Yang Yu 0008

dblp:46/2181-8 · DBLP profile ↗
← Back
22ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0003-0120-0648ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 3 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Revisiting the Concrete Security of $\mathrm {\textsc {{Falcon}}}$-Type Signatures
Huiwen Jia, Shiduo Zhang, Yang Yu 0008, Chunming Tang 0003
PKC (1)3
2025 GPV Preimage Sampling with Weak Smoothness and Its Applications to Lattice Signatures
Shiduo Zhang, Huiwen Jia, Delong Ran, Yang Yu 0008, Yu Yu 0001, Xiaoyun Wang 0001
ASIACRYPT (3)4
2025 Do Not Disturb a Sleeping Falcon - Floating-Point Error Sensitivity of the Falcon Sampler and Its Consequences
Xiuhan Lin, Mehdi Tibouchi, Yang Yu 0008, Shiduo Zhang
EUROCRYPT (2)3
2025 Thorough Power Analysis on Falcon Gaussian Samplers and Practical Countermeasure
Xiuhan Lin, Shiduo Zhang, Yang Yu 0008, Weijia Wang 0003, Qidi You, Ximing Xu 0003, Xiaoyun Wang 0001
PKC (1)3
2025 Exploiting the Symmetry of $\mathbb {Z}^n$: Randomization and the Automorphism Problem
Kaijie Jiang 0001, Anyu Wang 0001, Hengyi Luo, Guoxiao Liu, Yang Yu 0008, Xiaoyun Wang 0001
J. Cryptol.5
2024 Compact Instruction Set Extensions for Kyber
abstract
Kyber is the only post-quantum cryptography (PQC) key encapsulation mechanism in the National Institute of Standards and Technology PQC project. This brief investigates the design of compact instruction set extensions (ISEs) for Kyber. We focus on implementing number-theoretic transform (NTT) and propose a hardware design of the modular multiplication based on an optimized$k^{2}$-reduction. Compared to other works, our design is more compact since the optimized$k^{2}$-reduction comprises multiplications with significantly smaller multipliers than Montgomery reduction and Barrett reduction. Then, we integrate the$k^{2}$-reduction into an instruction for the butterfly transformation. We also propose auxiliary instructions that can switch the half words between two registers to facilitate the rearranging coefficients in NTT. To showcase the advantage of the instructions, we implement the ISEs in a chip design for the Hummingbird E203 core. Compared to the software implementation on RISC-V with assembly code, our co-design implementations for NTT show a speedup by a factor of 2.6. Besides, the area overhead is 93 LUTs and 1 DSP without any additional resources of FFs and RAMs using Artix-7 FPGA, which is more compact than previous software–hardware co-designs of Kyber.
Lu Li 0006, Guofeng Qin, Yang Yu 0008, Weijia Wang 0003
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2023 On Gaussian Sampling, Smoothing Parameter and Application to Signatures
Thomas Espitau, Alexandre Wallet, Yang Yu 0008
ASIACRYPT (7)3
2023 Exploiting the Symmetry of $\mathbb {Z}^n$: Randomization and the Automorphism Problem
Kaijie Jiang 0001, Anyu Wang 0001, Hengyi Luo, Guoxiao Liu, Yang Yu 0008, Xiaoyun Wang 0001
ASIACRYPT (4)5
2023 Compact Lattice Gadget and Its Applications to Hash-and-Sign Signatures
Yang Yu 0008, Huiwen Jia, Xiaoyun Wang 0001
CRYPTO (5)1
2023 Improved Power Analysis Attacks on Falcon
Shiduo Zhang, Xiuhan Lin, Yang Yu 0008, Weijia Wang 0003
EUROCRYPT (4)3
2023 Lattice-based cryptosystems in standardisation processes: A survey
abstract
Abstract The current widely used public‐key cryptosystems are vulnerable to quantum attacks. To prepare for cybersecurity in the quantum era, some projects have been launched to call for post‐quantum alternatives. Due to solid security and desirable performance, lattice‐based cryptosystems are viewed as promising candidates in the upcoming standardisation of post‐quantum cryptography. This study surveys the lattice‐based cryptosystems in the post‐quantum standardisation processes including the NIST Post‐Quantum Cryptography Standardisation and the Chinese Cryptographic Algorithm Design Competition, from both design and security aspects. We present generic design paradigms of lattice‐based schemes and describe several representative proposals and recent progress. We also recap some main cryptanalytic results and methods for estimating the concrete security of lattice‐based schemes.
Anyu Wang 0001, Dianyan Xiao, Yang Yu 0008
IET Inf. Secur.3
2022 Shorter Hash-and-Sign Lattice-Based Signatures
Thomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008
CRYPTO (2)4
2022 Mitaka: A Simpler, Parallelizable, Maskable Variant of Falcon
abstract
This work describes the Mitaka signature scheme: a new hash-and-sign signature scheme over NTRU lattices which can be seen as a variant of NIST finalist Falcon . It achieves comparable efficiency but is considerably simpler, online/offline, and easier to parallelize and protect against side-channels, thus offering significant advantages from an implementation standpoint. It is also much more versatile in terms of parameter selection. We obtain this signature scheme by replacing the FFO lattice Gaussian sampler in Falcon by the “hybrid” sampler of Ducas and Prest, for which we carry out a detailed and corrected security analysis. In principle, such a change can result in a substantial security loss, but we show that this loss can be largely mitigated using new techniques in key generation that allow us to construct much higher quality lattice trapdoors for the hybrid sampler relatively cheaply. This new approach can also be instantiated on a wide variety of base fields, in contrast with Falcon ’s restriction to power-of-two cyclotomics. We also introduce a new lattice Gaussian sampler with the same quality and efficiency, but which is moreover compatible with the integral matrix Gram root technique of Ducas et al., allowing us to avoid floating point arithmetic. This makes it possible to realize the same signature scheme as Mitaka efficiently on platforms with poor support for floating point numbers. Finally, we describe a provably secure masking of Mitaka . More precisely, we introduce novel gadgets that allow provable masking at any order at much lower cost than previous masking techniques for Gaussian sampling-based signature schemes, for cheap and dependable side-channel protection.
Thomas Espitau, Pierre-Alain Fouque, François Gérard, Melissa Rossi, Akira Takahashi 0002, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008
EUROCRYPT (3)8
2021 Learning Strikes Again: The Case of the DRS Signature Scheme
Léo Ducas, Yang Yu 0008
J. Cryptol.2
2020 Integral Matrix Gram Root and Lattice Gaussian Sampling Without Floats
Léo Ducas, Steven D. Galbraith, Thomas Prest, Yang Yu 0008
EUROCRYPT (2)4
2020 Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU Lattices
Pierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008
EUROCRYPT (3)5
2018 Learning Strikes Again: The Case of the DRS Signature Scheme
Yang Yu 0008, Léo Ducas
ASIACRYPT (2)1
2018 Orthogonalized lattice enumeration for solving SVP
Zhongxiang Zheng, Xiaoyun Wang 0001, Guangwu Xu, Yang Yu 0008
Sci. China Inf. Sci.4
2018 Klepto for Ring-LWE Encryption
abstract
Due to its great efficiency and quantum resistance, public key cryptography based on Ring-LWE problem has drawn much attention in recent years. A batch of cryptanalysis works provided ever-improved security estimations for various Ring-LWE schemes, but few works discussed the security of Ring-LWE cryptography from kleptographic aspect. In this paper, we show how to embed a backdoor into a classic Ring-LWE encryption scheme so that partial bits of the plaintext are leaked to the owner of the backdoor. By theoretical analysis and experimental observations, we argue that the klepto Ring-LWE encryption scheme with such backdoor is feasible and practical.
Dianyan Xiao, Yang Yu 0008
Comput. J.2
2018 Improved broadcast attacks against subset sum problems via lattice oracle
Yang Yu 0008, Dianyan Xiao
Inf. Sci.1
2018 Cryptanalysis of Compact-LWE and Related Lightweight Public Key Encryption
abstract
In the emerging Internet of Things (IoT), lightweight public key cryptography plays an essential role in security and privacy protection. With the approach of quantum computing era, it is important to design and evaluate lightweight quantum-resistant cryptographic algorithms applicable to IoT. LWE-based cryptography is a widely used and well-studied family of postquantum cryptographic constructions whose hardness is based on worst-case lattice problems. To make LWE friendly to resource-constrained IoT devices, a variant of LWE, named Compact-LWE, was proposed and used to design lightweight cryptographic schemes. In this paper, we study the so-called Compact-LWE problem and clarify that under certain parameter settings it can be solved in polynomial time. As a consequence, our result leads to a practical attack against an instantiated scheme based on Compact-LWE proposed by Liu et al. in 2017.
Dianyan Xiao, Yang Yu 0008
Secur. Commun. Networks2
2017 Second Order Statistical Behavior of LLL and BKZ
Yang Yu 0008, Léo Ducas
SAC1