{"id":"https://openalex.org/W7136206371","doi":"https://doi.org/10.46586/tosc.v2026.i1.253-292","title":"Cube and Integral Attacks on ChiLow-32","display_name":"Cube and Integral Attacks on ChiLow-32","publication_year":2026,"publication_date":"2026-03-16","ids":{"openalex":"https://openalex.org/W7136206371","doi":"https://doi.org/10.46586/tosc.v2026.i1.253-292"},"language":"en","primary_location":{"id":"doi:10.46586/tosc.v2026.i1.253-292","is_oa":true,"landing_page_url":"https://doi.org/10.46586/tosc.v2026.i1.253-292","pdf_url":"https://tosc.iacr.org/index.php/ToSC/article/download/12786/12475","source":{"id":"https://openalex.org/S4210236173","display_name":"IACR Transactions on Symmetric Cryptology","issn_l":"2519-173X","issn":["2519-173X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IACR Transactions on Symmetric Cryptology","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://tosc.iacr.org/index.php/ToSC/article/download/12786/12475","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5090609083","display_name":"S. L. Peng","orcid":null},"institutions":[{"id":"https://openalex.org/I4210132990","display_name":"State Key Laboratory of Cryptology","ror":"https://ror.org/02pn5rj08","country_code":"CN","type":"government","lineage":["https://openalex.org/I4210132990"]},{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shuo Peng","raw_affiliation_strings":["School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China"],"raw_orcid":"https://orcid.org/0009-0000-6461-9898","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China","institution_ids":["https://openalex.org/I4210132990","https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069246999","display_name":"Akram Khalesi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Akram Khalesi","raw_affiliation_strings":["Research Center for Development of Advanced Technologies, Tehran, Iran"],"raw_orcid":"https://orcid.org/0009-0006-2052-492X","affiliations":[{"raw_affiliation_string":"Research Center for Development of Advanced Technologies, Tehran, Iran","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048904017","display_name":"Zahra Ahmadian","orcid":"https://orcid.org/0000-0001-9356-4064"},"institutions":[{"id":"https://openalex.org/I48379061","display_name":"Shahid Beheshti University","ror":"https://ror.org/0091vmj44","country_code":"IR","type":"education","lineage":["https://openalex.org/I48379061"]}],"countries":["IR"],"is_corresponding":false,"raw_author_name":"Zahra Ahmadian","raw_affiliation_strings":["Faculty of Electrical Engineering, Shahid Beheshti University, Tehran, Iran"],"raw_orcid":"https://orcid.org/0000-0001-9356-4064","affiliations":[{"raw_affiliation_string":"Faculty of Electrical Engineering, Shahid Beheshti University, Tehran, Iran","institution_ids":["https://openalex.org/I48379061"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029184294","display_name":"Hosein Hadipour","orcid":"https://orcid.org/0000-0002-3820-3765"},"institutions":[{"id":"https://openalex.org/I904495901","display_name":"Ruhr University Bochum","ror":"https://ror.org/04tsk2644","country_code":"DE","type":"education","lineage":["https://openalex.org/I904495901"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Hosein Hadipour","raw_affiliation_strings":["Faculty of Computer Science, Ruhr University Bochum, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0002-3820-3765","affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, Ruhr University Bochum, Bochum, Germany","institution_ids":["https://openalex.org/I904495901"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047157992","display_name":"Jiahui He","orcid":"https://orcid.org/0000-0002-4033-588X"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Jiahui He","raw_affiliation_strings":["School of Cyber Science and Technology, Shandong University, Qingdao, China; COSIC, Katholieke Universiteit Leuven, Leuven, Belgium"],"raw_orcid":"https://orcid.org/0000-0002-4033-588X","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shandong University, Qingdao, China; COSIC, Katholieke Universiteit Leuven, Leuven, Belgium","institution_ids":["https://openalex.org/I99464096"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071613345","display_name":"Kai Hu","orcid":null},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kai Hu","raw_affiliation_strings":["School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China; Suzhou Research Institute, Shandong University, Suzhou, 215123, China"],"raw_orcid":"https://orcid.org/0000-0003-3552-7200","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China; Suzhou Research Institute, Shandong University, Suzhou, 215123, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Zhongfeng Niu","orcid":"https://orcid.org/0009-0009-6932-2116"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Zhongfeng Niu","raw_affiliation_strings":["School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore, Singapore"],"raw_orcid":"https://orcid.org/0009-0009-6932-2116","affiliations":[{"raw_affiliation_string":"School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078438173","display_name":"Shahram Rasoolzadeh","orcid":"https://orcid.org/0000-0001-6848-2227"},"institutions":[{"id":"https://openalex.org/I904495901","display_name":"Ruhr University Bochum","ror":"https://ror.org/04tsk2644","country_code":"DE","type":"education","lineage":["https://openalex.org/I904495901"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Shahram Rasoolzadeh","raw_affiliation_strings":["Faculty of Computer Science, Ruhr University Bochum, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0001-6848-2227","affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, Ruhr University Bochum, Bochum, Germany","institution_ids":["https://openalex.org/I904495901"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100707460","display_name":"Mengdi Wang","orcid":"https://orcid.org/0000-0002-2101-9507"},"institutions":[{"id":"https://openalex.org/I4210132990","display_name":"State Key Laboratory of Cryptology","ror":"https://ror.org/02pn5rj08","country_code":"CN","type":"government","lineage":["https://openalex.org/I4210132990"]},{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Meiqin Wang","raw_affiliation_strings":["School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shandong University, Qingdao, China; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, China","institution_ids":["https://openalex.org/I4210132990","https://openalex.org/I80143920"]}]}],"institutions":[],"countries_distinct_count":5,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.28119571,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"2026","issue":"1","first_page":"253","last_page":"292"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9573000073432922,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9573000073432922,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11130","display_name":"Coding theory and cryptography","score":0.019099999219179153,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.005200000014156103,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/block-cipher","display_name":"Block cipher","score":0.6392999887466431},{"id":"https://openalex.org/keywords/ciphertext","display_name":"Ciphertext","score":0.6389999985694885},{"id":"https://openalex.org/keywords/cryptanalysis","display_name":"Cryptanalysis","score":0.49459999799728394},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.4260999858379364},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4235000014305115},{"id":"https://openalex.org/keywords/correctness","display_name":"Correctness","score":0.41200000047683716},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.40639999508857727},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.39079999923706055},{"id":"https://openalex.org/keywords/key-schedule","display_name":"Key schedule","score":0.37450000643730164}],"concepts":[{"id":"https://openalex.org/C106544461","wikidata":"https://www.wikidata.org/wiki/Q543151","display_name":"Block cipher","level":3,"score":0.6392999887466431},{"id":"https://openalex.org/C93974786","wikidata":"https://www.wikidata.org/wiki/Q1589480","display_name":"Ciphertext","level":3,"score":0.6389999985694885},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5688999891281128},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.5633999705314636},{"id":"https://openalex.org/C181149355","wikidata":"https://www.wikidata.org/wiki/Q897511","display_name":"Cryptanalysis","level":3,"score":0.49459999799728394},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.4260999858379364},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4235000014305115},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.41200000047683716},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.40639999508857727},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.40450000762939453},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.39079999923706055},{"id":"https://openalex.org/C112145980","wikidata":"https://www.wikidata.org/wiki/Q2569509","display_name":"Key schedule","level":5,"score":0.37450000643730164},{"id":"https://openalex.org/C207468940","wikidata":"https://www.wikidata.org/wiki/Q869370","display_name":"Brute-force attack","level":3,"score":0.36640000343322754},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.36090001463890076},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.35989999771118164},{"id":"https://openalex.org/C2777210771","wikidata":"https://www.wikidata.org/wiki/Q4927124","display_name":"Block (permutation group theory)","level":2,"score":0.350600004196167},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.3488999903202057},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.34860000014305115},{"id":"https://openalex.org/C84392682","wikidata":"https://www.wikidata.org/wiki/Q1952404","display_name":"Multilinear map","level":2,"score":0.320499986410141},{"id":"https://openalex.org/C2780221543","wikidata":"https://www.wikidata.org/wiki/Q4681865","display_name":"Cipher","level":3,"score":0.3190000057220459},{"id":"https://openalex.org/C131672422","wikidata":"https://www.wikidata.org/wiki/Q852594","display_name":"Provable security","level":3,"score":0.2883000075817108},{"id":"https://openalex.org/C60448319","wikidata":"https://www.wikidata.org/wiki/Q154021","display_name":"Block cipher mode of operation","level":2,"score":0.28459998965263367},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.2685999870300293},{"id":"https://openalex.org/C2780069185","wikidata":"https://www.wikidata.org/wiki/Q7977945","display_name":"Equivalence (formal languages)","level":2,"score":0.25760000944137573},{"id":"https://openalex.org/C153207627","wikidata":"https://www.wikidata.org/wiki/Q863873","display_name":"Code word","level":3,"score":0.25099998712539673},{"id":"https://openalex.org/C9376300","wikidata":"https://www.wikidata.org/wiki/Q168817","display_name":"Algebraic number","level":2,"score":0.25049999356269836}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.46586/tosc.v2026.i1.253-292","is_oa":true,"landing_page_url":"https://doi.org/10.46586/tosc.v2026.i1.253-292","pdf_url":"https://tosc.iacr.org/index.php/ToSC/article/download/12786/12475","source":{"id":"https://openalex.org/S4210236173","display_name":"IACR Transactions on Symmetric Cryptology","issn_l":"2519-173X","issn":["2519-173X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IACR Transactions on Symmetric Cryptology","raw_type":"journal-article"},{"id":"pmh:oai:lirias2repo.kuleuven.be:20.500.12942/788797","is_oa":true,"landing_page_url":"https://lirias.kuleuven.be/handle/20.500.12942/788797","pdf_url":null,"source":{"id":"https://openalex.org/S7407055369","display_name":"Lirias","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":"IACR Transactions on Symmetric Cryptology, vol. 2026 (1), (253-292)","raw_type":"info:eu-repo/semantics/article"},{"id":"pmh:oai:doaj.org/article:d98dda53ea4e4f43aa15e6e8f1efc437","is_oa":true,"landing_page_url":"https://doaj.org/article/d98dda53ea4e4f43aa15e6e8f1efc437","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IACR Transactions on Symmetric Cryptology, Vol 2026, Iss 1 (2026)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.46586/tosc.v2026.i1.253-292","is_oa":true,"landing_page_url":"https://doi.org/10.46586/tosc.v2026.i1.253-292","pdf_url":"https://tosc.iacr.org/index.php/ToSC/article/download/12786/12475","source":{"id":"https://openalex.org/S4210236173","display_name":"IACR Transactions on Symmetric Cryptology","issn_l":"2519-173X","issn":["2519-173X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IACR Transactions on Symmetric Cryptology","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.6763452291488647,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G3301971763","display_name":null,"funder_award_id":"JYB2025XDXM114","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6220799212","display_name":"Cybersecurity Research Program Flanders \u2013 second cycle","funder_award_id":"VOEWICS02","funder_id":"https://openalex.org/F4320327336","funder_display_name":"Vlaamse regering"},{"id":"https://openalex.org/G6785854632","display_name":null,"funder_award_id":"U2336207","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7735407926","display_name":null,"funder_award_id":"62032014","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321106","display_name":"Ministry of Education of the People's Republic of China","ror":"https://ror.org/01mv9t934"},{"id":"https://openalex.org/F4320321605","display_name":"Government of Jiangsu Province","ror":"https://ror.org/004svx814"},{"id":"https://openalex.org/F4320322769","display_name":"Natural Science Foundation of Jiangsu Province","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320324174","display_name":"Natural Science Foundation of Shandong Province","ror":null},{"id":"https://openalex.org/F4320327336","display_name":"Vlaamse regering","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7136206371.pdf","grobid_xml":"https://content.openalex.org/works/W7136206371.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"protection":[1],"of":[2,83,89,161,191,210,220,264,292,326,343],"executable":[3],"code":[4,70],"in":[5,68,99,231,282],"embedded":[6],"systems":[7],"requires":[8,317],"efficient":[9],"mechanisms":[10],"that":[11,112,280,316],"ensure":[12],"confidentiality":[13],"and":[14,59,85,96,101,127,153,188,193,207,217,234,237,241,260,271,296,330],"integrity.":[15],"Belkheyar":[16],"et":[17],"al.":[18],"recently":[19],"proposed":[20],"the":[21,30,80,87,105,115,129,163,172,218,222,232,262,266,283,289,299,340,344],"Authenticated":[22],"Code":[23],"Encryption":[24],"(ACE)":[25],"framework,":[26],"with":[27,48,124,166,339],"ChiLow":[28],"as":[29],"first":[31],"ACE-2":[32],"instantiation":[33],"at":[34,134],"EUROCRYPT":[35],"2025.":[36],"ChiLow-(32":[37,90,120,155,177,196,312],"+":[38,91,121,156,178,197,313],"\u03c4":[39,92,122,157,179,198,314],")":[40,93,123,180,199,315],"is":[41],"a":[42,49,60,135,247,252,303,307,323],"32-bit":[43],"tweakable":[44],"block":[45],"cipher":[46],"combined":[47],"pseudorandom":[50],"function,":[51],"featuring":[52],"quadratic":[53],"nonlinear":[54],"layers":[55],"called":[56],"ChiChi":[57],"(\u03c7\u03c7)":[58],"nested":[61,253],"tweak/key":[62],"schedule":[63],"optimized":[64],"for":[65,118,175,194],"low-latency":[66],"decryptions":[67],"secure":[69],"execution":[71],"under":[72],"strict":[73],"query":[74],"limits.In":[75],"this":[76],"paper,":[77],"we":[78,108,170,305],"exploit":[79],"algebraic":[81],"structure":[82],"\u03c7\u03c7":[84],"study":[86],"resistance":[88],"to":[94,131,224,245,255,287],"cube-like":[95],"integral":[97,215,229,243,284],"cryptanalysis":[98,216],"single-":[100,233],"multiple-tweak":[102,106,235],"settings.":[103],"In":[104],"setting,":[107],"present":[109,251],"conditional":[110],"attacks":[111,150,336],"can":[113],"recover":[114,171,256],"full":[116,164,173],"key":[117,165,174,268,272,294],"5-round":[119,176],"practical":[125,167],"complexity,":[126],"extend":[128,238],"analysis":[130,223],"6":[132],"rounds":[133],"still":[136],"non-trivial":[137],"but":[138],"purely":[139],"theoretical":[140],"cost":[141],"below":[142],"brute":[143],"force.":[144],"We":[145,227,250],"additionally":[146],"construct":[147],"borderline":[148],"cube":[149],"on":[151,214,311],"5-":[152],"6-round":[154,195],"),":[158],"each":[159],"capable":[160],"recovering":[162],"complexity.":[168,301],"Specifically,":[169],"using":[181,200],"232":[182],"decryptions,":[183,202],"218.58":[184],"chosen":[185,204,319],"ciphertext":[186,205,320],"data,":[187,206,321],"233.56":[189],"bits":[190,209,295],"memory,":[192],"234":[201],"233.58":[203],"254.28":[208],"memory.We":[211],"then":[212],"focus":[213],"challenge":[219],"extending":[221],"7":[225],"rounds.":[226],"identify":[228],"distinguishers":[230,244],"models":[236],"suitable":[239],"2-round":[240],"3-round":[242],"build":[246],"7-round":[248,308],"attack.":[249],"strategy":[254],"all":[257,334],"round":[258],"tweaks":[259],"tackle":[261],"problem":[263],"deriving":[265],"master":[267],"from":[269],"round-tweak":[270],"information.":[273],"Our":[274],"key-recovery":[275,285,309],"method":[276],"exploits":[277],"high-degree":[278],"monomials":[279],"arise":[281],"phase":[286],"reduce":[288,298],"average":[290],"number":[291],"guessed":[293],"hence":[297],"time":[300,324],"As":[302],"result,":[304],"mount":[306],"attack":[310],"26.32":[318],"has":[322],"complexity":[325],"about":[327],"2108.55":[328],"encryptions,":[329],"needs":[331],"negligible":[332],"memory.Notably,":[333],"our":[335],"remain":[337],"consistent":[338],"security":[341],"claims":[342],"design.":[345]},"counts_by_year":[],"updated_date":"2026-07-03T08:13:44.112507","created_date":"2026-03-17T00:00:00"}
