{"id":"https://openalex.org/W2814638054","doi":"https://doi.org/10.1109/tr.2018.2847247","title":"Finding Bugs in Cryptographic Hash Function Implementations","display_name":"Finding Bugs in Cryptographic Hash Function Implementations","publication_year":2018,"publication_date":"2018-07-06","ids":{"openalex":"https://openalex.org/W2814638054","doi":"https://doi.org/10.1109/tr.2018.2847247","mag":"2814638054","pmid":"https://pubmed.ncbi.nlm.nih.gov/31092953"},"language":"en","primary_location":{"id":"doi:10.1109/tr.2018.2847247","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tr.2018.2847247","pdf_url":null,"source":{"id":"https://openalex.org/S87725633","display_name":"IEEE Transactions on Reliability","issn_l":"0018-9529","issn":["0018-9529","1558-1721"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Reliability","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/6512998","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5036504001","display_name":"Nicky Mouha","orcid":"https://orcid.org/0000-0001-8861-782X"},"institutions":[{"id":"https://openalex.org/I1321296531","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416","country_code":"US","type":"funder","lineage":["https://openalex.org/I1321296531","https://openalex.org/I1343035065"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Nicky Mouha","raw_affiliation_strings":["National Institute of Standards and Technology. nicky.mouha@nist.gov","National Institute of Standards and Technology, Gaithersburg, MD, USA"],"raw_orcid":"https://orcid.org/0000-0001-8861-782X","affiliations":[{"raw_affiliation_string":"National Institute of Standards and Technology. nicky.mouha@nist.gov","institution_ids":["https://openalex.org/I1321296531"]},{"raw_affiliation_string":"National Institute of Standards and Technology, Gaithersburg, MD, USA","institution_ids":["https://openalex.org/I1321296531"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041317074","display_name":"M S Raunak","orcid":"https://orcid.org/0000-0003-4934-7331"},"institutions":[{"id":"https://openalex.org/I165556055","display_name":"Loyola University Maryland","ror":"https://ror.org/01by1wp65","country_code":"US","type":"education","lineage":["https://openalex.org/I165556055"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mohammad S. Raunak","raw_affiliation_strings":["Department of Computer Science, Loyola University Maryland, Baltimore, MD 21210. raunak@loyola.edu","Department of Computer Science, Loyola University Maryland, Baltimore, MD, USA"],"raw_orcid":"https://orcid.org/0000-0003-4934-7331","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Loyola University Maryland, Baltimore, MD 21210. raunak@loyola.edu","institution_ids":["https://openalex.org/I165556055"]},{"raw_affiliation_string":"Department of Computer Science, Loyola University Maryland, Baltimore, MD, USA","institution_ids":["https://openalex.org/I165556055"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011985891","display_name":"D. Richard Kuhn","orcid":"https://orcid.org/0000-0003-0050-1596"},"institutions":[{"id":"https://openalex.org/I1321296531","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416","country_code":"US","type":"funder","lineage":["https://openalex.org/I1321296531","https://openalex.org/I1343035065"]},{"id":"https://openalex.org/I4210124755","display_name":"National Institute of Standards","ror":"https://ror.org/02zftm050","country_code":"EG","type":"facility","lineage":["https://openalex.org/I4210124755"]}],"countries":["EG","US"],"is_corresponding":false,"raw_author_name":"D. Richard Kuhn","raw_affiliation_strings":["National Institute of Standards and Technology","National Institute of Standards and Technology, Gaithersburg, MD, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Institute of Standards and Technology","institution_ids":["https://openalex.org/I4210124755","https://openalex.org/I1321296531"]},{"raw_affiliation_string":"National Institute of Standards and Technology, Gaithersburg, MD, USA","institution_ids":["https://openalex.org/I1321296531"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5061215075","display_name":"Raghu N. Kacker","orcid":"https://orcid.org/0000-0002-7666-3391"},"institutions":[{"id":"https://openalex.org/I1321296531","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416","country_code":"US","type":"funder","lineage":["https://openalex.org/I1321296531","https://openalex.org/I1343035065"]},{"id":"https://openalex.org/I4210124755","display_name":"National Institute of Standards","ror":"https://ror.org/02zftm050","country_code":"EG","type":"facility","lineage":["https://openalex.org/I4210124755"]}],"countries":["EG","US"],"is_corresponding":false,"raw_author_name":"Raghu Kacker","raw_affiliation_strings":["National Institute of Standards and Technology","National Institute of Standards and Technology, Gaithersburg, MD, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Institute of Standards and Technology","institution_ids":["https://openalex.org/I4210124755","https://openalex.org/I1321296531"]},{"raw_affiliation_string":"National Institute of Standards and Technology, Gaithersburg, MD, USA","institution_ids":["https://openalex.org/I1321296531"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5036504001"],"corresponding_institution_ids":["https://openalex.org/I1321296531"],"apc_list":null,"apc_paid":null,"fwci":4.6374,"has_fulltext":false,"cited_by_count":50,"citation_normalized_percentile":{"value":0.95702845,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":"67","issue":"3","first_page":"870","last_page":"884"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.8615272045135498},{"id":"https://openalex.org/keywords/cryptographic-hash-function","display_name":"Cryptographic hash function","score":0.824545681476593},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7456240057945251},{"id":"https://openalex.org/keywords/sha-2","display_name":"SHA-2","score":0.7223153114318848},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.6395375728607178},{"id":"https://openalex.org/keywords/implementation","display_name":"Implementation","score":0.591011106967926},{"id":"https://openalex.org/keywords/nist","display_name":"NIST","score":0.5151337385177612},{"id":"https://openalex.org/keywords/secure-hash-algorithm","display_name":"Secure Hash Algorithm","score":0.4966748356819153},{"id":"https://openalex.org/keywords/test-suite","display_name":"Test suite","score":0.46590477228164673},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.444318950176239},{"id":"https://openalex.org/keywords/cryptographic-primitive","display_name":"Cryptographic primitive","score":0.4310973882675171},{"id":"https://openalex.org/keywords/digital-signature","display_name":"Digital signature","score":0.42351043224334717},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.35218721628189087},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3041631579399109},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.22738438844680786},{"id":"https://openalex.org/keywords/test-case","display_name":"Test case","score":0.22639071941375732},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.13215318322181702},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.07397153973579407}],"concepts":[{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.8615272045135498},{"id":"https://openalex.org/C7608002","wikidata":"https://www.wikidata.org/wiki/Q477202","display_name":"Cryptographic hash function","level":3,"score":0.824545681476593},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7456240057945251},{"id":"https://openalex.org/C190157925","wikidata":"https://www.wikidata.org/wiki/Q1968605","display_name":"SHA-2","level":4,"score":0.7223153114318848},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.6395375728607178},{"id":"https://openalex.org/C26713055","wikidata":"https://www.wikidata.org/wiki/Q245962","display_name":"Implementation","level":2,"score":0.591011106967926},{"id":"https://openalex.org/C111219384","wikidata":"https://www.wikidata.org/wiki/Q6954384","display_name":"NIST","level":2,"score":0.5151337385177612},{"id":"https://openalex.org/C9661340","wikidata":"https://www.wikidata.org/wiki/Q257799","display_name":"Secure Hash Algorithm","level":5,"score":0.4966748356819153},{"id":"https://openalex.org/C151552104","wikidata":"https://www.wikidata.org/wiki/Q7705809","display_name":"Test suite","level":4,"score":0.46590477228164673},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.444318950176239},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.4310973882675171},{"id":"https://openalex.org/C118463975","wikidata":"https://www.wikidata.org/wiki/Q220849","display_name":"Digital signature","level":3,"score":0.42351043224334717},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.35218721628189087},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3041631579399109},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.22738438844680786},{"id":"https://openalex.org/C128942645","wikidata":"https://www.wikidata.org/wiki/Q1568346","display_name":"Test case","level":3,"score":0.22639071941375732},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.13215318322181702},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.07397153973579407},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.0},{"id":"https://openalex.org/C152877465","wikidata":"https://www.wikidata.org/wiki/Q208042","display_name":"Regression analysis","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/tr.2018.2847247","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tr.2018.2847247","pdf_url":null,"source":{"id":"https://openalex.org/S87725633","display_name":"IEEE Transactions on Reliability","issn_l":"0018-9529","issn":["0018-9529","1558-1721"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Reliability","raw_type":"journal-article"},{"id":"pmid:31092953","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/31092953","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on reliability","raw_type":null},{"id":"pmh:oai:pubmedcentral.nih.gov:6512998","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/6512998","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Trans Reliab","raw_type":"Text"}],"best_oa_location":{"id":"pmh:oai:pubmedcentral.nih.gov:6512998","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/6512998","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Trans Reliab","raw_type":"Text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G520378974","display_name":null,"funder_award_id":"70NANB17H035","funder_id":"https://openalex.org/F4320332178","funder_display_name":"National Institute of Standards and Technology"}],"funders":[{"id":"https://openalex.org/F4320332178","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W15574367","https://openalex.org/W45979384","https://openalex.org/W103427359","https://openalex.org/W142920396","https://openalex.org/W200599792","https://openalex.org/W616055941","https://openalex.org/W1508796064","https://openalex.org/W1591098212","https://openalex.org/W1656731780","https://openalex.org/W1660562555","https://openalex.org/W1702158037","https://openalex.org/W1971233427","https://openalex.org/W1995841147","https://openalex.org/W2004513455","https://openalex.org/W2010962701","https://openalex.org/W2041713059","https://openalex.org/W2043998723","https://openalex.org/W2058858100","https://openalex.org/W2092115639","https://openalex.org/W2103184699","https://openalex.org/W2103239853","https://openalex.org/W2110441383","https://openalex.org/W2128204165","https://openalex.org/W2154897437","https://openalex.org/W2189437830","https://openalex.org/W2241022088","https://openalex.org/W2324595780","https://openalex.org/W2407671386","https://openalex.org/W2428841090","https://openalex.org/W2533023104","https://openalex.org/W2617512516","https://openalex.org/W2619630761","https://openalex.org/W2782311202","https://openalex.org/W2894806357","https://openalex.org/W2950285309","https://openalex.org/W4247184692","https://openalex.org/W4290474734","https://openalex.org/W4403868128","https://openalex.org/W6600626145","https://openalex.org/W6601908694","https://openalex.org/W6604171925","https://openalex.org/W6608218161","https://openalex.org/W6637620405","https://openalex.org/W6713688643","https://openalex.org/W6763807806","https://openalex.org/W6841466026","https://openalex.org/W7054730758","https://openalex.org/W7073554479"],"related_works":["https://openalex.org/W2785118141","https://openalex.org/W1663728611","https://openalex.org/W2342330140","https://openalex.org/W2087091654","https://openalex.org/W1773180899","https://openalex.org/W4289821808","https://openalex.org/W275246813","https://openalex.org/W1590262417","https://openalex.org/W2141288318","https://openalex.org/W2227130482"],"abstract_inverted_index":{"Cryptographic":[0],"hash":[1,36,65,84,100,195],"functions":[2],"are":[3,112],"security-critical":[4],"algorithms":[5],"with":[6],"many":[7,30],"practical":[8],"applications,":[9],"notably":[10],"in":[11,79,115,144,162],"digital":[12],"signatures.":[13],"Developing":[14],"an":[15],"approach":[16],"to":[17,42,53,108,123,152,188],"test":[18,126],"them":[19],"can":[20,26],"be":[21],"particularly":[22,180],"difficult,":[23],"and":[24,47,86,117,178],"bugs":[25,143,204],"remain":[27],"unnoticed":[28],"for":[29,175],"years.":[31],"We":[32,103,201],"revisit":[33],"the":[34,44,60,80,83,87,94,99,105,125,136,147,153,157,167,190,194,199],"NIST":[35],"function":[37,66],"competition,":[38,155],"which":[39],"was":[40],"used":[41],"develop":[43,70,104],"SHA-3":[45,154,168],"standard,":[46],"apply":[48],"a":[49,64,160,185,206],"new":[50],"testing":[51,121,208],"strategy":[52,187],"all":[54,163],"available":[55],"reference":[56,149],"implementations.":[57],"Motivated":[58],"by":[59,129,198],"cryptographic":[61],"properties":[62],"that":[63,91,110],"should":[67],"satisfy,":[68],"we":[69],"four":[71],"tests.":[72],"The":[73],"Bit-Contribution":[74],"Test":[75,89,107],"checks":[76,90],"if":[77],"changes":[78,92],"message":[81,96,191],"affect":[82],"value,":[85],"Bit-Exclusion":[88],"beyond":[93],"last":[95],"bit":[97],"leave":[98],"value":[101,196],"unchanged.":[102],"Update":[106],"verify":[109],"messages":[111],"processed":[113],"correctly":[114],"chunks,":[116],"then":[118],"use":[119],"combinatorial":[120],"methods":[122],"reduce":[124],"set":[127],"size":[128],"several":[130],"orders":[131],"of":[132,146,159,166],"magnitude":[133],"while":[134],"retaining":[135],"same":[137],"fault-detection":[138],"capability.":[139],"Our":[140],"tests":[141],"detect":[142,202],"41":[145],"86":[148],"implementations":[150,165],"submitted":[151,164],"including":[156],"rediscovery":[158],"bug":[161,172],"finalist":[169],"BLAKE.":[170],"This":[171],"remained":[173],"undiscovered":[174],"seven":[176],"years,":[177],"is":[179],"serious":[181],"because":[182],"it":[183],"provides":[184],"simple":[186],"modify":[189],"without":[192],"changing":[193],"returned":[197],"implementation.":[200],"these":[203],"using":[205],"fully-automated":[207],"approach.":[209]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":8},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":11},{"year":2018,"cited_by_count":4}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
