Xuejia Lai

dblp:05/4632 · DBLP profile ↗
← Back
52ranked-venue papers
6as first author
8since 2021 · last 2024
0000-0001-5917-4783ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Theory of computation · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2024 Real-Time Related-Key Attack on Full-Round Shadow Designed for IoT Nodes
abstract
With the rapid development of the Internet of Things (IoT), many new lightweight block ciphers are designed in recent years to meet the security demand in IoT devices. Shadow is a lightweight block cipher designed for IoT Nodes (IEEE Internet of Things Journal, 2021). In this article, an efficient attack on full-round Shadow is proposed based on the idea of a related-key differential attack. First, a differential transfer property for AND operation is illustrated. This property demonstrates a link between the difference and the input value. If the difference of the input is not zero, to lead to a zero difference, there are some constraints on the input value. Furthermore, two properties for Shadow family ciphers are identified. According to these properties, some related keys on Shadow will lead to an internal collision for the subkey generator, which will eventually lead to a full-round distinguisher. Finally, with the idea of related-key differential attack, an efficient attack is applied to Shadow. For Shadow-32, with 4 related keys, 8 master key bits can be derived in about 0.044 seconds on average. For Shadow-64, with 4 related keys, 24 master key bits can be derived in about 3.9 hours on average. All our theoretical results are verified by experiments.
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
IEEE Trans. Computers2
2024 Impossible Differential Cryptanalysis and a Security Evaluation Framework for AND-RX Ciphers
abstract
In this paper, a security evaluation framework for AND-RX ciphers against impossible differential cryptanalysis is proposed. This framework is constructed based on three different methods towards finding the theoretical upper boundary, theoretical lower boundary, and practical boundary of impossible differential distinguishers (short for ID) respectively. The provable security boundary (upper boundary) can be calculated with two round-function-related matrices through a few matrix multiplications, this calculation is beyond actual input and output differences. For searching longer IDs (lower boundary), an automatic method is proposed. With this method, given the input and output difference, all the possible direct and indirect contradictions are detected. For the practical boundary, a method of approximating all the potential longest IDs with concrete differential trails is introduced. The three boundaries validate the correctness from each other. According to our result, on the one hand, the boundaries derived with well-designed ID-construction methods can already reach the practical boundary for some block ciphers and it is unlikely to be improved based on known construction methods or future unknown construction methods. On the other hand, for those ciphers whose current best result does not reach our boundary, longer IDs can be discovered with this framework. The correctness is validated by a series of applications. For the provable security boundary, four family ciphers-SIMON, Simeck, Friet-PC and SAND are investigated. For SIMON and Simeck, the lengths of current longest IDs have reached their provable security boundaries. For Friet-PC and SAND, there is a gap between the provable security boundary and current best results. With the automatic searching method, some longer IDs on Friet-PC and SAND are discovered. For Friet-PC, 128 11-round IDs are discovered, while the previous best differential distinguisher is 9-round. For SAND64, 256 11-round IDs are proposed. For SAND128, 456 14-round IDs are presented. Both results extend previous longest IDs by one round and all these newly proposed distinguishers reached corresponding provable security boundaries. For Simeck, the length of longest IDs has not been improved. However, more distinguishers of the same length are discovered. For Simeck64, the increased ratio for the quantity can reach 300%. Besides, the practical boundary of SIMON is investigated, the results indicate that for SIMON, the practical boundary is identical with the provable security boundary or the boundary derived with the automatic searching method.
Kai Zhang 0026, Senpeng Wang, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Tairong Shi
IEEE Trans. Inf. Theory3
2023 A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011
Sci. China Inf. Sci.2
2023 Weak rotational property and its application
Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011
Des. Codes Cryptogr.2
2023 Meet-in-the-middle attack with splice-and-cut technique and a general automatic framework
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
Des. Codes Cryptogr.2
2023 Selecting Rotation Constants on SIMON-Type Ciphers
abstract
In 2013, a lightweight block cipher SIMON is proposed by NSA. This paper tries to investigate this design criterion in terms of resisting against impossible differential cryptanalysis. On one hand, starting from all the possible rotation constants, this paper sieves those “bad parameters” step by step, for each step, the regular patterns for those “bad parameters” are deduced. Accordingly, basic rules for selecting rotation constants on SIMON-type ciphers to construct shorter longest impossible differentials are proposed. On the other hand, the authors categorize the optimal parameters proposed in CRYPTO 2015, according to these results, some “good parameters” in terms of differential cryptanalysis may be rather “bad parameters” while considering impossible differential cryptanalysis. Finally, a concrete attack on 26-round SIMON(13,0,10) is proposed, which is a suggested SIMON variant in CRYPTO 2015 against differential cryptanalysis and linear cryptanalysis. The result in this paper indicates that it is very important to choose appropriate rotation constants when designing a new block cipher.
Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011
J. Database Manag.2
2023 Rotational-XOR Differential Cryptanalysis and an Automatic Framework for AND-RX Ciphers
abstract
In this paper, a security evaluation framework for AND-RX ciphers against rotational-XOR differential cryptanalysis is proposed. This framework first models the structure of all the possible rotational-XOR differential (abbreviated to “RXD”) trails and introduces a method to calculate this structure round by round. Based on this approach, an automatic method is proposed for searching RXD trails. In this method, four strategies are proposed to derive better result and improve the efficiency. Unlike previous automations, the time complexity for this framework can be pre-computed, which is bounded by${\mathcal{ O}}\left ({{c\cdot n\cdot R^{2}\cdot C_{n}^{n_{1}}} }\right)$(where$n$is the block size,$n_{1}$is the number of active bits for the starting point of automatic method,$R$is the length of the targeted rounds and$c$is a fixed constant). Under the given strategies and searching subspaces, the derived RXD trails are guaranteed to be optimal. To prove the correctness and efficiency, this framework is applied to all the ten variants for SIMON and three variants for Simeck. When compared with previous RXD trails, the best improvement is up to three rounds. To validate the correctness of the derived rotational-XOR differential trails, a concrete experiment on Simeck32 is conducted and the experimental result complies with the theoretical analysis. As far as we know, for all the variants of Simeck, current longest distinguishers over all the cryptanalytic methods are obtained in this paper.
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
IEEE Trans. Inf. Theory2
2021 Secure key-alternating Feistel ciphers without key schedule
Yaobin Shen, Hailun Yan, Lei Wang 0031, Xuejia Lai
Sci. China Inf. Sci.4
2020 Tweaking Key-Alternating Feistel Block Ciphers
Hailun Yan, Lei Wang 0031, Yaobin Shen, Xuejia Lai
ACNS (1)4
2019 Improved Integral Attack on Generalized Feistel Cipher
Xuejia Lai
Inscrypt3
2019 New observation on the key schedule of RECTANGLE
Hailun Yan, Yiyuan Luo, Xuejia Lai
Sci. China Inf. Sci.4
2019 New zero-sum distinguishers on full 24-round Keccak-f using the division property
abstract
The authors analyse the security of K eccak (the winner in SHA‐3 competition) by focusing on the zero‐sum distinguishers of its underlying permutation (named K eccak ‐ f ). The authors’ analyses are developed by using the division property, a generalised integral property that was initially used in the integral cryptanalysis of symmetric‐key algorithms. Following the work pioneered by Todo at CRYPTO 2015, they first formalise and prove a more delicate propagation rule of the division property under the assumption that the S‐box's specification is known to attackers. Then, they apply this rule to the inverse S‐box in K eccak ‐ f with a further study on properties of its algebraic degree. They find that the rate of decline in the division property is gentler than that of a randomly chosen S‐box. Meanwhile, they get the same results for the S‐box in A scon permutation. Thanks to this vulnerable property, they can improve the higher‐order differential characteristics against the inverse of K eccak ‐ f in terms of the required number of chosen plaintexts. As an application, they give new zero‐sum distinguishers on full 24‐round K eccak ‐ f of size . To the authors’ knowledge, this is currently the best zero‐sum distinguishers of full‐round K eccak ‐ f permutation. Incidentally, they give the corresponding results for 12‐round A scon permutation.
Hailun Yan, Xuejia Lai, Lei Wang 0031, Yu Yu 0001, Yiran Xing
IET Inf. Secur.2
2018 Security Evaluation and Improvement of a White-Box SMS4 Implementation Based on Affine Equivalence Algorithm
abstract
The purpose of white-box implementation of a cipher is to protect the secret key of the cipher against a white-box attack, where the white-box adversary has full control over the execution environment and total visibility of internal details of the implementation. In 2015, Shi et al. proposed a lightweight white-box SMS4 implementation and claimed that the implementation is secure against known white-box attacks and known side-channel attacks. Based on the affine equivalence algorithm proposed by Biryukov et al., this paper presents an adjusted version of the affine equivalence algorithm and uses it as an attack against the white-box symmetric encryption algorithm proposed by Shi et al. With our attack, one byte of a round key of SMS4 can be recovered with worst time complexity of O(249) and the full cipher key of SMS4 can be recovered with time complexity of O(253)⁠. Moreover, we present a simple way to improve the white-box SMS4 implementation, which will make the time complexity of recovering one byte key increase to O(292)⁠.
Hailun Yan, Xuejia Lai, Yixin Zhong, Yin Jia
Comput. J.3
2017 A new construction on randomized message-locked encryption in the standard model via UCEs
Huige Wang, Kefei Chen, Baodong Qin, Xuejia Lai, Yunhua Wen
Sci. China Inf. Sci.4
2017 Generic attacks on the Lai-Massey scheme
Yiyuan Luo, Xuejia Lai
Des. Codes Cryptogr.2
2017 A New Feistel-Type White-Box Encryption Scheme
Xuejia Lai, Weijia Xue, Yin Jia
J. Comput. Sci. Technol.2
2017 Improvements for Finding Impossible Differentials of Block Cipher Structures
abstract
We improve Wu and Wang’s method for finding impossible differentials of block cipher structures. This improvement is more general than Wu and Wang’s method where it can find more impossible differentials with less time. We apply it on Gen-CAST256, Misty, Gen-Skipjack, Four-Cell, Gen-MARS, SMS4, MIBS, Camellia⁎ , LBlock, E2, and SNAKE block ciphers. All impossible differentials discovered by the algorithm are the same as Wu’s method. Besides, for the 8-round MIBS block cipher, we find 4 new impossible differentials, which are not listed in Wu and Wang’s results. The experiment results show that the improved algorithm can not only find more impossible differentials, but also largely reduce the search time.
Yiyuan Luo, Xuejia Lai
Secur. Commun. Networks2
2016 Transposition of AES Key Schedule
Jialin Huang, Hailun Yan, Xuejia Lai
Inscrypt3
2016 Discussion on the theoretical results of white-box cryptography
Xuejia Lai, Weijia Xue, Geshi Huang
Sci. China Inf. Sci.2
2016 On the estimation of the second largest eigenvalue of Markov ciphers
abstract
Abstract Differential cryptanalysis is an effective tool in modern cryptanalysis. The differential chain of a Markov cipher forms a Markov chain, and the second largest eigenvalue (SLE) of the transition matrix determines the number of iterations such that the Markov cipher can resist differential cryptanalysis. Owing to the huge scale of the transition matrix, it is infeasible to compute the SLE. Thus, an estimation method would be desirable. We find two methods to estimate the SLE by using the elements of the row‐stochastic matrix in the literature. Their advantage is parallel computing, without generating the complete matrix. We apply these two methods to the transition matrix of International Data Encryption Algorithm(8) and investigate the accuracy of such estimation. Because the International Data Encryption Algorithm is a primitive Markov cipher, its transition matrix will converge to a uniform distribution. We use the power of the initial transition matrix to estimate the SLE for different number of rounds and compare the results. The errors of the estimation will be acceptable after several rounds when there are less zero elements in the transition matrix and the distribution is more uniform. Moreover, we present a simple relation between the SLE and the number of iterations that the Markov cipher requires against differential cryptanalysis and show the necessary condition of the matrix decomposition method. Copyright © 2016 John Wiley & Sons, Ltd.
Weijia Xue, Xin Shun, Fenglei Xue, Xuejia Lai
Secur. Commun. Networks5
2015 Capacity and Data Complexity in Multidimensional Linear Attack
Jialin Huang, Serge Vaudenay, Xuejia Lai, Kaisa Nyberg
CRYPTO (1)3
2015 Multidimensional Zero-Correlation Linear Cryptanalysis on 23-Round LBlock-s
Ping Jia, Geshi Huang, Xuejia Lai
ICICS4
2015 Survey on cyberspace security
Huanguo Zhang, Wenbao Han, Xuejia Lai, Dongdai Lin, Jianfeng Ma 0001
Sci. China Inf. Sci.3
2015 Optimal assignment schemes for general access structures based on linear programming
Qiang Li 0026, Xiangxue Li, Xuejia Lai, Kefei Chen
Des. Codes Cryptogr.3
2015 Construction of perfect diffusion layers from linear feedback shift registers
abstract
Maximum distance separable (MDS) matrices are widely used in the diffusion layers of block ciphers and hash functions. Inspired by Guo, Sajadieh and Wu et al . 's recursive construction of perfect diffusion layers from linear feedback shift registers (LFSRs), the authors further study how to construct perfect diffusion layers from LFSRs of Fibonacci and Galois architectures, and present a systematic analysis of 4 × 4 words diffusion layer constructed with those two structures. Compared with known results, the MDS matrices constructed by us have the advantage that their inverses are usually also MDS matrices, and can be efficiently implemented with the same computational complexity.
Yonghui Zheng, Xuejia Lai
IET Inf. Secur.3
2015 Impossible differential cryptanalysis of MARS-like structures
abstract
The MARS‐like structure is a generalised Feistel structure. Unified impossible differential (UID) method is an effective method to discover impossible differential characteristics for block cipher structures. In this study, for a specific kind of MARS‐like structure, the authors use UID to show that when n , the number of subblocks, is even, there always exist 3 n − 1 rounds impossible differentials. Moreover, the authors prove that when n is odd, the MARS‐like structure has impossible differentials for any number of rounds, which is a clear but interesting result.
Weijia Xue, Xuejia Lai
IET Inf. Secur.2
2014 On the Recursive Construction of MDS Matrices for Lightweight Cryptography
Hong Xu 0008, Lin Tan 0003, Xuejia Lai
ISPEC3
2014 DNA-chip-based dynamic broadcast encryption scheme with constant-size ciphertexts and decryption keys
Xiwen Fang, Xuejia Lai
Sci. China Inf. Sci.2
2014 What is the effective key length for a block cipher: an attack on every practical block cipher
Jialin Huang, Xuejia Lai
Sci. China Inf. Sci.2
2014 Revisiting key schedule's diffusion in relation with round function's diffusion
Jialin Huang, Xuejia Lai
Des. Codes Cryptogr.2
2014 Distinguishing properties and applications of higher order derivatives of Boolean functions
Ming Duan, Mohan Yang, Xiaorui Sun, Bo Zhu 0007, Xuejia Lai
Inf. Sci.5
2014 A unified method for finding impossible differentials of block cipher structures
Yiyuan Luo, Xuejia Lai, Zhongming Wu, Guang Gong
Inf. Sci.2
2013 Chosen-plaintext linear attacks on Serpent
abstract
In this study, the authors consider chosen‐plaintext variants of the linear attack on reduced round Serpent. By reasonably fixing parts of the plaintexts of 10‐round Serpent the number of texts required in a linear attack with single approximation can be significantly reduced by a factor of 2 22 . The authors also give the best data complexity on 10‐round Serpent so far, which is 2 80 . Moreover, the authors extend the chosen‐plaintext technique to the linear attack using multiple approximations and improve the results of cryptanalysis in data complexity or/and time complexity in different scenarios. As an application to show the usefulness of this technique, an experiment in the multidimensional linear model on 5‐round Serpent is given.
Jialin Huang, Xuejia Lai
IET Inf. Secur.2
2012 Improved preimage attack on one-block MD4
Jinmin Zhong, Xuejia Lai
J. Syst. Softw.2
2010 A Lightweight Stream Cipher WG-7 for RFID Encryption and Authentication
abstract
The family of WG stream ciphers has good randomness properties. In this paper, we parameterize WG-7 stream cipher for RFID tags, where the modest computation/storage capabilities and the necessity to keep their prices low present a challenging problem that goes beyond the well-studied cryptography. The rigorous security analysis of WG-7 indicates that it is secure against time/memory/data trade off attack, differential attack, algebraic attack, correlation attack and Discrete Fourier Transform (DFT) attack. Furthermore, we offer efficient implementation of WG-7 on the 4-bit microcontroller ATAM893-D and the 8-bit microcontroller ATmega8 from ATmel. The experimental results show that WG-7 outperforms most of previous proposals in terms of throughput and implementation complexity. Moreover, we propose a mutual authentication protocol based on WG-7, which provides the untraceability, resistance of tag impersonation and reader impersonation. With its verified cryptographic properties, low implementation complexity and ideal throughput, WG-7 is a promising candidate for RFID applications.
Yiyuan Luo, Qi Chai, Guang Gong, Xuejia Lai
GLOBECOM4
2010 Asymmetric encryption and signature method with DNA technology
Xuejia Lai, MingXin Lu, Junsong Han, Xiwen Fang
Sci. China Inf. Sci.1
2010 Pseudorandomness analysis of the (extended) Lai-Massey scheme
Yiyuan Luo, Xuejia Lai
Inf. Process. Lett.2
2009 The Key-Dependent Attack on Block Ciphers
Xiaorui Sun, Xuejia Lai
ASIACRYPT2
2009 Improved efficiency of Kiltz07-KEM
Xianhui Lu, Xuejia Lai, Dake He
Inf. Process. Lett.2
2009 When is a key establishment protocol correct?
abstract
Abstract This paper presents sufficient and necessary conditions to guarantee the security of a Key Establishment (KE) protocol based on our formalism of the belief multisets. The formalism is used to express the security of a KE protocol and to reason about beliefs in the protocol. We observe that a freshness identifier such as a nonce may not be fresh for a legitimate party in a particular protocol run, hence we distinguish a trusted freshness identifier from the commonly used freshness identifier in the sense of a participant's beliefs about the security. A central ingredient in our approach is that all the beliefs should be established on the basis of a trusted freshness identifier. The reasoning results of our approach, comparing with the security conditions, can either establish the correctness of a KE protocol when the protocol is in fact correct, or identify the absence of the security properties, which leads to the structure to construct attacks directly. Two examples, the Kerberos pair‐key agreement approach in distributed sensor networks and the Needham—Schroeder public key protocol, are given to show the usability and the efficiency of our approach. Copyright © 2009 John Wiley & Sons, Ltd.
Ling Dong, Kefei Chen, Xuejia Lai, Mi Wen
Secur. Commun. Networks3
2008 A synthetic indifferentiability analysis of some block-cipher-based hash functions
Xuejia Lai, Kefei Chen
Des. Codes Cryptogr.2
2007 Symmetric-key cryptosystem with DNA technology
MingXin Lu, Xuejia Lai, Guozhen Xiao
Sci. China Ser. F Inf. Sci.2
2007 Improved Collision Attack on Hash Function MD5
Xuejia Lai
J. Comput. Sci. Technol.2
2005 Cryptanalysis of the Hash Functions MD4 and RIPEMD
Xiaoyun Wang 0001, Xuejia Lai, Dengguo Feng, Xiuyuan Yu
EUROCRYPT2
2000 Public Key Infrastructure: Managing the e-Business Security
Xuejia Lai
SEC1
1998 Attacks on Fast Double Block Length Hash Functions
Lars R. Knudsen, Xuejia Lai, Bart Preneel
J. Cryptol.2
1996 Attacks on the HKM/HFX Cryptosystem
Xuejia Lai, Rainer A. Rueppel
FSE1
1994 Additive and Linear Structures of Cryptographic Functions
Xuejia Lai
FSE1
1993 Security of Iterated Hash Functions Based on Block Ciphers
Walter Hohl, Xuejia Lai, Thomas Meier 0001, Christian Waldvogel
CRYPTO2
1993 Attacks on Double Block Length Hash Functions
Xuejia Lai, Lars R. Knudsen
FSE1
1991 VLSI Implementation of a New Block Cipher
abstract
The high speed architecture for a VLSI implementation of a new smart-key block cipher is presented. The chip performs data encryption and decryption in a single hardware unit. It runs with a maximum clock frequency of 33 MHz permitting a data conversion rate of more than 55 Mb/s. This high data rate, compared to currently available DES (data encryption standard) implementations, has been achieved by implementing a pipelined architecture and by using a sophisticated data scheduling scheme guaranteeing a continuously fully loaded pipeline.>
Heinz Bonnenberg, Andreas Curiger, Norbert Felber, Hubert Kaeslin, Xuejia Lai
ICCD5
1987 Condition for the nonsingularity of a feedback shift-register over a general finite field
abstract
The necessary and sufficient condition for a feedback shift-register over a general finite field to be nonsingular is established. The general condition is contrasted to the well-known necessary and sufficient condition for nonsingularity of a binary feedback shift-register.
Xuejia Lai
IEEE Trans. Inf. Theory1