{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T13:02:53Z","timestamp":1772283773872,"version":"3.50.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[1996,3,1]],"date-time":"1996-03-01T00:00:00Z","timestamp":825638400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. Cryptology"],"published-print":{"date-parts":[[1996,3]]},"DOI":"10.1007\/bf02254789","type":"journal-article","created":{"date-parts":[[2005,11,22]],"date-time":"2005-11-22T21:29:05Z","timestamp":1132694945000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":49,"title":["Substitution-permutation networks resistant to differential and linear cryptanalysis"],"prefix":"10.1007","volume":"9","author":[{"given":"Howard M.","family":"Heys","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stafford E.","family":"Tavares","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"BF02254789_CR1","volume-title":"A Formal and Practical Design Procedure for Substitution-Permutation Network Cryptosystems","author":"C. M. Adams","year":"1990","unstructured":"C. M. Adams. A Formal and Practical Design Procedure for Substitution-Permutation Network Cryptosystems. Ph.D. thesis, Queen's University, Kingston, Ontario, 1990."},{"issue":"2","key":"BF02254789_CR2","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1016\/0020-0190(92)90258-W","volume":"41","author":"C. M. Adams","year":"1992","unstructured":"C. M. Adams. On immunity against Biham and Shamir's differential cryptanalysis.Information Processing Letters, 41(2):77\u201380, 1992.","journal-title":"Information Processing Letters"},{"issue":"1","key":"BF02254789_CR3","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/BF00203967","volume":"3","author":"C. M. Adams","year":"1990","unstructured":"C. M. Adams and S. E. Tavares. The structured design of cryptographically good S-boxes.Journal of Cryptology, 3(1):27\u201341, 1990.","journal-title":"Journal of Cryptology"},{"key":"BF02254789_CR4","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1016\/0167-4048(83)90010-X","volume":"2","author":"F. Ayoub","year":"1982","unstructured":"F. Ayoub. The design of complete encryption networks using cryptographically equivalent permutations.Computers and Security, 2:261\u2013267, 1982.","journal-title":"Computers and Security"},{"issue":"1","key":"BF02254789_CR5","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E. Biham","year":"1991","unstructured":"E. Biham and A. Shamir. Differential cryptanalysis of DES-like cryptosystems.Journal of Cryptology, 4(1):3\u201372, 1991.","journal-title":"Journal of Cryptology"},{"key":"BF02254789_CR6","first-page":"1","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '91","author":"E. Biham","year":"1991","unstructured":"E. Biham and A. Shamir. Differential cryptanalysis of FEAL and N-Hash.Advances in Cryptology: Proceedings of EUROCRYPT '91, Springer-Verlag, Berlin, pages 1\u201316, 1991."},{"key":"BF02254789_CR7","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1007\/3-540-46766-1_11","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '91","author":"E. Biham","year":"1992","unstructured":"E. Biham and A. Shamir. Differential cryptanalysis of Snefru, Khafre, REDOC-II, LOKI, and Lucifer.Advances in Cryptology: Proceedings of CRYPTO '91, Springer-Verlag, Berlin, pages 156\u2013171, 1992."},{"key":"BF02254789_CR8","doi-asserted-by":"crossref","first-page":"487","DOI":"10.1007\/3-540-48071-4_34","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '92","author":"E. Biham","year":"1993","unstructured":"E. Biham and A. Shamir. Differential cryptanalysis of the full 16-round DES.Advances in Cryptology: Proceedings of CRYPTO '92, Springer-Verlag, Berlin, pages 487\u2013496, 1993."},{"key":"BF02254789_CR9","first-page":"3","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '86","author":"E. F. Brickell","year":"1987","unstructured":"E. F. Brickell, J. H. Moore, and M. R. Purtill. Structures in the S-boxes of DES.Advances in Cryptology: Proceedings of CRYPTO '86, Springer-Verlag, Berlin, pages 3\u20138, 1987."},{"key":"BF02254789_CR10","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1007\/BFb0030364","volume-title":"Advances in Cryptology: Proceedings of AUSCRYPT '90","author":"L. Brown","year":"1990","unstructured":"L. Brown, J. Pieprzyk, and J. Seberry. LOKI\u2014a cryptographic primitive for authentication and secrecy applications.Advances in Cryptology: Proceedings of AUSCRYPT '90, Springer-Verlag, Berlin, pages 229\u2013236, 1990."},{"key":"BF02254789_CR11","first-page":"696","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '89","author":"L. Brown","year":"1989","unstructured":"L. Brown and J. R. Seberry. On the design of permutation P in DES type cryptosystems.Advances in Cryptology: Proceedings of EUROCRYPT '89, Springer-Verlag, Berlin, pages 696\u2013705, 1989."},{"key":"BF02254789_CR12","doi-asserted-by":"crossref","first-page":"352","DOI":"10.1007\/3-540-46416-6_30","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '91","author":"M. H. Dawson","year":"1991","unstructured":"M. H. Dawson and S. E. Tavares. An expanded set of S-box design criteria based on information theory and its relation to differential-like attacks.Advances in Cryptology: Proceedings of EUROCRYPT '91, Springer-Verlag, Berlin, pages 352\u2013367, 1991."},{"issue":"5","key":"BF02254789_CR13","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1038\/scientificamerican0573-15","volume":"228","author":"H. Feistel","year":"1973","unstructured":"H. Feistel. Cryptography and computer privacy.Scientific American, 228(5):15\u201323, 1973.","journal-title":"Scientific American"},{"issue":"11","key":"BF02254789_CR14","doi-asserted-by":"crossref","first-page":"1545","DOI":"10.1109\/PROC.1975.10005","volume":"63","author":"H. Feistel","year":"1975","unstructured":"H. Feistel, W. A. Notz, and J. L. Smith. Some cryptographic techniques for machine-to-machine data communications.Proceedings of the IEEE, 63(11):1545\u20131554, 1975.","journal-title":"Proceedings of the IEEE"},{"issue":"3","key":"BF02254789_CR15","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/BF00190799","volume":"2","author":"R. Forr\u00e9","year":"1990","unstructured":"R. Forr\u00e9. Methods and instruments for designing S-boxes.Journal of Cryptology, 2(3):115\u2013130, 1990.","journal-title":"Journal of Cryptology"},{"issue":"10","key":"BF02254789_CR16","doi-asserted-by":"crossref","first-page":"747","DOI":"10.1109\/TC.1979.1675242","volume":"28","author":"J. B. Kam","year":"1979","unstructured":"J. B. Kam and G. I. Davida. A structured design of substitution-permutation encryption networks.IEEE Transactions on Computers, 28(10):747\u2013753, 1979.","journal-title":"IEEE Transactions on Computers"},{"key":"BF02254789_CR17","doi-asserted-by":"crossref","first-page":"497","DOI":"10.1007\/3-540-48071-4_35","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '92","author":"L. R. Knudsen","year":"1993","unstructured":"L. R. Knudsen. Iterative characteristics of DES and s2-DES.Advances in Cryptology: Proceedings of CRYPTO '92, Springer-Verlag, Berlin, pages 497\u2013511, 1993."},{"key":"BF02254789_CR18","doi-asserted-by":"crossref","first-page":"386","DOI":"10.1007\/3-540-48285-7_33","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '93","author":"M. Matsui","year":"1994","unstructured":"M. Matsui. Linear cryptanalysis method for DES cipher.Advances in Cryptology: Proceedings of EUROCRYPT '93, Springer-Verlag, Berlin, pages 386\u2013397, 1994."},{"key":"BF02254789_CR19","first-page":"549","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '89","author":"W. Meier","year":"1990","unstructured":"W. Meier and O. Staffelbach. Nonlinearity criteria for cryptographic functions.Advances in Cryptology: Proceedings of EUROCRYPT '89, Springer-Verlag, Berlin, pages 549\u2013562, 1990."},{"key":"BF02254789_CR20","unstructured":"National Bureau of Standards.Data Encryption Standard (DES). Federal Information Processing Standard Publication 46, U.S. Department of Commerce, January 1977."},{"key":"BF02254789_CR21","doi-asserted-by":"crossref","first-page":"378","DOI":"10.1007\/3-540-46416-6_32","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '91","author":"K. Nyberg","year":"1991","unstructured":"K. Nyberg. Perfect nonlinear S-boxes.Advances in Cryptology: Proceedings of EUROCRYPT '91, Springer-Verlag, Berlin, pages 378\u2013386, 1991."},{"key":"BF02254789_CR22","first-page":"92","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '92","author":"K. Nyberg","year":"1992","unstructured":"K. Nyberg. On the construction of highly nonlinear permutations.Advances in Cryptology: Proceedings of EUROCRYPT '92, Springer-Verlag, Berlin, pages 92\u201398, 1992."},{"key":"BF02254789_CR23","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/3-540-48285-7_6","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '93","author":"K. Nyberg","year":"1994","unstructured":"K. Nyberg. Differentially uniform mappings for cryptography.Advances in Cryptology: Proceedings of EUROCRYPT '93, Springer-Verlag, Berlin, pages 55\u201364, 1994."},{"key":"BF02254789_CR24","volume-title":"An Analysis of Product Ciphers Based on the Properties of Boolean Functions","author":"L. O'Connor","year":"1992","unstructured":"L. O'Connor. An Analysis of Product Ciphers Based on the Properties of Boolean Functions. Ph.D. thesis, University of Waterloo, Ontario, 1992."},{"key":"BF02254789_CR25","first-page":"360","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '93","author":"L. J. O'Connor","year":"1994","unstructured":"L. J. O'Connor. On the distribution of characteristics in bijective mappings.Advances in Cryptology: Proceedings of EUROCRYPT '93, Springer-Verlag, Berlin, pages 360\u2013370, 1994."},{"issue":"6","key":"BF02254789_CR26","first-page":"325","volume":"135","author":"J. Pieprzyk","year":"1988","unstructured":"J. Pieprzyk and G. Finkelstein. Towards effective nonlinear cryptosystem design.IEE Proceedings, Part E, 135(6):325\u2013335, 1988.","journal-title":"IEE Proceedings, Part E"},{"key":"BF02254789_CR27","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1007\/3-540-46877-3_14","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '90","author":"B. Preneel","year":"1991","unstructured":"B. Preneel, W. Van Leekwijck, R. Goevarts, and J. Vanderwalle. Propagation characteristics of boolean functions.Advances in Cryptology: Proceedings of EUROCRYPT '90, Springer-Verlag, Berlin, pages 161\u2013173, 1991."},{"key":"BF02254789_CR28","doi-asserted-by":"crossref","first-page":"656","DOI":"10.1002\/j.1538-7305.1949.tb00928.x","volume":"28","author":"C. E. Shannon","year":"1949","unstructured":"C. E. Shannon. Communication theory of secrecy systems.Bell System Technical Journal, 28:656\u2013715, 1949.","journal-title":"Bell System Technical Journal"},{"key":"BF02254789_CR29","first-page":"267","volume-title":"Advances in Cryptology: Proceedings of EUROCRYPT '87","author":"A. Shimizu","year":"1988","unstructured":"A. Shimizu and S. Miyaguchi. Fast data encipherment algorithm: FEAL.Advances in Cryptology: Proceedings of EUROCRYPT '87, Springer-Verlag, Berlin, pages 267\u2013278, 1988."},{"key":"BF02254789_CR30","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1007\/3-540-48071-4_18","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '92","author":"M. Sivabalan","year":"1993","unstructured":"M. Sivabalan, S. E. Tavares, and L. E. Peppard. On the design of SP networks from an information-theoretic point of view.Advances in Cryptology: Proceedings of CRYPTO '92, Springer-Verlag, Berlin, pages 260\u2013279, 1993."},{"key":"BF02254789_CR31","doi-asserted-by":"crossref","first-page":"523","DOI":"10.1007\/3-540-39799-X_41","volume-title":"Advances in Cryptology: Proceedings of CRYPTO '85","author":"A. F. Webster","year":"1986","unstructured":"A. F. Webster and S. E. Tavares. On the design of S-boxes.Advances in Cryptology: Proceedings of CRYPTO '85, Springer-Verlag, Berlin, pages 523\u2013534, 1986."}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/BF02254789.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/BF02254789\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/BF02254789","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/BF02254789.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,11]],"date-time":"2020-04-11T03:54:07Z","timestamp":1586577247000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/BF02254789"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1996,3]]},"references-count":31,"journal-issue":{"issue":"1","published-print":{"date-parts":[[1996,3]]}},"alternative-id":["BF02254789"],"URL":"https:\/\/doi.org\/10.1007\/bf02254789","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[1996,3]]},"assertion":[{"value":"11 November 1993","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 September 1994","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}