{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,24]],"date-time":"2026-01-24T23:35:22Z","timestamp":1769297722195,"version":"3.49.0"},"reference-count":19,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2012,12,29]],"date-time":"2012-12-29T00:00:00Z","timestamp":1356739200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2014,4]]},"DOI":"10.1007\/s00145-012-9142-5","type":"journal-article","created":{"date-parts":[[2012,12,28]],"date-time":"2012-12-28T15:58:51Z","timestamp":1356710331000},"page":"183-209","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Improved Practical Attacks on Round-Reduced Keccak"],"prefix":"10.1007","volume":"27","author":[{"given":"Itai","family":"Dinur","sequence":"first","affiliation":[]},{"given":"Orr","family":"Dunkelman","sequence":"additional","affiliation":[]},{"given":"Adi","family":"Shamir","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2012,12,29]]},"reference":[{"key":"9142_CR1","doi-asserted-by":"crossref","unstructured":"M.R. Albrecht, C. Cid, Algebraic techniques in differential cryptanalysis, in Dunkelman [13], pp.\u00a0193\u2013208","DOI":"10.1007\/978-3-642-03317-9_12"},{"key":"9142_CR2","unstructured":"J.-P. Aumasson, W. Meier, Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi. NIST mailing list, 2009"},{"key":"9142_CR3","unstructured":"D.J. Bernstein, Second preimages for 6 (7? (8??)) rounds of Keccak? NIST mailing list, 2010"},{"key":"9142_CR4","unstructured":"G. Bertoni, J. Daemen, M. Peeters, G. Van Assche, Sponge functions. Presented at the ECRYPT Hash Workshop, 2007"},{"key":"9142_CR5","unstructured":"G. Bertoni, J. Daemen, M. Peeters, G. Van Assche, The Keccak SHA-3 submission. Submission to NIST (Round 3), 2011"},{"key":"9142_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-19574-7_1","volume-title":"Selected Areas in Cryptography","author":"C. Boura","year":"2010","unstructured":"C. Boura, A. Canteaut, Zero-sum distinguishers for iterated permutations and application to Keccak-f and Hamsi-256, in Selected Areas in Cryptography, ed. by A. Biryukov, G. Gong, D.R. Stinson. Lecture Notes in Computer Science, vol. 6544 (Springer, Berlin, 2010), pp. 1\u201317"},{"key":"9142_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1007\/978-3-642-21702-9_15","volume-title":"FSE","author":"C. Boura","year":"2011","unstructured":"C. Boura, A. Canteaut, C. De Canni\u00e8re, Higher-order differential properties of Keccak and Luffa, in FSE, ed. by A. Joux. Lecture Notes in Computer Science, vol. 6733 (Springer, Berlin, 2011), pp. 252\u2013269"},{"key":"9142_CR8","series-title":"Lecture Notes in Computer Science","volume-title":"Fast Software Encryption\u201419th International Workshop","year":"2012","unstructured":"A. Canteaut (ed.), Fast Software Encryption\u201419th International Workshop, FSE 2012, Washington, DC, USA, March 19\u201321, 2012. Lecture Notes in Computer Science, vol. 7549 (Springer, Berlin, 2012), Revised selected papers"},{"key":"9142_CR9","doi-asserted-by":"crossref","unstructured":"J. Daemen, G. Van Assche, Differential propagation analysis of Keccak, in Canteaut [8], pp. 422\u2013441","DOI":"10.1007\/978-3-642-34047-5_24"},{"issue":"1","key":"9142_CR10","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1049\/iet-ifs:20060099","volume":"1","author":"J. Daemen","year":"2007","unstructured":"J. Daemen, V. Rijmen, Plateau characteristics. IET Inf. Secur.\n                  1(1), 11\u201317 (2007)","journal-title":"IET Inf. Secur."},{"key":"9142_CR11","unstructured":"M. Duan, X. Lai, Improved zero-sum distinguisher for full round Keccak-f permutation. Cryptology ePrint Archive, Report 2011\/023, 2011"},{"key":"9142_CR12","doi-asserted-by":"crossref","unstructured":"A. Duc, J. Guo, T. Peyrin, L. Wei, Unaligned rebound attack: application to Keccak, in Canteaut [8], pp. 402\u2013421","DOI":"10.1007\/978-3-642-34047-5_23"},{"key":"9142_CR13","series-title":"Lecture Notes in Computer Science","volume-title":"Fast Software Encryption, 16th International Workshop","year":"2009","unstructured":"O. Dunkelman (ed.), Fast Software Encryption, 16th International Workshop, FSE 2009, Leuven, Belgium, February 22\u201325, 2009. Lecture Notes in Computer Science, vol. 5665 (Springer, Berlin, 2009), Revised selected papers"},{"key":"9142_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1007\/978-3-642-05445-7_7","volume-title":"Selected Areas in Cryptography","author":"D. Khovratovich","year":"2009","unstructured":"D. Khovratovich, Cryptanalysis of hash functions with structures, in Selected Areas in Cryptography, ed. by M.J. Jacobson Jr., V. Rijmen, R. Safavi-Naini. Lecture Notes in Computer Science, vol. 5867 (Springer, Berlin, 2009), pp. 108\u2013125"},{"key":"9142_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1007\/978-3-642-00862-7_11","volume-title":"CT-RSA","author":"D. Khovratovich","year":"2009","unstructured":"D. Khovratovich, A. Biryukov, I. Nikolic, Speeding up collision search for byte-oriented hash functions, in CT-RSA, ed. by M. Fischlin. Lecture Notes in Computer Science, vol. 5473 (Springer, Berlin, 2009), pp. 164\u2013181"},{"key":"9142_CR16","doi-asserted-by":"crossref","unstructured":"F. Mendel, C. Rechberger, M. Schl\u00e4ffer, S.S. Thomsen, The rebound attack: cryptanalysis of reduced Whirlpool and Gr\u00f8stl, in Dunkelman [13], pp. 260\u2013276","DOI":"10.1007\/978-3-642-03317-9_16"},{"key":"9142_CR17","unstructured":"P. Morawiecki, M. Srebrny, A SAT-based preimage analysis of reduced KECCAK hash functions. Cryptology ePrint Archive, Report 2010\/285, 2010"},{"key":"9142_CR18","series-title":"Lecture Notes in Computers Science","volume-title":"Progress in Cryptology\u2014INDOCRYPT 2011","author":"M. Naya-Plasencia","year":"2011","unstructured":"M. Naya-Plasencia, A. R\u00f6ck, W. Meier, Practical analysis of reduced-round Keccak, in Progress in Cryptology\u2014INDOCRYPT 2011, ed. by D.J. Bernstein, S. Chatterjee. Lecture Notes in Computers Science, vol. 7107 (Springer, Heidelberg, 2011)"},{"key":"9142_CR19","unstructured":"The Keccak team, Keccak crunchy crypto collision and pre-image contest, 2011"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-012-9142-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-012-9142-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-012-9142-5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-012-9142-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:10:23Z","timestamp":1586333423000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-012-9142-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,12,29]]},"references-count":19,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2014,4]]}},"alternative-id":["9142"],"URL":"https:\/\/doi.org\/10.1007\/s00145-012-9142-5","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,12,29]]},"assertion":[{"value":"26 June 2012","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 December 2012","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}