Gregor Leander

dblp:90/4585 · also Nils Gregor Leander · DBLP profile ↗
← Back
95ranked-venue papers
12as first author
27since 2021 · last 2026
0000-0002-2579-8587ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 80 · 9 first-author · 24 since 2021Theory of computation · 12 · 3 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2026 Robust Single-Trace Full-Key Extraction from Million-Point Traces With Cross-Implementation Transfer
Aron Gohr, Friederike Laus, Gregor Leander
CRYPTO (7)3
2026 When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks
Christof Beierle, Gregor Leander, Yevhen Perehuda
EUROCRYPT2
2026 Pairwise Independence of AES-Like Block Ciphers
Tim Beyne, Gregor Leander, Immo Schütt
EUROCRYPT2
2025 Integral Resistance of Block Ciphers with Key Whitening by Modular Addition
Christof Beierle, Phil Hebborn, Gregor Leander, Yevhen Perehuda
CRYPTO (5)3
2025 INDIANA - Verifying (Random) Probing Security Through Indistinguishability Analysis
Christof Beierle, Jakob Feldtkeller, Anna Guinet, Tim Güneysu, Gregor Leander, Jan Richter-Brockmann, Pascal Sasdrich
EUROCRYPT (8)5
2025 ChiLow and ChiChi: New Constructions for Code Encryption
Yanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander, Silvia Mella, Léo Perrin, Shahram Rasoolzadeh, Lukas Stennes, Siwei Sun, Gilles Van Assche, Damian Vizár
EUROCRYPT (1)4
2025 Commutative cryptanalysis as a generalization of differential cryptanalysis
abstract
Abstract Recently, Baudrin et al. analyzed a special case of Wagner’s commutative diagram cryptanalysis, referred to as commutative cryptanalysis. For a family $$(E_k)_k$$ ( E k ) k of permutations on a finite vector space G, commutative cryptanalysis exploits the existence of affine permutations $$A,B :G \rightarrow G$$ A , B : G → G , $$I \notin \{A,B\}$$ I ∉ { A , B } such that $$E_k \circ A (x) = B \circ E_k(x)$$ E k ∘ A ( x ) = B ∘ E k ( x ) holds with high probability, taken over inputs x, for a significantly large set of weak keys k. Several attacks against symmetric cryptographic primitives can be formulated within the framework of commutative cryptanalysis, most importantly differential attacks, as well as rotational and rotational-differential attacks. Besides, the notion of c-differentials on S-boxes can be analyzed as a special case within this framework. We discuss the relations between a general notion of commutative cryptanalysis, with A and B being arbitrary functions over a finite Abelian group, and differential cryptanalysis, both from the view of conducting an attack on a symmetric cryptographic primitive, as well as from the view of a theoretical study of cryptographic S-boxes.
Jules Baudrin, Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Léo Perrin, Lukas Stennes
Des. Codes Cryptogr.4
2025 Improved key recovery attacks on reduced-round Salsa20
Sabyasachi Dey 0001, Gregor Leander, Nitin Kumar Sharma 0001
Des. Codes Cryptogr.2
2024 General Practical Cryptanalysis of the Sum of Round-Reduced Block Ciphers and ZIP-AES
Antonio Flórez-Gutiérrez, Lorenzo Grassi 0001, Gregor Leander, Ferdinand Sibleyras, Yosuke Todo
ASIACRYPT (9)3
2024 HAWKEYE - Recovering Symmetric Cryptography From Hardware Circuits
Gregor Leander, Christof Paar, Julian Speith, Lukas Stennes
CRYPTO (4)1
2023 On Perfect Linear Approximations and Differentials over Two-Round SPNs
Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Lukas Stennes
CRYPTO (3)3
2023 Differential Meet-In-The-Middle Cryptanalysis
Christina Boura, Nicolas David 0001, Patrick Derbez, Gregor Leander, María Naya-Plasencia
CRYPTO (3)4
2023 Pitfalls and Shortcomings for Decompositions and Alignment
Baptiste Lambin, Gregor Leander, Patrick Neumann 0004
EUROCRYPT (4)2
2023 SCARF - A Low-Latency Block Cipher for Secure Cache-Randomization
Federico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma, Yosuke Todo, Rei Ueno
USENIX Security Symposium3
2023 ClepsydraCache - Preventing Cache Attacks with Time-Based Evictions
Jan Philipp Thoma, Christian Niesler, Dominic A. Funke, Gregor Leander, Pierre Mayr, Nils Pohl, Lucas Davi, Tim Güneysu
USENIX Security Symposium4
2022 Constructing and Deconstructing Intentional Weaknesses in Symmetric Ciphers
Christof Beierle, Tim Beyne, Patrick Felke, Gregor Leander
CRYPTO (3)4
2022 Simon's Algorithm and Symmetric Crypto: Generalizations and Automatized Applications
Federico Canale, Gregor Leander, Lukas Stennes
CRYPTO (3)2
2022 New Attacks from Old Distinguishers Improved Attacks on Serpent
Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo
CT-RSA5
2022 A Cautionary Note on Protecting Xilinx' UltraScale(+) Bitstream Encryption and Authentication Engine
abstract
FPGA bitstream protection schemes are often the first line of defense for secure hardware designs. In general, breaking the bitstream encryption would enable attackers to subvert the confidentiality and infringe on the IP. Or breaking the authenticity enables manipulating the design, e.g., inserting hardware Trojans. Since FPGAs see widespread use in our interconnected world, such attacks can lead to severe damages, including physical harm. Recently we [1] presented a surprising attack — Starbleed — on Xilinx 7-Series FPGAs, tricking an FPGA into acting as a decryption oracle. For their UltraScale(+) series, Xilinx independently upgraded the security features to AES-GCM, RSA signatures, and a periodic GHASH-based checksum to validate the bitstream during decryption. Hence, UltraScale(+) devices were considered not affected by Starbleed-like attacks [2], [1].We identified novel security weaknesses in Xilinx UltraScale(+) FPGAs if configured outside recommended settings. In particular, we present four attacks in this situation: two attacks on the AES encryption and novel GHASH-based checksum and two authentication downgrade attacks. As a major contribution, we show that the Starbleed attack is still possible within the UltraScale(+) series by developing an attack against the GHASH-based checksum. After describing and analyzing the attacks, we list the subtle configuration changes which can lead to security vulnerabilities and secure configurations not affected by our attacks. As Xilinx only recommends configurations not affected by our attacks, users should be largely secure. However, it is not unlikely that users employ settings outside the recommendations, given the rather large number of configuration options and the fact that Security Misconfiguration is among the leading top 10 OWASP security issues. We note that these security weaknesses shown in this paper had been unknown before.
Maik Ender, Gregor Leander, Amir Moradi 0001, Christof Paar
FCCM2
2022 Trims and extensions of quadratic APN functions
abstract
Abstract In this work, we study functions that can be obtained by restricting a vectorial Boolean function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n to an affine hyperplane of dimension $$n-1$$ n-1 and then projecting the output to an $$n-1$$ n-1 -dimensional space. We show that a multiset of $$2 \cdot (2^n-1)^2$$ 2·(2n-1)2 EA-equivalence classes of such restrictions defines an EA-invariant for vectorial Boolean functions on $$\mathbb {F}_{2}^n$$ F2n . Further, for all of the known quadratic APN functions in dimension $$n < 10$$ n<10 , we determine the restrictions that are also APN. Moreover, we construct 6368 new quadratic APN functions in dimension eight up to EA-equivalence by extending a quadratic APN function in dimension seven. A special focus of this work is on quadratic APN functions with maximum linearity. In particular, we characterize a quadratic APN function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n with linearity of $$2^{n-1}$$ 2n-1 by a property of the ortho-derivative of its restriction to a linear hyperplane. Using the fact that all quadratic APN functions in dimension seven are classified, we are able to obtain a classification of all quadratic 8-bit APN functions with linearity $$2^7$$ 27 up to EA-equivalence.
Christof Beierle, Gregor Leander, Léo Perrin
Des. Codes Cryptogr.2
2022 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo
J. Cryptol.6
2022 New Instances of Quadratic APN Functions
abstract
In a recent work, Beierle, Brinkmann and Leander presented a recursive tree search for finding APN permutations with linear self-equivalences in small dimensions. In this paper, we describe how this search can be adapted to find many new instances of quadratic APN functions. In particular, we found 12,921 new quadratic APN functions in dimension eight, 35 new quadratic APN functions in dimension nine and five new quadratic APN functions in dimension ten up to CCZ-equivalence. Remarkably, two of the 35 new APN functions in dimension nine are APN permutations. Among the 8-bit APN functions, there are three extended Walsh spectra that do not correspond to any of the previously-known quadratic 8-bit APN functions and, surprisingly, there exist at least four CCZ-inequivalent 8-bit APN functions with linearity 27, i.e., the highest possible non-trivial linearity for quadratic functions in dimension eight.
Christof Beierle, Gregor Leander
IEEE Trans. Inf. Theory2
2021 Generic Framework for Key-Guessing Improvements
Marek Broll, Federico Canale, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia
ASIACRYPT (1)4
2021 Strong and Tight Security Guarantees Against Integral Distinguishers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo
ASIACRYPT (1)3
2021 Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes
EUROCRYPT (2)3
2021 Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
J. Cryptol.2
2021 Linearly Self-Equivalent APN Permutations in Small Dimension
abstract
All almost perfect nonlinear (APN) permutations that we know to date admit a special kind of linear self-equivalence, i.e., there exists a permutation G in their CCZ-equivalence class and two linear permutations A and B, such that G °A = B °G. After providing a survey on the known APN functions with a focus on the existence of self-equivalences, we search for APN permutations in dimension 6, 7, and 8 that admit such a linear self-equivalence. In dimension six, we were able to conduct an exhaustive search and obtain that there is only one such APN permutation up to CCZ-equivalence. In dimensions 7 and 8, we performed an exhaustive search for all but a few classes of linear self-equivalences and we did not find any new APN permutation. As one interesting result in dimension 7, we obtain that all APN permutation polynomials with coefficients in \mathbb F2must be (up to CCZ-equivalence) monomial functions.
Christof Beierle, Marcus Brinkmann, Gregor Leander
IEEE Trans. Inf. Theory3
2020 Lower Bounds on the Degree of Block Ciphers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo
ASIACRYPT (1)3
2020 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Gregor Leander, Yosuke Todo
CRYPTO (3)2
2020 Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer
CRYPTO (3)5
2020 Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
EUROCRYPT (1)2
2020 PRINCEv2 - More Security for (Almost) No Overhead
Dusan Bozilov, Maria Eichlseder, Miroslav Knezevic, Baptiste Lambin, Gregor Leander, Thorben Moos, Ventzislav Nikov, Shahram Rasoolzadeh, Yosuke Todo, Friedrich Wiemer
SAC5
2020 Weak-Key Distinguishers for AES
Lorenzo Grassi 0001, Gregor Leander, Christian Rechberger, Cihangir Tezcan, Friedrich Wiemer
SAC2
2019 Universal Forgery and Multiple Forgeries of MergeMAC and Generalized Constructions
Tetsu Iwata, Virginie Lallemand, Gregor Leander, Yu Sasaki 0001
CT-RSA3
2019 bison Instantiating the Whitened Swap-Or-Not Construction
Anne Canteaut, Virginie Lallemand, Gregor Leander, Patrick Neumann 0004, Friedrich Wiemer
EUROCRYPT (3)3
2019 Nonlinear Invariant Attack: Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
J. Cryptol.2
2018 Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger
CRYPTO (1)5
2018 Nonlinear diffusion layers
Yunwen Liu, Vincent Rijmen, Gregor Leander
Des. Codes Cryptogr.3
2017 Grover Meets Simon - Quantumly Attacking the FX-construction
Gregor Leander, Alexander May 0001
ASIACRYPT (2)1
2017 Proving Resistance Against Invariant Attacks: How to Choose the Round Constants
Christof Beierle, Anne Canteaut, Gregor Leander, Yann Rotella
CRYPTO (2)3
2017 Reflection ciphers
Christina Boura, Anne Canteaut, Lars R. Knudsen, Gregor Leander
Des. Codes Cryptogr.4
2017 Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg
J. Cryptol.2
2016 Nonlinear Invariant Attack - Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
ASIACRYPT (2)2
2016 Strong 8-bit Sboxes with Efficient Masking in Hardware
Erik Boss, Vincent Grosso, Tim Güneysu, Gregor Leander, Amir Moradi 0001, Tobias Schneider 0002
CHES4
2016 The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim
CRYPTO (2)4
2016 Lightweight Multiplication in GF(2^n) with Applications to MDS Matrices
Christof Beierle, Thorsten Kranz, Gregor Leander
CRYPTO (1)3
2015 Observations on the SIMON Block Cipher Family
Stefan Kölbl, Gregor Leander, Tyge Tiessen
CRYPTO (1)2
2015 Analyzing Permutations for AES-like Ciphers: Understanding ShiftRows
Christof Beierle, Philipp Jovanovic, Martin M. Lauridsen, Gregor Leander, Christian Rechberger
CT-RSA4
2015 A Generic Approach to Invariant Subspace Attacks: Cryptanalysis of Robin, iSCREAM and Zorro
Gregor Leander, Brice Minaud, Sondre Rønjom
EUROCRYPT (1)1
2015 Custom-fit security for efficient and pollution-resistant multicast OTA-programming with fountain codes
abstract
In this work we describe the implementation details of a protocol suite for a secure and reliable over-the-air reprogramming of wireless restricted devices. Although, recently forward error correction codes aiming at a robust transmission over a noisy wireless medium have extensively been discussed and evaluated, we believe that the clear value of the contribution at hand is to share our experience when it comes to a meaningful combination and implementation of various multihop (broadcast) transmission protocols and custom-fit security building blocks: For a robust and reliable data transmission we make use of fountain codes a.k.a. rateless erasure codes and show how to combine such schemes with an underlying medium access control protocol, namely a distributed low duty cycle medium access control (DLDC-MAC). To handle the well known problem of packet pollution of forward-error-correction approaches where an attacker bogusly modifies or infiltrates some minor number of encoded packets and thus pollutes the whole data stream at the receiver side, we apply homomorphic message authentication codes (HomMAC). We discuss implementation details and the pros and cons of the two currently available HomMAC candidates for our setting. Both require as the core cryptographic primitive a symmetric block cipher for which, as we will argue later, we have opted for the PRESENT, PRIDE and PRINCE (exchangeable) ciphers in our implementation.
Oliver Stecklina, Stephan Kornemann, Felix Grehl, Ramona Jung, Thorsten Kranz, Gregor Leander, Dennis Schweer, Katharina Mollus, Dirk Westhoff
I4CS6
2015 Intrinsic Code Attestation by Instruction Chaining for Embedded Devices
Oliver Stecklina, Peter Langendörfer, Frank Vater, Thorsten Kranz, Gregor Leander
SecureComm5
2014 Block Ciphers - Focus on the Linear Layer (feat. PRIDE)
Martin R. Albrecht, Benedikt Driessen, Elif Bilge Kavun, Gregor Leander, Christof Paar, Tolga Yalçin
CRYPTO (1)4
2014 Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg
FSE2
2013 Bounds in Shallows and in Miseries
Céline Blondeau, Andrey Bogdanov, Gregor Leander
CRYPTO (1)3
2013 Fuming Acid and Cryptanalysis: Handy Tools for Overcoming a Digital Locking and Access Control System
Daehyun Strobel, Benedikt Driessen, Timo Kasper, Gregor Leander, David F. Oswald, Falk Schellenberg, Christof Paar
CRYPTO (1)4
2013 A new construction of bent functions based on $${\mathbb{Z}}$$ -bent functions
Sugata Gangopadhyay, Anand B. Joshi, Gregor Leander, Rajendra Kumar Sharma
Des. Codes Cryptogr.3
2013 Slender-Set Differential Cryptanalysis
Julia Borghoff, Lars R. Knudsen, Gregor Leander, Søren S. Thomsen
J. Cryptol.3
2013 SPONGENT: The Design Space of Lightweight Cryptographic Hashing
abstract
The design of secure yet efficiently implementable cryptographic algorithms is a fundamental problem of cryptography. Lately, lightweight cryptography--optimizing the algorithms to fit the most constrained environments--has received a great deal of attention, the recent research being mainly focused on building block ciphers. As opposed to that, the design of lightweight hash functions is still far from being well investigated with only few proposals in the public domain. In this paper, we aim to address this gap by exploring the design space of lightweight hash functions based on the sponge construction instantiated with present-type permutations. The resulting family of hash functions is called spongent. We propose 13 spongent variants--or different levels of collision and (second) preimage resistance as well as for various implementation constraints. For each of them, we provide several ASIC hardware implementations--ranging from the lowest area to the highest throughput. We make efforts to address the fairness of comparison with other designs in the field by providing an exhaustive hardware evaluation on various technologies, including an open core library. We also prove essential differential properties of spongent permutations, give a security analysis in terms of collision and preimage resistance, as well as study in detail dedicated linear distinguishers.
Andrey Bogdanov, Miroslav Knezevic, Gregor Leander, Deniz Toz, Kerem Varici, Ingrid Verbauwhede
IEEE Trans. Computers3
2012 Integral and Multidimensional Linear Distinguishers with Correlation Zero
Andrey Bogdanov, Gregor Leander, Kaisa Nyberg
ASIACRYPT2
2012 PRINCE - A Low-Latency Block Cipher for Pervasive Computing Applications - Extended Abstract
Julia Borghoff, Anne Canteaut, Tim Güneysu, Elif Bilge Kavun, Miroslav Knezevic, Lars R. Knudsen, Gregor Leander, Ventzislav Nikov, Christof Paar, Christian Rechberger, Peter Rombouts, Søren S. Thomsen, Tolga Yalçin
ASIACRYPT7
2012 On the Distribution of Linear Biases: Three Instructive Examples
Mohamed Ahmed Abdelraheem, Martin Ågren, Peter Beelen, Gregor Leander
CRYPTO4
2012 Key-Alternating Ciphers in a Provable Setting: Encryption Using a Small Number of Public Permutations - (Extended Abstract)
Andrey Bogdanov, Lars R. Knudsen, Gregor Leander, François-Xavier Standaert, John P. Steinberger, Elmar Tischhauser
EUROCRYPT3
2012 An All-In-One Approach to Differential Cryptanalysis for Small Block Ciphers
Martin R. Albrecht, Gregor Leander
Selected Areas in Cryptography2
2011 spongent: A Lightweight Hash Function
Andrey Bogdanov, Miroslav Knezevic, Gregor Leander, Deniz Toz, Kerem Varici, Ingrid Verbauwhede
CHES3
2011 A Cryptanalysis of PRINTcipher: The Invariant Subspace Attack
Gregor Leander, Mohamed Ahmed Abdelraheem, Hoda Alkhzaimi, Erik Zenner
CRYPTO1
2011 On Linear Hulls, Statistical Saturation Attacks, PRESENT and a Cryptanalysis of PUFFIN
Gregor Leander
EUROCRYPT1
2011 Differential Cryptanalysis of Round-Reduced PRINTcipher: Computing Roots of Permutations
Mohamed Ahmed Abdelraheem, Gregor Leander, Erik Zenner
FSE2
2011 Cryptanalysis of PRESENT-Like Ciphers with Secret S-Boxes
Julia Borghoff, Lars R. Knudsen, Gregor Leander, Søren S. Thomsen
FSE3
2011 Counting all bent functions in dimension eight 99270589265934370305785861242880
Philippe Langevin, Gregor Leander
Des. Codes Cryptogr.2
2011 Bounds on the degree of APN polynomials: the case of x-1 + g(x)
Gregor Leander, François Rodier
Des. Codes Cryptogr.1
2010 PRINTcipher: A Block Cipher for IC-Printing
Lars R. Knudsen, Gregor Leander, Axel Poschmann, Matthew J. B. Robshaw
CHES2
2009 Cryptanalysis of C2
Julia Borghoff, Lars R. Knudsen, Gregor Leander, Krystian Matusiewicz
CRYPTO3
2009 Cache Timing Analysis of LFSR-Based Stream Ciphers
Gregor Leander, Erik Zenner, Philip Hawkes
IMACC1
2008 Sufficient Conditions for Intractability over Black-Box Groups: Generic Lower Bounds for Generalized DL and DH Problems
Andy Rupp, Gregor Leander, Endre Bangerter, Alexander W. Dent, Ahmad-Reza Sadeghi
ASIACRYPT2
2008 Ultra-Lightweight Implementations for Smart Devices - Security for 1000 Gate Equivalents
Carsten Rolfes, Axel Poschmann, Gregor Leander, Christof Paar
CARDIS3
2008 Hash Functions and RFID Tags: Mind the Gap
Andrey Bogdanov, Gregor Leander, Christof Paar, Axel Poschmann, Matthew J. B. Robshaw, Yannick Seurin
CHES2
2008 On the classification of APN functions up to dimension five
Marcus Brinkmann, Gregor Leander
Des. Codes Cryptogr.2
2008 Bent functions embedded into the recursive framework of ℤ-bent functions
Hans Dobbertin, Gregor Leander
Des. Codes Cryptogr.2
2008 Two Classes of Quadratic APN Binomials Inequivalent to Power Functions
abstract
This paper introduces the first found infinite classes of almost perfect nonlinear (APN) polynomials which are not Carlet-Charpin-Zinoviev (CCZ)-equivalent to power functions (at least for some values of the number of variables). These are two classes of APN binomials from F2nto F2n(for n divisible by 3, resp., 4). We prove that these functions are extended affine (EA)-inequivalent to any power function and that they are CCZ-inequivalent to the Gold, Kasami, inverse, and Dobbertin functions when n ges 12. This means that for n even they are CCZ-inequivalent to any known APN function. In particular, for n = 12,20,24, they are therefore CCZ-inequivalent to any power function.
Lilya Budaghyan, Claude Carlet, Gregor Leander
IEEE Trans. Inf. Theory3
2008 On Codes, Matroids, and Secure Multiparty Computation From Linear Secret-Sharing Schemes
abstract
Error-correcting codes and matroids have been widely used in the study of ordinary secret sharing schemes. In this paper, the connections between codes, matroids, and a special class of secret sharing schemes, namely, multiplicative linear secret sharing schemes (LSSSs), are studied. Such schemes are known to enable multiparty computation protocols secure against general (nonthreshold) adversaries. Two open problems related to the complexity of multiplicative LSSSs are considered in this paper. The first one deals with strongly multiplicative LSSSs. As opposed to the case of multiplicative LSSSs, it is not known whether there is an efficient method to transform an LSSS into a strongly multiplicative LSSS for the same access structure with a polynomial increase of the complexity. A property of strongly multiplicative LSSSs that could be useful in solving this problem is proved. Namely, using a suitable generalization of the well-known Berlekamp-Welch decoder, it is shown that all strongly multiplicative LSSSs enable efficient reconstruction of a shared secret in the presence of malicious faults. The second one is to characterize the access structures of ideal multiplicative LSSSs. Specifically, the considered open problem is to determine whether all self-dual vector space access structures are in this situation. By the aforementioned connection, this in fact constitutes an open problem about matroid theory, since it can be restated in terms of representability of identically self-dual matroids by self-dual codes. A new concept is introduced, the flat-partition, that provides a useful classification of identically self-dual matroids. Uniform identically self-dual matroids, which are known to be representable by self-dual codes, form one of the classes. It is proved that this property also holds for the family of matroids that, in a natural way, is the next class in the above classification: the identically self-dual bipartite matroids.
Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jiménez Urroz, Gregor Leander, Jaume Martí-Farré, Carles Padró
IEEE Trans. Inf. Theory5
2007 PRESENT: An Ultra-Lightweight Block Cipher
Andrey Bogdanov, Lars R. Knudsen, Gregor Leander, Christof Paar, Axel Poschmann, Matthew J. B. Robshaw, Yannick Seurin, C. Vikkelsoe
CHES3
2007 New Lightweight DES Variants
Gregor Leander, Christof Paar, Axel Poschmann, Kai Schramm
FSE1
2007 New Light-Weight Crypto Algorithms for RFID
abstract
The authors propose a new block cipher, DESL (DES Lightweight extension), which is strong, compact and efficient. Due to its low area constraints DESL is especially suited for RFID(Radio Frequency Identification) devices. DESL is based on the classical DES (Data Encryption Standard) design, however, unlike DES it uses a single S-box repeated eight times. This approach makes it possible to considerably decrease chip size requirements. The S-box has been highly optimized in such a way that DESL resists common attacks, i.e., linear and differential cryptanalysis, and the Davies-Murphy-attack. Therefore DESL achieves a security level which is appropriate for many applications. Furthermore, we propose a light-weight implementation of DESL which requires 45% less chip size and 86% less clock cycles than the best AES implementations with regard to RFID applications. Compared to the smallest DES implementation published, our DESL design requires 38% less transistors. Our 0.18μmDESL implementation requires a chip size of 7392 transistors (1848 gate equivalences) and is capable to encrypt a 64-bit plaintext in 144 clock cycles. When clocked at 100 kHz, it draws an average current of only 0.89μA. These hardware figures are in the range of the best eSTREAM streamcipher candidates, comprising DESL as a new alternative for ultra low-cost encryption
Axel Poschmann, Gregor Leander, Kai Schramm, Christof Paar
ISCAS2
2007 On the Classification of 4 Bit S-Boxes
Gregor Leander, Axel Poschmann
WAIFI1
2007 A Counterexample to a Conjecture of Niho
abstract
A conjecture of Niho states that under certain assumptions the Fourier transform of the function${\rm Tr}(x^{d})$on$\BBF _{2^{n}}$, where$d=(2^{tk}+1)/(2^{k}+1)$, has a spectrum with at most five values. We present a counterexample to this conjecture, and the theory behind finding it. We use the theory of quadratic forms over$\BBF _{2}$.
Philippe Langevin, Gregor Leander, Gary McGuire
IEEE Trans. Inf. Theory2
2006 On the Equivalence of RSA and Factoring Regarding Generic Ring Algorithms
Gregor Leander, Andy Rupp
ASIACRYPT1
2006 An infinite class of quadratic APN functions which are not equivalent to power mappings
abstract
We exhibit an infinite class of almost perfect nonlinear quadratic polynomials from F2nto F2n(n ges 12, n divisible by 3 but not by 9). We prove that these functions are EA-inequivalent to any power function and that they are CCZ-inequivalent to any Gold function. In a forthcoming full paper, we shall also prove that at least some of these functions are CCZ-inequivalent to any Kasami function
Lilya Budaghyan, Claude Carlet, Patrick Felke, Gregor Leander
ISIT4
2006 Finding nonnormal bent functions
Anne Canteaut, Magnus Daum, Hans Dobbertin, Gregor Leander
Discret. Appl. Math.4
2006 Monomial bent functions
abstract
In this correspondence, we focus on bent functions of the form F(2/sup n/) /spl rarr/ F(2) where x /spl rarr/ Tr(/spl alpha/x/sup d/). The main contribution of this correspondence is, that we prove that for n=4r, r odd, the exponent d=(2/sup r/+1)/sup 2/ allows the construction of bent functions. This open question has been posed by Canteaut based on computer experiments. As a consequence for each of the well understood families of bent functions, we now know an exponent d that yields to bent functions of the given type.
Gregor Leander
IEEE Trans. Inf. Theory1
2006 Bent Functions With 2r Niho Exponents
abstract
In this note, a new primary construction of bent functions consisting of a linear combination of $2^r$ Niho exponents is presented. This construction generalizes one of the constructions proven by H. Dobbertin, G. Leander, A. Canteaut, C. Carlet, P. Felke, and P. Gaborit.
Gregor Leander, Alexander Kholosha
IEEE Trans. Inf. Theory1
2005 On Codes, Matroids and Secure Multi-party Computation from Linear Secret Sharing Schemes
Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jiménez Urroz, Gregor Leander, Jaume Martí-Farré, Carles Padró
CRYPTO5
2005 Secure Computation of the Mean and Related Statistics
Eike Kiltz, Gregor Leander, John Malone-Lee
TCC2
2004 A Collision-Attack on AES: Combining Side Channel- and Differential-Attack
Kai Schramm, Gregor Leander, Patrick Felke, Christof Paar
CHES2
2004 A Survey of Some Recent Results on Bent Functions
Hans Dobbertin, Gregor Leander
SETA2
2004 Normal Extensions of Bent Functions
abstract
In this paper, the notion of normal extension is introduced for bent functions, i.e., maximally nonlinear Boolean functions. We apply this concept to characterize when the direct sum of bent functions is normal, and we prove that the direct sum of a normal bent function and a nonnormal bent function is always nonnormal.
Claude Carlet, Hans Dobbertin, Gregor Leander
IEEE Trans. Inf. Theory3