{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T16:39:51Z","timestamp":1779295191124,"version":"3.51.4"},"reference-count":17,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2007,9,14]],"date-time":"2007-09-14T00:00:00Z","timestamp":1189728000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2008,1]]},"DOI":"10.1007\/s00145-007-9013-7","type":"journal-article","created":{"date-parts":[[2007,9,13]],"date-time":"2007-09-13T16:03:31Z","timestamp":1189699411000},"page":"131-147","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":172,"title":["On Probability of Success in Linear and\u00a0Differential\u00a0Cryptanalysis"],"prefix":"10.1007","volume":"21","author":[{"given":"Ali Ayd\u0131n","family":"Sel\u00e7uk","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2007,9,14]]},"reference":[{"key":"9013_CR1","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4613-9314-6","volume-title":"Differential Cryptanalysis of the Data Encryption Standard","author":"E. Biham","year":"1993","unstructured":"E. Biham, A. Shamir, Differential Cryptanalysis of the Data Encryption Standard (Springer, Berlin, 1993)"},{"key":"9013_CR2","series-title":"LNCS","first-page":"12","volume-title":"Advances in Cryptology\u2014Eurocrypt\u201999","author":"E. Biham","year":"1999","unstructured":"E. Biham, A. Biryukov, A. Shamir, Cryptanalysis of skipjack reduced to 31 rounds using impossible differentials, in Advances in Cryptology\u2014Eurocrypt\u201999, ed. by J. Stern. LNCS, vol.\u00a01592 (Springer, Berlin, 1999), pp. 12\u201323"},{"key":"9013_CR3","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1007\/3-540-48519-8_10","volume-title":"Fast Software Encryption, 6th International Workshop","author":"E. Biham","year":"1999","unstructured":"E. Biham, A. Biryukov, A. Shamir, Miss in the middle attacks on IDEA, Khufu, and Khafre, in Fast Software Encryption, 6th International Workshop, ed. by L. Knudsen. LNCS, vol.\u00a01636 (Springer, Berlin, 1999), pp. 124\u2013138"},{"key":"9013_CR4","series-title":"LNCS","first-page":"1","volume-title":"Advances in Cryptology\u2014Crypto\u201904","author":"A. Biryukov","year":"2004","unstructured":"A. Biryukov, C. De Canni\u00e8re, M. Quisquater, On multiple linear approximations, in Advances in Cryptology\u2014Crypto\u201904. LNCS, vol.\u00a03152 (Springer, Berlin, 2004), pp. 1\u201322"},{"key":"9013_CR5","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"328","DOI":"10.1007\/3-540-45473-X_27","volume-title":"Fast Software Encryption, 8th International Workshop","author":"L. Granboulan","year":"2001","unstructured":"L. Granboulan, Flaws in differential cryptanalysis of Skipjack, in Fast Software Encryption, 8th International Workshop, ed. by M. Matsui. LNCS, vol.\u00a02355 (Springer, Berlin, 2001), pp. 328\u2013336"},{"key":"9013_CR6","series-title":"LNCS","first-page":"17","volume-title":"Advances in Cryptology\u2014Crypto\u201994","author":"M. Hellman","year":"1994","unstructured":"M. Hellman, S. Langford, Differential-linear cryptanalysis, in Advances in Cryptology\u2014Crypto\u201994, ed. by Y.G. Desmedt. LNCS, vol.\u00a0839 (Springer, Berlin, 1994), pp. 17\u201325"},{"key":"9013_CR7","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/3-540-45537-X_16","volume-title":"Selected Areas in Cryptography\u201901","author":"P. Junod","year":"2001","unstructured":"P. Junod, On the complexity of Matsui\u2019s attack, in Selected Areas in Cryptography\u201901. LNCS, vol.\u00a02259 (Springer, Berlin, 2001), pp. 199\u2013211"},{"key":"9013_CR8","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1007\/978-3-540-39887-5_18","volume-title":"Fast Software Encryption, 10th International Workshop","author":"P. Junod","year":"2003","unstructured":"P. Junod, S. Vaudenay, Optimal key ranking procedures in a statistical cryptanalysis, in Fast Software Encryption, 10th International Workshop. LNCS, vol.\u00a02887 (Springer, Berlin, 2003), pp. 235\u2013246"},{"key":"9013_CR9","series-title":"LNCS","first-page":"26","volume-title":"Advances in Cryptology\u2014Crypto\u201994","author":"S.B. Kaliski","year":"1994","unstructured":"S.B. Kaliski, M.J. Robshaw, Linear cryptanalysis using multiple approximations, in Advances in Cryptology\u2014Crypto\u201994, ed. by Y.G. Desmedt. LNCS, vol.\u00a0839 (Springer, Berlin, 1994), pp. 26\u201339"},{"key":"9013_CR10","doi-asserted-by":"publisher","first-page":"543","DOI":"10.2307\/1266560","volume":"3","author":"F.C. Leone","year":"1961","unstructured":"F.C. Leone, N.L. Nelson, R.B. Nottingham, The folded normal distribution, Technometrics 3, 543\u2013550 (1961)","journal-title":"Technometrics"},{"key":"9013_CR11","series-title":"LNCS","first-page":"386","volume-title":"Advances in Cryptology\u2014Eurocrypt\u201993","author":"M. Matsui","year":"1993","unstructured":"M. Matsui, Linear cryptanalysis method for DES cipher, in Advances in Cryptology\u2014Eurocrypt\u201993, ed. by T. Helleseth. LNCS, vol.\u00a0765 (Springer, Berlin, 1993), pp. 386\u2013397"},{"key":"9013_CR12","series-title":"LNCS","first-page":"1","volume-title":"Advances in Cryptology\u2014Crypto\u201994","author":"M. Matsui","year":"1994","unstructured":"M. Matsui, The first experimental cryptanalysis of the Data Encryption Standard, in Advances in Cryptology\u2014Crypto\u201994, ed. by Y.G. Desmedt. LNCS, vol.\u00a0839 (Springer, Berlin, 1994), pp. 1\u201311"},{"key":"9013_CR13","volume-title":"Probability Theory","author":"A. R\u00e9nyi","year":"1970","unstructured":"A. R\u00e9nyi, Probability Theory (American Elsevier, New York, 1970)"},{"key":"9013_CR14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-69710-1_1","volume-title":"Fast Software Encryption, 5th International Workshop","author":"A.A. Sel\u00e7uk","year":"1998","unstructured":"A.A. Sel\u00e7uk, New results in linear cryptanalysis of RC5, in Fast Software Encryption, 5th International Workshop, ed. by S. Vaudenay. LNCS, vol.\u00a01372 (Springer, Berlin, 1998), pp. 1\u201316"},{"key":"9013_CR15","series-title":"LNCS","first-page":"52","volume-title":"Indocrypt 2000","author":"A.A. Sel\u00e7uk","year":"2000","unstructured":"A.A. Sel\u00e7uk, On bias estimation in linear cryptanalysis, in Indocrypt 2000. LNCS, vol.\u00a01977 (Springer, Berlin, 2000), pp. 52\u201366"},{"key":"9013_CR16","series-title":"Wiley Series in Probability and Mathematical Statistics","doi-asserted-by":"crossref","DOI":"10.1002\/9780470316481","volume-title":"Approximation Theorems of Mathematical Statistics","author":"R.J. Serfling","year":"1980","unstructured":"R.J. Serfling, Approximation Theorems of Mathematical Statistics. Wiley Series in Probability and Mathematical Statistics (Wiley, New York, 1980)"},{"key":"9013_CR17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/3-540-48519-8_12","volume-title":"Fast Software Encryption, 6th International Workshop","author":"D. Wagner","year":"1999","unstructured":"D. Wagner, The boomerang attack, in Fast Software Encryption, 6th International Workshop, ed. by L. Knudsen. LNCS, vol.\u00a01636 (Springer, Berlin, 1999), pp. 156\u2013170"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9013-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-007-9013-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9013-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9013-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:36:49Z","timestamp":1586335009000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-007-9013-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,9,14]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2008,1]]}},"alternative-id":["9013"],"URL":"https:\/\/doi.org\/10.1007\/s00145-007-9013-7","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2007,9,14]]},"assertion":[{"value":"28 April 2003","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 August 2007","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 September 2007","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}