{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T03:12:04Z","timestamp":1783653124920,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":44,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540772712","type":"print"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-77272-9_10","type":"book-chapter","created":{"date-parts":[[2007,12,6]],"date-time":"2007-12-06T06:56:55Z","timestamp":1196924215000},"page":"152-169","source":"Crossref","is-referenced-by-count":86,"title":["Algebraic Cryptanalysis of the Data Encryption Standard"],"prefix":"10.1007","author":[{"given":"Nicolas T.","family":"Courtois","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gregory V.","family":"Bard","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"10_CR1","unstructured":"Bard, G.: Algorithms for Solving Linear and Polynomial Systems of Equations over Finite Fields with Applications to Cryptanalysis. PhD Thesis, University of Maryland at College Park (April 30, 2007)"},{"key":"10_CR2","unstructured":"Bard, G.V., Courtois, N.T., Jefferson, C.: Efficient Methods for Conversion and Solution of Sparse Systems of Low-Degree Multivariate Polynomials over GF(2) via SAT-Solvers, http:\/\/eprint.iacr.org\/2007\/024\/"},{"key":"10_CR3","unstructured":"Augot, D., Biryukov, A., Canteaut, A., Cid, C., Courtois, N., Canni\u00e8re, C.D., Gilbert, H., Lauradoux, C., Parker, M., Preneel, B., Robshaw, M., Seurin, Y.: AES Security Report, D.STVL.2 report, IST-2002-507932 ECRYPT European Network of Excellence in Cryptology, www.ecrypt.eu.org\/documents\/D.STVL.2-1.0.pdf"},{"key":"10_CR4","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E. Biham","year":"1991","unstructured":"Biham, E., Shamir, A.: Differential Cryptanalysis of DES-like Cryptosystems. Journal of Cryptology (IACR)\u00a04, 3\u201372 (1991)","journal-title":"Journal of Cryptology (IACR)"},{"key":"10_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"192","DOI":"10.1007\/3-540-39799-X_16","volume-title":"Crypto 1985","author":"D. Chaum","year":"1986","unstructured":"Chaum, D., Evertse, J.-H.: Cryptanalysis of DES with a Reduced Number of Rounds. In: Williams, H.C. (ed.) CRYPTO 1985. LNCS, vol.\u00a0218, pp. 192\u2013211. Springer, Heidelberg (1986)"},{"key":"10_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1007\/3-540-46766-1_12","volume-title":"CRYPTO 1991","author":"A. Tardy-Corfdir","year":"1992","unstructured":"Tardy-Corfdir, A., Gilbert, H.: A Known Plaintext Attack of FEAL-4 and FEAL-6. In: Feigenbaum, J. (ed.) CRYPTO 1991. LNCS, vol.\u00a0576, pp. 172\u2013181. Springer, Heidelberg (1992)"},{"key":"10_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44598-6_11","volume-title":"CRYPTO 2000","author":"D. Coppersmith","year":"2000","unstructured":"Coppersmith, D.: The development of DES, Invited Talk. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol.\u00a01880, Springer, Heidelberg (2000)"},{"key":"10_CR8","unstructured":"Courtois, N.: Examples of equations generated for experiments with algebraic cryptanalysis of DES, http:\/\/www.cryptosystem.net\/aes\/toyciphers.html"},{"key":"10_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1007\/11506447_7","volume-title":"AES 2005","author":"N. Courtois","year":"2005","unstructured":"Courtois, N.: General Principles of Algebraic Attacks and New Design Criteria for Components of Symmetric Ciphers. In: Dobbertin, H., Rijmen, V., Sowa, A. (eds.) AES 2005. LNCS, vol.\u00a03373, pp. 67\u201383. Springer, Heidelberg (2005)"},{"key":"10_CR10","unstructured":"Courtois, N.T.: How Fast can be Algebraic Attacks on Block Ciphers? In: Biham, E., Handschuh, H., Lucks, S., Rijmen, V. (eds.) Symmetric Cryptography (January 07-12, 2007) http:\/\/drops.dagstuhl.de\/portals\/index.php?semnr=07021"},{"key":"10_CR11","unstructured":"Courtois, N., Bard, G.V., Wagner, D.: Algebraic and Slide Attacks on KeeLoq, (preprint) http:\/\/eprint.iacr.org\/2007\/062\/"},{"key":"10_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1007\/3-540-45539-6_27","volume-title":"EUROCRYPT 2000","author":"N. Courtois","year":"2000","unstructured":"Courtois, N., Shamir, A., Patarin, J., Klimov, A.: Efficient Algorithms for solving Overdefined Systems of Multivariate Polynomial Equations. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol.\u00a01807, pp. 392\u2013407. Springer, Heidelberg (2000)"},{"key":"10_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1007\/3-540-45353-9_20","volume-title":"CT-RSA 2001","author":"N. Courtois","year":"2001","unstructured":"Courtois, N.: The security of Hidden Field Equations (HFE). In: Naccache, D. (ed.) CT-RSA 2001. LNCS, vol.\u00a02020, pp. 266\u2013281. Springer, Heidelberg (2001)"},{"key":"10_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/3-540-36178-2_17","volume-title":"ASIACRYPT 2002","author":"N. Courtois","year":"2002","unstructured":"Courtois, N., Pieprzyk, J.: Cryptanalysis of Block Ciphers with Overdefined Systems of Equations. In: Zheng, Y. (ed.) ASIACRYPT 2002. LNCS, vol.\u00a02501, pp. 267\u2013287. Springer, Heidelberg (2002)"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Courtois, N., Pieprzyk, J.: Cryptanalysis of Block Ciphers with Overdefined Systems of Equations, http:\/\/eprint.iacr.org\/2002\/044\/","DOI":"10.1007\/3-540-36178-2_17"},{"key":"10_CR16","unstructured":"Courtois, N.: The Best Differential Characteristics and Subtleties of the Biham-Shamir Attacks on DES, http:\/\/eprint.iacr.org\/2005\/202"},{"key":"10_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/3-540-39200-9_21","volume-title":"Eurocrypt 2003","author":"N. Courtois","year":"2003","unstructured":"Courtois, N., Meier, W.: Algebraic Attacks on Stream Ciphers with Linear Feedback. In: Biham, E. (ed.) Eurocrypt 2003. LNCS, vol.\u00a02656, pp. 345\u2013359. Springer, Heidelberg (2003)"},{"key":"10_CR18","unstructured":"Courtois, N., Castagnos, G., Goubin, L.: What do DES S-boxes Say to Each Other? http:\/\/eprint.iacr.org\/2003\/184\/"},{"key":"10_CR19","series-title":"Lecture Notes in Computer Science","first-page":"177","volume-title":"CRYPTO 2003","author":"N. Courtois","year":"2003","unstructured":"Courtois, N.: Fast Algebraic Attacks on Stream Ciphers with Linear Feedback. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol.\u00a02729, pp. 177\u2013194. Springer, Heidelberg (2003)"},{"key":"10_CR20","series-title":"Lecture Notes in Computer Science","volume-title":"ICISC 2004","author":"N. Courtois","year":"2005","unstructured":"Courtois, N.: Algebraic Attacks on Combiners with Memory and Several Outputs. In: Park, C.-s., Chee, S. (eds.) ICISC 2004. LNCS, vol.\u00a03506, Springer, Heidelberg (2005), http:\/\/eprint.iacr.org\/2003\/125\/"},{"key":"10_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"170","DOI":"10.1007\/11506447_15","volume-title":"AES 4 Conference, Bonn","author":"N. Courtois","year":"2005","unstructured":"Courtois, N.: The Inverse S-box, Non-linear Polynomial Relations and Cryptanalysis of Block Ciphers. In: Dobbertin, H., Rijmen, V., Sowa, A. (eds.) AES 4 Conference, Bonn. LNCS, vol.\u00a03373, pp. 170\u2013188. Springer, Heidelberg (2005)"},{"key":"10_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/3-540-36563-X_10","volume-title":"CT-RSA 2003","author":"N. Courtois","year":"2003","unstructured":"Courtois, N., Patarin, J.: About the XL Algorithm over GF(2), Cryptographers. In: Joye, M. (ed.) CT-RSA 2003. LNCS, vol.\u00a02612, pp. 141\u2013157. Springer, Heidelberg (2003)"},{"key":"10_CR23","first-page":"171","volume-title":"Crypto 1983","author":"M. Davio","year":"1984","unstructured":"Davio, M., Desmedt, Y., Fosseprez, M., Govaerts, R., Hulsbosch, J., Neutjens, P., Piret, P., Quisquater, J.-J., Vandewalle, J., Wouters, P.: Analytical Characteristics of the DES. In: Crypto 1983, pp. 171\u2013202. Plenum Press, New York (1984)"},{"key":"10_CR24","volume-title":"Workshop on Applications of Commutative Algebra","author":"J.C. Faug\u00e8re","year":"2002","unstructured":"Faug\u00e8re, J.C.: A new efficient algorithm for computing Gr\u00f6bner bases without reduction to zero (F5). In: Workshop on Applications of Commutative Algebra, Catania, Italy, 3-6 April 2002, ACM Press, New York (2002)"},{"key":"10_CR25","unstructured":"Data Encryption Standard (DES), Federal Information Processing Standards Publication (FIPS PUB) 46-3, National Bureau of Standards, Gaithersburg, MD,(1999) http:\/\/csrc.nist.gov\/publications\/fips\/fips46-3\/fips46-3.pdf"},{"key":"10_CR26","unstructured":"Hulsbosch, J.: Analyse van de zwakheden van het DES-algoritme door middel van formele codering, Master thesis, K. U. Leuven, Belgium (1982)"},{"key":"10_CR27","series-title":"Lecture Notes in Computer Science","first-page":"44","volume-title":"CRYPTO 2003","author":"A. Joux","year":"2003","unstructured":"Joux, A., Faug\u00e8re, J.-C.: Algebraic Cryptanalysis of Hidden Field Equation (HFE) Cryptosystems Using Gr\u00f6bner Bases. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol.\u00a02729, pp. 44\u201360. Springer, Heidelberg (2003)"},{"key":"10_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1007\/BFb0055730","volume-title":"CRYPTO 1998","author":"T. Jakobsen","year":"1998","unstructured":"Jakobsen, T.: Cryptanalysis of Block Ciphers with Probabilistic Non-Linear Relations of Low Degree. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol.\u00a01462, pp. 212\u2013222. Springer, Heidelberg (1998)"},{"key":"10_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1007\/978-3-540-45229-4_15","volume-title":"SAC","author":"K. Kim","year":"2003","unstructured":"Kim, K., Lee, S., Park, S., Lee, D.: Securing DES S-boxes against Three Robust Cryptanalysis. In: Nyberg, K., Heys, H.M. (eds.) SAC 2002. LNCS, vol.\u00a02595, pp. 145\u2013157. Springer, Heidelberg (2003)"},{"key":"10_CR30","unstructured":"Kwan, M.: Reducing the Gate Count of Bitslice DES, http:\/\/eprint.iacr.org\/2000\/051 , equations: http:\/\/www.darkside.com.au\/bitslice\/nonstd.c"},{"key":"10_CR31","unstructured":"MAGMA, High performance software for Algebra, Number Theory, and Geometry, \u2014 a large commercial software package: http:\/\/magma.maths.usyd.edu.au\/"},{"key":"10_CR32","unstructured":"Massacci, F.: Using Walk-SAT and Rel-SAT for Cryptographic Key Search. In: IJCAI 1999. International Joint Conference on Artifical Intelligence, pp. 290\u2013295 (1999)"},{"key":"10_CR33","unstructured":"Massacci, F., Marraro, L.: Logical cryptanalysis as a SAT-problem: Encoding and analysis of the U.SS. Data Encryption Standard. Journal of Automated Reasoning 24, 165\u2013203 (2000). And In: Gent, J., van Maaren, H., Walsh, T. (eds.) The proceedings of SAT-2000 conference, Highlights of Satisfiability Research at the Year 2000, pp. 343\u2013376. IOS Press, Amsterdam (2000)"},{"key":"10_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1007\/3-540-48285-7_33","volume-title":"EUROCRYPT 1993","author":"M. Matsui","year":"1994","unstructured":"Matsui, M.: Linear Cryptanalysis Method for DES Cipher. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol.\u00a0765, pp. 386\u2013397. Springer, Heidelberg (1994)"},{"key":"10_CR35","unstructured":"E\u00e9n, N., S\u00f6rensson, N.: MiniSat 2.0. An open-source SAT solver package, http:\/\/www.cs.chalmers.se\/Cs\/Research\/FormalMethods\/MiniSat\/"},{"key":"10_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"102","DOI":"10.1007\/11814948_13","volume-title":"SAT 2006","author":"I. Mironov","year":"2006","unstructured":"Mironov, I., Zhang, L.: Applications of SAT Solvers to Cryptanalysis of Hash Functions. In: Biere, A., Gomes, C.P. (eds.) SAT 2006. LNCS, vol.\u00a04121, pp. 102\u2013115. Springer, Heidelberg (2006), http:\/\/eprint.iacr.org\/2006\/254"},{"key":"10_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45708-9_1","volume-title":"CRYPTO 2002","author":"S. Murphy","year":"2002","unstructured":"Murphy, S., Robshaw, M.: Essential Algebraic Structure within the AES. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol.\u00a02442, Springer, Heidelberg (2002)"},{"key":"10_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"248","DOI":"10.1007\/3-540-44750-4_20","volume-title":"CRYPTO 1995","author":"J. Patarin","year":"1995","unstructured":"Patarin, J.: Cryptanalysis of the Matsumoto and Imai Public Key Scheme of Eurocrypt 1988. In: Coppersmith, D. (ed.) CRYPTO 1995. LNCS, vol.\u00a0963, pp. 248\u2013261. Springer, Heidelberg (1995)"},{"key":"10_CR39","unstructured":"Raddum, H., Semaev, I.: New Technique for Solving Sparse Equation Systems, ECRYPT STVL, http:\/\/eprint.iacr.org\/2006\/475\/"},{"key":"10_CR40","unstructured":"Raddum, H., Semaev, I.: Solving MRHS linear equations. In: ECRYPT Tools for Cryptanalysis workshop, Krak\u00f3w, Poland (September 24-25, 2007)(accepted)"},{"key":"10_CR41","unstructured":"Singular: A Free Computer Algebra System for polynomial computations. http:\/\/www.singular.uni-kl.de\/"},{"key":"10_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1007\/3-540-39799-X_22","volume-title":"Advances in Cryptology","author":"A. Shamir","year":"1986","unstructured":"Shamir, A.: On the security of DES. In: Williams, H.C. (ed.) CRYPTO 1985. LNCS, vol.\u00a0218, pp. 280\u2013281. Springer, Heidelberg (1986)"},{"key":"10_CR43","first-page":"704","volume":"28","author":"C.E. Shannon","year":"1949","unstructured":"Shannon, C.E.: Communication theory of secrecy systems. Bell System Technical Journal\u00a028, 704 (1949)","journal-title":"Bell System Technical Journal"},{"key":"10_CR44","series-title":"Lecture Notes in Computer Science","volume-title":"Cryptography","author":"I. Schaumuller-Bichl","year":"1983","unstructured":"Schaumuller-Bichl, I.: Cryptanalysis of the Data Encryption Standard by the Method of Formal Coding. In: Beth, T. (ed.) Cryptography. LNCS, vol.\u00a0149, Springer, Heidelberg (1983)"}],"container-title":["Lecture Notes in Computer Science","Cryptography and Coding"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-77272-9_10.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T07:06:52Z","timestamp":1619507212000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-77272-9_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540772712"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-77272-9_10","relation":{},"subject":[]}}