VLDB 2026 Research / reviewers in the wild / expert
Joan Daemen
dblp:93/3962
· DBLP profile ↗
45ranked-venue papers
23as first author
9since 2021 · last 2025
0000-0002-4102-0775ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 41 · 23 first-author · 8 since 2021Systems, architecture and hardware · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Shaking up authenticated encryptionabstractAuthenticated encryption (AE) is a cryptographic mechanism that allows communicating parties to protect the confidentiality and integrity of messages exchanged over a public channel, provided they share a secret key. In this work, we present new AE schemes leveraging the SHA- 3 standard functions SHAKE128 and SHAKE256, offering 128 and 256 bits of security strength, respectively, and their “Turbo” counterparts. They support session-based communication, where a ciphertext authenticates the sequence of messages since the start of the session. The chaining in the session allows decryption in segments, avoiding the need to buffer the entire deciphered cryptogram between decryption and validation. And, thanks to the collision resistance of (Turbo)SHAKE, they provide so-called CMT-4 committing security, meaning that they provide strong guarantees that a ciphertext uniquely binds to the key, plaintext and associated data. The AE schemes we propose have a unique combination of advantages. The most important are that 1) their security is based on the security claim of SHAKE, that has received a large amount of public scrutiny, that 2) they make use of the standard KECCAK-p permutation that not only receives more and more dedicated hardware support, but also allows competitive software-only implementations thanks to the TurboSHAKE instances, and that 3) they do not suffer from a 64-bit birthday bound like most AES-based schemes. Of independent interest, we introduce the deck cipher as the stateful counterpart of the deck function and the duplex cipher generalizing keyed duplex and harmonize their security notions. Finally, we provide an elegant solution for multi-layer domain separation. Joan Daemen, Seth Hoffert, Silvia Mella, Gilles Van Assche, Ronny Van Keer |
EuroS&P | 1 |
| 2024 | Koala: A Low-Latency Pseudorandom Function
Parisa A. Eliasi, Yanis Belkheyar, Joan Daemen, Santosh Ghosh, Daniël Kuijsters, Alireza Mehrdad, Silvia Mella, Shahram Rasoolzadeh, Gilles Van Assche |
SAC (2) | 3 |
| 2024 | The state diagram of χabstractAbstract In symmetric cryptography, block ciphers, stream ciphers and permutations often make use of a round function and many round functions consist of a linear and a non-linear layer. One that is often used is based on the cellular automaton that is denoted by $$\chi $$ χ as a Boolean map on bi-infinite sequences, $${\mathbb {F}}_2^{{\mathbb {Z}}}$$ F2Z . It is defined by $$\sigma \mapsto \nu $$ σ↦ν where each $$\nu _i = \sigma _i + (\sigma _{i+1}+1)\sigma _{i+2}$$ νi=σi+(σi+1+1)σi+2 . A map $$\chi _n$$ χn is a map that operates onn-bit arrays with periodic boundary conditions. This corresponds with $$\chi $$ χ restricted to periodic infinite sequences with period that dividesn. This map $$\chi _n$$ χn is used in various permutations, e.g.,Keccak-f (the permutation in SHA-3), ASCON (the NIST standard for lightweight cryptography), Xoodoo, Rasta and Subterranean (2.0). In this paper, we characterize the graph of $$\chi $$ χ on periodic sequences. It turns out that $$\chi $$ χ is surjective on the set ofallperiodic sequences. We will show what sequences will give collisions after one application of $$\chi $$ χ . We prove that, for oddn, the order of $$\chi _n$$ χn (in the group of bijective maps on $${\mathbb {F}}_2^n$$ F2n ) is $$2^{\lceil {\text {lg}}(\frac{n+1}{2})\rceil }$$ 2⌈lg(n+12)⌉ . A given periodic sequence lies on a cycle in the graph of $$\chi $$ χ , or it can be represented as a polynomial. By regarding the divisors of such a polynomial one can see whether it lies in a cycle, or after how many iterations of $$\chi $$ χ it will. Furthermore, we can see, for a given $$\sigma $$ σ , the length of the cycle in its component in the state diagram. Finally, we extend the surjectivity of $$\chi $$ χ to $${\mathbb {F}}_2^{{\mathbb {Z}}}$$ F2Z , thus to include non-periodic sequences. Jan Schoone, Joan Daemen |
Des. Codes Cryptogr. | 2 |
| 2024 | Algebraic properties of the maps χ nabstractAbstract The Boolean map $$\chi _n :\mathbb {F}_2^n \rightarrow \mathbb {F}_2^n,\ x \mapsto y$$ χn:F2n→F2n,x↦y defined by $$y_i = x_i + (x_{i+1}+1)x_{i+2}$$ yi=xi+(xi+1+1)xi+2 (where $$i\in \mathbb {Z}/n\mathbb {Z}$$ i∈Z/nZ ) is used in various permutations that are part of cryptographic schemes, e.g.,Keccak-f (the SHA-3-permutation), ASCON (the winner of the NIST Lightweight competition), Xoodoo, Rasta and Subterranean (2.0). In this paper, we study various algebraic properties of this map. We consider $$\chi _n$$ χn (through vectorial isomorphism) as a univariate polynomial. We show that it is a power function if and only if $$n=1,3$$ n=1,3 . We furthermore compute bounds on the sparsity and degree of these univariate polynomials, and the number of different univariate representations. Secondly, we compute the number of monomials of given degree in the inverse of $$\chi _n$$ χn (if it exists). This number coincides with binomial coefficients. Lastly, we consider $$\chi _n$$ χn as a polynomial map, to study whether the same rule ( $$y_i = x_i + (x_{i+1}+1)x_{i+2}$$ yi=xi+(xi+1+1)xi+2 ) gives a bijection on field extensions of $$\mathbb {F}_2$$ F2 . We show that this is not the case for extensions whose degree is divisible by two or three. Based on these results, we conjecture that this rule does not give a bijection on any extension field of $$\mathbb {F}_2$$ F2 . Jan Schoone, Joan Daemen |
Des. Codes Cryptogr. | 2 |
| 2023 | On the Security of Keyed Hashing Based on Public Permutations
Jonathan Fuchs, Yann Rotella, Joan Daemen |
CRYPTO (3) | 3 |
| 2023 | Twin Column Parity Mixers and Gaston - A New Mixing Layer and Permutation
Solane El Hirch, Joan Daemen, Raghvendra Rohit 0001, Rusydi H. Makarim |
CRYPTO (3) | 2 |
| 2022 | Jammin' on the Deck
Nicoleta-Norica Bacuieti, Joan Daemen, Seth Hoffert, Gilles Van Assche, Ronny Van Keer |
ASIACRYPT (2) | 2 |
| 2022 | Energy and side-channel security evaluation of near-threshold cryptographic circuits in 28nm FD-SOI technologyabstractThis paper is the first to present an implementation of a cryptographic circuit in 28nm FD-SOI using near-threshold design. The implemented cipher, Ketje Jr, is a lightweight authenticated encryption algorithm. The energy consumption of representative authenticated encryption operations as well as the information leakage through the power consumption side-channel are evaluated. The results show that an ultra-low energy implementation can be achieved, and that the near-threshold design has little influence on the Signal to Noise Ratio in the power measurements of our chip. Arthur Beckers, Roel Uytterhoeven, Thomas Vandenabeele, Jo Vliegen, Lennert Wouters, Joan Daemen, Wim Dehaene, Benedikt Gierlichs, Nele Mentens |
CF | 6 |
| 2021 | Thinking Outside the Superbox
Nicolas Bordes, Joan Daemen, Daniël Kuijsters, Gilles Van Assche |
CRYPTO (3) | 2 |
| 2020 | Novel Bloom filter algorithms and architectures for ultra-high-speed network security applicationsabstractThis paper proposes novel Bloom filter algorithms and FPGA architectures for high-speed searching applications. A Bloom filter is a memory structure that is used to test whether input search data are present in a table of stored data. Bloom filters are extensively used in network security solutions that apply traffic flow monitoring or deep packet inspection. Improving the speed of Bloom filters can therefore have a significant impact on the speed of many network applications. The most important components determining the speed of Bloom filters are hash functions. While hash functions in Bloom filters do not require strong cryptographic properties, they do need a minimized computational delay. We take on the challenge of developing ultra-high-speed Bloom filters on FPGAs by proposing a new noncryptographic hash function, called Xoodoo-NC, derived from the cryptographic permutation Xoodoo. Xoodoo-NC is a reducedround, reduced-state version of Xoodoo, inheriting Xoodoo's desired avalanche properties and low logical depth, resulting in an ultra-low-latency non-cryptographic hash function. We evaluate the performance of Bloom filter architectures based on Xoodoo-NC on a Xilinx UltraScale+FPGA and we compare the performance and resource occupation to existing Bloom filter implementations. We additionally compare our results to memories that use the built-in CAM cores in Xilinx UltraScale+ FPGAs. Our proposed algorithmic and architectural advances lead to Bloom filters that, to the best of our knowledge, outperform all other FPGA-based solutions. Arish Sateesan, Jo Vliegen, Joan Daemen, Nele Mentens |
DSD | 3 |
| 2020 | Friet: An Authenticated Encryption Scheme with Built-in Fault Detection
Thierry Simon, Lejla Batina, Joan Daemen, Vincent Grosso, Pedro Maat Costa Massolino, Kostas Papagiannopoulos, Francesco Regazzoni 0001, Niels Samwel |
EUROCRYPT (1) | 3 |
| 2018 | KangarooTwelve: Fast Hashing Based on Keccak-p
Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche, Ronny Van Keer, Benoît Viguier |
ACNS | 2 |
| 2018 | Breaking Ed25519 in WolfSSL
Niels Samwel, Lejla Batina, Guido Bertoni, Joan Daemen, Ruggero Susella |
CT-RSA | 4 |
| 2017 | Full-State Keyed Duplex with Built-In Multi-user Support
Joan Daemen, Bart Mennink, Gilles Van Assche |
ASIACRYPT (2) | 1 |
| 2017 | Changing of the Guards: A Simple and Efficient Method for Achieving Uniformity in Threshold Sharing
Joan Daemen |
CHES | 1 |
| 2016 | Exploring the use of shift register lookup tables for Keccak implementations on Xilinx FPGAsabstractWe explore the possibility of using shift register lookup tables (SRLs) for the implementation of Keccak on Xilinx FPGAs. The approach originates from the observation that the ρ step in combination with the state storage can be implemented as a collection of shift registers. This way, we achieve a slice-wise implementation using 25 shift registers of various lengths, resulting in 75 32-bit and 6 16-bit SRL primitives on a Virtex-5. This approach, however, does not comply efficiently with the common interface of Keccak. We therefore propose to utilize a modified interface in order to avoid the redundant storage of the state. This modified version of Keccak, with equivalent cryptographic strength, can be implemented without Block RAM, outperforming all previously proposed implementations in terms of the number of slices. Furthermore it outperforms several other lightweight slice-wise implementations in terms of throughput. Jori Winderickx, Joan Daemen, Nele Mentens |
FPL | 2 |
| 2015 | Security of Keyed Sponge Constructions Using a Modular Proof Approach
Elena Andreeva 0001, Joan Daemen, Bart Mennink, Gilles Van Assche |
FSE | 2 |
| 2014 | Sakura: A Flexible Coding for Tree Hashing
Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche |
ACNS | 2 |
| 2013 | Efficient and First-Order DPA Resistant Implementations of Keccak
Begül Bilgin, Joan Daemen, Ventzislav Nikov, Svetla Nikova, Vincent Rijmen, Gilles Van Assche |
CARDIS | 2 |
| 2013 | Keccak
Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche |
EUROCRYPT | 2 |
| 2012 | Differential Propagation Analysis of Keccak
Joan Daemen, Gilles Van Assche |
FSE | 1 |
| 2010 | Sponge-Based Pseudo-Random Number Generators
Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche |
CHES | 2 |
| 2010 | Refinements of the ALRED construction and MAC security claimsabstractThe authors present three security claims for iterated message authentication codes (MAC functions). Next, they propose ALRED, a construction method for MAC functions based on a block cipher that has provable security in the absence of internal collisions. They apply this construction to advanced encryption standard (AES) resulting in two MAC functions: ALPHA-MAC and PELICAN. The authors provide a model for describing different types of internal collisions in ALRED and provide evidence that the security claims they propose are usable for MAC functions that use the ALRED construction. Finally, they provide a motivation for the security claims that accompany PELICAN. Joan Daemen, Vincent Rijmen |
IET Inf. Secur. | 1 |
| 2008 | On the Indifferentiability of the Sponge Construction
Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche |
EUROCRYPT | 2 |
| 2007 | Producing Collisions for Panama, Instantaneously
Joan Daemen, Gilles Van Assche |
FSE | 1 |
| 2007 | Plateau characteristicsabstractPlateau characteristics are a special type of characteristics whose probability depends on the key and can have only two values. For a (usually small) subset of the keys it has a non-zero probability and for all other keys its probability is zero. For a large group of ciphers, including the AES, all two-round characteristics are plateau characteristics. For the AES and other ciphers with a similar structure, the vast majority of characteristics over four or more rounds are plateau characteristics. In the case of the AES, for most keys, there are two-round characteristics with fixed-key probability equal to 32/232, whereas the maximum expected differential probability of two-round differentials is at most 13.25/232. Joan Daemen, Vincent Rijmen |
IET Inf. Secur. | 1 |
| 2005 | A New MAC Construction ALRED and a Specific Instance ALPHA-MAC
Joan Daemen, Vincent Rijmen |
FSE | 1 |
| 2002 | AES and the Wide Trail Design Strategy
Joan Daemen, Vincent Rijmen |
EUROCRYPT | 1 |
| 2001 | The Wide Trail Design Strategy
Joan Daemen, Vincent Rijmen |
IMACC | 1 |
| 2001 | Linear Frameworks for Block Ciphers
Joan Daemen, Lars R. Knudsen, Vincent Rijmen |
Des. Codes Cryptogr. | 1 |
| 2000 | Bitslice Ciphers and Power Analysis Attacks
Joan Daemen, Michaël Peeters, Gilles Van Assche |
FSE | 1 |
| 1998 | The Block Cipher BKSQ
Joan Daemen, Vincent Rijmen |
CARDIS | 1 |
| 1998 | The Block Cipher Rijndael
Joan Daemen, Vincent Rijmen |
CARDIS | 1 |
| 1998 | The Banksys Signature Transport (BST) Protocol
Michel Dawirs, Joan Daemen |
CARDIS | 2 |
| 1998 | Fast Hashing and Stream Encryption with PANAMA
Joan Daemen, Craig S. K. Clapp |
FSE | 1 |
| 1997 | The Block Cipher Square
Joan Daemen, Lars R. Knudsen, Vincent Rijmen |
FSE | 1 |
| 1996 | The Cipher SHARK
Vincent Rijmen, Joan Daemen, Bart Preneel, Antoon Bosselaers, Erik De Win |
FSE | 2 |
| 1994 | Correlation Matrices
Joan Daemen, René Govaerts, Joos Vandewalle |
FSE | 1 |
| 1993 | Weak Keys for IDEA
Joan Daemen, René Govaerts, Joos Vandewalle |
CRYPTO | 1 |
| 1993 | A New Approach to Block Cipher Design
Joan Daemen, René Govaerts, Joos Vandewalle |
FSE | 1 |
| 1993 | Subterranean: A 600 Mbit/Sec Cryptographic VLSI ChipabstractA high-speed cryptographic coprocessor is presented. This coprocessor is named Subterranean and can be used for both cryptographic pseudorandom sequence generation (Substream) and cryptographic hashing (Subhash). In Substream mode the chip can be used for stream encryption/decryption under control of a 256-bit key. A cryptographic resynchronization mechanism is provided for fast accessibility of encrypted data by legitimate particles. Application fields include the real-time encryption of digital HDTV signals as well as high speed telecommunication and networking such as ATM. The chip has been fabricated within the INVOMEC/EUROCHIP educational VLSI Design Facilities in MIETEC 2.4 /spl mu/ CMOS technology. Measured samples are operating at encryption/decryption rates of 286 Mb/s and hashing rates of 572 Mb/s. The operation of the chip is demonstrated by a setup showing the real-time encryption and decryption of digitized PAL color composite video signals. The designed cryptographic module can be used as a stand-alone device or embedded as a mega-block in a larger chip.> Luc Claesen, Joan Daemen, Mark Genoe, G. Peeters |
ICCD | 2 |
| 1992 | A Hardware Design Model for Cryptographic Algorithms
Joan Daemen, René Govaerts, Joos Vandewalle |
ESORICS | 1 |
| 1991 | Limitations of the Even-Mansour Construction
Joan Daemen |
ASIACRYPT | 1 |
| 1991 | Collisions for Schnorr's Hash Function FFT-Hash Presented at Crypto '91
Joan Daemen, Antoon Bosselaers, René Govaerts, Joos Vandewalle |
ASIACRYPT | 1 |
| 1991 | A Framework for the Design of One-Way Hash Functions Including Cryptanalysis of Damgård's One-Way Function Based on a Cellular Automaton
Joan Daemen, René Govaerts, Joos Vandewalle |
ASIACRYPT | 1 |