{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T20:34:15Z","timestamp":1782851655963,"version":"3.54.5"},"reference-count":29,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T00:00:00Z","timestamp":1633392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072445"],"award-info":[{"award-number":["62072445"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,1,17]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Diffusion layers are crucial components for lightweight cryptographic schemes. Optimal binary matrices are widely used diffusion layers that can be easier to achieve the best security\/performance trade-off. However, most of the constructions of binary matrices are concentrated in smaller dimensions. Besides, to maximize the number of branches, the performance is often neglected. In this paper, we investigate the diffusion of the Lai-Massey (L-M) structures and propose a series of binary diffusion layers with the best possible branch number and efficient software\/hardware implementations as well for feasible parameters (up to 64). Firstly, we prove the lower bound of the circuit depth of a binary matrix with a fixed branch number. Then, we construct binary matrices by L-M structure with cyclic shift as round functions because of taking account of the improvement of software performance and demonstrate that this construction can not get the diffusion layers with branch number &amp;gt;4. Then, we get some 4 $\\times $ 4 and 6 $\\times $ 6 optimal binary matrices with branch number 4 by one-round L-M structure. Note that the depth of these results is optimal, i. e. they achieve the lowest hardware costs without loss of software efficiency. Secondly, we construct diffusion layers by extended L-M structures to obtain binary matrices with large sizes. We give a list of software\/hardware friendly optimal binary matrices with large dimensions, especially for dimensions 48 and 64. In particular, some of the solutions are Maximum Distance Binary Linear matrices. Finally, we also present diffusion layers constructed by the extended generalized L-M structure to improve their applicabilities on other platforms.<\/jats:p>","DOI":"10.1093\/comjnl\/bxab151","type":"journal-article","created":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T14:33:49Z","timestamp":1633444429000},"page":"160-173","source":"Crossref","is-referenced-by-count":4,"title":["Constructing Binary Matrices with Good Implementation Properties for Low-Latency Block Ciphers based on Lai-Massey Structure"],"prefix":"10.1093","volume":"66","author":[{"given":"Xiaodan","family":"Li","sequence":"first","affiliation":[{"name":"Trusted Computing and Information Assurance Laboratory , Institute of Software Chinese Academy of Sciences, Beijing 100190, China"},{"name":"State Key Laboratory of Cryptology , P.O.Box 5159, Beijing 100878, China"},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenling","family":"Wu","sequence":"additional","affiliation":[{"name":"Trusted Computing and Information Assurance Laboratory , Institute of Software Chinese Academy of Sciences, Beijing 100190, China"},{"name":"State Key Laboratory of Cryptology , P.O.Box 5159, Beijing 100878, China"},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2021,10,5]]},"reference":[{"key":"2023011814194251500_ref1","first-page":"426","volume-title":"Proc. Int. Conf. CHES 2012","author":"Kne\u017eevi\u0107","year":"2012"},{"key":"2023011814194251500_ref2","first-page":"419","volume-title":"Proc. Int. Conf. CRYPTO 2020","author":"Beierle","year":"2020"},{"key":"2023011814194251500_ref3","first-page":"137","article-title":"The Design of Rijndael","volume":"26","author":"Daemen","year":"2002","journal-title":"Information Security & Cryptography"},{"key":"2023011814194251500_ref4","first-page":"39","volume-title":"Proc. Int. Conf. SAC 2000","author":"Aoki","year":"2001"},{"key":"2023011814194251500_ref5","first-page":"432","volume-title":"Proc. Int. Conf. ICISC 2003","author":"Kwon","year":"2004"},{"key":"2023011814194251500_ref6","first-page":"48","article-title":"E2 - a new 128-bit block cipher","volume":"83","author":"Kanda","year":"2000","journal-title":"IEICE Trans. Fundament. Electron. Commun. Comp. Sci."},{"key":"2023011814194251500_ref7","first-page":"690","article-title":"The block cipher ublock","volume":"6","author":"Wu","year":"2019","journal-title":"J. Cryptol. Res."},{"key":"2023011814194251500_ref8","first-page":"371","volume-title":"Proc. Int. Conf. CT-RSA 2015","author":"Dobraunig","year":"2015"},{"key":"2023011814194251500_ref9","doi-asserted-by":"crossref","first-page":"295","DOI":"10.46586\/tosc.v2020.iS1.295-349","article-title":"Spook: Sponge-based leakage-resistant authenticated encryption with a masked tweakable block cipher","volume":"2020","author":"Bellizia","year":"2020","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"2023011814194251500_ref10","first-page":"413","volume-title":"In 2010 First ACIS International Symposium on Cryptography, and Network Security, Data Mining and Knowledge Discovery, E-Commerce and Its Applications, and Embedded Systems","author":"Gao","year":"2010"},{"key":"2023011814194251500_ref11","first-page":"489","volume-title":"Proc. Int. Conf. WISA 2003","author":"Koo","year":"2004"},{"key":"2023011814194251500_ref12","first-page":"51","volume-title":"Proc. Int. Conf. ICISC 2006","author":"Koo","year":"2006"},{"key":"2023011814194251500_ref13","doi-asserted-by":"crossref","DOI":"10.1155\/2014\/540253","article-title":"On the construction of 20 \u00d7 20 and 24 \u00d7 24 binary matrices with good implementation properties for lightweight block ciphers and hash functions","volume":"2014","author":"Sakalli","year":"2014","journal-title":"Math. Probl. Eng."},{"key":"2023011814194251500_ref14","volume-title":"Bitwise Linear Mappings with Good Cryptographic Properties and Efficient Implementation","author":"Dehnavi","year":"2015"},{"key":"2023011814194251500_ref15","first-page":"352","volume-title":"Proc. Int. Conf. SAC 2015","author":"Guo","year":"2016"},{"key":"2023011814194251500_ref16","doi-asserted-by":"crossref","first-page":"3558","DOI":"10.1002\/sec.1561","article-title":"Generating binary diffusion layers with maximum\/high branch numbers and low search complexity","volume":"9","author":"Akleylek","year":"2016","journal-title":"Secur. Commun. Net."},{"key":"2023011814194251500_ref17","first-page":"389","volume-title":"Proc. Int. Conf. EUROCRYPT 1990","author":"Lai","year":"1991"},{"key":"2023011814194251500_ref18","first-page":"8","volume-title":"Proc. Int. Conf. ASIACRYPT 1999","author":"Vaudenay","year":"1999"},{"key":"2023011814194251500_ref19","doi-asserted-by":"crossref","first-page":"130","DOI":"10.46586\/tosc.v2017.i4.130-168","article-title":"Optimizing implementations of lightweight building blocks","volume":"2017","author":"Jean","year":"2017","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"2023011814194251500_ref20","doi-asserted-by":"crossref","first-page":"188","DOI":"10.46586\/tosc.v2017.i4.188-211","article-title":"Shorter linear straight-line programs for MDS matrices","volume":"2017","author":"Kranz","year":"2017","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"2023011814194251500_ref21","first-page":"203","article-title":"Improved heuristics for short linear programs","volume":"2020","author":"Tan","year":"2020","journal-title":"IACR Trans. Cryptograp. Hardware Embedded Syst."},{"key":"2023011814194251500_ref22","first-page":"109","volume-title":"Proc. Int. Conf. IWSEC 2019, Tokyo, Japan, 28-30 August","author":"Banik","year":"2019"},{"key":"2023011814194251500_ref23","doi-asserted-by":"crossref","first-page":"91","DOI":"10.46586\/tches.v2019.i4.91-125","article-title":"New circuit minimization techniques for smaller and faster AES SBoxes","volume":"2019","author":"Maximov","year":"2019","journal-title":"IACR Trans. Cryptograp. Hardware Embedded Syst."},{"key":"2023011814194251500_ref24","doi-asserted-by":"crossref","first-page":"120","DOI":"10.46586\/tosc.v2020.i2.120-145","article-title":"Optimizing implementations of linear layers","volume":"2020","author":"Xiang","year":"2020","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"2023011814194251500_ref25","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1007\/978-3-662-53887-6_18","volume-title":"Proc. Int. Conf. ASIACRYPT 2016","author":"Dinu","year":"2016"},{"key":"2023011814194251500_ref26","volume-title":"Bounds on the Minimum Distance of Linear Codes and Quantum Codes","author":"Grassl","year":"2007"},{"key":"2023011814194251500_ref27","first-page":"121","volume-title":"Proc. Int. Conf. FSE 2016","author":"Li","year":"2016"},{"key":"2023011814194251500_ref28","doi-asserted-by":"crossref","first-page":"84","DOI":"10.46586\/tosc.v2019.i1.84-117","article-title":"Constructing low-latency involutory MDS matrices with lightweight circuits","volume":"2019","author":"Li","year":"2019","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"2023011814194251500_ref29","first-page":"123","volume-title":"Proc. Int. Conf. CRYPTO 2016","author":"Beierle","year":"2016"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/66\/1\/160\/48729090\/bxab151.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/66\/1\/160\/48729090\/bxab151.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,18]],"date-time":"2023-01-18T14:20:03Z","timestamp":1674051603000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/66\/1\/160\/6381817"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,5]]},"references-count":29,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,10,5]]},"published-print":{"date-parts":[[2023,1,17]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxab151","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2023,1]]},"published":{"date-parts":[[2021,10,5]]}}}