{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:00:21Z","timestamp":1777489221626,"version":"3.51.4"},"publisher-location":"Berlin, Heidelberg","reference-count":46,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783662498897","type":"print"},{"value":"9783662498903","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-662-49890-3_15","type":"book-chapter","created":{"date-parts":[[2016,4,27]],"date-time":"2016-04-27T00:40:46Z","timestamp":1461717646000},"page":"372-402","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":37,"title":["Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr1"],"prefix":"10.1007","author":[{"given":"Alex","family":"Biryukov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"L\u00e9o","family":"Perrin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aleksei","family":"Udovenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,4,28]]},"reference":[{"key":"15_CR1","series-title":"Information Security and Cryptography","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael: AES-The Advanced Encryption Standard","author":"J Daemen","year":"2002","unstructured":"Daemen, J., Rijmen, V.: The Design of Rijndael: AES-The Advanced Encryption Standard. Information Security and Cryptography. Springer, Heidelberg (2002)"},{"issue":"1","key":"15_CR2","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E Biham","year":"1991","unstructured":"Biham, E., Shamir, A.: Differential cryptanalysis of DES-like cryptosystems. J. Crypt. 4(1), 3\u201372 (1991)","journal-title":"J. Crypt."},{"key":"15_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1007\/3-540-46766-1_12","volume-title":"Advances in Cryptology - CRYPTO 1992","author":"A Tardy-Corfdir","year":"1992","unstructured":"Tardy-Corfdir, A., Gilbert, H.: A known plaintext attack of FEAL-4 and FEAL-6. In: Feigenbaum, J. (ed.) Advances in Cryptology - CRYPTO 1992. LNCS, vol. 576, pp. 172\u2013182. Springer, Berlin Heidelberg (1992)"},{"key":"15_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"386","DOI":"10.1007\/3-540-48285-7_33","volume-title":"Advances in Cryptology - EUROCRYPT 1993","author":"M Matsui","year":"1994","unstructured":"Matsui, M.: Linear cryptanalysis method for DES cipher. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol. 765, pp. 386\u2013397. Springer, Heidelberg (1994)"},{"key":"15_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/3-540-48285-7_6","volume-title":"Advances in Cryptology - EUROCRYPT 1993","author":"K Nyberg","year":"1994","unstructured":"Nyberg, K.: Differentially uniform mappings for cryptography. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol. 765, pp. 55\u201364. Springer, Heidelberg (1994)"},{"key":"15_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"339","DOI":"10.1007\/978-3-642-35999-6_22","volume-title":"Selected Areas in Cryptography","author":"T Suzaki","year":"2013","unstructured":"Suzaki, T., Minematsu, K., Morioka, S., Kobayashi, E.: TWINE : A lightweight block cipher for multiple platforms. In: Knudsen, L.R., Wu, H. (eds.) SAC 2012. LNCS, vol. 7707, pp. 339\u2013354. Springer, Heidelberg (2013)"},{"key":"15_CR7","unstructured":"U.S. Department: OF COMMERCE\/National Institute of Standards and Technology: Data encryption standard. Publication, Federal Information Processing Standards (1999)"},{"issue":"3","key":"15_CR8","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1147\/rd.383.0243","volume":"38","author":"D Coppersmith","year":"1994","unstructured":"Coppersmith, D.: The data encryption standard (DES) and its strength against attacks. IBM J. Res. Develop. 38(3), 243\u2013250 (1994)","journal-title":"IBM J. Res. Develop."},{"key":"15_CR9","unstructured":"National Security Agency, N.S.A.: SKIPJACK and KEA AlgorithmSpecifications (1998)"},{"key":"15_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/978-3-662-47989-6_6","volume-title":"Advances in Cryptology - CRYPTO 2015","author":"A Biryukov","year":"2015","unstructured":"Biryukov, A., Perrin, L.: On reverse-engineering s-boxes with hidden design criteria or structure. In: Gennaro, R., Robshaw, M. (eds.) Advances in Cryptology - CRYPTO 2015. LNCS, vol. 9215, pp. 116\u2013140. Springer, Berlin, Heidelberg (2015)"},{"key":"15_CR11","unstructured":"Federal Agency on Technical Regulation and Metrology: GOST R34.11-2012: Streebog hash function (2012). \n                    https:\/\/www.streebog.net\/"},{"key":"15_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/978-3-319-13051-4_12","volume-title":"Selected Areas in Cryptography - SAC 2014","author":"J Guo","year":"2014","unstructured":"Guo, J., Jean, J., Leurent, G., Peyrin, T., Wang, L.: The usage of counter revisited: second-preimage attack on new russian standardized hash function. In: Joux, A., Youssef, A. (eds.) SAC 2014. LNCS, vol. 8781, pp. 195\u2013211. Springer International Publishing, Switzerland (2014)"},{"issue":"6","key":"15_CR13","doi-asserted-by":"publisher","first-page":"328","DOI":"10.1049\/iet-ifs.2014.0540","volume":"9","author":"R AlTawy","year":"2015","unstructured":"AlTawy, R., Youssef, A.M.: Watch your constants: malicious streebog. IET Inf. Secur. 9(6), 328\u2013333 (2015)","journal-title":"IET Inf. Secur."},{"key":"15_CR14","unstructured":"Rudskoy, V.: Note on Streebog constants origin (2015). \n                    http:\/\/www.tc26.ru\/en\/ISO_IEC\/streebog\/streebog_constants_eng.pdf"},{"key":"15_CR15","unstructured":"Biryukov, A., Perrin, L., Udovenko, A.: Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr 1. Cryptology ePrint Archive, report 2016\/071 (2016). \n                    http:\/\/eprint.iacr.org\/"},{"key":"15_CR16","unstructured":"Shishkin, V., Dygin, D., Lavrikov, I., Marshalko, G., Rudskoy, V., Trifonov, D.: Low-weight and hi-end: draft russian encryption standard. In: Preproceedings of CTCrypt 2014, 05\u201306 June 2014, Moscow. Russia, pp. 183\u2013188 (2014)"},{"key":"15_CR17","unstructured":"Federal Agency on Technical Regulation and Metrology: Block ciphers (2015). \n                    http:\/\/www.tc26.ru\/en\/standard\/draft\/ENG_GOST_R_bsh.pdf"},{"key":"15_CR18","unstructured":"AlTawy, R., Youssef, A.M.: A meet in the middle attack on reduced round Kuznyechik. Cryptology ePrint Archive, report 2015\/096 (2015). \n                    http:\/\/eprint.iacr.org\/"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Dolmatov, V.: GOST 28147\u201389: Encryption, decryption, and message authentication code (MAC) algorithms, RFC 5830, March 2010. \n                    http:\/\/www.rfc-editor.org\/rfc\/rfc5830.txt","DOI":"10.17487\/rfc5830"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Saarinen, M.J.O.: STRIBOB: Authenticated encryption from GOST R 34.11-2012 LPS permutation. In: \n                    \n                   [Mathematical Aspects of Cryptography]. vol.6(2), pp. 67\u201378. Steklov Mathematical Institute ofRussian Academy of Sciences (2015)","DOI":"10.4213\/mvk146"},{"key":"15_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-319-26502-5_8","volume-title":"Secure IT Systems","author":"MJO Saarinen","year":"2015","unstructured":"Saarinen, M.J.O., Brumley, B.B.: WHIRLBOB, the whirlpool based variant of STRIBOB. In: Buchegger, S., Dam, M. (eds.) NordSec 2015. LNCS, vol. 9417, pp. 106\u2013122. Springer International Publishing, Cham (2015)"},{"key":"15_CR22","unstructured":"Barreto, P., Rijmen, V.: The whirlpool hashing function. In: First open NESSIE Workshop, Leuven, Belgium. vol. 13, p. 14 (2000)"},{"key":"15_CR23","unstructured":"Saarinen, M.J.O.: STRIBOBr 2 availability. Mail to the CAESAR mailing list. \n                    https:\/\/groups.google.com\/forum\/#!topic\/crypto-competitions\/_zgi54-NEFM"},{"key":"15_CR24","unstructured":"Shishkin, V.: \n                    \n                  \n          \n                    \n                   (2013). \n                    http:\/\/www.ruscrypto.ru\/resource\/summary\/rc2013\/ruscrypto_2013_066.zip"},{"key":"15_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1007\/3-540-48405-1_11","volume-title":"Advances in Cryptology-CRYPTO 1999","author":"LR Knudsen","year":"1999","unstructured":"Knudsen, L.R., Robshaw, M.J., Wagner, D.: Truncated differentials and skipjack. In: Wiener, M. (ed.) Advances in Cryptology-CRYPTO 1999. LNCS, vol. 1666, pp. 165\u2013180. Springer, Heidelberg (1999)"},{"key":"15_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1007\/3-540-48892-8_27","volume-title":"Selected Areas in Cryptography","author":"E Biham","year":"1999","unstructured":"Biham, E., Biryukov, A., Dunkelman, O., Richardson, E., Shamir, A.: Initial observations on skipjack: cryptanalysis of skipjack-3XOR. In: Tavares, S., Meijer, H. (eds.) SAC 1998. LNCS, vol. 1556, p. 362. Springer, Heidelberg (1999)"},{"issue":"1","key":"15_CR27","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1016\/S0166-218X(00)00347-4","volume":"111","author":"L Knudsen","year":"2001","unstructured":"Knudsen, L., Wagner, D.: On the structure of Skipjack. Discrete Appl. Math. 111(1), 103\u2013116 (2001)","journal-title":"Discrete Appl. Math."},{"key":"15_CR28","unstructured":"Kazymyrov, O., Kazymyrova, V.: Algebraic aspects of the russian hash standard GOST R 34.11-2012. In: IACR Cryptology ePrint Archive 2013 556 (2013)"},{"key":"15_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/3-540-44987-6_24","volume-title":"Advances in Cryptology - EUROCRYPT 2001","author":"A Biryukov","year":"2001","unstructured":"Biryukov, A., Shamir, A.: Structural cryptanalysis of SASAS. In: Pfitzmann, B. (ed.) Advances in Cryptology - EUROCRYPT 2001. LNCS, vol. 2045, pp. 395\u2013405. Springer, Berlin Heidelberg (2001)"},{"key":"15_CR30","unstructured":"Dinur, I., Dunkelman, O., Kranz, T., Leander, G.: Decomposing the ASASA block cipher construction. In: Cryptology ePrint Archive, report 2015\/507 (2015). \n                    http:\/\/eprint.iacr.org\/"},{"key":"15_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-662-48800-3_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"B Minaud","year":"2015","unstructured":"Minaud, B., Derbez, P., Fouque, P.A., Karpman, P.: Key-Recovery attacks on ASASA. In: Iwata, T., Cheon, J.H. (eds.) Advances in Cryptology \u2013 ASIACRYPT 2015. LNCS, vol. 9453, pp. 3\u201327. Springer, Heidelberg (2015)"},{"key":"15_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-26617-6","volume-title":"Selected Areas in Cryptography - SAC 2015","author":"A Biryukov","year":"2015","unstructured":"Biryukov, A., Leurent, G., Perrin, L.: Cryptanalysis of Feistel networks with secret round functions. In: Dunkelman, O., Keliher, L. (eds.) SAC 2015. LNCS. Springer International Publishing, Heidelberg (2015)"},{"issue":"3","key":"15_CR33","first-page":"221","volume":"1","author":"J Daemen","year":"2007","unstructured":"Daemen, J., Rijmen, V.: Probability distributions of correlation and differentials in block ciphers. J. Math. Crypt. JMC 1(3), 221\u2013242 (2007)","journal-title":"J. Math. Crypt. JMC"},{"issue":"2","key":"15_CR34","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1504\/IJICOT.2010.032132","volume":"1","author":"C Blondeau","year":"2010","unstructured":"Blondeau, C., Canteaut, A., Charpin, P.: Differential properties of power functions. Int. J. Inf. Coding Theory 1(2), 149\u2013170 (2010)","journal-title":"Int. J. Inf. Coding Theory"},{"key":"15_CR35","unstructured":"Preneel, B.: Analysis and design of cryptographic hash functions. Ph.D. thesis, Katholieke Universiteit Leuven (1993)"},{"key":"15_CR36","unstructured":"The Sage Developers: Sage Mathematics Software (Version 6.8) (2015). \n                    http:\/\/www.sagemath.org"},{"key":"15_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1007\/11545262_32","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2005","author":"D Canright","year":"2005","unstructured":"Canright, D.: A very compact S-Box for AES. In: Rao, J., Sunar, B. (eds.) Cryptographic Hardware and Embedded Systems - CHES 2005. LNCS, vol. 3659, pp. 441\u2013455. Springer, Berlin Heidelberg (2005)"},{"key":"15_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1007\/978-3-642-34961-4_16","volume-title":"Advances in Cryptology - ASIACRYPT 2012","author":"A Bogdanov","year":"2012","unstructured":"Bogdanov, A., Leander, G., Nyberg, K., Wang, M.: Integral and multidimensional linear distinguishers with correlation zero. In: Wang, X., Sako, K. (eds.) Advances in Cryptology - ASIACRYPT 2012. LNCS, vol. 7658, pp. 244\u2013261. Springer, Berlin Heidelberg (2012)"},{"key":"15_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1007\/978-3-642-40349-1_22","volume-title":"Cryptographic Hardware and Embedded Systems - CHES 2013","author":"B G\u00e9rard","year":"2013","unstructured":"G\u00e9rard, B., Grosso, V., Naya-Plasencia, M., Standaert, F.-X.: Block ciphers that are easier to mask: how far can we go? In: Bertoni, G., Coron, J.-S. (eds.) CHES 2013. LNCS, vol. 8086, pp. 383\u2013399. Springer, Heidelberg (2013)"},{"key":"15_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/978-3-540-25937-4_18","volume-title":"Fast Software Encryption","author":"FX Standaert","year":"2004","unstructured":"Standaert, F.X., Piret, G., Rouvroy, G., Quisquater, J.J., Legat, J.D.: ICEBERG : An involutional cipher efficient for block encryption in reconfigurable hardware. In: Roy, B., Meier, W. (eds.) Fast Software Encryption. LNCS, vol. 3017, pp. 279\u2013298. Springer, Berlin Heidelberg (2004)"},{"key":"15_CR41","unstructured":"Barreto, P., Rijmen, V.: The Khazad legacy-level block cipher. In: Primitive submitted to NESSIE 97 (2000)"},{"key":"15_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-74619-5_12","volume-title":"Fast Software Encryption","author":"T Shirai","year":"2007","unstructured":"Shirai, T., Shibutani, K., Akishita, T., Moriai, S., Iwata, T.: The 128-Bit blockcipher CLEFIA (Extended Abstract). In: Biryukov, A. (ed.) FSE 2007. LNCS, vol. 4593, pp. 181\u2013195. Springer, Heidelberg (2007)"},{"key":"15_CR43","doi-asserted-by":"crossref","unstructured":"Grosso, V., Leurent, G., Standaert, F.X., Var\u0131c\u0131, K.: LS-designs: Bitslice encryption for efficient masked software implementations. In: Fast Software Encryption (2014)","DOI":"10.1007\/978-3-662-46706-0_2"},{"key":"15_CR44","series-title":"Lecture Notes in Computer Science","volume-title":"Selected Areas in Cryptography - SAC 2015","author":"A Canteaut","year":"2015","unstructured":"Canteaut, A., Duval, S., Leurent, G.: Construction of lightweight s-boxes using feistel and MISTY structures. In: Dunkelman, O., Keliher, L. (eds.) Selected Areas in Cryptography - SAC 2015. LNCS, vol. 8731. Springer International Publishing, Heidelberg (2015)"},{"key":"15_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/BFb0052334","volume-title":"Fast Software Encryption","author":"M Matsui","year":"1997","unstructured":"Matsui, M.: New block encryption algorithm MISTY. In: Biham, E. (ed.) FSE 1997. LNCS, vol. 1267, pp. 54\u201368. Springer, Berlin, Heidelberg (1997)"},{"key":"15_CR46","unstructured":"Specification of the 3GPP Confidentiality and Integrity Algorithms 128-EEA3 & 128-EIA3. Document 4 : Design and Evaluation Report, Technical report, ETSI\/Sage, September 2011. \n                    http:\/\/www.gsma.com\/aboutus\/wp-content\/uploads\/2014\/12\/EEA3_EIA3_Design_Evaluation_v2_0.pdf"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2016"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-49890-3_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,6]],"date-time":"2020-05-06T20:04:56Z","timestamp":1588795496000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-49890-3_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783662498897","9783662498903"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-49890-3_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"28 April 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}