Willi Meier

dblp:47/6600 · DBLP profile ↗
← Back
71ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0003-4594-1501ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 61 · 5 first-author · 15 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Systems, architecture and hardware · 4Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Finding the Inverse of some Shift Invariant Transformations
Fukang Liu, Vaibhav Dixit, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
J. Cryptol.4
2025 Vectorial Fast Correlation Attacks
Bin Zhang 0003, Ruitao Liu, Willi Meier, Siwei Sun, Dengguo Feng, Wenling Wu
ASIACRYPT (1)3
2024 Modelling Ciphers with Overdefined Systems of Quadratic Equations: Application to Friday, Vision, RAIN and Biscuit
Fukang Liu, Mohammad Mahzoun, Willi Meier
ASIACRYPT (7)3
2023 Near Collision Attack Against Grain V1
Subhadeep Banik, Daniel Collins 0001, Willi Meier
ACNS (1)3
2023 Coefficient Grouping for Complex Affine Layers
Fukang Liu, Lorenzo Grassi 0001, Clémence Bouvier, Willi Meier, Takanori Isobe 0001
CRYPTO (3)4
2023 Coefficient Grouping: Breaking Chaghri and More
Fukang Liu, Ravi Anand, Willi Meier, Takanori Isobe 0001
EUROCRYPT (4)4
2023 Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILP
Fukang Liu, Gaoli Wang, Santanu Sarkar 0001, Ravi Anand, Willi Meier, Yingxin Li, Takanori Isobe 0001
EUROCRYPT (4)5
2023 Differential cryptanalysis of Mod-2/Mod-3 constructions of binary weak PRFs
abstract
Pseudo-random functions are a fundamental building block in many cryptographic applications. In certain scenarios, a weaker notion (where security is restricted to uniformly random input), but more computationally efficient, called weak pseudo-random functions, is sufficient. In this work, we present new differential attacks on the main binary weak pseudo-random function constructions, namely the so-called Alternative Mod-2/Mod-3. For the Alternative Mod-2/Mod-3 wPRF, the best distinguisher proposed by Cheon et al. achieves O(20.21n) complexity, where n is the input length. We show that our attack asymptotically outperforms this and requires far fewer samples that can be applied in restricted oracle settings. By minimizing computational complexity, we can achieve O(20.166n) complexity. Additionally, in a small experiment, we indicate that their proposed fix of using keys with large Hamming weight is even more vulnerable to our attack.
Thomas Johansson 0001, Willi Meier
ISIT2
2023 A Closer Look at the S-Box: Deeper Analysis of Round-Reduced ASCON-HASH
Xiaorui Yu, Fukang Liu, Gaoli Wang, Siwei Sun, Willi Meier
SAC5
2023 Differential-Aided Preimage Attacks On Round-Reduced Keccak
abstract
Abstract At FSE 2008, Leurent introduced the preimage attack on MD4 by exploiting differential trails. In this paper, we apply the differential-aided preimage attack to Keccak with the message modification techniques. Instead of directly finding the preimage, we exploit differential characteristics to modify the messages, so that the differences of their hashing values and the changes of given target can be controlled. By adding some constraints, a trail can be used to change one bit at a time and reduce the time complexity by a factor of 2. When the number of rounds increases, we introduce two-stage modification techniques to satisfy part of constraints as well. In order to solve other constraints, we also combine the linear-structure technique and accordingly give a preimage attack on 5-round Keccak[$r=1440,c=160,l=80$].
Congming Wei, Xiaoyang Dong 0001, Willi Meier, Lingyue Qin, Ximing Fu
Comput. J.3
2022 Algebraic Meet-in-the-Middle Attack on LowMC
Fukang Liu, Santanu Sarkar 0001, Gaoli Wang, Willi Meier, Takanori Isobe 0001
ASIACRYPT (1)4
2022 The Inverse of χ and Its Applications to Rasta-Like Ciphers
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
J. Cryptol.3
2022 Revisiting Cryptanalysis on ChaCha From Crypto 2020 and Eurocrypt 2021
abstract
ChaCha has been one of the most prominent ARX designs of the last few years because of its use in several systems. The cryptanalysis of ChaCha involves a differential attack that exploits the idea of Probabilistic Neutral Bits (PNBs). For a long period, the single-bit distinguisher in this differential attack was found up to 3rd round. At Crypto 2020, Beierle et al. introduced for the first time the single bit distinguishers for 3.5th round, which contributed significantly to regaining the flow of the research work in this direction. This discovery became the primary factor behind the huge improvement in the key recovery attack complexity in that work. This was followed by another work at Eurocrypt 2021, where a single bit distinguisher at 3.5th round helped to produce a 7th round distinguisher of ChaCha and a further improvement in the key recovery. In this paper, first, we provide the theoretical framework for the distinguisher given by Beierle et al. We mathematically derive the observed differential correlation for the particular position where the output difference is observed at 3.5th round. Also, Beierle et al. mentioned the issue of the availability of proper IVs to produce such distinguishers, and pointed out that not all keys have such IVs available. Here we provide a theoretical insight of this issue. Next, we revisit the work of Coutinhoet al.(Eurocrypt 2021). Using Differential-Linear attacks against ChaCha, they claimed the distinguisher and the key recovery with complexities 2218and$2^{228.51}$respectively. We show that the differential correlation for the 3.5th round is much smaller than the claim of Coutinho et al. This makes the attack complexities much higher than their claim.
Sabyasachi Dey 0001, Chandan Dey, Santanu Sarkar 0001, Willi Meier
IEEE Trans. Inf. Theory4
2021 Algebraic Attacks on Round-Reduced Keccak
Fukang Liu, Takanori Isobe 0001, Willi Meier, Zhonghao Yang 0003
ACISP3
2021 Algebraic Attacks on Rasta and Dasta Using Low-Degree Equations
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
ASIACRYPT (1)3
2021 Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier, Hirotaka Yoshida
CANS4
2021 Cryptanalysis of Full LowMC and LowMC-M with Algebraic Techniques
Fukang Liu, Takanori Isobe 0001, Willi Meier
CRYPTO (3)3
2021 Interpolation Attacks on Round-Reduced Elephant, Kravatte and Xoofff
abstract
Abstract We introduce an interpolation attack using the Moebius Transform. This can reduce the time complexity to get a linear system of equations for specified intermediate state bits, which is general to cryptanalysis of some ciphers with update function of low algebraic degree. Along this line, we perform an interpolation attack against Elephant-Delirium, a round 2 submission of the ongoing national institute of standards and technology (NIST) lightweight cryptography project. This is the first third-party cryptanalysis on this cipher. Moreover, we promote the interpolation attack by applying it to the Farfalle pseudo-random constructions Kravatte and Xoofff. Our attacks turn out to be the most efficient method for these ciphers thus far.
Rui Zong, Xiaoyang Dong 0001, Keting Jia, Willi Meier
Comput. J.5
2021 Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
J. Cryptol.3
2020 Automatic Verification of Differential Characteristics: Application to Reduced Gimli
Fukang Liu, Takanori Isobe 0001, Willi Meier
CRYPTO (3)3
2020 Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
EUROCRYPT (1)3
2020 Practical Key-Recovery Attacks On Round-Reduced Ketje Jr, Xoodoo-AE And Xoodyak
abstract
Abstract A new conditional cube attack was proposed by Li et al. at ToSC 2019 for cryptanalysis of Keccak keyed modes. In this paper, we find a new property of Li et al.’s method. The conditional cube attack is modified and applied to cryptanalysis of 5-round Ketje Jr, 6-round Xoodoo-AE and Xoodyak, where Ketje Jr is among the third round CAESAR competition candidates and Xoodyak is a Round 2 submission of the ongoing NIST lightweight cryptography project. For the updated conditional cube attack, all our results are shown to be of practical time complexity with negligible memory cost, and test codes are provided. Notably, our results on Xoodyak represent the first third-party cryptanalysis for Xoodyak.
Zheng Li 0008, Xiaoyang Dong 0001, Keting Jia, Willi Meier
Comput. J.5
2020 New cube distinguishers on NFSR-based stream ciphers
Abhishek Kesarwani 0002, Dibyendu Roy 0001, Santanu Sarkar 0001, Willi Meier
Des. Codes Cryptogr.4
2020 Generalized related-key rectangle attacks on block ciphers with linear key schedule: applications to SKINNY and GIFT
Boxin Zhao, Xiaoyang Dong 0001, Willi Meier, Keting Jia, Gaoli Wang
Des. Codes Cryptogr.3
2019 Cryptanalysis of ForkAES
Subhadeep Banik, Jannis Bossert, Amit Jana, Eik List, Stefan Lucks, Willi Meier, Mostafizar Rahman, Dhiman Saha, Yu Sasaki 0001
ACNS6
2019 On the Data Limitation of Small-State Stream Ciphers: Correlation Attacks on Fruit-80 and Plantlet
Yosuke Todo, Willi Meier, Kazumaro Aoki
SAC2
2019 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
abstract
At CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively.
Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001
IEEE Trans. Computers5
2019 A New Cube Attack on MORUS by Using Division Property
abstract
MORUS is an authenticated encryption algorithm and one of the candidates in the CAESAR competition. Currently, the security of MORUS received extensive attention. In this paper, a new existence terms detection method in superpoly recovery phase in cube attack is proposed. More precisely, the upper bounding degree of superpoly is first estimated by using the cube attack based on the division property with Mixed Integer Linear Programming tool. Moreover, the t-degree monomials that may be involved in the superpoly are divided into two groups, where the elements of the first group can be directly determined without using the solver via the embedded property. Compared with previous methods, the time consumption by the solvers of our new method is reduced significantly. In particular, the truth table from only the existent terms can be used to recover the superpoly in the offline phase of the cube attack. Therefore, the time complexity of cube attack can be further reduced. As illustrative example, the security of the reduced-step variants of MORUS-640-128 against cube attack is evaluated by using this new method. It is demonstrated that the key recovery attacks can be applied to 6/7-step MORUS-640-128. Furthermore, some integral distinguishers of 7-step MORUS-640-128/MORUS-1280-256 are achieved.
Yongzhuang Wei, Willi Meier
IEEE Trans. Computers3
2018 A Key-Recovery Attack on 855-round Trivium
Ximing Fu, Xiaoyun Wang 0001, Xiaoyang Dong 0001, Willi Meier
CRYPTO (2)4
2018 Fast Correlation Attack Revisited - Cryptanalysis on Full Grain-128a, Grain-128, and Grain-v1
Yosuke Todo, Takanori Isobe 0001, Willi Meier, Kazumaro Aoki, Bin Zhang 0003
CRYPTO (2)3
2018 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier
CRYPTO (1)6
2018 Fast Near Collision Attack on the Grain v1 Stream Cipher
Bin Zhang 0003, Willi Meier
EUROCRYPT (2)3
2018 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
abstract
The cube attack is a powerful cryptanalytic technique and is especially powerful against stream ciphers. Since we need to analyze the complicated structure of a stream cipher in the cube attack, the cube attack basically analyzes it by regarding it as a blackbox. Therefore, the cube attack is an experimental attack, and we cannot evaluate the security when the size of cube exceeds an experimental range, e.g., 40. In this paper, we propose cube attacks on non-blackbox polynomials. Our attacks are developed by using the division property, which is recently applied to various block ciphers. The clear advantage is that we can exploit large cube sizes because it never regards the cipher as a blackbox. We apply the new cube attack to Trivium, Grain128a, ACORN and Kreyvium. As a result, the secret keys of 832-round Trivium, 183-round Grain128a, 704-round ACORN and 872-round Kreyvium are recovered. These attacks are the current best key-recovery attack against these ciphers.
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
IEEE Trans. Computers4
2017 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
CRYPTO (3)4
2017 Truncated differential based known-key attacks on round-reduced SIMON
Yonglin Hao, Willi Meier
Des. Codes Cryptogr.2
2015 Optimized Interpolation Attacks on LowMC
Itai Dinur, Yunwen Liu, Willi Meier, Qingju Wang 0001
ASIACRYPT (2)3
2015 Fast Correlation Attacks over Extension Fields, Large-Unit Linear Approximation and Cryptanalysis of SNOW 2.0
Bin Zhang 0003, Willi Meier
CRYPTO (1)3
2014 Dependence in IV-Related Bytes of RC4 Key Enhances Vulnerabilities in WPA
Sourav Sen Gupta 0001, Subhamoy Maitra, Willi Meier, Goutam Paul 0001, Santanu Sarkar 0001
FSE3
2013 Quark: A Lightweight Hash
Jean-Philippe Aumasson, Luca Henzen, Willi Meier, María Naya-Plasencia
J. Cryptol.3
2012 Conditional Differential Cryptanalysis of Grain-128a
Michael Lehmann, Willi Meier
CANS2
2011 Cryptanalysis of the Knapsack Generator
Simon Knellwolf, Willi Meier
FSE2
2011 Fast Correlation Attacks: Methods and Countermeasures
Willi Meier
FSE1
2011 VLSI Characterization of the Cryptographic Hash Function BLAKE
abstract
Cryptographic hash functions are used to protect information integrity and authenticity in a wide range of applications. After the discovery of weaknesses in the current deployed standards, the U.S. Institute of Standards and Technology started a public competition to develop the future standard SHA-3, which will be implemented in a multitude of environments, after its selection in 2012. In this paper, we investigate high-speed and low-area hardware architectures of one of the 14 “second-round” candidates in this competition: BLAKE. VLSI performance results of the proposed high-speed designs indicate a throughput improvement between 16% and 36% compared to the current standard SHA-2. Additionally, we propose a compact implementation of BLAKE with memory optimization that fits in 0.127 mm2of a 0.18 μ m CMOS. Measurements reveal a minimal power dissipation of 9.59 μW/MHz at 0.65 V, which suggests that BLAKE is suitable for resource-limited systems.
Luca Henzen, Jean-Philippe Aumasson, Willi Meier, Raphael C.-W. Phan
IEEE Trans. Very Large Scale Integr. Syst.3
2010 Conditional Differential Cryptanalysis of NLFSR-Based Cryptosystems
Simon Knellwolf, Willi Meier, María Naya-Plasencia
ASIACRYPT2
2010 Quark: A Lightweight Hash
Jean-Philippe Aumasson, Luca Henzen, Willi Meier, María Naya-Plasencia
CHES3
2010 Differential and Invertibility Properties of BLAKE
Jean-Philippe Aumasson, Jian Guo 0001, Simon Knellwolf, Krystian Matusiewicz, Willi Meier
FSE5
2010 Cryptanalysis of ESSENCE
María Naya-Plasencia, Andrea Röck, Jean-Philippe Aumasson, Yann Laigle-Chapuy, Gaëtan Leurent, Willi Meier, Thomas Peyrin
FSE6
2009 Inside the Hypercube
Jean-Philippe Aumasson, Eric Brier, Willi Meier, María Naya-Plasencia, Thomas Peyrin
ACISP3
2009 Improved Cryptanalysis of Skein
Jean-Philippe Aumasson, Çagdas Çalik, Willi Meier, Onur Özen, Raphael C.-W. Phan, Kerem Varici
ASIACRYPT3
2009 Linearization Framework for Collision Attacks: Application to CubeHash and MD6
Eric Brier, Shahram Khazaei, Willi Meier, Thomas Peyrin
ASIACRYPT3
2009 Cube Testers and Key Recovery Attacks on Reduced-Round MD6 and Trivium
Jean-Philippe Aumasson, Itai Dinur, Willi Meier, Adi Shamir
FSE3
2008 New Features of Latin Dances: Analysis of Salsa, ChaCha, and Rumba
Jean-Philippe Aumasson, Simon Fischer 0002, Shahram Khazaei, Willi Meier, Christian Rechberger
FSE4
2008 The Hash Function Family LAKE
Jean-Philippe Aumasson, Willi Meier, Raphael C.-W. Phan
FSE2
2007 TCHo: A Hardware-Oriented Trapdoor Cipher
Jean-Philippe Aumasson, Matthieu Finiasz, Willi Meier, Serge Vaudenay
ACISP3
2007 Algebraic Immunity of S-Boxes and Augmented Functions
Simon Fischer 0002, Willi Meier
FSE2
2006 Efficient Computation of Algebraic Immunity for Algebraic and Fast Algebraic Attacks
Frederik Armknecht, Claude Carlet, Philippe Gaborit, Simon Fischer 0002, Willi Meier, Olivier Ruatta
EUROCRYPT5
2006 Cryptanalysis of Achterbahn
Thomas Johansson 0001, Willi Meier, Frédéric Muller
FSE2
2006 A Stream Cipher Proposal: Grain-128
abstract
A new stream cipher, Grain-128, is proposed. The design is very small in hardware and it targets environments with very limited resources in gate count, power consumption, and chip area. Grain-128 supports key size of 128 bits and IV size of 96 bits. The design is very simple and based on two shift registers, one linear and one nonlinear, and an output function
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier
ISIT4
2005 The Conditional Correlation Attack: A Practical Attack on Bluetooth Encryption
Yi Lu 0002, Willi Meier, Serge Vaudenay
CRYPTO2
2004 Algebraic Attacks and Decomposition of Boolean Functions
Willi Meier, Enes Pasalic, Claude Carlet
EUROCRYPT1
2003 Algebraic Attacks on Stream Ciphers with Linear Feedback
Nicolas T. Courtois, Willi Meier
EUROCRYPT2
2003 Predicting the Shrinking Generator with Fixed Connections
Patrik Ekdahl, Willi Meier, Thomas Johansson 0001
EUROCRYPT2
2001 Analysis of SSC2
Daniel Bleichenbacher, Willi Meier
FSE2
2000 Correlations in RC6 with a Reduced Number of Rounds
Lars R. Knudsen, Willi Meier
FSE2
1999 Cryptanalysis of an Identification Scheme Based on the Permuted Perceptron Problem
Lars R. Knudsen, Willi Meier
EUROCRYPT2
1998 Analysis Methods for (Alleged) RC4
Lars R. Knudsen, Willi Meier, Bart Preneel, Vincent Rijmen, Sven Verdoolaege
ASIACRYPT2
1996 Improved Differential Attacks on RC5
Lars R. Knudsen, Willi Meier
CRYPTO2
1992 Efficient Multiplication on Certain Nonsupersingular Elliptic Curves
Willi Meier, Othmar Staffelbach
CRYPTO1
1992 Correlation Properties of Combiners with Memory in Stream Ciphers
Willi Meier, Othmar Staffelbach
J. Cryptol.1
1990 Cryptographic Significance of the Carry for Ciphers Based on Integer Addition
Othmar Staffelbach, Willi Meier
CRYPTO2
1989 Fast Correlation Attacks on Certain Stream Ciphers
Willi Meier, Othmar Staffelbach
J. Cryptol.1