{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T16:11:32Z","timestamp":1778083892412,"version":"3.51.4"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T00:00:00Z","timestamp":1771545600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T00:00:00Z","timestamp":1771545600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1007\/s00145-026-09575-8","type":"journal-article","created":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T23:16:19Z","timestamp":1771629379000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Exponential Sums in Linear Cryptanalysis"],"prefix":"10.1007","volume":"39","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5638-9885","authenticated-orcid":false,"given":"Tim","family":"Beyne","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9554-9543","authenticated-orcid":false,"given":"Cl\u00e9mence","family":"Bouvier","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,2,20]]},"reference":[{"issue":"2","key":"9575_CR1","doi-asserted-by":"publisher","first-page":"367","DOI":"10.2307\/1971424","volume":"130","author":"Alan Adolphson","year":"1989","unstructured":"Alan Adolphson and Steven Sperber. Exponential sums and Newton polyhedra: cohomology and estimates. Annals of Mathematics, 130(2):367\u2013406, 1989.","journal-title":"Annals of Mathematics"},{"key":"9575_CR2","doi-asserted-by":"crossref","unstructured":"Martin R. Albrecht, Lorenzo Grassi, Christian Rechberger, Arnab Roy, and Tyge Tiessen. MiMC: Efficient encryption and cryptographic hashing with minimal multiplicative complexity. In Jung Hee Cheon and Tsuyoshi Takagi, editors, Advances in Cryptology \u2013 ASIACRYPT 2016, Part I, volume 10031 of Lecture Notes in Computer Science, pages 191\u2013219, Hanoi, Vietnam, December 4\u20138, 2016. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/978-3-662-53887-6_7"},{"issue":"3","key":"9575_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.46586\/tosc.v2020.i3.1-45","volume":"2020","author":"Abdelrahaman Aly","year":"2020","unstructured":"Abdelrahaman Aly, Tomer Ashur, Eli Ben-Sasson, Siemen Dhooghe, and Alan Szepieniec. Design of symmetric-key primitives for advanced cryptographic protocols. IACR Transactions on Symmetric Cryptology, 2020(3):1\u201345, 2020.","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"9575_CR4","doi-asserted-by":"crossref","unstructured":"Thomas Baign\u00e8res, Jacques Stern, and Serge Vaudenay. Linear cryptanalysis of non binary ciphers. In Carlisle M. Adams, Ali Miri, and Michael J. Wiener, editors, SAC 2007: 14th Annual International Workshop on Selected Areas in Cryptography, volume 4876 of Lecture Notes in Computer Science, pages 184\u2013211, Ottawa, Canada, August 16\u201317, 2007. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/978-3-540-77360-3_13"},{"key":"9575_CR5","doi-asserted-by":"crossref","unstructured":"Tim Beyne. Block cipher invariants as eigenvectors of correlation matrices. In Thomas Peyrin and Steven Galbraith, editors, Advances in Cryptology \u2013 ASIACRYPT 2018, Part I, volume 11272 of Lecture Notes in Computer Science, pages 3\u201331, Brisbane, Queensland, Australia, December 2\u20136, 2018. Springer, Cham, Switzerland.","DOI":"10.1007\/978-3-030-03326-2_1"},{"key":"9575_CR6","unstructured":"Tim Beyne. Linear cryptanalysis in the weak key model. Master\u2019s thesis, KU Leuven, 2019."},{"key":"9575_CR7","doi-asserted-by":"crossref","unstructured":"Tim Beyne. A geometric approach to linear cryptanalysis. In Mehdi Tibouchi and Huaxiong Wang, editors, Advances in Cryptology \u2013 ASIACRYPT 2021, Part I, volume 13090 of Lecture Notes in Computer Science, pages 36\u201366, Singapore, December 6\u201310, 2021. Springer, Cham, Switzerland.","DOI":"10.1007\/978-3-030-92062-3_2"},{"key":"9575_CR8","doi-asserted-by":"crossref","unstructured":"Tim Beyne. A geometric approach to symmetric-key cryptanalysis. PhD thesis, KU Leuven, June 2023.","DOI":"10.46586\/tosc.v2023.i4.244-269"},{"key":"9575_CR9","unstructured":"Tim Beyne and Cl\u00e9mence Bouvier. Linear approximations of the Flystel construction. Cryptology ePrint Archive, Paper 2024\/1465, 2024."},{"key":"9575_CR10","unstructured":"Tim Beyne, Anne Canteaut, Gregor Leander, Mar\u00eda Naya-Plasencia, L\u00e9o Perrin, and Friedrich Wiemer. On the security of the rescue hash function. Cryptology ePrint Archive, Report 2020\/820, 2020."},{"key":"9575_CR11","unstructured":"Cl\u00e9mence Bouvier. Cryptanalysis and design of symmetric primitives defined over large finite fields. PhD thesis, Sorbonne Universit\u00e9, November 2023."},{"key":"9575_CR12","doi-asserted-by":"crossref","unstructured":"Cl\u00e9mence Bouvier, Pierre Briaud, Pyrros Chaidos, L\u00e9o Perrin, Robin Salen, Vesselin Velichkov, and Danny Willems. New design techniques for efficient arithmetization-oriented hash functions: Anemoi permutations and Jive compression mode. In Helena Handschuh and Anna Lysyanskaya, editors, Advances in Cryptology \u2013 CRYPTO 2023, Part III, volume 14083 of Lecture Notes in Computer Science, pages 507\u2013539, Santa Barbara, CA, USA, August 20\u201324, 2023. Springer, Cham, Switzerland.","DOI":"10.1007\/978-3-031-38548-3_17"},{"key":"9575_CR13","doi-asserted-by":"crossref","unstructured":"Cl\u00e9mence Bouvier, Pierre Briaud, Pyrros Chaidos, L\u00e9o Perrin, Robin Salen, Vesselin Velichkov, and Danny Willems. New design techniques for efficient arithmetization-oriented hash functions: Anemoi permutations and Jive compression mode. Cryptology ePrint Archive, Paper 2022\/840, 2022.","DOI":"10.1007\/978-3-031-38548-3_17"},{"issue":"11","key":"9575_CR14","doi-asserted-by":"publisher","first-page":"7575","DOI":"10.1109\/TIT.2017.2676807","volume":"63","author":"Anne Canteaut","year":"2017","unstructured":"Anne Canteaut, S\u00e9bastien Duval, and L\u00e9o Perrin. A generalisation of Dillon\u2019s APN permutation with the best known differential and nonlinear properties for all fields of size $$2^{4k+2}$$. IEEE Trans. Inf. Theory, Vol. 63(11):7575\u20137591, 2017.","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"6","key":"9575_CR15","doi-asserted-by":"publisher","first-page":"1147","DOI":"10.1007\/s12095-019-00361-x","volume":"11","author":"Anne Canteaut","year":"2019","unstructured":"Anne Canteaut, L\u00e9o Perrin, and Shizhu Tian. If a generalised butterfly is APN then it operates on 6 bits. Cryptography and Communications, Vol. 11(6):1147\u20131164, 2019.","journal-title":"Cryptography and Communications"},{"key":"9575_CR16","doi-asserted-by":"crossref","unstructured":"Anne Canteaut and Jo\u00eblle Rou\u00e9. On the behaviors of affine equivalent sboxes regarding differential and linear attacks. In Elisabeth Oswald and Marc Fischlin, editors, Advances in Cryptology \u2013 EUROCRYPT 2015, Part I, volume 9056 of Lecture Notes in Computer Science, pages 45\u201374, Sofia, Bulgaria, April 26\u201330, 2015. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/978-3-662-46800-5_3"},{"issue":"2","key":"9575_CR17","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1023\/A:1008344232130","volume":"15","author":"Claude Carlet","year":"1998","unstructured":"Claude Carlet, Pascale Charpin, and Victor Zinoviev. Codes, bent functions and permutations suitable for DES-like cryptosystems. Designs, Codes and Cryptography, Vol. 15(2):125\u2013156, 1998.","journal-title":"Designs, Codes and Cryptography"},{"key":"9575_CR18","unstructured":"Joan Daemen and Vincent Rijmen. The wide trail design strategy. In Bahram Honary, editor, 8th IMA International Conference on Cryptography and Coding, volume 2260 of Lecture Notes in Computer Science, pages 222\u2013238, Cirencester, UK, December 17\u201319, 2001. Springer, Berlin, Heidelberg, Germany."},{"key":"9575_CR19","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/BF02684373","volume":"43","author":"Pierre Deligne","year":"1974","unstructured":"Pierre Deligne. La conjecture de Weil: I. Publication Math\u00e9matiques de l\u2019IH\u00c9S, 43:273\u2013307, 1974.","journal-title":"Publication Math\u00e9matiques de l\u2019IH\u00c9S"},{"key":"9575_CR20","doi-asserted-by":"crossref","unstructured":"Pierre Deligne. S\u00e9minaire de g\u00e9om\u00e9trie alg\u00e9brique du Bois Marie \u2013 cohomologie \u00e9tale (SGA $$4\\frac{1}{2}$$). Lecture Notes in Mathematics, 1977.","DOI":"10.1007\/BFb0091516"},{"key":"9575_CR21","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/BF02684780","volume":"52","author":"Pierre Deligne","year":"1980","unstructured":"Pierre Deligne. La conjecture de Weil: II. Publications Math\u00e9matiques de l\u2019IH\u00c9S, 52:137\u2013252, 1980.","journal-title":"Publications Math\u00e9matiques de l\u2019IH\u00c9S"},{"issue":"1","key":"9575_CR22","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/BF01243914","volume":"106","author":"Jan Denef","year":"1991","unstructured":"Jan Denef and Fran\u00e7ois Loeser. Weights of exponential sums, intersection cohomology, and Newton polyhedra. Inventiones mathematicae, 106(1):275\u2013294, 1991.","journal-title":"Inventiones mathematicae"},{"issue":"2","key":"9575_CR23","first-page":"228","volume":"2017","author":"Fu Shihui","year":"2017","unstructured":"Shihui Fu, Xiutao Feng, and Baofeng Wu. Differentially 4-uniform permutations with the best known nonlinearity from butterflies. IACR Transactions on Symmetric Cryptology, 2017(2):228\u2013249, 2017.","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"9575_CR24","unstructured":"Lorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy, and Markus Schofnegger. Poseidon: A new hash function for zero-knowledge proof systems. In Michael Bailey and Rachel Greenstadt, editors, USENIX Security 2021: 30th USENIX Security Symposium, pages 519\u2013535. USENIX Association, August 11\u201313, 2021."},{"key":"9575_CR25","unstructured":"Alexander Grothendieck. S\u00e9minaire de g\u00e9om\u00e9trie alg\u00e9brique du Bois Marie \u2013 cohomologie $$\\ell $$-adique et fonctions $$L$$. Lecture Notes in Mathematics, 1977."},{"key":"9575_CR26","doi-asserted-by":"crossref","unstructured":"Seokhie Hong, Sangjin Lee, Jongin Lim, Jaechul Sung, Dong Hyeon Cheon, and Inho Cho. Provable security against differential and linear cryptanalysis for the SPN structure. In Bruce Schneier, editor, Fast Software Encryption \u2013 FSE 2000, volume 1978 of Lecture Notes in Computer Science, pages 273\u2013283, New York, NY, USA, April 10\u201312, 2001. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/3-540-44706-7_19"},{"issue":"2","key":"9575_CR27","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1049\/iet-ifs:20060161","volume":"1","author":"Liam Keliher","year":"2007","unstructured":"Liam Keliher and Jiayuan Sui. Exact maximum expected differential and linear probability for two-round advanced encryption standard. IET Information Security, 1(2):53\u201357, 2007.","journal-title":"IET Information Security"},{"issue":"1","key":"9575_CR28","doi-asserted-by":"publisher","first-page":"160","DOI":"10.46586\/tosc.v2018.i1.160-179","volume":"2018","author":"Yongqiang Li","year":"2018","unstructured":"Yongqiang Li, Shizhu Tian, Yuyin Yu, and Mingsheng Wang. On the generalization of butterfly structure. IACR Transactions on Symmetric Cryptology, 2018(1):160\u2013179, 2018.","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"9575_CR29","volume-title":"Singular points of complex hypersurfaces","author":"John Willard Milnor","year":"1968","unstructured":"John Willard Milnor. Singular points of complex hypersurfaces. Annals of Mathematics Studies. Princeton University Press, 1968."},{"key":"9575_CR30","doi-asserted-by":"crossref","unstructured":"Kaisa Nyberg. Differentially uniform mappings for cryptography. In Tor Helleseth, editor, Advances in Cryptology \u2013 EUROCRYPT\u201993, volume 765 of Lecture Notes in Computer Science, pages 55\u201364, Lofthus, Norway, May 23\u201327, 1994. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/3-540-48285-7_6"},{"issue":"1","key":"9575_CR31","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/BF00204800","volume":"8","author":"Kaisa Nyberg","year":"1995","unstructured":"Kaisa Nyberg and Lars R. Knudsen. Provable security against a differential attack. Journal of Cryptology, 8(1):27\u201337, 1995.","journal-title":"Journal of Cryptology"},{"key":"9575_CR32","doi-asserted-by":"crossref","unstructured":"L\u00e9o Perrin, Aleksei Udovenko, and Alex Biryukov. Cryptanalysis of a theorem: Decomposing the only known solution to the big APN problem. In Matthew Robshaw and Jonathan Katz, editors, Advances in Cryptology \u2013 CRYPTO 2016, Part II, volume 9815 of Lecture Notes in Computer Science, pages 93\u2013122, Santa Barbara, CA, USA, August 14\u201318, 2016. Springer, Berlin, Heidelberg, Germany.","DOI":"10.1007\/978-3-662-53008-5_4"},{"issue":"2","key":"9575_CR33","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1112\/S0010437X05001697","volume":"142","author":"Antonio Rojas-Le\u00f3n","year":"2006","unstructured":"Antonio Rojas-Le\u00f3n. Purity of exponential sums on $${\\mathbb{A}}^{n}$$. Compositio Mathematica, 142(2):295\u2013306, 2006.","journal-title":"Compositio Mathematica"},{"issue":"5","key":"9575_CR34","doi-asserted-by":"publisher","first-page":"204","DOI":"10.1073\/pnas.34.5.204","volume":"34","author":"Andr\u00e9 Weil","year":"1948","unstructured":"Andr\u00e9 Weil. On some exponential sums. Proceedings of the National Academy of Sciences, 34(5):204\u2013207, 1948.","journal-title":"Proceedings of the National Academy of Sciences"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-026-09575-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-026-09575-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-026-09575-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T15:18:45Z","timestamp":1778080725000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-026-09575-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,20]]},"references-count":34,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["9575"],"URL":"https:\/\/doi.org\/10.1007\/s00145-026-09575-8","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,20]]},"assertion":[{"value":"25 October 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 January 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 January 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 February 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"16"}}