{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,8]],"date-time":"2025-07-08T00:47:06Z","timestamp":1751935626318,"version":"3.40.5"},"reference-count":45,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T00:00:00Z","timestamp":1567296000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Processing Letters"],"published-print":{"date-parts":[[2019,9]]},"DOI":"10.1016\/j.ipl.2019.05.001","type":"journal-article","created":{"date-parts":[[2019,5,9]],"date-time":"2019-05-09T03:15:24Z","timestamp":1557371724000},"page":"1-5","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"special_numbering":"C","title":["An observation on NORX, BLAKE2, and ChaCha"],"prefix":"10.1016","volume":"149","author":[{"given":"Samuel","family":"Neves","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-1663-1937","authenticated-orcid":false,"given":"Filipe","family":"Araujo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"year":"2015","series-title":"Higher Order Differential Analysis of NORX","author":"Das","key":"10.1016\/j.ipl.2019.05.001_br0010"},{"key":"10.1016\/j.ipl.2019.05.001_br0020","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/s001459900025","article-title":"A construction of a cipher from a single pseudorandom permutation","volume":"10","author":"Even","year":"1997","journal-title":"J. Cryptol."},{"key":"10.1016\/j.ipl.2019.05.001_br0030","series-title":"CRYPTO 2015, Part I","first-page":"189","article-title":"Tweaking Even-Mansour ciphers","volume":"vol. 9215","author":"Cogliati","year":"2015"},{"key":"10.1016\/j.ipl.2019.05.001_br0040","series-title":"CRYPTO 2016, Part I","first-page":"64","article-title":"XPX: generalized tweakable Even-Mansour with improved security guarantees","volume":"vol. 9814","author":"Mennink","year":"2016"},{"key":"10.1016\/j.ipl.2019.05.001_br0050","series-title":"EUROCRYPT 2016, Part I","first-page":"263","article-title":"Improved masking for tweakable blockciphers with applications to authenticated encryption","volume":"vol. 9665","author":"Granger","year":"2016"},{"key":"10.1016\/j.ipl.2019.05.001_br0060","series-title":"ECRYPT Hash Workshop 2007","article-title":"Sponge functions","author":"Bertoni","year":"2007"},{"key":"10.1016\/j.ipl.2019.05.001_br0070","series-title":"EUROCRYPT 2008","first-page":"181","article-title":"On the indifferentiability of the sponge construction","volume":"vol. 4965","author":"Bertoni","year":"2008"},{"author":"Bertoni","key":"10.1016\/j.ipl.2019.05.001_br0080"},{"key":"10.1016\/j.ipl.2019.05.001_br0090","series-title":"CHES 2010","first-page":"33","article-title":"Sponge-based pseudo-random number generators","volume":"vol. 6225","author":"Bertoni","year":"2010"},{"key":"10.1016\/j.ipl.2019.05.001_br0100","series-title":"SAC 2011","first-page":"320","article-title":"Duplexing the sponge: single-pass authenticated encryption and other applications","volume":"vol. 7118","author":"Bertoni","year":"2012"},{"key":"10.1016\/j.ipl.2019.05.001_br0110","doi-asserted-by":"crossref","unstructured":"M.-J.O. Saarinen, Beyond modes: building a secure record protocol from a cryptographic sponge permutation, in: [44], 2014, pp. 270\u2013285, https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/978-3-319-04852-9_14.","DOI":"10.1007\/978-3-319-04852-9_14"},{"year":"2017","series-title":"The STROBE Protocol Framework","author":"Hamburg","key":"10.1016\/j.ipl.2019.05.001_br0120"},{"key":"10.1016\/j.ipl.2019.05.001_br0130","series-title":"New Stream Cipher Designs - The eSTREAM Finalists","first-page":"84","article-title":"The Salsa20 family of stream ciphers","volume":"vol. 4986","author":"Bernstein","year":"2008"},{"key":"10.1016\/j.ipl.2019.05.001_br0140","series-title":"Workshop Record of SASC 2008: The State of the Art of Stream Ciphers","article-title":"ChaCha, a variant of Salsa20","author":"Bernstein","year":"2008"},{"author":"Aumasson","key":"10.1016\/j.ipl.2019.05.001_br0150"},{"key":"10.1016\/j.ipl.2019.05.001_br0160","series-title":"ACNS 13","first-page":"119","article-title":"BLAKE2: simpler, smaller, fast as MD5","volume":"vol. 7954","author":"Aumasson","year":"2013"},{"key":"10.1016\/j.ipl.2019.05.001_br0170","series-title":"ESORICS 2014, Part II","first-page":"19","article-title":"NORX: parallel and scalable AEAD","volume":"vol. 8713","author":"Aumasson","year":"2014"},{"key":"10.1016\/j.ipl.2019.05.001_br0180","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1016\/j.dam.2016.02.020","article-title":"Chosen IV cryptanalysis on reduced round chacha and salsa","volume":"208","author":"Maitra","year":"2016","journal-title":"Discrete Appl. Math."},{"key":"10.1016\/j.ipl.2019.05.001_br0190","doi-asserted-by":"crossref","unstructured":"J.C.H. Castro, J.M. Est\u00e9vez-Tapiador, J.-J. Quisquater, On the Salsa20 core function, in: [45], 2008, pp. 462\u2013469, https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/978-3-540-71039-4_29.","DOI":"10.1007\/978-3-540-71039-4_29"},{"key":"10.1016\/j.ipl.2019.05.001_br0200","series-title":"ICISC 12","first-page":"337","article-title":"Improved key recovery attacks on reduced-round Salsa20 and ChaCha","volume":"vol. 7839","author":"Shi","year":"2013"},{"key":"10.1016\/j.ipl.2019.05.001_br0210","series-title":"INDOCRYPT 2008","first-page":"1","article-title":"Slid pairs in Salsa20 and Trivium","volume":"vol. 5365","author":"Priemuth-Schmid","year":"2008"},{"year":"2015","series-title":"Salsa20 Cryptanalysis: New Moves and Revisiting Old Styles","author":"Maitra","key":"10.1016\/j.ipl.2019.05.001_br0220"},{"year":"2005","series-title":"Truncated Differential Cryptanalysis of Five Rounds of Salsa20","author":"Crowley","key":"10.1016\/j.ipl.2019.05.001_br0230"},{"key":"10.1016\/j.ipl.2019.05.001_br0240","doi-asserted-by":"crossref","unstructured":"J.-P. Aumasson, S. Fischer, S. Khazaei, W. Meier, C. Rechberger, New features of Latin dances: analysis of Salsa, ChaCha, and Rumba, in: [45], 2008, pp. 470\u2013488, https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/978-3-540-71039-4_30.","DOI":"10.1007\/978-3-540-71039-4_30"},{"key":"10.1016\/j.ipl.2019.05.001_br0250","doi-asserted-by":"crossref","unstructured":"J. Guo, P. Karpman, I. Nikolic, L. Wang, S. Wu, Analysis of BLAKE2, in: [44], 2014, pp. 402\u2013423, https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/978-3-319-04852-9_21.","DOI":"10.1007\/978-3-319-04852-9_21"},{"year":"2009","series-title":"Attacks on Round-Reduced BLAKE","author":"Li","key":"10.1016\/j.ipl.2019.05.001_br0260"},{"key":"10.1016\/j.ipl.2019.05.001_br0270","series-title":"FSE 2011","first-page":"218","article-title":"Boomerang attacks on BLAKE-32","volume":"vol. 6733","author":"Biryukov","year":"2011"},{"key":"10.1016\/j.ipl.2019.05.001_br0280","series-title":"Information Security and Cryptology - 10th International Conference","first-page":"286","article-title":"The boomerang attacks on BLAKE and BLAKE2","volume":"vol. 8957","author":"Hao","year":"2014"},{"key":"10.1016\/j.ipl.2019.05.001_br0290","series-title":"FSE 2010","first-page":"318","article-title":"Differential and invertibility properties of BLAKE","volume":"vol. 6147","author":"Aumasson","year":"2010"},{"key":"10.1016\/j.ipl.2019.05.001_br0300","series-title":"LATINCRYPT 2014","first-page":"306","article-title":"Analysis of NORX: investigating differential and rotational properties","volume":"vol. 8895","author":"Aumasson","year":"2015"},{"key":"10.1016\/j.ipl.2019.05.001_br0310","series-title":"FSE 2016","first-page":"554","article-title":"Cryptanalysis of reduced NORX","volume":"vol. 9783","author":"Bagheri","year":"2016"},{"key":"10.1016\/j.ipl.2019.05.001_br0320","doi-asserted-by":"crossref","first-page":"156","DOI":"10.46586\/tosc.v2017.i1.156-174","article-title":"Cryptanalysis of NORX v2.0","volume":"2017","author":"Chaigneau","year":"2017","journal-title":"IACR Trans. Symm. Cryptol."},{"year":"2017","series-title":"Analysis of the NORX Core Permutation","author":"Biryukov","key":"10.1016\/j.ipl.2019.05.001_br0330"},{"key":"10.1016\/j.ipl.2019.05.001_br0340","doi-asserted-by":"crossref","first-page":"57","DOI":"10.46586\/tosc.v2018.i1.57-73","article-title":"Distinguishing attack on NORX permutation","volume":"2018","author":"Huang","year":"2018","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"10.1016\/j.ipl.2019.05.001_br0350","first-page":"261","article-title":"Significantly improved multi-bit differentials for reduced round Salsa and ChaCha","volume":"2016","author":"Choudhuri","year":"2016","journal-title":"IACR Trans. Symm. Cryptol."},{"author":"Aumasson","key":"10.1016\/j.ipl.2019.05.001_br0360"},{"key":"10.1016\/j.ipl.2019.05.001_br0370","series-title":"ASIACRYPT 2007","first-page":"315","article-title":"Known-key distinguishers for some block ciphers","volume":"vol. 4833","author":"Knudsen","year":"2007"},{"key":"10.1016\/j.ipl.2019.05.001_br0380","series-title":"ISC 2015","first-page":"177","article-title":"From distinguishers to key recovery: improved related-key attacks on Even-Mansour","volume":"vol. 9290","author":"Karpman","year":"2015"},{"key":"10.1016\/j.ipl.2019.05.001_br0390","series-title":"ASIACRYPT 2014, Part I","first-page":"158","article-title":"Automatic security evaluation and (related-key) differential characteristic search: application to SIMON, PRESENT, LBlock, DES(L) and other bit-oriented block ciphers","volume":"vol. 8873","author":"Sun","year":"2014"},{"key":"10.1016\/j.ipl.2019.05.001_br0400","series-title":"FSE'99","first-page":"156","article-title":"The boomerang attack","volume":"vol. 1636","author":"Wagner","year":"1999"},{"key":"10.1016\/j.ipl.2019.05.001_br0410","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-17342-4","article-title":"The Block Cipher Companion","author":"Knudsen","year":"2011"},{"key":"10.1016\/j.ipl.2019.05.001_br0420","series-title":"ICICS 11","first-page":"255","article-title":"Latin dances revisited: new analytic results of Salsa20 and ChaCha","volume":"vol. 7043","author":"Ishiguro","year":"2011"},{"key":"10.1016\/j.ipl.2019.05.001_br0430","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.dam.2017.04.034","article-title":"Improved analysis for reduced round Salsa and ChaCha","volume":"227","author":"Dey","year":"2017","journal-title":"Discrete Appl. Math."},{"volume":"vol. 8366","year":"2014","series-title":"CT-RSA 2014","key":"10.1016\/j.ipl.2019.05.001_br0440"},{"volume":"vol. 5086","year":"2008","series-title":"FSE 2008","key":"10.1016\/j.ipl.2019.05.001_br0450"}],"container-title":["Information Processing Letters"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S0020019019300821?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S0020019019300821?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2020,12,11]],"date-time":"2020-12-11T19:44:14Z","timestamp":1607715854000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/linkinghub.elsevier.com\/retrieve\/pii\/S0020019019300821"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,9]]},"references-count":45,"alternative-id":["S0020019019300821"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.ipl.2019.05.001","relation":{},"ISSN":["0020-0190"],"issn-type":[{"type":"print","value":"0020-0190"}],"subject":[],"published":{"date-parts":[[2019,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"An observation on NORX, BLAKE2, and ChaCha","name":"articletitle","label":"Article Title"},{"value":"Information Processing Letters","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.ipl.2019.05.001","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2019 Elsevier B.V. All rights reserved.","name":"copyright","label":"Copyright"}]}}