principle used in linear cryptanalysis to construct linear approximation to the action of block ciphers