{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T21:03:51Z","timestamp":1757624631167,"version":"3.44.0"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783032019004"},{"type":"electronic","value":"9783032019011"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-01901-1_5","type":"book-chapter","created":{"date-parts":[[2025,8,16]],"date-time":"2025-08-16T08:44:50Z","timestamp":1755333890000},"page":"139-171","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Guess-and-Determine Rebound: Applications to\u00a0Key Collisions on\u00a0AES"],"prefix":"10.1007","author":[{"given":"Lingyue","family":"Qin","sequence":"first","affiliation":[]},{"given":"Wenquan","family":"Bi","sequence":"additional","affiliation":[]},{"given":"Xiaoyang","family":"Dong","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,8,17]]},"reference":[{"key":"5_CR1","unstructured":"Albertini, A., Duong, T., Gueron, S., K\u00f6lbl, S., Luykx, A., Schmieg, S.: How to abuse and fix authenticated encryption without key commitment. In: Kevin, R.B.B., Thomas, K. (eds.) 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022, pp. 3291\u20133308. USENIX Association (2022)"},{"key":"5_CR2","first-page":"105","volume":"9","author":"DJ Bernstein","year":"2009","unstructured":"Bernstein, D.J.: Cost analysis of hash collisions: will quantum computers make SHARCS obsolete. SHARCS 9, 105 (2009)","journal-title":"SHARCS"},{"key":"5_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1007\/978-3-642-13190-5_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2010","author":"A Biryukov","year":"2010","unstructured":"Biryukov, A., Dunkelman, O., Keller, N., Khovratovich, D., Shamir, A.: Key recovery attacks of practical complexity on AES-256 variants with up to 10 rounds. In: Gilbert, H. (ed.) EUROCRYPT 2010. LNCS, vol. 6110, pp. 299\u2013319. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13190-5_15"},{"key":"5_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"552","DOI":"10.1007\/978-3-030-34578-5_20","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"X Bonnetain","year":"2019","unstructured":"Bonnetain, X., Hosoyamada, A., Naya-Plasencia, M., Sasaki, Yu., Schrottenloher, A.: Quantum attacks without superposition queries: the offline Simon\u2019s algorithm. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019, Part I. LNCS, vol. 11921, pp. 552\u2013583. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_20"},{"key":"5_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-642-22792-9_10","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"C Bouillaguet","year":"2011","unstructured":"Bouillaguet, C., Derbez, P., Fouque, P.-A.: Automatic search of attacks on round-reduced AES and applications. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 169\u2013187. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22792-9_10"},{"key":"5_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/978-3-319-70697-9_8","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"A Chailloux","year":"2017","unstructured":"Chailloux, A., Naya-Plasencia, M., Schrottenloher, A.: An Efficient quantum collision search algorithm and implications on symmetric cryptography. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017, Part II. LNCS, vol. 10625, pp. 211\u2013240. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_8"},{"issue":"4","key":"5_CR7","doi-asserted-by":"publisher","first-page":"64","DOI":"10.46586\/tosc.v2024.i4.64-96","volume":"2024","author":"S Chen","year":"2024","unstructured":"Chen, S., Dong, X., Guo, J., Zhang, T.: Chosen-prefix collisions on AES-like hashing. IACR Trans. Symmetric Cryptol. 2024(4), 64\u201396 (2024)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Chen, Y.L., et al.: Key committing security of AEZ and more. IACR Trans. Symmetric Cryptol. 2023(4), 452\u2013488 (2023)","DOI":"10.46586\/tosc.v2023.i4.452-488"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/11832072_6","volume-title":"Security and Cryptography for Networks","author":"J Daemen","year":"2006","unstructured":"Daemen, J., Rijmen, V.: Understanding two-round differentials in AES. In: De Prisco, R., Yung, M. (eds.) SCN 2006. LNCS, vol. 4116, pp. 78\u201394. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11832072_6"},{"key":"5_CR10","series-title":"Information Security and Cryptography","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael: AES - The Advanced Encryption Standard","author":"J Daemen","year":"2002","unstructured":"Daemen, J., Rijmen, V.: The Design of Rijndael: AES - The Advanced Encryption Standard. Information Security and Cryptography, Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/978-3-662-04722-4"},{"issue":"1","key":"5_CR11","doi-asserted-by":"publisher","first-page":"135","DOI":"10.46586\/tosc.v2024.i1.135-157","volume":"2024","author":"P Derbez","year":"2024","unstructured":"Derbez, P., Fouque, P.-A., Isobe, T., Rahman, M., Schrottenloher, A.: Key committing attacks against AES-based AEAD schemes. IACR Trans. Symmetric Cryptol. 2024(1), 135\u2013157 (2024)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"5_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56877-1_13","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"P Derbez","year":"2020","unstructured":"Derbez, P., Huynh, P., Lallemand, V., Naya-Plasencia, M., Perrin, L., Schrottenloher, A.: Cryptanalysis results on spook. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part III. LNCS, vol. 12172, pp. 359\u2013388. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_13"},{"key":"5_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"719","DOI":"10.1007\/978-3-642-32009-5_42","volume-title":"Advances in Cryptology \u2013 CRYPTO 2012","author":"I Dinur","year":"2012","unstructured":"Dinur, I., Dunkelman, O., Keller, N., Shamir, A.: Efficient dissection of composite problems, with applications to cryptanalysis, knapsacks, and combinatorial search problems. In: Safavi-Naini, R., Canetti, R. (eds.) CRYPTO 2012. LNCS, vol. 7417, pp. 719\u2013740. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-32009-5_42"},{"key":"5_CR14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/978-3-031-15802-5_4","volume-title":"CRYPTO 2022, Part I","author":"X Dong","year":"2022","unstructured":"Dong, X., Guo, J., Li, S., Pham, P.: Triangulating rebound attack on AES-like hashing. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022, Part I. LNCS, vol. 13507, pp. 94\u2013124. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15802-5_4"},{"key":"5_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"727","DOI":"10.1007\/978-3-030-64834-3_25","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"X Dong","year":"2020","unstructured":"Dong, X., Sun, S., Shi, D., Gao, F., Wang, X., Hu, L.: Quantum collision attacks on AES-like hashing with low quantum random access memories. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 727\u2013757. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_25"},{"key":"5_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-030-92062-3_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"X Dong","year":"2021","unstructured":"Dong, X., Zhang, Z., Sun, S., Wei, C., Wang, X., Hu, L.: Automatic classical and quantum rebound attacks on AES-like hashing by exploiting related-key differentials. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021, Part I. LNCS, vol. 13090, pp. 241\u2013271. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_9"},{"key":"5_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1007\/978-3-642-34047-5_23","volume-title":"Fast Software Encryption","author":"A Duc","year":"2012","unstructured":"Duc, A., Guo, J., Peyrin, T., Wei, L.: Unaligned rebound attack: application to Keccak. In: Canteaut, A. (ed.) FSE 2012. LNCS, vol. 7549, pp. 402\u2013421. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34047-5_23"},{"issue":"1","key":"5_CR18","doi-asserted-by":"publisher","first-page":"449","DOI":"10.46586\/tosc.v2017.i1.449-473","volume":"2017","author":"P Farshim","year":"2017","unstructured":"Farshim, P., Orlandi, C., Rosie, R.: Security of symmetric primitives under incorrect usage of keys. IACR Trans. Symmetric Cryptol. 2017(1), 449\u2013473 (2017)","journal-title":"IACR Trans. Symmetric Cryptol."},{"issue":"4","key":"5_CR19","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/s00145-021-09413-z","volume":"34","author":"A Fl\u00f3rez-Guti\u00e9rrez","year":"2021","unstructured":"Fl\u00f3rez-Guti\u00e9rrez, A., Leurent, G., Naya-Plasencia, M., Perrin, L., Schrottenloher, A., Sibleyras, F.: Internal symmetries and linear properties: Full-permutation distinguishers and improved collisions on Gimli. J. Cryptol. 34(4), 45 (2021)","journal-title":"J. Cryptol."},{"key":"5_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1007\/978-3-642-40041-4_11","volume-title":"Advances in Cryptology \u2013 CRYPTO 2013","author":"P-A Fouque","year":"2013","unstructured":"Fouque, P.-A., Jean, J., Peyrin, T.: Structural evaluation of AES and chosen-key distinguisher of 9-round AES-128. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013, Part I. LNCS, vol. 8042, pp. 183\u2013203. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40041-4_11"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"G\u00e9rault, D., Lafourcade, P., Minier, M., Solnon, C.: Computing AES related-key differential characteristics with constraint programming. Artif. Intell. 278 (2020)","DOI":"10.1016\/j.artint.2019.103183"},{"key":"5_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1007\/978-3-642-13858-4_21","volume-title":"Fast Software Encryption","author":"H Gilbert","year":"2010","unstructured":"Gilbert, H., Peyrin, T.: Super-Sbox cryptanalysis: improved attacks for AES-like permutations. In: Hong, S., Iwata, T. (eds.) FSE 2010. LNCS, vol. 6147, pp. 365\u2013383. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13858-4_21"},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: Proceedings of the Twenty-Eighth Annual ACM Symposium on the Theory of Computing, Philadelphia, Pennsylvania, USA, May 22\u201324, 1996, pp. 212\u2013219 (1996)","DOI":"10.1145\/237814.237866"},{"key":"5_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-030-45724-2_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"A Hosoyamada","year":"2020","unstructured":"Hosoyamada, A., Sasaki, Yu.: Finding hash collisions with quantum computers by using differential trails with smaller probability than birthday bound. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part II. LNCS, vol. 12106, pp. 249\u2013279. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_9"},{"key":"5_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"616","DOI":"10.1007\/978-3-030-84242-0_22","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"A Hosoyamada","year":"2021","unstructured":"Hosoyamada, A., Sasaki, Yu.: Quantum collision attacks on reduced SHA-256 and SHA-512. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12825, pp. 616\u2013646. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_22"},{"key":"5_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1007\/978-3-642-34047-5_7","volume-title":"Fast Software Encryption","author":"J Jean","year":"2012","unstructured":"Jean, J., Naya-Plasencia, M., Peyrin, T.: Improved rebound attack on the finalist Gr\u00f8stl. In: Canteaut, A. (ed.) FSE 2012. LNCS, vol. 7549, pp. 110\u2013126. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34047-5_7"},{"key":"5_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1007\/978-3-662-43414-7_27","volume-title":"Selected Areas in Cryptography \u2013 SAC 2013","author":"J Jean","year":"2014","unstructured":"Jean, J., Naya-Plasencia, M., Peyrin, T.: Multiple limited-birthday distinguishers and applications. In: Lange, T., Lauter, K., Lison\u011bk, P. (eds.) SAC 2013. LNCS, vol. 8282, pp. 533\u2013550. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43414-7_27"},{"key":"5_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-662-53008-5_8","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"M Kaplan","year":"2016","unstructured":"Kaplan, M., Leurent, G., Leverrier, A., Naya-Plasencia, M.: Breaking symmetric cryptosystems using\u00a0quantum\u00a0period finding. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016, Part II. LNCS, vol. 9815, pp. 207\u2013237. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53008-5_8"},{"key":"5_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/978-3-642-00862-7_11","volume-title":"Topics in Cryptology \u2013 CT-RSA 2009","author":"D Khovratovich","year":"2009","unstructured":"Khovratovich, D., Biryukov, A., Nikolic, I.: Speeding up collision search for byte-oriented hash functions. In: Fischlin, M. (ed.) CT-RSA 2009. LNCS, vol. 5473, pp. 164\u2013181. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-00862-7_11"},{"issue":"3","key":"5_CR30","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1007\/s00145-013-9150-0","volume":"27","author":"D Khovratovich","year":"2014","unstructured":"Khovratovich, D., Nikolic, I., Rechberger, C.: Rotational rebound attacks on reduced Skein. J. Cryptol. 27(3), 452\u2013479 (2014)","journal-title":"J. Cryptol."},{"key":"5_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1007\/978-3-642-10366-7_8","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2009","author":"M Lamberger","year":"2009","unstructured":"Lamberger, M., Mendel, F., Rechberger, C., Rijmen, V., Schl\u00e4ffer, M.: Rebound distinguishers: results on the full whirlpool compression function. In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol. 5912, pp. 126\u2013143. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-10366-7_8"},{"key":"5_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/978-3-319-70697-9_6","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"G Leander","year":"2017","unstructured":"Leander, G., May, A.: Grover meets Simon \u2013 quantumly attacking the FX-construction. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017, Part II. LNCS, vol. 10625, pp. 161\u2013178. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_6"},{"key":"5_CR33","doi-asserted-by":"publisher","unstructured":"Matusiewicz, K., Naya-Plasencia, M., Nikoli\u0107, I., Sasaki, Yu., Schl\u00e4ffer, M.: Rebound attack on the full Lane compression function. In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol. 5912, pp. 106\u2013125. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-10366-7_7","DOI":"10.1007\/978-3-642-10366-7_7"},{"key":"5_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"260","DOI":"10.1007\/978-3-642-03317-9_16","volume-title":"Fast Software Encryption","author":"F Mendel","year":"2009","unstructured":"Mendel, F., Rechberger, C., Schl\u00e4ffer, M., Thomsen, S.S.: The rebound attack: cryptanalysis of reduced whirlpool and Gr\u00f8stl. In: Dunkelman, O. (ed.) FSE 2009. LNCS, vol. 5665, pp. 260\u2013276. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03317-9_16"},{"key":"5_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"509","DOI":"10.1007\/978-3-662-46706-0_26","volume-title":"Fast Software Encryption","author":"F Mendel","year":"2015","unstructured":"Mendel, F., Rijmen, V., Schl\u00e4ffer, M.: Collision attack on 5 rounds of Gr\u00f8stl. In: Cid, C., Rechberger, C. (eds.) FSE 2014. LNCS, vol. 8540, pp. 509\u2013521. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46706-0_26"},{"issue":"1","key":"5_CR36","first-page":"67","volume":"2023","author":"M Nageler","year":"2023","unstructured":"Nageler, M., Pallua, F., Eichlseder, M.: Finding collisions for round-reduced Romulus-h. IACR Trans. Symmetric Cryptol. 2023(1), 67\u201388 (2023)","journal-title":"IACR Trans. Symmetric Cryptol."},{"issue":"4","key":"5_CR37","doi-asserted-by":"publisher","first-page":"420","DOI":"10.46586\/tosc.v2023.i4.420-451","volume":"2023","author":"Y Naito","year":"2023","unstructured":"Naito, Y., Sasaki, Y., Sugawara, T.: Committing security of ASCON: cryptanalysis on primitive and proof on mode. IACR Trans. Symmetric Cryptol. 2023(4), 420\u2013451 (2023)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"5_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-642-22792-9_11","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"M Naya-Plasencia","year":"2011","unstructured":"Naya-Plasencia, M.: How to improve rebound attacks. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 188\u2013205. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22792-9_11"},{"key":"5_CR39","unstructured":"Ni, j., Li, y., Liu, f., Wang, G.: Practical key collision on AES and Kiasu-bc. IACR Cryptol. ePrint Arch. 462 (2025)"},{"key":"5_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1007\/978-3-642-21702-9_22","volume-title":"Fast Software Encryption","author":"Yu Sasaki","year":"2011","unstructured":"Sasaki, Yu.: Meet-in-the-middle preimage attacks on AES hashing modes and an application to whirlpool. In: Joux, A. (ed.) FSE 2011. LNCS, vol. 6733, pp. 378\u2013396. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-21702-9_22"},{"key":"5_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1007\/978-3-642-17373-8_3","volume-title":"Advances in Cryptology - ASIACRYPT 2010","author":"Yu Sasaki","year":"2010","unstructured":"Sasaki, Yu., Li, Y., Wang, L., Sakiyama, K., Ohta, K.: Non-full-active super-Sbox analysis: applications to ECHO and Gr\u00f8stl. In: Abe, M. (ed.) ASIACRYPT 2010. LNCS, vol. 6477, pp. 38\u201355. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-17373-8_3"},{"key":"5_CR42","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"258","DOI":"10.1007\/978-3-031-38554-4_9","volume-title":"CRYPTO 2023, Part V","author":"A Schrottenloher","year":"2023","unstructured":"Schrottenloher, A.: Quantum linear key-recovery attacks using the QFT. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part V. LNCS, vol. 14085, pp. 258\u2013291. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38554-4_9"},{"key":"5_CR43","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-981-96-0941-3_9","volume-title":"ASIACRYPT, Part VII","author":"K Taiyama","year":"2024","unstructured":"Taiyama, K., Sakamoto, K., Ito, R., Taka, K., Isobe, T.: Key collisions on AES and its applications. In: Chung, K.-M., Sasaki, Yu. (eds.) ASIACRYPT, Part VII. LNCS, vol. 15490, pp. 267\u2013300. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-981-96-0941-3_9"},{"key":"5_CR44","doi-asserted-by":"crossref","unstructured":"Taiyama, K., Sakamoto, K., Ito, R., Taka, K., Isobe, T.: Key collisions on AES and its applications. IACR Cryptol. ePrint Arch. pp. 1508 (2024)","DOI":"10.1007\/978-981-96-0941-3_9"},{"issue":"2","key":"5_CR45","doi-asserted-by":"publisher","first-page":"85","DOI":"10.46586\/tosc.v2024.i2.85-117","volume":"2024","author":"R Takeuchi","year":"2024","unstructured":"Takeuchi, R., Todo, Y., Iwata, T.: Key recovery, universal forgery, and committing attacks against revised ROCCA: how finalization affects security. IACR Trans. Symmetric Cryptol. 2024(2), 85\u2013117 (2024)","journal-title":"IACR Trans. Symmetric Cryptol."},{"issue":"1","key":"5_CR46","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/PL00003816","volume":"12","author":"PC van Oorschot","year":"1999","unstructured":"van Oorschot, P.C., Wiener, M.J.: Parallel collision search with cryptanalytic applications. J. Cryptol. 12(1), 1\u201328 (1999)","journal-title":"J. Cryptol."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-01901-1_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,9]],"date-time":"2025-09-09T14:57:36Z","timestamp":1757429856000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-01901-1_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032019004","9783032019011"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-01901-1_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"17 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}