been shown that 10 round variant without FL function
under a 256-bit secret key is attackable by Higher Order Differential Attack and even if FL function is included, 9 round
variant is attackable by Square Attack. In this paper, we present a new attack of Camellia using 16-th order Differential and show that 11 round variant without FL function is attackable. Moreover, we show that 11
round variant with FL function is attackable, if we use chosen ciphertexts for this attack.
We call that paper “Higher Order Differential Attack of Camellia (I)”