VLDB 2026 Research / reviewers in the wild / expert
Gaoli Wang
dblp:32/6238
· DBLP profile ↗
48ranked-venue papers
13as first author
25since 2021 · last 2026
0000-0002-2121-9306ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 8 first-author · 16 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 4 first-author · 3 since 2021Computer networks · 5 · 5 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang, Jiali Shi |
CRYPTO (6) | 3 |
| 2026 | Tracking Algebraic Degree with Exponent Sets: Higher-Order Differential Attacks on FHE-Friendly Cipher sf Yu2sf X
Jianqiang Ni, Gaoli Wang, Yingxin Li |
Des. Codes Cryptogr. | 2 |
| 2026 | New SAT-based model for constructing linear layers with good cryptographic properties and implementation
Tianling Weng, Gaoli Wang |
Frontiers Comput. Sci. | 2 |
| 2026 | New Records in Collision Attacks on SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian, Xiaoyang Dong 0001, Siwei Sun, Danping Shi |
J. Cryptol. | 3 |
| 2025 | New Collision Attacks on Round-Reduced SHA-512
Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian, Keting Jia |
CRYPTO (5) | 3 |
| 2025 | Exploiting output bits and the χ operation in MitM preimage attacks on Keccak
Tianling Weng, Gaoli Wang, Keting Jia, Xiaoyang Dong 0001, Siwei Sun, Tingting Cui |
Des. Codes Cryptogr. | 2 |
| 2025 | Security Analysis of the Lightweight Cryptographic Algorithm Sycon for IoT DevicesabstractWith the rapid proliferation of the Internet of Things (IoT), the security of IoT devices has become an increasingly critical concern, particularly in the context of lightweight cryptographic algorithms designed for resource-constrained environments. Lightweight cryptography is indispensable for ensuring the confidentiality and integrity of communications across IoT networks. This paper presents a thorough security evaluation of the Sycon algorithm, focusing on its susceptibility to a range of cryptographic attacks. We begin by introducing Meet-in-the-Middle (MitM) preimage and collision attacks on 3-round and 4-round Sycon-Hash. These attacks are the first published analysis results on reduced-round Sycon-Hash. By employing an SMT-based modeling approach in conjunction with the STP solver, we successfully construct and validate MitM attack paths, thereby providing novel insights into the resilience of Sycon against such threats. In addition, we propose and implement a committing attack on the 2-round Sycon-AEAD-64 using the CMT-3 framework, which uncovers potential vulnerabilities within its authenticated encryption mechanism. Our analysis not only advances the understanding of Sycon’s cryptographic robustness but also offers valuable methodologies for the future assessment of lightweight cryptographic solutions in resource-constrained contexts. Gaoli Wang, Yingxin Li, Jianqiang Ni, Jianyong Hu |
IEEE Internet Things J. | 2 |
| 2025 | HML-BFT: Hybrid multi-layer BFT consensus with reputation model for large-scale blockchain
Gaoli Wang, Leibo Li, Entang Li |
Peer Peer Netw. Appl. | 3 |
| 2025 | Practical Key Collision on AES and Kiasu-BCabstractThe key collision attack was proposed as an open problem in key-committing security in Authenticated Encryption (AE) schemes like AES-GCM and ChaCha20Poly1305. In ASIACRYPT 2024, Taiyama et al. introduce a novel type of key collision—target-plaintext key collision (TPKC) for AES. Depending on whether the plaintext is fixed, TPKC can be divided into fixed-TPKC and free-TPKC, which can be directly converted into collision attacks and semi-free-start collision attacks on the Davies-Meyer (DM) hashing mode. In this paper, we propose a new rebound attack framework leveraging a time-memory tradeoff strategy, enabling practical key collision attacks with optimized complexity. We also present an improved automatic method for findingrebound-friendlydifferential characteristics by controlling the probabilities in the inbound and outbound phases, allowing the identified characteristics to be directly used inrebound-basedkey collision attacks. Our analysis reveals that the 2-round AES-128 fixed-TPKC attack proposed by Taiyama et al. is, in fact, a free-TPKC attack. This distinction is significant, as fixed-TPKC attacks are substantially more difficult than their free-TPKC counterparts. By integrating our improved automatic method with a new rebound attack framework, we successfully identify a new differential characteristic for the 2-round AES-128 fixed-TPKC attack and develope the first practical fixed-TPKC attack against 2-round AES-128. Additionally, we present practical fixed-TPKC attacks against 5-round AES-192 and 3-round Kiasu-BC, along with a practical free-TPKC attack against 6-round Kiasu-BC. Furthermore, we reduce time complexities for free-TPKC and fixed-TPKC attacks on other AES variants. Jianqiang Ni, Yingxin Li, Fukang Liu, Gaoli Wang |
IEEE Trans. Inf. Theory | 4 |
| 2024 | The First Practical Collision for 31-Step SHA-256
Yingxin Li, Fukang Liu, Gaoli Wang, Xiaoyang Dong 0001, Siwei Sun |
ASIACRYPT (7) | 3 |
| 2024 | New Records in Collision Attacks on SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang |
EUROCRYPT (1) | 3 |
| 2024 | A New (Related-Key) Neural Distinguisher Using Two Differences for Differential CryptanalysisabstractAt CRYPTO 2019, Gohr showed the significant advantages of neural distinguishers over traditional distinguishers in differential cryptanalysis. At fast software encryption (FSE) 2024, Bellini et al. provided a generic tool to automatically train the (related‐key) differential neural distinguishers for different block ciphers. In this paper, based on the intrinsic principle of differential cryptanalysis and neural distinguisher, we propose a superior (related‐key) differential neural distinguisher that uses the ciphertext pairs generated by two different differences. In addition, we give a framework to automatically train our (related‐key) differential neural distinguisher with four steps: difference selection, sample generation, training pipeline, and evaluation scheme. To demonstrate the effectiveness of our approach, we apply it to the block ciphers: Simon, Speck, Simeck, and Hight. Compared to the existing results, our method can provide improved accuracy and even increase the number of rounds that can be analyzed. The source codes are available in https://github.com/differentialdistinguisher/AutoND_New . Gaoli Wang, Siwei Sun |
IET Inf. Secur. | 2 |
| 2024 | Keeping classical distinguisher and neural distinguisher in balance
Gaoli Wang |
J. Inf. Secur. Appl. | 2 |
| 2024 | Attribute-Based Data Sharing Scheme Using Blockchain for 6G-Enabled VANETsabstractThe advent of 6G communications technology will bring about a transition from the “Internet of Everything” to the “Intelligent Connection of Everything”. 6G-enabled vehicular ad hoc networks (VANETs) will enjoy lower latency, higher speed, and greater capacity network services. Nevertheless, achieving secure data sharing will be an even tougher challenge. Given this, we propose an attribute-based data sharing scheme with blockchain for 6G-enabled VANETs. First, we propose an efficient multi-tree-based user revocation mechanism. With the Chinese remainder theorem, our mechanism supports user batch revocation and batch joining. Second, we achieve distributed data storage by utilizing the blockchain and smart contracts. To solve the problem of insufficient storage capacity on the blockchain, we adopt a combination of on-chain and off-chain storage. Third, to reduce the computation burden on users, our proposal supports online/offline encryption and verifiable outsourced decryption. Meanwhile, our mechanism supports policy hiding, data revocation, and cross-domain data sharing. The proposed scheme is proven to satisfy the indistinguishability under chosen plaintext attack (IND-CPA) in the standard model. Theoretical analysis shows that our mechanism outperforms existing schemes in functionality and security. Simulation experiments show that our proposal is efficient and suitable for 6G-enabled VANETs. Zhenzhen Guo, Gaoli Wang, Yingxin Li, Jianqiang Ni, Guoyan Zhang |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILP
Fukang Liu, Gaoli Wang, Santanu Sarkar 0001, Ravi Anand, Willi Meier, Yingxin Li, Takanori Isobe 0001 |
EUROCRYPT (4) | 2 |
| 2023 | A Closer Look at the S-Box: Deeper Analysis of Round-Reduced ASCON-HASH
Xiaorui Yu, Fukang Liu, Gaoli Wang, Siwei Sun, Willi Meier |
SAC | 3 |
| 2023 | Accountable Attribute-Based Data-Sharing Scheme Based on Blockchain for Vehicular Ad Hoc NetworkabstractVehicular ad hoc network (VANET), as one of the bases of intelligent transport systems, plays an essential role in improving road traffic safety. Nevertheless, in such a complicated, distributed, and highly mobile network structure, how to achieve secure data sharing is a great challenge. The ciphertext-policy attribute-based encryption (CP-ABE) is a potential method to realize one-to-many data sharing for VANET. However, the key abuse problems of users and attribute authorities (AAs) incur many security concerns for VANET. Both issues are extremely important because the attribute keys directly affect users’ access to shared data. To solve the above issues, we propose an accountable attribute-based data-sharing scheme with the blockchain technology (AT-DS-VAHN, in short). For AAs key abuse, we use the consortium blockchain maintained by AAs to achieve distributed key storage and distribution. The attribute keys generated by each AA and its key distribution records are recorded on the blockchain in the form of transactions. Based on the traceability of blockchain, the key abuse behavior of AAs can be caught and prosecuted. For user key abuse, we achieve white-box traceability and efficient user revocation. Based on the principle of traceable-then-revocable, malicious users can be tracked and then revoked directly from the system without complex operations. Besides, to reduce the computation burden on users, our proposal supports online/offline encryption and verifiable outsourced decryption. Security and efficiency analyses show that our proposal is secure and efficient, with high practicability and reliability for VANET. Zhenzhen Guo, Gaoli Wang, Yingxin Li, Jianqiang Ni, Runmeng Du |
IEEE Internet Things J. | 2 |
| 2023 | A Multifactor Combined Data Sharing Scheme for Vehicular Fog Computing Using BlockchainabstractVehicular fog computing (VFC), as an extended model of fog computing, combines fog computing with traditional in-vehicle networks to provide real-time response services for users. However, in such a dynamic system architecture, achieving secure and efficient data sharing is an enormous challenge. Ciphertext-policy attribute-based encryption (CP-ABE) is widely regarded as an excellent way of achieving one-to-many data sharing. Nevertheless, several practical challenges hinder its widespread application in VFC, such as inefficient attribute revocation, single-factor access control, and centralized data storage. For this purpose, we design a multifactor combined data sharing scheme for VFC with CP-ABE and blockchain (MC-DS-VFC, in short). We first propose an efficient attribute revocation mechanism that does not require complex key update operations. We then embed time, user attributes, and access interests into data sharing for more fine-grain access control, which enables users with sufficient attributes to efficiently access real-time shared data according to their access interests. Finally, we combine the interplanetary file system (IPFS) and the blockchain maintained by roadside units (RSUs) to achieve distributed collaborative storage. Furthermore, our mechanism also supports user traceability, attribute joining, online/offline encryption, and verifiable outsourced decryption. Our proposal is shown to satisfy the indistinguishability under chosen plaintext attack (IND-CPA) in the standard model. Theoretical analysis and simulation experiments indicate that the MC-DS-VFC scheme is efficient and practical for VFC. Zhenzhen Guo, Gaoli Wang, Guoyan Zhang, Yingxin Li, Jianqiang Ni |
IEEE Internet Things J. | 2 |
| 2023 | Tweakable SM4: How to tweak SM4 into tweakable block ciphers?
Zhenzhen Guo, Gaoli Wang, Orr Dunkelman, Yinxue Pan |
J. Inf. Secur. Appl. | 2 |
| 2022 | Improved Differential-Linear Attack with Application to Round-Reduced Speck32/64
Gaoli Wang |
ACNS | 2 |
| 2022 | Algebraic Meet-in-the-Middle Attack on LowMC
Fukang Liu, Santanu Sarkar 0001, Gaoli Wang, Willi Meier, Takanori Isobe 0001 |
ASIACRYPT (1) | 3 |
| 2022 | Improved Collision Detection Of MD5 Using Sufficient Condition CombinationabstractAbstract Counter-cryptanalysis uses cryptanalytic techniques to detect cryptanalytic attacks. It was introduced by Stevens with a collision detection algorithm that detects whether a message is one of a colliding message pair constructed using a collision attack. Later, Stevens and Shumow improved the collision detection against SHA-1 by using unavoidable conditions. However, there are no results improving collision detection against MD5 due to its weak diffusion properties. In this paper, an improved collision detection algorithm against MD5 is proposed by using the 14-bit sufficient condition combinations. This leads to the dividing the 223 classes into four sets. Each element, belonging to the first two sets, holds the same sufficient condition combination. Our new algorithm can classify 126 classes efficiently. The runtime is 28.6% of the previous collision detection method. Yanzhao Shen, Ting Wu 0001, Gaoli Wang, Haifeng Qian |
Comput. J. | 3 |
| 2021 | Improved Differential-ML Distinguisher: Machine Learning Based Generic Extension for Differential Analysis
Gaoli Wang |
ICICS (2) | 2 |
| 2021 | Improved Machine Learning Assisted (Related-key) Differential Distinguishers For Lightweight CiphersabstractAt CRYPTO 2019, Gohr first proposes a deep learning based attack on round-reduced Speck32/64. It is an all-in-one differential approach under the Markov assumption. Then Baksi presents the method for non-Markov ciphers and applies it to Gimli by simulating the all-in-one differentials. However, all studies are still only for single-key differential distinguishers and the selection of input difference is based on traditional cryptanalysis. Inspired by the work of Gohr and Baksi, we extend and apply machine learning techniques to related-key differential distinguishers for the first time and propose a novel approach to develop (related-key) differential distinguishers without using prior cryptanalysis. We experimentally show that the differences with low Hamming weights are more suitable for building distinguishers. Then we present an exhaustive algorithm and a greedy algorithm to find an appreciable difference for the distinguisher. Finally, to obtain a suitable machine model for distinguishers, we adopt a Bayesian optimization tool named Hyperopt for parameter optimization and model selection. As proof of works, we apply our method to round-reduced Speck32/64, Present64/80 and get some improved cryptanalysis results. Gaoli Wang |
TrustCom | 2 |
| 2021 | Improved File-injection Attacks on Searchable Encryption Using Finite Set TheoryabstractAbstract Searchable encryption (SE) allows the cloud server to search over the encrypted data and leak information as little as possible. Most existing efficient SE schemes assume that the leakage of search pattern and access pattern is acceptable. A series of work was proposed, instructing malicious users to use this leakage to come up with attacks. Especially, with a devastating attack proposed by Zhang et al., the cloud server can reveal the keywords queried by normal users by using some injected files. From the method of constructing uniform $(k,n)$-set of a finite set $A$ proposed by Cao, we put forward a new file-injection attack. In our attack, the server needs fewer injected files than the previous attack when the size of $T$ is larger than 9 and the size of keyword set is larger than $2T$, where $T$ is the threshold of the number of keywords in each injected file. Our attack is more practical and easier to implement in the real scenario. Gaoli Wang, Zhenfu Cao, Xiaolei Dong |
Comput. J. | 1 |
| 2020 | Improved (semi-free-start/near-) collision and distinguishing attacks on round-reduced RIPEMD-160
Gaoli Wang, Fukang Liu, Binbin Cui, Florian Mendel, Christoph Dobraunig |
Des. Codes Cryptogr. | 1 |
| 2020 | Generalized related-key rectangle attacks on block ciphers with linear key schedule: applications to SKINNY and GIFT
Boxin Zhao, Xiaoyang Dong 0001, Willi Meier, Keting Jia, Gaoli Wang |
Des. Codes Cryptogr. | 5 |
| 2019 | Fast Chosen-Key Distinguish Attacks on Round-Reduced AES-192
Chunbo Zhu, Gaoli Wang, Boyu Zhu |
ACISP | 2 |
| 2019 | Efficient Collision Attack Frameworks for RIPEMD-160
Fukang Liu, Christoph Dobraunig, Florian Mendel, Takanori Isobe 0001, Gaoli Wang, Zhenfu Cao |
CRYPTO (2) | 5 |
| 2019 | MILP-based Related-Key Rectangle Attack and Its Application to GIFT, Khudra, MIBSabstractAbstract The rectangle attack is the extension of the traditional differential attack and is evolved from the boomerange attack. It has been widely used to attack several existing ciphers. In this article, we study the security of lightweight block ciphers GIFT, Khudra and MIBS against related-key rectangle attack. We use Mixed-Integer Linear Programming-aided cryptanalysis to search rectangle distinguishers by taking into account the effect of the ladder switch technique. For GIFT, we build a 19-round related-key rectangle distinguisher and attack on 23-round GIFT-64, which requires 260 chosen plaintexts and 2107 encryptions. For Khudra, a 14-round related-key rectangle distinguisher can be built, which leads us to a 17-round rectangle attack. Our attack on 17-round Khudra requires a data complexity of 262.9 chosen plaintexts and a time complexity of 273.9 encryptions. For MIBS, we construct a 13-round related-key rectangle distinguisher and propose an attack on 15-round MIBS-64 with time complexity of 259 and data complexity of 245. Compared to the previous best related-key rectangle attack, we can attack one more round on Khudra and MIBS-64 than before. Gaoli Wang, Guoyan Zhang |
Comput. J. | 2 |
| 2019 | Improved Fault-Tolerant Aggregate SignaturesabstractFault-tolerant aggregate signatures allow the verification algorithm to recognize and verify all the valid individual signatures in an aggregate signature. However, in ordinary aggregate signature schemes, if there is a single faulty individual signature in the valid aggregate, the whole aggregate will be invalid. This will make great difficulties in many applications including secure logging and batch verification in vehicular ad hoc network et al. In this paper, inspired by the finite set theory called uniform (k,n)-set proposed by Cao, we put forward a novel fault-tolerant aggregate signature scheme. Our new scheme is more efficient compared with previous fault-tolerant aggregate signature scheme based on cover-free family. It is noted that our scheme is quite easy to be implemented in the real scenario. Gaoli Wang, Zhenfu Cao, Xiaolei Dong |
Comput. J. | 1 |
| 2018 | Cryptanalysis of Reduced sLiSCP Permutation in Sponge-Hash and Duplex-AE Modes
Yunwen Liu, Yu Sasaki 0001, Ling Song 0001, Gaoli Wang |
SAC | 4 |
| 2017 | Related-Key Impossible-Differential Attack on Reduced-Round Skinny
Ralph Ankele, Subhadeep Banik, Avik Chakraborti, Eik List, Florian Mendel, Siang Meng Sim, Gaoli Wang |
ACNS | 7 |
| 2017 | Collisions and Semi-Free-Start Collisions for Round-Reduced RIPEMD-160
Fukang Liu, Florian Mendel, Gaoli Wang |
ASIACRYPT (1) | 3 |
| 2017 | Single key recovery attacks on reduced AES-192 and Kalyna-128/256
Gaoli Wang, Chunbo Zhu |
Sci. China Inf. Sci. | 1 |
| 2015 | Improved boomerang attacks on round-reduced SM3 and keyed permutation of BLAKE-256abstractIn this study, the authors study the security of hash functions SM3 and BLAKE‐256 against boomerang attack. SM3 is designed by Wang et al . and published by Chinese Commercial Cryptography Administration Office for the use of electronic certification service system in China. BLAKE is one of the five finalists of the NIST SHA‐3 competition submitted by Aumasson et al . For SM3, they present boomerang distinguishers for the compression function reduced to 34/35/36/37 steps out of 64 steps, with time complexities 2 31.4 , 2 33.6 , 2 73.4 and 2 192 , respectively. Then, they show some incompatible problems existed in the previous boomerang attacks on SM3. Meanwhile, they launch boomerang attacks on up to 7‐ and 8‐round keyed permutation of BLAKE‐256, which are the first valid 7‐round and 8‐round boomerangs for BLAKE‐256. Especially, since the author's distinguishers on 34/35‐steps compression function of SM3 and 7‐round keyed permutation of BLAKE‐256 are practical, they are able to obtain boomerang quartets of these attacks. As far as they know, these are the best results against round‐reduced SM3 and BLAKE‐256. Dongxia Bai, Gaoli Wang, Xiaoyun Wang 0001 |
IET Inf. Secur. | 3 |
| 2015 | Improved cryptanalysis on RIPEMD-128abstractRIPEMD‐128 is an ISO/IEC standard cryptographic hash function proposed in 1996 by Dobbertin, Bosselaers and Preneel. The compression function of RIPEMD‐128 consists of two different and almost independent parallel lines denoted by line1 operation and line2 operation. The initial values and the output values of the last step of the two operations are combined, resulting in the final value of one iteration. In this study, the authors present collision differential characteristics for both 40‐step line1 operation and 40‐step line2 operation by choosing a proper message difference. By using message modification technique, they improve the probabilities of the differential characteristics so that they can give a collision attack on 40‐step RIPEMD‐128 hash function with a complexity of 2 35 computations. Meanwhile, they improve the distinguishing attack proposed by Landelle and Peyrin at EUROCRYPT 2013, and give a distinguisher on the full RIPEMD‐128 hash function with a complexity of 2 90.4 by doing message modification. Gaoli Wang |
IET Inf. Secur. | 1 |
| 2014 | Practical Collision Attack on 40-Step RIPEMD-128
Gaoli Wang |
CT-RSA | 1 |
| 2014 | (Pseudo-) Preimage Attacks on Step-Reduced HAS-160 and RIPEMD-160
Gaoli Wang, Yanzhao Shen |
ISC | 1 |
| 2013 | Improved Boomerang Attacks on SM3
Dongxia Bai, Gaoli Wang, Xiaoyun Wang 0001 |
ACISP | 3 |
| 2013 | Preimage and pseudo-collision attacks on step-reduced SM3 hash function
Gaoli Wang, Yanzhao Shen |
Inf. Process. Lett. | 1 |
| 2013 | Collision Attack on the Full Extended MD4 and Pseudo-Preimage Attack on RIPEMD
Gaoli Wang |
J. Comput. Sci. Technol. | 1 |
| 2012 | Boomerang and Slide-Rotational Analysis of the SM3 Hash Function
Aleksandar Kircanski, Yanzhao Shen, Gaoli Wang, Amr M. Youssef |
Selected Areas in Cryptography | 3 |
| 2011 | Collision Attack for the Hash Function Extended MD4
Gaoli Wang |
ICICS | 1 |
| 2010 | Distinguishing Attacks on LPMAC Based on the Full RIPEMD and Reduced-Step RIPEMD-{256, 320}
Gaoli Wang |
Inscrypt | 1 |
| 2009 | Preimage Attack on Hash Function RIPEMD
Gaoli Wang, Shaohui Wang |
ISPEC | 1 |
| 2007 | Related-Key Rectangle Attack on 43-Round SHACAL-2
Gaoli Wang |
ISPEC | 1 |
| 2005 | The Second-Preimage Attack on MD4
Gaoli Wang, Guoyan Zhang, Xiaoyun Wang 0001 |
CANS | 2 |