VLDB 2026 Research / reviewers in the wild / expert
Chenhui Jin
dblp:57/3168
· DBLP profile ↗
58ranked-venue papers
0as first author
28since 2021 · last 2026
0000-0003-4941-7133ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 12 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 since 2021Theory of computation · 8 · 7 since 2021Computer networks · 5 · 5 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting Linear Distinguishing Attacks on SNOW 2.0 Stream CipherabstractSNOW 2.0 is a word-oriented stream cipher that has been standardized by ISO/IEC 18033-4. At FSE 2006, Nyberg et al. proposed a linear distinguisher for SNOW 2.0 with absolute correlation 2−85:89, derived from four linear approximations of the Finite State Machine (FSM). When deriving the overall correlation, they assumed these four linear approximations to be mutually independent. However, they are in fact dependent because of a shared variable, which leads to the inaccuracy of the correlation calculation. Moreover, they impose the unnecessary restriction that all masks of the distinguisher must be identical, artificially limiting the search space and yielding inaccurate conclusions about the minimum number of active S-boxes. To resolve these contradictions, we first establish a general SNOW 2.0 linear distinguisher without any unnecessary restrictions. Secondly, we present and prove an exact formula to calculate the correlations of the general SNOW 2.0 distinguishers, thereby correcting the current best absolute correlation from 2−85:89to 2−86:14. Thirdly, we establish an Mixed Integer Linear Programming (MILP) model to search for the optimal SNOW 2.0 linear approximation trail, which will be used to derive both the optimal linear approximation trail and the minimum number of active S-boxes. The results prove that the maximum absolute correlation of the SNOW 2.0 linear approximation trail is no higher than 2−75. Consequently, if the maximum absolute correlation of the linear approximation trail is taken as the security measure, then SNOW 2.0 can guarantee the 128-bit security level against the linear distinguishing attack. Based on the MILP model, we prove that the minimum number of active S-boxes of the linear distinguisher is 12, not 14 as previously reported. Finally, we observe that the identical distinguisher masks tend to yield high absolute correlation. We therefore exhaustively enumerate this large class of distinguishers and find that the best absolute correlation remains 2−86:14. Then the time/data complexity of the linear distinguishing attack on SNOW 2.0 can be evaluated as 2172:28. Additionally, our formula reveals another distinguisher whose true correlation is 2−88:37, while the result calculated by the original formula is 2−107:23. These results demonstrate that ignoring the dependency among approximations can lead to significant underestimation of the correlation. Sudong Ma, Chenhui Jin, Qiuling He, Jie Guan, Ting Cui, Lin Ding 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Key committing attack on Tiaoxin-346 algorithmabstractAbstract Key committing security is a crucial metric of authentication encryption schemes, complementing the fundamental principles of confidentiality and integrity. It ensures that an adversary cannot decrypt a given ciphertext to different sets of key, nonce, and associated data. In this study, we explore a key committing attack on the authenticated encryption stream cipher Tiaoxin-346 from the perspective of internal state collisions. We establish a more rigorous constraint within the FROB framework by identifying a different settings of $$\left( k_{2}, Nonce, AD^{*}\right)$$ k 2 , N o n c e , A D ∗ for any specified $$\left( k_{1}, Nonce, AD_{1}\right)$$ k 1 , N o n c e , A D 1 . Specifically, we demonstrate that for the Tiaoxin-346 algorithm, it is possible to find another settings of key $$k_{2}$$ k 2 and associated data $$AD^{*}$$ A D ∗ with a computational complexity of O(1), given any key $$k_{1}$$ k 1 and $$AD_{1}$$ A D 1 . We provide a detailed explanation of the rationale and a step-by-step methodology for constructing an internal state collision at the seventh round of the update process, aimed at recovering the appropriate $$AD^{*}$$ A D ∗ . Notably, the computational complexity of our attack is O(1), significantly lower than the generic attack complexity of $$O\left( 2^{64}\right)$$ O 2 64 , which effectively violates the key commitment security of Tiaoxin-346. The results of this study contribute to refining the security of authenticated encryption algorithms and offer valuable insights for the design of round update functions in AES-based schemes. Chenhui Jin |
Cybersecur. | 2 |
| 2025 | Fast computation of linear approximation of general word-oriented composite function
Sudong Ma, Chenhui Jin, Jie Guan, Ziyu Guan |
Discret. Appl. Math. | 2 |
| 2025 | A novel distinguishing attack on RoccaabstractAbstract The security of an encryption algorithm often hinges on the indistinguishability between ciphertext and random numbers. In block ciphers, pseudorandomness and super‐pseudorandomness are commonly used to depict the indistinguishability between ciphertext and random numbers. Whereas, stream cipher algorithms can be viewed as functions of variables such as the key K, initialization vector IV, and plaintext M. For an ideal stream cipher algorithm, the ciphertext sequences for any two different plaintexts should exhibit good independence across various K‐IV pairs. Consequently, the probability of the two ciphertext sequences being equal or having sufficiently long matching segments should be negligible. This study examines a new type of attack that stems from key commitment attacks. By exploiting the independence between the ciphertext sequences, a novel distinguishing attack against the stream cipher is constructed and applied to the encryption of Rocca. Focusing on the authenticated encryption algorithm Rocca, a guess‐and‐determine method is employed to demonstrate that for any plaintext and two different sets of , another plaintext can be found with a time complexity , resulting in identical ciphertext sequences except for the initial bits. Furthermore, it is proved that under chosen plaintext conditions, the time complexity of this distinguishing attack is . These findings imply that Rocca does not offer 256‐bit security against such distinguishing attacks, providing valuable insights into the design of round update functions for stream ciphers like Rocca. Chenhui Jin, Jie Guan, Ting Cui |
IET Commun. | 2 |
| 2025 | Differential fault attack on the XOR version of SNOW 5G stream cipher
Wenhao Liu 0002, Chenhui Jin |
J. Inf. Secur. Appl. | 2 |
| 2025 | Improved Methods to Solve Nonlinear Invariants with Low Algebraic Degree for Linear Transformation
Zebin Wang, Chenhui Jin, Jiyan Zhang, Ting Cui |
Theory Comput. Syst. | 2 |
| 2025 | Provable Security Evaluations of XOR-Versions of SNOW Family Stream Ciphers Against Fast Correlation AttacksabstractFast correlation attack is one of the most powerful attack methods for LFSR-based stream ciphers, and the primary problem of the attack is to construct the linear approximations with great absolute correlations. For some stream ciphers with complex structures of linear approximations, the search for the maximum absolute correlation of linear approximations has always been a difficult problem because of the extremely high amount of masks that need to be searched. In this paper, an analysis method for searching maximum absolute correlation based on the linear mask structure is developed, including the filtering technology based on mask propagation trail, a structural characteristic of linear approximations of linear transformations with fewer active bytes, and linear approximation equivalence theorem of composite function composed of the parallel identical S-boxes and linear transformation. These methods efficiently reduce the exhaustive time complexity of the masks. As applications, this paper proves that the suprema of absolute correlations of all the linear approximations for the five XOR-versions of SNOW family stream ciphers (i.e., SNOW 2.0⊕, SNOW 3G⊕, SNOW-V⊕, SNOWVi⊕, SNOW 5G⊕) are 2−9/2−15:893/2−37:964/2−37:964/2−37:964. The exhaustive time complexity of the masks can be reduced fromO(232)/O(296)/O(2384)/O(2384)/O(2384) toO(224)/O(231.98)/O(239.98)/O(239.98)/O(239.98), respectively. Furthermore, we give the provable security evaluations of the five ciphers against fast correlation attacks under the success probability of 0:99 for the known fast correlation attack method. For SNOW-V⊕/SNOW-Vi⊕/SNOW 5G⊕, the time/data/memory complexity of the optimal fast correlation attacks are allO(2227.54)/O(2227.72)/O(2227.72). The results show that SNOWV⊕/SNOW-Vi⊕/SNOW 5G⊕cannot guarantee the claimed 256- bit key security for the known fast correlation attack methods if we ignore the design constraint that the maximum length of keystream for a single pair of key and IV is 264. For SNOW 2.0⊕and SNOW 3G⊕, the time/data/memory complexity of the optimal fast correlation attacks areO(2151.94)/O(2151.35)/O(2151.35) andO(2165.91)/O(2165.43)/O(2165.43), respectively. The results show that both SNOW 2.0⊕and SNOW 3G⊕can guarantee the claimed 128-bit key security for the known fast correlation attack methods. In addition, this paper also discusses that the existing fast correlation attacks based on multiple linear approximations are invalid for these five ciphers. Sudong Ma, Chenhui Jin, Xinxin Gong, Senpeng Wang, Ting Cui, Lin Ding 0001, Jie Guan |
IEEE Trans. Inf. Theory | 2 |
| 2024 | A Second Preimage Attack on the XOR Hash CombinerabstractThe exclusive‐or (XOR) hash combiner is a classical hash function combiner, which is well known as a good PRF and MAC combiner, and is used in practice in TLS versions 1.0 and 1.1. In this work, we analyze the second preimage resistance of the XOR combiner underlying two different narrow‐pipe hash functions with weak ideal compression functions. To control simultaneously the behavior of the two different hash functions, we develop a new structure called multicollision‐and‐double‐diamond. Multicollision‐and‐double‐diamond structure is constructed using the idea of meet‐in‐the‐middle technique, combined with Joux’s multicollision and Chen’s inverse‐diamond structure. Then based on the multicollision‐and‐double‐diamond structure, we present a second preimage attack on the XOR hash combiner with the time complexity of about O ((2 n + 1)2 n /2 + ( n − l )2 n − l + ( n − k )2 n − k + 2 l +1 + 2 k +1 ) ( n is the size of the XOR hash combiner and l and k are respectively the depths of the two inverse‐diamond structures), less than the ideal time complexity O (2 n ), and memory of about O (2 k + 2 l ). Ting Cui, Chenhui Jin, Congjun Wang |
IET Inf. Secur. | 3 |
| 2024 | Unveiling the Neutral Difference and Its Automated SearchabstractGiven a differential characteristic and an existing plaintext pair that satisfies it (referred to as a right pair), generating additional right pairs at a reduced cost is an appealing prospect. The neutral bit technique, referred to as neutral differences throughout this paper, provides a solution to this challenge. Traditionally, the search for neutral differences has heavily depended on experimental testing, leading to limitations in the search range. In this work, we propose the neutral difference table and establish a link between boomerang cryptanalysis and neutral differences. Furthermore, we propose an automated search for neutral differences to address the problem of a limited search range of neutral differences, as previous approaches relied on experimental testing. This approach provides a basis for the subspace spanned by the neutral differences, and we apply this technique to both SPECK32 and LEA, where the predicted results closely match the experimental ones. Consequently, we present the improved differential‐linear distinguishers for SPECK32 and LEA, along with the 18‐round attacks on LEA192 and LEA256 with the lowest time complexity up to date. Guangqiu Lv, Chenhui Jin, Ting Cui |
IET Inf. Secur. | 2 |
| 2024 | Differential-Invariant Subspace Cryptanalysis - A Real-Time Attack Against IoT-Friendly Word-Based Block CiphersabstractThis paper considers a new cryptanalysis called differential invariant subspace cryptanalysis, which can be used to evaluate the security of IoT-friendly word-based block ciphers. This cryptanalysis estimates the behavior of differential propagation for particularly chosen input differences, and applies to the ciphers contain only the word-based components, e.g., word-based S-boxes, word-based linear mappings, etc. Firstly, this paper proves that, for any word-based block cipher, if the S-box causes the differential invariant subspace property, it then indicates a full-round distinguisher with probability 1, even if the target cipher is believed to be resistant enough against traditional differential or linear cryptanalysis. Secondly, a class of linear-equivalent S-boxes meeting the differential invariant subspace property are constructed as L∘S∘L-1, where L is any invertible linear mapping and S is a group of S-boxes in parallel. Finally, as application, we provide a full-round differential invariant subspace distinguisher for the variant Midori128 (the only difference is that the variant version utilizes only one single type S-box instead of four types). This distinguishing is experimentally verified and could be executed within negligible time. Ting Cui, Yi Zhang 0116, Jiyan Zhang, Chenhui Jin |
IEEE Internet Things J. | 4 |
| 2024 | Congruent Differential Cluster for Binary SPN CiphersabstractThis study is focused on the differential clustering effect of the SPN block cipher, which employs a binary matrix as its diffusion layer. We present a novel strategy for differential estimation, named the congruent differential cluster. This method does not guarantee the optimization of each single differential characteristic but gathers a large number of characteristics satisfying a specific condition, i.e., the output differences of active S-boxes are equal. Given a binary SPN cipher, the exact probability of the congruent differential cluster can be obtained with negligible computational resources. Moreover, we consider a popular instance, binary AES-like ciphers, since the processing of their column-mixing layer can be divided into several independent parts. Therefore, if we set the output differences of the active S-boxes in the same partition to be equal, we can obtain more differential characteristics in the cluster, known as a semicongruent differential cluster. To demonstrate the application of the proposed method, we apply it to several block ciphers, i.e., Midori-64, CRAFT-64, SKINNY-64 and their variants proposed in [1]. Compared with the active S-box counting method, the congruent differential clusters have considerably higher probabilities for most instances. In addition, we find a 7-round semicongruent differential cluster for Midori-64 with probability 2-52.25, an 8-round semicongruent differential cluster for SKINNY-64 with probability 2-50.72and a 10-round semicongruent differential cluster for CRAFT-64 with probability 2-42.32. To the best of our knowledge, the semicongruent differential clusters we identify for 7-round Midori-64, 8-round SKINNY-64 and 10-round CRAFT-64 have the highest probabilities thus far among the existing differential clusters with the same rounds. Therefore, we believe that the proposed method is a valuable tool for evaluating the differential security of associated block ciphers. Ting Cui, Yiming Mao 0011, Jiyan Zhang, Chenhui Jin |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Improved Fast Correlation Attack Using Multiple Linear Approximations and Its Application on SOSEMANUKabstractAt CRYPTO 2018, Todo et al. proposed an effective fast correlation attack using multiple linear approximations, and gave effective attacks on the Grain-like stream ciphers with the same size of LFSR and key. However, many stream ciphers require that the size of LFSR must be at least twice the key size. For this type of stream ciphers, we propose an improved fast correlation attack using multiple linear approximations. The main idea is to reduce the number of attacked bits of parity-check equations by XORing the same linear approximation at different clocks, and then further bypass some unknown variables of parity-check equations by multiple linear approximations with an expected probability. Finally, full unknown variables are recovered by solving systems of linear equations. SOSEMANUK is one of the finalists in the eSTREAM project. The best absolute correlation of linear approximations of SOSEMANUK we found is 2-20.84, which improves the linear approximations with current best absolute correlation of 2-21.41. Finally, the improved fast correlation attack method is applied to SOSEMANUK, and a fast correlation attack with time/data/memory complexity ofO(2139.75)/O(2139.37)/O(2139.37) is given, and the success probability is 0.99. It improves the current best fast correlation attack with time/data/memory complexity ofO(2147.88)/O(2145.5)/O(2147.1) (ASIACRYPT 2008). For the optional key size ranging from 128-bit to 256-bit of SOSEMANUK, our attack result shows that SOSEMANUK can only guarantee the security of 140-bit key. In addition, we declare that our new fast correlation attack method can be applied to the linear analysis of other LFSR-based stream ciphers. Sudong Ma, Chenhui Jin, Jie Guan, Ting Cui |
IEEE Trans. Inf. Theory | 2 |
| 2024 | Correlation Attacks on SNOW-V-Like Stream Ciphers Based on a Heuristic MILP ModelabstractSNOW-V and SNOW-Vi are two new LFSR-based stream ciphers of the SNOW family designed for the 5G mobile communication system. Correlation attack is a well-known cryptanalysis tool for LFSR-based stream ciphers. The first step of a correlation attack is to establish a linear approximation of the cipher with high correlation. The process can be modeled and solved by automatic techniques. How to efficiently model the 8-bit S-box and how to give an effective search strategy are two challenges to automatically search for linear approximations of SNOW-V-like ciphers. For the first problem, we propose a divide-and-conquer dimension reduction method for modeling large S-boxes with Mixed Integer Linear Programming (MILP). It can transform the problem of modeling a high-dimensional set into sub-problems of modeling some low-dimensional sets. For the second problem, we propose an efficient heuristic MILP search algorithm for SNOW-V-like ciphers, which is applied to searching for the linear approximations of SNOW-V, SNOW-Vi, SNOW-Vi⊞32,⊞8, SNOW-Vi⊞16,⊞16and SNOW-Viσ0ciphers with high absolute correlations. Then we get the best absolute correlations of these ciphers at present, where the linear approximation of SNOW-Vi with the absolute correlation 2-45.796improves the absolute correlation 2-47.76proposed at EUROCRYPT 2022 by Shi et al. and the absolute correlation 2-47.567proposed at DCC 2022 by Zhou et al. Thus, a correlation attack with time/data/memory complexity of 2243.79/2235.08/2235.08is got. It is also the best state recovery attack at present. Thirdly, to simplify the search algorithm of the linear approximations of SNOW-V, we give two sufficient conditions under which a linear approximation of SNOW-Vi is also a linear approximation of SNOW-V. It can be proved that the correlation attack on SNOW-V has the same attack complexity as SNOW-Vi. Finally, for SNOW-Vi⊞32,⊞8and SNOW-Viσ0, we give the best state recovery attacks so far. The current best state recovery attacks of SNOW-Vi⊞32,⊞8and SNOW-Viσ0can be reduced by a factor of 264and 262, respectively. We also give the first attack on SNOW-Vi⊞16,⊞16. We emphasize that the new heuristic MILP model can be applied to the security evaluation of correlation attacks on the LFSR-based stream cipher structures. In addition, note that the existing fast correlation attacks, including our attacks do not threaten the security of SNOW-V-like ciphers because of the design constraint that the maximum length of keystream for a single pair of key and IV vectors is 264. Sudong Ma, Chenhui Jin, Ting Cui, Jie Guan |
IEEE Trans. Inf. Theory | 2 |
| 2024 | Approximating neural distinguishers using differential-linear imbalanceabstractAt CRYPTO 2019, Gohr first proposed neural distinguishers (NDs) on SPECK32, which are superior to the distinguishers based on the differential distribution table (DDT). Benamira et al. noted that NDs rely on the differential distribution of the last three rounds, and Bao et al. pointed out that NDs depend on the strong correlations between the bit values of ciphertext pairs satisfying the expected differential. Hence, one may guess that there exist deep relations between NDs and the differential-linear imbalances. To approximate NDs under a single ciphertext pair, we utilize differential-linear imbalances to construct simplified distinguishers. These newly constructed distinguishers offer comparable distinguishing advantages to that of NDs but with reduced time complexities. For instance, one such simplified distinguisher has only $$2^{-1.35}$$ of the original time complexity of NDs. Our experiments demonstrate that these new distinguishers achieve a matching rate of 98.2% for 5-round SPECK32 under a single ciphertext pair. Furthermore, we achieve the highest accuracies for 7-round and 8-round SPECK32 up to date by using a maximum of 512 ciphertext pairs. Finally, by replacing NDs with simplified distinguishers, we significantly reduce the time complexities of differential-neural attacks on 11–14 rounds of SPECK32. Guangqiu Lv, Chenhui Jin, Ting Cui |
J. Supercomput. | 2 |
| 2023 | Linear Attacks On SNOW 3G And SNOW-V Using Automatic SearchabstractAbstract In this paper, a linear attack model of SNOW 3G and SNOW-V based on automatic search technology is proposed. We first describe the linear approximation of Finite State Machine transformation, which allows a wider range of automatic search, then model it with the automatic search technology based on SAT/SMT program. Adopting this generic method, we seek out a binary linear approximation of SNOW 3G with correlation of $2^{-21.92}$ which has been verified by test. Treating this binary approximation as a mask of an 8-bit distribution in a fixed field, we provide a method to obtain the 8-bit distribution. The binary approximation is used in a fast correlation attack with expected time and memory complexity $2^{184.67}$, given $2^{173.96}$ key stream words. For the full version of SNOW-V, considering the linear relationship between Linear Feedback Shift Register parts at three successive moments, we search out a distinguisher with correlation of $2^{-175.51}$, which results in a distinguishing attack with an expected complexity of $2^{351.02}$. Chenhui Jin |
Comput. J. | 2 |
| 2023 | Fast Correlation Attacks on K2 Stream CipherabstractK2 is an LFSR-based dynamic feedback stream cipher and has been standardized by ISO/IEC 18033-4. The fast correlation attack (FCA) is a well-known cryptanalysis tool for LFSR-based stream ciphers. In this paper, we propose a guess-and-determine FCA on a dynamic feedback stream ciphers model. Moreover, we give a fast calculation method to calculate the correlation of the function$F(x,y,z)=x\boxplus _{n} S(y)\boxminus _{n} z$by directly characterizing subtraction modulo$2^{n}$. Then we propose a kind of mask structure of the linear approximations of the function$F(x,y,z)$with high correlations. The structural characteristics of the kind of masks reduce both the time complexity of the fast calculation and the memory complexity of connection matrices, which enables us to efficiently search for linear approximations with high correlations. Based on the structural characteristics and the analysis of the number of active S-boxes of the linear approximations of K2, we present an effective search strategy, where the number of active S-boxes is 4. The best absolute correlation we found is$2^{-24.21}$. Finally, we study the resistance of K2 against the FCA. For any of the four variants of K2, we give the best key recovery attack so far. The time/data/memory complexity is$O(2^{190.06})/O(2^{189.80})/O(2^{188.80})$, respectively. The results indicate that the four variants of K2 cannot guarantee the claimed 192-bit and 256-bit security if we ignore the design constraint that the maximum keystream length for a single pair of key and IV is limited to$2^{64}$. For the full version of K2, we present the first FCA, which is also the best attack result yet. And the time/data/memory complexity is$O(2^{313.57})/O(2^{149.02})/O(2^{148.02})$, respectively. The large security redundancy indicates that the dynamic feedback structure provides higher security. Sudong Ma, Chenhui Jin, Jie Guan |
IEEE Trans. Inf. Theory | 2 |
| 2023 | A General Correlation Evaluation Model on LFSR-Based Stream CiphersabstractIn this paper, a general model for evaluating the correlations of correlation attack distinguishers for an LFSR-based stream cipher is given by the Walsh spectrum theory of composite functions. We transform equivalently the linear approximations with$k$consecutive keystream words into that of a composite function consisting of several simple functions, which enables cryptanalysts to derive linear approximations of any LFSR-based stream cipher by this model and to search for linear trails with high absolute correlations. This model suits any LFSR-based stream cipher, does not need the implicit independence assumption widely used in previous cryptanalysis, and can theoretically ensure that the correlation obtained is the accurate correlation of a correlation attack distinguisher. In addition, we prove that it is enough to consider the distinguishers where the masks of all LFSR elements are zero except for those of a maximal linearly independent system of LFSR elements involved in the update function and output function. As applications, the approximation processes for the correlation attack distinguishers of SNOW-V, SNOW2.0, ZUC, and Grain-128 are exhibited respectively by this method. Moreover, by the proposed method we can perform a full coverage search for binary linear approximations of them. For SNOW-V, we prove that the approximation given by our model is equivalent to that by Shi et al. at EUROCRYPT 2022, and is simpler and more intuitive. For SNOW2.0, we find more linear approximations with the best correlation. For ZUC, for the first time we get the accurate correlations of a series of linear approximations including the known results, and give the supremum of the absolute correlations for a larger set of linear approximations. For Grain-128, utilizing our method, we rediscover the best known correlation as well, which provides more support for the validity of our general model. Our work can give some evidence for the provable security of LFSR-based stream ciphers against correlation attack to some extent, and may provide the key clues in the analysis of complex stream ciphers. Chenhui Jin, Jiyan Zhang, Ting Cui, Lin Ding 0001, Yu Jin 0009 |
IEEE Trans. Inf. Theory | 2 |
| 2022 | A Correlation Attack on Full SNOW-V and SNOW-Vi
Chenhui Jin, Jiyan Zhang, Ting Cui, Lin Ding 0001, Yu Jin 0009 |
EUROCRYPT (3) | 2 |
| 2022 | Improved linear cryptanalysis on 25-round SMS4abstractAbstract SMS4 is the Chinese national standard for WLAN, which is also an ISO/IEC international standard. This paper presents a linear cryptanalysis on 25‐round SMS4 for the first time. Firstly, this paper adopts a new statistic in linear cryptanalysis, which is aimed to compute the distance between one cipher system and one random permutation, which can be used to distinguish the right key from the wrong keys by the different probability distributions they follow. Secondly, the attack principal and data complexity are given when this new statistic is used in multiple linear cryptanalysis. Thirdly, this paper presents 21‐round linear approximations with absolute correlation by fixing the least significant input bit of the Sbox with nonzero mask in the first round to be 1. Furthermore, this paper gives 48 21‐round linear approximations with absolute correlation . Based on the restrictions between those 48 linear approximations and fast Fourier transformation technique, the whole attack needs known plaintexts, 25‐round SMS4 encryptions along with memory accesses, and bytes of memory, which is the best cryptanalysis result on SMS4 so far. Finally, this paper generalizes the linear cryptanalysis method with conditioned linear approximation, which can also be adopted in attacking other ciphers. Lishi Fu, Chenhui Jin |
IET Commun. | 2 |
| 2022 | Improved differential attacks on the reduced-round SNOW-V and SNOW-Vi stream cipher
Sudong Ma, Chenhui Jin, Jie Guan |
J. Inf. Secur. Appl. | 2 |
| 2021 | Security Analysis of Even-Mansour Structure Hash Functions
Ting Cui, Chenhui Jin |
ICICS (2) | 3 |
| 2021 | New Rectangle Attack Against SKINNY Block Cipher
Jiyan Zhang, Ting Cui, Chenhui Jin |
WASA (3) | 3 |
| 2021 | Improved Guess and Determine attack on the MASHA stream cipher
Lin Ding 0001, Dawu Gu, Lei Wang 0031, Chenhui Jin, Jie Guan |
Sci. China Inf. Sci. | 4 |
| 2021 | Bounding the length of impossible differentials for SPN block ciphers
Qian Wang 0013, Chenhui Jin |
Des. Codes Cryptogr. | 2 |
| 2021 | Construction of higher-level MDS matrices in nested SPNs
Ting Cui, Chenhui Jin |
Inf. Sci. | 3 |
| 2021 | A real-time related key attack on the WG-16 stream cipher for securing 4G-LTE networks
Lin Ding 0001, Dawu Gu, Lei Wang 0031, Chenhui Jin, Jie Guan |
J. Inf. Secur. Appl. | 4 |
| 2021 | A generic framework for decomposing block cipher structure with secret components
Jiyan Zhang, Ting Cui, Chenhui Jin |
J. Inf. Secur. Appl. | 3 |
| 2021 | ICT: A Cryptanalysis Toolbox for Block Cipher Structure With Secret ComponentsabstractIn this paper, we present a new technique for recovering the secret inner components of block cipher structures. This technique does not simply distinguish a block cipher structure from a random permutation but recovers the secret inner components. In addition, our technique is more general than ad hoc structural cryptanalysis for specific structures. A new tool, the Inequality Constraints Table (ICT), is introduced to characterize the constraint relation of the secret inner components. If a complete ICT can be constructed, the secret components will be determined by a recursive algorithm. Based on the fundamental structure, an iterative method is proposed to construct an equivalent structure to simplify the initial guess regarding the secret components. Finally, we apply the new technique to several block cipher structures and obtain the secret component recovery results for the 5-round MISTY structure, 23- and 25- round Skipjack structure. To the best of our knowledge, this is the first time to present the structural cryptanalysis against the 5-round MISTY structure, 23- and 25-round Skipjack structure. Jiyan Zhang, Ting Cui, Chenhui Jin |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | A New General Method of Searching for Cubes in Cube Attacks
Lin Ding 0001, Lei Wang 0031, Dawu Gu, Chenhui Jin, Jie Guan |
ICICS | 4 |
| 2020 | Integral distinguishers for Grøstl-512 and Kupyna-512 permutation functionsabstractGrøstl is one of the SHA‐3 finalist hash functions. Kupyna is the new Ukrainian hash standard, which is structurally very similar to Grøstl. The authors investigate the randomness of the two permutations used in Grøstl‐512 and one of the two permutations used in Kupyna‐512, in this study. New integral distinguishers of the three permutations are constructed. First, using an automatic search tool of division property, they find improved integral distinguishers of the permutations in both the forward and backward directions. Then, subspace trails are utilised to extend the length of the backward integral distinguishers by one round. Finally, the forward and backward integral distinguishers are combined using the inside‐out method. As far as they know, they decrease the computational cost of 8, 9 and 10‐round distinguishers and their 12‐round distinguishers are the longest distinguishers for the three permutations. Rongjia Li, Chenhui Jin, Hongchen Pan |
IET Inf. Secur. | 2 |
| 2019 | Improved Integral Distinguishers on Compression Function of GOST R Hash FunctionabstractStreebog is a new Russian hash function standard (GOST R 34.11–2012). The compression function of Streebog employs an AES-like block cipher which is used in Miyaguchi–Preneel mode. In this paper, we investigate the integral distinguisher on reduced-round Streebog compression function. First, we find 6/7/8/9/10-round integral distinguishers using word-based division property. Then, we further reduce the complexity of the integral distinguishers utilizing subspace trails. As far as we know, we improve the previous best integral distinguisher by three rounds. Rongjia Li, Chenhui Jin, Ruya Fan |
Comput. J. | 2 |
| 2019 | An Improvement of the CS Attack to DSC CipherabstractAbstract The DECT standard cipher (DSC) is a 64-bit stream cipher, which was used in the digital enhanced cordless telecommunications (DECT) standard to protect the privacy of users. The Coisel–Sanchez (CS) attack proposed by Coisel and Sanchez in CHES 2015 is the most effective cryptanalysis against the DSC cipher up to now. Based on the CS attack, we present an improved attack in which an information collection method with unknown memory is used to improve the utilization of information and the message classification technique is adopted to reduce the computation time of evaluation indexes. Meanwhile, we present an improved pre-sieving technique to avoid the computation of evaluation indexes of a large number of incorrect candidates. Our known plaintext attack requires only 2 min of communication compared to 3 min for the CS attack. By analyzing 213 keystreams, our approach is able to increase the success probability of retrieving secret key from 55–89%. As far as we know, the attack we present in this paper is the most effective one among the existing attacks to the DSC cipher. Hanqiu Liu, Chenhui Jin |
Comput. J. | 2 |
| 2019 | A Method to Bound the Number of Active S-Boxes for a Kind of AES-Like StructureabstractAbstract Due to the strong security and high performance of the AES block cipher, many hash functions take AES-like structures as building blocks. To evaluate the security of these AES-like structures against differential cryptanalysis, giving the lower bounds on the number of active S-boxes in a differential trail, is an important perspective. However, the original ‘wide-trail strategy’ for AES becomes less effective to get tight bounds for these AES-like structures, because of the different state dimensions (M×M2, instead of M×M) and different round functions from AES. In this paper, we focus on a kind of AES-like structure with state dimensions M×M2, diffusion-optimal permutations and MixColumns transformations using MDS matrices. Inspired by the ‘wide-trail strategy’, we propose a theoretical method to count active S-boxes, by which we prove that there are at least rBd(Bd−1) active S-boxes in any 2r(r≥3) rounds of such an AES-like structure, where Bd is the differential branch number of the MixColumns transformation and equals to M+1. What’s more, this lower bound can be achieved by some diffusion layers. As examples, we apply our method to the LANE hash function and 3D block cipher, optimal lower bounds are both got. Qian Wang 0013, Chenhui Jin |
Comput. J. | 2 |
| 2019 | More accurate results on the provable security of AES against impossible differential cryptanalysis
Qian Wang 0013, Chenhui Jin |
Des. Codes Cryptogr. | 2 |
| 2019 | Meet-in-the-middle attacks on round-reduced tweakable block cipher Deoxys-BCabstractDeoxys‐BC is a tweakable block cipher designed by Jean et al . at ASIACRYPT 2014 within the TWEAKEY framework. Then Deoxys‐BC is used in the CAESAR finalist Deoxys. In this study, the authors consider the security of Deoxys‐BC against meet‐in‐the‐middle attack in the single‐key setting. Using the idea that a chosen tweak difference allows to cancel a difference in the state, they can construct 5‐round meet‐in‐the‐middle distinguisher on Deoxys‐BC‐128‐128 which can be extended to attack on 8‐round Deoxys‐BC‐128‐128. Moreover, they construct 6‐round meet‐in‐the‐middle distinguisher on Deoxys‐BC‐256‐128 which can be extended to attack on 10‐round Deoxys‐BC‐256‐128. As far as the authors know, these are the best attacks against Deoxys‐BC in the single‐key setting. Rongjia Li, Chenhui Jin |
IET Inf. Secur. | 2 |
| 2019 | Key recovery attacks on reduced-round Joltik-BC in the single-key setting
Rongjia Li, Chenhui Jin, Hongchen Pan |
Inf. Process. Lett. | 2 |
| 2019 | Algebraic Degree Estimation of ACORN v3 Using Numeric MappingabstractACORN v3 is a lightweight authenticated encryption cipher, which was selected as one of the seven finalists of CAESAR competition in March 2018. It is intended for lightweight applications (resource-constrained environments). By using the technique numeric mapping proposed at CRYPTO 2017, an efficient algorithm for algebraic degree estimation of ACORN v3 is proposed. As a result, new distinguishing attacks on 647, 649, 670, 704, and 721 initialization rounds of ACORN v3 are obtained, respectively. So far, as we know, all of our distinguishing attacks on ACORN v3 are the best. The effectiveness and accuracy of our algorithm is confirmed by the experimental results. Lin Ding 0001, Lei Wang 0031, Dawu Gu, Chenhui Jin, Jie Guan |
Secur. Commun. Networks | 4 |
| 2018 | A non-alternate 3D structure and its practical security evaluation against differential and linear cryptanalysis
Qian Wang 0013, Chenhui Jin |
Sci. China Inf. Sci. | 2 |
| 2018 | Meet-in-the-Middle Attacks on Reduced-Round QARMA-64/128abstractQARMA is a new family of lightweight tweakable block ciphers which is used in the Pointer Authentication of ARMv8.3-A. In this paper, we apply meet-in-the-middle attack to QARMA-64 and QARMA-128 including the outer whitening keys. First, we observe that a linear relation exists between four cells out of the eight input/output cells in the MixColumns operation. Then, the idea of canceling the state difference with the tweak difference is used to make one blank round. Finally, we construct meet-in-the-middle distinguishers on 5-round QARMA-128 and QARMA-64, respectively. Therefore, the attack on QARMA4-128 is obtained by appending three rounds on the top of the distinguisher and two round on the bottom. Similarly, the attack on QARMA3-64 is obtained. Besides, this attack can be extended to attack on 9-round QARMA-64 without increasing the overall complexity. To the best of our knowledge, these are the first attacks on QARMA block ciphers including the outer whitening keys. Rongjia Li, Chenhui Jin |
Comput. J. | 2 |
| 2018 | Upper bound of the length of truncated impossible differentials for AES
Qian Wang 0013, Chenhui Jin |
Des. Codes Cryptogr. | 2 |
| 2018 | Multiple Impossible Differentials Cryptanalysis on 7-Round ARIA-192abstractThis paper studies the security of 7-round ARIA-192 against multiple impossible differentials cryptanalysis. We propose six special 4-round impossible differentials which have the same input difference and different output difference with the maximum number of nonzero common bytes. Based on these differentials, we construct six attack trails including the maximum number of common subkey bytes. Under such circumstances, we utilize an efficient sieving process to improve the efficiency of eliminating common subkeys; therefore, both data and time complexities are reduced. Furthermore, we also present an efficient algorithm to recover the master key via guess-and-determine technique. Taking advantage of the above advances, we have obtained the best result so far for impossible differential cryptanalysis of ARIA-192, with time, data, and memory complexities being 2189.8 7-round ARIA encryptions, 2116.6 chosen plaintexts, and 2139.3 bytes, respectively. Zilong Jiang, Chenhui Jin |
Secur. Commun. Networks | 2 |
| 2017 | Meet in the Middle Attack on Type-1 Feistel Construction
Yuanhao Deng, Chenhui Jin, Rongjia Li |
Inscrypt | 2 |
| 2017 | Searching all truncated impossible differentials in SPNabstractThis study concentrates on finding all truncated impossible differentials in substitution–permutation networks (SPNs) ciphers. Instead of using the miss‐in‐the‐middle approach, the authors propose a mathematical description of the truncated impossible differentials. First, they prove that all truncated impossible differentials in an r + 1 rounds SPN cipher could be obtained by searching entry ‘0’ in D ( P ) r , where D ( P ) denotes the differential pattern matrix (DPM) of P ‐layer, thus the length of impossible differentials of an SPN cipher is upper bounded by the minimum integer r such that there is no entry ‘0’ in D ( P ) r . Second, they provide two efficient algorithms to compute the DPMs for both bit‐shuffles and matrices over GF(2 n ). Using these tools they prove that the longest truncated impossible differentials in SPN structure is 2‐round, if the P ‐layer is designed as an maximum distance separable (MDS) matrix. Finally, all truncated impossible differentials of advanced encryption standard (AES), ARIA, AES‐MDS, PRESENT, MAYA and Puffin are obtained. Ting Cui, Chenhui Jin, Guoshuang Zhang |
IET Inf. Secur. | 2 |
| 2017 | Improved meet-in-the-middle attacks on Crypton and mCryptonabstractThis study presents several meet‐in‐the‐middle attacks on reduced‐round Crypton and mCrypton block ciphers. Using the generalised δ ‐set, the authors construct 5‐round distinguishers on Crypton and mCrypton. Based on these distinguishers, the authors propose meet‐in‐the‐middle attacks on 8‐round Crypton and mCrypton‐96/128. The attack on Crypton needs 2 121 chosen plaintexts, 2 132 encryptions and 2 130 128‐bit blocks; the attacks on mCrypton need 2 61 chosen plaintexts, 2 80 encryptions and 2 78 64‐bit blocks. Furthermore, the attack can be extended to 9 rounds for mCrypton‐128 with complexities of 2 61 chosen plaintexts, 2 112 encryptions and 2 82 64‐bit blocks. Rongjia Li, Chenhui Jin |
IET Inf. Secur. | 2 |
| 2016 | Key recovery attack for PRESENT using slender-set linear cryptanalysis
Chenhui Jin, Zhiyin Kong |
Sci. China Inf. Sci. | 2 |
| 2016 | Meet-in-the-middle attacks on 10-round AES-256
Rongjia Li, Chenhui Jin |
Des. Codes Cryptogr. | 2 |
| 2016 | Multidimensional zero-correlation linear cryptanalysis of lightweight block cipher Piccolo-128abstractAbstract Piccolo is a lightweight block cipher proposed at CHES 2011. This paper firstly gives the zero‐correlation linear approximations over 7‐round Piccolo and studies the security of Piccolo‐128 against multidimensional zero‐correlation linear cryptanalysis. Based on the statistic used in multidimensional linear cryptanalysis to detect the right key and wrong keys, this paper gives the data complexity when using this statistic in multidimensional zero‐correlation linear cryptanalysis. Finally, with partial sum technique and the relation between the round keys in Piccolo‐128, the first known‐plaintexts attacks on round 0–12/round, 15–28/round, and 14–28 of Piccolo‐128 are proposed; the data complexities of those attacks are 256.8/252.43/255.6 known plaintexts, respectively; and the time complexities are 2117.2,2123.09,2126.55, respectively. Copyright © 2016 John Wiley & Sons, Ltd. Lishi Fu, Chenhui Jin |
Secur. Commun. Networks | 2 |
| 2015 | New Related Key Attacks on the RAKAPOSHI Stream Cipher
Lin Ding 0001, Chenhui Jin, Jie Guan, Ting Cui |
ISPEC | 2 |
| 2015 | Cryptanalysis of WG Family of Stream CiphersabstractThe well-known Welch–Gong (WG) stream cipher, proposed by Nawaz and Gong in 2005, was submitted to the hardware profile of the eSTREAM project. In the last several years, the original WG has come under several cryptanalytic attacks. However, as for the final version of WG, no attack has been published on it until now. In this paper, an efficient key recovery attack on the final WG stream cipher in the related key setting is proposed. Under related keys, we can recover the 128-bit secret key of WG-128 with a time complexity of |$2^{89}$| and a memory complexity of |$2^{45}$|. The success probability of the attack is 0.6321. This result shows that our attack on WG-128 is much better than an exhaustive key search in the related key setting. Furthermore, our cryptanalytic results show that WG with IV size no less than 80 bits is vulnerable to a related key attack. The main feature of our attack is that it is independent of the number of steps in the key/IV setup of WG, and then increasing the number of steps in the key/IV setup cannot strengthen the resistance of WG against a related key attack. Finally, a recommended approach to repair the weakness and strengthen the resistance of WG against a related key attack is presented. Lin Ding 0001, Chenhui Jin, Jie Guan, Ting Cui |
Comput. J. | 2 |
| 2015 | Lower Bounds of Differential and Linear Active S-boxes for 3D-like StructureabstractThis paper studies the minimum number of differential and linear active S-boxes for 3D-like structure with block size of n3m bits. We prove that the lower bounds of differential active S-boxes in 2 rounds and 4 rounds are d(π) and d(π)2, respectively, where π is the MixColumn transformation and d(π) is its differential branch number with respect to m bits. Moreover, for r≥3 and d(π)≥3, the lower bounds of differential active S-boxes in 2r rounds and 2r+1 rounds are (d(π) − 1)d(π)r and (d(π) − 1)(d(π)r+1) respectively, where r is the number of the rounds. By the duality between differential trails and linear trails, for l(π)≥3, the lower bounds of linear active S-boxes in 2, 4, 2r and 2r+1 consecutive rounds are l(π), l(π)2, (l(π) − 1)l(π)r and (l(π) − 1)(l(π)r+1) respectively, where l(π) is the linear branch number of the MixColumn transformation. We give some sufficient conditions for the reachability of the lower bounds. It is worth mentioning that the lower bounds are all reachable for 3D block cipher. Huacui Liu, Chenhui Jin |
Comput. J. | 2 |
| 2015 | Slide attack on standard stream cipher Enocoro-80 in the related-key chosen IV setting
Lin Ding 0001, Chenhui Jin, Jie Guan |
Pervasive Mob. Comput. | 2 |
| 2015 | A second preimage attack on zipper hashabstractAbstract The zipper hash utilizes two‐pass hashing to strengthen the iterated hash functions against the generic attack. In this paper, we analyze the features of zipper hash and several existing generic attacks on hash functions. A new tree structure called inverse‐diamond, which starts from one fixed point and ends with many points, is exploited to guarantee that the corresponding message blocks in the two passes be identical. Then, combining the inverse‐diamond structure of depth l, with the multicollision of length n – l (n is bit number of the hash value) and the (k, 2k + k − 1)‐expandable message together, we firstly present a second preimage attack on zipper hash of which the time complexity is about O((2 k + n)2n/2 + 2n − k + (n − l)2n − l + 2l + 1), less than O(2n), and the memory complexity is about O(2k + 1 + 3*2l). Specially, if k = l = n/2, then the time complexity is about O(n2n/2), and the memory complexity is about O(2n/2). Copyright © 2015 John Wiley & Sons, Ltd. Chenhui Jin |
Secur. Commun. Networks | 2 |
| 2015 | On Compact Cauchy Matrices for Substitution-Permutation NetworksabstractMaximum distance separable (MDS) matrices are widely used in the design of block ciphers. However, it is highly nontrival to find MDS matrices which could be used in practice. This paper focuses on the design of efficient MDS matrices for substitution-permutation networks (SPNs). We provide a new method to construct and count these MDS matrices. Moreover, we identified an interesting class of Cauchy matrices (named compact Cauchy matrices) which has the fewest different entries and is thus more favorable for implementation. Finally, we prove that all compact Cauchy matrices could be modified into an involution compact Cauchy matrix, and show how to maximize the occurrences of entry “1” in a compact Cauchy matrix. Ting Cui, Chenhui Jin, Zhiyin Kong |
IEEE Trans. Computers | 2 |
| 2014 | Cryptanalysis of Lightweight WG-8 Stream CipherabstractWG-8 is a new lightweight variant of the well-known Welch-Gong (WG) stream cipher family, and takes an 80-bit secret key and an 80-bit initial vector (IV) as inputs. So far no attack on the WG-8 stream cipher has been published except the attacks by the designers. This paper shows that there exist Key-IV pairs for WG-8 that can generate keystreams, which are exact shifts of each other throughout the keystream generation. By exploiting this slide property, an effective key recovery attack on WG-8 in the related key setting is proposed, which has a time complexity of 253.32and requires 252chosen IVs. The attack is minimal in the sense that it only requires one related key. Furthermore, we present an efficient key recovery attack on WG-8 in the multiple related key setting. As confirmed by the experimental results, our attack recovers all 80 bits of WG-8 in on a PC with 2.5-GHz Intel Pentium 4 processor. This is the first time that a weakness is presented for WG-8, assuming that the attacker can obtain only a few dozen consecutive keystream bits for each IV. Finally, we give a new Key/IV loading proposal for WG-8, which takes an 80-bit secret key and a 64-bit IV as inputs. The new proposal keeps the basic structure of WG-8 and provides enough resistance against our related key attacks. Lin Ding 0001, Chenhui Jin, Jie Guan, Qiuyan Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | Practical security against linear cryptanalysis for SMS4-like ciphers with SP round function
Bin Zhang 0015, Chenhui Jin |
Sci. China Inf. Sci. | 2 |
| 2009 | A Second Preimage Attack on the Merkle-Damgard Scheme with a Permutation for Hash Functions
Chenhui Jin |
SECRYPT | 2 |
| 2009 | Security evaluation against differential and linear cryptanalyses for Feistel ciphers
Nianping Wang, Chenhui Jin |
Frontiers Comput. Sci. China | 2 |
| 2007 | An Improved Collision Attack on MD5 Algorithm
Chenhui Jin |
Inscrypt | 2 |