{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:03:01Z","timestamp":1784361781146,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":69,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819230174","type":"print"},{"value":"9789819230181","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-3018-1_5","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T07:26:08Z","timestamp":1784359568000},"page":"123-141","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["SoK: The Cryptanalysis of\u00a0SHA-3 Standard"],"prefix":"10.1007","author":[{"given":"Hailun","family":"Yan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anze","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiahao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zheng","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"5_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-642-18178-8_5","volume-title":"Information Security","author":"E Andreeva","year":"2011","unstructured":"Andreeva, E., Mennink, B., Preneel, B.: Security reductions of the second round SHA-3 candidates. In: Burmester, M., Tsudik, G., Magliveras, S., Ili\u0107, I. (eds.) ISC 2010. LNCS, vol. 6531, pp. 39\u201353. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-18178-8_5"},{"key":"5_CR2","unstructured":"Aumasson, J.P., Meier, W.: Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi. Technical note, FHNW, Windisch, Switzerland (2009). https:\/\/www.aumasson.jp\/data\/papers\/AM09.pdf. Accessed 23 Feb 2026"},{"key":"5_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-78967-3_11","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2008","author":"G Bertoni","year":"2008","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: On the indifferentiability of the sponge construction. In: Smart, N. (ed.) EUROCRYPT 2008. LNCS, vol. 4965, pp. 181\u2013197. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78967-3_11"},{"key":"5_CR4","unstructured":"Bertoni, G., Daemen, J., Peeters, M., et\u00a0al.: Sponge functions. ECRYPT Hash Workshop 2007, available as public comment to NIST (2007). https:\/\/csrc.nist.rip\/groups\/ST\/hash\/documents\/JoanDaemen.pdf. Accessed 23 Feb 2026"},{"key":"5_CR5","unstructured":"Bertoni, G., Daemen, J., Peeters, M., et\u00a0al.: The Keccak Crunchy Crypto Collision and Pre-image Contest. The Keccak Team (2011). https:\/\/keccak.team\/crunchy_contest.html. Accessed 06 Feb 2026"},{"key":"5_CR6","unstructured":"Bertoni, G., Daemen, J., Peeters, M., et\u00a0al.: The Keccak Reference. Submission to NIST (Round 3) (2011). https:\/\/keccak.team\/files\/Keccak-reference-3.0.pdf, version 3.0. Accessed 06 Feb 2026"},{"issue":"6","key":"5_CR7","doi-asserted-by":"publisher","first-page":"1271","DOI":"10.1007\/S10623-018-0526-X","volume":"87","author":"W Bi","year":"2019","unstructured":"Bi, W., Dong, X., Li, Z., et al.: MILP-aided cube-attack-like cryptanalysis on Keccak keyed modes. Des. Codes Crypt. 87(6), 1271\u20131296 (2019). https:\/\/doi.org\/10.1007\/S10623-018-0526-X","journal-title":"Des. Codes Crypt."},{"key":"5_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"552","DOI":"10.1007\/978-3-030-34578-5_20","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2019","author":"X Bonnetain","year":"2019","unstructured":"Bonnetain, X., Hosoyamada, A., Naya-Plasencia, M., Sasaki, Yu., Schrottenloher, A.: Quantum attacks without superposition queries: the offline Simon\u2019s algorithm. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019. LNCS, vol. 11921, pp. 552\u2013583. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34578-5_20"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-19574-7_1","volume-title":"Selected Areas in Cryptography","author":"C Boura","year":"2011","unstructured":"Boura, C., Canteaut, A.: Zero-sum distinguishers for iterated permutations and application to Keccak-f and Hamsi-256. In: Biryukov, A., Gong, G., Stinson, D.R. (eds.) SAC 2010. LNCS, vol. 6544, pp. 1\u201317. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19574-7_1"},{"key":"5_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-642-21702-9_15","volume-title":"Fast Software Encryption","author":"C Boura","year":"2011","unstructured":"Boura, C., Canteaut, A., De Canni\u00e8re, C.: Higher-order differential properties of Keccak and Luffa. In: Joux, A. (ed.) FSE 2011. LNCS, vol. 6733, pp. 252\u2013269. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-21702-9_15"},{"key":"5_CR11","doi-asserted-by":"publisher","unstructured":"Chaigneau, C., et al.: Key-recovery attacks on full kravatte. IACR Trans. Symmetric Cryptol. 2018(1), 5\u201328 (2018). https:\/\/doi.org\/10.13154\/TOSC.V2018.I1.5-28","DOI":"10.13154\/TOSC.V2018.I1.5-28"},{"key":"5_CR12","doi-asserted-by":"publisher","unstructured":"Che, C., Tian, T.: Enhancing the DATF technique in differential-linear cryptanalysis. In: Advances in Cryptology - ASIACRYPT 2025. LNCS, pp. 352\u2013382. Springer (2025). https:\/\/doi.org\/10.1007\/978-981-95-5018-0_12","DOI":"10.1007\/978-981-95-5018-0_12"},{"key":"5_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/978-3-030-81652-0_7","volume-title":"Selected Areas in Cryptography","author":"T Cui","year":"2021","unstructured":"Cui, T., Grassi, L.: Algebraic key-recovery attacks on\u00a0reduced-round Xoofff. In: Dunkelman, O., Jacobson, Jr., M.J., O\u2019Flynn, C. (eds.) SAC 2020. LNCS, vol. 12804, pp. 171\u2013197. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81652-0_7"},{"issue":"6","key":"5_CR14","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/C-M.1977.217750","volume":"10","author":"W Diffie","year":"1977","unstructured":"Diffie, W., Hellman, M.E.: Special feature exhaustive cryptanalysis of the NBS data encryption standard. Computer 10(6), 74\u201384 (1977). https:\/\/doi.org\/10.1109\/C-M.1977.217750","journal-title":"Computer"},{"key":"5_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1007\/978-3-030-77870-5_14","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"I Dinur","year":"2021","unstructured":"Dinur, I.: Cryptanalytic applications of the polynomial method for solving multivariate equation systems over GF(2). In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021. LNCS, vol. 12696, pp. 374\u2013403. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_14"},{"key":"5_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"442","DOI":"10.1007\/978-3-642-34047-5_25","volume-title":"Fast Software Encryption","author":"I Dinur","year":"2012","unstructured":"Dinur, I., Dunkelman, O., Shamir, A.: New attacks on Keccak-224 and Keccak-256. In: Canteaut, A. (ed.) FSE 2012. LNCS, vol. 7549, pp. 442\u2013461. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34047-5_25"},{"key":"5_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-662-43933-3_12","volume-title":"Fast Software Encryption","author":"I Dinur","year":"2014","unstructured":"Dinur, I., Dunkelman, O., Shamir, A.: Collision attacks on up to 5 rounds of SHA-3 using generalized internal differentials. In: Moriai, S. (ed.) FSE 2013. LNCS, vol. 8424, pp. 219\u2013240. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43933-3_12"},{"key":"5_CR18","doi-asserted-by":"publisher","unstructured":"Dinur, I., Dunkelman, O., Shamir, A.: Improved practical attacks on round-reduced Keccak. J. Cryptol. 27(2), 183\u2013209 (2014). https:\/\/doi.org\/10.1007\/S00145-012-9142-5D","DOI":"10.1007\/S00145-012-9142-5"},{"key":"5_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"733","DOI":"10.1007\/978-3-662-46800-5_28","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2015","author":"I Dinur","year":"2015","unstructured":"Dinur, I., Morawiecki, P., Pieprzyk, J., Srebrny, M., Straus, M.: Cube attacks and cube-attack-like cryptanalysis on the round-reduced Keccak sponge function. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9056, pp. 733\u2013761. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46800-5_28"},{"key":"5_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"490","DOI":"10.1007\/978-3-662-48800-3_20","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2015","author":"C Dobraunig","year":"2015","unstructured":"Dobraunig, C., Eichlseder, M., Mendel, F.: Heuristic tool for linear cryptanalysis with applications to CAESAR candidates. In: Iwata, T., Cheon, J.H. (eds.) ASIACRYPT 2015. LNCS, vol. 9453, pp. 490\u2013509. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48800-3_20"},{"issue":"6","key":"5_CR21","doi-asserted-by":"publisher","first-page":"694","DOI":"10.1007\/s11434-011-4909-x","volume":"57","author":"M Duan","year":"2012","unstructured":"Duan, M., Lai, X.: Improved zero-sum distinguisher for full round Keccak-F permutation. Chin. Sci. Bull. 57(6), 694\u2013697 (2012). https:\/\/doi.org\/10.1007\/s11434-011-4909-x","journal-title":"Chin. Sci. Bull."},{"key":"5_CR22","unstructured":"Dunkelman, O., Weizman, A.: Differential-linear cryptanalysis on xoodyak. In: NIST LWC Workshop (2022). https:\/\/csrc.nist.gov\/csrc\/media\/Events\/2022\/lightweight-cryptography-workshop-2022\/documents\/papers\/differential-linear-cryptanalysis-on-xoodyak.pdf"},{"key":"5_CR23","doi-asserted-by":"publisher","unstructured":"Fuhr, T., Naya-Plasencia, M., Rotella, Y.: State-recovery attacks on modified Ketje Jr. IACR Trans. Symmetric Cryptol. 2018(1), 29\u201356 (2018). https:\/\/doi.org\/10.13154\/tosc.v2018.i1.29-56","DOI":"10.13154\/tosc.v2018.i1.29-56"},{"key":"5_CR24","doi-asserted-by":"publisher","unstructured":"Fuhr, T., Naya-Plasencia, M., Rotella, Y.: State-recovery attacks on modified Ketje Jr. IACR Trans. Symmetric Cryptol. 2018(1), 29\u201356 (2018). https:\/\/doi.org\/10.13154\/TOSC.V2018.I1.29-56","DOI":"10.13154\/TOSC.V2018.I1.29-56"},{"issue":"1","key":"5_CR25","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1007\/S00145-019-09313-3","volume":"33","author":"J Guo","year":"2020","unstructured":"Guo, J., Liao, G., Liu, G., et al.: Practical collision attacks against round-reduced SHA-3. J. Cryptol. 33(1), 228\u2013270 (2020). https:\/\/doi.org\/10.1007\/S00145-019-09313-3","journal-title":"J. Cryptol."},{"key":"5_CR26","doi-asserted-by":"publisher","unstructured":"Guo, J., Liu, G., Song, L., et\u00a0al.: Exploring SAT for cryptanalysis: (quantum) collision attacks against 6-round SHA-3. In: Imai, H., Takagi, T. (eds.) ASIACRYPT 2022. LNCS, vol. 13793, pp. 645\u2013674. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22969-5_22","DOI":"10.1007\/978-3-031-22969-5_22"},{"key":"5_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-662-53887-6_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"J Guo","year":"2016","unstructured":"Guo, J., Liu, M., Song, L.: Linear structures: applications to cryptanalysis of round-reduced Keccak. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. LNCS, vol. 10031, pp. 249\u2013274. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_9"},{"key":"5_CR28","doi-asserted-by":"publisher","unstructured":"He, L., Lin, X., Yu, H.: Improved preimage attacks on 4-round Keccak-224\/256. IACR Trans. Symmetric Cryptol. 2021(1), 217\u2013238 (2021). https:\/\/doi.org\/10.46586\/TOSC.V2021.I1.217-238","DOI":"10.46586\/TOSC.V2021.I1.217-238"},{"issue":"3","key":"5_CR29","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/S10623-025-01780-Z","volume":"94","author":"L He","year":"2026","unstructured":"He, L., Lin, X., Yu, H.: Improved preimage attacks on round-reduced Keccak-384\/512. Des. Codes Cryptography. 94(3), 55 (2026). https:\/\/doi.org\/10.1007\/S10623-025-01780-Z","journal-title":"Des. Codes Cryptography."},{"key":"5_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-642-33260-9_4","volume-title":"Computer Information Systems and Industrial Management","author":"E Homsirikamol","year":"2012","unstructured":"Homsirikamol, E., Morawiecki, P., Rogawski, M., Srebrny, M.: Security margin evaluation of SHA-3 contest finalists through SAT-based attacks. In: Cortesi, A., Chaki, N., Saeed, K., Wierzcho\u0144, S. (eds.) CISIM 2012. LNCS, vol. 7564, pp. 56\u201367. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33260-9_4"},{"key":"5_CR31","doi-asserted-by":"publisher","unstructured":"Hu, K., Peyrin, T., Tan, Q.Q., Yap, T.: Revisiting higher-order differential-linear attacks from an algebraic perspective. In: Advances in Cryptology - ASIACRYPT 2023. LNCS, pp. 405\u2013435. Springer (2023). https:\/\/doi.org\/10.1007\/978-981-99-8727-6_14","DOI":"10.1007\/978-981-99-8727-6_14"},{"key":"5_CR32","doi-asserted-by":"publisher","unstructured":"Huang, S., Ben-Yehuda, O.A., Dunkelman, O., et\u00a0al.: Finding collisions against 4-round SHA-3-384 in practical time. IACR Trans. Symmetric Cryptol. 2022(3), 239\u2013270 (2022). https:\/\/doi.org\/10.46586\/TOSC.V2022.I3.239-270","DOI":"10.46586\/TOSC.V2022.I3.239-270"},{"key":"5_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-319-56614-6_9","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"S Huang","year":"2017","unstructured":"Huang, S., Wang, X., Xu, G., Wang, M., Zhao, J.: Conditional cube attack on reduced-round Keccak sponge function. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10211, pp. 259\u2013288. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56614-6_9"},{"key":"5_CR34","unstructured":"Jean, J.: TikZ for Cryptographers. International Association for Cryptologic Research (IACR) (2016). https:\/\/www.iacr.org\/authors\/tikz\/. Accessed 06 Feb 2026"},{"key":"5_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/978-3-662-48116-5_26","volume-title":"Fast Software Encryption","author":"J Jean","year":"2015","unstructured":"Jean, J., Nikoli\u0107, I.: Internal differential boomerangs: practical analysis of the round-reduced Keccak-$$f$$ permutation. In: Leander, G. (ed.) FSE 2015. LNCS, vol. 9054, pp. 537\u2013556. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48116-5_26"},{"key":"5_CR36","doi-asserted-by":"publisher","unstructured":"Lefevre, C., Mennink, B.: Tight preimage resistance of the sponge construction. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022. LNCS, pp. 185\u2013204. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-15985-5_7","DOI":"10.1007\/978-3-031-15985-5_7"},{"key":"5_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"556","DOI":"10.1007\/978-3-030-17659-4_19","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"T Li","year":"2019","unstructured":"Li, T., Sun, Y.: Preimage attacks on round-reduced Keccak-224\/256 via an allocating approach. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11478, pp. 556\u2013584. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17659-4_19"},{"key":"5_CR38","doi-asserted-by":"publisher","unstructured":"Li, T., Sun, Y., Liao, M., et\u00a0al.: Preimage attacks on the round-reduced Keccak with cross-linear structures. IACR Trans. Symmetric Cryptol. 2017(4), 39\u201357 (2017). https:\/\/doi.org\/10.13154\/tosc.v2017.i4.39-57","DOI":"10.13154\/tosc.v2017.i4.39-57"},{"key":"5_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-319-70694-8_4","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"Z Li","year":"2017","unstructured":"Li, Z., Bi, W., Dong, X., Wang, X.: Improved conditional cube attacks on Keccak keyed modes with MILP method. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10624, pp. 99\u2013127. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70694-8_4"},{"key":"5_CR40","doi-asserted-by":"publisher","unstructured":"Li, Z., Dong, X., Bi, W., et\u00a0al.: New conditional cube attack on Keccak keyed modes. IACR Trans. Symmetric Cryptol. 2019(2), 94\u2013124 (2019). https:\/\/doi.org\/10.13154\/tosc.v2019.i2.94-124","DOI":"10.13154\/tosc.v2019.i2.94-124"},{"issue":"9","key":"5_CR41","doi-asserted-by":"publisher","first-page":"3761","DOI":"10.1007\/S10623-025-01655-3","volume":"93","author":"X Lin","year":"2025","unstructured":"Lin, X., He, L., Lu, Z., et al.: Internal differential structure: preimage attacks on up to 5-round Keccak. Des. Codes Crypt. 93(9), 3761\u20133808 (2025). https:\/\/doi.org\/10.1007\/S10623-025-01655-3","journal-title":"Des. Codes Crypt."},{"key":"5_CR42","doi-asserted-by":"publisher","unstructured":"Lin, X., He, L., Yu, H.: Practical preimage attacks on 3-round Keccak-256 and 4-round Keccak[r=640, c=160]. IACR Trans. Symmetric Cryptol. 2025(1), 328\u2013356 (2025). https:\/\/doi.org\/10.46586\/TOSC.V2025.I1.328-356","DOI":"10.46586\/TOSC.V2025.I1.328-356"},{"key":"5_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/978-3-030-26834-3_17","volume-title":"Advances in Information and Computer Security","author":"F Liu","year":"2019","unstructured":"Liu, F., Cao, Z., Wang, G.: Finding ordinary cube variables for Keccak-MAC with greedy algorithm. In: Attrapadung, N., Yagi, T. (eds.) IWSEC 2019. LNCS, vol. 11689, pp. 287\u2013305. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26834-3_17"},{"key":"5_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1007\/978-3-030-90567-5_5","volume-title":"Information Security and Privacy","author":"F Liu","year":"2021","unstructured":"Liu, F., Isobe, T., Meier, W., Yang, Z.: Algebraic attacks on round-reduced Keccak. In: Baek, J., Ruj, S. (eds.) ACISP 2021. LNCS, vol. 13083, pp. 91\u2013110. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-90567-5_5"},{"key":"5_CR45","doi-asserted-by":"publisher","unstructured":"Liu, M., Hou, C., Lu, X., Wang, S., Lin, D.: Differential-linear cryptanalysis from an algebraic perspective. J. Cryptol. 39(1), 7 (2026). https:\/\/doi.org\/10.1007\/S00145-025-09564-3","DOI":"10.1007\/S00145-025-09564-3"},{"key":"5_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-662-43933-3_13","volume-title":"Fast Software Encryption","author":"P Morawiecki","year":"2014","unstructured":"Morawiecki, P., Pieprzyk, J., Srebrny, M.: Rotational cryptanalysis of round-reduced Keccak. In: Moriai, S. (ed.) FSE 2013. LNCS, vol. 8424, pp. 241\u2013262. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43933-3_13"},{"key":"5_CR47","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Secure hash standard (SHS). FIPS Publication 180-1, National Institute of Standards and Technology, Gaithersburg, MD, USA (1995). https:\/\/doi.org\/10.6028\/NIST.FIPS.180-1","DOI":"10.6028\/NIST.FIPS.180-1"},{"key":"5_CR48","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Third-round report of the SHA-3 cryptographic hash algorithm competition. NIST interagency report (NIST IR 7896), National Institute of Standards and Technology, Gaithersburg, MD, USA (2012). https:\/\/doi.org\/10.6028\/NIST.IR.7896","DOI":"10.6028\/NIST.IR.7896"},{"key":"5_CR49","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: Secure hash standard (SHS). FIPS Publication 180-4, National Institute of Standards and Technology, Gaithersburg, MD, USA (2015). https:\/\/doi.org\/10.6028\/NIST.FIPS.180-4","DOI":"10.6028\/NIST.FIPS.180-4"},{"key":"5_CR50","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: SHA-3 standard: permutation-based hash and extendable-output functions. FIPS Publication\u00a0202, National Institute of Standards and Technology, Gaithersburg, MD, USA (2015). https:\/\/doi.org\/10.6028\/NIST.FIPS.202","DOI":"10.6028\/NIST.FIPS.202"},{"key":"5_CR51","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: SHA-3 derived functions: cSHAKE, KMAC, TupleHash, and ParallelHash. NIST SP 800-185, National Institute of Standards and Technology, Gaithersburg, MD, USA (2016). https:\/\/doi.org\/10.6028\/NIST.SP.800-185","DOI":"10.6028\/NIST.SP.800-185"},{"key":"5_CR52","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1007\/978-3-642-25578-6_18","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2011","author":"M Naya-Plasencia","year":"2011","unstructured":"Naya-Plasencia, M., R\u00f6ck, A., Meier, W.: Practical analysis of reduced-round Keccak. In: Bernstein, D.J., Chatterjee, S. (eds.) INDOCRYPT 2011. LNCS, vol. 7107, pp. 236\u2013254. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25578-6_18"},{"key":"5_CR53","unstructured":"Next-generation Commercial Cryptographic Algorithms Program (NGCC): Call for proposals for the next-generation cryptographic hash algorithms. Institute of Commercial Cryptography Standards, China (2025). https:\/\/www.niccs.org.cn\/niccs\/Notice\/pc\/content\/content_1975892908773478400.html. Accessed 05 Feb 2026"},{"key":"5_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1007\/978-3-642-14623-7_20","volume-title":"Advances in Cryptology \u2013 CRYPTO 2010","author":"T Peyrin","year":"2010","unstructured":"Peyrin, T.: Improved differential attacks for ECHO and Gr\u00f8stl. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 370\u2013392. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_20"},{"key":"5_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/978-3-319-56617-7_8","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"K Qiao","year":"2017","unstructured":"Qiao, K., Song, L., Liu, M., Guo, J.: New collision attacks on round-reduced Keccak. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10212, pp. 216\u2013243. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56617-7_8"},{"key":"5_CR56","doi-asserted-by":"publisher","unstructured":"Qin, L., Hua, J., Dong, X., et\u00a0al.: Meet-in-the-middle preimage attacks on sponge-based hashing. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. LNCS, vol. 14007, pp. 158\u2013188. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30634-1_6","DOI":"10.1007\/978-3-031-30634-1_6"},{"key":"5_CR57","doi-asserted-by":"publisher","unstructured":"Qin, L., Zhao, B., Hou, Q., et\u00a0al.: Linear cancellations in the MitM attacks on sponge functions. IACR Trans. Symmetric Cryptol. 2025(3), 633\u2013692 (2025). https:\/\/doi.org\/10.46586\/TOSC.V2025.I3.633-692","DOI":"10.46586\/TOSC.V2025.I3.633-692"},{"key":"5_CR58","doi-asserted-by":"publisher","unstructured":"Song, L., Guo, J.: Cube-attack-like cryptanalysis of round-reduced Keccak using MILP. IACR Trans. Symmetric Cryptol. 2018(3), 182\u2013214 (2018). https:\/\/doi.org\/10.13154\/tosc.v2018.i3.182-214","DOI":"10.13154\/tosc.v2018.i3.182-214"},{"key":"5_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-030-03329-3_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"L Song","year":"2018","unstructured":"Song, L., Guo, J., Shi, D., Ling, S.: New MILP modeling: improved conditional cube attacks on Keccak-based constructions. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11273, pp. 65\u201395. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03329-3_3"},{"key":"5_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-319-63715-0_15","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"L Song","year":"2017","unstructured":"Song, L., Liao, G., Guo, J.: Non-full Sbox linearization: applications to collision attacks on round-reduced Keccak. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017. LNCS, vol. 10402, pp. 428\u2013451. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63715-0_15"},{"key":"5_CR61","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1007\/978-3-319-63688-7_19","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"M Stevens","year":"2017","unstructured":"Stevens, M., Bursztein, E., Karpman, P., Albertini, A., Markov, Y.: The first collision for full SHA-1. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017. LNCS, vol. 10401, pp. 570\u2013596. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63688-7_19"},{"key":"5_CR62","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/11535218_2","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"X Wang","year":"2005","unstructured":"Wang, X., Yin, Y.L., Yu, H.: Finding collisions in the full SHA-1. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol. 3621, pp. 17\u201336. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11535218_2"},{"key":"5_CR63","doi-asserted-by":"publisher","unstructured":"Wei, C., Wu, C., Fu, X., et\u00a0al.: Preimage attacks on 4-round Keccak by solving multivariate quadratic systems. In: Park, J.H., Seo, S. (eds.) Information Security and Cryptology \u2013 ICISC 2021. LNCS, vol. 13218, pp. 195\u2013216. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-031-08896-4_10","DOI":"10.1007\/978-3-031-08896-4_10"},{"issue":"5","key":"5_CR64","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1049\/IET-IFS.2018.5263","volume":"13","author":"HL Yan","year":"2019","unstructured":"Yan, H.L., Lai, X.J., Wang, L., et al.: New zero-sum distinguishers on full 24-round Keccak-f using the division property. IET Inf. Secur. 13(5), 469\u2013478 (2019). https:\/\/doi.org\/10.1049\/IET-IFS.2018.5263","journal-title":"IET Inf. Secur."},{"key":"5_CR65","unstructured":"Ye, C.D., Tian, T.: New insights into divide-and-conquer attacks on the round-reduced Keccak-MAC. Cryptology ePrint Archive, Paper 2018\/059 (2018). https:\/\/eprint.iacr.org\/2018\/059. Accessed 23 Feb 2026"},{"key":"5_CR66","doi-asserted-by":"publisher","unstructured":"Zhang, Z., Hou, C., Liu, M.: Collision attacks on round-reduced SHA-3 using conditional internal differentials. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023. LNCS, vol. 14007, pp. 220\u2013251. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30634-1_8","DOI":"10.1007\/978-3-031-30634-1_8"},{"key":"5_CR67","doi-asserted-by":"publisher","unstructured":"Zhang, Z., Hou, C., Liu, M.: Probabilistic linearization: internal differential collisions in up to 6 rounds of SHA-3. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024. LNCS, vol. 14923, pp. 241\u2013272. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68385-5_8","DOI":"10.1007\/978-3-031-68385-5_8"},{"key":"5_CR68","doi-asserted-by":"publisher","unstructured":"Zhang, Z., Hou, C., Liu, M.: Preimage attacks on up to 5 rounds of SHA-3 using internal differentials. In: Fehr, S., Fouque, P. (eds.) EUROCRYPT 2025. LNCS, vol. 15601, pp. 333\u2013363. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-91107-1_12","DOI":"10.1007\/978-3-031-91107-1_12"},{"key":"5_CR69","doi-asserted-by":"publisher","unstructured":"Zhou, H., Li, Z., Dong, X., Jia, K., Meier, W.: Practical key-recovery attacks on round-reduced KETJE JR, XOODOO-AE and XOODYAK. Comput. J. 63(8), 1231\u20131246 (2020). https:\/\/doi.org\/10.1093\/COMJNL\/BXZ152","DOI":"10.1093\/COMJNL\/BXZ152"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3018-1_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T07:26:12Z","timestamp":1784359572000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3018-1_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819230174","9789819230181"],"references-count":69,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3018-1_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"18 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACISP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australasian Conference on Information Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Perth, WA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acisp2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acisp-conference.github.io\/acisp2026\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}