VLDB 2026 Research / reviewers in the wild / expert
Hailun Yan
dblp:195/7186
· DBLP profile ↗
16ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0002-0592-6772ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: The Cryptanalysis of SHA-3 Standard
Hailun Yan, Anze Sun |
ACISP (3) | 1 |
| 2026 | Link Between the Differential Cryptanalysis and Linear Approximations over Finite Abelian Groups And Its ApplicationsabstractAbstract In recent years, progress in practical applications of multi-party computation (MPC), fully homomorphic encryption (FHE), and zero-knowledge proofs (ZKP) motivates people to explore symmetric-key cryptographic algorithms, as well as corresponding cryptanalysis techniques (such as differential cryptanalysis, linear cryptanalysis), over finite Abelian groups or prime fields $${\mathbb {F}}_p$$ F p for large p . In this paper, we establish the links between linear cryptanalysis and differential cryptanalysis over general finite Abelian groups. As the first application, we revisit linear cryptanalysis and give general results of linear approximations over arbitrary finite Abelian groups. More precisely, we consider the linearity , which is the maximal non-trivial linear approximation, to characterize the resistance of a function against linear cryptanalysis. This thereby generalizes the work of Pott in 2004 and completes the generalization of Sidelnikov–Chabaud–Vaudenay’s bound from $${\mathbb {F}}_2^n$$ F 2 n to finite Abelian groups. As the second application, we give an exact expression for the correlation of differential-linear approximations over arbitrary finite Abelian groups ( $${\mathbb {F}}_p^n$$ F p n ) under the sole assumption that the two parts of the cipher are independent of each other. In particular, we completely generalize the differential-linear cryptanalysis from $${\mathbb {F}}_2^n$$ F 2 n to arbitrary finite Abelian groups ( $${\mathbb {F}}_p^n$$ F p n ). Zhongfeng Niu, Siwei Sun, Hailun Yan, Qi Wang 0012 |
J. Cryptol. | 3 |
| 2025 | Cryptanalysis of Fruit-F: Exploiting Key-Derivation Weaknesses and Initialization Vulnerabilities
Subhadeep Banik, Hailun Yan |
ACISP (1) | 2 |
| 2024 | A Security-Enhanced Conditional Privacy-Preserving Certificateless Aggregate Signature Scheme for Vehicular Ad-Hoc NetworksabstractVehicular ad-hoc networks (VANETs) can help facilitate traffic flow, reduce accidents, and enhance the driving experience. However, VANETs have some problems in terms of the authenticity and integrity of transmitted information and the preservation of vehicles’ privacy. Many certificateless aggregate signature (CLAS) schemes have been proposed to address these concerns. Nevertheless, most of these schemes suffer from security and efficiency challenges, such as the inability to resist forgery attacks and high computation costs. Recently, an efficient CLAS scheme with conditional privacy protection has been put forward by Chen et al. However, there is a security flaw in this scheme. In this paper, we give a specific attack algorithm to indicate that Chen et al.’s proposal cannot resist a public key replacement attack initiated by external adversaries and then put forward a security-enhanced scheme. Furthermore, an efficient invalid signature identification algorithm is designed to identify invalid signatures after an aggregate verification has failed. Through rigorous security analysis, it has been verified that the scheme put forward can satisfy the fundamental security requirements of VANETs. Compared with other related schemes, our proposal improves efficiency while providing privacy and security guarantees for VANETs. Liangliang Wang 0001, Yiyuan Luo, Yu Long 0001, Kai Zhang 0016, Hailun Yan, Kefei Chen |
IEEE Internet Things J. | 6 |
| 2023 | Meet-in-the-Middle Preimage Attacks on Sponge-Based Hashing
Lingyue Qin, Jialiang Hua, Xiaoyang Dong 0001, Hailun Yan, Xiaoyun Wang 0001 |
EUROCRYPT (4) | 4 |
| 2023 | Optimal Symmetric Ratcheting for Secure CommunicationabstractAbstract To mitigate state exposure threats to long-lived instant messaging sessions, ratcheting was introduced, which is used in practice in protocols like Signal. However, existing ratcheting protocols generally come with a high cost. Recently, Caforio et al. proposed pragmatic constructions, which compose a weakly secure ‘light’ protocol and a strongly secure ‘heavy’ protocol, in order to achieve so-called ratcheting on-demand. The light protocol they proposed has still a high complexity. In this paper, we propose the lightest possible protocol we could imagine, which essentially encrypts and then hashes the secret key. We prove it secure in the standard model by introducing a new security notion, which relates symmetric encryption with key updates by hashing. Our protocol composes well with the generic transformation techniques by Caforio et al. to offer high security and performance at the same time. In a second step, we propose another protocol based on a newly defined integrated primitive, extending standard one-time authenticated encryption with an additional output block used as a secret key for the next message. We instantiate this primitive firstly from any authenticated encryption with associated data, and then we propose an efficient instantiation using advanced encryption standard (AES) encryption to update the key and AES-Galois/Counter mode of operation to encrypt and decrypt messages. Hailun Yan, Serge Vaudenay, Daniel Collins 0001, Andrea Caforio |
Comput. J. | 1 |
| 2023 | New cryptanalysis of LowMC with algebraic techniquesabstractAbstract LowMC is a family of block ciphers proposed by Albrecht et al. at EUROCRYPT 2015, which is tailored specifically for FHE and MPC applications. At ToSC 2018, a difference enumeration attack was given for the cryptanalysis of low-data instances of full LowMCv2 with few applied S-boxes per round. Recently at CRYPTO 2021, an efficient algebraic technique was proposed to attack 4-round LowMC adopting a full S-box layer. Following these works, we present a new difference enumeration attack framework, which is based on our new observations on the LowMC S-box, to analyze LowMC instances with a full S-box layer. As a result, with only 3 chosen plaintexts, we can attack 4-round LowMC instances which adopt a full S-box layer with block size of 129, 192, and 255 bits, respectively. We show that all these attacks have either a lower time complexity or a higher success probability than those reported in the CRYPTO paper. Wenxiao Qiao, Hailun Yan, Siwei Sun, Lei Hu 0003, Jiwu Jing |
Des. Codes Cryptogr. | 2 |
| 2022 | BERT-Enhanced with Context-Aware Embedding for Instance Segmentation in 3D Point CloudsabstractInspired by the successful implementation of transformer network in the Natural Language Processing (NLP), we propose a novel Bidirectional Encoder Representations from Transformers (BERT)-based point cloud segmentation method. Specifically, the whole point cloud is scanned by multiple overlapping windows. We made the first attempt ever to input each window-point-cloud into the BERT model which outputs points' semantic labels and high-dimensional context-aware point embeddings. In the process of training, the Kullback-Leibler (KL)-Divergence-based clustering loss is utilized to optimize the network's parameters by calculating similarity matrices between the point embeddings and the predicted semantic labels. The final instance labels can be obtained by softmax function on these optimized point embeddings. By evaluating on the Stanford 3D Indoor Scene (S3DIS) dataset, our proposed method has reached a micro-mean accuracy (mAcc) of 87.3% on the semantic segmentation task and an Average Precision (mAP) on the instance segmentation task. The results on both tasks have surpassed the traditional point cloud segmentation models. Hailun Yan, Ruisheng Wang 0001 |
IGARSS | 2 |
| 2021 | New Attacks on LowMC Instances with a Single Plaintext/Ciphertext Pair
Subhadeep Banik, Khashayar Barooti, Serge Vaudenay, Hailun Yan |
ASIACRYPT (1) | 4 |
| 2021 | Secure key-alternating Feistel ciphers without key schedule
Yaobin Shen, Hailun Yan, Lei Wang 0031, Xuejia Lai |
Sci. China Inf. Sci. | 2 |
| 2020 | Tweaking Key-Alternating Feistel Block Ciphers
Hailun Yan, Lei Wang 0031, Yaobin Shen, Xuejia Lai |
ACNS (1) | 1 |
| 2019 | New observation on the key schedule of RECTANGLE
Hailun Yan, Yiyuan Luo, Xuejia Lai |
Sci. China Inf. Sci. | 1 |
| 2019 | New zero-sum distinguishers on full 24-round Keccak-f using the division propertyabstractThe authors analyse the security of K eccak (the winner in SHA‐3 competition) by focusing on the zero‐sum distinguishers of its underlying permutation (named K eccak ‐ f ). The authors’ analyses are developed by using the division property, a generalised integral property that was initially used in the integral cryptanalysis of symmetric‐key algorithms. Following the work pioneered by Todo at CRYPTO 2015, they first formalise and prove a more delicate propagation rule of the division property under the assumption that the S‐box's specification is known to attackers. Then, they apply this rule to the inverse S‐box in K eccak ‐ f with a further study on properties of its algebraic degree. They find that the rate of decline in the division property is gentler than that of a randomly chosen S‐box. Meanwhile, they get the same results for the S‐box in A scon permutation. Thanks to this vulnerable property, they can improve the higher‐order differential characteristics against the inverse of K eccak ‐ f in terms of the required number of chosen plaintexts. As an application, they give new zero‐sum distinguishers on full 24‐round K eccak ‐ f of size . To the authors’ knowledge, this is currently the best zero‐sum distinguishers of full‐round K eccak ‐ f permutation. Incidentally, they give the corresponding results for 12‐round A scon permutation. Hailun Yan, Xuejia Lai, Lei Wang 0031, Yu Yu 0001, Yiran Xing |
IET Inf. Secur. | 1 |
| 2018 | Length-Preserving Encryption Based on Single-Key Tweakable Block Cipher
Yaobin Shen, Hailun Yan, Ying Zou 0008, Zheyi Wu, Lei Wang 0031 |
ProvSec | 3 |
| 2018 | Security Evaluation and Improvement of a White-Box SMS4 Implementation Based on Affine Equivalence AlgorithmabstractThe purpose of white-box implementation of a cipher is to protect the secret key of the cipher against a white-box attack, where the white-box adversary has full control over the execution environment and total visibility of internal details of the implementation. In 2015, Shi et al. proposed a lightweight white-box SMS4 implementation and claimed that the implementation is secure against known white-box attacks and known side-channel attacks. Based on the affine equivalence algorithm proposed by Biryukov et al., this paper presents an adjusted version of the affine equivalence algorithm and uses it as an attack against the white-box symmetric encryption algorithm proposed by Shi et al. With our attack, one byte of a round key of SMS4 can be recovered with worst time complexity of O(249) and the full cipher key of SMS4 can be recovered with time complexity of O(253). Moreover, we present a simple way to improve the white-box SMS4 implementation, which will make the time complexity of recovering one byte key increase to O(292). Hailun Yan, Xuejia Lai, Yixin Zhong, Yin Jia |
Comput. J. | 2 |
| 2016 | Transposition of AES Key Schedule
Jialin Huang, Hailun Yan, Xuejia Lai |
Inscrypt | 2 |