.. only:: not html .. bibliography:: references.bib .. only:: html .. _references: References ========== :ref:`A ` | :ref:`B ` | :ref:`C ` | :ref:`D ` | :ref:`E ` | :ref:`F ` | :ref:`G ` | :ref:`H ` | :ref:`I ` | :ref:`J ` | :ref:`K ` | :ref:`L ` | :ref:`M ` | :ref:`N ` | :ref:`O ` | :ref:`P ` | :ref:`Q ` | :ref:`R ` | :ref:`S ` | :ref:`T ` | :ref:`U ` | :ref:`V ` | :ref:`W ` | :ref:`X ` | :ref:`Y ` | :ref:`Z ` | .. _claasp-ref-A: .. only:: html **A** .. [ALLW2014] Abed F., List E., Lucks S., Wenzel J. : *Differential Cryptanalysis of Round-Reduced SIMON and SPECK* : International Workshop on Fast Software Encryption, 2014 : https://link.springer.com/content/pdf/10.1007%2F978-3-662-46706-0_27.pdf .. [ADP2018] Albrecht M. R., Deo A., Paterson K. G. : *Cold Boot Attacks on Ring and Module LWE Keys Under the NTT* : IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018(3), 173-213 .. [AK2019] Ankele R., Kölbl S. : *Mind the Gap - A Closer Look at the Security of Block Ciphers against Differential Cryptanalysis* : Selected Areas in Cryptography -- SAC 2018, Springer International Publishing 2019 : https://link.springer.com/chapter/10.1007%2F978-3-030-10970-7_8 .. [ASTTY2017] Abdelkhalek A., Sasaki Y., Todo Y., Tolba M., Youssef A. M. : *MILP modeling for (large) s-boxes to optimize probability of differential characteristics* : IACR Transactions on Symmetric Cryptology (2017): 99-129 : https://tosc.iacr.org/index.php/ToSC/article/view/805/759 .. _claasp-ref-B: .. only:: html **B** .. [BC2003] Biryukov A., Canniere C. D. : *Block Ciphers and Systems of Quadratic Equations* : In Proceedings of Fast Software Encryption 2003, LNCS 2887, pp. 274-289, Springer-Verlag 2003 .. [BFS2003] Bardet M., Faugère J.-C., Salvy B. : *Complexity of Gröbner basis computation for Semi-regular Overdetermined sequences over F2 with solutions in F2* : Research Report RR-5049, INRIA, 2003. .. [BDKLLSSSS18] Bos, J.W., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M., Schwabe, P., Seiler, G., Stehlé, D. : *CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based* KEM. EuroS&P 2018: 353-367. .. [BHPR2021] Bellini E., Hambitzer A., Protopapa M., Rossi M. : *Limitations of the Use of Neural Networks in Black Box Cryptanalysis* : In Innovative Security Solutions for Information Technology and Communications: 14th International Conference, SecITC 2021, Virtual Event, November 25–26, 2021, Revised Selected Papers. Springer-Verlag, Berlin, Heidelberg, 100–124 .. [BR2021] Bellini, E., Rossi, M. : *Performance Comparison Between Deep Learning-Based and Conventional Cryptographic Distinguishers* : In: Arai, K. (eds) Intelligent Computing. Lecture Notes in Networks and Systems, vol 285. Springer .. [BKLPPRSV2007] Bogdanov A., Knudsen L., Leander G., Paar C., Poschmann A., Robshaw M., Seurin Y., Vikkelsoe C. : *PRESENT: An Ultra-Lightweight Block Cipher* : In Proceedings of CHES 2007, LNCS 4727, pp. 450-466, Springer Verlag 2007 : https://doi.org/10.1007/978-3-540-74735-2_31 .. [BLP2008] Bernstein D. J., Lange T., Peters C. : *Attacking and defending the mceliece cryptosystem* : In International Workshop on Post-Quantum Cryptography, pp. 31–46, Springer 2008 .. [BFP2009] Bettale L., Faugère J.-C., Perret L. : *Hybrid approach for solving multivariate systems over finite fields* : J. Mathematical Cryptology,3(3):177–197, 2009 .. [BGHR2023] Bellini E., Gerault D., Hambitzer A., Rossi M. : *A Cipher-Agnostic Neural Training Pipeline with Automated Finding of Good Input Differences* : In IACR Transactions on Symmetric Cryptology 2023 .. [BCC+2010] Bouillaguet C., Chen H-C., Cheng H-C, Chou T., Niederhagen R., Shamir A., Yang B. Y. : *Fast exhaustive search for polynomial systems in F2* : In Cryptographic Hardware and Embedded Systems,CHES 2010, 12th International Workshop, Santa Barbara, CA, USA, August17-20, 2010. Proceedings, pages 203–218, 2010 .. [Ber2010] Bernstein D. J. : *Grover vs. McEliece* : In International Workshop on Post-QuantumCryptography. pp. 73–80. Springer (2010) .. [BFS+2011] Bardet M., Faugère J.-C., Salvy B., Spaenlehauer P.-J. : *On the complexity of solving quadratic boolean systems* : CoRR,abs/1112.6263, 2011 .. [BLP2011] Bernstein D. J., Lange T., Peters C. : *Smaller decoding exponents: ball-collision decoding* : In Annual Cryptology Conference. pp. 743–760. Springer (2011) .. [BS2011] Byrne E., Sneyd A. : *On the Parameters of Codes with Two Homogeneous Weights* : WCC 2011-Workshop on coding and cryptography, pp. 81-90, 2011 : https://hal.inria.fr/inria-00607341/document .. [BH2012] Brouwer A., Haemers W. : *Spectra of graphs* : Springer, 2012 : http://homepages.cwi.nl/~aeb/math/ipm/ipm.pdf .. [BFS2015] Bardet M., Faugère J.-C., Salvy B. : *On the complexity of the F5 Gröbner basis algorithm* : Journal of Symbolic Computation, 70:49–70,2015. .. [BM2018] Both L., May A. : *Decoding linear codes with high error rate and its impact for LPN security* : In International Conference on Post-Quantum Cryptography. pp. 25--46. Springer (2018) .. [BKW2019] Björklund A., Kaski P., Williams, R. : *Solving Systemsof Polynomial Equations over GF(2) by a Parity-Counting Self-Reduction* : In International Colloquium on Automata, Languages, and Programming (ICALP 2019), volume 132 of Leibniz International Proceedings in Informatics (LIPIcs), pages 26:1–26:13, Dagstuhl, Germany, 2019. Schloss Dagstuhl–Leibniz-Zentrum fuer Informatik. .. [BJMM2012] Becker A., Joux A., May A., Meurer A. : *Decoding random binary linear codes in 2^(n/20): How 1+1=0 improves information set decoding* : In Annual international conference on the theory and applications of cryptographic techniques. pp. 520–536. Springer (2012) .. [BCG+2020] Bardet M., Bros M., Cabarcas D., Gaborit M., Perlner R., Smith-Tone D., Tillich J.-P., Verbel J. : *Improvements of algebraic attacks for solving the rank decoding and minrank problems* : In Advances in Cryptology–ASIACRYPT2020 .. _claasp-ref-C: .. only:: html **C** .. [Cou2001] Courtois N. : *La sécurité des primitives cryptographiques basées sur des problèmes algébriques multivariables* : MQ, IP, MinRank, HFE. PhD thesis, Université de Paris 6 - Pierre et Marie Curie, 2001. .. [CHPSS18] Cid C., Huang T., Peyrin T., Sasaki Y., Song L. : *Boomerang Connectivity Table: A New Cryptanalysis Tool* (2018) : IACR Transactions on Symmetric Cryptology, Vol 2017, Issue 4, pre-print : https://eprint.iacr.org/2018/161.pdf .. [CZZ2023] Cao, W., Zhang, W., Zhou, C. : *New Automatic Search Tool for Searching for Impossible Differentials Using Undisturbed Bits* In: Deng, Y., Yung, M. (eds) Information Security and Cryptology. Inscrypt 2022. Lecture Notes in Computer Science, vol 13837. Springer, Cham. https://doi.org/10.1007/978-3-031-26553-2_3 .. _claasp-ref-D: .. only:: html **D** .. [DAKRV18] D'Anvers, J.-P., Karmakar, A., Roy S.S., Vercauteren F.: *Saber: Module-LWR Based Key Exchange, CPA-Secure Encryption and CCA-Secure KEM* : AFRICACRYPT 2018: 282-305. .. [Din2021Cry] Dinur I. : *Cryptanalytic Applications of the Polynomial Method for Solving Multivariate Equation Systems over GF(2).* Springer-Verlag, 2021. .. [Din2021Imp] Dinur I. : *Improved algorithms for solving polynomial systems over GF(2) by multiple parity-counting* : In Proceedings of the 2021 ACM-SIAM Symposium on Discrete Algorithms (SODA), pages 2550–2564 .. [DKLLSSS18] Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schwabe, P., Seiler, G., Stehlé, D. : *CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme* : IACR Trans. Cryptogr. Hardw. Embed. Syst. 2018(1): 238-268. .. [Dum1991] Dumer I. : *On minimum distance decoding of linear codes* : In Proc. 5th Joint Soviet-Swedish Int. Workshop Inform. Theory. pp. 50–52 (1991) .. [Du2001] Duursma I. : *From weight enumerators to zeta functions* : In Discrete Applied Mathematics, vol. 111, no. 1-2, pp. 55-73, 2001 .. [Du2004] Duursma I. : *Combinatorics of the two-variable zeta function* : Finite fields and applications, 109-136, Lecture Notes in Comput. Sci., 2948, Springer, Berlin, 2004 .. [Du2018] Dunkelman O. : *Efficient Construction of the Boomerang Connection Table* : (preprint), in Cryptology ePrint Archive, (2018), 631 .. [Dio2020] Diogo Duarte : *J. On the complexity of the crossbred algorithm* : CryptologyePrint Archive, Report 2020/1058, 2020. : https://eprint.iacr.org/2020/1058 .. _claasp-ref-E: .. only:: html **E** .. _claasp-ref-F: .. only:: html **F** .. [FSS2011] Faugère J.-C., Safey El Din M., Spaenlehauer P.-J. : *On the complexity of the generalized minrank problem* : CoRR, abs/1112.4411,2011. .. [FWGSH2016] Fu K., Wang M., Guo Y., Sun S., Hu L. : *MILP-based automatic search algorithms for differential and linear trails for speck* : In Cryptology ePrint Archive, (2016), 407 : https://eprint.iacr.org/2016/407.pdf .. _claasp-ref-G: .. only:: html **G** .. [Go2019] Gohr A. : *Improving Attacks on Round-Reduced Speck32/64 using Deep Learning * : In Advances in Cryptology – CRYPTO 2019 .. [GreMW24] Greene P., Motley M., Weeks B.: *ARADI and LLAMA: Low-Latency Cryptography for Memory Encryption*. IACR Cryptol. ePrint Arch., 2024, 1240. Available at https://eprint.iacr.org/2024/1240. .. _claasp-ref-H: .. only:: html **H** .. [He2002] Heys H. : *A Tutorial on Linear and Differential Cryptanalysis* : 2002 : http://www.engr.mun.ca/~howard/PAPERS/ldc_tutorial.pdf .. [HP2003] Huffman W. C., Pless V. : *Fundamentals of Error-Correcting Codes* : Cambridge Univ. Press, 2003 .. _claasp-ref-I: .. only:: html **I** .. _claasp-ref-J: .. only:: html **J** .. [JV2018] Joux A., Vitse V. : *A crossbred algorithm for solving boolean polynomial systems* : In Jerzy Kaczorowski, Josef Pieprzyk, JacekPomyka la, editors, Number-Theoretic Methods in Cryptology, pages 3–21, Cham, 2018. Springer International Publishing. .. _claasp-ref-K: .. only:: html **K** .. [KPG1999] Kipnis A., Patarin J., Goubin L. : *Unbalanced oil and vinegar signature schemes* : In Advances in Cryptology EUROCRYPT99, pages 206–222, Berlin, Heidelberg, 1999. Springer BerlinHeidelberg. .. [Knudsen2011TheBC] Knudsen, L. R., & Robshaw, M. J. B., : *The Block Cipher Companion* : Information Security and Cryptography, 2011. https://link.springer.com/book/10.1007/978-3-642-17342-4 .. _claasp-ref-L: .. only:: html **L** .. [LMM+2021] Leander G., Moos T., Moradi A., Rasoolzadeh S. (2021). *The SPEEDY Family of Block Ciphers: Engineering an Ultra Low-Latency Cipher from Gate Level for Secure Processor Architectures*. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021(4), 510–545. https://doi.org/10.46586/tches.v2021.i4.510-545 .. [Lin1999] van Lint J. : *Introduction to coding theory* : 3rd ed. Springer-Verlag GTM, 86, 1999 .. [LM2001] Lipmaa H., Moriai S. : *Efficient Algorithms for Computing Differential Properties of Addition* : International Workshop on Fast Software Encryption, 2001 : https://link.springer.com/content/pdf/10.1007%2F3-540-45473-X_28.pdf .. [LPT+2017] Lokshtanov D., Paturi R., Tamaki S., Williams R., Yu H. : *Beating brute force for systems of polynomial equation sover finite fields* : In Proceedings of the Twenty-Eighth Annual ACM-SIAM Symposium on Discrete Algorithms, SODA '17, page 2190–2202, USA, 2017. Society for Industrial and Applied Mathematics .. [LWR2016] Liu Y., Wang Q., Rijmen V. : *Automatic Search of Linear Trails in ARX with Applications to SPECK and Chaskey* : Applied Cryptography and Network Security, Springer International Publishing 2016 : https://link.springer.com/chapter/10.1007%2F978-3-319-39555-5_26 .. _claasp-ref-M: .. only:: html **M** .. [MMT2011] May A., Meurer A., Thomae E. : *Decoding random linear codes in 2^(0.054n)* : In International Conference on the Theory and Application of Cryptology and Information Security. pp. 107–124. Springer (2011) .. [MHT2013] Miura H., Hashimoto Y., Takagi T. : *Extended algorithm for solving underdefined multivariate quadratic equations* : In Post-Quantum Cryptography, 2013. Springer Berlin Heidelberg. .. [MO2015] May A., Ozerov I. : *On computing nearest neighbors with applications to decoding of binary linear codes* : In Annual International Conference on the Theory and Applications of Cryptographic Techniques. pp. 203--228. Springer (2015) .. [MUR2020] Murilo C., Rafael T., and Fabio B. : *Continuous Diffusion Analysis* : In IEEE Access. pp. 123735--123745. IEEE Access (2020) .. _claasp-ref-N: .. only:: html **N** .. _claasp-ref-O: .. only:: html **O** .. _claasp-ref-P: .. only:: html **P** .. [Pra1962] Prange E. : *The use of information sets in decoding cyclic codes* : IRE Transactions on Information Theory 8(5), 5–9 (1962) .. _claasp-ref-Q: .. only:: html **Q** .. _claasp-ref-R: .. only:: html **R** .. _claasp-ref-S: .. only:: html **S** .. [Ste1988] Stern J. : *A method for finding codewords of small weight* : In International Colloquium on Coding Theory and Applications. pp. 106–113. Springer (1988) .. [SGLYTQH2017] Sun S., Gerault D., Lafourcade P., Yang Q., Todo Y., Qiao K., Hu L. : *Analysis of AES, SKINNY, and others with constraint programming* : In IACR transactions on symmetric cryptology 2017 (1), 281--306 .. [SGWW2020] Sun L., Gerault D., Wang W., Wang M. : *On the usage of deterministic (related-key) truncated differentials and multidimensional linear approximations for SPN ciphers* : IACR Transactions on Symmetric Cryptology, 2020, 262-287 : https://tosc.iacr.org/index.php/ToSC/article/view/8702/8294 .. [SHW+2014] Sun S., Hu L., Wang M., Wang P., Qiao K., Ma X., Shi D., Song L., Fu, K. : *Towards finding the best characteristics of some bit-oriented block ciphers and automatic enumeration of (related-key) differential and linear characteristics with predefined properties* : Cryptology ePrint Archive (2014) : https://eprint.iacr.org/2014/747.pdf .. [SW2023] Sun, L., Wang, M. : *SoK: Modeling for Large S-boxes Oriented to Differential Probabilities and Linear Correlations (Long Paper)* : Cryptology ePrint Archive, 2023. .. _claasp-ref-T: .. only:: html **T** .. [TW2012] Thomae E., Wolf C. : *Solving underdetermined systems of multivariate quadratic equations revisited* : In Public Key Cryptography – PKC 2012, Berlin, Heidelberg, 2012. Springer Berlin Heidelberg. .. _claasp-ref-U: .. only:: html **U** .. _claasp-ref-V: .. only:: html **V** .. [VBC+2019] Verbel J., Baena J., Cabarcas D., Perlner R., Smith-Tone D. : *On the complexity of “superdetermined” minrank instances* : In Post-Quantum Cryptography, pages 167–186, Cham, 2019. Springer International Publishing. .. _claasp-ref-W: .. only:: html **W** .. _claasp-ref-X: .. only:: html **X** .. _claasp-ref-Y: .. only:: html **Y** .. [YC2004] Yang B.-Y., Chen J.-M. : *Theoretical analysis of XL over small fields* : In Information Security and Privacy, pages 277–288, Berlin, Heidelberg, 2004. Springer Berlin Heidelberg .. _claasp-ref-Z: .. only:: html **Z**