{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T10:59:38Z","timestamp":1778065178435,"version":"3.51.4"},"publisher-location":"Berlin, Heidelberg","reference-count":42,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783662479889","type":"print"},{"value":"9783662479896","type":"electronic"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-662-47989-6_6","type":"book-chapter","created":{"date-parts":[[2015,7,30]],"date-time":"2015-07-30T22:36:05Z","timestamp":1438295765000},"page":"116-140","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":28,"title":["On Reverse-Engineering S-Boxes with Hidden Design Criteria or Structure"],"prefix":"10.1007","author":[{"given":"Alex","family":"Biryukov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"L\u00e9o","family":"Perrin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,8,1]]},"reference":[{"issue":"1","key":"6_CR1","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E Biham","year":"1991","unstructured":"Biham, E., Shamir, A.: Differential cryptanalysis of DES-like cryptosystems. J. Cryptology 4(1), 3\u201372 (1991)","journal-title":"J. Cryptology"},{"key":"6_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/3-540-48285-7_6","volume-title":"Advances in Cryptology - EUROCRYPT \u201993","author":"K Nyberg","year":"1994","unstructured":"Nyberg, K.: Differentially uniform mappings for cryptography. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol. 765, pp. 55\u201364. Springer, Heidelberg (1994)"},{"key":"6_CR3","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.ffa.2014.10.007","volume":"32","author":"C Blondeau","year":"2015","unstructured":"Blondeau, C., Nyberg, K.: Perfect nonlinear functions and cryptography. Finite Fields Appl. 32, 120\u2013147 (2015). Special Issue: Second Decade of FFA","journal-title":"Finite Fields Appl."},{"key":"6_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1007\/3-540-48285-7_33","volume-title":"Advances in Cryptology - EUROCRYPT \u201993","author":"M Matsui","year":"1994","unstructured":"Matsui, M.: Linear cryptanalysis method for DES cipher. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol. 765, pp. 386\u2013397. Springer, Heidelberg (1994)"},{"key":"6_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1007\/BFb0053460","volume-title":"Advances in Cryptology - EUROCRYPT \u201994","author":"K Nyberg","year":"1995","unstructured":"Nyberg, K.: Linear approximation of block ciphers. In: De Santis, A. (ed.) EUROCRYPT 1994. LNCS, vol. 950, pp. 439\u2013444. Springer, Heidelberg (1995)"},{"key":"6_CR6","unstructured":"Barreto, P., Rijmen, V.: The whirlpool hashing function. In: First open NESSIE Workshop, Leuven, Belgium, vol. 13, p. 14 (2000)"},{"key":"6_CR7","unstructured":"Barreto, P., Rijmen, V.: The khazad legacy-level block cipher. Primitive submitted to NESSIE 97 (2000)"},{"key":"6_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1007\/978-3-662-46706-0_2","volume-title":"Fast Software Encryption","author":"V Grosso","year":"2015","unstructured":"Grosso, V., Leurent, G., Standaert, F.-X., Var\u0131c\u0131, K.: LS-Designs: bitslice encryption for efficient masked software implementations. In: Cid, C., Rechberger, C. (eds.) FSE 2014. LNCS, vol. 8540, pp. 18\u201337. Springer, Heidelberg (2015)"},{"key":"6_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1007\/978-3-642-40349-1_22","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2013","author":"B G\u00e9rard","year":"2013","unstructured":"G\u00e9rard, B., Grosso, V., Naya-Plasencia, M., Standaert, F.-X.: Block ciphers that are easier to mask: how far can we go? In: Bertoni, G., Coron, J.-S. (eds.) CHES 2013. LNCS, vol. 8086, pp. 383\u2013399. Springer, Heidelberg (2013)"},{"key":"6_CR10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael: AES-the Advanced Encryption Standard","author":"J Daemen","year":"2002","unstructured":"Daemen, J., Rijmen, V.: The Design of Rijndael: AES-the Advanced Encryption Standard. Springer, Heidelberg (2002)"},{"key":"6_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1007\/978-3-662-45611-8_4","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2014","author":"A Biryukov","year":"2014","unstructured":"Biryukov, A., Bouillaguet, C., Khovratovich, D.: Cryptographic schemes based on the \n                      \n                        \n                      \n                      $${\\sf ASASA}$$\n                      \n                        \n                          ASASA\n                        \n                      \n                     structure:\u00a0black-box,\u00a0white-box, and\u00a0public-key (extended abstract). In: Sarkar, P., Iwata, T. (eds.) ASIACRYPT 2014. LNCS, vol. 8873, pp. 63\u201384. Springer, Heidelberg (2014)"},{"key":"6_CR12","unstructured":"U.S. DEPARTMENT: OF COMMERCE\/National Institute of Standards and Technology: Data encryption standard. Publication, Federal Information Processing Standards (1999)"},{"key":"6_CR13","unstructured":"National Security Agency, N.S.A.: SKIPJACK and KEA Algorithm Specifications (1998)"},{"key":"6_CR14","unstructured":"Beaulieu, R., Shors, D., Smith, J., Treatman-Clark, S., Weeks, B., Wingers, L.: The simon and speck families of lightweight block ciphers. IACR Cryptology ePrint Archive 2013, 404 (2013)"},{"issue":"3","key":"6_CR15","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1147\/rd.383.0243","volume":"38","author":"D Coppersmith","year":"1994","unstructured":"Coppersmith, D.: The Data Encryption Standard (DES) and its strength against attacks. IBM J. Res. Dev. 38(3), 243\u2013250 (1994)","journal-title":"IBM J. Res. Dev."},{"key":"6_CR16","series-title":"Lecture Notes in Computer Science","first-page":"394","volume-title":"Advances in Cryptology - EUROCRYPT 2001","author":"A Biryukov","year":"2001","unstructured":"Biryukov, A., Shamir, A.: Structural cryptanalysis of SASAS. In: Pfitzmann, B. (ed.) EUROCRYPT 2001. LNCS, vol. 2045, pp. 394\u2013405. Springer, Heidelberg (2001)"},{"key":"6_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/978-3-540-45146-4_30","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"J Patarin","year":"2003","unstructured":"Patarin, J.: Luby-Rackoff: 7 rounds are enough for formula \n                      \n                        \n                      \n                      $$2^{n(1-\\epsilon )}$$\n                      \n                        \n                          \n                            2\n                            \n                              n\n                              (\n                              1\n                              -\n                              \u03f5\n                              )\n                            \n                          \n                        \n                      \n                     security. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 513\u2013529. Springer, Heidelberg (2003)"},{"issue":"4","key":"6_CR18","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/s00145-005-0129-3","volume":"18","author":"E Biham","year":"2005","unstructured":"Biham, E., Biryukov, A., Shamir, A.: Cryptanalysis of skipjack reduced to 31 rounds using impossible differentials. J. Cryptology 18(4), 291\u2013311 (2005)","journal-title":"J. Cryptology"},{"key":"6_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/3-540-48405-1_11","volume-title":"Advances in Cryptology - CRYPTO \u201999","author":"LR Knudsen","year":"1999","unstructured":"Knudsen, L.R., Robshaw, M., Wagner, D.: Truncated differentials and skipjack. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 165\u2013180. Springer, Heidelberg (1999)"},{"issue":"1","key":"6_CR20","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1016\/S0166-218X(00)00347-4","volume":"111","author":"L Knudsen","year":"2001","unstructured":"Knudsen, L., Wagner, D.: On the structure of skipjack. Discrete Appl. Math. 111(1), 103\u2013116 (2001)","journal-title":"Discrete Appl. Math."},{"key":"6_CR21","first-page":"33","volume":"518","author":"K Browning","year":"2010","unstructured":"Browning, K., Dillon, J., McQuistan, M., Wolfe, A.: An apn permutation in dimension six. Finite Fields: Theory Appl. 518, 33\u201342 (2010)","journal-title":"Finite Fields: Theory Appl."},{"issue":"3","key":"6_CR22","first-page":"221","volume":"1","author":"J Daemen","year":"2007","unstructured":"Daemen, J., Rijmen, V.: Probability distributions of correlation and differentials in block ciphers. J. Math. Cryptology JMC 1(3), 221\u2013242 (2007)","journal-title":"J. Math. Cryptology JMC"},{"key":"6_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/3-540-60590-8_10","volume-title":"Fast Software Encryption","author":"L O\u2019Connor","year":"1995","unstructured":"O\u2019Connor, L.: Properties of linear approximation tables. In: Preneel, B. (ed.) FSE 1995. LNCS, vol. 1008, pp. 131\u2013136. Springer, Heidelberg (1995)"},{"key":"6_CR24","unstructured":"Brickell, E.F., Denning, D.E., Kent, S.T., Maher, D.P., Tuchman, W.: Skipjack review: Interim report (1993)"},{"key":"6_CR25","unstructured":"Anonymous: This looks like it might be interesting. sci.crypt (usenet), August 1995. \n                      https:\/\/groups.google.com\/forum\/#!msg\/sci.crypt\/vLtuBDoqPfc\/jm6MshFbomgJ"},{"key":"6_CR26","unstructured":"Schneier, B.: The S-1 Algorithm. mail to the cypherpunk mailing list (1995). \n                      http:\/\/cypherpunks.venona.com\/date\/1995\/09\/msg00315.html"},{"key":"6_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"22","DOI":"10.1007\/3-540-38424-3_2","volume-title":"Advances in Cryptology - CRYPTO \u201990","author":"H Gilbert","year":"1991","unstructured":"Gilbert, H., Chass\u00e9, G.: A statistical attack of the FEAL-8 cryptosystem. In: Menezes, A., Vanstone, S.A. (eds.) CRYPTO 1990. LNCS, vol. 537, pp. 22\u201333. Springer, Heidelberg (1991)"},{"key":"6_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1007\/3-540-46766-1_12","volume-title":"Advances in Cryptology - CRYPTO \u201991","author":"A Tardy-Corfdir","year":"1992","unstructured":"Tardy-Corfdir, A., Gilbert, H.: A known plaintext attack of FEAL-4 and FEAL-6. In: Feigenbaum, J. (ed.) CRYPTO 1991. LNCS, vol. 576, pp. 172\u2013182. Springer, Heidelberg (1992)"},{"key":"6_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1007\/3-540-47555-9_7","volume-title":"Advances in Cryptology - EUROCRYPT \u201992","author":"M Matsui","year":"1993","unstructured":"Matsui, M., Yamagishi, A.: A new method for known plaintext attack of FEAL cipher. In: Rueppel, R.A. (ed.) EUROCRYPT 1992. LNCS, vol. 658, pp. 81\u201391. Springer, Heidelberg (1993)"},{"key":"6_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/3-540-45682-1_14","volume-title":"Advances in Cryptology - ASIACRYPT 2001","author":"J Patarin","year":"2001","unstructured":"Patarin, J.: Generic attacks on feistel schemes. In: Boyd, C. (ed.) ASIACRYPT 2001. LNCS, vol. 2248, pp. 222\u2013238. Springer, Heidelberg (2001)"},{"key":"6_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/3-540-45661-9_11","volume-title":"Fast Software Encryption","author":"R Wernsdorf","year":"2002","unstructured":"Wernsdorf, R.: The round functions of RIJNDAEL generate the alternating group. In: Daemen, J., Rijmen, V. (eds.) FSE 2002. LNCS, vol. 2365, pp. 143\u2013148. Springer, Heidelberg (2002)"},{"issue":"2","key":"6_CR32","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1504\/IJICOT.2010.032132","volume":"1","author":"C Blondeau","year":"2010","unstructured":"Blondeau, C., Canteaut, A., Charpin, P.: Differential properties of power functions. Int. J. Inf. Coding Theory 1(2), 149\u2013170 (2010)","journal-title":"Int. J. Inf. Coding Theory"},{"issue":"12","key":"6_CR33","doi-asserted-by":"publisher","first-page":"1676","DOI":"10.1016\/j.jsc.2008.02.005","volume":"44","author":"F Jean-Charles","year":"2009","unstructured":"Jean-Charles, F., Perret, L.: An efficient algorithm for decomposing multivariate polynomials and its applications to cryptography. J. Symbolic Comput. 44(12), 1676\u20131689 (2009)","journal-title":"J. Symbolic Comput."},{"issue":"2","key":"6_CR34","doi-asserted-by":"publisher","first-page":"373","DOI":"10.1137\/0217022","volume":"17","author":"M Luby","year":"1988","unstructured":"Luby, M., Rackoff, C.: How to construct pseudorandom permutations from pseudorandom functions. SIAM J. Comput. 17(2), 373\u2013386 (1988)","journal-title":"SIAM J. Comput."},{"key":"6_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"301","DOI":"10.1007\/3-540-46766-1_25","volume-title":"Advances in Cryptology - CRYPTO \u201991","author":"J Patarin","year":"1992","unstructured":"Patarin, J.: New results on pseudorandom permutation generators based on the DES scheme. In: Feigenbaum, J. (ed.) CRYPTO 1991. LNCS, vol. 576, pp. 301\u2013312. Springer, Heidelberg (1992)"},{"key":"6_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-540-28628-8_7","volume-title":"Advances in Cryptology \u2013 CRYPTO 2004","author":"J Patarin","year":"2004","unstructured":"Patarin, J.: Security of random feistel schemes with 5 or more rounds. In: Franklin, M. (ed.) CRYPTO 2004. LNCS, vol. 3152, pp. 106\u2013122. Springer, Heidelberg (2004)"},{"key":"6_CR37","unstructured":"Een, N., S\u00f6rensson, N.: Minisat: A sat solver with conflict-clause minimization. Sat 5 (2005)"},{"key":"6_CR38","unstructured":"Biryukov, A., Leurent, G., Perrin, L.: ESC 2015 S-box Reverse-Engineering Challenge. In: Early Symmetric Crypto, ESC 2015, pp. 104\u2013107 (2015)"},{"key":"6_CR39","unstructured":"Canteaut, A.: Analyse et Conception de Chiffrements \u00e0 Clef Secr\u00e8te. Habilitation \u00e0 diriger des recherches, Institut National de Recherche en Informatique et Automatique, Rocquencourt, September 2006"},{"key":"6_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-74619-5_12","volume-title":"Fast Software Encryption","author":"T Shirai","year":"2007","unstructured":"Shirai, T., Shibutani, K., Akishita, T., Moriai, S., Iwata, T.: The 128-Bit blockcipher CLEFIA (extended abstract). In: Biryukov, A. (ed.) FSE 2007. LNCS, vol. 4593, pp. 181\u2013195. Springer, Heidelberg (2007)"},{"key":"6_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-58108-1_1","volume-title":"Fast Software Encryption","author":"JL Massey","year":"1994","unstructured":"Massey, J.L.: Safer k-64: A byte-oriented block-ciphering algorithm. In: Anderson, R. (ed.) FSE 1993. LNCS, vol. 809, pp. 1\u201317. Springer, Heidelberg (1994)"},{"key":"6_CR42","unstructured":"Stein, W., et al.: Sage Mathematics Software (Version 5.10). The Sage Development Team (2013). \n                      http:\/\/www.sagemath.org"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology -- CRYPTO 2015"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-47989-6_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,9]],"date-time":"2019-08-09T20:03:28Z","timestamp":1565381008000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-47989-6_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783662479889","9783662479896"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-47989-6_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"1 August 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}