VLDB 2026 Research / reviewers in the wild / expert
Zhenzhen Bao
dblp:142/1663
· DBLP profile ↗
20ranked-venue papers
12as first author
9since 2021 · last 2026
0000-0003-2839-6687ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 12 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Geometric Approach to Quantum Distinguishers
Zhi-Li Wu, Zhenzhen Bao |
CRYPTO (5) | 2 |
| 2024 | Automatic Quantum Multi-collision Distinguishers and Rebound Attacks with Triangulation Algorithm
Zhenzhen Bao, Jian Guo 0001, Shun Li 0004, Phuong Pham |
ACISP (2) | 1 |
| 2023 | More Insight on Deep Learning-Aided Cryptanalysis
Zhenzhen Bao, Jinyu Lu, Yiran Yao |
ASIACRYPT (3) | 1 |
| 2023 | Differential-Linear Approximation Semi-unconstrained Searching and Partition Tree: Application to LEA and Speck
Yi Chen 0011, Zhenzhen Bao |
ASIACRYPT (3) | 2 |
| 2023 | XOCB: Beyond-Birthday-Bound Secure Authenticated Encryption Mode with Rate-One Computation
Zhenzhen Bao, Seongha Hwang, Akiko Inoue, ByeongHak Lee, Jooyoung Lee 0001, Kazuhiko Minematsu |
EUROCRYPT (4) | 1 |
| 2022 | Enhancing Differential-Neural Cryptanalysis
Zhenzhen Bao, Jian Guo 0001, Meicheng Liu |
ASIACRYPT (1) | 1 |
| 2022 | Superposition Meet-in-the-Middle Attacks: Updates on Fundamental Security of AES-like Hashing
Zhenzhen Bao, Jian Guo 0001, Danping Shi |
CRYPTO (1) | 1 |
| 2022 | Evaluating the Security of Merkle-Damgård Hash Functions and Combiners in Quantum Settings
Zhenzhen Bao, Jian Guo 0001, Shun Li 0004, Phuong Pham |
NSS | 1 |
| 2021 | Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like Hashing
Zhenzhen Bao, Xiaoyang Dong 0001, Jian Guo 0001, Zheng Li 0008, Danping Shi, Siwei Sun, Xiaoyun Wang 0001 |
EUROCRYPT (1) | 1 |
| 2020 | TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo 0002, Jian Guo 0001, Ling Song 0001 |
EUROCRYPT (2) | 1 |
| 2020 | WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri |
SAC | 2 |
| 2020 | Generic Attacks on Hash CombinersabstractHash combiners are a practical way to make cryptographic hash functions more tolerant to future attacks and compatible with existing infrastructure. A combiner combines two or more hash functions in a way that is hopefully more secure than each of the underlying hash functions, or at least remains secure as long as one of them is secure. Two classical hash combiners are the exclusive-or (XOR) combiner \( \mathcal {H}_1(M) \oplus \mathcal {H}_2(M) \) and the concatenation combiner \( \mathcal {H}_1(M) \Vert \mathcal {H}_2(M) \) . Both of them process the same message using the two underlying hash functions in parallel. Apart from parallel combiners, there are also cascade constructions sequentially calling the underlying hash functions to process the message repeatedly, such as Hash-Twice \(\mathcal {H}_2(\mathcal {H}_1(IV, M), M)\) and the Zipper hash \(\mathcal {H}_2(\mathcal {H}_1(IV, M), \overleftarrow{M})\) , where \(\overleftarrow{M}\) is the reverse of the message M . In this work, we study the security of these hash combiners by devising the best-known generic attacks. The results show that the security of most of the combiners is not as high as commonly believed. We summarize our attacks and their computational complexities (ignoring the polynomial factors) as follows: Several generic preimage attacks on the XOR combiner: A first attack with a best-case complexity of \( 2^{5n/6} \) obtained for messages of length \( 2^{n/3} \) . It relies on a novel technical tool named interchange structure. It is applicable for combiners whose underlying hash functions follow the Merkle–Damgård construction or the HAIFA framework. A second attack with a best-case complexity of \( 2^{2n/3} \) obtained for messages of length \( 2^{n/2} \) . It exploits properties of functional graphs of random mappings. It achieves a significant improvement over the first attack but is only applicable when the underlying hash functions use the Merkle–Damgård construction. An improvement upon the second attack with a best-case complexity of \( 2^{5n/8} \) obtained for messages of length \( 2^{5n/8} \) . It further exploits properties of functional graphs of random mappings and uses longer messages. These attacks show a rather surprising result: regarding preimage resistance, the sum of two n -bit narrow-pipe hash functions following the considered constructions can never provide n -bit security. A generic second-preimage attack on the concatenation combiner of two Merkle–Damgård hash functions. This attack finds second preimages faster than \( 2^n \) for challenges longer than \( 2^{2n/7} \) and has a best-case complexity of \( 2^{3n/4} \) obtained for challenges of length \( 2^{3n/4} \) . It also exploits properties of functional graphs of random mappings. The first generic second-preimage attack on the Zipper hash with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{3n/5} \) , obtained for challenge messages of length \( 2^{2n/5} \) . An improved generic second-preimage attack on Hash-Twice with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{13n/22} \) , obtained for challenge messages of length \( 2^{13n/22} \) . The last three attacks show that regarding second-preimage resistance, the concatenation and cascade of two n -bit narrow-pipe Merkle–Damgård hash functions do not provide much more security than that can be provided by a single n -bit hash function. Our main technical contributions include the following: The interchange structure, which enables simultaneously controlling the behaviours of two hash computations sharing the same input. The simultaneous expandable message, which is a set of messages of length covering a whole appropriate range and being multi-collision for both of the underlying hash functions. New ways to exploit the properties of functional graphs of random mappings generated by fixing the message block input to the underlying compression functions. Zhenzhen Bao, Itai Dinur, Jian Guo 0001, Gaëtan Leurent, Lei Wang 0031 |
J. Cryptol. | 1 |
| 2017 | Functional Graph Revisited: Updates on (Second) Preimage Attacks on Hash Combiners
Zhenzhen Bao, Lei Wang 0031, Jian Guo 0001, Dawu Gu |
CRYPTO (2) | 1 |
| 2016 | Applying MILP Method to Searching Integral Distinguishers Based on Division Property for 6 Lightweight Block Ciphers
Zejun Xiang 0001, Zhenzhen Bao, Dongdai Lin |
ASIACRYPT (1) | 3 |
| 2016 | The Linear Complexity and 2-Error Linear Complexity Distribution of 2^n 2 n -Periodic Binary Sequences with Fixed Hamming Weight
Wenlun Pan, Zhenzhen Bao, Dongdai Lin, Feng Liu 0001 |
ICICS | 2 |
| 2016 | The Distribution of 2^n 2 n -Periodic Binary Sequences with Fixed k-Error Linear Complexity
Wenlun Pan, Zhenzhen Bao, Dongdai Lin, Feng Liu 0001 |
ISPEC | 2 |
| 2015 | A New Classification of 4-bit Optimal S-boxes and Its Application to PRESENT, RECTANGLE and SPONGENT
Zhenzhen Bao, Vincent Rijmen, Meicheng Liu |
FSE | 2 |
| 2015 | Bitsliced Implementations of the PRINCE, LED and RECTANGLE Block Ciphers on AVR 8-Bit Microcontrollers
Zhenzhen Bao, Dongdai Lin |
ICICS | 1 |
| 2015 | RECTANGLE: a bit-slice lightweight block cipher suitable for multiple platforms
Zhenzhen Bao, Dongdai Lin, Vincent Rijmen, Bohan Yang 0001, Ingrid Verbauwhede |
Sci. China Inf. Sci. | 2 |
| 2014 | Speeding Up the Search Algorithm for the Best Differential and Best Linear Trails
Zhenzhen Bao, Dongdai Lin |
Inscrypt | 1 |