{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:11:07Z","timestamp":1785831067527,"version":"3.56.0"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T00:00:00Z","timestamp":1758240000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T00:00:00Z","timestamp":1758240000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2025,10]]},"DOI":"10.1007\/s00145-025-09554-5","type":"journal-article","created":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T15:39:08Z","timestamp":1758296348000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Improving Linear Key Recovery Attacks using Walsh Spectrum Puncturing"],"prefix":"10.1007","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7749-8925","authenticated-orcid":false,"given":"Antonio","family":"Fl\u00f3rez-Guti\u00e9rrez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6839-4777","authenticated-orcid":false,"given":"Yosuke","family":"Todo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,9,19]]},"reference":[{"key":"9554_CR1","doi-asserted-by":"publisher","unstructured":"Aumasson, J., Fischer, S., Khazaei, S., Meier, W., Rechberger, C.: New features of latin dances: Analysis of salsa, chacha, and rumba. In: Nyberg, K. (ed.) Fast Software Encryption, 15th International Workshop, FSE 2008, Lausanne, Switzerland, February 10-13, 2008, Revised Selected Papers. Lecture Notes in Computer Science, vol. 5086, pp. 470\u2013488. Springer (2008), https:\/\/doi.org\/10.1007\/978-3-540-71039-4_30","DOI":"10.1007\/978-3-540-71039-4_30"},{"key":"9554_CR2","unstructured":"Banik, S., Chakraborti, A., Iwata, T., Minematsu, K., Nandi, M., Peyrin, T., Sasaki, Y., Sim, S.M., Todo, Y.: GIFT-COFB. IACR Cryptol. ePrint Arch. p. 738 (2020), https:\/\/eprint.iacr.org\/2020\/738"},{"key":"9554_CR3","doi-asserted-by":"crossref","unstructured":"Banik, S., Pandey, S.K., Peyrin, T., Sasaki, Y., Sim, S.M., Todo, Y.: GIFT: A small present - towards reaching the limit of lightweight encryption. In: Cryptographic Hardware and Embedded Systems - CHES 2017, Proceedings. Lecture Notes in Computer Science, vol. 10529, pp. 321\u2013345. Springer (2017)","DOI":"10.1007\/978-3-319-66787-4_16"},{"issue":"4","key":"9554_CR4","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/s00145-022-09437-z","volume":"35","author":"C Beierle","year":"2022","unstructured":"Beierle, C., Broll, M., Canale, F., David, N., Fl\u00f3rez-Guti\u00e9rrez, A., Leander, G., Naya-Plasencia, M., Todo, Y.: Improved differential-linear attacks with applications to ARX ciphers. Journal of Cryptology 35(4), \u00a029 (2022)","journal-title":"Journal of Cryptology"},{"key":"9554_CR5","doi-asserted-by":"crossref","unstructured":"Beyne, T.: A geometric approach to linear cryptanalysis. In: Advances in Cryptology - ASIACRYPT 2021, Prooceedings. Lecture Notes in Computer Science, vol. 13090, pp. 36\u201366. Springer (2021)","DOI":"10.1007\/978-3-030-92062-3_2"},{"key":"9554_CR6","doi-asserted-by":"crossref","unstructured":"Biham, E., Anderson, R.J., Knudsen, L.R.: Serpent: A new block cipher proposal. In: Fast Software Encryption 1998, Proceedings. Lecture Notes in Computer Science, vol. 1372, pp. 222\u2013238. Springer (1998)","DOI":"10.1007\/3-540-69710-1_15"},{"key":"9554_CR7","unstructured":"Biham, E., Anderson, R.J., Knudsen, L.R.: Serpent: A proposal for the Advanced Encryption Standard. AES competition (1998)"},{"key":"9554_CR8","doi-asserted-by":"crossref","unstructured":"Biham, E., Dunkelman, O., Keller, N.: Differential-linear cryptanalysis of serpent. In: Fast Software Encryption, 10th International Workshop, Revised Papers. Lecture Notes in Computer Science, vol. 2887, pp. 9\u201321. Springer (2003)","DOI":"10.1007\/978-3-540-39887-5_2"},{"key":"9554_CR9","doi-asserted-by":"crossref","unstructured":"Biham, E., Dunkelman, O., Keller, N.: Linear cryptanalysis of reduced round serpent. In: Fast Software Encryption, 8th International Workshop, FSE 2001, Revised Papers. Lecture Notes in Computer Science, vol. 2355, pp. 16\u201327. Springer (2001)","DOI":"10.1007\/3-540-45473-X_2"},{"key":"9554_CR10","doi-asserted-by":"crossref","unstructured":"Biham, E., Shamir, A.: Differential cryptanalysis of the full 16-round DES. In: Advances in Cryptology - CRYPTO \u201992, Proceedings. Lecture Notes in Computer Science, vol. 740, pp. 487\u2013496. Springer (1992)","DOI":"10.1007\/3-540-48071-4_34"},{"issue":"3","key":"9554_CR11","doi-asserted-by":"publisher","first-page":"215","DOI":"10.46586\/tosc.v2018.i3.215-264","volume":"2018","author":"E Biham","year":"2018","unstructured":"Biham, E., Perle, S.: Conditional linear cryptanalysis - Cryptanalysis of DES with less than $$2^{42}$$ complexity. IACR Transactions on Symmetric Cryptology 2018(3), 215\u2013264 (2018)","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"9554_CR12","doi-asserted-by":"crossref","unstructured":"Biryukov, A., Canni\u00e8re, C.D., Quisquater, M.: On multiple linear approximations. In: Advances in Cryptology - CRYPTO 2004, Proceedings. Lecture Notes in Computer Science, vol. 3152, pp. 1\u201322. Springer (2004)","DOI":"10.1007\/978-3-540-28628-8_1"},{"issue":"2","key":"9554_CR13","first-page":"162","volume":"2016","author":"C Blondeau","year":"2016","unstructured":"Blondeau, C., Nyberg, K.: Improved parameter estimates for correlation and capacity deviates in linear cryptanalysis. IACR Transactions on Symmetric Cryptology 2016(2), 162\u2013191 (2016)","journal-title":"IACR Transactions on Symmetric Cryptology"},{"issue":"1\u20132","key":"9554_CR14","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/s10623-016-0268-6","volume":"82","author":"C Blondeau","year":"2017","unstructured":"Blondeau, C., Nyberg, K.: Joint data and key distribution of simple, multiple, and multidimensional linear cryptanalysis test statistic and its impact to data complexity. Designs, Codes and Cryptography 82(1-2), 319\u2013349 (2017)","journal-title":"Designs, Codes and Cryptography"},{"key":"9554_CR15","doi-asserted-by":"crossref","unstructured":"Bogdanov, A., Vejre, P.S.: Linear cryptanalysis of DES with asymmetries. In: Advances in Cryptology - ASIACRYPT 2017, Proceedings. Lecture Notes in Computer Science, vol. 10624, pp. 187\u2013216. Springer (2017)","DOI":"10.1007\/978-3-319-70694-8_7"},{"key":"9554_CR16","doi-asserted-by":"crossref","unstructured":"Broll, M., Canale, F., David, N., Fl\u00f3rez-Guti\u00e9rrez, A., Leander, G., Naya-Plasencia, M., Todo, Y.: New attacks from old distinguishers - Improved attacks on serpent. In: Topics in Cryptology - CT-RSA 2022, Proceedings. Lecture Notes in Computer Science, vol. 13161, pp. 484\u2013510. Springer (2022)","DOI":"10.1007\/978-3-030-95312-6_20"},{"key":"9554_CR17","doi-asserted-by":"crossref","unstructured":"Broll, M., Canale, F., Fl\u00f3rez-Guti\u00e9rrez, A., Leander, G., Naya-Plasencia, M.: Generic framework for key-guessing improvements. In: Advances in Cryptology - ASIACRYPT 2021, Proceedings, Part I. Lecture Notes in Computer Science, vol. 13090, pp. 453\u2013483. Springer (2021)","DOI":"10.1007\/978-3-030-92062-3_16"},{"key":"9554_CR18","doi-asserted-by":"crossref","unstructured":"Carlet, C.: Boolean Functions for Cryptography and Coding Theory. Cambridge University Press (2021)","DOI":"10.1017\/9781108606806"},{"key":"9554_CR19","doi-asserted-by":"crossref","unstructured":"Chakraborti, A., Iwata, T., Minematsu, K., Nandi, M.: Blockcipher-based authenticated encryption: How small can we go? In: Cryptographic Hardware and Embedded Systems - CHES 2017 - 19th International Conference, Proceedings. Lecture Notes in Computer Science, vol. 10529, pp. 277\u2013298. Springer (2017)","DOI":"10.1007\/978-3-319-66787-4_14"},{"key":"9554_CR20","unstructured":"Chakraborti, A., Nilanjan Datta\u00a0and, A.J., Nandi, M.: HyENA. Submission to the NIST Lightweight Cryptography project, 2019. (2019), https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/lightweight-cryptography\/documents\/round-2\/spec-doc-rnd2\/hyena-spec-round2.pdf"},{"key":"9554_CR21","doi-asserted-by":"crossref","unstructured":"Collard, B., Standaert, F., Quisquater, J.: Improved and multiple linear cryptanalysis of reduced round Serpent. In: Information Security and Cryptology, Inscrypt 2007, Revised Selected Papers. Lecture Notes in Computer Science, vol. 4990, pp. 51\u201365. Springer (2007)","DOI":"10.1007\/978-3-540-79499-8_6"},{"key":"9554_CR22","doi-asserted-by":"crossref","unstructured":"Collard, B., Standaert, F., Quisquater, J.: Improving the time complexity of Matsui\u2019s linear cryptanalysis. In: Information Security and Cryptology - ICISC 2007, Proceedings. Lecture Notes in Computer Science, vol. 4817, pp. 77\u201388. Springer (2007)","DOI":"10.1007\/978-3-540-76788-6_7"},{"key":"9554_CR23","doi-asserted-by":"crossref","unstructured":"Cooley, J., Tukey, J.: An algorithm for the machine calculation of complex Fourier series. Mathematics of Computation 19, 297\u2013301 (01 1965)","DOI":"10.1090\/S0025-5718-1965-0178586-1"},{"key":"9554_CR24","doi-asserted-by":"crossref","unstructured":"Daemen, J., Govaerts, R., Vandewalle, J.: Correlation matrices. In: Fast Software Encryption 1994, Proceedings. Lecture Notes in Computer Science, vol. 1008, pp. 275\u2013285. Springer (1994)","DOI":"10.1007\/3-540-60590-8_21"},{"key":"9554_CR25","doi-asserted-by":"crossref","unstructured":"Daemen, J., Peeters, M., Van\u00a0Assche, G., Rijmen, V.: The NOEKEON block cipher. Proposal to the NESSIE Project (2000)","DOI":"10.1007\/10721064_22"},{"key":"9554_CR26","unstructured":"Data Encryption Standard (DES). Federal Information Processing Standards Publication 46-3, U.S. Department of Commerce, National Institute of Standards and Technology (1977, reaffirmed 1988,1993,1999, withdrawn 2005)"},{"issue":"1","key":"9554_CR27","first-page":"49","volume":"4","author":"P Erd\u00f6s","year":"1959","unstructured":"Erd\u00f6s, P., R\u00e9nyi, A.: On the central limit theorem for samples from a finite population. Publications of the Mathematical Institute of the Hungarian Academy of Sciences 4(1), 49\u201357 (1959)","journal-title":"Publications of the Mathematical Institute of the Hungarian Academy of Sciences"},{"key":"9554_CR28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78783-9","volume-title":"The Doctrine of Chances: Probabilistic Aspects of Gambling","author":"SN Ethier","year":"2010","unstructured":"Ethier, S.N.: The Doctrine of Chances: Probabilistic Aspects of Gambling. Probability and its Applications, Springer (2010)"},{"key":"9554_CR29","doi-asserted-by":"crossref","unstructured":"Fl\u00f3rez-Guti\u00e9rrez, A., Naya-Plasencia, M.: Improving key-recovery in linear attacks: Application to 28-round PRESENT. In: Advances in Cryptology - EUROCRYPT 2020, Proceedings. Lecture Notes in Computer Science, vol. 12105, pp. 221\u2013249. Springer (2020)","DOI":"10.1007\/978-3-030-45721-1_9"},{"key":"9554_CR30","doi-asserted-by":"publisher","unstructured":"Fl\u00f3rez-Guti\u00e9rrez, A., Todo, Y.: Improving linear key recovery attacks using walsh spectrum puncturing. In: Joye, M., Leander, G. (eds.) Advances in Cryptology - EUROCRYPT 2024 - 43rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland, May 26-30, 2024, Proceedings, Part I. Lecture Notes in Computer Science, vol. 14651, pp. 187\u2013216. Springer (2024), https:\/\/doi.org\/10.1007\/978-3-031-58716-0_7","DOI":"10.1007\/978-3-031-58716-0_7"},{"key":"9554_CR31","doi-asserted-by":"crossref","unstructured":"Fl\u00f3rez-Guti\u00e9rrez, A.: Optimising linear key recovery attacks with affine Walsh transform pruning. In: Advances in Cryptology - ASIACRYPT 2022, Proceedings. Lecture Notes in Computer Science, vol. 13794. Springer (2022)","DOI":"10.1007\/978-3-031-22972-5_16"},{"key":"9554_CR32","doi-asserted-by":"crossref","unstructured":"Hermelin, M., Cho, J.Y., Nyberg, K.: Multidimensional extension of Matsui\u2019s Algorithm 2. In: Fast Software Encryption, FSE 2009, Revised Selected Papers. Lecture Notes in Computer Science, vol. 5665, pp. 209\u2013227. Springer (2009)","DOI":"10.1007\/978-3-642-03317-9_13"},{"key":"9554_CR33","doi-asserted-by":"crossref","unstructured":"Hermelin, M., Cho, J.Y., Nyberg, K.: Multidimensional linear cryptanalysis of reduced round Serpent. In: Australasian Conference on Information Security and Privacy, ACISP 2008, Proceedings. pp. 203\u2013215 (2008)","DOI":"10.1007\/978-3-540-70500-0_15"},{"issue":"1","key":"9554_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s00145-018-9308-x","volume":"32","author":"M Hermelin","year":"2019","unstructured":"Hermelin, M., Cho, J.Y., Nyberg, K.: Multidimensional linear cryptanalysis. Journal of Cryptology 32(1), 1\u201334 (2019)","journal-title":"Journal of Cryptology"},{"key":"9554_CR35","doi-asserted-by":"crossref","unstructured":"Liu, M., Lu, X., Lin, D.: Differential-linear cryptanalysis from an algebraic perspective. In: Advances in Cryptology - CRYPTO 2021, Virtual Event, Proceedings, Part III. Lecture Notes in Computer Science, vol. 12827, pp. 247\u2013277. Springer (2021)","DOI":"10.1007\/978-3-030-84252-9_9"},{"key":"9554_CR36","doi-asserted-by":"crossref","unstructured":"Matsui, M., Yamagishi, A.: A new method for known plaintext attack of FEAL cipher. In: Advances in Cryptology - EUROCRYPT \u201992, Proceedings. Lecture Notes in Computer Science, vol. 658, pp. 81\u201391. Springer (1992)","DOI":"10.1007\/3-540-47555-9_7"},{"key":"9554_CR37","doi-asserted-by":"crossref","unstructured":"Matsui, M.: Linear cryptanalysis method for DES cipher. In: Advances in Cryptology - EUROCRYPT \u201993, Proceedings. Lecture Notes in Computer Science, vol. 765, pp. 386\u2013397. Springer (1993)","DOI":"10.1007\/3-540-48285-7_33"},{"key":"9554_CR38","doi-asserted-by":"crossref","unstructured":"Matsui, M.: The first experimental cryptanalysis of the Data Encryption Standard. In: Advances in Cryptology - CRYPTO \u201994, Proceedings. Lecture Notes in Computer Science, vol. 839, pp. 1\u201311. Springer (1994)","DOI":"10.1007\/3-540-48658-5_1"},{"key":"9554_CR39","doi-asserted-by":"crossref","unstructured":"McLaughlin, J., Clark, J.A.: Filtered nonlinear cryptanalysis of reduced-round Serpent, and the wrong-key randomization hypothesis. In: IMA International Conference on Cryptography and Coding, IMACC 2013, Proceedings. Lecture Notes in Computer Science, vol. 8308, pp. 120\u2013140. Springer (2013)","DOI":"10.1007\/978-3-642-45239-0_8"},{"key":"9554_CR40","unstructured":"Nguyen, P.H., Wu, H., Wang, H.: Improving the algorithm 2 in multidimensional linear cryptanalysis. In: Information Security and Privacy - 16th Australasian Conference, ACISP 2011, Melbourne, Australia, July 11-13, 2011. Proceedings. Lecture Notes in Computer Science, vol. 6812, pp. 61\u201374. Springer (2011)"},{"key":"9554_CR41","doi-asserted-by":"crossref","unstructured":"Nyberg, K.: Linear approximation of block ciphers. In: Advances in Cryptology - EUROCRYPT \u201994, Proceedings. Lecture Notes in Computer Science, vol. 950, pp. 439\u2013444. Springer (1994)","DOI":"10.1007\/BFb0053460"},{"key":"9554_CR42","unstructured":"O\u2019Donnell, R.: Analysis of Boolean Functions. Cambridge University Press (2014)"},{"issue":"1","key":"9554_CR43","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s00145-007-9013-7","volume":"21","author":"AA Sel\u00e7uk","year":"2008","unstructured":"Sel\u00e7uk, A.A.: On probability of success in linear and differential cryptanalysis. Journal of Cryptology 21(1), 131\u2013147 (2008)","journal-title":"Journal of Cryptology"},{"issue":"2","key":"9554_CR44","doi-asserted-by":"publisher","first-page":"199","DOI":"10.46586\/tosc.v2021.i2.199-221","volume":"2021","author":"L Sun","year":"2021","unstructured":"Sun, L., Wang, W., Wang, M.: Linear cryptanalyses of three AEADs with GIFT-128 as underlying primitives. IACR Transactions on Symmetric Cryptology 2021(2), 199\u2013221 (2021)","journal-title":"IACR Transactions on Symmetric Cryptology"},{"issue":"1","key":"9554_CR45","doi-asserted-by":"publisher","first-page":"212","DOI":"10.46586\/tosc.v2022.i1.212-219","volume":"2022","author":"L Sun","year":"2022","unstructured":"Sun, L., Wang, W., Wang, M.: Addendum to linear cryptanalyses of three AEADs with GIFT-128 as underlying primitives. IACR Transactions on Symmetric Cryptology 2022(1), 212\u2013219 (2022)","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"9554_CR46","doi-asserted-by":"publisher","unstructured":"Wang, S., Liu, M., Hou, S., Lin, D.: Differential-linear cryptanalysis of GIFT family and gift-based ciphers. IACR Commun. Cryptol. 1(1), \u00a013 (2024), https:\/\/doi.org\/10.62056\/a6n5txol7","DOI":"10.62056\/a6n5txol7"},{"issue":"1","key":"9554_CR47","doi-asserted-by":"publisher","first-page":"156","DOI":"10.46586\/tosc.v2021.i1.156-184","volume":"2021","author":"R Zong","year":"2021","unstructured":"Zong, R., Dong, X., Chen, H., Luo, Y., Wang, S., Li, Z.: Towards key-recovery-attack friendly distinguishers: Application to GIFT-128. IACR Transactions on Symmetric Cryptology 2021(1), 156\u2013184 (2021)","journal-title":"IACR Transactions on Symmetric Cryptology"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-025-09554-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-025-09554-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-025-09554-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T03:16:49Z","timestamp":1761621409000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-025-09554-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,19]]},"references-count":47,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,10]]}},"alternative-id":["9554"],"URL":"https:\/\/doi.org\/10.1007\/s00145-025-09554-5","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,19]]},"assertion":[{"value":"14 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 August 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 August 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 September 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"34"}}