{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:00:23Z","timestamp":1786978823129,"version":"3.56.0"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031159817","type":"print"},{"value":"9783031159824","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-15982-4_25","type":"book-chapter","created":{"date-parts":[[2022,10,11]],"date-time":"2022-10-11T04:40:54Z","timestamp":1665463254000},"page":"748-778","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Constructing and\u00a0Deconstructing Intentional Weaknesses in Symmetric Ciphers"],"prefix":"10.1007","author":[{"given":"Christof","family":"Beierle","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"Beyne","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Patrick","family":"Felke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gregor","family":"Leander","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,10,12]]},"reference":[{"key":"25_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-319-13051-4_1","volume-title":"Selected Areas in Cryptography \u2013 SAC 2014","author":"A Albertini","year":"2014","unstructured":"Albertini, A., Aumasson, J.-P., Eichlseder, M., Mendel, F., Schl\u00e4ffer, M.: Malicious hashing: Eve\u2019s variant of SHA-1. In: Joux, A., Youssef, A. (eds.) SAC 2014. LNCS, vol. 8781, pp. 1\u201319. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13051-4_1"},{"key":"25_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"430","DOI":"10.1007\/978-3-662-46800-5_17","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2015","author":"MR Albrecht","year":"2015","unstructured":"Albrecht, M.R., Rechberger, C., Schneider, T., Tiessen, T., Zohner, M.: Ciphers for MPC and FHE. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9056, pp. 430\u2013454. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46800-5_17"},{"key":"25_CR3","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/978-3-031-07082-2_3","volume-title":"EUROCRYPT 2022","author":"D Amzaleg","year":"2022","unstructured":"Amzaleg, D., Dinur, I.: Refined cryptanalysis of the GPRS ciphers GEA-1 and GEA-2. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT 2022. LNCS, vol. 13277, pp. 57\u201385. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_3"},{"key":"25_CR4","doi-asserted-by":"crossref","unstructured":"Avanzi, R.: The QARMA block cipher family. Almost MDS matrices over rings with zero divisors, nearly symmetric even-mansour constructions with non-involutory central rounds, and search heuristics for low-latency s-boxes. IACR Trans. Symmetric Cryptol. 2017(1), 4\u201344 (2017)","DOI":"10.46586\/tosc.v2017.i1.4-44"},{"key":"25_CR5","doi-asserted-by":"crossref","unstructured":"Bannier, A., Filiol, E.: Partition-based trapdoor ciphers. IntechOpen (2017)","DOI":"10.5772\/intechopen.70420"},{"key":"25_CR6","unstructured":"Beierle, C., Beyne, T., Felke, P., Leander, G.: Constructing and deconstructing intentional weaknesses in symmetric ciphers. Cryptology ePrint Archive, Report 2021\/829 (2021). https:\/\/ia.cr\/2021\/829"},{"key":"25_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"647","DOI":"10.1007\/978-3-319-63715-0_22","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"C Beierle","year":"2017","unstructured":"Beierle, C., Canteaut, A., Leander, G., Rotella, Y.: Proving resistance against invariant attacks: how to choose the round constants. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017. LNCS, vol. 10402, pp. 647\u2013678. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63715-0_22"},{"key":"25_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-030-77886-6_6","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"C Beierle","year":"2021","unstructured":"Beierle, C., et al.: Cryptanalysis of the GPRS encryption algorithms GEA-1 and GEA-2. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021. LNCS, vol. 12697, pp. 155\u2013183. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77886-6_6"},{"key":"25_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/978-3-662-49301-4_17","volume-title":"The New Codebreakers","author":"DJ Bernstein","year":"2016","unstructured":"Bernstein, D.J., Lange, T., Niederhagen, R.: Dual EC: a standardized back door. In: Ryan, P.Y.A., Naccache, D., Quisquater, J.-J. (eds.) The New Codebreakers. LNCS, vol. 9100, pp. 256\u2013281. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-49301-4_17"},{"key":"25_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-03326-2_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"T Beyne","year":"2018","unstructured":"Beyne, T.: Block cipher invariants as eigenvectors of correlation matrices. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11272, pp. 3\u201331. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03326-2_1"},{"key":"25_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/978-3-030-92062-3_2","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"T Beyne","year":"2021","unstructured":"Beyne, T.: A geometric approach to\u00a0linear cryptanalysis. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13090, pp. 36\u201366. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_2"},{"key":"25_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"196","DOI":"10.1007\/978-3-030-34578-5_8","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"X Bonnetain","year":"2019","unstructured":"Bonnetain, X., Perrin, L., Tian, S.: Anomalies and vector space search: tools for S-Box analysis. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019. LNCS, vol. 11921, pp. 196\u2013223. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_8"},{"key":"25_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/978-3-642-34961-4_14","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2012","author":"J Borghoff","year":"2012","unstructured":"Borghoff, J., et al.: PRINCE \u2013 a low-latency block cipher for pervasive computing applications. In: Wang, X., Sako, K. (eds.) ASIACRYPT 2012. LNCS, vol. 7658, pp. 208\u2013225. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34961-4_14"},{"key":"25_CR14","doi-asserted-by":"publisher","unstructured":"Daemen, J., Rijmen, V.: The Design of Rijndael - The Advanced Encryption Standard (AES). Information Security and Cryptography, 2nd edn. Springer, Heidelberg (2020). https:\/\/doi.org\/10.1007\/978-3-662-04722-4","DOI":"10.1007\/978-3-662-04722-4"},{"key":"25_CR15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/978-3-030-10970-7_2","volume-title":"SAC 2018","author":"P Derbez","year":"2018","unstructured":"Derbez, P., Fouque, P., Jean, J., Lambin, B.: Variants of the AES key schedule for better truncated differential bounds. In: Cid, C., Jacobson, M., Jr. (eds.) SAC 2018. LNCS, vol. 11349, pp. 27\u201349. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-10970-7_2"},{"key":"25_CR16","doi-asserted-by":"crossref","unstructured":"Dunkelman, O., Perrin, L.: Adapting rigidity to symmetric cryptography: towards \u201cunswerving\u201d designs. In: Mehrnezhad, M., van der Merwe, T., Hao, F. (eds.) Proceedings of the 5th ACM Workshop on Security Standardisation Research Workshop, pp. 69\u201380. ACM (2019)","DOI":"10.1145\/3338500.3360335"},{"key":"25_CR17","unstructured":"Dworkin, M.: SHA-3 standard: permutation-based hash and extendable-output functions (2015)"},{"key":"25_CR18","unstructured":"Filiol, E.: BSEA-1 - a stream cipher backdooring technique. arXiv preprint arXiv:1903.11063 (2019)"},{"key":"25_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/BFb0052331","volume-title":"Fast Software Encryption","author":"C Harpes","year":"1997","unstructured":"Harpes, C., Massey, J.L.: Partitioning cryptanalysis. In: Biham, E. (ed.) FSE 1997. LNCS, vol. 1267, pp. 13\u201327. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052331"},{"key":"25_CR20","unstructured":"Hoffman, K., Kunze, R.A.: Linear Algebra. PHI Learning (2004)"},{"issue":"2","key":"25_CR21","doi-asserted-by":"publisher","first-page":"59","DOI":"10.46586\/tosc.v2017.i2.59-83","volume":"2017","author":"K Khoo","year":"2017","unstructured":"Khoo, K., Lee, E., Peyrin, T., Sim, S.M.: Human-readable proof of the related-key security of AES-128. IACR Trans. Symmetric Cryptol. 2017(2), 59\u201383 (2017)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"25_CR22","doi-asserted-by":"publisher","unstructured":"Koblitz, N.: Algebraic Aspects of Cryptography, Algorithms and Computation in Mathematics, vol. 3. Springer, New York (1998). https:\/\/doi.org\/10.1007\/978-3-662-03642-6","DOI":"10.1007\/978-3-662-03642-6"},{"key":"25_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1007\/11506447_11","volume-title":"Advanced Encryption Standard \u2013 AES","author":"T Van Le","year":"2005","unstructured":"Van Le, T., Sparr, R., Wernsdorf, R., Desmedt, Y.: Complementation-like and cyclic properties of AES round functions. In: Dobbertin, H., Rijmen, V., Sowa, A. (eds.) AES 2004. LNCS, vol. 3373, pp. 128\u2013141. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11506447_11"},{"key":"25_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/978-3-642-22792-9_12","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"G Leander","year":"2011","unstructured":"Leander, G., Abdelraheem, M.A., AlKhzaimi, H., Zenner, E.: A cryptanalysis of PRINTcipher: the invariant subspace attack. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 206\u2013221. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22792-9_12"},{"key":"25_CR25","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511525926","volume-title":"Finite Fields","author":"R Lidl","year":"1996","unstructured":"Lidl, R., Niederreiter, H.: Finite Fields, 2nd edn. Encyclopedia of Mathematics and its Applications, Cambridge University Press (1996)","edition":"2"},{"key":"25_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1007\/978-3-540-39887-5_19","volume-title":"Fast Software Encryption","author":"S Park","year":"2003","unstructured":"Park, S., Sung, S.H., Lee, S., Lim, J.: Improving the upper bound on the maximum differential and the maximum linear hull probability for SPN structures and AES. In: Johansson, T. (ed.) FSE 2003. LNCS, vol. 2887, pp. 247\u2013260. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-39887-5_19"},{"key":"25_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/3-540-48519-8_15","volume-title":"Fast Software Encryption","author":"KG Paterson","year":"1999","unstructured":"Paterson, K.G.: Imprimitive permutation groups and trapdoors in iterated block ciphers. In: Knudsen, L. (ed.) FSE 1999. LNCS, vol. 1636, pp. 201\u2013214. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48519-8_15"},{"key":"25_CR28","unstructured":"Perlroth, N., Larson, J., Shane, S.: N.S.A. able to foil basic safeguards of privacy on web. International New York Times (2013). https:\/\/www.nytimes.com\/2013\/09\/06\/us\/nsa-foils-much-internet-encryption.html. Accessed 30 Sept 2021"},{"issue":"1","key":"25_CR29","doi-asserted-by":"publisher","first-page":"302","DOI":"10.46586\/tosc.v2019.i1.302-329","volume":"2019","author":"L Perrin","year":"2019","unstructured":"Perrin, L.: Partitions in the s-box of Streebog and Kuznyechik. IACR Trans. Symmetric Cryptol. 2019(1), 302\u2013329 (2019)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"25_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-030-56877-1_9","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"T Peyrin","year":"2020","unstructured":"Peyrin, T., Wang, H.: The MALICIOUS framework: embedding backdoors into tweakable block ciphers. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12172, pp. 249\u2013278. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_9"},{"key":"25_CR31","unstructured":"Posteuca, R., Ashur, T.: How to backdoor a cipher. IACR Cryptol. ePrint Arch, p. 442 (2021)"},{"key":"25_CR32","unstructured":"Fips, P.U.B.: 46: Data Encryption Standard (DES). National Bureau of Standards, US Department of Commerce (1977)"},{"key":"25_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/BFb0052342","volume-title":"Fast Software Encryption","author":"V Rijmen","year":"1997","unstructured":"Rijmen, V., Preneel, B.: A family of trapdoor ciphers. In: Biham, E. (ed.) FSE 1997. LNCS, vol. 1267, pp. 139\u2013148. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052342"},{"key":"25_CR34","unstructured":"Sage Developers: SageMath, the Sage Mathematics Software System (Version 9.3) (2021). https:\/\/www.sagemath.org"},{"key":"25_CR35","unstructured":"Schneier, B.: Applied Cryptography - Protocols, Algorithms, and Source Code in C, 2nd edn. Wiley (1996)"},{"issue":"4","key":"25_CR36","doi-asserted-by":"publisher","first-page":"1383","DOI":"10.1007\/s00145-018-9285-0","volume":"32","author":"Y Todo","year":"2019","unstructured":"Todo, Y., Leander, G., Sasaki, Y.: Nonlinear invariant attack: practical attack on full SCREAM, iSCREAM, and Midori64. J. Cryptol. 32(4), 1383\u20131422 (2019)","journal-title":"J. Cryptol."},{"issue":"4","key":"25_CR37","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1080\/0025570X.1994.11996233","volume":"67","author":"WP Wardlaw","year":"1994","unstructured":"Wardlaw, W.P.: Matrix representation of finite fields. Math. Mag. 67(4), 289\u2013293 (1994)","journal-title":"Math. Mag."},{"issue":"4","key":"25_CR38","doi-asserted-by":"publisher","first-page":"62","DOI":"10.46586\/tosc.v2018.i4.62-79","volume":"2018","author":"Y Wei","year":"2018","unstructured":"Wei, Y., Ye, T., Wu, W., Pasalic, E.: Generalized nonlinear invariant attack and a new design criterion for round constants. IACR Trans. Symmetric Cryptol. 2018(4), 62\u201379 (2018)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"25_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1007\/3-540-49649-1_11","volume-title":"Advances in Cryptology \u2014 ASIACRYPT\u201998","author":"H Wu","year":"1998","unstructured":"Wu, H., Bao, F., Deng, R.H., Ye, Q.-Z.: Cryptanalysis of Rijmen-Preneel trapdoor ciphers. In: Ohta, K., Pei, D. (eds.) ASIACRYPT 1998. LNCS, vol. 1514, pp. 126\u2013132. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/3-540-49649-1_11"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-15982-4_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:06:38Z","timestamp":1760133998000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-15982-4_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031159817","9783031159824"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-15982-4_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"12 October 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"42","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}