{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T09:44:17Z","timestamp":1782812657396,"version":"3.54.5"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"National Key Laboratory of Security Communication Foundation","award":["61421030424"],"award-info":[{"award-number":["61421030424"]}]},{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2024YFA1013000"],"award-info":[{"award-number":["2024YFA1013000"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In the realm of lightweight cryptography, the construction of efficient and secure diffusion layers constitutes a critical component in block cipher design. The evaluation of diffusion layers primarily focuses on their cryptographic properties and circuit implementation costs. We propose an automatic model based on the g-XOR metric to design optimal binary diffusion layers with the lowest latency. The model employs graph theory, and from a circuit implementation perspective, translates branch number, invertibility, circuit area and depth into mathematical problems. Under these constraints, it explores improved implementations of Maximum Distance Binary Linear (MDBL) matrices (achieving maximum branch number) across different dimensions from 4 to 16 under the minimum latency. We find the tight lower bound for the implementation area of matrices with dimensions 4, 6, and 8, all with branch number of 4. We present matrices with dimensions 8 and 10, and branch numbers 5 and 6, whose implementation cost outperform existing results. For the first time, we provide optimized experimental results for dimensions 12, 14, and 16 with a branch number of 8 under the minimum depth of 3. Our work achieves the lowest latency, facilitating the design of highly efficient lightweight block ciphers.<\/jats:p>","DOI":"10.1186\/s42400-026-00617-z","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T08:50:22Z","timestamp":1782809422000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An STP-based model toward designing binary diffusion layers with the lowest latency"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5868-4730","authenticated-orcid":false,"given":"Tingting","family":"Cui","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5438-7028","authenticated-orcid":false,"given":"Xi","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Congkai","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siqin","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"issue":"16","key":"617_CR1","doi-asserted-by":"publisher","first-page":"3558","DOI":"10.1002\/sec.1561","volume":"9","author":"S Akleylek","year":"2016","unstructured":"Akleylek S, Sakall\u0131 MT, \u00d6zt\u00fcrk E, Mesut A\u015e, Tuncay G (2016) Generating binary diffusion layers with maximum\/high branch numbers and low search complexity. Sec Commun Net 9(16):3558\u20133569","journal-title":"Sec Commun Net"},{"key":"617_CR2","doi-asserted-by":"crossref","unstructured":"Aoki K, Ichikawa T, Kanda M, Matsui M, Moriai S, Nakajima J, Tokita T (2001) Camellia: A 128-bit block cipher suitable for multiple platforms\u2014design andanalysis. In: Selected Areas in Cryptography: 7th Annual International Workshop, SAC 2000 Waterloo, Ontario, Canada, August 14\u201315, 2000 Proceedings 7, pp. 39\u201356 . Springer","DOI":"10.1007\/3-540-44983-3_4"},{"key":"617_CR3","doi-asserted-by":"crossref","unstructured":"Bellizia D, Berti F, Bronchain O, Cassiers G, Duval S, Guo C, Leander G, Leurent G, Levi I, Momin C (2020) Spook: Sponge-based leakage-resistant authenticated encryption with a masked tweakable block cipher. IACR Transactions on Symmetric Cryptology 295\u2013349","DOI":"10.46586\/tosc.v2020.iS1.295-349"},{"key":"617_CR4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04722-4","volume-title":"The Design of Rijndael","author":"J Daemen","year":"2002","unstructured":"Daemen J, Rijmen V (2002) The Design of Rijndael, vol 2. Springer, Berlin"},{"key":"617_CR5","unstructured":"Dehnavi SM, Rishakani AM, Shamsabad MM (2015) Bitwise linear mappings with good cryptographic properties and efficient implementation. Cryptology ePrint Archive"},{"key":"617_CR6","doi-asserted-by":"crossref","unstructured":"Dinu D, Perrin L, Udovenko A, Velichkov V, Gro\u00dfsch\u00e4dl J, Biryukov A (2016) Design strategies for arx with provable bounds: Sparx and lax. International Conference on the Theory and Application of Cryptology and Information Security. Springer, pp 484\u2013513","DOI":"10.1007\/978-3-662-53887-6_18"},{"key":"617_CR7","doi-asserted-by":"crossref","unstructured":"Dobraunig C, Eichlseder M, Mendel F, Schl\u00e4ffer M (2015) Cryptanalysis of ascon. Cryptographers\u2019 Track at the RSA Conference. Springer, pp 371\u2013387","DOI":"10.1007\/978-3-319-16715-2_20"},{"key":"617_CR8","doi-asserted-by":"crossref","unstructured":"Gao Y, Guo G (2010) Unified approach to construct 8x8 binary matrices with branch number 5. 2010 First ACIS International Symposium on Cryptography, and Network Security, Data Mining and Knowledge Discovery, E-Commerce and Its Applications, and Embedded Systems. IEEE, pp 413\u2013416","DOI":"10.1109\/CDEE.2010.86"},{"key":"617_CR9","unstructured":"Grassl M (2007) Bounds on the minimum distance of linear codes and quantum codes"},{"key":"617_CR10","doi-asserted-by":"crossref","unstructured":"Guo Z, Wu W, Gao S (2016) Constructing lightweight optimal diffusion primitives with feistel structure. In: Selected Areas in Cryptography\u2013SAC 2015: 22nd International Conference, Sackville, NB, Canada, August 12\u201314, 2015, Revised Selected Papers 22, pp. 352\u2013372 . Springer","DOI":"10.1007\/978-3-319-31301-6_21"},{"key":"617_CR11","doi-asserted-by":"crossref","unstructured":"Jean J, Peyrin T, Sim SM, Tourteaux J (2017) Optimizing implementations of lightweight building blocks. Cryptology ePrint Archive","DOI":"10.46586\/tosc.v2017.i4.130-168"},{"issue":"1","key":"617_CR12","first-page":"48","volume":"83","author":"M Kanda","year":"2000","unstructured":"Kanda M, Moriai S, Aoki K, Ueda H, Takashima Y, Ohta K, Matsumoto T (2000) E2-a new 128-bit block cipher. IEICE Trans Fundam Electron Commun Comput Sci 83(1):48\u201359","journal-title":"IEICE Trans Fundam Electron Commun Comput Sci"},{"key":"617_CR13","doi-asserted-by":"crossref","unstructured":"Kanda M, Takashima Y, Matsumoto T, Aoki K, Ohta K (1998) A strategy for constructing fast round functions with practical security against differential and linear cryptanalysis. International Workshop on Selected Areas in Cryptography. Springer, pp 264\u2013279","DOI":"10.1007\/3-540-48892-8_21"},{"key":"617_CR14","doi-asserted-by":"crossref","unstructured":"Khoo K, Peyrin T, Poschmann AY, Yap H (2014) Foam: searching for hardware-optimal spn structures and components with a fair comparison. In: Cryptographic Hardware and Embedded Systems\u2013CHES 2014: 16th International Workshop, Busan, South Korea, September 23-26, 2014. Proceedings 16, pp. 433\u2013450 . Springer","DOI":"10.1007\/978-3-662-44709-3_24"},{"key":"617_CR15","unstructured":"Koo BW, Jang HS, Song JH (2004) Constructing and cryptanalysis of a 16$$\\times$$ 16 binary matrix as a diffusion layer. In: Information Security Applications: 4th International Workshop, WISA 2003 Jeju Island, Korea, August 25-27, 2003 Revised Papers 4, pp. 489\u2013503 . Springer"},{"key":"617_CR16","doi-asserted-by":"crossref","unstructured":"Koo BW, Jang HS, Song JH (2006) On constructing of a 32$$\\times$$ 32 binary matrix as a diffusion layer for a 256-bit block cipher. In: Information Security and Cryptology\u2013ICISC 2006: 9th International Conference, Busan, Korea, November 30-December 1, 2006. Proceedings 9, pp. 51\u201364 . Springer","DOI":"10.1007\/11927587_7"},{"key":"617_CR17","doi-asserted-by":"crossref","unstructured":"Kranz T, Leander G, Stoffelen K, Wiemer F (2017) Shorter linear straight-line programs for mds matrices. Cryptology ePrint Archive","DOI":"10.46586\/tosc.v2017.i4.188-211"},{"key":"617_CR18","doi-asserted-by":"crossref","unstructured":"Kwon D, Kim J, Park S, Sung SH, Sohn Y, Song JH, Yeom Y, Yoon E-J, Lee S, Lee J (2003) New block cipher: Aria. In: International Conference on Information Security and Cryptology, pp. 432\u2013445 . Springer","DOI":"10.1007\/978-3-540-24691-6_32"},{"issue":"1","key":"617_CR19","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1093\/comjnl\/bxab151","volume":"66","author":"X Li","year":"2023","unstructured":"Li X, Wu W (2023) Constructing binary matrices with good implementation properties for low-latency block ciphers based on lai-massey structure. Comput J 66(1):160\u2013173","journal-title":"Comput J"},{"key":"617_CR20","doi-asserted-by":"crossref","unstructured":"Li S, Sun S, Li C, Wei Z, Hu L (2019) Constructing low-latency involutory mds matrices with lightweight circuits. IACR Transactions on Symmetric Cryptology, 84\u2013117","DOI":"10.46586\/tosc.v2019.i1.84-117"},{"key":"617_CR21","doi-asserted-by":"crossref","unstructured":"Lin D, Xiang Z, Zeng X, Zhang S (2021) A framework to optimize implementations of matrices. Cryptographers\u2019 Track at the RSA Conference. Springer, pp 609\u2013632","DOI":"10.1007\/978-3-030-75539-3_25"},{"key":"617_CR22","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/s10623-011-9578-x","volume":"64","author":"M Sajadieh","year":"2012","unstructured":"Sajadieh M, Dakhilalian M, Mala H, Omoomi B (2012) On construction of involutory mds matrices from vandermonde matrices in gf (2 q). Des Codes Crypt 64:287\u2013308","journal-title":"Des Codes Crypt"},{"issue":"1","key":"617_CR23","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/540253","volume":"2014","author":"MT Sakall\u0131","year":"2014","unstructured":"Sakall\u0131 MT, Akleylek S, Aslan B, Bulu\u015f E, Sakall\u0131 FB (2014) On the construction of 20$$\\times$$ 20 and 24$$\\times$$ 24 binary matrices with good implementation properties for lightweight block ciphers and hash functions. Math Probl Eng 2014(1):540253","journal-title":"Math Probl Eng"},{"issue":"4","key":"617_CR24","doi-asserted-by":"publisher","first-page":"489","DOI":"10.46586\/tosc.v2023.i4.489-510","volume":"2023","author":"H Shi","year":"2023","unstructured":"Shi H, Feng X, Xu S (2023) A framework with improved heuristics to optimize low-latency implementations of linear layers. IACR Transact Symmet Cryptol 2023(4):489\u2013510","journal-title":"IACR Transact Symmet Cryptol"},{"key":"617_CR25","doi-asserted-by":"crossref","unstructured":"Sim SM, Khoo K, Oggier F, Peyrin T (2015) Lightweight mds involution matrices. In: Fast Software Encryption: 22nd International Workshop, FSE 2015, Istanbul, Turkey, March 8-11, 2015, Revised Selected Papers 22, pp. 471\u2013493 . Springer","DOI":"10.1007\/978-3-662-48116-5_23"},{"issue":"4","key":"617_CR26","doi-asserted-by":"publisher","first-page":"266","DOI":"10.46586\/tosc.v2022.i4.266-290","volume":"2022","author":"A Venkateswarlu","year":"2022","unstructured":"Venkateswarlu A, Kesarwani A, Sarkar S (2022) On the lower bound of cost of mds matrices. IACR Transact Symmet Cryptol 2022(4):266\u2013290","journal-title":"IACR Transact Symmet Cryptol"},{"issue":"10","key":"617_CR27","doi-asserted-by":"publisher","first-page":"2010812","DOI":"10.1007\/s11704-025-40011-5","volume":"20","author":"T Weng","year":"2026","unstructured":"Weng T, Wang G (2026) New sat-based model for constructing linear layers with good cryptographic properties and implementation. Front Comp Sci 20(10):2010812","journal-title":"Front Comp Sci"},{"issue":"6","key":"617_CR28","first-page":"690","volume":"6","author":"W Wu","year":"2019","unstructured":"Wu W, Zhang YZL, Li L (2019) The block cipher ublock. J Cryptol Res 6(6):690\u2013703","journal-title":"J Cryptol Res"},{"key":"617_CR29","doi-asserted-by":"crossref","unstructured":"Xiang Z, Zeng X, Lin D, Bao Z, Zhang S (2020) Optimizing implementations of linear layers. IACR Transactions on Symmetric Cryptology","DOI":"10.46586\/tosc.v2020.i2.120-145"},{"issue":"2","key":"617_CR30","doi-asserted-by":"publisher","first-page":"322","DOI":"10.46586\/tosc.v2024.i2.322-347","volume":"2024","author":"Y Yuan","year":"2024","unstructured":"Yuan Y, Wu W, Shi T, Zhang L, Zhang Y (2024) A framework to improve the implementations of linear layers. IACR Transact Symmet Cryptol 2024(2):322\u2013347","journal-title":"IACR Transact Symmet Cryptol"},{"key":"617_CR31","unstructured":"Zhao R, Wu B, Zhang R, Zhang Q (2016) Designing optimal implementations of linear layers (full version). Cryptology ePrint Archive"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00617-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00617-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00617-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T08:50:55Z","timestamp":1782809455000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00617-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":31,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["617"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00617-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]},"assertion":[{"value":"15 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"184"}}