{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T07:00:05Z","timestamp":1777964405016,"version":"3.51.4"},"reference-count":24,"publisher":"Oxford University Press (OUP)","issue":"5","license":[{"start":{"date-parts":[[2022,3,2]],"date-time":"2022-03-02T00:00:00Z","timestamp":1646179200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5,19]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>In this paper, a linear attack model of SNOW 3G and SNOW-V based on automatic search technology is proposed. We first describe the linear approximation of Finite State Machine transformation, which allows a wider range of automatic search, then model it with the automatic search technology based on SAT\/SMT program. Adopting this generic method, we seek out a binary linear approximation of SNOW 3G with correlation of $2^{-21.92}$ which has been verified by test. Treating this binary approximation as a mask of an 8-bit distribution in a fixed field, we provide a method to obtain the 8-bit distribution. The binary approximation is used in a fast correlation attack with expected time and memory complexity $2^{184.67}$, given $2^{173.96}$ key stream words. For the full version of SNOW-V, considering the linear relationship between Linear Feedback Shift Register parts at three successive moments, we search out a distinguisher with correlation of $2^{-175.51}$, which results in a distinguishing attack with an expected complexity of $2^{351.02}$.<\/jats:p>","DOI":"10.1093\/comjnl\/bxac012","type":"journal-article","created":{"date-parts":[[2022,1,25]],"date-time":"2022-01-25T12:08:05Z","timestamp":1643112485000},"page":"1268-1278","source":"Crossref","is-referenced-by-count":3,"title":["Linear Attacks On SNOW 3G And SNOW-V Using Automatic Search"],"prefix":"10.1093","volume":"66","author":[{"given":"Zhen","family":"Shi","sequence":"first","affiliation":[{"name":"Department of Applied Mathematics , PLA SSF Information Engineering University, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenhui","family":"Jin","sequence":"additional","affiliation":[{"name":"Department of Applied Mathematics , PLA SSF Information Engineering University, Zhengzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2022,3,2]]},"reference":[{"key":"2023052000434254500_ref1","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1007\/BF02252874","article-title":"Fast correlation attacks on certain stream ciphers","volume":"1","author":"Meier","year":"1989","journal-title":"J. Cryptol."},{"key":"2023052000434254500_ref2","first-page":"181","article-title":"A simple algorithm for fast correlation attacks on stream ciphers","volume-title":"Fast Software Encryption, 7th International Workshop, FSE 2000, New York, NY, USA, April 10-12, 2000, Proceedings","author":"Chepyzhov","year":"2000"},{"key":"2023052000434254500_ref3","first-page":"209","article-title":"Fast correlation attacks: An algorithmic point of view","volume-title":"Advances in Cryptology - EUROCRYPT 2002, International Conference on the Theory and Applications of Cryptographic Techniques, Amsterdam, The Netherlands, April 28 - May 2, 2002, Proceedings","author":"Chose","year":"2002"},{"key":"2023052000434254500_ref4","first-page":"300","article-title":"Fast correlation attacks through reconstruction of linear polynomials","volume-title":"Advances in Cryptology - CRYPTO 2000, 20th Annual International Cryptology Conference, Santa Barbara, California, USA, August 20-24, 2000, Proceedings","author":"Johansson","year":"2000"},{"key":"2023052000434254500_ref5","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/3-540-45661-9_15","article-title":"Scream: A software-efficient stream cipher","volume-title":"Fast Software Encryption, 9th International Workshop, FSE 2002, Leuven, Belgium, February 4-6, 2002, Revised Papers","author":"Halevi","year":"2002"},{"key":"2023052000434254500_ref6","first-page":"294","volume-title":"Strumok keystream generator","author":"Gorbenko","year":"2018"},{"key":"2023052000434254500_ref7","article-title":"Primitive specification and supporting documentation for Sober-t16 submission to nessie","volume-title":"First Open NESSIE Workshop, proceedings, 2000","author":"Hawkes","year":"2000"},{"key":"2023052000434254500_ref8","doi-asserted-by":"crossref","first-page":"98","DOI":"10.1007\/978-3-540-68351-3_9","article-title":"Sosemanuk, a fast software-oriented stream cipher","volume-title":"New Stream Cipher Designs - The eSTREAM Finalists","author":"Berbain","year":"2008"},{"key":"2023052000434254500_ref9","first-page":"167","volume-title":"SNOW-a new stream cipher. Proceedings of First Open NESSIE Workshop, KU-Leuven","author":"Ekdahl","year":"2000"},{"key":"2023052000434254500_ref10","first-page":"47","article-title":"A new version of the stream cipher SNOW","volume-title":"Selected Areas in Cryptography, 9th Annual International Workshop, SAC 2002, St. John\u2019s, Newfoundland, Canada, August 15-16, 2002. Revised Papers","author":"Ekdahl","year":"2002"},{"key":"2023052000434254500_ref11","volume-title":"Specification of the 3gpp confidentiality and integrity algorithms UEA2& UIA2","author":"ETSI\/SAGE","year":"2006"},{"key":"2023052000434254500_ref12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.46586\/tosc.v2019.i3.1-42","article-title":"A new SNOW stream cipher called SNOW-V","author":"Ekdahl","year":"2019","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"2023052000434254500_ref13","first-page":"643","article-title":"Fast correlation attacks over extension fields, large-unit linear approximation and cryptanalysis of SNOW 2.0","volume-title":"Advances in Cryptology - CRYPTO 2015 - 35th Annual Cryptology Conference, Santa Barbara, CA, USA, August 16\u201320, 2015, Proceedings, Part I","author":"Zhang","year":"2015"},{"key":"2023052000434254500_ref14","first-page":"249","article-title":"Vectorized linear approximations for attacks on SNOW 3G","volume":"2019","author":"Yang","year":"2019","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2023052000434254500_ref15","doi-asserted-by":"crossref","first-page":"2407","DOI":"10.1007\/s10623-020-00790-3","article-title":"Fast computation of linear approximation over certain composition functions and applications to SNOW 2.0 and SNOW 3G","volume":"88","author":"Gong","year":"2020","journal-title":"Des. Codes Cryptogr."},{"key":"2023052000434254500_ref16","first-page":"158","article-title":"Automatic security evaluation and (related-key) differential characteristic search: Application to simon, present, lblock, DES(L) and other bit-oriented block ciphers","volume-title":"Advances in Cryptology - ASIACRYPT 2014","author":"Sun","year":"2014"},{"key":"2023052000434254500_ref17","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1007\/s10623-012-9668-4","article-title":"On ccz-equivalence of addition mod 2$^n$","volume":"66","author":"Schulte-Geers","year":"2013","journal-title":"Des. Codes Cryptogr"},{"key":"2023052000434254500_ref18","first-page":"64","article-title":"STP models of optimal differential and linear trail for S-box based ciphers","author":"Liu","year":"2021","journal-title":"Sci. China Inf. Sci"},{"key":"2023052000434254500_ref19","doi-asserted-by":"crossref","first-page":"99","DOI":"10.46586\/tosc.v2017.i4.99-129","article-title":"MILP modeling for (large) s-boxes to optimize probability of differential characteristics","volume":"2017","author":"Abdelkhalek","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"2023052000434254500_ref20","first-page":"288","article-title":"A generalized birthday problem","volume-title":"Advances in Cryptology - CRYPTO 2002, 22nd Annual International Cryptology Conference, Santa Barbara, California, USA, August 18-22, 2002, Proceedings","author":"Wagner","year":"2002"},{"key":"2023052000434254500_ref21","doi-asserted-by":"crossref","first-page":"432","DOI":"10.1007\/978-3-540-30539-2_31","article-title":"How far can we go beyond linear cryptanalysis?","volume-title":"Advances in Cryptology - ASIACRYPT 2004, 10th International Conference on the Theory and Application of Cryptology and Information Security, Jeju Island, Korea, December 5-9, 2004, Proceedings","author":"Baign\u00e8res","year":"2004"},{"key":"2023052000434254500_ref22","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ITWITWN.2007.4318037","article-title":"Multidimensional walsh transform and a characterization of bent functions","volume-title":"Proceedings of the IEEE Information Theory Workshop on Information Theory for Wireless Networks, July 1-6, 2007, Solstrand, Norway","author":"Nyberg","year":"2007"},{"key":"2023052000434254500_ref23","volume-title":"Stp constraint solver","author":"Ganesh","year":"2011"},{"key":"2023052000434254500_ref24","doi-asserted-by":"crossref","first-page":"54","DOI":"10.46586\/tosc.v2021.i3.54-83","article-title":"Improved guess-and-determine and distinguishing attacks on SNOW-V","volume":"2021","author":"Yang","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/66\/5\/1268\/50397588\/bxac012.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/66\/5\/1268\/50397588\/bxac012.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,20]],"date-time":"2023-05-20T00:45:00Z","timestamp":1684543500000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/66\/5\/1268\/6540627"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,2]]},"references-count":24,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2022,3,2]]},"published-print":{"date-parts":[[2023,5,19]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxac012","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2023,5]]},"published":{"date-parts":[[2022,3,2]]}}}