{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T22:06:20Z","timestamp":1773525980056,"version":"3.50.1"},"reference-count":66,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2013,11,12]],"date-time":"2013-11-12T00:00:00Z","timestamp":1384214400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2015,4]]},"DOI":"10.1007\/s00145-013-9166-5","type":"journal-article","created":{"date-parts":[[2013,11,11]],"date-time":"2013-11-11T21:08:26Z","timestamp":1384204106000},"page":"257-296","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["The Rebound Attack and Subspace Distinguishers: Application to Whirlpool"],"prefix":"10.1007","volume":"28","author":[{"given":"Mario","family":"Lamberger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Mendel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Schl\u00e4ffer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Rechberger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vincent","family":"Rijmen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,11,12]]},"reference":[{"key":"9166_CR1","unstructured":"P.S.L.M. Barreto, V. Rijmen, The Whirlpool Hashing Function. Submitted to NESSIE (2000). Available online: \n                    http:\/\/www.larc.usp.br\/~pbarreto\/WhirlpoolPage.html"},{"issue":"1","key":"9166_CR2","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E. Biham","year":"1991","unstructured":"E. Biham, A. Shamir, Differential cryptanalysis of DES-like cryptosystems. J. Cryptol.\n                  4(1), 3\u201372 (1991)","journal-title":"J. Cryptol."},{"key":"9166_CR3","series-title":"LNCS","first-page":"231","volume-title":"CRYPTO","author":"A. Biryukov","year":"2009","unstructured":"A. Biryukov, D. Khovratovich, I. Nikoli\u0107, Distinguisher and related-key attack on the full AES-256, in CRYPTO, ed. by S. Halevi. LNCS, vol.\u00a05677 (Springer, Berlin, 2009), pp.\u00a0231\u2013249"},{"key":"9166_CR4","series-title":"LNCS","first-page":"344","volume-title":"ASIACRYPT","author":"A. Bogdanov","year":"2011","unstructured":"A. Bogdanov, D. Khovratovich, C. Rechberger, Biclique cryptanalysis of the full AES, in ASIACRYPT, ed. by D.H. Lee, X. Wang. LNCS, vol.\u00a07073 (Springer, Berlin, 2011), pp.\u00a0344\u2013371"},{"key":"9166_CR5","series-title":"LNCS","first-page":"169","volume-title":"CRYPTO","author":"C. Bouillaguet","year":"2011","unstructured":"C. Bouillaguet, P. Derbez, P.A. Fouque, Automatic search of attacks on round-reduced AES and applications, in CRYPTO, ed. by P. Rogaway. LNCS, vol.\u00a06841 (Springer, Berlin, 2011), pp.\u00a0169\u2013187"},{"key":"9166_CR6","series-title":"LNCS","first-page":"56","volume-title":"CRYPTO","author":"F. Chabaud","year":"1998","unstructured":"F. Chabaud, A. Joux, Differential collisions in SHA-0, in CRYPTO, ed. by H. Krawczyk. LNCS, vol.\u00a01462 (Springer, Berlin, 1998), pp.\u00a056\u201371"},{"key":"9166_CR7","series-title":"LNCS","first-page":"222","volume-title":"IMA Int. Conf.","author":"J. Daemen","year":"2001","unstructured":"J. Daemen, V. Rijmen, The wide trail design strategy, in IMA Int. Conf., ed. by B. Honary. LNCS, vol.\u00a02260 (Springer, Berlin, 2001), pp.\u00a0222\u2013238"},{"key":"9166_CR8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael: AES\u2014The Advanced Encryption Standard","author":"J. Daemen","year":"2002","unstructured":"J. Daemen, V. Rijmen, The Design of Rijndael: AES\u2014The Advanced Encryption Standard (Springer, Berlin, 2002)"},{"key":"9166_CR9","series-title":"LNCS","first-page":"416","volume-title":"CRYPTO","author":"I. Damg\u00e5rd","year":"1989","unstructured":"I. Damg\u00e5rd, A design principle for hash functions, in CRYPTO, ed. by G. Brassard. LNCS, vol.\u00a0435 (Springer, Berlin, 1989), pp.\u00a0416\u2013427"},{"key":"9166_CR10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-540-77360-3_4","volume-title":"Selected Areas in Cryptography","author":"C. Canni\u00e8re De","year":"2007","unstructured":"C. De Canni\u00e8re, F. Mendel, C. Rechberger, Collisions for 70-step SHA-1: on the full cost of collision search, in Selected Areas in Cryptography, ed. by C.M. Adams, A. Miri, M.J. Wiener. LNCS, vol.\u00a04876 (Springer, Berlin, 2007), pp.\u00a056\u201373"},{"key":"9166_CR11","series-title":"LNCS","first-page":"1","volume-title":"ASIACRYPT","author":"C. Canni\u00e8re De","year":"2006","unstructured":"C. De Canni\u00e8re, C. Rechberger, Finding SHA-1 characteristics: general results and applications, in ASIACRYPT, ed. by X. Lai, K. Chen. LNCS, vol.\u00a04284 (Springer, Berlin, 2006), pp.\u00a01\u201320"},{"key":"9166_CR12","series-title":"LNCS","first-page":"225","volume-title":"INDOCRYPT","author":"P. Derbez","year":"2012","unstructured":"P. Derbez, P.A. Fouque, J. Jean, Faster chosen-key distinguishers on reduced-round AES, in INDOCRYPT, ed. by S.D. Galbraith, M. Nandi. LNCS, vol.\u00a07668 (Springer, Berlin, 2012), pp.\u00a0225\u2013243"},{"key":"9166_CR13","series-title":"LNCS","first-page":"719","volume-title":"CRYPTO","author":"I. Dinur","year":"2012","unstructured":"I. Dinur, O. Dunkelman, N. Keller, A. Shamir, Efficient dissection of composite problems, with applications to cryptanalysis, knapsacks, and combinatorial search problems, in CRYPTO, ed. by R. Safavi-Naini, R. Canetti. LNCS, vol.\u00a07417 (Springer, Berlin, 2012), pp.\u00a0719\u2013740"},{"issue":"2","key":"9166_CR14","first-page":"1","volume":"2","author":"H. Dobbertin","year":"1996","unstructured":"H. Dobbertin, The status of MD5 after a recent attack. CryptoBytes\n                  2(2), 1\u20136 (1996)","journal-title":"CryptoBytes"},{"issue":"4","key":"9166_CR15","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1007\/s001459900047","volume":"11","author":"H. Dobbertin","year":"1998","unstructured":"H. Dobbertin, Cryptanalysis of MD4. J. Cryptol.\n                  11(4), 253\u2013271 (1998)","journal-title":"J. Cryptol."},{"key":"9166_CR16","series-title":"LNCS","first-page":"402","volume-title":"FSE","author":"A. Duc","year":"2012","unstructured":"A. Duc, J. Guo, T. Peyrin, L. Wei, Unaligned rebound attack: application to Keccak, in FSE, ed. by A.\u00a0Canteaut. LNCS, vol.\u00a07549 (Springer, Berlin, 2012), pp.\u00a0402\u2013421"},{"issue":"6","key":"9166_CR17","doi-asserted-by":"publisher","first-page":"639","DOI":"10.2307\/2314805","volume":"73","author":"S. Fisher","year":"1966","unstructured":"S. Fisher, Classroom notes: matrices over a finite field. Am. Math. Mon.\n                  73(6), 639\u2013641 (1966)","journal-title":"Am. Math. Mon."},{"key":"9166_CR18","series-title":"LNCS","first-page":"183","volume-title":"CRYPTO (1)","author":"P.A. Fouque","year":"2013","unstructured":"P.A. Fouque, J. Jean, T. Peyrin, Structural evaluation of AES and chosen-key distinguisher of 9-round AES-128, in CRYPTO (1), ed. by R. Canetti, J.A. Garay. LNCS, vol.\u00a08042 (Springer, Berlin, 2013), pp.\u00a0183\u2013203"},{"key":"9166_CR19","first-page":"230","volume-title":"AES Candidate Conference","author":"H. Gilbert","year":"2000","unstructured":"H. Gilbert, M. Minier, A collision attack on 7 rounds of Rijndael, in AES Candidate Conference, (2000), pp.\u00a0230\u2013241"},{"key":"9166_CR20","series-title":"LNCS","first-page":"365","volume-title":"FSE","author":"H. Gilbert","year":"2010","unstructured":"H. Gilbert, T. Peyrin, Super-Sbox cryptanalysis: improved attacks for AES-like permutations, in FSE, ed. by S. Hong, T. Iwata. LNCS, vol.\u00a06147 (Springer, Berlin, 2010), pp.\u00a0365\u2013383"},{"key":"9166_CR21","unstructured":"N. Haller, The S\/KEY One-Time Password System. IETF Request for Comments (RFC) 1760 (1995). Available online: \n                    http:\/\/www.faqs.org\/rfcs\/rfc1760.html"},{"key":"9166_CR22","unstructured":"N. Haller, C. Metz, P. Nesser, M. Straw, A One-Time Password System. IETF Request for Comments (RFC) 2289 (1998). Available online: \n                    http:\/\/www.faqs.org\/rfcs\/rfc2289.html"},{"key":"9166_CR23","series-title":"LNCS","first-page":"1","volume-title":"ISC","author":"K. Ideguchi","year":"2010","unstructured":"K. Ideguchi, E. Tischhauser, B. Preneel, Improved collision attacks on the reduced-round Gr\u00f8stl hash function, in ISC, ed. by M. Burmester, G. Tsudik, S.S. Magliveras, I. Ilic. LNCS, vol.\u00a06531 (Springer, Berlin, 2010), pp.\u00a01\u201316"},{"key":"9166_CR24","unstructured":"International Organization for Standardization: Information Technology\u2014Security Techniques\u2014Hash-Functions. Part 3: Dedicated Hash-Functions. ISO\/IEC 10118-3:2004 (2004)"},{"key":"9166_CR25","series-title":"LNCS","first-page":"107","volume-title":"FSE","author":"J. Jean","year":"2011","unstructured":"J. Jean, P.A. Fouque, Practical near-collisions and collisions on round-reduced ECHO-256 compression function, in FSE, ed. by A. Joux. LNCS, vol.\u00a06733 (Springer, Berlin, 2011), pp.\u00a0107\u2013127"},{"key":"9166_CR26","series-title":"LNCS","first-page":"110","volume-title":"FSE","author":"J. Jean","year":"2012","unstructured":"J. Jean, M. Naya-Plasencia, T. Peyrin, Improved rebound attack on the finalist Gr\u00f8stl, in FSE, ed. by A. Canteaut. LNCS, vol.\u00a07549 (Springer, Berlin, 2012), pp.\u00a0110\u2013126"},{"key":"9166_CR27","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-28496-0_2","volume-title":"Selected Areas in Cryptography","author":"J. Jean","year":"2011","unstructured":"J. Jean, M. Naya-Plasencia, M. Schl\u00e4ffer, Improved analysis of ECHO-256, in Selected Areas in Cryptography, ed. by A. Miri, S. Vaudenay. LNCS, vol.\u00a07118 (Springer, Berlin, 2011), pp.\u00a019\u201336"},{"key":"9166_CR28","series-title":"LNCS","first-page":"111","volume-title":"FSE","author":"J. Kelsey","year":"2006","unstructured":"J. Kelsey, S. Lucks, Collisions and near-collisions for reduced-round Tiger, in FSE, ed. by M.J.B. Robshaw. LNCS, vol.\u00a04047 (Springer, Berlin, 2006), pp.\u00a0111\u2013125"},{"key":"9166_CR29","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/978-3-642-19574-7_26","volume-title":"Selected Areas in Cryptography","author":"D. Khovratovich","year":"2010","unstructured":"D. Khovratovich, M. Naya-Plasencia, A. R\u00f6ck, M. Schl\u00e4ffer, Cryptanalysis of Luffa v2 components, in Selected Areas in Cryptography, ed. by A. Biryukov, G. Gong, D.R. Stinson. LNCS, vol.\u00a06544 (Springer, Berlin, 2010), pp.\u00a0388\u2013409"},{"key":"9166_CR30","series-title":"LNCS","first-page":"1","volume-title":"ASIACRYPT","author":"D. Khovratovich","year":"2010","unstructured":"D. Khovratovich, I. Nikoli\u0107, C. Rechberger, Rotational rebound attacks on reduced Skein, in ASIACRYPT, ed. by M. Abe. LNCS, vol.\u00a06477 (Springer, Berlin, 2010), pp.\u00a01\u201319"},{"key":"9166_CR31","series-title":"LNCS","first-page":"196","volume-title":"FSE","author":"L.R. Knudsen","year":"1994","unstructured":"L.R. Knudsen, Truncated and higher order differentials, in FSE, ed. by B. Preneel. LNCS, vol.\u00a01008 (Springer, Berlin, 1994), pp.\u00a0196\u2013211"},{"key":"9166_CR32","unstructured":"L.R. Knudsen, Non-random properties of reduced-round Whirlpool. NESSIE public report, NES\/DOC\/UIB\/WP5\/017\/1 (2002)"},{"key":"9166_CR33","series-title":"LNCS","first-page":"315","volume-title":"ASIACRYPT","author":"L.R. Knudsen","year":"2007","unstructured":"L.R. Knudsen, V. Rijmen, Known-key distinguishers for some block ciphers, in ASIACRYPT, ed. by K.\u00a0Kurosawa. LNCS, vol.\u00a04833 (Springer, Berlin, 2007), pp.\u00a0315\u2013324"},{"key":"9166_CR34","series-title":"LNCS","first-page":"449","volume-title":"ACNS","author":"S. K\u00f6lbl","year":"2011","unstructured":"S. K\u00f6lbl, F. Mendel, Practical attacks on the Maelstrom-0 compression function, in ACNS, ed. by J.\u00a0Lopez, G.\u00a0Tsudik. LNCS, vol.\u00a06715, (2011), pp.\u00a0449\u2013461"},{"key":"9166_CR35","series-title":"LNCS","first-page":"126","volume-title":"ASIACRYPT","author":"M. Lamberger","year":"2009","unstructured":"M. Lamberger, F. Mendel, C. Rechberger, V. Rijmen, M. Schl\u00e4ffer, Rebound distinguishers: results on the full whirlpool compression function, in ASIACRYPT, ed. by M. Matsui. LNCS, vol.\u00a05912 (Springer, Berlin, 2009), pp.\u00a0126\u2013143"},{"key":"9166_CR36","series-title":"LNCS","first-page":"241","volume-title":"CRYPTO (1)","author":"G. Leurent","year":"2013","unstructured":"G. Leurent, Construction of differential characteristics in ARX designs application to Skein, in CRYPTO (1), ed. by R. Canetti, J.A. Garay. LNCS, vol.\u00a08042 (Springer, Berlin, 2013), pp.\u00a0241\u2013258"},{"key":"9166_CR37","volume-title":"Encyclopedia of Mathematics and Its Applications","author":"R. Lidl","year":"1997","unstructured":"R. Lidl, H. Niederreiter, Finite fields, in Encyclopedia of Mathematics and Its Applications, vol.\u00a020, 2nd edn. (Cambridge University Press, Cambridge, 1997). With a foreword by P.M. Cohn","edition":"2"},{"key":"9166_CR38","series-title":"LNCS","first-page":"106","volume-title":"ASIACRYPT","author":"K. Matusiewicz","year":"2009","unstructured":"K. Matusiewicz, M. Naya-Plasencia, I. Nikoli\u0107, Y. Sasaki, M. Schl\u00e4ffer, Rebound attack on the full lane compression function, in ASIACRYPT, ed. by M. Matsui. LNCS, vol.\u00a05912 (Springer, Berlin, 2009), pp.\u00a0106\u2013125"},{"key":"9166_CR39","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-642-05445-7_2","volume-title":"Selected Areas in Cryptography","author":"F. Mendel","year":"2009","unstructured":"F. Mendel, T. Peyrin, C. Rechberger, M. Schl\u00e4ffer, Improved cryptanalysis of the reduced Gr\u00f8stl compression function, ECHO permutation and AES block cipher, in Selected Areas in Cryptography, ed. by M.J. Jacobson Jr., V. Rijmen, R. Safavi-Naini. LNCS, vol.\u00a05867 (Springer, Berlin, 2009), pp.\u00a016\u201335"},{"key":"9166_CR40","series-title":"LNCS","first-page":"63","volume-title":"INDOCRYPT","author":"F. Mendel","year":"2006","unstructured":"F. Mendel, B. Preneel, V. Rijmen, H. Yoshida, D. Watanabe, Update on Tiger, in INDOCRYPT, ed. by R. Barua, T. Lange. LNCS, vol.\u00a04329 (Springer, Berlin, 2006), pp.\u00a063\u201379"},{"key":"9166_CR41","series-title":"LNCS","first-page":"342","volume-title":"ACNS","author":"F. Mendel","year":"2009","unstructured":"F. Mendel, C. Rechberger, M. Schl\u00e4ffer, Cryptanalysis of Twister, in ACNS, ed. by M. Abdalla, D. Pointcheval, P.A. Fouque, D. Vergnaud. LNCS, vol.\u00a05536, (2009), pp.\u00a0342\u2013353"},{"key":"9166_CR42","series-title":"LNCS","first-page":"260","volume-title":"FSE","author":"F. Mendel","year":"2009","unstructured":"F. Mendel, C. Rechberger, M. Schl\u00e4ffer, S.S. Thomsen, The rebound attack: cryptanalysis of reduced whirlpool and Gr\u00f8stl, in FSE, ed. by O. Dunkelman. LNCS, vol.\u00a05665 (Springer, Berlin, 2009), pp.\u00a0260\u2013276"},{"key":"9166_CR43","series-title":"LNCS","first-page":"350","volume-title":"CT-RSA","author":"F. Mendel","year":"2010","unstructured":"F. Mendel, C. Rechberger, M. Schl\u00e4ffer, S.S. Thomsen, Rebound attacks on the reduced Gr\u00f8stl hash function, in CT-RSA, ed. by J. Pieprzyk. LNCS, vol.\u00a05985 (Springer, Berlin, 2010), pp.\u00a0350\u2013365"},{"key":"9166_CR44","series-title":"LNCS","first-page":"536","volume-title":"ASIACRYPT","author":"F. Mendel","year":"2007","unstructured":"F. Mendel, V. Rijmen, Cryptanalysis of the Tiger hash function, in ASIACRYPT, ed. by K. Kurosawa. LNCS, vol.\u00a04833 (Springer, Berlin, 2007), pp.\u00a0536\u2013550"},{"key":"9166_CR45","series-title":"LNCS","first-page":"428","volume-title":"CRYPTO","author":"R.C. Merkle","year":"1989","unstructured":"R.C. Merkle, One way hash functions and DES, in CRYPTO, ed. by G. Brassard. LNCS, vol.\u00a0435 (Springer, Berlin, 1989), pp.\u00a0428\u2013446"},{"key":"9166_CR46","series-title":"LNCS","first-page":"68","volume-title":"FSE","author":"M. Minier","year":"2011","unstructured":"M. Minier, M. Naya-Plasencia, T. Peyrin, Analysis of Reduced-SHAvite-3-256 v2, in FSE, ed. by A.\u00a0Joux. LNCS, vol.\u00a06733 (Springer, Berlin, 2011), pp.\u00a068\u201387"},{"key":"9166_CR47","unstructured":"National Institute of Standards and Technology: Announcing request for candidate algorithm nominations for a new cryptographic hash algorithm (SHA-3) family. Federal Register 27(212), 62212\u201362220 (November 2007). Available online: \n                    http:\/\/csrc.nist.gov\/groups\/ST\/hash\/documents\/FR_Notice_Nov07.pdf"},{"key":"9166_CR48","series-title":"LNCS","first-page":"188","volume-title":"CRYPTO","author":"M. Naya-Plasencia","year":"2011","unstructured":"M. Naya-Plasencia, How to improve rebound attacks, in CRYPTO, ed. by P. Rogaway. LNCS, vol.\u00a06841 (Springer, Berlin, 2011), pp.\u00a0188\u2013205"},{"key":"9166_CR49","series-title":"LNCS","first-page":"252","volume-title":"ASIACRYPT","author":"M. Naya-Plasencia","year":"2011","unstructured":"M. Naya-Plasencia, D. Toz, K. Varici, Rebound attack on JH42, in ASIACRYPT, ed. by D.H. Lee, X. Wang. LNCS, vol.\u00a07073 (Springer, Berlin, 2011), pp.\u00a0252\u2013269"},{"key":"9166_CR50","unstructured":"NESSIE, New European Schemes for Signatures, Integrity, and Encryption. IST-1999-12324. Available online: \n                    http:\/\/cryptonessie.org\/"},{"key":"9166_CR51","series-title":"LNCS","first-page":"551","volume-title":"ASIACRYPT","author":"T. Peyrin","year":"2007","unstructured":"T. Peyrin, Cryptanalysis of Grindahl, in ASIACRYPT, ed. by K. Kurosawa. LNCS, vol.\u00a04833 (Springer, Berlin, 2007), pp.\u00a0551\u2013567"},{"key":"9166_CR52","series-title":"LNCS","first-page":"370","volume-title":"CRYPTO","author":"T. Peyrin","year":"2010","unstructured":"T. Peyrin, Improved differential attacks for ECHO and Gr\u00f8stl, in CRYPTO, ed. by T. Rabin. LNCS, vol.\u00a06223 (Springer, Berlin, 2010), pp.\u00a0370\u2013392"},{"key":"9166_CR53","series-title":"LNCS","first-page":"242","volume-title":"FSE","author":"V. Rijmen","year":"1994","unstructured":"V. Rijmen, B. Preneel, Improved characteristics for differential cryptanalysis of hash functions based on block ciphers, in FSE, ed. by B. Preneel. LNCS, vol.\u00a01008 (Springer, Berlin, 1994), pp.\u00a0242\u2013248"},{"key":"9166_CR54","series-title":"LNCS","first-page":"286","volume-title":"FSE","author":"V. Rijmen","year":"2010","unstructured":"V. Rijmen, D. Toz, K. Varici, Rebound attack on reduced-round versions of JH, in FSE, ed. by S. Hong, T. Iwata. LNCS, vol.\u00a06147 (Springer, Berlin, 2010), pp.\u00a0286\u2013303"},{"key":"9166_CR55","doi-asserted-by":"publisher","first-page":"26","DOI":"10.2307\/2308012","volume":"62","author":"H. Robbins","year":"1955","unstructured":"H. Robbins, A remark on Stirling\u2019s formula. Am. Math. Mon.\n                  62, 26\u201329 (1955)","journal-title":"Am. Math. Mon."},{"key":"9166_CR56","series-title":"LNCS","first-page":"378","volume-title":"FSE","author":"Y. Sasaki","year":"2011","unstructured":"Y. Sasaki, Meet-in-the-middle preimage attacks on AES hashing modes and an application to whirlpool, in FSE, ed. by A. Joux. LNCS, vol.\u00a06733 (Springer, Berlin, 2011), pp.\u00a0378\u2013396"},{"key":"9166_CR57","series-title":"LNCS","first-page":"38","volume-title":"ASIACRYPT","author":"Y. Sasaki","year":"2010","unstructured":"Y. Sasaki, Y. Li, L. Wang, K. Sakiyama, K. Ohta, Non-full-active Super-Sbox analysis: applications to ECHO and Gr\u00f8stl, in ASIACRYPT, ed. by M. Abe. LNCS, vol.\u00a06477 (Springer, Berlin, 2010), pp.\u00a038\u201355"},{"key":"9166_CR58","series-title":"LNCS","first-page":"178","volume-title":"IWSEC","author":"Y. Sasaki","year":"2011","unstructured":"Y. Sasaki, N. Takayanagi, K. Sakiyama, K. Ohta, Experimental verification of Super-Sbox analysis\u2014confirmation of detailed attack complexity, in IWSEC, ed. by T. Iwata, M. Nishigaki. LNCS, vol.\u00a07038 (Springer, Berlin, 2011), pp.\u00a0178\u2013192"},{"key":"9166_CR59","series-title":"LNCS","first-page":"562","volume-title":"ASIACRYPT","author":"Y. Sasaki","year":"2012","unstructured":"Y. Sasaki, L. Wang, S. Wu, W. Wu, Investigating fundamental security requirements on whirlpool: improved preimage and collision attacks, in ASIACRYPT, ed. by X. Wang, K. Sako. LNCS, vol.\u00a07658 (Springer, Berlin, 2012), pp.\u00a0562\u2013579"},{"key":"9166_CR60","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"369","DOI":"10.1007\/978-3-642-19574-7_25","volume-title":"Selected Areas in Cryptography","author":"M. Schl\u00e4ffer","year":"2010","unstructured":"M. Schl\u00e4ffer, Subspace distinguisher for 5\/8 rounds of the ECHO-256 hash function, in Selected Areas in Cryptography, ed. by A. Biryukov, G. Gong, D.R. Stinson. LNCS, vol.\u00a06544 (Springer, Berlin, 2010), pp.\u00a0369\u2013387"},{"key":"9166_CR61","series-title":"LNCS","first-page":"156","volume-title":"FSE","author":"D. Wagner","year":"1999","unstructured":"D. Wagner, The boomerang attack, in FSE, ed. by L.R. Knudsen. LNCS, vol.\u00a01636 (Springer, Berlin, 1999), pp.\u00a0156\u2013170"},{"key":"9166_CR62","series-title":"LNCS","first-page":"17","volume-title":"CRYPTO","author":"X. Wang","year":"2005","unstructured":"X. Wang, Y.L. Yin, H. Yu, Finding collisions in the full SHA-1, in CRYPTO, ed. by V. Shoup. LNCS, vol.\u00a03621 (Springer, Berlin, 2005), pp.\u00a017\u201336"},{"key":"9166_CR63","series-title":"LNCS","first-page":"19","volume-title":"EUROCRYPT","author":"X. Wang","year":"2005","unstructured":"X. Wang, H. Yu, How to break MD5 and other hash functions, in EUROCRYPT, ed. by R. Cramer. LNCS, vol.\u00a03494 (Springer, Berlin, 2005), pp.\u00a019\u201335"},{"key":"9166_CR64","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1007\/978-3-642-05445-7_8","volume-title":"Selected Areas in Cryptography","author":"S. Wu","year":"2009","unstructured":"S. Wu, D. Feng, W. Wu, Cryptanalysis of the LANE hash function, in Selected Areas in Cryptography, ed. by M.J. Jacobson Jr., V. Rijmen, R. Safavi-Naini. LNCS, vol.\u00a05867 (Springer, Berlin, 2009), pp.\u00a0126\u2013140"},{"key":"9166_CR65","series-title":"LNCS","first-page":"300","volume-title":"ICISC","author":"S. Wu","year":"2009","unstructured":"S. Wu, D. Feng, W. Wu, Practical rebound attack on 12-round Cheetah-256, in ICISC, ed. by D. Lee, S. Hong. LNCS, vol.\u00a05984 (Springer, Berlin, 2009), pp.\u00a0300\u2013314"},{"key":"9166_CR66","doi-asserted-by":"crossref","unstructured":"H. Yu, J. Chen, X. Wang, Partial-collision attack on the round-reduced compression function of Skein-256, in FSE, ed. by S. Moriai. LNCS (Springer, Berlin, 2013, to appear)","DOI":"10.1007\/978-3-662-43933-3_14"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-013-9166-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-013-9166-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-013-9166-5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-013-9166-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:14:15Z","timestamp":1586333655000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-013-9166-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,11,12]]},"references-count":66,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,4]]}},"alternative-id":["9166"],"URL":"https:\/\/doi.org\/10.1007\/s00145-013-9166-5","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,11,12]]},"assertion":[{"value":"1 April 2010","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 November 2013","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}