{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T23:12:39Z","timestamp":1778022759054,"version":"3.51.4"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032253323","type":"print"},{"value":"9783032253330","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-25333-0_9","type":"book-chapter","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T22:45:14Z","timestamp":1778021114000},"page":"243-272","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Algorithmic Toolkit for\u00a0Linearization of\u00a0S-Boxes"],"prefix":"10.1007","author":[{"given":"Alex","family":"Biryukov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Philip","family":"Ture\u010dek","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aleksei","family":"Udovenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,6]]},"reference":[{"key":"9_CR1","doi-asserted-by":"publisher","unstructured":"Banik, S., Barooti, K., Durak, F.B., Vaudenay, S.: Cryptanalysis of LowMC instances using single plaintext\/ciphertext pair. IACR Trans. Symm. Cryptol. 2020(4), 130\u2013146 (2020). https:\/\/doi.org\/10.46586\/tosc.v2020.i4.130-146","DOI":"10.46586\/tosc.v2020.i4.130-146"},{"key":"9_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-662-48800-3_17","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"S Banik","year":"2015","unstructured":"Banik, S., et al.: Midori: a block cipher for low energy. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015. LNCS, vol. 9453, pp. 411\u2013436. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48800-3_17"},{"key":"9_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1007\/978-3-030-75245-3_11","volume-title":"Public-Key Cryptography \u2013 PKC 2021","author":"C Baum","year":"2021","unstructured":"Baum, C., de Saint Guilhem, C.D., Kales, D., Orsini, E., Scholl, P., Zaverucha, G.: Banquet: short and fast signatures from AES. In: Garay, J.A. (ed.) PKC 2021. LNCS, vol. 12710, pp. 266\u2013297. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-75245-3_11"},{"key":"9_CR4","unstructured":"Beierle, C., et al.: Schwaemm and ESCH: lightweight authenticated encryption and hashing using the Sparkle permutation family. NIST Round 2 (2019), version 1.1"},{"key":"9_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/978-3-662-53008-5_5","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"C Beierle","year":"2016","unstructured":"Beierle, C., et al.: The SKINNY family of block ciphers and its low-latency variant MANTIS. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016. LNCS, vol. 9815, pp. 123\u2013153. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53008-5_5"},{"issue":"1","key":"9_CR6","doi-asserted-by":"publisher","first-page":"670","DOI":"10.1109\/TIT.2021.3120698","volume":"68","author":"C Beierle","year":"2022","unstructured":"Beierle, C., Leander, G.: New instances of quadratic APN functions. IEEE Trans. Inf. Theory 68(1), 670\u2013678 (2022). https:\/\/doi.org\/10.1109\/TIT.2021.3120698","journal-title":"IEEE Trans. Inf. Theory"},{"key":"9_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/3-540-38424-3_1","volume-title":"Advances in Cryptology-CRYPT0\u2019 90","author":"E Biham","year":"1991","unstructured":"Biham, E., Shamir, A.: Differential cryptanalysis of DES-like cryptosystems. In: Menezes, A.J., Vanstone, S.A. (eds.) CRYPTO 1990. LNCS, vol. 537, pp. 2\u201321. Springer, Heidelberg (1991). https:\/\/doi.org\/10.1007\/3-540-38424-3_1"},{"key":"9_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/978-3-662-47989-6_6","volume-title":"Advances in Cryptology \u2013 CRYPTO 2015","author":"A Biryukov","year":"2015","unstructured":"Biryukov, A., Perrin, L.: On reverse-engineering S-boxes with hidden design criteria or structure. In: Gennaro, R., Robshaw, M. (eds.) CRYPTO 2015. LNCS, vol. 9215, pp. 116\u2013140. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-47989-6_6"},{"key":"9_CR9","doi-asserted-by":"publisher","unstructured":"Biryukov, A., Ture\u010dek, P., Udovenko, A.: Algorithmic toolkit for linearization of S-boxes - Supporting code (2026). https:\/\/doi.org\/10.5281\/zenodo.18715466","DOI":"10.5281\/zenodo.18715466"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Bouvier, C., et al.: Skyscraper: Fast hashing on big primes. Cryptology ePrint Archive, Report 2025\/058 (2025). https:\/\/eprint.iacr.org\/2025\/058","DOI":"10.46586\/tches.v2025.i2.743-780"},{"issue":"1\u20133","key":"9_CR11","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/s10623-008-9194-6","volume":"49","author":"M Brinkmann","year":"2008","unstructured":"Brinkmann, M., Leander, G.: On the classification of APN functions up to dimension five. DCC 49(1\u20133), 273\u2013288 (2008). https:\/\/doi.org\/10.1007\/s10623-008-9194-6","journal-title":"DCC"},{"issue":"12","key":"9_CR12","doi-asserted-by":"publisher","first-page":"8325","DOI":"10.1109\/TIT.2021.3114958","volume":"67","author":"C Carlet","year":"2021","unstructured":"Carlet, C.: Bounds on the nonlinearity of differentially uniform functions by means of their image set size, and on their distance to affine functions. IEEE Trans. Inf. Theory 67(12), 8325\u20138334 (2021). https:\/\/doi.org\/10.1109\/TIT.2021.3114958","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"2","key":"9_CR13","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/s00145-025-09538-5","volume":"38","author":"C Carlet","year":"2025","unstructured":"Carlet, C.: Two generalizations of almost perfect nonlinearity. J. Cryptol. 38(2), 20 (2025). https:\/\/doi.org\/10.1007\/s00145-025-09538-5","journal-title":"J. Cryptol."},{"issue":"2","key":"9_CR14","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1023\/A:1008344232130","volume":"15","author":"C Carlet","year":"1998","unstructured":"Carlet, C., Charpin, P., Zinoviev, V.A.: Codes, bent functions and permutations suitable for DES-like cryptosystems. DCC 15(2), 125\u2013156 (1998). https:\/\/doi.org\/10.1023\/A:1008344232130","journal-title":"DCC"},{"key":"9_CR15","unstructured":"Chen, L., Fu, F.: On the nonlinearity of multi-output boolean functions. Acta Scientificiarum Naturalium University Nankaiensis 34(4), 28\u201333 (2001). https:\/\/www.alljournals.cn\/view_abstract.aspx?pcid=01BA20E8BA813E1908F3698710BBFEFEE816345F465FEBA5&cid=96E6E851B5104576C2DD9FC1FBCB69EF&jid=2F663905325EBF0C8638CFC155B7BC91&aid=A4F31984B5D18D95&yid=14E7EF987E4155E6"},{"key":"9_CR16","doi-asserted-by":"publisher","unstructured":"Chen, S., Guo, J., List, E., Shi, D., Zhang, T.: Diving deep into the preimage security of AES-like hashing. In: Joye, M., Leander, G. (eds.) EUROCRYPT\u00a02024, Part\u00a0I. LNCS, vol. 14651, pp. 398\u2013426. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58716-0_14","DOI":"10.1007\/978-3-031-58716-0_14"},{"key":"9_CR17","unstructured":"Courtois, N.T., Amiel, F., de\u00a0Fonvillars, A.B.: On maximum size simultaneous linear approximations in Ascon and Keccak and related translation and differential properties. Cryptology ePrint Archive, Report 2024\/802 (2024). https:\/\/eprint.iacr.org\/2024\/802"},{"key":"9_CR18","doi-asserted-by":"publisher","unstructured":"Gorodilova, A.A., et al.: An overview of the eight international olympiad in cryptography \u201cNon-Stop University CRYPTO\u201d. Sibirskie \u00c8lektronnye Matematicheskie Izvestiya [Siberian Electronic Mathematical Reports] 19(1), A9\u2013A37 (2022). https:\/\/doi.org\/10.33048\/semi.2022.19.023. http:\/\/mi.mathnet.ru\/semr1488","DOI":"10.33048\/semi.2022.19.023"},{"key":"9_CR19","doi-asserted-by":"publisher","unstructured":"Grassi, L., et al.: Poseidon(2)b: binary field versions of poseidon\/poseidon2. IACR Commun. Cryptol. 2(4) (2026). https:\/\/doi.org\/10.62056\/a66ce0zn4","DOI":"10.62056\/a66ce0zn4"},{"key":"9_CR20","doi-asserted-by":"publisher","unstructured":"Grassi, L., Khovratovich, D., L\u00fcftenegger, R., Rechberger, C., Schofnegger, M., Walch, R.: Monolith: circuit-friendly hash functions with new nonlinear layers for fast and constant-time implementations. IACR Trans. Symmetric Cryptol. 2024(3), 44\u201383 (2024). https:\/\/doi.org\/10.46586\/tosc.v2024.i3.44-83","DOI":"10.46586\/tosc.v2024.i3.44-83"},{"key":"9_CR21","doi-asserted-by":"publisher","unstructured":"Grassi, L., Khovratovich, D., Schofnegger, M.: Poseidon2: a faster version of the poseidon hash function. In: El Mrabet, N., De Feo, L., Duquesne, S. (eds.) AFRICACRYPT 23. LNCS, vol. 14064, pp. 177\u2013203. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-37679-5_8","DOI":"10.1007\/978-3-031-37679-5_8"},{"key":"9_CR22","unstructured":"Guido, B., Joan, D., Micha\u00ebl, P., Gilles, V.: Cryptographic sponge functions. 2011-STMicroelectronics NXP Semiconductors, Version 0.1 January 14 (2011)"},{"issue":"1","key":"9_CR23","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1007\/s00145-019-09313-3","volume":"33","author":"J Guo","year":"2020","unstructured":"Guo, J., Liao, G., Liu, G., Liu, M., Qiao, K., Song, L.: Practical collision attacks against round-reduced SHA-3. J. Cryptol. 33(1), 228\u2013270 (2020). https:\/\/doi.org\/10.1007\/s00145-019-09313-3","journal-title":"J. Cryptol."},{"key":"9_CR24","doi-asserted-by":"publisher","unstructured":"Guo, J., Peyrin, T., Poschmann, A., Robshaw, M.J.B.: The LED block cipher. In: Preneel, B., Takagi, T. (eds.) CHES\u00a02011. LNCS, vol.\u00a06917, pp. 326\u2013341. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23951-9_22","DOI":"10.1007\/978-3-642-23951-9_22"},{"key":"9_CR25","unstructured":"Kazymyrov, O., Kazymyrova, V., Oliynykov, R.: A method for generation of high-nonlinear S-boxes based on gradient descent. Cryptology ePrint Archive, Paper 2013\/578 (2013). https:\/\/eprint.iacr.org\/2013\/578"},{"key":"9_CR26","doi-asserted-by":"publisher","unstructured":"Kim, S., et al.: AIM: symmetric primitive for shorter signatures with stronger security. In: ACM CCS 2023, pp. 401\u2013415. ACM, New York, NY, USA (2023). https:\/\/doi.org\/10.1145\/3576915.3616579","DOI":"10.1145\/3576915.3616579"},{"key":"9_CR27","unstructured":"Langevin, P.: Classification of APN cubics in dimension 6 over GF(2) (2012). http:\/\/langevin.univ-tln.fr\/project\/apn-6\/apn6.html"},{"issue":"3","key":"9_CR28","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/S12095-015-0176-Z","volume":"9","author":"J Liu","year":"2017","unstructured":"Liu, J., Mesnager, S., Chen, L.: On the nonlinearity of S-boxes and linear codes. Cryptogr. Commun. 9(3), 345\u2013361 (2017). https:\/\/doi.org\/10.1007\/S12095-015-0176-Z","journal-title":"Cryptogr. Commun."},{"key":"9_CR29","doi-asserted-by":"publisher","unstructured":"Matsui, M.: Linear cryptanalysis method for DES cipher. In: Helleseth, T. (ed.) EUROCRYPT\u201993. LNCS, vol.\u00a0765, pp. 386\u2013397. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48285-7_33","DOI":"10.1007\/3-540-48285-7_33"},{"key":"9_CR30","doi-asserted-by":"publisher","unstructured":"Matsui, M.: New block encryption algorithm MISTY. In: Biham, E. (ed.) FSE\u201997. LNCS, vol.\u00a01267, pp. 54\u201368. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052334","DOI":"10.1007\/BFb0052334"},{"key":"9_CR31","doi-asserted-by":"publisher","unstructured":"Matsui, M., Yamagishi, A.: A new method for known plaintext attack of FEAL cipher. In: Rueppel, R.A. (ed.) EUROCRYPT\u201992. LNCS, vol.\u00a0658, pp. 81\u201391. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/3-540-47555-9_7","DOI":"10.1007\/3-540-47555-9_7"},{"issue":"6","key":"9_CR32","doi-asserted-by":"publisher","first-page":"1703","DOI":"10.1007\/s12095-025-00808-4","volume":"17","author":"GP Nagy","year":"2025","unstructured":"Nagy, G.P.: On the minimum Hamming distance between vectorial Boolean and affine functions. Cryptogr. Commun. 17(6), 1703\u20131720 (2025). https:\/\/doi.org\/10.1007\/s12095-025-00808-4","journal-title":"Cryptogr. Commun."},{"key":"9_CR33","doi-asserted-by":"publisher","unstructured":"Nagy, G.P.: Sidon sets, thin sets, and the nonlinearity of vectorial Boolean functions. J. Comb. Theory Ser. A 212, 106001 (2025). https:\/\/doi.org\/10.1016\/j.jcta.2024.106001","DOI":"10.1016\/j.jcta.2024.106001"},{"key":"9_CR34","doi-asserted-by":"publisher","unstructured":"Nyberg, K.: On the construction of highly nonlinear permutations. In: Rueppel, R.A. (ed.) EUROCRYPT\u201992. LNCS, vol.\u00a0658, pp. 92\u201398. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/3-540-47555-9_8","DOI":"10.1007\/3-540-47555-9_8"},{"key":"9_CR35","doi-asserted-by":"publisher","unstructured":"Nyberg, K.: Differentially uniform mappings for cryptography. In: Helleseth, T. (ed.) EUROCRYPT\u201993. LNCS, vol.\u00a0765, pp. 55\u201364. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48285-7_6","DOI":"10.1007\/3-540-48285-7_6"},{"key":"9_CR36","doi-asserted-by":"publisher","unstructured":"Nyberg, K., Knudsen, L.R.: Provable security against differential cryptanalysis. In: Brickell, E.F. (ed.) Advances in Cryptology \u2013 CRYPTO\u201992. LNCS, vol.\u00a0740, pp. 566\u2013574. Springer, Heidelberg (1993). https:\/\/doi.org\/10.1007\/3-540-48071-4_41","DOI":"10.1007\/3-540-48071-4_41"},{"key":"9_CR37","doi-asserted-by":"publisher","unstructured":"Perrin, L., Udovenko, A.: Exponential s-boxes: a link between the s-boxes of BelT and Kuznyechik\/Streebog. IACR Trans. Symm. Cryptol. 2016(2), 99\u2013124 (2016). https:\/\/doi.org\/10.13154\/tosc.v2016.i2.99-124. https:\/\/tosc.iacr.org\/index.php\/ToSC\/article\/view\/567","DOI":"10.13154\/tosc.v2016.i2.99-124"},{"key":"9_CR38","unstructured":"Perrin, L., Wiemer, F., Stennes, L.: S-boxes used in cryptographic schemes (2019). https:\/\/doc.sagemath.org\/html\/en\/reference\/cryptography\/sage\/crypto\/sboxes.html, SageMath module"},{"key":"9_CR39","doi-asserted-by":"publisher","unstructured":"Qiao, K., Song, L., Liu, M., Guo, J.: New collision attacks on round-reduced Keccak. In: Coron, J.S., Nielsen, J.B. (eds.) EUROCRYPT\u00a02017, Part\u00a0III. LNCS, vol. 10212, pp. 216\u2013243. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56617-7_8","DOI":"10.1007\/978-3-319-56617-7_8"},{"key":"9_CR40","doi-asserted-by":"publisher","unstructured":"Ryabov, V.: Nonlinearity of APN functions: comparative analysis and estimates. [Prikladnaya Diskretnaya Matematika] (61), 15\u201327 (2023). https:\/\/doi.org\/10.17223\/20710410\/61\/2. https:\/\/www.mathnet.ru\/rus\/pdm810","DOI":"10.17223\/20710410\/61\/2"},{"key":"9_CR41","unstructured":"Sage Developers: SageMath, the Sage Mathematics Software System (Version 10.7) (2025). https:\/\/www.sagemath.org"},{"key":"9_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/978-3-319-69284-5_11","volume-title":"Innovative Security Solutions for Information Technology and Communications","author":"Yu Sasaki","year":"2017","unstructured":"Sasaki, Yu., Todo, Y.: New algorithm for modeling S-box in MILP based differential and division trail search. In: Farshim, P., Simion, E. (eds.) SecITC 2017. LNCS, vol. 10543, pp. 150\u2013165. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-69284-5_11"},{"key":"9_CR43","unstructured":"Zaverucha, G., et al.: Picnic. Technical report, National Institute of Standards and Technology (2017). https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\/post-quantum-cryptography-standardization\/round-1-submissions"},{"key":"9_CR44","doi-asserted-by":"publisher","unstructured":"Zhang, K., Wang, Q., Yu, Y., Guo, C., Cui, H.: Algebraic attacks on round-reduced rain and full AIM-III. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT\u00a02023, Part\u00a0III. LNCS, vol. 14440, pp. 285\u2013310. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-8727-6_10","DOI":"10.1007\/978-981-99-8727-6_10"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-25333-0_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T22:45:18Z","timestamp":1778021118000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-25333-0_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032253323","9783032253330"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-25333-0_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"6 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 May 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}