VLDB 2026 Research / reviewers in the wild / expert
Qingju Wang 0001
dblp:28/11235-1
· DBLP profile ↗
33ranked-venue papers
4as first author
13since 2021 · last 2025
0000-0003-4565-8394ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 3 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Persistence of Hourglass(-like) Structure: Improved Differential-Linear Distinguishers for Several ARX Ciphers
Xinxin Gong, Qingju Wang 0001, Yonglin Hao, Lin Jiao, Xichao Hu |
ASIACRYPT (1) | 2 |
| 2025 | General Key Recovery Attack on Pointwise-Keyed Functions - Application to Alternating Moduli Weak PRFs
Antoine Sidem, Qingju Wang 0001 |
ASIACRYPT (1) | 2 |
| 2024 | Minimize the Randomness in Rasta-Like Designs: How Far Can We Go? - Application to Pasta
Lorenzo Grassi 0001, Fukang Liu, Christian Rechberger, Fabian Schmid, Roman Walch, Qingju Wang 0001 |
SAC (2) | 6 |
| 2024 | Combining MILP modeling with algebraic bias evaluation for linear mask search: improved fast correlation attacks on SNOW
Xinxin Gong, Yonglin Hao, Qingju Wang 0001 |
Des. Codes Cryptogr. | 3 |
| 2024 | Superposition Attacks on Pseudorandom Schemes Based on Two or Less PermutationsabstractWe study quantum superposition attacks against permutation‐based pseudorandom cryptographic schemes. We first extend Kuwakado and Morii’s attack against the Even–Mansour cipher and exhibit key recovery attacks against a large class of pseudorandom schemes based on a single call to an n ‐bit permutation, with polynomial O ( n ) (or O ( n 2 ), if the concrete cost of Hadamard transform is also taken in) quantum steps. We then consider schemes, namely, two permutation‐based pseudorandom cryptographic schemes. Using the improved Grover‐meet‐Simon method, we show that the keys of a wide class of schemes can be recovered with O ( n ) superposition queries (the complexity of the original is O ( n 2 n /2 )) and O ( n 2 n /2 ) quantum steps. We also exhibit subclasses of “degenerated” schemes that lack certain internal operations and exhibit more efficient key recovery attacks using either the Simon’s algorithm or collision searching algorithm. Further, using the all‐subkeys‐recovery idea of Isobe and Shibutani, our results give rise to key recovery attacks against several recently proposed permutation‐based PRFs, as well as the two‐round Even–Mansour ciphers with generic key schedule functions and their tweakable variants. From a constructive perspective, our results establish new quantum Q2 security upper bounds for two permutation‐based pseudorandom schemes as well as sound design choices. Chun Guo 0002, Qingju Wang 0001 |
IET Inf. Secur. | 3 |
| 2023 | Algebraic Attacks on Round-Reduced Rain and Full AIM-III
Kaiyi Zhang 0001, Qingju Wang 0001, Yu Yu 0001, Chun Guo 0002, Hongrui Cui |
ASIACRYPT (3) | 2 |
| 2023 | Key Filtering in Cube Attacks from the Implementation Aspect
Yonglin Hao, Qingju Wang 0001, Xinxin Gong, Lin Jiao |
CANS | 3 |
| 2023 | Cryptanalysis of Symmetric Primitives over Rings and a Key Recovery Attack on Rubato
Lorenzo Grassi 0001, Irati Manterola Ayala, Martha Norberg Hovd, Morten Øygarden, Håvard Raddum, Qingju Wang 0001 |
CRYPTO (3) | 6 |
| 2023 | Horst Meets Fluid-SPN: Griffin for Zero-Knowledge Applications
Lorenzo Grassi 0001, Yonglin Hao, Christian Rechberger, Markus Schofnegger, Roman Walch, Qingju Wang 0001 |
CRYPTO (3) | 6 |
| 2022 | Integral Attacks on Pyjamask-96 and Round-Reduced Pyjamask-128
Jiamin Cui, Kai Hu 0001, Qingju Wang 0001, Meiqin Wang 0001 |
CT-RSA | 3 |
| 2021 | Massive Superpoly Recovery with Nested Monomial Predictions
Kai Hu 0001, Siwei Sun, Yosuke Todo, Meiqin Wang 0001, Qingju Wang 0001 |
ASIACRYPT (1) | 5 |
| 2021 | Related-Tweak Impossible Differential Cryptanalysis of Reduced-Round TweAES
Muzhou Li, Qingju Wang 0001, Siu-Ming Yiu |
SAC | 4 |
| 2021 | Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
J. Cryptol. | 5 |
| 2020 | An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC
Maria Eichlseder, Lorenzo Grassi 0001, Reinhard Lüftenegger, Morten Øygarden, Christian Rechberger, Markus Schofnegger, Qingju Wang 0001 |
ASIACRYPT (1) | 7 |
| 2020 | An Algebraic Formulation of the Division Property: Revisiting Degree Evaluations, Cube Attacks, and Key-Independent Sums
Kai Hu 0001, Siwei Sun, Meiqin Wang 0001, Qingju Wang 0001 |
ASIACRYPT (1) | 4 |
| 2020 | Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001 |
CRYPTO (3) | 8 |
| 2020 | Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
EUROCRYPT (1) | 5 |
| 2020 | New insights on linear cryptanalysis
Zhiqiang Liu 0001, Shuai Han 0001, Qingju Wang 0001, Wei Li 0013, Ya Liu 0001, Dawu Gu |
Sci. China Inf. Sci. | 3 |
| 2019 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of SuperpolyabstractAt CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively. Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
IEEE Trans. Computers | 7 |
| 2018 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier |
CRYPTO (1) | 1 |
| 2018 | Zero-Sum Partitions of PHOTON Permutations
Qingju Wang 0001, Lorenzo Grassi 0001, Christian Rechberger |
CT-RSA | 1 |
| 2018 | Impossible meet-in-the-middle fault analysis on the LED lightweight cipher in VANETs
Wei Li 0013, Vincent Rijmen, Qingju Wang 0001, Hua Chen 0011, Yunwen Liu, Chaoyun Li, Ya Liu 0001 |
Sci. China Inf. Sci. | 4 |
| 2018 | Improved meet-in-the-middle attacks on reduced-round Piccolo
Ya Liu 0001, Zhiqiang Liu 0001, Wei Li 0013, Qingju Wang 0001, Dawu Gu |
Sci. China Inf. Sci. | 5 |
| 2016 | Automatic Search of Linear Trails in ARX with Applications to SPECK and Chaskey
Yunwen Liu, Qingju Wang 0001, Vincent Rijmen |
ACNS | 2 |
| 2016 | Improved zero-correlation linear cryptanalysis of reduced-round Camellia under weak keysabstractCamellia is one of the widely used block ciphers, which has been included in the NESSIE block cipher portfolio and selected as a standard by ISO/IEC. In this study, the authors observe that there exist some interesting properties of the FL / FL −1 functions in Camellia. With this observation they derive some weak keys for the cipher, based on which they present the first known 8‐round zero‐correlation linear distinguisher of Camellia with FL / FL −1 layers. This result shows that the FL / FL −1 layers inserted in Camellia cannot resist zero‐correlation linear cryptanalysis effectively for some weak keys since the currently best zero‐correlation linear distinguisher for Camellia without FL / FL −1 layers also covers eight rounds. Moreover, by using the novel distinguisher, they launch key recovery attacks on 13‐round Camellia‐192 and 14‐round Camellia‐256. To their knowledge, these results are the best for Camellia‐192 and Camellia‐256 with FL / FL −1 and whitening layers. Zhiqiang Liu 0001, Bing Sun 0001, Qingju Wang 0001, Kerem Varici, Dawu Gu |
IET Inf. Secur. | 3 |
| 2016 | Improved impossible differential attack on reduced version of Camellia with FL/FL -1 functionsabstractAs an ISO/IEC international standard, Camellia has been used in various cryptographic applications. In this study, the authors present the best currently known attacks on Camellia‐192/256 with key‐dependent layers FL / FL −1 (without the whitening layers) by taking advantage of the intrinsic weakness of keyed functions, the redundancy of key schedule and the early abort technique. Specifically, the authors mount the first impossible differential attack on 13‐round Camellia‐192 with 2 124.79 chosen plaintexts, 2 186.09 13‐round encryptions and 2 129.79 bytes, while the analysis for the biggest number of rounds in previous results on Camellia‐192 worked on 12 rounds. Furthermore, the authors successfully attack on 14‐round Camellia‐256 with 2 122.14 chosen plaintexts, 2 228.33 14‐round encryptions and 2 134.14 bytes. Compared with the previously best known attack on 14‐round Camellia‐256, the time and memory complexities are reduced by 2 9.87 times and 2 46.06 times, and the data complexity is comparable. Ya Liu 0001, Anren Yang, Zhiqiang Liu 0001, Wei Li 0013, Qingju Wang 0001, Dawu Gu |
IET Inf. Secur. | 5 |
| 2015 | Optimized Interpolation Attacks on LowMC
Itai Dinur, Yunwen Liu, Willi Meier, Qingju Wang 0001 |
ASIACRYPT (2) | 4 |
| 2015 | Links Among Impossible Differential, Integral and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Zhiqiang Liu 0001, Vincent Rijmen, Ruilin Li 0002, Qingju Wang 0001, Hoda Alkhzaimi, Chao Li 0002 |
CRYPTO (1) | 6 |
| 2015 | Related-key rectangle cryptanalysis of Rijndael-160 and Rijndael-192abstractIn this study, the authors present the first related‐key rectangle cryptanalysis of Rijndael‐160/160 and Rijndael‐192/192. The author's attack on Rijndael‐160/160 covers eight rounds. The attack complexities are 2 126.5 chosen plaintexts, 2 129.28 8‐round Rijndael‐160/160 encryptions and 2 132.82 bytes. Their attack on Rijndael‐192/192 covers ten rounds. It requires 2 179 chosen plaintexts, 2 181.09 10‐round Rijndael‐192/192 encryptions and 2 185.59 bytes memory. These are the currently best cryptanalytic results on Rijndael‐160/160 and Rijndael‐192/192 in terms of the number of attacked rounds. Furthermore, their results show that the slow diffusion in the key schedule of Rijndael makes it a target for this type of analysis. Qingju Wang 0001, Zhiqiang Liu 0001, Deniz Toz, Kerem Varici, Dawu Gu |
IET Inf. Secur. | 1 |
| 2015 | Meet-in-the-middle fault analysis on word-oriented substitution-permutation network block ciphersabstract© 2014 John Wiley & Sons, Ltd. Meet-in-the-Middle (MitM) fault analysis is a kind of powerful cryptanalytic approach suitable for various block ciphers. When applying the method to analyze the security of block ciphers, it is very crucial to find effective MitM characteristics based on some fault models. In this paper, we investigate the security of word-oriented substitution-permutation network (SPN) block ciphers by means of MitM fault analysis and observe that if the diffusion layers of the ciphers have some special properties, it is easy to derive effective MitM characteristics under the condition of single-word fault model, which can lead to efficient fault attacks on the ciphers. In order to demonstrate the effectiveness of our observation, we apply it to ARIA and AES and obtain some effective MitM characteristics, respectively; then, we present efficient MitM fault attacks on the ciphers in terms of these characteristics. It is expected that our work could be helpful in evaluating the security of word-oriented SPN block ciphers against fault attack. We also hope that this work could be beneficial to the design strategy of diffusion layers of block ciphers. Zhiqiang Liu 0001, Ya Liu 0001, Qingju Wang 0001, Dawu Gu, Wei Li 0013 |
Secur. Commun. Networks | 3 |
| 2013 | Fides: Lightweight Authenticated Cipher with Side-Channel Resistance for Constrained Hardware
Begül Bilgin, Andrey Bogdanov, Miroslav Knezevic, Florian Mendel, Qingju Wang 0001 |
CHES | 5 |
| 2012 | The provable constructive effect of diffusion switching mechanism in CLEFIA-type block ciphers
Qingju Wang 0001, Andrey Bogdanov |
Inf. Process. Lett. | 1 |
| 2011 | Differential and Linear Cryptanalysis Using Mixed-Integer Linear Programming
Nicky Mouha, Qingju Wang 0001, Dawu Gu, Bart Preneel |
Inscrypt | 2 |