VLDB 2026 Research / reviewers in the wild / expert
Jian Guo 0001
dblp:96/2596-1
· DBLP profile ↗
54ranked-venue papers
18as first author
20since 2021 · last 2026
0000-0001-8847-6748ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 52 · 17 first-author · 19 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Upper Bound on Information-Theoretic Security of Permutation-Based Pseudorandom Functions
Chun Guo 0002, Jian Guo 0001, Xinnian Li, Wenjie Nan |
EUROCRYPT | 2 |
| 2026 | Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5
Jian Guo 0001, Meicheng Liu, Shichang Wang, Tianyu Zhang 0004 |
EUROCRYPT | 1 |
| 2026 | Neural-Inspired Advances in Integral Cryptanalysis
Yiran Yao, Danping Shi, Dongchen Chai, Jian Guo 0001, Zilong Wang 0001 |
EUROCRYPT | 5 |
| 2025 | Scrutinizing the Security of AES-Based Hashing and One-Way Functions
Jian Guo 0001, Eik List, Danping Shi, Tianyu Zhang 0004 |
ASIACRYPT (1) | 2 |
| 2025 | Revisiting Time-Space Tradeoffs in Collision Search and Decision Problems
Jian Guo 0001, Wenjie Nan, Yiran Yao |
ASIACRYPT (1) | 1 |
| 2025 | Towards Combined Countermeasures against Differential Computation and Fault Analyses: An Approach with the ASASA Structure
Yufeng Tang, Jian Guo 0001, Xiaoyang Dong 0001, Liangju Zhao |
ASIACRYPT (2) | 3 |
| 2025 | Bootstrappable Fully Homomorphic Attribute-Based Encryption with Unbounded Circuit Depth
Feixiang Zhao, Shixin Chen, Man Ho Au, Jian Weng 0001, Huaxiong Wang, Jian Guo 0001 |
ASIACRYPT (7) | 6 |
| 2025 | Efficient Mixed Garbling from Homomorphic Secret Sharing and GGM-Tree
Jian Guo 0001, Wenjie Nan |
EUROCRYPT (6) | 1 |
| 2024 | Automatic Quantum Multi-collision Distinguishers and Rebound Attacks with Triangulation Algorithm
Zhenzhen Bao, Jian Guo 0001, Shun Li 0004, Phuong Pham |
ACISP (2) | 2 |
| 2024 | Hard-Label Cryptanalytic Extraction of Neural Network Models
Yi Chen 0011, Xiaoyang Dong 0001, Jian Guo 0001, Yantian Shen, Anyu Wang 0001, Xiaoyun Wang 0001 |
ASIACRYPT (8) | 3 |
| 2024 | Diving Deep into the Preimage Security of AES-Like Hashing
Jian Guo 0001, Eik List, Danping Shi, Tianyu Zhang 0004 |
EUROCRYPT (1) | 2 |
| 2024 | PEO-Store: Delegation-Proof Based Oblivious Storage With Secure Redundancy EliminationabstractRecently, Oblivious Storage has been proposed to prevent privacy leakage from user access patterns, which obfuscates and makes it computationally indistinguishable from the random sequences by fake accesses and probabilistic encryption. The same data exhibits distinct ciphertexts. Thus, it seriously impedes cloud providers’ efforts to improve storage utilization to remove user redundancy, which has been widely used in the existing cloud storage scenario. Inspired by the successful adoption of removing duplicate data in cloud storage, we attempt to integrate obliviousness, remove redundancy, and propose a practical oblivious storage, PEO-Store. Instead of fake accesses, introducing delegates breaks the mapping link between a valid access pattern and a specific client. The cloud interacts only with randomly authorized delegates. This design leverages non-interactive zero-knowledge-based redundancy detection, discrete logarithm problem-based key sharing, and secure time-based delivery proof. These components collectively protect access pattern privacy, accurately eliminate redundancy, and prove the data delivery among delegates and the cloud. Theoretical proof demonstrates that, in our design, the probability of identifying the valid access pattern with a specific client is negligible. Experimental results show that PEO-Store outperforms state-of-the-art methods, achieving an average throughput of up to 3 times faster and saving 74% of storage space. Jian Guo 0001, Zhiyong Xu 0003, Ruixuan Li 0001, Weijun Xiao |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Key Structures: Improved Related-Key Boomerang Attack Against the Full AES-256
Jian Guo 0001, Ling Song 0001, Haoyang Wang 0001 |
ACISP | 1 |
| 2022 | Enhancing Differential-Neural Cryptanalysis
Zhenzhen Bao, Jian Guo 0001, Meicheng Liu |
ASIACRYPT (1) | 2 |
| 2022 | Exploring SAT for Cryptanalysis: (Quantum) Collision Attacks Against 6-Round SHA-3
Jian Guo 0001, Guozhen Liu, Ling Song 0001 |
ASIACRYPT (3) | 1 |
| 2022 | Superposition Meet-in-the-Middle Attacks: Updates on Fundamental Security of AES-like Hashing
Zhenzhen Bao, Jian Guo 0001, Danping Shi |
CRYPTO (1) | 2 |
| 2022 | Triangulating Rebound Attack on AES-like Hashing
Xiaoyang Dong 0001, Jian Guo 0001, Shun Li 0004, Phuong Pham |
CRYPTO (1) | 2 |
| 2022 | Evaluating the Security of Merkle-Damgård Hash Functions and Combiners in Quantum Settings
Zhenzhen Bao, Jian Guo 0001, Shun Li 0004, Phuong Pham |
NSS | 2 |
| 2021 | Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like Hashing
Zhenzhen Bao, Xiaoyang Dong 0001, Jian Guo 0001, Zheng Li 0008, Danping Shi, Siwei Sun, Xiaoyun Wang 0001 |
EUROCRYPT (1) | 3 |
| 2021 | New Constructions of Complete PermutationsabstractIn this paper, we aim to construct a class of complete permutations$\mathcal F$over$\mathbb F_{q}^{n}$from some polynomials$f_{1},f_{2},\ldots,f_{n}$over$\mathbb F_{q}$. First of all, we determine a necessary and sufficient condition such that$\mathcal F$is complete. Briefly, we transform the completeness of$\mathcal F$into showing the permutation properties of two polynomials over$\mathbb F_{q}$obtained from these$f_{i}$’s. Then, following the wide applications, we investigate the constructions of linear complete permutations over$\mathbb F_{2}^{n}$based on the rotations andXORs. The following two cases are considered: the first one is to use some different circularly left shift transforms$f_{i}$’s and the second one is to assume$f_{i}$’s are of the form$b_{i}f$with a fixed$f$and different$b_{i}$’s in$\mathbb F_{q}$. In both cases, we show that the completeness of the permutation is closely related to the ranks of some matrices with particular forms, which can be determined by the cycle decomposition of the permutation over the$n$branches. Besides, we present several explicit linear complete permutations which might be used in the design as well as the provable security of cryptographic schemes. Bing Sun 0001, Kangquan Li, Jian Guo 0001, Longjiang Qu |
IEEE Trans. Inf. Theory | 3 |
| 2020 | Towards Closing the Security Gap of Tweak-aNd-Tweak (TNT)
Chun Guo 0002, Jian Guo 0001, Eik List, Ling Song 0001 |
ASIACRYPT (1) | 2 |
| 2020 | TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo 0002, Jian Guo 0001, Ling Song 0001 |
EUROCRYPT (2) | 3 |
| 2020 | Generic Attacks on Hash CombinersabstractHash combiners are a practical way to make cryptographic hash functions more tolerant to future attacks and compatible with existing infrastructure. A combiner combines two or more hash functions in a way that is hopefully more secure than each of the underlying hash functions, or at least remains secure as long as one of them is secure. Two classical hash combiners are the exclusive-or (XOR) combiner \( \mathcal {H}_1(M) \oplus \mathcal {H}_2(M) \) and the concatenation combiner \( \mathcal {H}_1(M) \Vert \mathcal {H}_2(M) \) . Both of them process the same message using the two underlying hash functions in parallel. Apart from parallel combiners, there are also cascade constructions sequentially calling the underlying hash functions to process the message repeatedly, such as Hash-Twice \(\mathcal {H}_2(\mathcal {H}_1(IV, M), M)\) and the Zipper hash \(\mathcal {H}_2(\mathcal {H}_1(IV, M), \overleftarrow{M})\) , where \(\overleftarrow{M}\) is the reverse of the message M . In this work, we study the security of these hash combiners by devising the best-known generic attacks. The results show that the security of most of the combiners is not as high as commonly believed. We summarize our attacks and their computational complexities (ignoring the polynomial factors) as follows: Several generic preimage attacks on the XOR combiner: A first attack with a best-case complexity of \( 2^{5n/6} \) obtained for messages of length \( 2^{n/3} \) . It relies on a novel technical tool named interchange structure. It is applicable for combiners whose underlying hash functions follow the Merkle–Damgård construction or the HAIFA framework. A second attack with a best-case complexity of \( 2^{2n/3} \) obtained for messages of length \( 2^{n/2} \) . It exploits properties of functional graphs of random mappings. It achieves a significant improvement over the first attack but is only applicable when the underlying hash functions use the Merkle–Damgård construction. An improvement upon the second attack with a best-case complexity of \( 2^{5n/8} \) obtained for messages of length \( 2^{5n/8} \) . It further exploits properties of functional graphs of random mappings and uses longer messages. These attacks show a rather surprising result: regarding preimage resistance, the sum of two n -bit narrow-pipe hash functions following the considered constructions can never provide n -bit security. A generic second-preimage attack on the concatenation combiner of two Merkle–Damgård hash functions. This attack finds second preimages faster than \( 2^n \) for challenges longer than \( 2^{2n/7} \) and has a best-case complexity of \( 2^{3n/4} \) obtained for challenges of length \( 2^{3n/4} \) . It also exploits properties of functional graphs of random mappings. The first generic second-preimage attack on the Zipper hash with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{3n/5} \) , obtained for challenge messages of length \( 2^{2n/5} \) . An improved generic second-preimage attack on Hash-Twice with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{13n/22} \) , obtained for challenge messages of length \( 2^{13n/22} \) . The last three attacks show that regarding second-preimage resistance, the concatenation and cascade of two n -bit narrow-pipe Merkle–Damgård hash functions do not provide much more security than that can be provided by a single n -bit hash function. Our main technical contributions include the following: The interchange structure, which enables simultaneously controlling the behaviours of two hash computations sharing the same input. The simultaneous expandable message, which is a set of messages of length covering a whole appropriate range and being multi-collision for both of the underlying hash functions. New ways to exploit the properties of functional graphs of random mappings generated by fixing the message block input to the underlying compression functions. Zhenzhen Bao, Itai Dinur, Jian Guo 0001, Gaëtan Leurent, Lei Wang 0031 |
J. Cryptol. | 3 |
| 2020 | Practical Collision Attacks against Round-Reduced SHA-3
Jian Guo 0001, Guohong Liao, Guozhen Liu, Meicheng Liu, Kexin Qiao, Ling Song 0001 |
J. Cryptol. | 1 |
| 2018 | New MILP Modeling: Improved Conditional Cube Attacks on Keccak-Based Constructions
Ling Song 0001, Jian Guo 0001, Danping Shi, San Ling |
ASIACRYPT (2) | 2 |
| 2017 | Functional Graph Revisited: Updates on (Second) Preimage Attacks on Hash Combiners
Zhenzhen Bao, Lei Wang 0031, Jian Guo 0001, Dawu Gu |
CRYPTO (2) | 3 |
| 2017 | Non-full Sbox Linearization: Applications to Collision Attacks on Round-Reduced Keccak
Ling Song 0001, Guohong Liao, Jian Guo 0001 |
CRYPTO (2) | 3 |
| 2017 | New Collision Attacks on Round-Reduced Keccak
Kexin Qiao, Ling Song 0001, Meicheng Liu, Jian Guo 0001 |
EUROCRYPT (3) | 4 |
| 2016 | Linear Structures: Applications to Cryptanalysis of Round-Reduced Keccak
Jian Guo 0001, Meicheng Liu, Ling Song 0001 |
ASIACRYPT (1) | 1 |
| 2016 | How to Build Fully Secure Tweakable Blockciphers from Classical Blockciphers
Lei Wang 0031, Jian Guo 0001, Guoyan Zhang, Dawu Gu |
ASIACRYPT (1) | 2 |
| 2016 | New Insights on AES-Like SPN Ciphers
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Longjiang Qu, Vincent Rijmen |
CRYPTO (1) | 3 |
| 2016 | Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Vincent Rijmen, Ruilin Li 0002 |
EUROCRYPT (1) | 3 |
| 2016 | Extended meet-in-the-middle attacks on some Feistel constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001 |
Des. Codes Cryptogr. | 1 |
| 2015 | An improved preimage attack against HAVAL-3
Jian Guo 0001, Chunhua Su, Wun-She Yap |
Inf. Process. Lett. | 1 |
| 2014 | Meet-in-the-Middle Attacks on Generic Feistel Constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001 |
ASIACRYPT (1) | 1 |
| 2014 | Updates on Generic Attacks against HMAC and NMAC
Jian Guo 0001, Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031 |
CRYPTO (1) | 1 |
| 2014 | Analysis of BLAKE2
Jian Guo 0001, Pierre Karpman, Ivica Nikolic, Lei Wang 0031, Shuang Wu 0004 |
CT-RSA | 1 |
| 2014 | Equivalent Key Recovery Attacks Against HMAC and NMAC with Whirlpool Reduced to 7 Rounds
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Long Wen 0002 |
FSE | 1 |
| 2014 | CLOC: Authenticated Encryption for Short Input
Tetsu Iwata, Kazuhiko Minematsu, Jian Guo 0001, Sumio Morioka |
FSE | 3 |
| 2014 | The Usage of Counter Revisited: Second-Preimage Attack on New Russian Standardized Hash Function
Jian Guo 0001, Jérémy Jean, Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031 |
Selected Areas in Cryptography | 1 |
| 2013 | Cryptanalysis of HMAC/NMAC-Whirlpool
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004 |
ASIACRYPT (2) | 1 |
| 2013 | Implementing Lightweight Block Ciphers on x86 Architectures
Ryad Benadjila, Jian Guo 0001, Victor Lomné, Thomas Peyrin |
Selected Areas in Cryptography | 2 |
| 2012 | Unaligned Rebound Attack: Application to Keccak
Alexandre Duc, Jian Guo 0001, Thomas Peyrin, Lei Wei 0001 |
FSE | 2 |
| 2012 | (Pseudo) Preimage Attack on Round-Reduced Grøstl Hash Function and Others
Shuang Wu 0004, Dengguo Feng, Wenling Wu, Jian Guo 0001, Jian Zou 0002 |
FSE | 4 |
| 2011 | Improved Meet-in-the-Middle Cryptanalysis of KTANTAN (Poster)
Lei Wei 0001, Christian Rechberger, Jian Guo 0001, Hongjun Wu 0001, Huaxiong Wang, San Ling |
ACISP | 3 |
| 2011 | The LED Block Cipher
Jian Guo 0001, Thomas Peyrin, Axel Poschmann, Matthew J. B. Robshaw |
CHES | 1 |
| 2011 | The PHOTON Family of Lightweight Hash Functions
Jian Guo 0001, Thomas Peyrin, Axel Poschmann |
CRYPTO | 1 |
| 2010 | Advanced Meet-in-the-Middle Preimage Attacks: First Results on Full Tiger, and Improved Results on MD4 and SHA-2
Jian Guo 0001, San Ling, Christian Rechberger, Huaxiong Wang |
ASIACRYPT | 1 |
| 2010 | Differential and Invertibility Properties of BLAKE
Jean-Philippe Aumasson, Jian Guo 0001, Simon Knellwolf, Krystian Matusiewicz, Willi Meier |
FSE | 2 |
| 2009 | Preimages for Step-Reduced SHA-2
Kazumaro Aoki, Jian Guo 0001, Krystian Matusiewicz, Yu Sasaki 0001, Lei Wang 0031 |
ASIACRYPT | 2 |
| 2009 | Cryptanalysis of the LAKE Hash Family
Alex Biryukov, Praveen Gauravaram, Jian Guo 0001, Dmitry Khovratovich, San Ling, Krystian Matusiewicz, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang |
FSE | 3 |
| 2008 | On the Improvement of the BDF Attack on LSBS-RSA
Mu-En Wu, Huaxiong Wang, Jian Guo 0001 |
ACISP | 4 |
| 2008 | Cryptanalysis of Short Exponent RSA with Primes Sharing Least Significant Bits
Mu-En Wu, Ron Steinfeld, Jian Guo 0001, Huaxiong Wang |
CANS | 4 |
| 2008 | Cryptanalysis of LASH
Ron Steinfeld, Scott Contini, Krystian Matusiewicz, Josef Pieprzyk, Jian Guo 0001, San Ling, Huaxiong Wang |
FSE | 5 |