Wenling Wu

dblp:74/2464 · DBLP profile ↗
← Back
105ranked-venue papers
10as first author
30since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 84 · 5 first-author · 22 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 5 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3Theory of computation · 3Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Security analysis of the P-SPN structure with a class of linear layer matrix against invariant subspace attack
Ee Duan, Wenling Wu
Des. Codes Cryptogr.2
2026 Construction of correctors using resilient fragmentary Boolean functions
Yaoda Hu, Yu Zhang 0216, Wenling Wu
Des. Codes Cryptogr.3
2026 Research on constructing integral distinguishers for block ciphers via the division property
Yu Zhang 0216, Wenling Wu, Yafei Zheng, Lei Zhang 0186, Yongxia Mao
Des. Codes Cryptogr.2
2025 Vectorial Fast Correlation Attacks
Bin Zhang 0003, Ruitao Liu, Willi Meier, Siwei Sun, Dengguo Feng, Wenling Wu
ASIACRYPT (1)6
2025 Quantum IND-CPA Security Notions for AEAD
Wenling Wu, Han Sui
PQCrypto (2)2
2025 A new automatic framework for searching rotational-XOR differential characteristics in ARX ciphers
Yafei Zheng, Wenling Wu
Des. Codes Cryptogr.4
2024 Efficient Search for Optimal Permutations of Refined Type-II Generalized Feistel Structures
Wenling Wu, Ee Duan
ACISP (1)2
2024 LOL: a highly flexible framework for designing stream ciphers
Dengguo Feng, Lin Jiao, Yonglin Hao, Qun-Xiong Zheng, Wenling Wu, Wen-Feng Qi 0001, Siwei Sun, Tian Tian 0004
Sci. China Inf. Sci.5
2024 New Integral Distinguishers On Permutation Of Whirlpool
abstract
Abstract Whirlpool is a hash function that has been standardized by ISO/IEC. In this paper, we develop a new type of distinguishing property for its underlying permutation $ W $. Division property proposed by Todo at EUROCRYPT 2015 was initially used in the integral cryptanalysis of symmetric-key algorithms. This work for the first time utilizes the MILP method to search for the integral distinguishers of $ W $ in both the forward and backward directions while concentrating on word-based division property. Under the known-key model, the fact that the permutation used in the hash function does not depend on any secret parameters allows the previous properties to be exploited from the middle, i.e. from an intermediate internal state. Therefore, we apply the inside-out strategy which is the essential step in the zero-sum property to connect the trails in opposite directions. Consequently, we obtain new distinguishers up to full rounds for the $ W $. To further reduce the complexity of the integral distinguishers, we add one round in the middle with the help of subspace trails. Finally, we succeed in extending the length and improving the complexity of the integral distinguishers. To the best of our knowledge, all the results in this paper are competitive with the previous work in both computational cost and memory complexity. It is worth mentioning that the methods presented in this paper are applicable to a broad class of hash functions.
Wenling Wu, Yuhan Zhang 0009
Comput. J.2
2024 Explicit Upper Bound Of Impossible Differentials For AES-Like Ciphers: Application To uBlock And Midori
abstract
Abstract Whether a block cipher can resist impossible differential attack is an important basis to evaluate the security of a block cipher. However, the length of impossible differentials is important for the security evaluation of block ciphers. Most of the previous studies are based on structural cryptanalysis to find the impossible differential, and the structural cryptanalysis covers a lot of specific cryptanalytic vectors which are independent of the nonlinear S-boxes. In this paper, we study the maximum length of the impossible differential of an Advanced Encryption Standard-like cipher in the setting with the details of S-boxes. Inspired by the ‘Divide-and-Conquer’ technique, we propose a new technique called Reduced Block, which combines the details of the S-box. With this tool, the maximum length of impossible differentials can be proven under reasonable assumptions. As applications, we use this tool on uBlock and Midori. Consequently, we prove that for uBlock-128, uBlock-256 and Midori-64, there are no impossible five-round, six-round and seven-round differentials with one active input nibble and one active output nibble, even when considering the details of S-boxes. Furthermore, we reveal some properties of the uBlock S-box and linear layer and demonstrate theoretically that there are no impossible differentials longer than four rounds for uBlock-128 under the assumption that the round keys are independent and uniformly random. This study might provide some insight into the bounds of the length of impossible differentials.
Yu Zhang 0216, Wenling Wu, Yongxia Mao, Yafei Zheng
Comput. J.3
2024 Yoyo attack on 4-round Lai-Massey scheme with secret round functions
Danxun Zhang, Wenling Wu
Des. Codes Cryptogr.4
2024 Security analysis of P-SPN schemes against invariant subspace attack with inactive S-boxes
Wenling Wu
Des. Codes Cryptogr.2
2024 New Differential-Based Distinguishers for Ascon via Constraint Programming
abstract
As the winner of the NIST lightweight cryptography project, Ascon has undergone extensive self‐evaluation and third‐party cryptanalysis. In this paper, we use constraint programming (CP) as a tool to analyze the Ascon permutation and propose several differential‐based distinguishers. We first propose a search methodology for finding truncated differentials for Ascon with CP, the core of which is modeling with the undisturbed bits of the S‐box. By using this method, we find the five‐ and six‐round truncated differentials with a probability of 2 −44 and 2 −162 , respectively. Considering the application of permutation in the context, we also provide the five‐ and six‐round truncated differential distinguishers under the weak‐key setting. Then, inspired by our five‐round truncated differentials, we propose a six‐round boomerang characteristic, and based on this, we obtain the five‐ and six‐round sandwich distinguishers with a complexity of 2 70 and 2 134 , respectively. Using the CP tool again and specifying that the “3‐3” differential pattern is satisfied in the middle rounds, we propose a six‐round differential characteristic with a probability of 2 −280 , which increases the probability by 2 25 compared to the best known six‐round differential characteristic.
Chan Song, Wenling Wu, Lei Zhang 0186
IET Inf. Secur.2
2024 Single-Key Attack on Full-Round Shadow Designed for IoT Nodes
abstract
With the rapid advancement of the Internet of Things (IoT), many innovative lightweight block ciphers have been introduced to meet the stringent security demands of IoT devices. Among these, the Shadow cipher stands out for its compactness, making it particularly well-suited for deployment in resource-constrained IoT nodes (IEEE Internet of Things Journal, 2021). This paper demonstrates two real-time attacks on Shadow for the first time: real-time plaintext recovery and key recovery. Firstly, numerous properties of Shadow are discussed, illustrating an equivalent representation of the two-round Shadow and the relationship between the round keys. Secondly, we introduce multiple two-round iterative linear approximations. Employing these approximations enables the derivation of full-round linear distinguishers. Moreover, we have uncovered numerous linear relationships between plaintext and ciphertext. Real-time plaintext recovery is achievable based on these established relationships. On average, it takes 5 seconds to recover the plaintext for a fixed ciphertext of Shadow-32. Thirdly, many properties of the propagation of difference through SIMON-like function are illustrated. According to these properties, various differential distinguishers up to full rounds are presented, allowing real-time key recovery. Specifically, the 64-bit master key of Shadow-32 can be retrieved in around two days on average. Experiments verify all our results.
Yuhan Zhang 0009, Wenling Wu, Lei Zhang 0186, Yafei Zheng
IEEE Trans. Computers2
2024 Dedicated Quantum Attacks on XOR-Type Function With Applications to Beyond-Birthday- Bound MACs
abstract
A lot of work in the field of quantum cryptanalysis is currently devoted to finding applications of Grover-meets-Simon algorithm and its complexity is given in the form of$\mathcal {O}$, but research on how to implement the attack efficiently is still insufficient. After all, it is crucial to study quantum attacks in resource-limited situations, according to NIST’s guidance on circuit depth. This work first evaluates the parallelization of Grover-meets-Simon by drawing on the Grover’s parallel approach and shows that as the width increases by$2^{t}(t\gt 0)$, the depth decreases by a factor of$\sqrt {2^{t}}$. Further, the first dedicated quantum attack on a class of functions that appear in cryptographic scheme applications (so-called XOR-type function) is proposed. The depth, width, and the number of gates required for the attack are greatly reduced compared to the general parallelization. Then we apply the attack to various Beyond-Birthday-Bound (BBB) MACs, where the XOR function can be constructed, includingSUM-ECBCand its variants (2K-SUM-ECBC,2K-ECBC_Plus), andGCM-SIV2. In the typical case whereSUM-ECBCis based on AES-128, our attack saves at least 62.3% in depth, 19.5% in width and 22.2% in gate count simultaneously. The impact on some lightweight ciphers is further explored, and it is interesting to note that the lighter the quantum circuit implementation of the cipher is, the greater the possible impact of an attack will be. This observation may provide new insights into quantum cryptanalysis.
Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Han Sui, Senpeng Wang
IEEE Trans. Inf. Forensics Secur.2
2023 Related-Cipher Attacks: Applications to Ballet and ANT
Yongxia Mao, Wenling Wu, Yafei Zheng, Lei Zhang 0186
ACISP2
2023 Constructing Binary Matrices with Good Implementation Properties for Low-Latency Block Ciphers based on Lai-Massey Structure
abstract
Abstract Diffusion layers are crucial components for lightweight cryptographic schemes. Optimal binary matrices are widely used diffusion layers that can be easier to achieve the best security/performance trade-off. However, most of the constructions of binary matrices are concentrated in smaller dimensions. Besides, to maximize the number of branches, the performance is often neglected. In this paper, we investigate the diffusion of the Lai-Massey (L-M) structures and propose a series of binary diffusion layers with the best possible branch number and efficient software/hardware implementations as well for feasible parameters (up to 64). Firstly, we prove the lower bound of the circuit depth of a binary matrix with a fixed branch number. Then, we construct binary matrices by L-M structure with cyclic shift as round functions because of taking account of the improvement of software performance and demonstrate that this construction can not get the diffusion layers with branch number >4. Then, we get some 4 $\times $ 4 and 6 $\times $ 6 optimal binary matrices with branch number 4 by one-round L-M structure. Note that the depth of these results is optimal, i. e. they achieve the lowest hardware costs without loss of software efficiency. Secondly, we construct diffusion layers by extended L-M structures to obtain binary matrices with large sizes. We give a list of software/hardware friendly optimal binary matrices with large dimensions, especially for dimensions 48 and 64. In particular, some of the solutions are Maximum Distance Binary Linear matrices. Finally, we also present diffusion layers constructed by the extended generalized L-M structure to improve their applicabilities on other platforms.
Wenling Wu
Comput. J.2
2023 Cryptanalysis on Reduced-Round 3D and Saturnin
abstract
Abstract 3D is an Advanced Encryption Standard (AES)-like cipher employed 3D structure proposed in 2008. The main innovation of 3D is the multi-dimensional state, generalizing the design of Rijndael and allowing block sizes beyond the 256-bit boundary. Saturnin, a lightweight block cipher has been selected as a second-round candidate in the National Institute of Standards and Technology standardization for lightweight cryptography. It also employs a 3D structure and provides high security against quantum and classic attacks. The exchange-equivalence attacks proposed by Bardeh and Rønjom consider how quadruples of plaintexts confirm distinguishable properties for AES. It is similar to the principle of yoyo attack, but it can find a longer number of rounds of distinguisher. In this paper, we investigate the exchange-equivalence attack on 3D and yoyo attack on Saturnin. Our new results turn out to be the first secret-key chosen plaintext distinguisher for 10-round 3D. The complexity of the distinguisher is about $2^{364.2}$ in terms of data, memory and computational complexity. For Saturnin, we propose the first six-super-round impossible differential yoyo attack, which is suitable for the two-S-layer version. Compared with the previous impossible differential attacks in the design report of Saturnin, the attacks presented here are the best in terms of the complexity under the chosen-plaintext scenario.
Li Zhang 0108, Wenling Wu, Yafei Zheng
Comput. J.2
2023 Post-quantum security on the Lai-Massey scheme
Zhongya Zhang, Wenling Wu, Han Sui
Des. Codes Cryptogr.2
2023 Similarity Property and Slide Attack of Block Cipher FESH
abstract
This paper focuses on similarity properties and extension of the classical slide property of block ciphers. Taking FESH, an award‐winning block cipher of the National Cryptographic Algorithm Design Competition 2019, as an example, similarity properties of the encryption and key transformation are found, owing to the similar structures that the encryption and key transformation adopted, and the constants generation. Based on the similarity properties, extended slide properties can be constructed for FESH. Slide attacks of FESH are then proposed. The similarity properties and extended slide property are immune to the increasing of iterated rounds, i.e., it cannot be avoided by increasing the round number of FESH. Furthermore, extended slide property helps relaxing the strict requirements of the subkeys in slide attacks. Taking Feistel and SPN structures as examples, frameworks of slide attacks based on the extended slide properties are presented. Slide attack of FESH is exactly a concrete example of SPN structure.
Yafei Zheng, Wenling Wu
IET Inf. Secur.2
2023 New Key-Independent Structural Properties of AES-Like Permutations
abstract
The Internet of Things (IoT) technology makes our lives very simple and convenient by interacting with sensors/devices around the world and using the smart data collected from them. However, IoT devices typically have a resource-constrained architecture, rendering them vulnerable to cyberattacks. The advent of lightweight cryptography provides an opportunity to meet the challenges of IoT. With the promotion of 5G (5th generation wireless systems) technology, the amount of data in IoT devices is bound to grow rapidly. The design and analysis of lightweight block cipher is still a hot issue that needs to be solved in the coming period of time, as it responds to the strong push of many national governments to adopt IoT systems in the management of public affairs. MANTIS is a new tweakable block cipher suitable for IoT with the goal of low-latency implementations and it has drawn lots of attention in the form of prior cryptanalysis. This work first reveals a novel property of MANTIS. The characteristic is established under the condition that there is a certain equivalence relation between the input pairs in a particular subspace and it is evidenced by the first introduction of a key-independent distinguisher for 6-round MANTIS. We obtain that the number of input plaintext pairs in the same equivalence class is always divisible by 8. Then, we demonstrate a general and comprehensive proof as why it has to exist. Additionally, we have successfully verified the validity of the distinguisher. Only 216 chosen plaintexts and 222 table lookups computational cost are required to guarantee that the success probability exceeds 99%. Moreover, we discover that the same kind of property holds for other AES-like permutations with the example of the lightweight hash function PHOTON. Finally, we put forward some future explorations in this promising field.
Wenling Wu
IEEE Internet Things J.2
2022 Improved Division Property for Ciphers with Complex Linear Layers
Yongxia Mao, Wenling Wu, Li Zhang 0108
ACISP2
2022 Improved Differential Attack on Round-Reduced LEA
Yuhan Zhang 0009, Wenling Wu, Lei Zhang 0186
ACISP2
2022 LLLWBC: A New Low-Latency Light-Weight Block Cipher
Lei Zhang 0186, Ruichen Wu, Yuhan Zhang 0009, Yafei Zheng, Wenling Wu
Inscrypt5
2022 Lattice-Based Fault Attacks on Deterministic Signature Schemes of ECDSA and EdDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen, Limin Fan, Wenling Wu
CT-RSA6
2022 Effective approximation of high-dimensional space using neural networks
Jian Zheng 0004, Shuping Chen, Jingjin Chen, Wenlong Zhong, Wenling Wu
J. Supercomput.7
2021 Constructions of Iterative Near-MDS Matrices with the Lowest XOR Count
Wenling Wu
ACISP2
2021 On Characterization of Transparency Order for (n, m)-functions
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu
Inscrypt6
2021 Transparency Order of (n, m)-Functions - Its Further Characterization and Applications
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu
ISC6
2021 Breaking LWC candidates: sESTATE and Elephant in quantum setting
Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Senpeng Wang
Des. Codes Cryptogr.2
2020 Quantum Circuit Implementations of AES with Fewer Qubits
Jian Zou 0002, Zihao Wei, Siwei Sun, Ximeng Liu, Wenling Wu
ASIACRYPT (2)5
2019 New method to describe the differential distribution table for large S-boxes in MILP and its application
abstract
Based on the method of the H‐representation of the convex hull, the linear inequalities of all possible differential patterns of 4‐bit S‐boxes in the mix integer linear programming (MILP) model can be generated easily by the SAGE software. Whereas this method cannot be apply to 8‐bit S‐boxes. In this study, the authors propose a new method to obtain the inequalities for large S‐boxes with the coefficients belonging to integer. The relationship between the coefficients of the inequalities and the corresponding excluded impossible differential patterns is obtained. As a result, the number of inequalities can be lower than 4000 for the AES S‐box. Then, the new method for finding the best probability of the differential characteristics of 4–15 rounds SM4 in the single‐key setting is presented. Especially, the authors found that the 15‐round SM4 exists four differential characteristics with 12 active S‐boxes. The exact lower bound of the number of differentially active S‐boxes of the 16‐round SM4 is 15. The authors also found eight differential characteristics of the 19‐round SM4 with the probability .
Lingchen Li, Wenling Wu, Lei Zhang 0012, Yafei Zheng
IET Inf. Secur.2
2019 On the extension and security of key schedule of GOST
abstract
A type of simple key schedule especially suitable for lightweight block ciphers is defined as straightforward key schedule in this study. As a typical example, GOST‐type key schedule, which is an extension of the key schedules of Russian Standard GOST and its newly modified version GOST2, is introduced and classified. GOST2 is designed based on the GOST encryption structure with different but the same type of key schedule to overcome the weakness of GOST against self‐similarity properties‐based attacks. However, it has been shown in Fast Software Encryption 2017, the simple change in the key schedule is insufficient to offer 256‐bit security. By constructing an evaluation framework combining self‐similarity properties and meet‐in‐the‐middle attack, properties of GOST‐type key schedules are evaluated, and candidate key schedules are provided in this work. These candidate key schedules are able to provide much better security for GOST and GOST2 ciphers than their original key schedules, and the pre‐existing self‐similarity properties‐based attacks of full round GOST and GOST2 can be avoided. The designers of GOST and GOST2 should have been more cautious choosing the parameters of key schedules. The evaluation framework proposed can be used for reference in the design of other Feistel ciphers with straightforward key schedules.
Yafei Zheng, Wenling Wu
IET Inf. Secur.2
2018 Improved meet-in-the-middle attacks on reduced-round Kalyna-128/256 and Kalyna-256/512
Li Lin 0003, Wenling Wu
Des. Codes Cryptogr.2
2018 New algorithms for the unbalanced generalised birthday problem
abstract
In this study, the authors present some new algorithms for the unbalanced generalised birthday problem (UGBP), which was proposed by Nikolić and Sasaki in their attacks on the generalised birthday problem (GBP). The authors’ first idea is simple, which uses some precomputing to convert UGBP into GBP. After the precomputing, they just adopt Wagner's k ‐tree algorithm or the algorithms of Bernstein et al . to solve UGBP. Their second idea combines the technique for the unbalanced meet‐in‐the‐middle problem with the improved time–memory trade‐off algorithm for GBP to solve UGBP. Besides, they will utilise the inactive technique and the rearrangement technique to improve the time complexities of their algorithms. The inactive technique is used to neglect the effect of some costly functions, and the rearrangement technique is adopted to balance the time costs between different functions. When k is not a power of 2, the time complexity of their algorithms for UGBP can also be improved by using the multicollision technique.
Jian Zou 0002, Wenling Wu
IET Inf. Secur.3
2017 My Traces Learn What You Did in the Dark: Recovering Secret Signals Without Key Guesses
Hua Chen 0011, Wenling Wu, Limin Fan, Weiqiong Cao, Xiangliang Ma
CT-RSA3
2017 Improved Automatic Search Tool for Bit-Oriented Block Ciphers and Its Applications
Lingchen Li, Wenling Wu, Lei Zhang 0012
ICICS2
2017 Improved Automatic Search Tool for Related-Key Differential Characteristics on Byte-Oriented Block Ciphers
Li Lin 0003, Wenling Wu, Yafei Zheng
ISC2
2017 Analysis of permutation choices for enhanced generalised Feistel structure with SP-type round function
abstract
Since the proposition of improved generalised Feistel structure (GFS), many researches and applications have been published. In this study, the authors further enhance the improved GFS with SP‐type round function by extending the sub‐block‐wise permutation to word‐wise permutation which can have better diffusion and security effect. Then, they study the security effect of different permutation choices for this kind of enhanced GFS cipher with SP‐type round function. By proving several propositions about the equivalent situation, they can eliminate isomorphic permutations so as to narrow down the candidate space notably and propose a method to compute the number of effective permutation candidates. Finally, they take three typical scenes as example, and for each experimental scene, they compute the number of effective permutation candidates and exhaustively evaluate their security results. They also give an optimum permutation as example for each scene.
Lei Zhang 0012, Wenling Wu
IET Inf. Secur.2
2017 New constructions of resilient functions with strictly almost optimal nonlinearity via non-overlap spectra functions
Yongzhuang Wei, Enes Pasalic, Fengrong Zhang, Wenling Wu, Cheng-Xiang Wang 0001
Inf. Sci.4
2016 Linear Regression Attack with F-test: A New SCARE Technique for Secret Block Ciphers
Hua Chen 0011, Wenling Wu, Limin Fan, Jingyi Feng, Xiangliang Ma
CANS3
2016 Biclique Attack of Block Cipher SKINNY
Yafei Zheng, Wenling Wu
Inscrypt2
2016 New Observations on Piccolo Block Cipher
Wenling Wu
CT-RSA2
2016 Automatic Search for Key-Bridging Technique: Applications to LBlock and TWINE
Li Lin 0003, Wenling Wu, Yafei Zheng
FSE2
2016 Structural Evaluation for Simon-Like Designs Against Integral Attack
Wenling Wu
ISPEC2
2016 Security of SM4 Against (Related-Key) Differential Cryptanalysis
Wenling Wu, Yafei Zheng
ISPEC2
2016 Collision Attacks on CAESAR Second-Round Candidate: ELmD
Wenling Wu, Yafei Zheng
ISPEC2
2016 New criterion for diffusion property and applications to improved GFS and EGFN
Wenling Wu
Des. Codes Cryptogr.2
2016 Utilizing Probabilistic Linear Equations in Cube Attacks
Bin Zhang 0003, Wenling Wu
J. Comput. Sci. Technol.3
2015 A Single Query Forgery Attack on Raviyoyla v1
abstract
Raviyoyla v1 is an authenticated encryption algorithm submitted to the first round of the CAESAR competition which is a grand occasion launched recently to identify efficient, flexible and secure authenticated encryption primitives. Raviyoyla v1 is composed by an additive stream cipher motivated by the eSTREAM candidate MAG v2 and a keyed hash function. The designer declares $128$ bit security for authentication. In this paper, we propose a method to construct forgeries using a single query and the complexity is negligible. Indeed, we introduce differential of specific form to the public message and try to canceling it before outputting any authenticated tags. Specially, the differential is not restricted to any particular value and thus multiple forgeries may be made through a single query. Our theoretical analysis shows that the probability for a randomly selected differential of our form to be canceled out is at least $0.307143$. Therefore, it is sufficient to have three trials to obtain a forgery. Moreover, the probability can approaches one for some specialized values. Furthermore, the revised Raviyoyla v1 is vulnerable from our attack as well.
Bin Zhang 0003, Wenling Wu
AsiaCCS3
2015 Practical Lattice-Based Fault Attack and Countermeasure on SM2 Signature Algorithm
Weiqiong Cao, Jingyi Feng, Shaofeng Zhu, Hua Chen 0011, Wenling Wu, Xucang Han, Xiaoguang Zheng
ICICS5
2015 Automatic Search for Linear Trails of the SPECK Family
Bin Zhang 0003, Wenling Wu
ISC3
2015 Constructing Lightweight Optimal Diffusion Primitives with Feistel Structure
Wenling Wu
SAC2
2015 Improved Meet-in-the-Middle Distinguisher on Feistel Schemes
Li Lin 0003, Wenling Wu, Yafei Zheng
SAC2
2015 The DBlock family of block ciphers
Wenling Wu, Lei Zhang 0012, Xiaoli Yu
Sci. China Inf. Sci.1
2015 Known-key distinguishers on 15-round 4-branch type-2 generalised Feistel networks with single substitution-permutation functions and near-collision attacks on its hashing modes
abstract
Generalised Feistel network (GFN) is a popular design for block ciphers and hash functions. The round function of the network often chooses a substitution–permutation (SP) transformation (consists of a subkey XOR, an S‐boxes layer and a linear layer). In 2011, Bogdanov and Shibutani provided another choice to build round functions, namely the double SP‐functions, which has two SP‐layers in series. They showed that a 4‐branch type‐2 GFN with double SP‐functions was stronger than the one with single SP‐function in terms of the number of active S‐boxes in a differential or linear cryptanalysis, but some subsequent results showed that the double SP‐function is the weaker one in some known‐key scenarios and hashing modes. In this study, the authors present a new result of the 4‐branch type‐2 GFN, whose round function is a single SP‐function. They show some 15‐round truncated differential distinguishers for this network with four usual parameters by utilising some rebound attack techniques. Based on these distinguishers, they construct some 15‐round near‐collision attacks on the Matyas–Meyer–Oseas and Miyaguchi–Preneel compression function modes in which the 4‐branch type‐2 GFN with the single SP‐function is used.
Wenling Wu, Jian Zou 0002
IET Inf. Secur.3
2015 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
J. Cryptol.4
2014 Improved Multidimensional Zero-Correlation Linear Cryptanalysis and Applications to LBlock and TWINE
Wenling Wu
ACISP2
2014 Differential Cryptanalysis and Linear Distinguisher of Full-Round Zorro
Wenling Wu, Xiaoli Yu
ACNS2
2014 Known-key distinguishers on type-1 Feistel scheme and near-collision attacks on its hashing modes
Wenling Wu, Shuang Wu 0004, Jian Zou 0002
Frontiers Comput. Sci.2
2014 Differential analysis of the Extended Generalized Feistel Networks
Lei Zhang 0012, Wenling Wu
Inf. Process. Lett.2
2013 Leaked-State-Forgery Attack against the Authenticated Encryption Algorithm ALE
Shengbao Wu, Hongjun Wu 0001, Tao Huang 0015, Mingsheng Wang, Wenling Wu
ASIACRYPT (1)5
2013 LHash: A Lightweight Hash Function
Wenling Wu, Shuang Wu 0004, Lei Zhang 0012, Jian Zou 0002
Inscrypt1
2013 Cryptanalysis of the Round-Reduced GOST Hash Function
Jian Zou 0002, Wenling Wu, Shuang Wu 0004
Inscrypt2
2013 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
FSE4
2013 Attacking and Fixing the CS Mode
Han Sui, Wenling Wu, Peng Wang 0009
ICICS2
2013 Cryptanalysis of the OKH Authenticated Encryption Scheme
Peng Wang 0009, Wenling Wu
ISPEC2
2012 Extending Higher-Order Integral: An Efficient Unified Algorithm of Constructing Integral Distinguishers for Block Ciphers
Wentao Zhang 0006, Bozhan Su, Wenling Wu, Dengguo Feng, Chuankun Wu
ACNS3
2012 Investigating Fundamental Security Requirements on Whirlpool: Improved Preimage and Collision Attacks
Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004, Wenling Wu
ASIACRYPT4
2012 3kf9: Enhancing 3GPP-MAC beyond the Birthday Bound
Wenling Wu, Han Sui, Peng Wang 0009
ASIACRYPT2
2012 (Pseudo) Preimage Attack on Round-Reduced Grøstl Hash Function and Others
Shuang Wu 0004, Dengguo Feng, Wenling Wu, Jian Guo 0001, Jian Zou 0002
FSE3
2012 Biclique Cryptanalysis of Reduced-Round Piccolo Block Cipher
Wenling Wu, Xiaoli Yu
ISPEC2
2012 Recursive Diffusion Layers for (Lightweight) Block Ciphers and Hash Functions
Shengbao Wu, Mingsheng Wang, Wenling Wu
Selected Areas in Cryptography3
2012 TrCBC: Another look at CBC-MAC
Wenling Wu, Peng Wang 0009
Inf. Process. Lett.2
2011 LBlock: A Lightweight Block Cipher
Wenling Wu, Lei Zhang 0012
ACNS1
2011 Cryptanalysis of Reduced-Round KLEIN Block Cipher
Xiaoli Yu, Wenling Wu, Lei Zhang 0012
Inscrypt2
2011 BCBC: A More Efficient MAC Algorithm
Wenling Wu
ISPEC2
2011 PolyE+CTR: A Swiss-Army-Knife Mode for Block Ciphers
Wenling Wu, Peng Wang 0009
ProvSec2
2011 CBCR: CBC MAC with rotating transformations
Wenling Wu, Lei Zhang 0012, Peng Wang 0009
Sci. China Inf. Sci.2
2010 Near-Collisions on the Reduced-Round Compression Functions of Skein and BLAKE
Bozhan Su, Wenling Wu, Shuang Wu 0004
CANS2
2010 Hyper-Sbox View of AES-like Permutations: A Generalized Distinguisher
Shuang Wu 0004, Dengguo Feng, Wenling Wu, Bozhan Su
Inscrypt3
2010 Constructing Rate-1 MACs from Related-Key Unpredictable Block Ciphers: PGV Model Revisited
Wenling Wu, Peng Wang 0009, Lei Zhang 0012, Shuang Wu 0004
FSE2
2010 Integral Attacks on Reduced-Round ARIA Block Cipher
Wenling Wu, Lei Zhang 0012
ISPEC2
2009 A note on Cook's elastic block cipher
abstract
"VIL Block Cipher" is a kind of block cipher that supports Variable Input-Lengths. It was first proposed by Bellare, etc. and since then several constructions have been given, among which Cook's elastic block cipher is a special one. In this paper we present a security model called "MIL model" for VIL block ciphers, investigating their security when a fixed secret key is used for multiple input-lengths. Our results show that if the key schedule is not well designed, Cook's elastic block cipher is vulnerable when processing multiple-length inputs under a fixed secret key. Thus, further considerations are needed to use Cook's elastic block cipher safely in practice.
Wenling Wu, Lei Zhang 0012
AsiaCCS2
2009 Proposition of Two Cipher Structures
Lei Zhang 0012, Wenling Wu
Inscrypt2
2009 Security Analysis of the GF-NLFSR Structure and Four-Cell Block Cipher
Wenling Wu, Lei Zhang 0012, Wentao Zhang 0006
ICICS1
2009 On the Correctness of an Approach against Side-Channel Attacks
Peng Wang 0009, Dengguo Feng, Wenling Wu
ISPEC3
2009 Some New Observations on the SMS4 Block Cipher in the Chinese WAPI Standard
Wentao Zhang 0006, Wenling Wu, Dengguo Feng, Bozhan Su
ISPEC2
2008 On the Unprovable Security of 2-Key XCBC
Peng Wang 0009, Dengguo Feng, Wenling Wu
ACISP3
2008 Cryptanalysis of Reduced-Round SMS4 Block Cipher
Lei Zhang 0012, Wentao Zhang 0006, Wenling Wu
ACISP3
2008 Security of Truncated MACs
Peng Wang 0009, Dengguo Feng, Changlu Lin, Wenling Wu
Inscrypt4
2008 Analysis of Zipper as a Hash Function
Pin Lin, Wenling Wu, Chuankun Wu
ISPEC2
2008 Improved Impossible Differential Attacks on Large-Block Rijndael
Lei Zhang 0012, Wenling Wu, Je Hong Park, Bonwook Koo, Yongjin Yeom
ISC2
2007 Differential Fault Analysis on CLEFIA
Hua Chen 0011, Wenling Wu, Dengguo Feng
ICICS2
2007 Constructing parallel long-message signcryption scheme from trapdoor permutation
ZhenYu Hu, Dongdai Lin, Wenling Wu, Dengguo Feng
Sci. China Ser. F Inf. Sci.3
2007 Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
Wenling Wu, Wentao Zhang 0006, Dengguo Feng
J. Comput. Sci. Technol.1
2006 An Improved Poly1305 MAC
Dayin Wang, Dongdai Lin, Wenling Wu
ACNS3
2006 OPMAC: One-Key Poly1305 MAC
Dayin Wang, Dongdai Lin, Wenling Wu
Inscrypt3
2006 Pseudorandomness of Camellia-Like Scheme
Wenling Wu
J. Comput. Sci. Technol.1
2006 Incomplete exponential sums over galois rings with applications to some binary sequences derived from Z2l
abstract
An upper bound for the incomplete exponential sums over Galois rings is derived explicitly. Based on the incomplete exponential sums, we analyze the partial period properties of some binary sequences derived from Z/sub 2//sup l/ in detail, such as the Kerdock-code binary sequences and the highest level sequences of primitive sequences over Z/sub 2//sup l/. The results show that the partial period distributions and the partial period independent r-pattern distributions of these binary sequences are asymptotically uniform. Nontrivial upper bounds for the aperiodic autocorrelation of these sequences are also given.
Honggang Hu, Dengguo Feng, Wenling Wu
IEEE Trans. Inf. Theory3
2005 On the Security of Tweakable Modes of Operation: TBC and TAE
Peng Wang 0009, Dengguo Feng, Wenling Wu
ISC3
2005 Collision attack on reduced-round Camellia
abstract
Camellia is the final winner of 128-bit block cipher in NESSIE.In this paper, we construct some efficient distinguishers between 4-round Camellia and a random permutation of the blocks space.By using collision-searching techniques, the distinguishers are used to attack on 6,7,8 and 9 rounds of Camellia with 128bit key and 8,9 and 10 rounds of Camellia with 192/256-bit key.The 128-bit key of 6 rounds Camellia can be recovered with 2 10 chosen plaintexts and 2 15 encryptions.The 128-bit key of 7 rounds Camellia can be recovered with 2 12 chosen plaintexts and 2 54.5 encryptions.The 128-bit key of 8 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 112.1 encryptions.The 128-bit key of 9 rounds Camellia can be recovered with 2 113.6 chosen plaintexts and 2 121 encryptions.The 192/256-bit key of 8 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 111.1 encryptions.The 192/256-bit key of 9 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 175.6 encryptions.The 256-bit key of 10 rounds Camellia can be recovered with 2 14 chosen plaintexts and 2 239.9 encryptions.
Wenling Wu, Dengguo Feng
Sci. China Ser. F Inf. Sci.1
2002 Linear cryptanalysis of NUSH block cipher
abstract
NUSH is a block cipher as a candidate for NESSIE. NUSH is analyzed by linear crypt-analysis. The complexity δ=(ε, η) of the attack consists of data complexity ε and time complexity η. Three linear approximations are used to analyze NUSH with 64-bit block. When | K |=128 bits, the complexities of three attacks are (2 58 , 2 124 ), (2 60 , 2 78 ) and (2 62 , 2 55 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 58 , 2 157 ) (2 60 , 2 96 ) and (2 62 , 2 58 ) respectively. When | K | =256 bits, the complexities of three attacks are (2 58 , 2 125 ), (2 60 , 2 78 ) and (2 62 , 2 53 ) respectively. Three linear approximations are used to analyze NUSH with 128-bit block. When | K |=128 bits, the complexities of three attacks are (2 122 , 2 95 ), (2 124 , 2 57 ) and (2 126 , 2 52 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 122 , 2 142 ), (2 124 , 2 75 ) and (2 126 , 2 58 ) respectively. When | K |=256 bits, the complexities of three attacks are (2 122 , 2 168 ), (2 124 , 2 81 ) and (2 126 , 2 64 ) respectively. Two linear approximations are used to analyze NUSH with 256-bit block. When | K |=128 bits, the complexities of two attacks are (2 252 , 2 122 ) and (2 254 , 2 119 ) respectively. When | K |=192 bits, the complexities of two attacks are (2 252 , 2 181 ) and (2 254 , 2 177 ) respectively. When | K |=256 bits, the complexities of two attacks are (2 252 , 2 240 ) and (2 254 , 2 219 ) respectively. These results show that NUSH is not immune to linear cryptanalysis, and longer key cannot enhance the security of NUSH.
Wenling Wu, Dengguo Feng
Sci. China Ser. F Inf. Sci.1
2000 Power Analysis of RC6 and Serpent
Wenling Wu, Dengguo Feng, Sihan Qing
SEC1
1999 Cryptanalysis of some AES Candidate Algorithms
Wenling Wu, Bao Li 0001, Dengguo Feng, Sihan Qing
ICICS1