{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T04:16:21Z","timestamp":1778040981301,"version":"3.51.4"},"reference-count":50,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T00:00:00Z","timestamp":1769990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2026,4,24]]},"abstract":"<jats:p>For future 6G, there is an anticipation that a speed of around 100 Gbps could become a requirement, a speed that most current ciphers cannot reach.     Due to this, we propose a new SNOW family AEAD stream cipher called SNOW-Axn that has the capability to adopt a variable length of the key (up to 256 bits), IV\/nonce (up to 224 bits) and MAC (up to 128 bits) for the three modes of operation (encryption only, integrity only, AEAD), application and\/or standardisation domain separations, and other parameters.<\/jats:p>\n                  <jats:p>SNOW-Axn has new updated LFSR and FSM components, the feature of aggregated processing, as well as a new integrity mechanism. These changes     bring a significant performance boost. We provide exampled instances called SNOW-Ax1 and SNOW-Ax4, where the latter reaches the encryption speed of 421 Gbps in pure software on a laptop-grade CPU.<\/jats:p>","DOI":"10.62056\/a6y7qj5vt","type":"journal-article","created":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T18:09:08Z","timestamp":1777918148000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Pushing to the limits: SNOW-Axn \u2013 a fast AEAD stream cipher in aggregated mode"],"prefix":"10.62056","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0392-3778","authenticated-orcid":false,"given":"Dachao","family":"Wang","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/012a77v79","id-type":"ROR","asserted-by":"publisher"}],"name":"Lund University","place":["Lund, 22100, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5103-199X","authenticated-orcid":false,"given":"Alexander","family":"Maximov","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05a7rhx54","id-type":"ROR","asserted-by":"publisher"}],"name":"Ericsson Research","place":["Lund, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Patrik","family":"Ekdahl","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05a7rhx54","id-type":"ROR","asserted-by":"publisher"}],"name":"Ericsson Research","place":["Lund, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1798-570X","authenticated-orcid":false,"given":"Thomas","family":"Johansson","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/012a77v79","id-type":"ROR","asserted-by":"publisher"}],"name":"Lund University","place":["Lund, 22100, Sweden"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2026,5,4]]},"reference":[{"key":"ref1:SA3-LS-256algos","volume-title":"LS on 256 bit Algorithms and Quantum Computing","author":"3GPP TSG-SA3","year":"2018"},{"key":"ref2:3gpp_256","volume-title":"TS 33.841 (V16.1.0): 3rd Generation Partnership Project;\n  Technical Specification Group Services and Systems Aspects; Security aspects;\n  Study on the support of 256-bit algorithms for 5G (Release 16)","author":"3GPP","year":"2019"},{"key":"ref3:itu-2017","volume-title":"Minimum requirements related to technical performance for\n  IMT-2020 radio interface(s).","author":"ITU","year":"2017"},{"key":"ref4:ToSC:YanJohMax19","doi-asserted-by":"publisher","first-page":"249","DOI":"10.13154\/tosc.v2019.i4.249-271","article-title":"Vectorized linear approximations for attacks on SNOW\n  3G","volume":"2019","author":"Jing Yang","year":"2019","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref5:SAC:HawRos02","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/3-540-36492-7_4","article-title":"Guess-and-Determine Attacks on SNOW","volume":"2595","author":"Philip Hawkes","year":"2003"},{"key":"ref6:ToSC:EJMY19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.13154\/tosc.v2019.i3.1-42","article-title":"A new SNOW stream cipher called SNOW-V","volume":"2019","author":"Patrik Ekdahl","year":"2019","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref7:EPRINT:EJMY18","volume-title":"A new SNOW stream cipher called SNOW-V","author":"Patrik Ekdahl","year":"2018"},{"key":"ref8:10.1145\/3448300.3467829","series-title":"WiSec '21","isbn-type":"print","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1145\/3448300.3467829","article-title":"SNOW-Vi: An Extreme Performance Variant of SNOW-V for Lower\n  Grade CPUs","author":"Patrik Ekdahl","year":"2021","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450383493"},{"key":"ref9:ToSC:GonZha21a","doi-asserted-by":"publisher","first-page":"71","DOI":"10.46586\/tosc.v2021.i2.71-103","article-title":"Comparing Large-unit and Bitwise Linear Approximations of\n  SNOW 2.0 and SNOW 3G and Related Attacks","volume":"2021","author":"Xinxin Gong","year":"2021","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref10:10288571","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TIT.2023.3326348","article-title":"Correlation attacks on SNOW-V-like stream ciphers based on\n  a heuristic MILP model","author":"Sudong Ma","year":"2023","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref11:SNOWV-Eval","volume-title":"A Security Evaluation of the SNOW-V Stream\n  Cipher","author":"Carlos Cid","year":"2020"},{"key":"ref12:SNOWV-GnD","doi-asserted-by":"publisher","first-page":"1789","DOI":"10.1093\/comjnl\/bxaa003","article-title":"A Guess-And-Determine Attack On SNOW-V Stream Cipher","volume":"63","author":"Lin Jiao","year":"2020","journal-title":"The Computer Journal","ISSN":"https:\/\/id.crossref.org\/issn\/0010-4620","issn-type":"electronic"},{"key":"ref13:ToSC:YanJohMax21","doi-asserted-by":"publisher","first-page":"54","DOI":"10.46586\/tosc.v2021.i3.54-83","article-title":"Improved guess-and-determine and distinguishing attacks on\n  SNOW-V","volume":"2021","author":"Jing Yang","year":"2021","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref14:ACISP:HIILS21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/978-3-030-90567-5_9","article-title":"Distinguishing and Key Recovery Attacks on the Reduced-Round\n  SNOW-V","volume":"13083","author":"Jin Hoki","year":"2021"},{"key":"ref15:MA2022103379","doi-asserted-by":"publisher","first-page":"103379","DOI":"10.1016\/j.jisa.2022.103379","article-title":"Improved differential attacks on the reduced-round SNOW-V\n  and SNOW-Vi stream cipher","volume":"71","author":"Sudong Ma","year":"2022","journal-title":"Journal of Information Security and Applications","ISSN":"https:\/\/id.crossref.org\/issn\/2214-2126","issn-type":"electronic"},{"key":"ref16:sym14061127","doi-asserted-by":"publisher","DOI":"10.3390\/sym14061127","article-title":"(Quantum) Time-Memory-Data Tradeoff Attacks on the SNOW-V\n  Stream Cipher","volume":"14","author":"Sijia Li","year":"2022","journal-title":"Symmetry","ISSN":"https:\/\/id.crossref.org\/issn\/2073-8994","issn-type":"electronic"},{"key":"ref17:EPRINT:YanJohMax21","volume-title":"Improved guess-and-determine and distinguishing attacks on\n  SNOW-V","author":"Jing Yang","year":"2021"},{"key":"ref18:10980226","doi-asserted-by":"publisher","first-page":"4035","DOI":"10.1109\/TIT.2025.3565463","article-title":"Provable Security Evaluations of XOR-Versions of SNOW Family\n  Stream Ciphers Against Fast Correlation Attacks","volume":"71","author":"Sudong Ma","year":"2025","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref19:10.1093\/comjnl\/bxac012","doi-asserted-by":"publisher","first-page":"1268","DOI":"10.1093\/comjnl\/bxac012","article-title":"Linear Attacks On SNOW 3G And SNOW-V Using Automatic\n  Search","volume":"66","author":"Zhen Shi","year":"2022","journal-title":"The Computer Journal","ISSN":"https:\/\/id.crossref.org\/issn\/0010-4620","issn-type":"electronic"},{"key":"ref20:DCC:ZhoFenZha22","doi-asserted-by":"publisher","first-page":"2449","DOI":"10.1007\/s10623-022-01090-8","article-title":"Efficient and extensive search for precise linear\n  approximations with high correlations of full SNOW-V","volume":"90","author":"Zhaocun Zhou","year":"2022","journal-title":"DCC"},{"key":"ref21:EC:SJZCDJ22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-031-07082-2_2","article-title":"A Correlation Attack on Full SNOW-V and SNOW-Vi","volume":"13277","author":"Zhen Shi","year":"2022"},{"key":"ref22:cryptoeprint:2023\/145","volume-title":"Combining MILP Modeling with Algebraic Bias Evaluation for\n  Linear Mask Search: Improved Fast Correlation Attacks on SNOW","author":"Xinxin Gong","year":"2023"},{"key":"ref23:ToSC:YJT24","doi-asserted-by":"crossref","first-page":"141","DOI":"10.46586\/tosc.v2024.i2.141-165","article-title":"Theoretical Linear Cryptanalysis of the 5G Standard\n  Candidate SNOW 5G","volume":"2024","author":"Yinuo Liu","year":"2024","journal-title":"IACR Transaction on Symmetric Cryptology"},{"key":"ref24:SAGE-256-specs","volume-title":"Specification of the 256-bit air interface algorithms","author":"ETSI SAGE","year":"2022"},{"key":"ref25:JCEng:CafBalBan22","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/s13389-020-00251-6","article-title":"Melting SNOW-V: improved lightweight architectures","volume":"12","author":"Andrea Caforio","year":"2022","journal-title":"Journal of Cryptographic Engineering"},{"key":"ref26:9533177","doi-asserted-by":"publisher","first-page":"1943","DOI":"10.1109\/TVLSI.2021.3108430","article-title":"FPGA Implementations of 256-Bit SNOW Stream Ciphers for\n  Postquantum Mobile Security","volume":"29","author":"Milad Bahadori","year":"2021","journal-title":"IEEE Transactions on Very Large Scale Integration (VLSI)\n  Systems"},{"key":"ref27:ITUR-2030","volume-title":"ITU-R Framework for IMT-2030: Review and Future Direction\n  v1.0 (February 15, 2025)","author":"NGMN Alliance","year":"2025"},{"key":"ref28:ToSC:SLNK21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.46586\/tosc.v2021.i2.1-30","article-title":"Rocca: An Efficient AES-based Encryption Scheme for\n  Beyond 5G","volume":"2021","author":"Kosei Sakamoto","year":"2021","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref29:Rocca2022","doi-asserted-by":"publisher","first-page":"123","DOI":"10.46586\/tosc.v2022.i3.123-151","article-title":"Cryptanalysis of Rocca and Feasibility of Its Security\n  Claim","volume":"2022","author":"Akinori Hosoyamada","year":"2022","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"ref30:aegisx4","volume-title":"The AEGIS Family of Authenticated Encryption Algorithms","author":"Frank Denis","year":"2025"},{"key":"ref31:aegisx4-eprint","volume-title":"Adding more parallelism to the AEGIS authenticated\n  encryption algorithms","author":"Frank Denis","year":"2023"},{"key":"ref32:smac-paper","article-title":"A new stand-alone MAC construct called SMAC","volume":"2025","author":"Dachao Wang","year":"2025","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref33:cpsatlp","volume-title":"CP-SAT (v9.9)","author":"Laurent Perron"},{"key":"ref34:NIST197","article-title":"Advanced Encryption Standard","author":"National Institute of Standards","year":"2001","journal-title":"NIST FIPS PUB 197"},{"key":"ref35:INDOCRYPT:Stankovski10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1007\/978-3-642-17401-8_16","article-title":"Greedy Distinguishers and Nonrandomness Detectors","volume":"6498","author":"Paul Stankovski","year":"2010"},{"key":"ref36:ToSC:ZhaGonMei17","doi-asserted-by":"publisher","first-page":"58","DOI":"10.13154\/tosc.v2017.i4.58-81","article-title":"Fast Correlation Attacks on Grain-like Small State Stream\n  Ciphers","volume":"2017","author":"Bin Zhang","year":"2017","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref37:ToSC:Sun21","doi-asserted-by":"publisher","first-page":"100","DOI":"10.46586\/tosc.v2021.i4.100-123","article-title":"Automatic Search of Cubes for Attacking Stream Ciphers","volume":"2021","author":"Yao Sun","year":"2021","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref38:ToSC:LiuTia24","doi-asserted-by":"publisher","first-page":"190","DOI":"10.46586\/tosc.v2024.i2.190-221","article-title":"Dynamic Cube Attacks against Grain-128AEAD","volume":"2024","author":"Chen Liu","year":"2024","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref39:ToSC:LiuYanTia24","doi-asserted-by":"publisher","first-page":"141","DOI":"10.46586\/tosc.v2024.i2.141-165","article-title":"Theoretical Linear Cryptanalysis of the 5G Standard\n  Candidate SNOW 5G","volume":"2024","author":"Yinuo Liu","year":"2024","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref40:EC:Todo15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/978-3-662-46800-5_12","article-title":"Structural Evaluation by Generalized Integral Property","volume":"9056","author":"Yosuke Todo","year":"2015"},{"key":"ref41:AC:XZBL16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"648","DOI":"10.1007\/978-3-662-53887-6_24","article-title":"Applying MILP Method to Searching Integral Distinguishers\n  Based on Division Property for 6 Lightweight Block Ciphers","volume":"10031","author":"Zejun Xiang","year":"2016"},{"key":"ref42:C:TIHM17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"250","DOI":"10.1007\/978-3-319-63697-9_9","article-title":"Cube Attacks on Non-Blackbox Polynomials Based on Division\n  Property","volume":"10403","author":"Yosuke Todo","year":"2017"},{"key":"ref43:C:WHTLIM18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/978-3-319-96884-1_10","article-title":"Improved Division Property Based Cube Attacks Exploiting\n  Algebraic Properties of Superpoly","volume":"10991","author":"Qingju Wang","year":"2018"},{"key":"ref44:hell2009overview","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/s12095-008-0006-7","article-title":"An overview of distinguishing attacks on stream ciphers","volume":"1","author":"Martin Hell","year":"2009","journal-title":"Cryptography and Communications"},{"key":"ref45:DCC:JiaHaoLi23","doi-asserted-by":"publisher","first-page":"2021","DOI":"10.1007\/s10623-022-01150-z","article-title":"Guess-and-determine attacks on SNOW-Vi stream cipher","volume":"91","author":"Lin Jiao","year":"2023","journal-title":"DCC"},{"key":"ref46:ACNS:HadEic22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1007\/978-3-031-09234-3_12","article-title":"Autoguess: A Tool for Finding Guess-and-Determine Attacks\n  and Key Bridges","volume":"13269","author":"Hosein Hadipour","year":"2022"},{"key":"ref47:EPRINT:ChaTur21","volume-title":"Recovering the Key from the Internal State of\n  Grain-128AEAD","author":"Donghoon Chang","year":"2021"},{"key":"ref48:RSA:BilGil05","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-540-30574-3_3","article-title":"Resistance of SNOW 2.0 Against Algebraic Attacks","volume":"3376","author":"Olivier Billet","year":"2005"},{"key":"ref49:AC:Hosoyamada24","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"396","DOI":"10.1007\/978-981-96-0944-4_13","article-title":"Quantum Algorithms for Fast Correlation Attacks on\n  LFSR-Based Stream Ciphers","author":"Akinori Hosoyamada","year":"2024"},{"key":"ref50:IETF-RoccaS","volume-title":"Encryption algorithm Rocca-S","author":"Y. Nakano","year":"2023"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T04:04:23Z","timestamp":1778040263000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/3\/1\/31"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,4]]},"references-count":50,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,5,4]]}},"URL":"https:\/\/doi.org\/10.62056\/a6y7qj5vt","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,4]]},"assertion":[{"value":"2026-02-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-24","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc3-1-90"}}