VLDB 2026 Research / reviewers in the wild / expert
Zhengting Li
dblp:360/7890
· DBLP profile ↗
13ranked-venue papers
4as first author
13since 2021 · last 2026
0009-0003-4302-7035ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 9 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhanced Differential-Linear Cryptanalysis of ChaCha Based on Bit Puncturing
Lin Ding 0001, Zhengting Li, Jiang Wan, Bin Hu 0011 |
IEEE Internet Things J. | 3 |
| 2026 | Practical Differential Fault Attacks on the GPRS Standard CiphersabstractGEA-1 and GEA-2 are two standard stream ciphers used in GPRS (General Packet Radio Service) to protect against eavesdropping GPRS between the base station and the phone. Now, a range of current phones still support them. In this paper, a differential fault attack on the GEA-like stream ciphers under the random fault model is proposed for the first time. In this attack, an efficient dedicated algorithm for identifying the exact fault location is proposed. By using this dedicated algorithm, the attacker can succeed in determining the exact fault location. As applications, practical differential fault attacks on the GPRS standard ciphers (i.e., GEA-1 and GEA-2) are presented, which recover the 64-bit secret keys of GEA-1 and GEA-2 with time complexities of${2^{{\mathrm{{33}}}{\mathrm{{.807}}}}}$and${2^{{\mathrm{{33}}}{\mathrm{{.858}}}}}$, respectively. We validate the cryptanalytic results by simulating the whole attacks on the platform ChipWhisperer Lite. The experimental results show that both GEA-1 and GEA-2 can be broken within sixteen minutes on a common laptop. Finally, the possible countermeasures are presented to protect the processed data of massive GPRS devices. Zhengting Li, Lin Ding 0001, An Wang 0001, Haotong Xu, Zheng Liu 0029, Jiang Wan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Cryptanalysis of the DIZY Stream Cipher With Provable SecurityabstractWith the increasing deployment of resource-constrained devices in daily life, ultra-lightweight ciphers become a necessity to tackle the security and privacy concerns in resource-constrained devices. In 2023, Gül and Kara studied the question of how to design a secure ultra-lightweight stream cipher with a small internal state, and introduced a new small-state stream cipher called DIZY. The cipher utilizes Truncated Pseudorandom Permutations (TPP) and has a provable security in the indistinguishability model. It consists of two versions, called DIZY-128 with a 128-bit key and DIZY-80 with an 80-bit key, respectively. In this paper, effective key recovery attacks on DIZY-80 and DIZY-128 are proposed. Both attacks leverage the weakness of DIZY that the attacker can easily reach a weak state in the middle of the initialization using chosen IVs. Based on constructing Hellman tables, the key recovery attacks on DIZY-80 and DIZY-128 are further improved. The cryptanalytic results show that DIZY-80/DIZY-128 can only provide a 65/86-bit security level against the key recovery attack, while it is claimed to provide an 80/112-bit security level by the designers. Finally, an improved variant of DIZY, called DIZYa, is proposed. The analysis on DIZYa shows that the improved variant can provide better security resistance against all known attacks including our attacks on DIZY, while maintaining the commendable characteristics of DIZY. This makes DIZYa a more suitable small-state stream cipher choice for resource-constrained devices like RFID tags. Zhengting Li, Lin Ding 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Enhanced Differential-Linear Cryptanalysis of Forró With MILPabstractARX-based design is a major building block of modern cryptographic ciphers due to its efficiency in software. Forró is an ARX-based stream cipher proposed by Coutinho et al. at ASIACRYPT 2022, which was designed to provide higher security margin than the ChaCha stream cipher. In this paper, we propose a full automated MILP model calledMinForró, to derive linear approximations for the Forró stream cipher. For the differential part, a two-stage strategy to search for single-bit differential trails with high differential correlations is presented, which helps us to find the first-ever 3-round differential trails for Forró. By combining the linear approximations obtained byMinForróand 3-round differential trail for Forró, we propose improved differential-linear distinguishers for 4-, 5-, 5.25-, 5.5-, 5.75-, 6-, 6.25- and 6.5-round Forró with complexities 232.44, 246, 250, 264.32, 287.12, 2117.92, 2174.92and 2226.88, respectively. The proposed differential-linear distinguishers for 4-, 5-, 5.25- and 5.5- round Forró significantly improve the existing distinguishers by factors of 24.11, 283.68, 2127.64and 2178.20, respectively. To the best of our knowledge, this is the first differential-linear distinguisher for Forró that reaches 6.5 rounds, which is a significant advancement over the existing record of 5.5 rounds. We have implemented the differential-linear distinguishers for 4- and 5- round Forró on a common PC, and the experimental results confirm the correctness of these distinguishers. Furthermore, when combined with theProbabilistic Neutral Bits(PNB) technique, we obtain key recovery attacks on 5.5-, 6-, 6.5- and 6.75-round Forró with time complexities 2149.20, 2151.84, 2213.49and 2251.97, respectively. The proposed key recovery attack on 5.5-round Forró significantly improves the time complexity of the existing attack by a factor of 275.84. To the best of our knowledge, this is the first key recovery attack on Forró that reaches 6.75 rounds, which is a significant advancement over the existing record of 5.5 rounds. Zhengting Li, Lin Ding 0001, Jiang Wan, Fan Zhang 0010 |
IEEE Trans. Inf. Theory | 1 |
| 2025 | TwoLayerF: A Two-Layer Framework of PNB-Based Key Recovery Attacks on ChaCha
Lin Ding 0001, Zhengting Li, Jiang Wan, Tairong Shi |
Inscrypt (1) | 3 |
| 2025 | Mixderive: A New Framework of Deriving Linear Approximations and Improved Differential-Linear Distinguishers for ChaCha
Zhengting Li, Lin Ding 0001, Jiang Wan |
ISPEC | 1 |
| 2025 | A New Cryptanalytic Technique on Bit-Oriented Stream Ciphers and Application to ACORN V3
Lin Ding 0001, Jiang Wan, Zhengting Li |
ISPEC | 4 |
| 2025 | Improved Differential-Linear Distinguishes on the ChaCha256 Stream CipherabstractChaCha is currently one of the most widely used symmetric ciphers. At FSE 2023, Bellini et al. proposed a four-round differential-linear distinguisher with a correlation of 2−34.15. Recently, Xu et al. improved the correlation of this four-round distinguisher to 2−32.2by considering the differential-linear hull effect. In this paper, we present a new linear approximation from 5-round to 6.5-round for ChaCha256. Combining this new linear approximation with the four-round differential-linear distinguisher, we propose the first differential-linear distinguisher for 6.5-round ChaCha256 with complexity 2112.84. Furthermore, we use the MILP tool to obtain a linear approximation from 6.5-round to 7-round, and then a new differential-linear distinguisher for 7-round ChaCha256 with complexity 2161.92is proposed. It is 24.97times faster than the previous best attack. Lin Ding 0001, Zhengting Li |
TrustCom | 3 |
| 2025 | Best Known Fast Correlation Attack on SNOW 3G Based on a New Insight
Lin Ding 0001, Jiang Wan, Zhengting Li |
IET Inf. Secur. | 4 |
| 2025 | Side Channel Attacks on GPRS Standard Encryption AlgorithmsabstractGEA-1 and its successor GEA-2 are stream ciphers that were selected as the General Packet Radio Service (GPRS) standard encryption algorithms, used to protect the communication between phones and base stations from eavesdropping. These stream ciphers, once widely used for GPRS encryption in the late 1990s and early 2000s, are surprisingly still supported in many current mobile phones and in numerous developing regions even today. GEA-2a is a more secure, improved version of GEA-2 designed by Ding et al. in 2022. Side channel attack utilizes easily accessible information from cryptographic devices, such as power consumption, electromagnetic radiation, and runtime, to obtain secret information in the cryptographic systems. Side channel attack is a powerful attack method that has been successfully applied in many stream ciphers, such as TRIVIUM and GRAIN-128-AEAD. In this article, we put forward an automated framework that can mount side channel attack on stream ciphers with structures similar to the GPRS standard encryption algorithms GEA-1 and GEA-2. We use satisfiability modulo theory for modeling, while considering the software and hardware implementation of the algorithms, and use Microsoft’s open source solver Z3 to solve the constructed instances. The experimental results indicate that the internal states of GEA-1, GEA-2, and GEA-2a in the keystream generation phase can be recovered practically under the HW/32 model. For models where the solution time is too long, by guessing a small number of bits, the state bits can be fully recovered within an acceptable time. Our automated framework is effective in both noiseless and noisy trace scenarios. Lin Ding 0001, Zhengting Li, Ziyu Guan |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | Breaking GEA-Like Stream Ciphers with Lower Time Cost
Lin Ding 0001, Zhengting Li |
ISPEC | 3 |
| 2024 | New Practical Attacks on GEA-1 Based on a New-Found WeaknessabstractGEA‐1, a proprietary stream cipher, was initially designed and used to protect against eavesdropping general packet radio service (GPRS) between the phone and the base station. Now, a variety of current mobile phones still support this standard cipher. In this paper, a structural weakness of the GEA‐1 stream cipher that has not been found in previous works is discovered and analyzed. That is the probability that two different inputs of GEA‐1 generate the identical keystream can be up to 2 −7.30 , which is quite high compared with an ideal stream cipher that generates random sequences. Based on this newfound weakness, a new practical distinguishing attack on GEA‐1 is proposed, which shows that the keystreams generated by GEA‐1 are far from random and can be easily distinguished with a practical time cost. After then, a new practical key recovery attack on GEA‐1 is presented. It has a time complexity of 2 21.02 GEA‐1 encryptions and requires only seven related keys, which is much less than the existing related key attack on GEA‐1. The experimental results show that GEA‐1 can be broken within about 41.75 s on a common PC in the related key setting. These cryptanalytic results show that GEA‐1 cannot provide enough security and should be immediately prohibited to be supported in the massive GPRS devices. Lin Ding 0001, Zhengting Li, Ziyu Guan |
IET Inf. Secur. | 3 |
| 2024 | Breaking the DECT Standard Cipher With Lower Time CostabstractThe DECT Standard Cipher (DSC) is a proprietary stream cipher used for encryption in the Digital Enhanced Cordless Telecommunications (DECT), which is a standard for short range cordless communication and widely deployed worldwide both in residential and enterprise environments. New weaknesses of the DSC stream cipher which are not discovered in previous works are explored and analyzed in this paper. Based on these weaknesses, new practical key recovery attacks and distinguishing attack on DSC with lower time cost are proposed. The first cryptanalytic result show that DSC can be broken in about 13.12 seconds in the known IV setting, when an offline phase that takes about 58.33 minutes is completed. After then, a distinguishing attack on DSC in the related key chosen IV setting is given, which has a time complexity of only 2 encryptions and a success probability of almost 1. Finally, based on the slide property, a key recovery attack on DSC with practical complexities is proposed. The experimental result shows that DSC can be broken on a common PC within about 44.97 seconds in the multiple related key setting. The attacks on DSC proposed in this paper clearly show that a well-designed initialization is absolutely necessary to design a secure stream cipher. Lin Ding 0001, Zhengting Li, Ziyu Guan |
IEEE Trans. Computers | 2 |