Bing Sun 0001

dblp:30/5583-1 · DBLP profile ↗
← Back
40ranked-venue papers
9as first author
10since 2021 · last 2025
0000-0002-7403-8795ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 5 first-author · 5 since 2021Theory of computation · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Further Insights on the Cryptanalysis of Lightweight Block Cipher ECLBC
abstract
ECLBC is a family of lightweight block ciphers designed especially for the Internet of Medical Things. The family contains two instances according to their block sizes, which are denoted by ECLBC-32 and ECLBC-64, respectively. ECLBC is based on SPN structure with an involutive nonlinear layer as well as an involutive linear layer. In this paper, we focus on the security of ECLBC against some attacks. Our strategy includes a direct approach and an indirect approach to make cryptanalysis of ECLBC. For differential, linear and integral attacks, we apply the attacks against SIMON to ECLBC by revealing the affine equivalent property between the two ciphers. The feasibility of such an indirect way relies on an important observation on the chosen linear layer of ECLBC, which results in a similar encryption procedure to SIMON. Thus, they have the same security against some cryptanalytic methods. We give a proof of the property in a mathematical manner and some better attacks than previous works by the designers are given. What’s more, to investigate the security of the new key schedules of ECLBC, we directly search for rotational-XOR distinguishers with different key schedules via an SAT-based method. Finally, we conclude a different result from previous works. This paper implies that ECLBC and SIMON are in a tight connection in the design and security based on the affine equivalent property. We mention that the linear layer should be noticed and carefully designed to avoid a block cipher being equivalent to existed ciphers.
Liyi Xiong, Bing Sun 0001
IEEE Internet Things J.5
2024 Feistel-Like Structures Revisited: Classification and Cryptanalysis
Bing Sun 0001, Zejun Xiang 0001, Zhengyi Dai, Xuan Shen, Longjiang Qu, Shaojing Fu
CRYPTO (4)1
2024 Improved (Related-Key) Differential-Based Neural Distinguishers for SIMON and SIMECK Block Ciphers
abstract
Abstract In CRYPTO 2019, Gohr made a pioneering attempt and successfully applied deep learning to the differential cryptanalysis against NSA block cipher Speck 32/64, achieving higher accuracy than the pure differential distinguishers. By its very nature, mining effective features in data plays a crucial role in data-driven deep learning. In this paper, in addition to considering the integrity of the information from the training data of the ciphertext pair, domain knowledge about the structure of differential cryptanalysis is also considered into the training process of deep learning to improve the performance. Meanwhile, taking the performance of the differential-neural distinguisher of Simon 32/64 as an entry point, we investigate the impact of input difference on the performance of the hybrid distinguishers to choose the proper input difference. Eventually, we improve the accuracy of the neural distinguishers of Simon 32/64, Simon 64/128, Simeck 32/64 and Simeck 64/128. We also obtain related-key differential-based neural distinguishers on round-reduced versions of Simon 32/64, Simon 64/128, Simeck 32/64 and Simeck 64/128 for the first time.
Jinyu Lu, Bing Sun 0001, Chao Li 0002, Li Liu 0002
Comput. J.3
2023 New Wine Old Bottles: Feistel Structure Revised
abstract
This paper mainly investigates the iterative structures whose decryption is similar to the encryption. Firstly, we unify many well-known structures which share similar procedures between the decryption and the encryption, and give a sufficient and necessary condition for this structure to be bijective, which reveals many new insights into the Feistel structure as well as the Lai-Massey structure. Secondly, we analyze the security of the unified structure against the known cryptanalysis. By extending the dual structure from a Feistel structure to the unified structure, we prove that a differential of the unified structure is impossible if and only if it is a zero-correlation linear hull of its dual structure, which presents a generalized link between the impossible differential and zero-correlation linear cryptanalysis shown in CRYPTO 2015. Significantly, several constraints on the linear components of the cipher and the permutation on the branches of the cipher are specified to make the structure resilient to differential and linear cryptanalysis. Furthermore, in the case that the order of the permutation equals the number of the branches$n$, we prove that there always exist a$(3n-1)$-round impossible differential and a$(3n-1)$-round zero-correlation linear hull of the structure, and also present an algorithm to construct these distinguishers. Finally, we propose some novel structures which might be used in future block cipher designs.
Bing Sun 0001, Li Liu 0002, Hua Zhang 0008, Chao Li 0002
IEEE Trans. Inf. Theory2
2022 Improved rotational-XOR cryptanalysis of Simon-like block ciphers
abstract
Abstract Rotational‐XOR (RX) cryptanalysis is a cryptanalytic method aimed at finding distinguishable statistical properties in Addition‐Rotation‐XOR‐C ciphers, that is, ciphers that can be described only by using modular addition, cyclic rotation, XOR and the injection of constants. In this study, we extend RX‐cryptanalysis to AND‐RX ciphers, a similar design paradigm where the modular addition is replaced by vectorial bitwise AND; such ciphers include the block cipher families Simon and Simeck. We analyse the propagation of RX‐differences through AND‐RX rounds and develop a closed form formula for their expected probability. Inspired by the MILP verification model proposed by Sadeghi et al., we develop a SAT/SMT model for searching compatible RX‐characteristics in Simon‐like ciphers, that is, that there is at least one right pair of messages/keys to satisfy the RK‐characteristics. To the best of our knowledge, this is the first model that takes the RX‐difference transitions and value transitions simultaneously into account in Simon‐like ciphers. Meanwhile, we investigate how the choice of the round constants affects the resistance of Simon‐like ciphers against RX‐cryptanalysis. Finally, we show how to use an RX‐distinguisher for a key recovery attack. Evaluating our model we find compatible RX‐characteristics of up to 20, 27 and 34 rounds with respective probabilities of 2 −26 , 2 −44 and 2 −56 for versions of Simeck with block sizes of 32, 48 and 64 bits, respectively, for large classes of weak keys in the related‐key model. In most cases, these are the longest published distinguishers for the respective variants of Simeck. In the case of Simon, we present compatible RX‐characteristics for round‐reduced versions of all 10 instances. We observe that for equal block and key sizes, the RX‐distinguishers cover fewer rounds in Simon than in Simeck. Concluding the paper, we present a key recovery attack on Simeck 64 reduced to 28 rounds using a 23‐round RX‐characteristic.
Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002
IET Inf. Secur.4
2022 Security evaluation on type-1 and type-1-like 4-branch generalized Feistel structures and application to reduced-round Lesamnta-LW-BC
abstract
Abstract Generalized Feistel structures (called GFSs for short) are one of the most popular block cipher structures. They are mainly divided into type‐1, type‐2 and type‐3 GFS. Among them, type‐1 and type‐1‐like ones attracted much attention during the past decades because of the simple design and high implementation efficiency. In this paper, the security of the type‐1 and type‐1‐like 4‐branch GFS with substitution permutation round functions against the impossible differential attack are evaluated. For these two structures, 21‐round impossible differential distinguishers are constructed when the linear layers P satisfy γ ( P ) ≥ 2, where γ ( P ) denotes the primitive index of P . Especially, when γ ( P ) = 2, the 21‐round distinguisher of the type‐1 structure is one round longer than before. Furthermore, for a specific block cipher Lesamnta‐LW‐BC, which takes the type‐1‐like structure, by exploiting the details of the linear layer, a better 21‐round impossible differential distinguisher is constructed, which contains more impossible differentials than before. With this distinguisher, a 27‐round impossible differential attack on Lesamnta‐LW‐BC is performed. The length of this attack is 8 rounds longer than the previous best one. Our results can provide guidance for designing and analysing the type‐1 and type‐1‐like GFS as well as the specific block ciphers which take the structures.
Xuan Shen, Bing Sun 0001
IET Inf. Secur.4
2021 Out of Non-linearity: Search Impossible Differentials by the Bitwise Characteristic Matrix
Yunxiao Yang, Xuan Shen, Bing Sun 0001
ISPEC3
2021 Revisiting Impossible Differential Distinguishers of Two Generalized Feistel Structures
abstract
Impossible differential attack is one of the most effective cryptanalytic methods for block ciphers. Its key step is to construct impossible differential distinguishers as long as possible. In this paper, we mainly focus on constructing longer impossible differential distinguishers for two kinds of generalized Feistel structures which are m -dataline CAST256-like and MARS-like structures. When their round function takes Substitution Permutation SP and Substitution Permutation Substitution SPS types, they are called CAST 256 SP / CAST 256 SPS and MARS SP / MARS SPS , respectively. For CAST 256 SP / CAST 256 SPS , the best known result for the length of the impossible differential distinguisher was m 2 + m / m 2 + m − 1 rounds, respectively. With the help of the linear layer P , we can construct m 2 + m + Λ 0 / m 2 + m + Λ 1 -round impossible differential distinguishers, where Λ 0 and
Xuan Shen, Bing Sun 0001
Secur. Commun. Networks3
2021 Provable Security Evaluation of Block Ciphers Against Demirci-Selçuk's Meet-in-the-Middle Attack
abstract
The Demirci-Selçuk's meet-in-the-middle attack is one of the most important methods among all the cryptanalytic vectors, which gives the best result against the round-reduced AES with respect to the rounds, and tradeoffs between data, time and memory. While we have already built provable security models against the differential cryptanalysis, linear cryptanalysis cryptanalysis, impossible differential and zero-correlation linear cryptanalysis, the provable security against the meet-in-the-middle attack is missing. In this paper, we propose the subset representation of function based on which we could give an algorithm to compute the exact number of parameters of the Demirci-Selçuk's distinguisher given the input and output, respectively. Experiments show that this algorithm can be more efficient than the automatical tool presented by Shi et al. at Asiacrypt 2018. We further extract a formula based on this algorithm and show an upper bound for the length of the Demirci-Selçuk's distinguisher of an iterative SPN cipher. We prove that for an SPN block cipher whose block size equals the key size, an effective Demirci-Selçuk-type meet-in-the-middle distinguisher covers at most twice the maximum of the primitive indexes of the linear layer and its inverse. As a result, we show that the known length of the Demirci-Selçuk's distinguisher of the AES-128 cannot be improved unless the details of the S-boxes are exploited, which demonstrates that the AES has a provable security against the Demirci-Selçuk's meet-in-the-middle attack.
Bing Sun 0001
IEEE Trans. Inf. Theory1
2021 New Constructions of Complete Permutations
abstract
In this paper, we aim to construct a class of complete permutations$\mathcal F$over$\mathbb F_{q}^{n}$from some polynomials$f_{1},f_{2},\ldots,f_{n}$over$\mathbb F_{q}$. First of all, we determine a necessary and sufficient condition such that$\mathcal F$is complete. Briefly, we transform the completeness of$\mathcal F$into showing the permutation properties of two polynomials over$\mathbb F_{q}$obtained from these$f_{i}$’s. Then, following the wide applications, we investigate the constructions of linear complete permutations over$\mathbb F_{2}^{n}$based on the rotations andXORs. The following two cases are considered: the first one is to use some different circularly left shift transforms$f_{i}$’s and the second one is to assume$f_{i}$’s are of the form$b_{i}f$with a fixed$f$and different$b_{i}$’s in$\mathbb F_{q}$. In both cases, we show that the completeness of the permutation is closely related to the ranks of some matrices with particular forms, which can be determined by the cycle decomposition of the permutation over the$n$branches. Besides, we present several explicit linear complete permutations which might be used in the design as well as the provable security of cryptographic schemes.
Bing Sun 0001, Kangquan Li, Jian Guo 0001, Longjiang Qu
IEEE Trans. Inf. Theory1
2020 Rotational-XOR Cryptanalysis of Simon-Like Block Ciphers
Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002
ACISP4
2020 The phantom of differential characteristics
Yunwen Liu, Wenying Zhang 0001, Bing Sun 0001, Vincent Rijmen, Chao Li 0002, Shaojing Fu, Meichun Cao
Des. Codes Cryptogr.3
2019 Improved Cryptanalysis on SipHash
Wenqian Xin, Yunwen Liu, Bing Sun 0001, Chao Li 0002
CANS3
2019 New Results About the Boomerang Uniformity of Permutation Polynomials
abstract
In EUROCRYPT 2018, Cid et al. introduced a new concept on the cryptographic property of S-boxes: boomerang connectivity table (BCT for short) for evaluating the subtleties of boomerang-style attacks. Very recently, BCT and the boomerang uniformity, the maximum value in BCT, were further studied by Boura and Canteaut. In this paper, aiming at providing new insights, we show some new results about BCT and the boomerang uniformity of permutations in terms of theory and experiment. First, we present an equivalent technique to compute BCT and the boomerang uniformity, which seems to be much simpler than the original definition by Cid et al. Second, thanks to Carlet's idea, we give a characterization of functions f from F2nto itself with boomerang uniformity δfby means of the Walsh transform. Third, by our method, we consider boomerang uniformities of some specific permutations, mainly the ones with low differential uniformity. Finally, we obtain another class of 4-uniform BCT permutation polynomials over F2n.
Kangquan Li, Longjiang Qu, Bing Sun 0001, Chao Li 0002
IEEE Trans. Inf. Theory3
2018 Programming the Demirci-Selçuk Meet-in-the-Middle Attack with Constraints
Danping Shi, Siwei Sun, Patrick Derbez, Yosuke Todo, Bing Sun 0001, Lei Hu 0003
ASIACRYPT (2)5
2017 Dual Relationship Between Impossible Differentials and Zero Correlation Linear Hulls of SIMON-Like Ciphers
Xuan Shen, Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Maodong Liao
ISPEC3
2017 Revised cryptanalysis for SMS4
Bing Sun 0001, Chao Li 0002
Sci. China Inf. Sci.2
2017 New observation on division property
Bing Sun 0001, Xin Hai, Zhichao Yang 0002
Sci. China Inf. Sci.1
2016 Impossible Differentials of SPN Ciphers
Xuan Shen, Bing Sun 0001, Chao Li 0002
Inscrypt3
2016 New Insights on AES-Like SPN Ciphers
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Longjiang Qu, Vincent Rijmen
CRYPTO (1)1
2016 Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Vincent Rijmen, Ruilin Li 0002
EUROCRYPT (1)1
2016 Improved zero-correlation linear cryptanalysis of reduced-round Camellia under weak keys
abstract
Camellia is one of the widely used block ciphers, which has been included in the NESSIE block cipher portfolio and selected as a standard by ISO/IEC. In this study, the authors observe that there exist some interesting properties of the FL / FL −1 functions in Camellia. With this observation they derive some weak keys for the cipher, based on which they present the first known 8‐round zero‐correlation linear distinguisher of Camellia with FL / FL −1 layers. This result shows that the FL / FL −1 layers inserted in Camellia cannot resist zero‐correlation linear cryptanalysis effectively for some weak keys since the currently best zero‐correlation linear distinguisher for Camellia without FL / FL −1 layers also covers eight rounds. Moreover, by using the novel distinguisher, they launch key recovery attacks on 13‐round Camellia‐192 and 14‐round Camellia‐256. To their knowledge, these results are the best for Camellia‐192 and Camellia‐256 with FL / FL −1 and whitening layers.
Zhiqiang Liu 0001, Bing Sun 0001, Qingju Wang 0001, Kerem Varici, Dawu Gu
IET Inf. Secur.2
2015 Links Among Impossible Differential, Integral and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Zhiqiang Liu 0001, Vincent Rijmen, Ruilin Li 0002, Qingju Wang 0001, Hoda Alkhzaimi, Chao Li 0002
CRYPTO (1)1
2015 Differential fault analysis on LED using Super-Sbox
abstract
Light encryption device (LED) is a 64 bit lightweight block cipher proposed by Guo et al . at CHES 2011, and its key size is primarily defined as 64 and 128 bits. This study studies differential fault analysis (DFA) of LED using the technique of Super‐Sbox analysis. Under various fault models, the fault pattern propagation rule of the Super‐Sbox can be obtained, based on which the efficiency of fault attack on LED can be greatly improved. For LED‐64, under the nibble‐based fault model, a random nibble fault at the 30th round can reduce the size of key search space to 2 7 –2 20 (average 2 14.02 ). Even if a random nibble fault is injected into the 29th round, the size of the key search space can also be reduced to about 2 17.43 –2 17.72 (average 2 17.65 ) using early‐abort technique. Although under the byte‐based fault model, a random byte fault at the 30th round can reduce the size of the key space to 2 7 –2 16 (average 2 11.92 ). If the adversary has the capability of injecting two random nibble faults at some specified rounds, then the above fault attack on LED‐64 can be similarly extended to LED‐128, and the size of the exhaustive search space for the 128 bit key can be reduced to 2 15 –2 27.94 (average 2 21.96 ). These results demonstrate that Super‐Sbox is a powerful technique that can be used to obtain significant improvements in the key filtration, and thus improve the efficiency of DFA on some special ciphers.
Guangyao Zhao, Ruilin Li 0002, Chao Li 0002, Bing Sun 0001
IET Inf. Secur.5
2015 Truncated differential cryptanalysis of PRINCE
abstract
Abstract PRINCE is a lightweight block cipher whose block size and key size are 64‐bit and 128‐bit, respectively. The core component of PRINCE is PRINCE which is wrapped by the initial and final key whitening. PRINCEcore adopts a 12‐round SPN structure. This paper exploits some new vulnerabilities of PRINCE from an aspect different from previous results, and applies truncated differential cryptanalysis to PRINCE. The result demonstrates that for several reduced versions of PRINCE, there exist 5‐round and 6‐round (out of 12 rounds) truncated differential distinguishers. We introduce a key‐recovery attack on 7‐round PRINCEcore using two 5‐round distinguishers, the data complexity is 250 chosen plaintexts and the time complexity is 248.2 7‐round encryptions, with a storage of about 222.6 counters. Both the distinguishers and key‐recovery attacks are not related to the value of α. Copyright © 2015 John Wiley & Sons, Ltd.
Guangyao Zhao, Bing Sun 0001, Chao Li 0002, Jinshu Su
Secur. Commun. Networks2
2013 A Low Data Complexity Attack on the GMR-2 Cipher Used in the Satellite Phones
Ruilin Li 0002, Chao Li 0002, Bing Sun 0001
FSE4
2013 Fault analysis study of the block cipher FOX64
Ruilin Li 0002, Jianxiong You, Bing Sun 0001, Chao Li 0002
Multim. Tools Appl.3
2011 Balanced rotation symmetric boolean functions with maximum algebraic immunity
abstract
Rotation symmetric Boolean functions (RSBFs) that are invariant under circular translation of indices have been used as components of different cryptosystems. In this paper, even-variable-balanced RSBFs with maximum algebraic immunity (AI) are investigated. At first, we give an original construction of 2m-variable-balanced RSBFs with maximum AI. Then we improve the construction to obtain more 2m-variable-balanced RSBFs with maximum AI, and these new RSBFs have higher non-linearity than all previously obtained RSBFs. Further, we generalise our construction of 2m-variable RSBFs to a new construction that can generate any even-variable RSBFs.
Shaojing Fu, Longjiang Qu, Chao Li 0002, Bing Sun 0001
IET Inf. Secur.4
2011 Impossible differential cryptanalysis of SPN ciphers
abstract
Impossible differential cryptanalysis is a very popular tool for analysing the security of modern block ciphers and the core of such attack is based on the existence of impossible differentials. Currently, most methods for finding impossible differentials are based on the miss-in-the-middle technique and they are very ad hoc. In this study, the authors concentrate on substitution–permutation network (SPN) ciphers whose diffusion layer is defined by a linear transformation P. Based on the theory of linear algebra, the authors propose several criteria on P and its inversion P-1 to characterise the existence of 3/4-round impossible differentials. The authors further discuss the possibility to extend these methods to analyse 5/6-round impossible differentials. Using these criteria, impossible differentials for reduced-round Rijndael are found that are consistent with the ones found before. New 4-round impossible differentials are discovered for block cipher ARIA. Many 4-round impossible differentials are firstly detected for a kind of SPN cipher that employs a 32×32 binary matrix proposed at ICISC 2006 as its diffusion layer. It is concluded that the linear transformation should be carefully designed in order to protect the cipher against impossible differential cryptanalysis.
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002
IET Inf. Secur.2
2011 Differential Fault Analysis on SMS4 using a single fault
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Jianxiong You
Inf. Process. Lett.2
2011 Impossible differential cryptanalysis of 13-round CLEFIA-128
Xuehai Tang, Bing Sun 0001, Ruilin Li 0002, Chao Li 0002
J. Syst. Softw.2
2011 A meet-in-the-middle attack on reduced-round ARIA
Xuehai Tang, Bing Sun 0001, Ruilin Li 0002, Chao Li 0002, Juhua Yin
J. Syst. Softw.2
2010 Cryptanalysis of a Generalized Unbalanced Feistel Network Structure
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Longjiang Qu
ACISP2
2010 Impossible Differential Cryptanalysis on Feistel Ciphers with SP and SPS Round Functions
Yuechuan Wei, Bing Sun 0001, Chao Li 0002
ACNS3
2010 SQUARE attack on block ciphers with low algebraic degree
Bing Sun 0001, Ruilin Li 0002, Longjiang Qu, Chao Li 0002
Sci. China Inf. Sci.1
2009 Saturation Attack on the Block Cipher HIGHT
Bing Sun 0001, Chao Li 0002
CANS2
2009 Integral Cryptanalysis of ARIA
Bing Sun 0001, Chao Li 0002
Inscrypt2
2009 New Cryptanalysis of Block Ciphers with Low Algebraic Degree
Bing Sun 0001, Longjiang Qu, Chao Li 0002
FSE1
2008 Enumeration of Homogeneous Rotation Symmetric Functions over Fp
Shaojing Fu, Chao Li 0002, Bing Sun 0001
CANS3
2008 Construction of Resilient Functions with Multiple Cryptographic Criteria
Chao Li 0002, Shaojing Fu, Bing Sun 0001
CANS3