{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T15:14:29Z","timestamp":1786979669406,"version":"build-2736575974"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2022,10]]},"DOI":"10.1007\/s00145-022-09439-x","type":"journal-article","created":{"date-parts":[[2022,10,4]],"date-time":"2022-10-04T15:02:17Z","timestamp":1664895737000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["The Inverse of $$\\chi $$ and Its Applications to Rasta-Like Ciphers"],"prefix":"10.1007","volume":"35","author":[{"given":"Fukang","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Santanu","family":"Sarkar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Willi","family":"Meier","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takanori","family":"Isobe","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,10,4]]},"reference":[{"key":"9439_CR1","unstructured":"M. Albrecht, G. Bard, The M4RI library. The M4RI Team (2021). http:\/\/m4ri.sagemath.org"},{"key":"9439_CR2","doi-asserted-by":"crossref","unstructured":"M.R. Albrecht, C. Cid, L. Grassi, D. Khovratovich, R. L\u00fcftenegger, C. Rechberger, M. Schofnegger, Algebraic cryptanalysis of STARK-friendly designs: application to MARVELlous and MiMC, in ASIACRYPT (3). Lecture Notes in Computer Science, vol. 11923 (Springer, 2019), pp. 371\u2013397","DOI":"10.1007\/978-3-030-34618-8_13"},{"key":"9439_CR3","doi-asserted-by":"crossref","unstructured":"M.R. Albrecht, L. Grassi, L. Perrin, S. Ramacher, C. Rechberger, D. Rotaru, A. Roy, M. Schofnegger, Feistel structures for MPC, and more, in ESORICS (2). Lecture Notes in Computer Sciencevol. 11736 (Springer, 2019), pp. 151\u2013171","DOI":"10.1007\/978-3-030-29962-0_8"},{"key":"9439_CR4","doi-asserted-by":"crossref","unstructured":"M.R. Albrecht, L. Grassi, C. Rechberger, A. Roy, T. Tiessen, MiMC: efficient encryption and cryptographic hashing with minimal multiplicative complexity, in ASIACRYPT (1). Lecture Notes in Computer Science, vol. 10031 (2016), pp. 191\u2013219","DOI":"10.1007\/978-3-662-53887-6_7"},{"key":"9439_CR5","doi-asserted-by":"crossref","unstructured":"M.R. Albrecht, C. Rechberger, T. Schneider, T. Tiessen, M. Zohner, Ciphers for MPC and FHE, in EUROCRYPT (1). Lecture Notes in Computer Science, vol. 9056 (Springer, 2015), pp. 430\u2013454","DOI":"10.1007\/978-3-662-46800-5_17"},{"key":"9439_CR6","doi-asserted-by":"crossref","unstructured":"J. Alman, V.V. Williams, A refined laser method and faster matrix multiplication, in SODA (SIAM, 2021), pp. 522\u2013539","DOI":"10.1137\/1.9781611976465.32"},{"key":"9439_CR7","doi-asserted-by":"crossref","unstructured":"A. Aly, T. Ashur, E. Ben-Sasson, S. Dhooghe, A. Szepieniec, Design of symmetric-key primitives for advanced cryptographic protocols. IACR Trans. Symmetric Cryptol. 2020(3), 1\u201345 (2020)","DOI":"10.46586\/tosc.v2020.i3.1-45"},{"key":"9439_CR8","unstructured":"T. Ashur, S. Dhooghe. MARVELlous: a STARK-friendly family of cryptographic primitives. Cryptology ePrint Archive, Report 2018\/1098 (2018). https:\/\/eprint.iacr.org\/2018\/1098"},{"key":"9439_CR9","doi-asserted-by":"crossref","unstructured":"G. Bertoni, J. Daemen, M. Peeters, G.V. Assche, Keccak, in EUROCRYPT. Lecture Notes in Computer Science, vol. 7881 (Springer, 2013), pp. 313\u2013314","DOI":"10.1007\/978-3-642-38348-9_19"},{"key":"9439_CR10","doi-asserted-by":"crossref","unstructured":"T. Beyne, A. Canteaut, I. Dinur, M. Eichlseder, G. Leander, G. Leurent, M. Naya-Plasencia, L. Perrin, Y. Sasaki, Y. Todo, F. Wiemer, Out of oddity\u2014new cryptanalytic techniques against symmetric primitives optimized for integrity proof systems, in CRYPTO (3). Lecture Notes in Computer Science, vol. 12172 (Springer, 2020), pp. 299\u2013328","DOI":"10.1007\/978-3-030-56877-1_11"},{"key":"9439_CR11","doi-asserted-by":"crossref","unstructured":"A. Biryukov, C. Bouillaguet, D. Khovratovich, Cryptographic schemes based on the ASASA structure: black-box, white-box, and public-key. IACR Cryptol. ePrint Arch. (2014), pp. 474","DOI":"10.1007\/978-3-662-45611-8_4"},{"key":"9439_CR12","doi-asserted-by":"crossref","unstructured":"A. Biryukov, C. Bouillaguet, D. Khovratovich, Cryptographic schemes based on the ASASA structure: black-box, white-box, and public-key (extended abstract), in ASIACRYPT (1). Lecture Notes in Computer Science, vol. 8873 (Springer, 2014), pp. 63\u201384","DOI":"10.1007\/978-3-662-45611-8_4"},{"key":"9439_CR13","unstructured":"A. Bj\u00f6rklund, P. Kaski, R. Williams, Solving systems of polynomial equations over GF(2) by a parity-counting self-reduction, in ICALP. LIPIcs, vol. 132 (Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik, 2019), pp. 26:1\u201326:13"},{"key":"9439_CR14","doi-asserted-by":"crossref","unstructured":"C. Bouillaguet, H. Chen, C. Cheng, T. Chou, R. Niederhagen, A. Shamir, B. Yang, Fast exhaustive search for polynomial systems in $$F_{2}$$, in CHES. Lecture Notes in Computer Science, vol. 6225 (Springer, 2010), pp. 203\u2013218","DOI":"10.1007\/978-3-642-15031-9_14"},{"key":"9439_CR15","doi-asserted-by":"crossref","unstructured":"A. Canteaut, S. Carpov, C. Fontaine, T. Lepoint, M. Naya-Plasencia, P. Paillier, R. Sirdey, Stream ciphers: a practical solution for efficient homomorphic-ciphertext compression. J. Cryptol. 31(3), 885\u2013916 (2018)","DOI":"10.1007\/s00145-017-9273-9"},{"key":"9439_CR16","doi-asserted-by":"crossref","unstructured":"N.T. Courtois, A. Klimov, J. Patarin, A. Shamir, Efficient algorithms for solving overdefined systems of multivariate polynomial equations, in EUROCRYPT. Lecture Notes in Computer Science, vol. 1807 (Springer, 2000), pp. 392\u2013407","DOI":"10.1007\/3-540-45539-6_27"},{"key":"9439_CR17","doi-asserted-by":"crossref","unstructured":"D.A. Cox, J. Little, D. O\u2019Shea, Ideals, varieties, and algorithms\u2014an introduction to computational algebraic geometry and commutative algebra (4. ed.). Undergraduate texts in mathematics (Springer, 2015)","DOI":"10.1007\/978-3-319-16721-3"},{"key":"9439_CR18","unstructured":"J. Daemen, Cipher and hash function design strategies based on linear and differential cryptanalysis. Ph.D. thesis (1995)"},{"key":"9439_CR19","doi-asserted-by":"crossref","unstructured":"I. Dinur, Cryptanalytic applications of the polynomial method for solving multivariate equation systems over GF(2), in EUROCRYPT (1). Lecture Notes in Computer Science, vol. 12696 (Springer, 2021), pp. 374\u2013403","DOI":"10.1007\/978-3-030-77870-5_14"},{"key":"9439_CR20","doi-asserted-by":"crossref","unstructured":"I. Dinur, Improved algorithms for solving polynomial systems over GF(2) by multiple parity-counting, in SODA (SIAM, 2021), pp. 2550\u20132564","DOI":"10.1137\/1.9781611976465.151"},{"key":"9439_CR21","doi-asserted-by":"crossref","unstructured":"I. Dinur, Y. Liu, W. Meier, Q. Wang, Optimized interpolation attacks on LowMC, in ASIACRYPT (2). Lecture Notes in Computer Science, vol. 9453 (Springer, 2015), pp. 535\u2013560","DOI":"10.1007\/978-3-662-48800-3_22"},{"key":"9439_CR22","doi-asserted-by":"crossref","unstructured":"C. Dobraunig, M. Eichlseder, L. Grassi, V. Lallemand, G. Leander, E. List, F. Mendel, C. Rechberger, Rasta: a cipher with low ANDdepth and few ANDs per bit, in CRYPTO (1). Lecture Notes in Computer Science, vol. 10991 (Springer, 2018), pp. 662\u2013692","DOI":"10.1007\/978-3-319-96884-1_22"},{"key":"9439_CR23","doi-asserted-by":"crossref","unstructured":"C. Dobraunig, M. Eichlseder, F. Mendel, Higher-order cryptanalysis of LowMC, in ICISC. Lecture Notes in Computer Science, vol. 9558 (Springer, 2015), pp. 87\u2013101","DOI":"10.1007\/978-3-319-30840-1_6"},{"key":"9439_CR24","doi-asserted-by":"crossref","unstructured":"C. Dobraunig, L. Grassi, A. Guinet, D. Kuijsters, Ciminion: symmetric encryption based on toffoli-gates over large finite fields, in EUROCRYPT (2). Lecture Notes in Computer Science, vol. 12697 (Springer, 2021), pp. 3\u201334","DOI":"10.1007\/978-3-030-77886-6_1"},{"key":"9439_CR25","doi-asserted-by":"crossref","unstructured":"C. Dobraunig, F. Moazami, C. Rechberger, H. Soleimany, Framework for faster key search using related-key higher-order differential properties: applications to Agrasta. IET Inf. Secur. 14(2), 202\u2013209 (2020)","DOI":"10.1049\/iet-ifs.2019.0326"},{"key":"9439_CR26","doi-asserted-by":"crossref","unstructured":"S. Duval, V. Lallemand, Y. Rotella, Cryptanalysis of the FLIP family of stream ciphers, in CRYPTO (1). Lecture Notes in Computer Science, vol. 9814 (Springer, 2016), pp. 457\u2013475","DOI":"10.1007\/978-3-662-53018-4_17"},{"key":"9439_CR27","doi-asserted-by":"crossref","unstructured":"M. Dworkin, SHA-3 standard: permutation-based hash and extendable-output functions, 2015-08-04 (2015)","DOI":"10.6028\/NIST.FIPS.202"},{"key":"9439_CR28","doi-asserted-by":"crossref","unstructured":"M. Eichlseder, L. Grassi, R. L\u00fcftenegger, M. \u00d8ygarden, C. Rechberger, M. Schofnegger, Q. Wang, An algebraic attack on ciphers with low-degree round functions: application to full MiMC, in ASIACRYPT (1). Lecture Notes in Computer Science, vol. 12491 (Springer, 2020), pp. 477\u2013506","DOI":"10.1007\/978-3-030-64837-4_16"},{"key":"9439_CR29","doi-asserted-by":"crossref","unstructured":"J.-C. Faug\u00e8re, A new efficient algorithm for computing Gr\u00f6bner bases (F4). J. Pure Appl. Algebra 139(1\u20133), 61\u201388 (1999)","DOI":"10.1016\/S0022-4049(99)00005-5"},{"key":"9439_CR30","doi-asserted-by":"crossref","unstructured":"J.-C. Faug\u00e8re, A new efficient algorithm for computing Gr\u00f6bner bases without reduction to zero F5, in International Symposium on Symbolic and Algebraic Computation Symposium\u2014ISSAC 2002, Villeneuve d\u2019Ascq, France, July 2002 (ACM, Colloque avec actes et comit\u00e9 de lecture. Internationale, 2002), pp. 75\u201383","DOI":"10.1145\/780506.780516"},{"key":"9439_CR31","unstructured":"L. Grassi, D. Khovratovich, C. Rechberger, A. Roy, M. Schofnegger, Poseidon: a new hash function for zero-knowledge proof systems, in USENIX Security Symposium (USENIX Association, 2021), pp. 519\u2013535"},{"key":"9439_CR32","doi-asserted-by":"crossref","unstructured":"L. Grassi, R. L\u00fcftenegger, C. Rechberger, D. Rotaru, M. Schofnegger, On a generalization of substitution-permutation networks: the HADES design strategy, in EUROCRYPT (2). Lecture Notes in Computer Science, vol. 12106 (Springer, 2020), pp. 674\u2013704","DOI":"10.1007\/978-3-030-45724-2_23"},{"key":"9439_CR33","doi-asserted-by":"crossref","unstructured":"J. Guo, M. Liu, L. Song, Linear structures: applications to cryptanalysis of round-reduced keccak, in ASIACRYPT (1). Lecture Notes in Computer Science, vol. 10031 (2016), pp. 249\u2013274","DOI":"10.1007\/978-3-662-53887-6_9"},{"key":"9439_CR34","doi-asserted-by":"crossref","unstructured":"P. Hebborn, G. Leander, Dasta\u2014alternative linear layer for Rasta. IACR Trans. Symmetric Cryptol. 2020(3), 46\u201386 (2020)","DOI":"10.46586\/tosc.v2020.i3.46-86"},{"key":"9439_CR35","doi-asserted-by":"crossref","unstructured":"D. Kales, G. Zaverucha, Improving the performance of the picnic signature scheme. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020(4), 154\u2013188 (2020)","DOI":"10.46586\/tches.v2020.i4.154-188"},{"key":"9439_CR36","doi-asserted-by":"crossref","unstructured":"F. Liu, T. Isobe, W. Meier, Cryptanalysis of full LowMC and LowMC-M with algebraic techniques, in CRYPTO (3). Lecture Notes in Computer Science, vol. 12827 (Springer, 2021), pp. 368\u2013401","DOI":"10.1007\/978-3-030-84252-9_13"},{"key":"9439_CR37","doi-asserted-by":"crossref","unstructured":"F. Liu, S. Sarkar, W. Meier, T. Isobe, Algebraic attacks on Rasta and Dasta using low-degree equations, in ASIACRYPT (1). Lecture Notes in Computer Science, vol. 13090 (Springer, 2021), pp. 214\u2013240","DOI":"10.1007\/978-3-030-92062-3_8"},{"key":"9439_CR38","unstructured":"F. Liu, S. Sarkar, G. Wang, W. Meier, T. Isobe, Algebraic meet-in-the-middle attack on LowMC. Cryptology ePrint Archive, Report 2022\/019 (2022). https:\/\/ia.cr\/2022\/019"},{"key":"9439_CR39","doi-asserted-by":"crossref","unstructured":"D. Lokshtanov, R. Paturi, S. Tamaki, R.R. Williams, H. Yu, Beating brute force for systems of polynomial equations over finite fields, in SODA (SIAM, 2017), pp. 2190\u20132202","DOI":"10.1137\/1.9781611974782.143"},{"key":"9439_CR40","doi-asserted-by":"crossref","unstructured":"P. M\u00e9aux, A. Journault, F. Standaert, C. Carlet, Towards stream ciphers for efficient FHE with low-noise ciphertexts, in EUROCRYPT (1). Lecture Notes in Computer Science, vol. 9665 (Springer, 2016), pp. 311\u2013343","DOI":"10.1007\/978-3-662-49890-3_13"},{"key":"9439_CR41","doi-asserted-by":"crossref","unstructured":"C. Rechberger, H. Soleimany, and T. Tiessen. Cryptanalysis of low-data instances of full lowmcv2. IACR Trans. Symmetric Cryptol., 2018(3):163\u2013181, 2018.","DOI":"10.46586\/tosc.v2018.i3.163-181"},{"key":"9439_CR42","doi-asserted-by":"crossref","unstructured":"V. Strassen, Gaussian elimination is not optimal. Numer. Math. 13, 354\u2013356 (1969)","DOI":"10.1007\/BF02165411"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09439-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-022-09439-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09439-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,20]],"date-time":"2022-10-20T16:11:08Z","timestamp":1666282268000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-022-09439-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10]]},"references-count":42,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,10]]}},"alternative-id":["9439"],"URL":"https:\/\/doi.org\/10.1007\/s00145-022-09439-x","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10]]},"assertion":[{"value":"19 April 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 August 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 August 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 October 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"28"}}