PRESENT: An ultra-lightweight block cipher A Bogdanov, LR Knudsen, G Leander, C Paar, A Poschmann, ... Cryptographic Hardware and Embedded Systems-CHES 2007, 450-466, 2007 | 2123 | 2007 |

Biclique cryptanalysis of the full AES A Bogdanov, D Khovratovich, C Rechberger Advances in Cryptology–ASIACRYPT 2011, 344-371, 2011 | 540 | 2011 |

SPONGENT: a lightweight hash function A Bogdanov, M Knežević, G Leander, D Toz, K Varıcı, I Verbauwhede Cryptographic Hardware and Embedded Systems–CHES 2011, 312-325, 2011 | 238 | 2011 |

Midori: A Block Cipher for Low Energy S Banik, A Bogdanov, T Isobe, K Shibutani, H Hiwatari, T Akishita, ... Advances in Cryptology–ASIACRYPT 2015, 411-436, 2015 | 198 | 2015 |

Hash functions and RFID tags: Mind the gap A Bogdanov, G Leander, C Paar, A Poschmann, MJB Robshaw, Y Seurin Cryptographic Hardware and Embedded Systems–CHES 2008, 283-299, 2008 | 193 | 2008 |

Linear hulls with correlation zero and linear cryptanalysis of block ciphers A Bogdanov, V Rijmen Cryptology ePrint archive: 2011/123: Listing for 2011, 2014 | 142 | 2014 |

A 3-subset meet-in-the-middle attack: cryptanalysis of the lightweight block cipher KTANTAN A Bogdanov, C Rechberger Selected Areas in Cryptography, 229-240, 2011 | 123 | 2011 |

Generalized Meet-in-the-Middle Attacks: Cryptanalysis of the Lightweight Block Cipher KTANTAN A Bogdanov, C Rechberger SAC, 228-238, 2010 | 123* | 2010 |

Parallelizable and authenticated online ciphers E Andreeva, A Bogdanov, A Luykx, B Mennink, E Tischhauser, K Yasuda Advances in Cryptology-ASIACRYPT 2013, 424-443, 2013 | 120 | 2013 |

ALE: AES-based lightweight authenticated encryption A Bogdanov, F Mendel, F Regazzoni, V Rijmen, E Tischhauser Fast Software Encryption, 447-466, 2014 | 108 | 2014 |

Zero correlation linear cryptanalysis with reduced data complexity A Bogdanov, M Wang Fast Software Encryption, 29-48, 2012 | 103 | 2012 |

Integral and multidimensional linear distinguishers with correlation zero A Bogdanov, G Leander, K Nyberg, M Wang Advances in Cryptology–ASIACRYPT 2012, 244-261, 2012 | 99 | 2012 |

Fides: Lightweight Authenticated Cipher with Side-Channel Resistance for Constrained Hardware B Bilgin, A Bogdanov, M Knežević, F Mendel, Q Wang Cryptographic Hardware and Embedded Systems-CHES 2013, 142-158, 2013 | 95 | 2013 |

Improved side-channel collision attacks on AES A Bogdanov Selected Areas in Cryptography, 84-95, 2007 | 93 | 2007 |

How to securely release unverified plaintext in authenticated encryption E Andreeva, A Bogdanov, A Luykx, B Mennink, N Mouha, K Yasuda Advances in Cryptology–ASIACRYPT 2014, 105-125, 2014 | 91 | 2014 |

Key-Alternating ciphers in a provable setting: encryption using a small number of public permutations A Bogdanov, LR Knudsen, G Leander, FX Standaert, J Steinberger, ... Advances in Cryptology–EUROCRYPT 2012, 45-62, 2012 | 90 | 2012 |

Multiple-differential side-channel collision attacks on AES A Bogdanov Cryptographic Hardware and Embedded Systems–CHES 2008, 30-44, 2008 | 82 | 2008 |

Time-Area Optimized Public-Key Engines:\ mathcal {MQ}-Cryptosystems as Replacement for Elliptic Curves? A Bogdanov, T Eisenbarth, A Rupp, C Wolf Cryptographic Hardware and Embedded Systems–CHES 2008, 45-61, 2008 | 78 | 2008 |

Spongent: The design space of lightweight cryptographic hashing A Bogdanov, M Knezevic, G Leander, D Toz, K Varici, I Verbauwhede Computers, IEEE Transactions on 62 (10), 2041-2053, 2013 | 77 | 2013 |

Zero-correlation linear cryptanalysis with FFT and improved attacks on ISO standards Camellia and CLEFIA A Bogdanov, H Geng, M Wang, L Wen, B Collard Selected Areas in Cryptography--SAC 2013, 306-323, 2014 | 70 | 2014 |