VLDB 2026 Research / reviewers in the wild / expert
Ling Song 0001
dblp:32/381-1
· DBLP profile ↗
42ranked-venue papers
11as first author
22since 2021 · last 2026
0000-0001-9298-7313ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 11 first-author · 20 since 2021Computer networks · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNY
Ling Song 0001, Yincen Chen, Qianqian Yang 0003, Lei Wang 0031, Lei Hu 0003, Jian Weng 0001 |
CRYPTO (6) | 1 |
| 2025 | Improving the Differential-Linear Attack with Applications to GIFT-COFB, GIFT-64 and HyENA
Yincen Chen, Ling Song 0001, Yin Lv |
ISC | 3 |
| 2025 | Preimage and collision attacks on reduced Ascon using algebraic strategiesabstractAbstract Ascon, a family of algorithms that supports hashing and authenticated encryption, is the winner of the NIST Lightweight Cryptography Project. In this paper, we propose an improved preimage attack against 2-round Ascon-XOF-64 with a complexity of $$2^{33}$$ 2 33 via a more effective guessing strategy. Furthermore, we successfully extend our preimage attack on 2-round Ascon-XOF-64 to 2-round Ascon-XOF-128, achieving a complexity of $$2^{97}$$ 2 97 , which is currently the best preimage attack against 2-round Ascon-XOF-128. Apart from the preimage attack, we also investigate the resistance of Ascon-HASH against collision attacks. To be specific, we introduce the linearization of the inverse of S-boxes and then propose a free-start collision attack on 3-round Ascon-HASH with a complexity of $$2^{14}$$ 2 14 using a differential trail searched dedicatedly. In addition, we construct different 2-round connectors using the linearization of the inverse of S-boxes and successfully extend the collision attack to 4 rounds and 5 rounds of Ascon-HASH with complexities of $$2^{18}$$ 2 18 and $$2^{41}$$ 2 41 , respectively. Although our attacks do not compromise the security of the full 12-round Ascon-XOF and Ascon-HASH, they provide some insights into Ascon’s security. Qinggan Fu, Qianqian Yang 0003, Ling Song 0001 |
Cybersecur. | 4 |
| 2025 | Generalized impossible differential attacks on block ciphers: application to SKINNY and ForkSKINNY
Ling Song 0001, Qinggan Fu, Qianqian Yang 0003, Yin Lv, Lei Hu 0003 |
Des. Codes Cryptogr. | 1 |
| 2024 | Generic Differential Key Recovery Attacks and Beyond
Ling Song 0001, Qianqian Yang 0003, Yincen Chen, Lei Hu 0003, Jian Weng 0001 |
ASIACRYPT (7) | 1 |
| 2024 | A Note on Neutral Bits for ARX Ciphers from the Perspective of BCT
Qianqian Yang 0003, Ling Song 0001, Lei Hu 0003 |
Inscrypt (2) | 3 |
| 2024 | Probabilistic Extensions: A One-Step Framework for Finding Rectangle Attacks and Beyond
Ling Song 0001, Qianqian Yang 0003, Yincen Chen, Lei Hu 0003, Jian Weng 0001 |
EUROCRYPT (1) | 1 |
| 2024 | Improving Differential-Neural Cryptanalysis for Large-State SPECK
Tianrong Huang, Yingying Li 0001, Qinggan Fu, Yincen Chen, Ling Song 0001 |
ICICS (1) | 5 |
| 2024 | Revisiting the shuffle of generalized Feistel structureabstractAbstract The Generalized Feistel Structure ( $$\texttt{GFS}$$ GFS ) is one of the most widely used frameworks in symmetric cipher design. In FES 2010, Suzaki and Minematsu strengthened the cryptanalysis security of $$\texttt{GFS}$$ GFS by searching for shuffles with the best diffusion property. In ASIACRYPT 2018, Shi et al. suggested a set of shuffles, which makes $$\texttt{GFS}$$ GFS a better resistance against Demirci–Selcuk meet-in-the-middle cryptanalysis. Since these shuffles are different from the currently known good ones and also different from the shuffles used in $$\texttt{TWINE}$$ TWINE and $$\texttt{LBlock}$$ LBlock , our research focuses on a more comprehensive evaluation of $$\texttt{GFS}$$ GFS with different shuffles, including diffusion property of shuffle, differential, linear, impossible differential, zero-correlation linear, integral and Demirci–Selcuk meet-in-the-middle cryptanalysis, to find the best one. Such evaluations entail significant time consumption. Thus, we utilize Mixed Integral Linear Programming models and introduce an evaluate-and-filter strategy to achieve it efficiently. Our results verify that the shuffles discovered by Suzaki and Minematsu and those used in $$\texttt{TWINE}$$ TWINE and $$\texttt{LBlock}$$ LBlock are the best so far. We also find that the cryptanalysis resistances of $$\texttt{GFS}$$ GFS are not necessarily consistent. It is this finding that makes the necessity of our more comprehensive evaluation self-evident. Yincen Chen, Xuanyu Liang, Ling Song 0001, Qianqian Yang 0003 |
Cybersecur. | 4 |
| 2024 | CCA security for contracting (quasi-)Feistel constructions with tight round complexity
Chun Guo 0002, Ling Song 0001 |
Des. Codes Cryptogr. | 2 |
| 2024 | Preimage Attacks on Xoodyak and Gaston Based on Algebraic StrategiesabstractAs the Internet of Things (IoT) continues to grow, the urgency to bolster IoT device security escalates, particularly in evaluating the security of lightweight ciphers. Since the inception of Keccak (also known as SHA-3), embedding a permutation within a certain operational mode has become a pivotal approach in designing lightweight cryptography. This led to numerous permutation-based lightweight ciphers tailored for IoT applications. Among them, Xoodyak and Gaston are typical examples and even incorporate Keccak’s nonlinear operation$\chi $within their round functions. This article focuses on assessing the security of Keccak-like lightweight hash functions against preimage attacks. We introduce a generic preimage attack framework from an algebraic perspective and propose a new linearization method that leverages the algebraic properties of$\chi $in the permutation. Additionally, in order to find good guessing strategies, we develop automatic tools based on bit-level mixed-integer linear programming on Xoodyak and Gaston. As a result, the complexity of finding a preimage for 2-round Xoodyak-XOF with a 128-bit digest is$2^{94.66}$while that for 3-round Xoodyak-XOF can be reduced from$2^{125.06}$to$2^{123.91}$and memory consumption from$2^{97}$to a negligible level. This marks the most efficient preimage attack against a 3-round Xoodyak-XOF to date. Furthermore, we present the first preimage attacks on 1-/2-round Gaston with complexities of$2^{90.56}$and$2^{122.15}$, respectively. Qinggan Fu, Yin Lv, Zhiquan Liu 0001, Yingying Li 0001, Ling Song 0001, Jian Weng 0001 |
IEEE Internet Things J. | 5 |
| 2024 | Optimizing Rectangle and Boomerang Attacks: A Unified and Generic Framework for Key Recovery
Qianqian Yang 0003, Ling Song 0001, Danping Shi, Lei Hu 0003, Jian Weng 0001 |
J. Cryptol. | 2 |
| 2024 | Revisiting the Boomerang Attack From a Perspective of 3-DifferentialabstractIn this paper, inspired by the work of Beyne and Rijmen at CRYPTO 2022, we explore the accurate probability ofd-differential in the fixed-key model. The theoretical foundations of our method are based on a special matrix - quasi-d-differential transition matrix, which is a natural extension of the quasidifferential transition matrix. The role of quasi-d-differential transition matrices in polytopic cryptananlysis is analogous to that of correlation matrices in linear cryptanalysis. Therefore, the fixed-key probability of ad-differential can be exactly expressed as the sum of the correlations of its quasi-d-differential trails. Then we revisit the boomerang attack from a perspective of 3-differential. Different from previous works, the probability of a boomerang distinguisher can be exactly expressed as the sum of the correlations of its quasi-3-differential trails without any assumptions in our work. In order to illustrate our theory, we apply it to the lightweight block cipher GIFT. It is interesting to find the probability of every optimal 3-differential characteristic of an existing 2-round boomerang is zero, which can be seen as an evidence that the security of block ciphers adopting half-round key XOR might be overestimated previously to some extent in differential-like attacks. Ling Song 0001, Baofeng Wu, Mostafizar Rahman, Takanori Isobe 0001 |
IEEE Trans. Inf. Theory | 2 |
| 2023 | Improved Differential Cryptanalysis on SPECK Using Plaintext Structures
Zhuohui Feng, Qianqian Yang 0003, Zhiquan Liu 0001, Ling Song 0001 |
ACISP | 6 |
| 2023 | Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNY
Danping Shi, Siwei Sun, Ling Song 0001, Lei Hu 0003, Qianqian Yang 0003 |
EUROCRYPT (4) | 3 |
| 2023 | Improved Related-Key Rectangle Attack Against the Full AES-192
Xuanyu Liang, Yincen Chen, Ling Song 0001, Qianqian Yang 0003, Zhuohui Feng, Tianrong Huang |
ICICS | 3 |
| 2023 | Improving the Rectangle Attack on GIFT-64
Yincen Chen, Xuanyu Liang, Ling Song 0001, Qianqian Yang 0003, Zhuohui Feng |
SAC | 4 |
| 2023 | Generic attacks on small-state stream cipher constructions in the multi-user settingabstractAbstract Small-state stream ciphers (SSCs), which violate the principle that the state size should exceed the key size by a factor of two, still demonstrate robust security properties while maintaining a lightweight design. These ciphers can be classified into several constructions and their basic security requirement is to resist generic attacks, i.e., the time–memory–data tradeoff (TMDTO) attack. In this paper, we investigate the security of small-state constructions in the multi-user setting. Based on it, the TMDTO distinguishing attack and the TMDTO key recovery attack are developed for such a setting. It is shown that SSCs which continuously use the key can not resist the TMDTO distinguishing attack. Moreover, SSCs based on the continuous-IV-key-use construction cannot withstand the TMDTO key recovery attack when the key length is shorter than the IV length, no matter whether the keystream length is limited or not. Finally, we apply these two generic attacks to TinyJAMBU and DRACO in the multi-user setting. The TMDTO distinguishing attack on TinyJAMBU with a 128-bit key can be mounted with time, memory, and data complexities of $$2^{64}$$ 2 64 , $$2^{48}$$ 2 48 , and $$2^{32}$$ 2 32 , respectively. This attack is comparable with a recent work on ToSC 2022, where partial key bits of TinyJAMBU are recovered with more than $$2^{50}$$ 2 50 users (or keys). As DRACO’s IV length is smaller than its key length, it is vulnerable to the TMDTO key recovery attack. The resulting attack has a time and memory complexity of both $$2^{112}$$ 2 112 , which means DRACO does not provide 128-bit security in the multi-user setting. Jianfu Huang, Qinggan Fu, Yincen Chen, Ling Song 0001 |
Cybersecur. | 6 |
| 2022 | Key Structures: Improved Related-Key Boomerang Attack Against the Full AES-256
Jian Guo 0001, Ling Song 0001, Haoyang Wang 0001 |
ACISP | 2 |
| 2022 | Exploring SAT for Cryptanalysis: (Quantum) Collision Attacks Against 6-Round SHA-3
Jian Guo 0001, Guozhen Liu, Ling Song 0001 |
ASIACRYPT (3) | 3 |
| 2022 | Optimizing Rectangle Attacks: A Unified and Generic Framework for Key Recovery
Ling Song 0001, Qianqian Yang 0003, Danping Shi, Lei Hu 0003, Jian Weng 0001 |
ASIACRYPT (1) | 1 |
| 2021 | Security analysis of Subterranean 2.0abstractAbstract Subterranean 2.0 is a cipher suite that can be used for hashing, authenticated encryption, MAC computation, etc. It was designed by Daemen, Massolino, Mehrdad, and Rotella, and has been selected as a candidate in the second round of NIST’s lightweight cryptography standardization process. Subterranean 2.0 is a duplex-based construction and utilizes a single-round permutation in the duplex. It is the simplicity of the round function that makes it an attractive target of cryptanalysis. In this paper, we examine the single-round permutation in various phases of Subterranean 2.0 and specify three related attack scenarios that deserve further investigation: keystream biases in the keyed squeezing phase, state collisions in the keyed absorbing phase, and one-round differential analysis in the nonce-misuse setting. To facilitate cryptanalysis in the first two scenarios, we novelly propose a set of size-reduced toy versions of Subterranean 2.0: Subterranean-m. Then we make an observation for the first time on the resemblance between the non-linear layer in the round function of Subterranean 2.0 and SIMON’s round function. Inspired by the existing work on SIMON, we propose explicit formulas for computing the exact correlation of linear trails of Subterranean 2.0 and other ciphers utilizing similar non-linear operations. We then construct our models for searching trails to be used in the keystream bias evaluation and state collision attacks. Our results show that most instances of Subterranean-m are secure in the first two attack scenarios but there exist instances that are not. Further, we find a flaw in the designers’ reasoning of Subterranean 2.0’s linear bias but support the designers’ claim that there is no linear bias measurable from at most $$2^{96}$$ 2 96 data blocks. Due to the time-consuming search, the security of Subterranean 2.0 against the state collision attack in keyed modes still remains an open question. Finally, we observe that one-round differentials allow to recover state bits in the nonce-misuse setting. By proposing nested one-round differentials, we obtain a sufficient number of state bits, leading to a practical state recovery with only 20 repetitions of the nonce and 88 blocks of data. It is noted that our work does not threaten the security of Subterranean 2.0. Ling Song 0001, Danping Shi, Lei Hu 0003 |
Des. Codes Cryptogr. | 1 |
| 2020 | Towards Closing the Security Gap of Tweak-aNd-Tweak (TNT)
Chun Guo 0002, Jian Guo 0001, Eik List, Ling Song 0001 |
ASIACRYPT (1) | 4 |
| 2020 | TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo 0002, Jian Guo 0001, Ling Song 0001 |
EUROCRYPT (2) | 4 |
| 2020 | Practical Collision Attacks against Round-Reduced SHA-3
Jian Guo 0001, Guohong Liao, Guozhen Liu, Meicheng Liu, Kexin Qiao, Ling Song 0001 |
J. Cryptol. | 6 |
| 2018 | New MILP Modeling: Improved Conditional Cube Attacks on Keccak-Based Constructions
Ling Song 0001, Jian Guo 0001, Danping Shi, San Ling |
ASIACRYPT (2) | 1 |
| 2018 | Boomerang Connectivity Table: A New Cryptanalysis Tool
Carlos Cid, Tao Huang 0015, Thomas Peyrin, Yu Sasaki 0001, Ling Song 0001 |
EUROCRYPT (2) | 5 |
| 2018 | Cryptanalysis of Reduced sLiSCP Permutation in Sponge-Hash and Duplex-AE Modes
Yunwen Liu, Yu Sasaki 0001, Ling Song 0001, Gaoli Wang |
SAC | 3 |
| 2017 | Non-full Sbox Linearization: Applications to Collision Attacks on Round-Reduced Keccak
Ling Song 0001, Guohong Liao, Jian Guo 0001 |
CRYPTO (2) | 1 |
| 2017 | New Collision Attacks on Round-Reduced Keccak
Kexin Qiao, Ling Song 0001, Meicheng Liu, Jian Guo 0001 |
EUROCRYPT (3) | 2 |
| 2017 | Improved linear (hull) cryptanalysis of round-reduced versions of SIMON
Danping Shi, Lei Hu 0003, Siwei Sun, Ling Song 0001, Kexin Qiao, Xiaoshuang Ma |
Sci. China Inf. Sci. | 4 |
| 2016 | Automatic Differential Analysis of ARX Block Ciphers with Application to SPECK and LEA
Ling Song 0001, Zhangjie Huang, Qianqian Yang 0003 |
ACISP (2) | 1 |
| 2016 | Linear Structures: Applications to Cryptanalysis of Round-Reduced Keccak
Jian Guo 0001, Meicheng Liu, Ling Song 0001 |
ASIACRYPT (1) | 3 |
| 2016 | Linear(hull) Cryptanalysis of Round-reduced Versions of KATAN
Danping Shi, Lei Hu 0003, Siwei Sun, Ling Song 0001 |
ICISSP | 4 |
| 2016 | Extension of Meet-in-the-Middle Technique for Truncated Differential and Its Application to RoadRunneR
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Ling Song 0001 |
NSS | 4 |
| 2015 | Improved Differential Analysis of Block Cipher PRIDE
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Kexin Qiao, Ling Song 0001, Jinyong Shan, Xiaoshuang Ma |
ISPEC | 5 |
| 2015 | Extending the Applicability of the Mixed-Integer Programming Technique in Automatic Differential Cryptanalysis
Siwei Sun, Lei Hu 0003, Qianqian Yang 0003, Kexin Qiao, Xiaoshuang Ma, Ling Song 0001, Jinyong Shan |
ISC | 7 |
| 2015 | Differential fault attack on Zorro block cipherabstractAbstract Zorro is a 24‐round block cipher presented at the CHES 2013 conference. In this paper, we propose a differential fault attack on Zorro under a byte fault model, in which faults are injected in the 20th round of Zorro at arbitrary positions. With two fault injections on average, a candidate set for the key of the cipher with at most 224 elements can be efficiently obtained in a low time complexity with a probability of at least 96.29%. In this attack, the position of the fault can be easily determined by the difference of the correct and faulty ciphertexts. Copyright © 2015 John Wiley & Sons, Ltd. Danping Shi, Lei Hu 0003, Ling Song 0001, Siwei Sun |
Secur. Commun. Networks | 3 |
| 2014 | Automatic Security Evaluation and (Related-key) Differential Characteristic Search: Application to SIMON, PRESENT, LBlock, DES(L) and Other Bit-Oriented Block Ciphers
Siwei Sun, Lei Hu 0003, Peng Wang 0009, Kexin Qiao, Xiaoshuang Ma, Ling Song 0001 |
ASIACRYPT (1) | 6 |
| 2014 | Error-Tolerant Algebraic Side-Channel Attacks Using BEE
Ling Song 0001, Lei Hu 0003, Siwei Sun, Danping Shi, Ronglin Hao |
ICICS | 1 |
| 2013 | Automatic Security Evaluation of Block Ciphers with S-bP Structures Against Related-Key Differential Attacks
Siwei Sun, Lei Hu 0003, Ling Song 0001, Yonghong Xie, Peng Wang 0009 |
Inscrypt | 3 |
| 2013 | Improved Algebraic and Differential Fault Attacks on the KATAN Block Cipher
Ling Song 0001, Lei Hu 0003 |
ISPEC | 1 |