{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,17]],"date-time":"2025-04-17T04:13:19Z","timestamp":1744863199912,"version":"3.38.0"},"publisher-location":"Berlin, Heidelberg","reference-count":61,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642239502"},{"type":"electronic","value":"9783642239519"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-23951-9_33","type":"book-chapter","created":{"date-parts":[[2011,9,26]],"date-time":"2011-09-26T05:17:11Z","timestamp":1317014231000},"page":"507-522","source":"Crossref","is-referenced-by-count":17,"title":["Efficient Hashing Using the AES Instruction Set"],"prefix":"10.1007","author":[{"given":"Joppe W.","family":"Bos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Onur","family":"\u00d6zen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martijn","family":"Stam","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"33_CR1","unstructured":"American National Standards Institute: Public key cryptography using reversible algorithms for the financial services industry. American National Standards Institute (1998)"},{"key":"33_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1007\/978-3-642-10366-7_10","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2009","author":"R. Benadjila","year":"2009","unstructured":"Benadjila, R., Billet, O., Gueron, S., Robshaw, M.J.B.: The Intel AES instructions set and the SHA-3 candidates. In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol.\u00a05912, pp. 162\u2013178. Springer, Heidelberg (2009)"},{"key":"33_CR3","unstructured":"Bernstein, D.J.: Cache-timing attacks on AES (2005), http:\/\/cr.yp.to\/papers.html#cachetiming"},{"key":"33_CR4","unstructured":"Bernstein, D.J., Lange, T. (eds.): eBACS: ECRYPT Benchmarking of Cryptographic Systems (2010), http:\/\/bench.cr.yp.to"},{"key":"33_CR5","first-page":"275","volume-title":"Application-specific Systems, Architectures and Processors","author":"G. Bertoni","year":"2006","unstructured":"Bertoni, G., Breveglieri, L., Farina, R., Regazzoni, F.: Speeding up AES by extending a 32 bit processor instruction set. In: Application-specific Systems, Architectures and Processors, pp. 275\u2013282. IEEE Computer Society, Los Alamitos (2006)"},{"key":"33_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-78967-3_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2008","author":"G. Bertoni","year":"2008","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: On the indifferentiability of the sponge construction. In: Smart, N.P. (ed.) EUROCRYPT 2008. LNCS, vol.\u00a04965, pp. 181\u2013197. Springer, Heidelberg (2008)"},{"key":"33_CR7","unstructured":"Biham, E., Dunkelman, O.: A framework for iterative hash functions \u2013 HAIFA. Presented at Second NIST Cryptographic Hash Workshop, Santa Barbara, USA (2006)"},{"key":"33_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-10366-7_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2009","author":"A. Biryukov","year":"2009","unstructured":"Biryukov, A., Khovratovich, D.: Related-key cryptanalysis of the full AES-192 and AES-256. In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol.\u00a05912, pp. 1\u201318. Springer, Heidelberg (2009)"},{"key":"33_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/978-3-642-03356-8_14","volume-title":"Advances in Cryptology - CRYPTO 2009","author":"A. Biryukov","year":"2009","unstructured":"Biryukov, A., Khovratovich, D., Nikoli\u0107, I.: Distinguisher and related-key attack on the full AES-256. In: Halevi, S. (ed.) CRYPTO 2009. LNCS, vol.\u00a05677, pp. 231\u2013249. Springer, Heidelberg (2009)"},{"issue":"4","key":"33_CR10","doi-asserted-by":"publisher","first-page":"519","DOI":"10.1007\/s00145-010-9071-0","volume":"23","author":"J. Black","year":"2010","unstructured":"Black, J., Rogaway, P., Shrimpton, T., Stam, M.: An analysis of the blockcipher-based hash functions from PGV. Journal of Cryptology\u00a023(4), 519\u2013545 (2010)","journal-title":"Journal of Cryptology"},{"key":"33_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/978-3-540-85053-3_18","volume-title":"Cryptographic Hardware and Embedded Systems \u2013 CHES 2008","author":"A. Bogdanov","year":"2008","unstructured":"Bogdanov, A., Leander, G., Paar, C., Poschmann, A., Robshaw, M.J.B., Seurin, Y.: Hash functions and RFID tags: Mind the gap. In: Oswald, E., Rohatgi, P. (eds.) CHES 2008. LNCS, vol.\u00a05154, pp. 283\u2013299. Springer, Heidelberg (2008)"},{"key":"33_CR12","doi-asserted-by":"crossref","unstructured":"Bos, J.W., \u00d6zen, O., Stam, M.: Efficient hashing using the AES instruction set. Cryptology ePrint Archive, Report 2010\/576 (2010)","DOI":"10.1007\/978-3-642-23951-9_33"},{"key":"33_CR13","unstructured":"Brachtl, B., Coppersmith, D., Hyden, M., Matyas Jr., S., Meyer, C., Oseas, J., Pilpel, S., Schilling, M.: Data authentication using modification detection codes based on a public one-way encryption function. U.S. Patent No 4,908,861 (1990)"},{"key":"33_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"416","DOI":"10.1007\/0-387-34805-0_39","volume-title":"Advances in Cryptology - CRYPTO \u201989","author":"I. Damg\u00e5rd","year":"1990","unstructured":"Damg\u00e5rd, I.: A design principle for hash functions. In: Brassard, G. (ed.) CRYPTO 1989. LNCS, vol.\u00a0435, pp. 416\u2013427. Springer, Heidelberg (1990)"},{"key":"33_CR15","unstructured":"De Canni\u00e8re, C., Sato, H., Watanabe, D.: Hash function Luffa: Supporting document. Submission to NIST (Round 2) (2009), http:\/\/www.sdl.hitachi.co.jp\/crypto\/luffa\/Luffa_v2_SupportingDocument_20090915.pdf"},{"key":"33_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/978-3-642-10868-6_10","volume-title":"Cryptography and Coding","author":"E. Fleischmann","year":"2009","unstructured":"Fleischmann, E., Gorski, M., Lucks, S.: Security of cyclic double block length hash functions. In: Parker, M.G. (ed.) Cryptography and Coding 2009. LNCS, vol.\u00a05921, pp. 153\u2013175. Springer, Heidelberg (2009)"},{"key":"33_CR17","unstructured":"Fog, A.: Instruction tables, lists of instruction latencies, throughputs and microoperation breakdowns for Intel, AMD and VIA CPUs (2010), http:\/\/www.agner.org\/optimize\/"},{"key":"33_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-3-642-03317-9_4","volume-title":"Fast Software Encryption","author":"S. Gueron","year":"2009","unstructured":"Gueron, S.: Intel\u2019s new AES instructions for enhanced performance and security. In: Dunkelman, O. (ed.) FSE 2009. LNCS, vol.\u00a05665, pp. 51\u201366. Springer, Heidelberg (2009)"},{"key":"33_CR19","unstructured":"Gueron, S.: Intel advanced encryption standard (AES) instructions set. Tech. rep., Intel (2010), http:\/\/software.intel.com\/file\/24917"},{"key":"33_CR20","unstructured":"Gueron, S., Kounavis, M.E.: Intel carry-less multiplication instruction and its usage for computing the GCM mode. Tech. rep., Intel (2010), http:\/\/software.intel.com\/file\/24918"},{"key":"33_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/11799313_14","volume-title":"Fast Software Encryption","author":"S. Hirose","year":"2006","unstructured":"Hirose, S.: Some plausible constructions of double-block-length hash functions. In: Robshaw, M. (ed.) FSE 2006. LNCS, vol.\u00a04047, pp. 210\u2013225. Springer, Heidelberg (2006)"},{"key":"33_CR22","unstructured":"Indesteege, S.: The LANE hash function. Submission to NIST (2008), http:\/\/www.cosic.esat.kuleuven.be\/publications\/article-1181.pdf"},{"key":"33_CR23","unstructured":"International Organization for Standardization: ISO\/IEC 10118-2: hash functions using an n-bit block cipher (2010)"},{"key":"33_CR24","unstructured":"Khovratovich, D.: New Approaches to the Cryptanalysis of Symmetric Primitives. Ph.D. thesis, University of Luxembourg (2010)"},{"key":"33_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-642-01001-9_6","volume-title":"Advances in Cryptology - EUROCRYPT 2009","author":"L.R. Knudsen","year":"2009","unstructured":"Knudsen, L.R., Mendel, F., Rechberger, C., Thomsen, S.S.: Cryptanalysis of MDC-2. In: Joux, A. (ed.) EUROCRYPT 2009. LNCS, vol.\u00a05479, pp. 106\u2013120. Springer, Heidelberg (2009)"},{"issue":"9","key":"33_CR26","doi-asserted-by":"publisher","first-page":"2524","DOI":"10.1109\/TIT.2002.801402","volume":"48","author":"L.R. Knudsen","year":"2002","unstructured":"Knudsen, L.R., Preneel, B.: Construction of secure and fast hash functions using nonbinary error-correcting codes. IEEE Transactions on Information Theory\u00a048(9), 2524\u20132539 (2002)","journal-title":"IEEE Transactions on Information Theory"},{"key":"33_CR27","unstructured":"Krause, M., Armknecht, F., Fleischmann, E.: Preimage resistance beyond the birthday barrier \u2013 the case of blockcipher based hashing. Cryptology ePrint Archive, Report 2010\/519 (2010)"},{"key":"33_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/3-540-47555-9_5","volume-title":"Advances in Cryptology - EUROCRYPT \u201992","author":"X. Lai","year":"1993","unstructured":"Lai, X., Massey, J.L.: Hash functions based on block ciphers. In: Rueppel, R. (ed.) EUROCRYPT 1992. LNCS, vol.\u00a0658, pp. 55\u201370. Springer, Heidelberg (1993)"},{"key":"33_CR29","unstructured":"Lee, J., Kwon, D.: The security of Abreast-DM in the ideal cipher model. Cryptology ePrint Archive, Report 2009\/225 (2009)"},{"key":"33_CR30","unstructured":"Lee, J., Park, J.H.: Adaptive preimage resistance and permutation-based hash functions. Cryptology ePrint Archive, Report 2009\/066 (2009)"},{"issue":"14-15","key":"33_CR31","doi-asserted-by":"publisher","first-page":"602","DOI":"10.1016\/j.ipl.2010.05.009","volume":"110","author":"J. Lee","year":"2010","unstructured":"Lee, J., Park, J.H.: Preimage resistance of LPmkr with r\u2009=\u2009m\u2009\u2212\u20091. Information Processing Letters\u00a0110(14-15), 602\u2013608 (2010)","journal-title":"Information Processing Letters"},{"key":"33_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/978-3-642-19074-2_15","volume-title":"Topics in Cryptology \u2013 CT-RSA 2011","author":"J. Lee","year":"2011","unstructured":"Lee, J., Stam, M.: MJH: A faster alternative to MDC-2. In: Kiayias, A. (ed.) CT-RSA 2011. LNCS, vol.\u00a06558, pp. 213\u2013236. Springer, Heidelberg (2011)"},{"key":"33_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"561","DOI":"10.1007\/978-3-642-22792-9_32","volume-title":"CRYPTO 2011","author":"J. Lee","year":"2011","unstructured":"Lee, J., Stam, M., Steinberger, J.: The collision security of Tandem-DM in the ideal cipher model. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol.\u00a06841, pp. 561\u2013568. Springer, Heidelberg (2011)"},{"key":"33_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/978-3-642-13190-5_29","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2010","author":"J. Lee","year":"2010","unstructured":"Lee, J., Steinberger, J.P.: Multi-property-preserving domain extension using polynomial-based modes of operation. In: Gilbert, H. (ed.) EUROCRYPT 2010. LNCS, vol.\u00a06110, pp. 573\u2013596. Springer, Heidelberg (2010)"},{"key":"33_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1007\/11593447_26","volume-title":"Advances in Cryptology - ASIACRYPT 2005","author":"S. Lucks","year":"2005","unstructured":"Lucks, S.: A failure-friendly design\u00a0principle for\u00a0hash\u00a0functions. In: Roy, B. (ed.) ASIACRYPT 2005. LNCS, vol.\u00a03788, pp. 474\u2013494. Springer, Heidelberg (2005)"},{"key":"33_CR36","unstructured":"Lucks, S.: A collision-resistant rate-1 double-block-length hash function. In: Symmetric Cryptography. No. 07021 in Dagstuhl Seminar Proceedings, Internationales Begegnungs- und Forschungszentrum f\u00fcr Informatik (IBFI), Schloss Dagstuhl, Germany (2007)"},{"key":"33_CR37","doi-asserted-by":"crossref","unstructured":"Manley, R., Magrath, P., Gregg, D.: Code generation for hardware accelerated AES. In: 21st IEEE International Conference on Application-specific Systems Architectures and Processors (ASAP), pp. 345\u2013348 (2010)","DOI":"10.1109\/ASAP.2010.5540955"},{"key":"33_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-642-10366-7_7","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2009","author":"K. Matusiewicz","year":"2009","unstructured":"Matusiewicz, K., Naya-Plasencia, M., Nikolic, I., Sasaki, Y., Schl\u00e4ffer, M.: Rebound attack on the full lane compression function. In: Matsui, M. (ed.) ASIACRYPT 2009. LNCS, vol.\u00a05912, pp. 106\u2013125. Springer, Heidelberg (2009)"},{"key":"33_CR39","doi-asserted-by":"publisher","DOI":"10.1201\/9781439821916","volume-title":"CRC-Handbook of Applied Cryptography","author":"A.J. Menezes","year":"1996","unstructured":"Menezes, A.J., van Oorschot, P.C., Vanstone, S.: CRC-Handbook of Applied Cryptography. CRC Press, Boca Raton (1996)"},{"key":"33_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"428","DOI":"10.1007\/0-387-34805-0_40","volume-title":"Advances in Cryptology - CRYPTO \u201989","author":"R.C. Merkle","year":"1990","unstructured":"Merkle, R.C.: One way hash functions and DES. In: Brassard, G. (ed.) CRYPTO 1989. LNCS, vol.\u00a0435, pp. 428\u2013446. Springer, Heidelberg (1990)"},{"key":"33_CR41","unstructured":"NIST: FIPS-197: Advanced encryption standard (AES) (2001), http:\/\/www.csrc.nist.gov\/publications\/fips\/fips197\/fips-197.pdf"},{"key":"33_CR42","unstructured":"NIST: Secure hash standard. FIPS 180-2, NIST (August 2002), http:\/\/www.itl.nist.gov\/fipspubs\/fip180-2.htm"},{"key":"33_CR43","unstructured":"NIST: Cryptographic hash algorithm competition (2008), http:\/\/csrc.nist.gov\/groups\/ST\/hash\/sha-3\/index.html"},{"key":"33_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/978-3-642-13858-4_6","volume-title":"Fast Software Encryption","author":"O. \u00d6zen","year":"2010","unstructured":"\u00d6zen, O., Shrimpton, T., Stam, M.: Attacking the Knudsen-Preneel compression functions. In: Hong, S., Iwata, T. (eds.) FSE 2010. LNCS, vol.\u00a06147, pp. 94\u2013115. Springer, Heidelberg (2010)"},{"key":"33_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"176","DOI":"10.1007\/978-3-642-10868-6_11","volume-title":"Cryptography and Coding","author":"O. \u00d6zen","year":"2009","unstructured":"\u00d6zen, O., Stam, M.: Another glance at double-length hashing. In: Parker, M. (ed.) Cryptography and Coding 2009. LNCS, vol.\u00a05921, pp. 176\u2013201. Springer, Heidelberg (2009)"},{"key":"33_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1007\/978-3-642-17373-8_5","volume-title":"Advances in Cryptology - ASIACRYPT 2010","author":"O. \u00d6zen","year":"2010","unstructured":"\u00d6zen, O., Stam, M.: Collision attacks against the Knudsen-Preneel compression functions. In: Abe, M. (ed.) ASIACRYPT 2010. LNCS, vol.\u00a06477, pp. 76\u201393. Springer, Heidelberg (2010)"},{"key":"33_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1007\/11935230_21","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2006","author":"T. Peyrin","year":"2006","unstructured":"Peyrin, T., Gilbert, H., Muller, F., Robshaw, M.J.B.: Combining compression functions and block cipher-based hash functions. In: Lai, X., Chen, K. (eds.) ASIACRYPT 2006. LNCS, vol.\u00a04284, pp. 315\u2013331. Springer, Heidelberg (2006)"},{"key":"33_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"368","DOI":"10.1007\/3-540-48329-2_31","volume-title":"Advances in Cryptology - CRYPTO \u201993","author":"B. Preneel","year":"1994","unstructured":"Preneel, B., Govaerts, R., Vandewalle, J.: Hash functions based on block ciphers: A synthetic approach. In: Stinson, D. (ed.) CRYPTO 1993. LNCS, vol.\u00a0773, pp. 368\u2013378. Springer, Heidelberg (1994)"},{"key":"33_CR49","first-page":"155","volume-title":"Foundations of Secure Computations","author":"M.O. Rabin","year":"1978","unstructured":"Rabin, M.O.: Digitalized signatures. In: Foundations of Secure Computations, pp. 155\u2013166. Academic Press, London (1978)"},{"key":"33_CR50","doi-asserted-by":"crossref","unstructured":"Rivest, R.: The MD5 message-digest algorithm, request for comments (RFC) 1320. Tech. rep., Internet Activities Board, Internet Privacy Task Force (1992)","DOI":"10.17487\/rfc1321"},{"key":"33_CR51","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1007\/978-3-540-78967-3_13","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2008","author":"P. Rogaway","year":"2008","unstructured":"Rogaway, P., Steinberger, J.: Security\/efficiency tradeoffs for permutation-based hashing. In: Smart, N. (ed.) EUROCRYPT 2008. LNCS, vol.\u00a04965, pp. 220\u2013236. Springer, Heidelberg (2008)"},{"key":"33_CR52","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"433","DOI":"10.1007\/978-3-540-85174-5_24","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"P. Rogaway","year":"2008","unstructured":"Rogaway, P., Steinberger, J.P.: Constructing cryptographic hash functions from fixed-key blockciphers. In: Wagner, D. (ed.) CRYPTO 2008. LNCS, vol.\u00a05157, pp. 433\u2013450. Springer, Heidelberg (2008)"},{"key":"33_CR53","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/978-3-540-74619-5_8","volume-title":"Fast Software Encryption","author":"Y. Seurin","year":"2007","unstructured":"Seurin, Y., Peyrin, T.: Security analysis of constructions combining FIL random oracles. In: Biryukov, A. (ed.) FSE 2007. LNCS, vol.\u00a04593, pp. 119\u2013136. Springer, Heidelberg (2007)"},{"key":"33_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"643","DOI":"10.1007\/978-3-540-70583-3_52","volume-title":"Automata, Languages and Programming","author":"T. Shrimpton","year":"2008","unstructured":"Shrimpton, T., Stam, M.: Building a collision-resistant compression function from non-compressing primitives. In: Aceto, L., Damg\u00e5rd, I., Goldberg, L., Halld\u00f3rsson, M., Ing\u00f3lfsd\u00f3ttir, A., Walukiewicz, I. (eds.) ICALP 2008, Part II. LNCS, vol.\u00a05126, pp. 643\u2013654. Springer, Heidelberg (2008)"},{"key":"33_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"397","DOI":"10.1007\/978-3-540-85174-5_22","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"M. Stam","year":"2008","unstructured":"Stam, M.: Beyond uniformity: Better security\/efficiency tradeoffs for compression functions. In: Wagner, D. (ed.) Crypto 2008. LNCS, vol. 5157, pp. 397\u2013412. Springer, Heidelberg (2008)"},{"key":"33_CR56","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/978-3-642-03317-9_5","volume-title":"Fast Software Encryption","author":"M. Stam","year":"2009","unstructured":"Stam, M.: Blockcipher-based hashing revisited. In: Dunkelman, O. (ed.) FSE 2009. LNCS, vol.\u00a05665, pp. 67\u201383. Springer, Heidelberg (2009)"},{"key":"33_CR57","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-540-72540-4_3","volume-title":"Advances in Cryptology - EUROCRYPT 2007","author":"J.P. Steinberger","year":"2007","unstructured":"Steinberger, J.P.: The collision intractability of MDC-2 in the ideal-cipher model. In: Naor, M. (ed.) EUROCRYPT 2007. LNCS, vol.\u00a04515, pp. 34\u201351. Springer, Heidelberg (2007)"},{"key":"33_CR58","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"270","DOI":"10.1007\/11894063_22","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2006","author":"S. Tillich","year":"2006","unstructured":"Tillich, S., Gro\u00dfsch\u00e4dl, J.: Instruction set extensions for efficient AES implementation on 32-bit processors. In: Goubin, L., Matsui, M. (eds.) CHES 2006. LNCS, vol.\u00a04249, pp. 270\u2013284. Springer, Heidelberg (2006)"},{"key":"33_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"170","DOI":"10.1007\/978-3-540-79263-5_11","volume-title":"Topics in Cryptology \u2013 CT-RSA 2008","author":"S. Tillich","year":"2008","unstructured":"Tillich, S., Herbst, C.: Boosting AES performance on a tiny processor core. In: Malkin, T. (ed.) CT-RSA 2008. LNCS, vol.\u00a04964, pp. 170\u2013186. Springer, Heidelberg (2008)"},{"key":"33_CR60","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/s00145-009-9049-y","volume":"23","author":"E. Tromer","year":"2010","unstructured":"Tromer, E., Osvik, D.A., Shamir, A.: Efficient cache attacks on AES, and countermeasures. Journal of Cryptology\u00a023, 37\u201371 (2010)","journal-title":"Journal of Cryptology"},{"key":"33_CR61","unstructured":"Wu, H.: The hash function JH. Submission to NIST (updated) (2009), http:\/\/icsd.i2r.a-star.edu.sg\/staff\/hongjun\/jh\/jh_round2.pdf"}],"container-title":["Lecture Notes in Computer Science","Cryptographic Hardware and Embedded Systems \u2013 CHES 2011"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-23951-9_33.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T01:16:00Z","timestamp":1741742160000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-23951-9_33"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642239502","9783642239519"],"references-count":61,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-23951-9_33","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}