VLDB 2026 Research / reviewers in the wild / expert
Xuejia Lai
dblp:05/4632
· DBLP profile ↗
52ranked-venue papers
6as first author
8since 2021 · last 2024
0000-0001-5917-4783ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Theory of computation · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Real-Time Related-Key Attack on Full-Round Shadow Designed for IoT NodesabstractWith the rapid development of the Internet of Things (IoT), many new lightweight block ciphers are designed in recent years to meet the security demand in IoT devices. Shadow is a lightweight block cipher designed for IoT Nodes (IEEE Internet of Things Journal, 2021). In this article, an efficient attack on full-round Shadow is proposed based on the idea of a related-key differential attack. First, a differential transfer property for AND operation is illustrated. This property demonstrates a link between the difference and the input value. If the difference of the input is not zero, to lead to a zero difference, there are some constraints on the input value. Furthermore, two properties for Shadow family ciphers are identified. According to these properties, some related keys on Shadow will lead to an internal collision for the subkey generator, which will eventually lead to a full-round distinguisher. Finally, with the idea of related-key differential attack, an efficient attack is applied to Shadow. For Shadow-32, with 4 related keys, 8 master key bits can be derived in about 0.044 seconds on average. For Shadow-64, with 4 related keys, 24 master key bits can be derived in about 3.9 hours on average. All our theoretical results are verified by experiments. Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
IEEE Trans. Computers | 2 |
| 2024 | Impossible Differential Cryptanalysis and a Security Evaluation Framework for AND-RX CiphersabstractIn this paper, a security evaluation framework for AND-RX ciphers against impossible differential cryptanalysis is proposed. This framework is constructed based on three different methods towards finding the theoretical upper boundary, theoretical lower boundary, and practical boundary of impossible differential distinguishers (short for ID) respectively. The provable security boundary (upper boundary) can be calculated with two round-function-related matrices through a few matrix multiplications, this calculation is beyond actual input and output differences. For searching longer IDs (lower boundary), an automatic method is proposed. With this method, given the input and output difference, all the possible direct and indirect contradictions are detected. For the practical boundary, a method of approximating all the potential longest IDs with concrete differential trails is introduced. The three boundaries validate the correctness from each other. According to our result, on the one hand, the boundaries derived with well-designed ID-construction methods can already reach the practical boundary for some block ciphers and it is unlikely to be improved based on known construction methods or future unknown construction methods. On the other hand, for those ciphers whose current best result does not reach our boundary, longer IDs can be discovered with this framework. The correctness is validated by a series of applications. For the provable security boundary, four family ciphers-SIMON, Simeck, Friet-PC and SAND are investigated. For SIMON and Simeck, the lengths of current longest IDs have reached their provable security boundaries. For Friet-PC and SAND, there is a gap between the provable security boundary and current best results. With the automatic searching method, some longer IDs on Friet-PC and SAND are discovered. For Friet-PC, 128 11-round IDs are discovered, while the previous best differential distinguisher is 9-round. For SAND64, 256 11-round IDs are proposed. For SAND128, 456 14-round IDs are presented. Both results extend previous longest IDs by one round and all these newly proposed distinguishers reached corresponding provable security boundaries. For Simeck, the length of longest IDs has not been improved. However, more distinguishers of the same length are discovered. For Simeck64, the increased ratio for the quantity can reach 300%. Besides, the practical boundary of SIMON is investigated, the results indicate that for SIMON, the practical boundary is identical with the provable security boundary or the boundary derived with the automatic searching method. Kai Zhang 0026, Senpeng Wang, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Tairong Shi |
IEEE Trans. Inf. Theory | 3 |
| 2023 | A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011 |
Sci. China Inf. Sci. | 2 |
| 2023 | Weak rotational property and its application
Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011 |
Des. Codes Cryptogr. | 2 |
| 2023 | Meet-in-the-middle attack with splice-and-cut technique and a general automatic framework
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
Des. Codes Cryptogr. | 2 |
| 2023 | Selecting Rotation Constants on SIMON-Type CiphersabstractIn 2013, a lightweight block cipher SIMON is proposed by NSA. This paper tries to investigate this design criterion in terms of resisting against impossible differential cryptanalysis. On one hand, starting from all the possible rotation constants, this paper sieves those “bad parameters” step by step, for each step, the regular patterns for those “bad parameters” are deduced. Accordingly, basic rules for selecting rotation constants on SIMON-type ciphers to construct shorter longest impossible differentials are proposed. On the other hand, the authors categorize the optimal parameters proposed in CRYPTO 2015, according to these results, some “good parameters” in terms of differential cryptanalysis may be rather “bad parameters” while considering impossible differential cryptanalysis. Finally, a concrete attack on 26-round SIMON(13,0,10) is proposed, which is a suggested SIMON variant in CRYPTO 2015 against differential cryptanalysis and linear cryptanalysis. The result in this paper indicates that it is very important to choose appropriate rotation constants when designing a new block cipher. Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011 |
J. Database Manag. | 2 |
| 2023 | Rotational-XOR Differential Cryptanalysis and an Automatic Framework for AND-RX CiphersabstractIn this paper, a security evaluation framework for AND-RX ciphers against rotational-XOR differential cryptanalysis is proposed. This framework first models the structure of all the possible rotational-XOR differential (abbreviated to “RXD”) trails and introduces a method to calculate this structure round by round. Based on this approach, an automatic method is proposed for searching RXD trails. In this method, four strategies are proposed to derive better result and improve the efficiency. Unlike previous automations, the time complexity for this framework can be pre-computed, which is bounded by${\mathcal{ O}}\left ({{c\cdot n\cdot R^{2}\cdot C_{n}^{n_{1}}} }\right)$(where$n$is the block size,$n_{1}$is the number of active bits for the starting point of automatic method,$R$is the length of the targeted rounds and$c$is a fixed constant). Under the given strategies and searching subspaces, the derived RXD trails are guaranteed to be optimal. To prove the correctness and efficiency, this framework is applied to all the ten variants for SIMON and three variants for Simeck. When compared with previous RXD trails, the best improvement is up to three rounds. To validate the correctness of the derived rotational-XOR differential trails, a concrete experiment on Simeck32 is conducted and the experimental result complies with the theoretical analysis. As far as we know, for all the variants of Simeck, current longest distinguishers over all the cryptanalytic methods are obtained in this paper. Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
IEEE Trans. Inf. Theory | 2 |
| 2021 | Secure key-alternating Feistel ciphers without key schedule
Yaobin Shen, Hailun Yan, Lei Wang 0031, Xuejia Lai |
Sci. China Inf. Sci. | 4 |
| 2020 | Tweaking Key-Alternating Feistel Block Ciphers
Hailun Yan, Lei Wang 0031, Yaobin Shen, Xuejia Lai |
ACNS (1) | 4 |
| 2019 | Improved Integral Attack on Generalized Feistel Cipher
Xuejia Lai |
Inscrypt | 3 |
| 2019 | New observation on the key schedule of RECTANGLE
Hailun Yan, Yiyuan Luo, Xuejia Lai |
Sci. China Inf. Sci. | 4 |
| 2019 | New zero-sum distinguishers on full 24-round Keccak-f using the division propertyabstractThe authors analyse the security of K eccak (the winner in SHA‐3 competition) by focusing on the zero‐sum distinguishers of its underlying permutation (named K eccak ‐ f ). The authors’ analyses are developed by using the division property, a generalised integral property that was initially used in the integral cryptanalysis of symmetric‐key algorithms. Following the work pioneered by Todo at CRYPTO 2015, they first formalise and prove a more delicate propagation rule of the division property under the assumption that the S‐box's specification is known to attackers. Then, they apply this rule to the inverse S‐box in K eccak ‐ f with a further study on properties of its algebraic degree. They find that the rate of decline in the division property is gentler than that of a randomly chosen S‐box. Meanwhile, they get the same results for the S‐box in A scon permutation. Thanks to this vulnerable property, they can improve the higher‐order differential characteristics against the inverse of K eccak ‐ f in terms of the required number of chosen plaintexts. As an application, they give new zero‐sum distinguishers on full 24‐round K eccak ‐ f of size . To the authors’ knowledge, this is currently the best zero‐sum distinguishers of full‐round K eccak ‐ f permutation. Incidentally, they give the corresponding results for 12‐round A scon permutation. Hailun Yan, Xuejia Lai, Lei Wang 0031, Yu Yu 0001, Yiran Xing |
IET Inf. Secur. | 2 |
| 2018 | Security Evaluation and Improvement of a White-Box SMS4 Implementation Based on Affine Equivalence AlgorithmabstractThe purpose of white-box implementation of a cipher is to protect the secret key of the cipher against a white-box attack, where the white-box adversary has full control over the execution environment and total visibility of internal details of the implementation. In 2015, Shi et al. proposed a lightweight white-box SMS4 implementation and claimed that the implementation is secure against known white-box attacks and known side-channel attacks. Based on the affine equivalence algorithm proposed by Biryukov et al., this paper presents an adjusted version of the affine equivalence algorithm and uses it as an attack against the white-box symmetric encryption algorithm proposed by Shi et al. With our attack, one byte of a round key of SMS4 can be recovered with worst time complexity of O(249) and the full cipher key of SMS4 can be recovered with time complexity of O(253). Moreover, we present a simple way to improve the white-box SMS4 implementation, which will make the time complexity of recovering one byte key increase to O(292). Hailun Yan, Xuejia Lai, Yixin Zhong, Yin Jia |
Comput. J. | 3 |
| 2017 | A new construction on randomized message-locked encryption in the standard model via UCEs
Huige Wang, Kefei Chen, Baodong Qin, Xuejia Lai, Yunhua Wen |
Sci. China Inf. Sci. | 4 |
| 2017 | Generic attacks on the Lai-Massey scheme
Yiyuan Luo, Xuejia Lai |
Des. Codes Cryptogr. | 2 |
| 2017 | A New Feistel-Type White-Box Encryption Scheme
Xuejia Lai, Weijia Xue, Yin Jia |
J. Comput. Sci. Technol. | 2 |
| 2017 | Improvements for Finding Impossible Differentials of Block Cipher StructuresabstractWe improve Wu and Wang’s method for finding impossible differentials of block cipher structures. This improvement is more general than Wu and Wang’s method where it can find more impossible differentials with less time. We apply it on Gen-CAST256, Misty, Gen-Skipjack, Four-Cell, Gen-MARS, SMS4, MIBS, Camellia⁎ , LBlock, E2, and SNAKE block ciphers. All impossible differentials discovered by the algorithm are the same as Wu’s method. Besides, for the 8-round MIBS block cipher, we find 4 new impossible differentials, which are not listed in Wu and Wang’s results. The experiment results show that the improved algorithm can not only find more impossible differentials, but also largely reduce the search time. Yiyuan Luo, Xuejia Lai |
Secur. Commun. Networks | 2 |
| 2016 | Transposition of AES Key Schedule
Jialin Huang, Hailun Yan, Xuejia Lai |
Inscrypt | 3 |
| 2016 | Discussion on the theoretical results of white-box cryptography
Xuejia Lai, Weijia Xue, Geshi Huang |
Sci. China Inf. Sci. | 2 |
| 2016 | On the estimation of the second largest eigenvalue of Markov ciphersabstractAbstract Differential cryptanalysis is an effective tool in modern cryptanalysis. The differential chain of a Markov cipher forms a Markov chain, and the second largest eigenvalue (SLE) of the transition matrix determines the number of iterations such that the Markov cipher can resist differential cryptanalysis. Owing to the huge scale of the transition matrix, it is infeasible to compute the SLE. Thus, an estimation method would be desirable. We find two methods to estimate the SLE by using the elements of the row‐stochastic matrix in the literature. Their advantage is parallel computing, without generating the complete matrix. We apply these two methods to the transition matrix of International Data Encryption Algorithm(8) and investigate the accuracy of such estimation. Because the International Data Encryption Algorithm is a primitive Markov cipher, its transition matrix will converge to a uniform distribution. We use the power of the initial transition matrix to estimate the SLE for different number of rounds and compare the results. The errors of the estimation will be acceptable after several rounds when there are less zero elements in the transition matrix and the distribution is more uniform. Moreover, we present a simple relation between the SLE and the number of iterations that the Markov cipher requires against differential cryptanalysis and show the necessary condition of the matrix decomposition method. Copyright © 2016 John Wiley & Sons, Ltd. Weijia Xue, Xin Shun, Fenglei Xue, Xuejia Lai |
Secur. Commun. Networks | 5 |
| 2015 | Capacity and Data Complexity in Multidimensional Linear Attack
Jialin Huang, Serge Vaudenay, Xuejia Lai, Kaisa Nyberg |
CRYPTO (1) | 3 |
| 2015 | Multidimensional Zero-Correlation Linear Cryptanalysis on 23-Round LBlock-s
Ping Jia, Geshi Huang, Xuejia Lai |
ICICS | 4 |
| 2015 | Survey on cyberspace security
Huanguo Zhang, Wenbao Han, Xuejia Lai, Dongdai Lin, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 3 |
| 2015 | Optimal assignment schemes for general access structures based on linear programming
Qiang Li 0026, Xiangxue Li, Xuejia Lai, Kefei Chen |
Des. Codes Cryptogr. | 3 |
| 2015 | Construction of perfect diffusion layers from linear feedback shift registersabstractMaximum distance separable (MDS) matrices are widely used in the diffusion layers of block ciphers and hash functions. Inspired by Guo, Sajadieh and Wu et al . 's recursive construction of perfect diffusion layers from linear feedback shift registers (LFSRs), the authors further study how to construct perfect diffusion layers from LFSRs of Fibonacci and Galois architectures, and present a systematic analysis of 4 × 4 words diffusion layer constructed with those two structures. Compared with known results, the MDS matrices constructed by us have the advantage that their inverses are usually also MDS matrices, and can be efficiently implemented with the same computational complexity. Yonghui Zheng, Xuejia Lai |
IET Inf. Secur. | 3 |
| 2015 | Impossible differential cryptanalysis of MARS-like structuresabstractThe MARS‐like structure is a generalised Feistel structure. Unified impossible differential (UID) method is an effective method to discover impossible differential characteristics for block cipher structures. In this study, for a specific kind of MARS‐like structure, the authors use UID to show that when n , the number of subblocks, is even, there always exist 3 n − 1 rounds impossible differentials. Moreover, the authors prove that when n is odd, the MARS‐like structure has impossible differentials for any number of rounds, which is a clear but interesting result. Weijia Xue, Xuejia Lai |
IET Inf. Secur. | 2 |
| 2014 | On the Recursive Construction of MDS Matrices for Lightweight Cryptography
Hong Xu 0008, Lin Tan 0003, Xuejia Lai |
ISPEC | 3 |
| 2014 | DNA-chip-based dynamic broadcast encryption scheme with constant-size ciphertexts and decryption keys
Xiwen Fang, Xuejia Lai |
Sci. China Inf. Sci. | 2 |
| 2014 | What is the effective key length for a block cipher: an attack on every practical block cipher
Jialin Huang, Xuejia Lai |
Sci. China Inf. Sci. | 2 |
| 2014 | Revisiting key schedule's diffusion in relation with round function's diffusion
Jialin Huang, Xuejia Lai |
Des. Codes Cryptogr. | 2 |
| 2014 | Distinguishing properties and applications of higher order derivatives of Boolean functions
Ming Duan, Mohan Yang, Xiaorui Sun, Bo Zhu 0007, Xuejia Lai |
Inf. Sci. | 5 |
| 2014 | A unified method for finding impossible differentials of block cipher structures
Yiyuan Luo, Xuejia Lai, Zhongming Wu, Guang Gong |
Inf. Sci. | 2 |
| 2013 | Chosen-plaintext linear attacks on SerpentabstractIn this study, the authors consider chosen‐plaintext variants of the linear attack on reduced round Serpent. By reasonably fixing parts of the plaintexts of 10‐round Serpent the number of texts required in a linear attack with single approximation can be significantly reduced by a factor of 2 22 . The authors also give the best data complexity on 10‐round Serpent so far, which is 2 80 . Moreover, the authors extend the chosen‐plaintext technique to the linear attack using multiple approximations and improve the results of cryptanalysis in data complexity or/and time complexity in different scenarios. As an application to show the usefulness of this technique, an experiment in the multidimensional linear model on 5‐round Serpent is given. Jialin Huang, Xuejia Lai |
IET Inf. Secur. | 2 |
| 2012 | Improved preimage attack on one-block MD4
Jinmin Zhong, Xuejia Lai |
J. Syst. Softw. | 2 |
| 2010 | A Lightweight Stream Cipher WG-7 for RFID Encryption and AuthenticationabstractThe family of WG stream ciphers has good randomness properties. In this paper, we parameterize WG-7 stream cipher for RFID tags, where the modest computation/storage capabilities and the necessity to keep their prices low present a challenging problem that goes beyond the well-studied cryptography. The rigorous security analysis of WG-7 indicates that it is secure against time/memory/data trade off attack, differential attack, algebraic attack, correlation attack and Discrete Fourier Transform (DFT) attack. Furthermore, we offer efficient implementation of WG-7 on the 4-bit microcontroller ATAM893-D and the 8-bit microcontroller ATmega8 from ATmel. The experimental results show that WG-7 outperforms most of previous proposals in terms of throughput and implementation complexity. Moreover, we propose a mutual authentication protocol based on WG-7, which provides the untraceability, resistance of tag impersonation and reader impersonation. With its verified cryptographic properties, low implementation complexity and ideal throughput, WG-7 is a promising candidate for RFID applications. Yiyuan Luo, Qi Chai, Guang Gong, Xuejia Lai |
GLOBECOM | 4 |
| 2010 | Asymmetric encryption and signature method with DNA technology
Xuejia Lai, MingXin Lu, Junsong Han, Xiwen Fang |
Sci. China Inf. Sci. | 1 |
| 2010 | Pseudorandomness analysis of the (extended) Lai-Massey scheme
Yiyuan Luo, Xuejia Lai |
Inf. Process. Lett. | 2 |
| 2009 | The Key-Dependent Attack on Block Ciphers
Xiaorui Sun, Xuejia Lai |
ASIACRYPT | 2 |
| 2009 | Improved efficiency of Kiltz07-KEM
Xianhui Lu, Xuejia Lai, Dake He |
Inf. Process. Lett. | 2 |
| 2009 | When is a key establishment protocol correct?abstractAbstract This paper presents sufficient and necessary conditions to guarantee the security of a Key Establishment (KE) protocol based on our formalism of the belief multisets. The formalism is used to express the security of a KE protocol and to reason about beliefs in the protocol. We observe that a freshness identifier such as a nonce may not be fresh for a legitimate party in a particular protocol run, hence we distinguish a trusted freshness identifier from the commonly used freshness identifier in the sense of a participant's beliefs about the security. A central ingredient in our approach is that all the beliefs should be established on the basis of a trusted freshness identifier. The reasoning results of our approach, comparing with the security conditions, can either establish the correctness of a KE protocol when the protocol is in fact correct, or identify the absence of the security properties, which leads to the structure to construct attacks directly. Two examples, the Kerberos pair‐key agreement approach in distributed sensor networks and the Needham—Schroeder public key protocol, are given to show the usability and the efficiency of our approach. Copyright © 2009 John Wiley & Sons, Ltd. Ling Dong, Kefei Chen, Xuejia Lai, Mi Wen |
Secur. Commun. Networks | 3 |
| 2008 | A synthetic indifferentiability analysis of some block-cipher-based hash functions
Xuejia Lai, Kefei Chen |
Des. Codes Cryptogr. | 2 |
| 2007 | Symmetric-key cryptosystem with DNA technology
MingXin Lu, Xuejia Lai, Guozhen Xiao |
Sci. China Ser. F Inf. Sci. | 2 |
| 2007 | Improved Collision Attack on Hash Function MD5
Xuejia Lai |
J. Comput. Sci. Technol. | 2 |
| 2005 | Cryptanalysis of the Hash Functions MD4 and RIPEMD
Xiaoyun Wang 0001, Xuejia Lai, Dengguo Feng, Xiuyuan Yu |
EUROCRYPT | 2 |
| 2000 | Public Key Infrastructure: Managing the e-Business Security
Xuejia Lai |
SEC | 1 |
| 1998 | Attacks on Fast Double Block Length Hash Functions
Lars R. Knudsen, Xuejia Lai, Bart Preneel |
J. Cryptol. | 2 |
| 1996 | Attacks on the HKM/HFX Cryptosystem
Xuejia Lai, Rainer A. Rueppel |
FSE | 1 |
| 1994 | Additive and Linear Structures of Cryptographic Functions
Xuejia Lai |
FSE | 1 |
| 1993 | Security of Iterated Hash Functions Based on Block Ciphers
Walter Hohl, Xuejia Lai, Thomas Meier 0001, Christian Waldvogel |
CRYPTO | 2 |
| 1993 | Attacks on Double Block Length Hash Functions
Xuejia Lai, Lars R. Knudsen |
FSE | 1 |
| 1991 | VLSI Implementation of a New Block CipherabstractThe high speed architecture for a VLSI implementation of a new smart-key block cipher is presented. The chip performs data encryption and decryption in a single hardware unit. It runs with a maximum clock frequency of 33 MHz permitting a data conversion rate of more than 55 Mb/s. This high data rate, compared to currently available DES (data encryption standard) implementations, has been achieved by implementing a pipelined architecture and by using a sophisticated data scheduling scheme guaranteeing a continuously fully loaded pipeline.> Heinz Bonnenberg, Andreas Curiger, Norbert Felber, Hubert Kaeslin, Xuejia Lai |
ICCD | 5 |
| 1987 | Condition for the nonsingularity of a feedback shift-register over a general finite fieldabstractThe necessary and sufficient condition for a feedback shift-register over a general finite field to be nonsingular is established. The general condition is contrasted to the well-known necessary and sufficient condition for nonsingularity of a binary feedback shift-register. Xuejia Lai |
IEEE Trans. Inf. Theory | 1 |