{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T13:07:44Z","timestamp":1765976864501,"version":"3.44.0"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032019004","type":"print"},{"value":"9783032019011","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-01901-1_8","type":"book-chapter","created":{"date-parts":[[2025,8,16]],"date-time":"2025-08-16T08:44:51Z","timestamp":1755333891000},"page":"230-259","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["How to\u00a0Recover the\u00a0Full Plaintext of\u00a0XCB"],"prefix":"10.1007","author":[{"given":"Peng","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuping","family":"Mao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruozhou","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,17]]},"reference":[{"key":"8_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-63697-9_1","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"T Ashur","year":"2017","unstructured":"Ashur, T., Dunkelman, O., Luykx, A.: Boosting authenticated encryption robustness with minimal modifications. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017, Part III. LNCS, vol. 10403, pp. 3\u201333. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63697-9_1"},{"key":"8_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"641","DOI":"10.1007\/978-3-030-45724-2_22","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"Z Bao","year":"2020","unstructured":"Bao, Z., Guo, C., Guo, J., Song, L.: TNT: how to tweak a block cipher. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12106, pp. 641\u2013673. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45724-2_22"},{"key":"8_CR3","unstructured":"Bhati, A.S., Verbauwhede, M., Andreeva, E.: Breaking, repairing and enhancing XCBv2 into the tweakable enciphering mode GEM. Cryptology ePrint Archive, Paper 2024\/1554 (2024). https:\/\/eprint.iacr.org\/2024\/1554"},{"key":"8_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-662-48800-3_7","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"R Bhaumik","year":"2015","unstructured":"Bhaumik, R., Nandi, M.: An inverse-free single-keyed tweakable enciphering scheme. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015, Part II. LNCS, vol. 9453, pp. 159\u2013180. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48800-3_7"},{"issue":"4","key":"8_CR5","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1007\/S12095-015-0127-8","volume":"7","author":"D Chakraborty","year":"2015","unstructured":"Chakraborty, D., Hernandez-Jimenez, V., Sarkar, P.: Another look at XCB. Cryptogr. Commun. 7(4), 439\u2013468 (2015). https:\/\/doi.org\/10.1007\/S12095-015-0127-8","journal-title":"Cryptogr. Commun."},{"key":"8_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/11799313_19","volume-title":"Fast Software Encryption","author":"D Chakraborty","year":"2006","unstructured":"Chakraborty, D., Sarkar, P.: A new mode of encryption providing a tweakable strong pseudo-random permutation. In: Robshaw, M. (ed.) FSE 2006. LNCS, vol. 4047, pp. 293\u2013309. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11799313_19"},{"issue":"4","key":"8_CR7","doi-asserted-by":"publisher","first-page":"1683","DOI":"10.1109\/TIT.2008.917623","volume":"54","author":"D Chakraborty","year":"2008","unstructured":"Chakraborty, D., Sarkar, P.: HCH: a new tweakable enciphering scheme using the hash-counter-hash approach. IEEE Trans. Inf. Theory 54(4), 1683\u20131699 (2008). https:\/\/doi.org\/10.1109\/TIT.2008.917623","journal-title":"IEEE Trans. Inf. Theory"},{"key":"8_CR8","unstructured":"Chen, Y.L., et al.: Proposal of requirements for an Accordion mode: discussion draft for the NIST Accordion mode workshop 2024 (2024)"},{"key":"8_CR9","doi-asserted-by":"publisher","unstructured":"Crowley, P., Biggers, E.: Adiantum: length-preserving encryption for entry-level processors. IACR Trans. Symmetric Cryptol. 2018(4), 39\u201361 (2018). https:\/\/doi.org\/10.13154\/TOSC.V2018.I4.39-61","DOI":"10.13154\/TOSC.V2018.I4.39-61"},{"key":"8_CR10","unstructured":"Crowley, P., Huckleberry, N., Biggers, E.: Length-preserving encryption with HCTR2. IACR Cryptol. ePrint Arch. p.\u00a01441 (2021). https:\/\/eprint.iacr.org\/2021\/1441"},{"key":"8_CR11","unstructured":"Datta, N., Dutta, A., Ghosh, S., Nandi, H.: Optimally secure TBC based accordion mode. IACR Cryptol. ePrint Arch. p.\u00a02053 (2024). https:\/\/eprint.iacr.org\/2024\/2053"},{"key":"8_CR12","unstructured":"Dobraunig, C., Matusiewicz, K., Mennink, B., Tereschenko, A.: Efficient instances of docked double decker with AES. IACR Cryptol. ePrint Arch. p.\u00a084 (2024). https:\/\/eprint.iacr.org\/2024\/084"},{"key":"8_CR13","unstructured":"Fleischmann, E., Forler, C., Lucks, S., Wenzel, J.: McOE: a family of almost foolproof on-line authenticated encryption schemes. Cryptology ePrint Archive, Paper 2011\/644 (2011). https:\/\/eprint.iacr.org\/2011\/644"},{"key":"8_CR14","unstructured":"Gueron, S., Langley, A., Lindell, Y.: AES-GCM-SIV: specification and analysis. IACR Cryptol. ePrint Arch. p.\u00a0168 (2017). http:\/\/eprint.iacr.org\/2017\/168"},{"key":"8_CR15","doi-asserted-by":"publisher","unstructured":"Gunsing, A., Daemen, J., Mennink, B.: Deck-based wide block cipher modes and an exposition of the blinded keyed hashing model. IACR Trans. Symmetric Cryptol. 2019(4), 1\u201322 (2019). https:\/\/doi.org\/10.13154\/TOSC.V2019.I4.1-22","DOI":"10.13154\/TOSC.V2019.I4.1-22"},{"key":"8_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/978-3-540-30556-9_25","volume-title":"Progress in Cryptology - INDOCRYPT 2004","author":"S Halevi","year":"2004","unstructured":"Halevi, S.: EME*: extending EME to handle arbitrary-length messages with associated data. In: Canteaut, A., Viswanathan, K. (eds.) INDOCRYPT 2004. LNCS, vol. 3348, pp. 315\u2013327. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30556-9_25"},{"key":"8_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1007\/978-3-540-74143-5_23","volume-title":"Advances in Cryptology - CRYPTO 2007","author":"S Halevi","year":"2007","unstructured":"Halevi, S.: Invertible universal hashing and the TET encryption mode. In: Menezes, A. (ed.) CRYPTO 2007. LNCS, vol. 4622, pp. 412\u2013429. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74143-5_23"},{"key":"8_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"482","DOI":"10.1007\/978-3-540-45146-4_28","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"S Halevi","year":"2003","unstructured":"Halevi, S., Rogaway, P.: A tweakable enciphering mode. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 482\u2013499. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_28"},{"key":"8_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/978-3-540-24660-2_23","volume-title":"Topics in Cryptology \u2013 CT-RSA 2004","author":"S Halevi","year":"2004","unstructured":"Halevi, S., Rogaway, P.: A parallelizable enciphering mode. In: Okamoto, T. (ed.) CT-RSA 2004. LNCS, vol. 2964, pp. 292\u2013304. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24660-2_23"},{"key":"8_CR20","unstructured":"IEEE 1619.2: IEEE standard for wide-block encryption for shared storage media (2011)"},{"key":"8_CR21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-031-58716-0_9","volume-title":"EUROCRYPT 2024, Part I","author":"A Jha","year":"2024","unstructured":"Jha, A., Khairallah, M., Nandi, M., Saha, A.: Tight security of TNT and beyond - attacks, proofs and possibilities for the cascaded LRW paradigm. In: Joye, M., Leander, G. (eds.) EUROCRYPT 2024, Part I. LNCS, vol. 14651, pp. 249\u2013279. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58716-0_9"},{"key":"8_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1007\/978-3-642-32009-5_2","volume-title":"Advances in Cryptology \u2013 CRYPTO 2012","author":"W Landecker","year":"2012","unstructured":"Landecker, W., Shrimpton, T., Terashima, R.S.: Tweakable blockciphers with beyond birthday-bound security. In: Safavi-Naini, R., Canetti, R. (eds.) CRYPTO 2012. LNCS, vol. 7417, pp. 14\u201330. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-32009-5_2"},{"key":"8_CR23","unstructured":"Lee, B.: A BBB secure accordion mode from hctr. NIST Workshop on the Requirements for an Accordion Cipher Mode (2024)"},{"key":"8_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/3-540-45708-9_3","volume-title":"Advances in Cryptology \u2014 CRYPTO 2002","author":"M Liskov","year":"2002","unstructured":"Liskov, M., Rivest, R.L., Wagner, D.: Tweakable block ciphers. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol. 2442, pp. 31\u201346. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45708-9_3"},{"key":"8_CR25","unstructured":"McGrew, D.A., Fluhrer, S.R.: The extended codebook (XCB) mode of operation. IACR Cryptol. ePrint Arch. p.\u00a0278 (2004). http:\/\/eprint.iacr.org\/2004\/278"},{"key":"8_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/978-3-540-77360-3_20","volume-title":"Selected Areas in Cryptography","author":"DA McGrew","year":"2007","unstructured":"McGrew, D.A., Fluhrer, S.R.: The security of the extended codebook (XCB) mode of operation. In: Adams, C., Miri, A., Wiener, M. (eds.) SAC 2007. LNCS, vol. 4876, pp. 311\u2013327. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-77360-3_20"},{"key":"8_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/978-3-540-30556-9_27","volume-title":"Progress in Cryptology - INDOCRYPT 2004","author":"DA McGrew","year":"2004","unstructured":"McGrew, D.A., Viega, J.: The security and performance of the Galois\/counter mode (GCM) of operation. In: Canteaut, A., Viswanathan, K. (eds.) INDOCRYPT 2004. LNCS, vol. 3348, pp. 343\u2013355. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30556-9_27"},{"key":"8_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-540-77026-8_19","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2007","author":"K Minematsu","year":"2007","unstructured":"Minematsu, K., Matsushima, T.: Tweakable enciphering schemes from hash-sum-expansion. In: Srinathan, K., Rangan, C.P., Yung, M. (eds.) INDOCRYPT 2007. LNCS, vol. 4859, pp. 252\u2013267. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-77026-8_19"},{"key":"8_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/978-3-642-55220-5_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2014","author":"C Namprempre","year":"2014","unstructured":"Namprempre, C., Rogaway, P., Shrimpton, T.: Reconsidering generic composition. In: Nguyen, P.Q., Oswald, E. (eds.) EUROCRYPT 2014. LNCS, vol. 8441, pp. 257\u2013274. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-642-55220-5_15"},{"key":"8_CR30","unstructured":"Nandi, M.: An efficient SPRP-secure construction based on pseudo random involution. IACR Cryptol. ePrint Arch. p.\u00a092 (2008). http:\/\/eprint.iacr.org\/2008\/092"},{"key":"8_CR31","doi-asserted-by":"publisher","unstructured":"Nir, Y., Langley, A.: Chacha20 and poly1305 for IETF protocols. RFC 7539, 1\u201345 (2015). https:\/\/doi.org\/10.17487\/RFC7539","DOI":"10.17487\/RFC7539"},{"key":"8_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"517","DOI":"10.1007\/978-3-540-72540-4_30","volume-title":"Advances in Cryptology - EUROCRYPT 2007","author":"K Pietrzak","year":"2007","unstructured":"Pietrzak, K., Sj\u00f6din, J.: Range extension for weak PRFs; the good, the bad, and the ugly. In: Naor, M. (ed.) EUROCRYPT 2007. LNCS, vol. 4515, pp. 517\u2013533. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-72540-4_30"},{"key":"8_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1007\/978-3-540-76788-6_15","volume-title":"Information Security and Cryptology - ICISC 2007","author":"P Sarkar","year":"2007","unstructured":"Sarkar, P.: Improving upon the TET mode of operation. In: Nam, K.-H., Rhee, G. (eds.) ICISC 2007. LNCS, vol. 4817, pp. 180\u2013192. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-76788-6_15"},{"key":"8_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-3-642-42033-7_21","volume-title":"Advances in Cryptology - ASIACRYPT 2013","author":"T Shrimpton","year":"2013","unstructured":"Shrimpton, T., Terashima, R.S.: A modular framework for building variable-input-length tweakable ciphers. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013, Part I. LNCS, vol. 8269, pp. 405\u2013423. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-42033-7_21"},{"key":"8_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1007\/11599548_15","volume-title":"Information Security and Cryptology","author":"P Wang","year":"2005","unstructured":"Wang, P., Feng, D., Wu, W.: HCTR: a variable-input-length enciphering mode. In: Feng, D., Lin, D., Yung, M. (eds.) CISC 2005. LNCS, vol. 3822, pp. 175\u2013188. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11599548_15"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-01901-1_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,16]],"date-time":"2025-08-16T08:44:54Z","timestamp":1755333894000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-01901-1_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032019004","9783032019011"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-01901-1_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"17 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}