{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,12]],"date-time":"2025-06-12T04:11:28Z","timestamp":1749701488906,"version":"3.41.0"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"2","license":[{"start":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T00:00:00Z","timestamp":1749600000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ToSC"],"abstract":"<jats:p>In ToSC 2025(1), Jia et al. proposed an SAT-aided automatic search tool for the S-box design. A part of the functionality of this tool is to search for implementations of an S-box with good area and gate-depth complexity. However, it is well-known that the gate depth complexity cannot precisely reflect the latency of an implementation. To overcome this problem, Rasoolzadeh introduced the concept of latency complexity, a more precise metric for the latency cost of implementing an S-box than the gate depth complexity in the real world.In this addendum, we adapt Jia et al.\u2019s tool to prioritize latency as the primary metric and area as the secondary metric to search for good implementations for existing S-boxes. The results show that the combination of Jia et al.\u2019s tool and Rasoolzadeh\u2019s latency complexity can lead to lower-latency S-box implementations. For S-boxes used in LBlock, Piccolo, SKINNY-64, RECTANGLE, PRESENT and TWINE, which are popular targets in this research line, we find new implementations with lower latency. We conducted synthesis comparisons of the area and latency under multiple standard libraries, where our results consistently outperformed in terms of latency. For example, for LBlock-S0, our solution reduces latency by around 50.0% \u223c 73.8% compared to previous implementations in TSMC 90nm library with the latency-optimized synthesis option.<\/jats:p>","DOI":"10.46586\/tosc.v2025.i2.192-205","type":"journal-article","created":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T13:54:02Z","timestamp":1749650042000},"page":"192-205","source":"Crossref","is-referenced-by-count":0,"title":["Addendum to How Small Can S-boxes Be?"],"prefix":"10.46586","volume":"2025","author":[{"given":"Yu","family":"Sun","sequence":"first","affiliation":[]},{"given":"Lixuan","family":"Wu","sequence":"additional","affiliation":[]},{"given":"Chenhao","family":"Jia","sequence":"additional","affiliation":[]},{"given":"Tingting","family":"Cui","sequence":"additional","affiliation":[]},{"given":"Kai","family":"Hu","sequence":"additional","affiliation":[]},{"given":"Meiqin","family":"Wang","sequence":"additional","affiliation":[]}],"member":"25480","published-online":{"date-parts":[[2025,6,11]]},"container-title":["IACR Transactions on Symmetric Cryptology"],"original-title":[],"link":[{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/download\/12248\/12055","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/download\/12248\/12055","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T13:54:02Z","timestamp":1749650042000},"score":1,"resource":{"primary":{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/view\/12248"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,11]]},"references-count":0,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,6,11]]}},"URL":"https:\/\/doi.org\/10.46586\/tosc.v2025.i2.192-205","relation":{},"ISSN":["2519-173X"],"issn-type":[{"value":"2519-173X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,11]]}}}