Jun Xu 0022

dblp:90/514-22 · DBLP profile ↗
← Back
25ranked-venue papers
14as first author
8since 2021 · last 2026
0000-0002-1179-7487ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 10 first-author · 6 since 2021Computer networks · 3 · 2 first-authorTheory of computation · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 New Results on Elliptic Curve Hidden Number Problem for ECDH Key Exchange
Jun Xu 0022, Santanu Sarkar 0001, Huaxiong Wang, Lei Hu 0003
J. Cryptol.1
2023 Revisiting Modular Inversion Hidden Number Problem and Its Applications
abstract
The Modular Inversion Hidden Number Problem (MIHNP), which was proposed at Asiacrypt 2001 by Boneh, Halevi, and Howgrave-Graham, is summarized as follows: Assume that the$\delta $most significant bits of$z$are denoted by${\mathrm {MSB}}_{\delta }(z)$. The goal is to retrieve the hidden number$\alpha \in \mathbb {Z}_{p}$given many samples$\left ({t_{i}, {\mathrm {MSB}}_{\delta }((\alpha + t_{i})^{-1} \bmod {p})}\right)$for random$t_{i} \in \mathbb {Z}_{p}$. MIHNP is a significant subset of Hidden Number Problems. Eichenauer and Lehn introduced the Inversive Congruential Generator (ICG) in 1986. It is basically characterized as follows: For iterated relations$v_{i+1}=(av^{-1}_{i}+b)\bmod {p}$with a secret seed$v_{0} \in \mathbb {Z}_{p}$, each iteration produces$\mathrm {MSB}_{\delta }(v_{i+1})$where$i \geq 0$. The ICG family of pseudorandom number generators is a significant subclass of number-theoretic pseudorandom number generators. Sakai-Kasahara scheme is an identity-based encryption (IBE) system proposed by Sakai and Kasahara. It is one of the few commercially implemented identity-based encryption schemes. We explore the Coppersmith approach for solving a class of modular polynomial equations, which is derived from the recovery issue for the hidden number$\alpha $in MIHNP and the secret seed$v_{0}$in ICG, respectively. Take a positive integer$n=d^{3+o(1)}$for some positive integer constant$d$. We propose a heuristic technique for recovering the hidden number$\alpha $or secret seed$v_{0}$with a probability close to 1 when$\delta /\log _{2} p>\frac {1}{d+1}+o\left({\frac {1}{d}}\right)$. The attack’s total time complexity is polynomial in the order of$\log _{2} p$, with the complexity of the LLL algorithm increasing as$d^{\mathcal {O}(d)}$and the complexity of the Gröbner basis computation increasing as$d^{\mathcal {O}(n)}$. When$d> 2$, this asymptotic bound surpasses the asymptotic bound$\delta /\log _{2} p>\frac {1}{3}$established by Boneh, Halevi, and Howgrave-Graham at Asiacrypt 2001. This is the first time a more precise constraint for solving MIHNP is established, implying that the claim that MIHNP is difficult is violated whenever$\delta /\log _{2} p < \frac {1}{3}$. Then we study ICG. To our knowledge, we achieve the best performance for attacking ICG to date. Finally, we provide an MIHNP-based lattice approach that recovers the signer’s secret key in the Sakai-Kasahara type signatures when the most (least) significant bits of the signing exponents are exposed. This improves the existing work in this direction.
Jun Xu 0022, Santanu Sarkar 0001, Lei Hu 0003, Huaxiong Wang, Yanbin Pan 0001
IEEE Trans. Inf. Theory1
2022 Improving Bounds on Elliptic Curve Hidden Number Problem for ECDH Key Exchange
Jun Xu 0022, Santanu Sarkar 0001, Huaxiong Wang, Lei Hu 0003
ASIACRYPT (3)1
2022 Inferring Sequences Produced by the Quadratic Generator
Jun Xu 0022, Lei Hu 0003
Inscrypt2
2022 New Results of Breaking the CLS Scheme from ACM-CCS 2014
Jun Xu 0022, Tianyu Wang 0021, Lei Hu 0003
ICICS2
2022 Revisiting orthogonal lattice attacks on approximate common divisor problems
Jun Xu 0022, Santanu Sarkar 0001, Lei Hu 0003
Theor. Comput. Sci.1
2021 On the Ideal Shortest Vector Problem over Random Rational Primes
Yanbin Pan 0001, Jun Xu 0022, Nick Wadleigh, Qi Cheng 0001
EUROCRYPT (1)2
2021 Integer LWE with Non-subgaussian Error and Related Attacks
Tianyu Wang 0021, Yuejun Liu, Jun Xu 0022, Lei Hu 0003, Yang Tao 0001, Yongbin Zhou
ISC3
2020 Cryptanalysis of elliptic curve hidden number problem from PKC 2017
Jun Xu 0022, Lei Hu 0003, Santanu Sarkar 0001
Des. Codes Cryptogr.1
2019 New Results on Modular Inversion Hidden Number Problem and Inversive Congruential Generator
Jun Xu 0022, Santanu Sarkar 0001, Lei Hu 0003, Huaxiong Wang, Yanbin Pan 0001
CRYPTO (1)1
2019 Certifying multi-power RSA
abstract
In this study, the authorspresent two rigorous algorithms to certify the trapdoor permutation property of the RSAfunction , where is a multi‐power RSA modulus with unknown factorisation and r is a known positive integer. Their work gives effective certification for a prime exponent e when and for a composite integer when for , where is a known prime, is a positive integer, and is some small enough constant. The algorithms apply Coppersmith's method for solving univariate modular polynomial equations and run in time , where is a constant number.
Xiaona Zhang, Jun Xu 0022
IET Inf. Secur.3
2018 Solving a class of modular polynomial equations and its relation to modular inversion hidden number problem and inversive congruential generator
Jun Xu 0022, Santanu Sarkar 0001, Lei Hu 0003, Zhangjie Huang, Liqiang Peng
Des. Codes Cryptogr.1
2017 Cryptanalysis of Dual RSA
Liqiang Peng, Lei Hu 0003, Yao Lu 0002, Jun Xu 0022, Zhangjie Huang
Des. Codes Cryptogr.4
2016 Cryptanalysis of Multi-Prime \varPhi -Hiding Assumption
Jun Xu 0022, Lei Hu 0003, Santanu Sarkar 0001, Xiaona Zhang, Zhangjie Huang, Liqiang Peng
ISC1
2016 Cryptanalysis and Improved Construction of a Group Key Agreement for Secure Group Communication
Jun Xu 0022, Lei Hu 0003, Xiaona Zhang, Liqiang Peng, Zhangjie Huang
ISC1
2015 Recovering a Sum of Two Squares Decomposition Revisited
Xiaona Zhang, Jun Xu 0022, Lei Hu 0003, Liqiang Peng, Zhangjie Huang, Zeyi Liu 0002
Inscrypt3
2015 Partial Prime Factor Exposure Attacks on RSA and Its Takagi's Variant
Liqiang Peng, Lei Hu 0003, Zhangjie Huang, Jun Xu 0022
ISPEC4
2014 Partial Key Exposure Attacks on Takagi's Variant of RSA
Zhangjie Huang, Lei Hu 0003, Jun Xu 0022, Liqiang Peng, Yonghong Xie
ACNS3
2014 Attacking RSA with a Composed Decryption Exponent Using Unravelled Linearization
Zhangjie Huang, Lei Hu 0003, Jun Xu 0022
Inscrypt3
2014 Modular Inversion Hidden Number Problem Revisited
Jun Xu 0022, Lei Hu 0003, Zhangjie Huang, Liqiang Peng
ISPEC1
2014 Cryptanalysis of two cryptosystems based on multiple intractability assumptions
abstract
Two public key cryptosystems based on the two intractable number‐theoretic problems, integer factorisation and simultaneous Diophantine approximation, were proposed in 2005 and 2009, respectively. In this study, the authors break these two cryptosystems for the recommended minimum parameters by solving the corresponding modular linear equations with small unknowns. For the first scheme, the public modulus is factorised and the secret key is recovered with the Gauss algorithm. By using the LLL basis reduction algorithm for a seven‐dimensional lattice, the public modulus in the second scheme is also factorised and the plaintext is recovered from a ciphertext. The author's attacks are efficient and verified by experiments which were done within 5s.
Jun Xu 0022, Lei Hu 0003, Siwei Sun
IET Commun.1
2014 Cryptanalysis of countermeasures against multiple transmission attacks on NTRU
abstract
The original Number Theory Research Unit (NTRU) public key cryptosystem is vulnerable to multiple transmission attacks, and the designers of NTRU presented two countermeasures to prevent such attacks. In this study, the authors show that the first countermeasure is still not secure, the plaintext can be revealed by a linearisation attack technique. Moreover, they demonstrate that the first countermeasure is even not secure for broadcast attacks, a class of more general attacks than multiple transmission attacks. For the second countermeasure, they show that one special case of its padding function for the plaintext is also insecure and the original plaintext can be obtained by lattice methods.
Jun Xu 0022, Lei Hu 0003, Siwei Sun, Yonghong Xie
IET Commun.1
2013 Analysis of two knapsack public key cryptosystems
abstract
Two knapsack‐based public key cryptosystems were proposed recently, in which the entries of the secret knapsack sequences are composed of products of random integers and the knapsack problems have nonbinary solutions. These features make the cryptosystems to be secure against low density attacks. In this study, the authors present lattice‐based complete private key recovery attacks on these two schemes. The authors attacks firstly find short vectors related to the public key and with some orthogonality to the secret knapsack sequences and then recover some components of the private key by computing common factors of the entries of the short vectors. Especially, the authors attack can both completely recover the unique key for these two schemes. The attacks are of practical complexities and verified by experiments.
Liqiang Peng, Lei Hu 0003, Jun Xu 0022, Yonghong Xie, Jinyin Zuo
IET Commun.3
2012 Cryptanalysis of a Lattice-Knapsack Mixed Public Key Cryptosystem
Jun Xu 0022, Lei Hu 0003, Siwei Sun
CANS1
2012 Implicit Polynomial Recovery and Cryptanalysis of a Combinatorial Key Cryptosystem
Jun Xu 0022, Lei Hu 0003, Siwei Sun
ICICS1