{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T00:39:34Z","timestamp":1768351174182,"version":"3.49.0"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319933863","type":"print"},{"value":"9783319933870","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-93387-0_21","type":"book-chapter","created":{"date-parts":[[2018,6,9]],"date-time":"2018-06-09T12:33:36Z","timestamp":1528547616000},"page":"400-418","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["KangarooTwelve: Fast Hashing Based on $${\\textsc {Keccak}\\text {-}p}{}$$"],"prefix":"10.1007","author":[{"given":"Guido","family":"Bertoni","sequence":"first","affiliation":[]},{"given":"Joan","family":"Daemen","sequence":"additional","affiliation":[]},{"given":"Micha\u00ebl","family":"Peeters","sequence":"additional","affiliation":[]},{"given":"Gilles","family":"Van Assche","sequence":"additional","affiliation":[]},{"given":"Ronny","family":"Van Keer","sequence":"additional","affiliation":[]},{"given":"Beno\u00eet","family":"Viguier","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2018,6,10]]},"reference":[{"key":"21_CR1","unstructured":"ARM corporation: ARM architecture reference manual ARMv8, for ARMv8-A architecture profile, document ARM DDI 0487C.a (ID121917). http:\/\/www.arm.com\/"},{"key":"21_CR2","unstructured":"Aumasson, J.-P., Henzen, L., Meier, W., Phan, R. C.-W., SHA-3 proposal BLAKE. Submission to NIST (2008)"},{"key":"21_CR3","unstructured":"Aumasson, J.-P., Meier, W.: Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi (2009). http:\/\/131002.net\/data\/papers\/AM09.pdf"},{"key":"21_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/978-3-642-38980-1_8","volume-title":"Applied Cryptography and Network Security","author":"J-P Aumasson","year":"2013","unstructured":"Aumasson, J.-P., Neves, S., Wilcox-O\u2019Hearn, Z., Winnerlein, C.: BLAKE2: simpler, smaller, fast as MD5. In: Jacobson, M., Locasto, M., Mohassel, P., Safavi-Naini, R. (eds.) ACNS 2013. LNCS, vol. 7954, pp. 119\u2013135. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38980-1_8"},{"key":"21_CR5","unstructured":"Bernstein, D.J., Lange, T., (eds.) eBACS: ECRYPT benchmarking of cryptographic systems. http:\/\/bench.cr.yp.to"},{"key":"21_CR6","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: Keccak specifications. NIST SHA-3 Submission, October 2008"},{"key":"21_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-78967-3_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2008","author":"G Bertoni","year":"2008","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: On the indifferentiability of the sponge construction. In: Smart, N. (ed.) EUROCRYPT 2008. LNCS, vol. 4965, pp. 181\u2013197. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78967-3_11"},{"key":"21_CR8","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: Cryptographic sponge functions, January 2011. https:\/\/keccak.team\/files\/SpongeFunctions.pdf"},{"key":"21_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1007\/978-3-319-07536-5_14","volume-title":"Applied Cryptography and Network Security","author":"G Bertoni","year":"2014","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: Sakura: a flexible coding for tree hashing. In: Boureanu, I., Owesarski, P., Vaudenay, S. (eds.) ACNS 2014. LNCS, vol. 8479, pp. 217\u2013234. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-07536-5_14"},{"key":"21_CR10","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1007\/s10207-013-0220-y","volume":"13","author":"G Bertoni","year":"2014","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: Sufficient conditions for sound tree and sequential hashing modes. Int. J. Inf. Secur. 13, 335\u2013353 (2014). https:\/\/doi.org\/10.1007\/s10207-013-0220-y","journal-title":"Int. J. Inf. Secur."},{"key":"21_CR11","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G., Van Keer, R.: KangarooTwelve: fast hashing based on Keccak-p. Cryptology ePrint Archive, Report 2016\/770 (2016). http:\/\/eprint.iacr.org\/2016\/770"},{"key":"21_CR12","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G., Van Keer, R.: Keccak code package, June 2016. https:\/\/github.com\/gvanas\/KeccakCodePackage"},{"key":"21_CR13","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G., Van Keer, R.: Keccak third-party cryptanalysis (2017). https:\/\/keccak.team\/third_party.html"},{"key":"21_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-642-21702-9_15","volume-title":"Fast Software Encryption","author":"C Boura","year":"2011","unstructured":"Boura, C., Canteaut, A., De Canni\u00e8re, C.: Higher-order differential properties of Keccak and Luffa. In: Joux, A. (ed.) FSE 2011. LNCS, vol. 6733, pp. 252\u2013269. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-21702-9_15"},{"key":"21_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-662-43933-3_12","volume-title":"Fast Software Encryption","author":"I Dinur","year":"2014","unstructured":"Dinur, I., Dunkelman, O., Shamir, A.: Collision attacks on up to 5 rounds of SHA-3 using generalized internal differentials. In: Moriai, S. (ed.) FSE 2013. LNCS, vol. 8424, pp. 219\u2013240. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43933-3_12"},{"issue":"2","key":"21_CR16","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1007\/s00145-012-9142-5","volume":"27","author":"I Dinur","year":"2014","unstructured":"Dinur, I., Dunkelman, O., Shamir, A.: Improved practical attacks on round-reduced Keccak. J. Cryptol. 27(2), 183\u2013209 (2014)","journal-title":"J. Cryptol."},{"key":"21_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"733","DOI":"10.1007\/978-3-662-46800-5_28","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2015","author":"I Dinur","year":"2015","unstructured":"Dinur, I., Morawiecki, P., Pieprzyk, J., Srebrny, M., Straus, M.: Cube attacks and cube-attack-like cryptanalysis on the round-reduced Keccak sponge function. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9056, pp. 733\u2013761. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46800-5_28"},{"key":"21_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1007\/978-3-662-48800-3_25","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"C Dobraunig","year":"2015","unstructured":"Dobraunig, C., Eichlseder, M., Mendel, F.: Analysis of SHA-512\/224 and SHA-512\/256. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015. LNCS, vol. 9453, pp. 612\u2013630. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48800-3_25"},{"key":"21_CR19","unstructured":"Ferguson, N., Lucks, S., Schneier, B., Whiting, D., Bellare, M., Kohno, T., Callas, J., Walker, J.: The skein hash function family. Submission to NIST (Round 2) (2009)"},{"key":"21_CR20","unstructured":"Gauravaram, P., Knudsen, L.R., Matusiewicz, K., Mendel, F., Rechberger, C., Schl\u00e4ffer, M., Thomsen, S.S.: Gr\u00f8stl - a SHA-3 candidate. Submission to NIST (Round 3) (2011)"},{"key":"21_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-662-53887-6_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"J Guo","year":"2016","unstructured":"Guo, J., Liu, M., Song, L.: Linear structures: applications to cryptanalysis of round-reduced Keccak. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. LNCS, vol. 10031, pp. 249\u2013274. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_9"},{"key":"21_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-319-56614-6_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"S Huang","year":"2017","unstructured":"Huang, S., Wang, X., Xu, G., Wang, M., Zhao, J.: Conditional cube attack on reduced-round Keccak sponge function. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10211, pp. 259\u2013288. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56614-6_9"},{"key":"21_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1007\/978-3-642-34047-5_16","volume-title":"Fast Software Encryption","author":"J Li","year":"2012","unstructured":"Li, J., Isobe, T., Shibutani, K.: Converting meet-in-the-middle preimage attack into pseudo collision attack: application to SHA-2. In: Canteaut, A. (ed.) FSE 2012. LNCS, vol. 7549, pp. 264\u2013286. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34047-5_16"},{"key":"21_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-540-24638-1_2","volume-title":"Theory of Cryptography","author":"U Maurer","year":"2004","unstructured":"Maurer, U., Renner, R., Holenstein, C.: Indifferentiability, impossibility results on reductions, and applications to the random oracle methodology. In: Naor, M. (ed.) TCC 2004. LNCS, vol. 2951, pp. 21\u201339. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24638-1_2"},{"key":"21_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"262","DOI":"10.1007\/978-3-642-38348-9_16","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2013","author":"F Mendel","year":"2013","unstructured":"Mendel, F., Nad, T., Schl\u00e4ffer, M.: Improving local collisions: new attacks on reduced SHA-256. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 262\u2013278. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_16"},{"key":"21_CR26","doi-asserted-by":"crossref","unstructured":"Micciancio, D., Walter, M.: On the bit security of cryptographic primitives. Eurocrypt (2018, to appear)","DOI":"10.1007\/978-3-319-78381-9_1"},{"key":"21_CR27","unstructured":"Neves, S.: BLAKE2 AVX2 implementations. https:\/\/github.com\/sneves\/blake2-avx2"},{"key":"21_CR28","unstructured":"NIST: Federal information processing standard 180\u20131, secure hash standard, April 1995"},{"key":"21_CR29","unstructured":"NIST: Federal information processing standard 180\u20132, secure hash standard, August 2002"},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"NIST: Federal information processing standard 202, SHA-3 standard: Permutation-based hash and extendable-output functions, August 2015. http:\/\/dx.doi.org\/10.6028\/NIST.FIPS.202","DOI":"10.6028\/NIST.FIPS.202"},{"key":"21_CR31","doi-asserted-by":"crossref","unstructured":"NIST: NIST special publication 800\u2013185, SHA-3 derived functions: cSHAKE, KMAC, TupleHash and ParallelHash, December 2016. https:\/\/doi.org\/10.6028\/NIST.SP.800-185","DOI":"10.6028\/NIST.SP.800-185"},{"key":"21_CR32","unstructured":"OpenSSL community: OpenSSL - cryptography and SSL\/TLS toolkit. https:\/\/github.com\/openssl\/openssl"},{"key":"21_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/978-3-642-20465-4_27","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2011","author":"T Ristenpart","year":"2011","unstructured":"Ristenpart, T., Shacham, H., Shrimpton, T.: Careful with composition: limitations of the indifferentiability framework. In: Paterson, K.G. (ed.) EUROCRYPT 2011. LNCS, vol. 6632, pp. 487\u2013506. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-20465-4_27"},{"key":"21_CR34","doi-asserted-by":"crossref","unstructured":"Rivest, R.: The MD5 message-digest algorithm. Internet Request for Comments, RFC 1321, April 1992","DOI":"10.17487\/rfc1321"},{"issue":"1","key":"21_CR35","doi-asserted-by":"crossref","first-page":"240","DOI":"10.46586\/tosc.v2017.i1.240-258","volume":"2017","author":"D Saha","year":"2017","unstructured":"Saha, D., Kuila, S., Chowdhury, D.R.: Symsum: symmetric-sum distinguishers against round reduced SHA3. IACR Trans. Symmetric Cryptol. 2017(1), 240\u2013258 (2017)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"21_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-63715-0_15","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"L Song","year":"2017","unstructured":"Song, L., Liao, G., Guo, J.: Non-full sbox linearization: applications to collision attacks on round-reduced Keccak. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017. LNCS, vol. 10402, pp. 428\u2013451. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63715-0_15"},{"key":"21_CR37","unstructured":"Song, L., Liao, G., Guo, J.: Solution to the 6-round collision challenge (2017). https:\/\/keccak.team\/crunchy_contest.html"},{"key":"21_CR38","unstructured":"Viguier, B.: KangarooTwelve. Internet Research Task Force draft, March 2018. https:\/\/datatracker.ietf.org\/doc\/draft-viguier-kangarootwelve\/"},{"key":"21_CR39","unstructured":"Wu, H.: The hash function JH. Submission to NIST (Round 3) (2011)"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-93387-0_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T15:02:20Z","timestamp":1710342140000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-93387-0_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319933863","9783319933870"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-93387-0_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"10 June 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Leuven","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 July 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.cosic.esat.kuleuven.be\/events\/acns2018\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}