{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:26:33Z","timestamp":1775838393020,"version":"3.50.1"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T00:00:00Z","timestamp":1718668800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T00:00:00Z","timestamp":1718668800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2024,11]]},"DOI":"10.1007\/s10623-024-01444-4","type":"journal-article","created":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T12:01:56Z","timestamp":1718712116000},"page":"3391-3427","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Multivariate correlation attacks and the cryptanalysis of LFSR-based stream ciphers"],"prefix":"10.1007","volume":"92","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0776-5060","authenticated-orcid":false,"given":"Isaac A.","family":"Canales-Mart\u00ednez","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Semaev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,6,18]]},"reference":[{"issue":"1","key":"1444_CR1","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1504\/IJWMC.2011.044106","volume":"5","author":"M \u00c5gren","year":"2011","unstructured":"\u00c5gren M., Hell M., Johansson T., Meier W.: Grain-128a: a new version of Grain-128 with optional authentication. Int. J. Wirel. Mobile Comput. 5(1), 48\u201359 (2011).","journal-title":"Int. J. Wirel. Mobile Comput."},{"issue":"3","key":"1444_CR2","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/s12095-012-0062-x","volume":"4","author":"M \u00c5gren","year":"2012","unstructured":"\u00c5gren M., L\u00f6ndahl C., Hell M., Johansson T.: A survey on fast correlation attacks. Cryptogr. Commun. 4(3), 173\u2013202 (2012).","journal-title":"Cryptogr. Commun."},{"key":"1444_CR3","doi-asserted-by":"crossref","unstructured":"Anderson R.: Searching for the optimum correlation attack. In: Preneel B. (ed.) Fast Software Encryption, vol. 1008, pp. 137\u2013143. Lecture Notes in Computer Science. Springer, Berlin (1995).","DOI":"10.1007\/3-540-60590-8_11"},{"key":"1444_CR4","unstructured":"Billingsley P.: Probability and Measure, 3rd edn. Wiley Series in Probability and Statistics. Wiley, New York (1995)."},{"key":"1444_CR5","doi-asserted-by":"crossref","unstructured":"Biryukov A., Shamir A.: Cryptanalytic time\/memory\/data tradeoffs for stream ciphers. In: Okamoto T. (ed.) Advances in Cryptology\u2014ASIACRYPT 2000, vol. 1976, pp. 1\u201313. Lecture Notes in Computer Science. Springer, Berlin (2000).","DOI":"10.1007\/3-540-44448-3_1"},{"key":"1444_CR6","doi-asserted-by":"crossref","unstructured":"Canteaut A., Trabbia M.: Improved fast correlation attacks using parity-check equations of weight 4 and 5. In: Preneel B. (ed.) Advances in Cryptology\u2014EUROCRYPT 2000, vol. 1807, pp. 573\u2013588. Lecture Notes in Computer Science. Springer, Berlin (2000).","DOI":"10.1007\/3-540-45539-6_40"},{"key":"1444_CR7","volume-title":"Boolean Functions for Cryptography and Coding Theory","author":"C Carlet","year":"2021","unstructured":"Carlet C.: Boolean Functions for Cryptography and Coding Theory. Cambridge University Press, Cambridge (2021)."},{"key":"1444_CR8","doi-asserted-by":"crossref","unstructured":"Chepyzhov V., Johansson T., Smeets B.: A simple algorithm for fast correlation attacks on stream ciphers. In: Goos G., Hartmanis J., Leeuwen J., Schneier B. (eds.) Fast Software Encryption, vol. 1978, pp. 181\u2013195. Lecture Notes in Computer Science. Springer, Berlin (2001).","DOI":"10.1007\/3-540-44706-7_13"},{"key":"1444_CR9","doi-asserted-by":"crossref","unstructured":"Chose P., Joux A., Mitton M.: Fast correlation attacks: an algorithmic point of view. In: Knudsen L. (ed.) Advances in Cryptology\u2014EUROCRYPT 2002, vol. 2332, pp. 209\u2013221. Lecture Notes in Computer Science. Springer, Berlin (2002).","DOI":"10.1007\/3-540-46035-7_14"},{"key":"1444_CR10","doi-asserted-by":"crossref","unstructured":"Courtois N., Meier W.: Algebraic attacks on stream ciphers with linear feedback. In: Biham E. (ed.) Advances in Cryptology\u2014EUROCRYPT 2003, vol. 2656, pp. 345\u2013359. Lecture Notes in Computer Science. Springer, Berlin (2003).","DOI":"10.1007\/3-540-39200-9_21"},{"key":"1444_CR11","doi-asserted-by":"crossref","unstructured":"Courtois N.: Fast algebraic attacks on stream ciphers with linear feedback. In: Boneh D. (ed.) Advances in Cryptology\u2014CRYPTO 2003, vol. 2729, pp. 176\u2013194. Lecture Notes in Computer Science. Springer, Berlin (2003).","DOI":"10.1007\/978-3-540-45146-4_11"},{"key":"1444_CR12","doi-asserted-by":"crossref","unstructured":"Didier F.: Attacking the filter generator by finding zero inputs of the filtering function. In: Srinathan K., Pandu Rangan C., Yung M. (eds.) Progress in Cryptology\u2014INDOCRYPT 2007, vol. 4859, pp. 404\u2013413. Lecture Notes in Computer Science. Springer, Berlin (2007).","DOI":"10.1007\/978-3-540-77026-8_32"},{"key":"1444_CR13","doi-asserted-by":"crossref","unstructured":"Ekdahl P., Maximov A., Johansson T., Yang J.: SNOW-Vi: an extreme performance variant of SNOW-V for lower grade CPUs. In: P\u00f6pper C., Vanhoef M., Batina L., Mayrhofer R. (eds.) WiSec \u201921, pp. 261\u2013272. Association for Computing Machinery, New York (2021).","DOI":"10.1145\/3448300.3467829"},{"issue":"3","key":"1444_CR14","first-page":"1","volume":"2019","author":"P Ekdahl","year":"2019","unstructured":"Ekdahl P., Johansson T., Maximov A., Yang J.: A new SNOW stream cipher called SNOW-V. IACR Trans. Symm. Cryptol. 2019(3), 1\u201342 (2019).","journal-title":"IACR Trans. Symm. Cryptol."},{"issue":"2","key":"1444_CR15","doi-asserted-by":"publisher","first-page":"79","DOI":"10.46586\/tosc.v2018.i2.79-110","volume":"2018","author":"S Fauskanger","year":"2018","unstructured":"Fauskanger S., Semaev I.: Separable statistics and multidimensional linear cryptanalysis. IACR Tran. Symm. Cryptol. 2018(2), 79\u2013110 (2018).","journal-title":"IACR Tran. Symm. Cryptol."},{"key":"1444_CR16","unstructured":"Goli\u0107 J.D., Morgari G.: Vectorial fast correlation attacks. Cryptology. ePrint Archive, Paper 2004\/247 (2004). https:\/\/eprint.iacr.org\/2004\/247."},{"key":"1444_CR17","doi-asserted-by":"crossref","unstructured":"Goli\u0107 J.D.: On the security of nonlinear filter generators. In: Gollmann D. (ed.) Fast Software Encryption, vol. 1039, pp. 173\u2013188. Lecture Notes Computer Science. Springer, Berlin (1996).","DOI":"10.1007\/3-540-60865-6_52"},{"issue":"10","key":"1444_CR18","doi-asserted-by":"publisher","first-page":"1100","DOI":"10.1109\/12.888045","volume":"49","author":"JD Goli\u0107","year":"2000","unstructured":"Goli\u0107 J.D., Clark A., Dwason E.: Generalized inversion attack on nonlinear filter generators. IEEE Trans. Comput. 49(10), 1100\u20131109 (2000).","journal-title":"IEEE Trans. Comput."},{"issue":"1","key":"1444_CR19","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/s10623-003-6148-x","volume":"35","author":"JD Goli\u0107","year":"2005","unstructured":"Goli\u0107 J.D., Hawkes P.: Vectorial approach to fast correlation attacks. Des. Codes Cryptogr. 35(1), 5\u201319 (2005).","journal-title":"Des. Codes Cryptogr."},{"key":"1444_CR20","doi-asserted-by":"crossref","unstructured":"Hell M., Johansson T., Maximov A., Meier W.: A stream cipher proposal: Grain-128. In: 2006 IEEE International Symposium on Information Theory, pp. 1614\u20131618. IEEE, New Jersey (2006).","DOI":"10.1109\/ISIT.2006.261549"},{"key":"1444_CR21","doi-asserted-by":"crossref","unstructured":"Hell M., Johansson T., Maximov A., Meier W.: In: Robshaw, M., Billet, O. (eds.) The Grain Family of Stream Ciphers. Lecture Notes in Computer Science, vol. 4986, pp. 179\u2013190. Springer, Berlin (2008).","DOI":"10.1007\/978-3-540-68351-3_14"},{"issue":"1","key":"1444_CR22","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1504\/IJWMC.2007.013798","volume":"2","author":"M Hell","year":"2007","unstructured":"Hell M., Johansson T., Meier W.: Grain: a stream cipher for constrained environments. Int. J. Wirel. Mobile Comput. 2(1), 86\u201393 (2007).","journal-title":"Int. J. Wirel. Mobile Comput."},{"key":"1444_CR23","doi-asserted-by":"crossref","unstructured":"Johansson T., J\u00f6nsson F.: Fast correlation attacks based on turbo code techniques. In: Wiener M. (ed.) Advances in Cryptology\u2014CRYPTO \u201999, vol. 1666, pp. 181\u2013197. Lecture Notes in Computer Science. Springer, Berlin (1999).","DOI":"10.1007\/3-540-48405-1_12"},{"key":"1444_CR24","doi-asserted-by":"crossref","unstructured":"Johansson T., J\u00f6nsson F.: Fast correlation attacks through reconstruction of linear polynomials. In: Bellare M. (ed.) Advances in Cryptology\u2014CRYPTO 2000, vol. 1880, pp. 300\u2013315. Lecture Notes in Computer Science. Springer, Berlin (2000).","DOI":"10.1007\/3-540-44598-6_19"},{"key":"1444_CR25","doi-asserted-by":"crossref","unstructured":"Johansson T., J\u00f6nsson F.: Improved fast correlation attacks on stream ciphers via convolutional codes. In: Stern J. (ed.) Advances in Cryptology\u2014EUROCRYPT \u201999, vol. 1592, pp. 347\u2013362. Lecture Notes in Computer Science. Springer, Berlin (1999).","DOI":"10.1007\/3-540-48910-X_24"},{"issue":"4","key":"1444_CR26","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"A Lenstra","year":"1982","unstructured":"Lenstra A., Lenstra H., Lov\u00e1sz L.: Factoring polynomials with rational coefficients. Math. Ann. 261(4), 515\u2013534 (1982).","journal-title":"Math. Ann."},{"key":"1444_CR27","doi-asserted-by":"crossref","unstructured":"Leveiller S., Boutros J., Guillot P., Z\u00e9mor G.: Cryptanalysis of nonlinear filter generators with $$\\{0, 1\\}$$-metric Viterbi decoding. In: Honary B. (ed.) Cryptography and Coding, vol. 2260, pp. 402\u2013414. Lecture Notes in Computer Science. Springer, Berlin (2001).","DOI":"10.1007\/3-540-45325-3_38"},{"key":"1444_CR28","doi-asserted-by":"crossref","unstructured":"Leveiller S., Z\u00e9mor G., Guillot P., Boutros J.: A new cryptanalytic attack for PN-generators filtered by a Boolean function. In: Nyberg K., Heys H. (eds.) Selected Areas in Cryptography, vol. 2595, pp. 232\u2013249. Lecture Notes in Computer Science. Springer, Berlin (2003).","DOI":"10.1007\/3-540-36492-7_16"},{"key":"1444_CR29","doi-asserted-by":"crossref","unstructured":"Meier W., Staffelbach O.: Nonlinearity criteria for cryptographic functions. In: Quisquater J.-J., Vandewalle J. (eds.) Advances in Cryptology\u2014EUROCRYPT \u201989, vol. 434, pp. 549\u2013562. Lecture Notes in Computer Science. Springer, Berlin (1990).","DOI":"10.1007\/3-540-46885-4_53"},{"key":"1444_CR30","doi-asserted-by":"crossref","unstructured":"Meier W.: Fast correlation attacks: methods and countermeasures. In: Joux, A. (ed.) Fast Software Encryption, vol. 6733, pp. 55\u201367. Lecture Notes in Computer Science. Springer, Berlin (2011).","DOI":"10.1007\/978-3-642-21702-9_4"},{"issue":"3","key":"1444_CR31","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/BF02252874","volume":"1","author":"W Meier","year":"1989","unstructured":"Meier W., Staffelbach O.: Fast correlation attacks on certain stream ciphers. J. Cryptol. 1(3), 159\u2013176 (1989).","journal-title":"J. Cryptol."},{"key":"1444_CR32","doi-asserted-by":"crossref","unstructured":"Mihaljevi\u0107 M., Fossorier M., Imai H.: Fast correlation attack algorithm with list decoding and an application. In: Matsui M. (ed.) Fast Software Encryption, vol. 2355, pp. 196\u2013210. Lecture Notes in Computer Science. Springer, Berlin (2002).","DOI":"10.1007\/3-540-45473-X_17"},{"key":"1444_CR33","doi-asserted-by":"crossref","unstructured":"Molland H., Mathiassen J.E., Helleseth T.: Improved fast correlation attack using low rate codes. In: Paterson K. (ed.) Cryptography and Coding, vol. 2898, pp. 67\u201381. Lecture Notes in Computer Science. Springer, Berlin (2003).","DOI":"10.1007\/978-3-540-40974-8_7"},{"key":"1444_CR34","unstructured":"R Core Team: R: A Language and Environment for Statistical Computing. R Foundation for Statistical Computing, Vienna (2021). https:\/\/www.R-project.org."},{"issue":"1","key":"1444_CR35","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/s10623-008-9180-z","volume":"49","author":"H Raddum","year":"2008","unstructured":"Raddum H., Semaev I.: Solving multiple right hand sides linear equations. Des. Codes Cryptogr. 49(1), 147\u2013160 (2008).","journal-title":"Des. Codes Cryptogr."},{"key":"1444_CR36","doi-asserted-by":"crossref","unstructured":"Shi Z., Jin C., Zhang J., Cui T., Ding L., Jin Y.: A correlation attack on full SNOW-V and SNOW-Vi. In: Dunkelman O., Dziembowski S. (eds.) Advances in Cryptology\u2014EUROCRYPT 2022, vol. 13277, pp. 34\u201356. Lecture Notes in Computer Science. Springer, Berlin (2022).","DOI":"10.1007\/978-3-031-07082-2_2"},{"issue":"1","key":"1444_CR37","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/TC.1985.1676518","volume":"49","author":"T Siegenthaler","year":"1985","unstructured":"Siegenthaler T.: Decrypting a class of stream ciphers using ciphertext only. IEEE Trans. Comput. C 49(1), 81\u201385 (1985).","journal-title":"IEEE Trans. Comput. C"},{"key":"1444_CR38","doi-asserted-by":"crossref","unstructured":"Todo Y., Isobe T., Meier W., Aoki K., Zhang B.: Fast correlation attack revisited. In: Shacham H., Boldyreva A. (eds.) Advances in Cryptology\u2014CRYPTO 2018, vol. 10992, pp. 129\u2013159. Lecture Notes in Computer Science. Springer, Berlin (2018).","DOI":"10.1007\/978-3-319-96881-0_5"},{"issue":"2","key":"1444_CR39","doi-asserted-by":"publisher","first-page":"322","DOI":"10.46586\/tosc.v2022.i2.322-350","volume":"2022","author":"Z Zhou","year":"2022","unstructured":"Zhou Z., Feng D., Zhang B.: Vectorial decoding algorithm for fast correlation attack and its applications to stream cipher Grain-128a. IACR Trans. Symm. Cryptol. 2022(2), 322\u2013350 (2022).","journal-title":"IACR Trans. Symm. Cryptol."}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01444-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-024-01444-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01444-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,29]],"date-time":"2024-09-29T18:02:27Z","timestamp":1727632947000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-024-01444-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,18]]},"references-count":39,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2024,11]]}},"alternative-id":["1444"],"URL":"https:\/\/doi.org\/10.1007\/s10623-024-01444-4","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"value":"0925-1022","type":"print"},{"value":"1573-7586","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,18]]},"assertion":[{"value":"8 July 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 June 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 June 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 June 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}