VLDB 2026 Research / reviewers in the wild / expert
Yongzhuang Wei
dblp:96/9555
· DBLP profile ↗
63ranked-venue papers
11as first author
33since 2021 · last 2026
0000-0002-3371-4865ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 3 first-author · 16 since 2021Theory of computation · 13 · 3 first-author · 2 since 2021Systems, architecture and hardware · 8 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Computer networks · 4 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Construction of Griesmer codes from subfield unions
Dexiang Li, Fengrong Zhang, Yongzhuang Wei |
ISIT | 3 |
| 2026 | PN-SCA: A High Generalization and Fast Profiled SCA Based on Prototypical Networks
Yu Ou, Yongzhuang Wei, Changhai Ou, Enes Pasalic |
J. Electron. Test. | 2 |
| 2026 | A Novel Graphic Leakage Structure for the Formal Verification of Composite ISW Masking Circuits
Yu Ou, Yongzhuang Wei |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2025 | NTRU-CLS: Efficient quantum-resistant NTRU lattice-based certificateless signature scheme for VANETs
Wanjun Xiong, Yongzhuang Wei |
Comput. Networks | 3 |
| 2025 | Intra-class CutMix data augmentation based deep learning side channel attacks
Runlian Zhang, Yu Mo, Zhaoxuan Pan, Hailong Zhang 0001, Yongzhuang Wei, Xiaonian Wu |
Integr. | 5 |
| 2025 | LLBC: A Novel Feistel-Based Low-Latency Block Cipher for IoT ApplicationsabstractLow-latency has been an important criterion in the design of block ciphers, especially in lightweight cryptography for IoT (Internet of Things) constrained devices to ensure secure real-time data transmission with limited resources. However, the design of most low-latency block ciphers today employ the so-called SPN (Substitution Permutation Network) structure with a few exceptions such as the SCARF cipher. In this article, by adopting the ideas of parallel execution for bridging the gap in latency between the standard Feistel and SPN structures, we propose a new low-latency cipher that uses the standard Feistel structure named as LLBC (Low Latency Block Cipher). It has a 128-bit block length with 128-bit (or 256-bit) key length. For the purpose of minimizing the latency and implementation costs, we were able to specify two 4-bit S-boxes, which not only have good cryptographic properties but are also excellent in terms of their hardware performance. More specifically, these S-boxes require only 18.5 GEs (Gate Equivalents) and have depth 3, which to the best of our knowledge are currently the best performing low-latency 4-bit S-boxes. Using these S-boxes in the design of LLBC, we achieve a significant reduction in both latency and implementation cost compared to Midori and QARMA. For instance, implementation of LLBC on the NanGate 45 nm open cell library achieves delay of about 2.79 ns which can be compared to the delay of PRINCE, Midori and QARMA being 4.06 ns, 4.94 ns, and 4.02 ns, respectively. Moreover, a standard security analysis shows that LLBC has enough security margin against various known attacks. Yongzhuang Wei, Enes Pasalic, Lang Li 0002, Ting Fan |
IEEE Internet Things J. | 2 |
| 2024 | Broader but More Efficient: Broad Learning in Power Side-channel AttacksabstractSide-channel attacks (SCAs) seriously threaten the security of cryptographic hardwares and embedded systems, especially following the introduction of deep learning techniques, with their powerful feature extraction capability that enables attackers to analyze the key information more efficiently. However, deep learning models in side-channel attacks also face with the problems of excessive model complexity and long training time. In this paper, we introduce Broad Learning Systems (BLS) to power side-channel attacks (SCAs) and then construct an efficient model of broad learning for power SCAs from the core of BLS. Then we optimize the model by making full use of the excellent features of incremental learning and feature extraction of BLS. Finally, we verify the effectiveness of the optimization model in diverse side-channel attack scenarios, achieving stable accuracy levels above 85% while significantly reducing time consumption compared to other models. This fully illustrates the superiority of our scheme. Changhai Ou, Yongzhuang Wei, Yifan Fan, Xuan Shen |
TrustCom | 3 |
| 2024 | Meet-in-the-middle attacks on AES with value constraints
Xiaoli Dong, Jun Liu 0099, Yongzhuang Wei, Wen Gao 0010, Jie Chen 0055 |
Des. Codes Cryptogr. | 3 |
| 2024 | Using Pτ property for designing bent functions provably outside the completed Maiorana-McFarland classabstractAbstract In this article, we identify certain instances of bent functions, constructed using the so-called $$P_\tau $$ P τ property, that are provably outside the completed Maiorana–McFarland ( $${\mathcal{M}\mathcal{M}}^\#$$ M M # ) class. This also partially answers an open problem in posed by Kan et al. (IEEE Trans Inf Theory, https://doi.org/10.1109/TIT.2022.3140180 , 2022). We show that this design framework (using the $$P_\tau $$ P τ property), can provide instances of bent functions that are outside the known classes of bent functions, including the classes $${\mathcal{M}\mathcal{M}}^\#$$ M M # , $${{\mathcal {C}}},{{\mathcal {D}}}$$ C , D and $${{\mathcal {D}}}_0$$ D 0 , where the latter three were introduced by Carlet in the early nineties. We provide two generic methods for identifying such instances, where most notably one of these methods uses permutations that may admit linear structures. For the first time, a set of sufficient conditions for the functions of the form $$h(y,z)=Tr(y\pi (z)) + G_1(Tr_1^m(\alpha _1y),\ldots ,Tr_1^m(\alpha _ky))G_2(Tr_1^m(\beta _{k+1}z),\ldots ,Tr_1^m(\beta _{\tau }z))+ G_3(Tr_1^m(\alpha _1y),\ldots ,Tr_1^m(\alpha _ky))$$ h ( y , z ) = T r ( y π ( z ) ) + G 1 ( T r 1 m ( α 1 y ) , … , T r 1 m ( α k y ) ) G 2 ( T r 1 m ( β k + 1 z ) , … , T r 1 m ( β τ z ) ) + G 3 ( T r 1 m ( α 1 y ) , … , T r 1 m ( α k y ) ) to be bent and outside $${\mathcal{M}\mathcal{M}}^\#$$ Enes Pasalic, Amar Bapic, Fengrong Zhang, Yongzhuang Wei |
Des. Codes Cryptogr. | 4 |
| 2024 | HDLBC: A lightweight block cipher with high diffusion
Jingya Feng, Qi Zhao 0028, Yongzhuang Wei |
Integr. | 4 |
| 2024 | Specifying cycles of minimal length for commonly used linear layers in block ciphers
Guoqiang Deng, Yongzhuang Wei, Xue-Feng Duan, Enes Pasalic, Samir Hodzic |
J. Inf. Secur. Appl. | 2 |
| 2024 | Optimizing AES Threshold Implementation Under the Glitch-Extended Probing ModelabstractThreshold Implementation (TI) is a well-known Boolean masking technique that provides provable security against side-channel attacks. In the presence of glitches, the probing model was replaced by the so-called glitch-extended probing model which specifies a broader security framework. In CHES 2021, Shahmirzadi et al. introduced a general search method for finding first-order 2-share TI schemes without fresh randomness (under the presence of glitches) for a given encryption algorithm. Although it handles well single-output Boolean functions, this method has to store output shares in registers when extended to vector Boolean functions, which results in more chip area and increased latency. Therefore, the design of TI schemes that have low implementation cost under the glitch-extended probing model appears to be an important research challenge. In this paper, we propose an approach to design the first-order glitch-extended probing secure TI schemes when quadratic functions are employed in the substitution layer. This method only requires a small amount of fresh random bits and a single clock cycle for its implementation. In particular, the random bits in our approach are reusable and compatible with the changing of the guards technique. Our dedicated TI scheme for the AES cipher gives 20.23% smaller implementation area and 4.2% faster encryption compared to the TI scheme of AES (without using fresh randomness) proposed in CHES 2021. Additionally, we propose a parallel implementation of two S-boxes that further reduces latency (about 39.83%) at the expense of increasing the chip area by 9%. We have positively confirmed the security of AES under the glitch-extended probing model using the verification tool -SILVER and the side-channel leakage assessment method -TVLA. Fu Yao, Hua Chen 0011, Yongzhuang Wei, Enes Pasalic, Limin Fan |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2024 | Novel Optimized Implementations of Lightweight Cryptographic S-Boxes via SAT SolversabstractAn optimized implementation of S-boxes has a significant impact on the performance of cryptographic primitives. SAT-based methods can find optimal implementations for moderately sized S-boxes but their efficiency decreases when handling complex S-boxes. To improve the efficiency of the implementations, we propose two different methods, namely OR-encoding and IF-encoding, to encode the implementations of S-boxes. Furthermore, we also simplify the encoding of the outputs of logic gates and introduce new SAT-based search methods to optimize the implementations of S-boxes. Finally, to get a better trade-off between the search results (optimized implementations of S-boxes) and the search efficiency (in terms of time complexity), an encoding scheme using local solutions is proposed. Compared to the previous methods, our algorithms are relatively simple and more efficient. For instance, when a serial software implementation is considered, then the S-boxes of Sycon, ASCON, and the$\chi $function in Xoodyak, require 6, 1, and 2 fewer programming instructions, respectively, than the best known methods. Similar improvements are obtained for hardware implementations of S-boxes in some cryptographic primitives (e.g. LBlock, RECTANGLE, PRESENT/PHOTON-Beetle, TWINE, and ASCON), with the saving of gate equivalent (GE) that range from 1.67GE to 5.34GE compared to the current best implementations. Furthermore, our model can be applied to 6-bit, 7-bit, and 8-bit S-boxes, when the considered S-boxes are of low complexity. Jingya Feng, Yongzhuang Wei, Fengrong Zhang, Enes Pasalic, Yu Zhou 0012 |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2024 | Minimal p-Ary Codes via the Direct Sum of Functions, Non-Covering Permutations and Subspaces of DerivativesabstractIn this article, we propose several generic methods for constructing minimal linear codes over the prime field Fp. The first construction uses the direct sum of an arbitrary functionf: Fpr→ Fpand a bent functiong: Fps→ Fpto induce minimal codes with parameters [pr+s- 1,r+s+ 1] and minimum distance larger thanpr(p- 1)(ps-1-ps/2-1). For the first time, we provide a general construction of linear codes from a subclass of non-weakly regular plateaued functions, which partially answers an open problem posed by Li and Mesnager. The second construction deals with a bent functiong: Fpm→ Fpand a suitable subspace of derivatives ofg, i.e., functions of the formg(y+a) -g(y) for somea∈ F*pm. We also provide a sound generalization of the recently introduced concept of non-covering permutations. Some important structural properties of this class of permutations are derived in this context. The most remarkable observation is that the class of non-covering permutations includes all APN power permutations (characterized by having two-to-one derivatives). Finally, the last construction combines the previous two methods (direct sum, non-covering permutations and subspaces of derivatives), using a bent function in the Maiorana-McFarland class, to construct minimal codes (even those violating the Ashikhmin-Barg bound) with larger dimensions. This last method proves to be highly flexible since it can lead to several non-equivalent codes, depending to a great extent on the choice of the underlying non-covering permutation. René Rodríguez-Aldama, Enes Pasalic, Fengrong Zhang, Yongzhuang Wei |
IEEE Trans. Inf. Theory | 4 |
| 2023 | New Meet-in-the-Middle Attacks on FOX Block CipherabstractAbstract FOX block cipher was designed with a Lai–Massey scheme, in which the round function uses the Substitution-Permutation-Substitution structure. A meet-in-the-middle (MITM) attack is one of the most important issues for the security of the block cipher, which consists of a precomputation phase for constructing a distinguisher and an online phase for key recovery. This paper studies the MITM attacks against FOX. The first MITM distinguishers of 5-round FOX64, 7-round FOX64-256 and 5-round FOX128 are presented when using the differential enumeration technique with truncated differential characteristics. Then, based on these distinguishers, the attacks for key recovery on 7-round FOX64, 11-round FOX64-256 and 7-round FOX128 are presented with the state-test and state-search techniques. It is shown that the attack on 11-round FOX64-256 is proposed for the first time; attacks on 7-round FOX64 and 7-round FOX128 can be improved with lower time and memory complexities compared with the currently known attacks. Xiaoli Dong, Yongzhuang Wei, Wen Gao 0010, Jie Chen 0055 |
Comput. J. | 2 |
| 2023 | Explicit infinite families of bent functions outside the completed Maiorana-McFarland classabstractAbstract During the last five decades, many different secondary constructions of bent functions were proposed in the literature. Nevertheless, apart from a few works, the question about the class inclusion of bent functions generated using these methods is rarely addressed. Especially, if such a “new” family belongs to the completed Maiorana–McFarland ( $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # ) class then there is no proper contribution to the theory of bent functions. In this article, we provide some fundamental results related to the inclusion in $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # and eventually we obtain many infinite families of bent functions that are provably outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # . The fact that a bent function f is in/outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # if and only if its dual is in/outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # is employed in the so-called 4-decomposition of a bent function on $${\mathbb {F}}_2^n$$ F 2 n , which was originally considered by Canteaut and Charpin (IEEE Trans Inf Theory 49(8):2004–2019, 2003) in terms of the second-order derivatives and later reformulated in (Hodžić et al. in IEEE Trans Inf Theory 65(11):7554–7565, 2019) in terms of the duals of its restrictions to the cosets of an $$(n-2)$$ ( n - 2 ) -dimensional subspace V. For each of the three possible cases of this 4-decomposition of a bent function (all four restrictions being bent, semi-bent, or 5-valued spectra functions), we provide generic methods for designing bent functions provably outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # . For instance, for the elementary case of defining a bent function $$h(\textbf{x},y_1,y_2)=f(\textbf{x}) \oplus y_1y_2$$ h ( x , y 1 , y 2 ) = f ( x ) ⊕ y 1 y 2 on $${\mathbb {F}}_2^{n+2}$$ F 2 n + 2 using a bent function f on $${\mathbb {F}}_2^n$$ F 2 n , we show that h is outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # if and only if f is outside $${{{\mathcal {M}}}{{\mathcal {M}}}}^\#$$ M M # . This approach is then generalized to the case when two bent functions are used. More precisely, the concatenation $$f_1||f_1||f_2||(1\oplus f_2)$$ f 1 | | f 1 | | f 2 | | Enes Pasalic, Amar Bapic, Fengrong Zhang, Yongzhuang Wei |
Des. Codes Cryptogr. | 4 |
| 2023 | New Second-order Threshold Implementation of Sm4 Block Cipher
Tianyi Shao, Bohua Wei, Yu Ou, Yongzhuang Wei, Xiaonian Wu |
J. Electron. Test. | 4 |
| 2023 | Improving the Performance of CPA Attacks for Ciphers Using Parallel Implementation of S-BoxesabstractSince their introduction in early 2000, CPA (correlation power analysis), as a cryptographic tool, has been widely used in the cryptanalysis of cryptographic algorithms (being applicable to both symmetric key ciphers as well as to public key encryption schemes). An application of the classical CPA method, along with its variants, to cryptographic algorithms that use parallel implementation of its substitution boxes (S‐boxes) commonly requires more power traces to extract the secret key compared to the case when serial implementation of S‐boxes is employed. To reduce the amount of power traces in this scenario, we propose a modification of the standard CPA approaches and demonstrate practically that our method performs better than the existing ones in this respect. To verify the efficiency of our improved CPA method, we apply it to the public databases of DPA Contest V2. In particular, the experimental results show that only 495 power traces are required to recover the secret key of AES. We also compare the performance of our attack to the relevant methods whose parameters are available at DPA Contest V2. The results show that compared to the best nonprofiling side‐channel attack (SCA) attack, our method reduces the number of power traces required to recover the secret key by 6,566. Also, our new method performs almost similarly as the best profiling SCA attack of Benoit Gerard (in terms of the required number of power traces), thus reducing the gap in the performance of profiling and nonprofiling SCA attacks. Fu Yao, Yongzhuang Wei, Hua Chen 0011, Enes Pasalic |
IET Inf. Secur. | 2 |
| 2022 | Minimal binary linear codes: a general framework based on bent concatenation
Fengrong Zhang, Enes Pasalic, René Rodríguez, Yongzhuang Wei |
Des. Codes Cryptogr. | 4 |
| 2022 | Two secondary constructions of bent functions without initial conditions
Yongzhuang Wei, Fengrong Zhang, Enes Pasalic, Nastja Cepak |
Des. Codes Cryptogr. | 2 |
| 2022 | New construction of highly nonlinear resilient S-boxes via linear codes
Haixia Zhao, Yongzhuang Wei |
Frontiers Comput. Sci. | 2 |
| 2022 | New attacks against reduced Rijndael-160abstractAbstract The first 9‐round meet‐in‐the‐middle (MITM) attack and improved 8‐round impossible differential (ID) attacks on Rijndael‐160 are studied here. For the first 9‐round MITM attack, a new effective attack path is explored by using the generalised δ ‐set and the generalised multiset, which are based on the property that the difference branch number of MixColumns is 5. With this attack path, a 5‐round MITM distinguisher with a technique of the truncated differential characteristic is proposed, and then the attack on 9‐round Rijndael‐160 is performed. For the improved 8‐round ID attacks, to take advantage of the key‐schedule weaknesses for Rijndael‐160 under key sizes of 160 and 256 bits, some new attack paths are found. With these attack paths, the 5‐round IDs are proposed based on the property of MixColumns above, and then the attacks on the 8‐round Rijndael‐160 under key sizes of 160 and 256 bits are performed. When compared with the currently known attacks, the proposed attacks have lower data, time, and memory complexities. Xiaoli Dong, Yongzhuang Wei |
IET Inf. Secur. | 2 |
| 2021 | On Characterization of Transparency Order for (n, m)-functions
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu |
Inscrypt | 2 |
| 2021 | Impossible Differential Cryptanalysis and Integral Cryptanalysis of the ACE-Class Permutation
Yongzhuang Wei, Lingcheng Li, Enes Pasalic |
ISPEC | 2 |
| 2021 | Transparency Order of (n, m)-Functions - Its Further Characterization and Applications
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu |
ISC | 2 |
| 2021 | Vectorial bent functions weakly/strongly outside the completed Maiorana-McFarland class
Enes Pasalic, Fengrong Zhang, Sadmir Kudin, Yongzhuang Wei |
Discret. Appl. Math. | 4 |
| 2021 | Wide minimal binary linear codes from the general Maiorana-McFarland class
Fengrong Zhang, Enes Pasalic, René Rodríguez, Yongzhuang Wei |
Des. Codes Cryptogr. | 4 |
| 2021 | Constructions of balanced Boolean functions on even number of variables with maximum absolute value in autocorrelation spectra 2n2☆
Fengrong Zhang, Enes Pasalic, Yongzhuang Wei |
Inf. Sci. | 3 |
| 2021 | On the transparency order relationships between one Boolean function and its decomposition functions
Yu Zhou 0012, Yongzhuang Wei |
J. Inf. Secur. Appl. | 3 |
| 2021 | Integral Distinguishers of the Full-Round Lightweight Block Cipher SAT_JoabstractIntegral cryptanalysis based on division property is a powerful cryptanalytic method whose range of successful applications was recently extended through the use of Mixed-Integer Linear Programming (MILP). Although this technique was demonstrated to be efficient in specifying distinguishers of reduced round versions of several families of lightweight block ciphers (such as SIMON, PRESENT, and few others), we show that this method provides distinguishers for a full-round block cipher SAT_Jo. SAT_Jo cipher is very similar to the well-known PRESENT block cipher, which has successfully withstood the known cryptanalytic methods. The main difference compared to PRESENT, which turns out to induce severe weaknesses of SAT_Jo algorithm, is its different choice of substitution boxes (S-boxes) and the bit-permutation layer for the reasons of making the cipher highly resource-efficient. Even though the designers provided a security analysis of this scheme against some major generic cryptanalytic methods, an application of the bit-division property in combination with MILP was not considered. By specifying integral distinguishers for the full-round SAT_Jo algorithm using this method, we essentially disapprove its use in intended applications. Using a 30-round distinguisher, we also describe a subkey recovery attack on the SAT_Jo algorithm whose time complexity is about 2 66 encryptions (noting that SAT_Jo is designed to provide 80 bits of security). Moreover, it seems that the choice of bit-permutation induces weak division properties since replacing the original bit-permutation of SAT_Jo by the one used in PRESENT immediately renders integral distinguishers inefficient. Xueying Qiu, Yongzhuang Wei, Samir Hodzic, Enes Pasalic |
Secur. Commun. Networks | 2 |
| 2021 | On the Modified Transparency Order of n , m -FunctionsabstractThe concept of transparency order is introduced to measure the resistance of n , m -functions against multi-bit differential power analysis in the Hamming weight model, including the original transparency order (denoted by TO ), redefined transparency order (denoted by RTO ), and modified transparency order (denoted by MTO ). In this paper, we firstly give a relationship between MTO and RTO and show that RTO is less than or equal to MTO for any n , m -functions. We also give a tight upper bound and a tight lower bound on MTO for balanced n , m -functions. Secondly, some relationships between MTO and the maximal absolute value of the Walsh transform (or the sum-of-squares indicator, algebraic immunity, and the nonlinearity of its coordinates) for n , m -functions are obtained, respectively. Finally, we give MTO and RTO for (4,4) S-boxes which are commonly used in the design of lightweight block ciphers, respectively. Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Wenzheng Zhang 0001 |
Secur. Commun. Networks | 2 |
| 2021 | Efficient Estimate of Sentence's Representation Based on the Difference Semantics ModelabstractSentence representation is an important research hotspot in natural language processing (NLP) since it can map the semantics of sentences into semantics vectors, thereby effectively solving complex semantics computing problems. Recently, sentence representations are mainly obtained by indirect means. Specifically, for sentence representations obtained by unsupervised means, they are often calculated by the weighted sum of embeddings of tokens in sentences; for sentence representations obtained by self-supervised or supervised means, they are often derived from intermediate encodings of sentences in prediction tasks. For example, Google's BERT and MUSE respectively use the embedding of [CLS] in the next sentence prediction task and intermediate encodings of sentences in the translation bridge task as sentence representations. In this paper, we use the observed semantics increment feature of sentences to directly model the semantics function of sentences. To be able to use the existing neural network language model to approximate the semantics function, we first implement the first-order Taylor expansion on the semantics function to obtain a difference semantics model and then add it to BERT as a subtask to perform self-supervised fine-tuning. Finally, we get a new sentence representation model S-BERT. S-BERT achieves the state-of-the-art performance on many datasets in Chinese, English, and Vietnamese. Xianwen Liao, Yongzhong Huang, Yongzhuang Wei, Yong Wang 0031 |
IEEE ACM Trans. Audio Speech Lang. Process. | 3 |
| 2021 | Energy Balanced Source Location Privacy Scheme Using Multibranch Path in WSNs for IoTabstractSource location privacy, one of the core contents of Wireless Sensor Network (WSN) security, has a significant impact on extensive application of WSNs. In this paper, a novel location privacy protection routing scheme called Energy Balanced Branch Tree (EBBT) is proposed by using multibranch and fake sources. This scheme has three phases. In the first place, the data of the source are randomly sent to a certain intermediate node. Then, a minimum hop routing (MHR) from the intermediate node to the base station is formed. Then, branch paths with fake sources are generated dynamically from some nodes on the MHR path. Finally, a tree‐shaped structure from real source nodes and fake source nodes to the base station is achieved. In difference to the previous schemes, the location of the real source in the EBBT scheme does not affect the location and the number of fake sources. During the formation of the tree‐shaped multibranch paths, the residual energy of nodes is considered sufficiently, and the control of the direction of each branch path is also involved. The influence of the number and length of branches on the network lifetime and network security is also investigated. Experimental results show that the proposed algorithm has the advantages of long network security period and lifetime, as well as high path diversity. Our simulation further illustrates that the EBBT scheme has favorable privacy of the source location without changing the network lifetime. Huijiao Wang, Yongzhuang Wei |
Wirel. Commun. Mob. Comput. | 4 |
| 2020 | Further analysis of bent functions from C and D which are provably outside or inside M#
Fengrong Zhang, Nastja Cepak, Enes Pasalic, Yongzhuang Wei |
Discret. Appl. Math. | 4 |
| 2020 | A general framework for secondary constructions of bent and plateaued functions
Samir Hodzic, Enes Pasalic, Yongzhuang Wei |
Des. Codes Cryptogr. | 3 |
| 2019 | Guess and determine cryptanalysis with variable sampling and its applicationsabstractNon‐linear filtering generators, as a well‐known family of stream ciphers, employ a filtering function to process the secret state bits and thus outputs binary keystream blocks of length m . In this study, the authors extend the framework of a generic cryptanalytic method applicable to non‐linear filtering generators called generalised filter state guessing attacks (GFSGA), introduced as a generalisation of the filter state guessing attack method, by applying a variable sampling of the keystream bits in order to retrieve as much information about the secret state bits as possible. Two different modes that use a variable sampling of keystream blocks are presented and it is shown that in many cases these modes may outperform the standard GFSGA mode. They also demonstrate the possibility of employing GFSGA‐like attacks to other design strategies such as non‐linear feedback shift register‐based ciphers (Grain family for instance). It is also indicated that the tap positions of Grain‐128 are not chosen optimally with respect to this generic cryptanalytic method and provide a better selection of taps that gives higher resistance to GFSGA‐like attacks. Samir Hodzic, Enes Pasalic, Yongzhuang Wei |
IET Inf. Secur. | 3 |
| 2019 | New second-order threshold implementation of AESabstractIn this work, the authors propose some alternative hardware efficient masking schemes dedicated to protect the Advanced Encryption Standard (AES) against higher order differential power analysis (DPA). In general, the existing masking schemes all have in common an intrinsic trade‐off between the two main parameters of interest, namely the generation of fresh random masking values and the cost of hardware implementation. The design of efficient masking schemes which are non‐expensive in both aspects appears to be a difficult task. In this study, the authors propose a second‐order threshold implementation of AES, which is characterised by a beneficial trade‐off between the two parameters. More precisely, compared to the masking scheme of De Cnudde et al . at CHES 2016, which currently attains the best practical trade‐off, the proposed masking scheme requires 28.4% less random masking bits, whereas the implementation cost is slightly increased for about 13.7% (thus the chip area is 1.4 kGE larger). This masking scheme has been used to implement AES on an field‐programmable gate array (FPGA) platform and its resistance against the second‐order DPA in a simulated attack environment has been confirmed. Yongzhuang Wei, Fu Yao, Enes Pasalic, An Wang 0001 |
IET Inf. Secur. | 1 |
| 2019 | Measuring the Sum-of-Squares Indicator of Boolean Functions in Encryption Algorithm for Internet of ThingsabstractEncryption algorithm has an important application in ensuring the security of the Internet of Things. Boolean function is the basic component of symmetric encryption algorithm, and its many cryptographic properties are important indicators to measure the security of cryptographic algorithm. This paper focuses on the sum-of-squares indicator of Boolean function; an upper bound and a lower bound of the sum-of-squares on Boolean functions are obtained by the decomposition Boolean functions; some properties and a search algorithm of Boolean functions with the same autocorrelation (or cross-correlation) distribution are given. Finally, a construction method to obtain a balanced Boolean function with small sum-of-squares indicator is derived by decomposition Boolean functions. Compared with the known balanced Boolean functions, the constructed functions have the higher nonlinearity and the better global avalanche characteristics property. Yu Zhou 0012, Yongzhuang Wei, Fengrong Zhang |
Secur. Commun. Networks | 2 |
| 2019 | A New Cube Attack on MORUS by Using Division PropertyabstractMORUS is an authenticated encryption algorithm and one of the candidates in the CAESAR competition. Currently, the security of MORUS received extensive attention. In this paper, a new existence terms detection method in superpoly recovery phase in cube attack is proposed. More precisely, the upper bounding degree of superpoly is first estimated by using the cube attack based on the division property with Mixed Integer Linear Programming tool. Moreover, the t-degree monomials that may be involved in the superpoly are divided into two groups, where the elements of the first group can be directly determined without using the solver via the embedded property. Compared with previous methods, the time consumption by the solvers of our new method is reduced significantly. In particular, the truth table from only the existent terms can be used to recover the superpoly in the offline phase of the cube attack. Therefore, the time complexity of cube attack can be further reduced. As illustrative example, the security of the reduced-step variants of MORUS-640-128 against cube attack is evaluated by using this new method. It is demonstrated that the key recovery attacks can be applied to 6/7-step MORUS-640-128. Furthermore, some integral distinguishers of 7-step MORUS-640-128/MORUS-1280-256 are achieved. Yongzhuang Wei, Willi Meier |
IEEE Trans. Computers | 2 |
| 2019 | Privacy-Preserving Cloud-Based Road Condition Monitoring With Source Authentication in VANETsabstractThe connected vehicular ad hoc network (VANET) and cloud computing technology allows entities in VANET to enjoy the advantageous storage and computing services offered by some cloud service provider. However, the advantages do not come free, since their combination brings many new security and privacy requirements for VANET applications. In this paper, we investigate the cloud-based road condition monitoring (RCoM) scenario, where the authority needs to monitor real-time road conditions with the help of a cloud server so that it could make sound responses to emergency cases timely. When some bad road condition is detected, e.g., some geologic hazard or accident happens, vehicles on site are able to report such information to a cloud server engaged by the authority. We focus on addressing three key issues in RCoM. First, the vehicles have to be authorized by some roadside unit before generating a road condition report in the domain and uploading it to the cloud server. Second, to guarantee the privacy against the cloud server, the road condition information should be reported in ciphertext format, which requires that the cloud server should be able to distinguish the reported data from different vehicles in ciphertext format for the same place without compromising their confidentiality. Third, the cloud server and authority should be able to validate the report source, i.e., to check whether the road conditions are reported by legitimate vehicles. To address these issues, we present an efficient RCoM scheme, analyze its efficiency theoretically, and demonstrate the practicality through experiments. Yong Ding 0005, Qianhong Wu, Yongzhuang Wei, Huiyong Wang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Designing Plateaued Boolean Functions in Spectral Domain and Their ClassificationabstractThe design of plateaued functions over GF(2)n, also known as 3-valued Walsh spectra functions (taking the values from the set {0, ±2Γ(n+s/2)1}), has been commonly approached by specifying a suitable algebraic normal form which then induces this particular Walsh spectral characterization. In this paper, we consider the reversed design method which specifies these functions in the spectral domain by specifying a suitable allocation of the nonzero spectral values and their signs. We analyze the properties of trivial and nontrivial plateaued functions (as affine inequivalent distinct subclasses), which are distinguished by their Walsh support Sf (the subset of GF(2)n having the nonzero spectral values) in terms of whether it is an affine subspace or not. The former class exactly corresponds to partially bent functions and admits linear structures, whereas the latter class may contain functions without linear structures. A simple sufficient condition on Sf , which ensures the nonexistence of linear structures, is derived and some generic design methods of nontrivial plateaued functions without linear structures are given. The extended affine equivalence of plateaued functions is also addressed using the concept of dual of plateaued functions. Furthermore, we solve the problem of specifying disjoint spectra (non)trivial plateaued functions of maximal cardinality whose concatenation can be used to construct bent functions in a generic manner. This approach may lead to new classes of bent functions due to large variety of possibilities to select underlying duals that define these disjoint spectra plateaued functions. An additional method of specifying affine in equivalent plateaued functions, obtained by applying a nonlinear transform to their input domain, is also given. Samir Hodzic, Enes Pasalic, Yongzhuang Wei, Fengrong Zhang |
IEEE Trans. Inf. Theory | 3 |
| 2018 | Lightweight attribute based encryption scheme for mobile cloud assisted cyber-physical systems
Ning Zhang 0001, Yongzhuang Wei, Yan Zhang 0002 |
Comput. Networks | 3 |
| 2018 | Weak keys of the full MISTY1 block cipher for related-key amplified boomerang cryptanalysisabstractThe MISTY1 block cipher has a 64‐bit block size, a 128‐bit master key, and a total of 8 rounds. It is an ISO international standard, a Japanese CRYPTREC‐recommended e‐government cipher, and a European NESSIE selected cipher. In this study, the authors show another cryptographic weakness of the full MISTY1 cipher: they describe four classes of weak keys of the full MISTY1 cipher for a related‐key amplified boomerang attack that has a data complexity of chosen plaintexts and a time complexity of encryptions under each class of weak keys. The result shows that the MISTY1 cipher can be distinguishable from an ideal cipher in terms of related‐key amplified boomerang cryptanalysis, and users should be very careful when using MISTY1 for a full security in relevant application situations. Jiqiang Lu, Wun-She Yap, Yongzhuang Wei |
IET Inf. Secur. | 3 |
| 2018 | Large Sets of Disjoint Spectra Plateaued Functions Inequivalent to Partially Linear FunctionsabstractIn this paper, we give an efficient method for constructing a large set of disjoint spectra functions without linear structures, which are not equivalent to partially linear functions. This positively answers the open problem [“how to construct a large set of disjoint spectra functions which are not (linearly equivalent to) partially linear functions” raised by Zhang and Xiao]. At the same time, this significantly extends a recent result of Zhang, where a method of specifying four disjoint spectra functions was given. It is demonstrated that such sets can be utilized in the design of highly nonlinear resilient functions. In the second part, based on a generalization of the indirect sum method, we give an alternative approach for designing sets of disjoint spectra functions of even larger cardinality than already given ones, but these functions then admit linear structures. In addition, it is shown that using suitable initial functions in the generalized indirect sum method we can specify highly nonlinear resilient Boolean functions (in odd number of input variables n) whose nonlinearity in many cases exceeds the current best known values. Moreover, we design some balanced functions (for odd n) that also achieve the highest nonlinearity known. Fengrong Zhang, Yongzhuang Wei, Enes Pasalic, Shixiong Xia |
IEEE Trans. Inf. Theory | 2 |
| 2017 | Efficient probabilistic algorithm for estimating the algebraic properties of Boolean functions for large n
Yongzhuang Wei, Enes Pasalic, Fengrong Zhang, Samir Hodzic |
Inf. Sci. | 1 |
| 2017 | New constructions of resilient functions with strictly almost optimal nonlinearity via non-overlap spectra functions
Yongzhuang Wei, Enes Pasalic, Fengrong Zhang, Wenling Wu, Cheng-Xiang Wang 0001 |
Inf. Sci. | 1 |
| 2017 | Constructing Bent Functions Outside the Maiorana-McFarland Class Using a General Form of RothausabstractIn the mid 1960s, Rothaus proposed the so-called “most general form” of constructing new bent functions by using three (initial) bent functions whose sum is again bent. In this paper, we utilize a special case of Rothaus construction when two of these three bent functions differ by a suitably chosen characteristic function of an n/2-dimensional subspace. This simplification allows us to treat the induced bent conditions more easily, also implying the possibility to specify the initial functions in the partial spread class and most notably to identify several instances of the so-called non-normal bent functions. Affine inequivalent bent functions within this class are then identified using a suitable selection of initial bent functions within the partial spread class (stemming from the complete Desarguesian spread). It is also shown that when the initial bent functions belong to the class D, then, under certain conditions, the constructed functions provably do not belong to the completed Maiorana-McFarland class. We conjecture that our method potentially generates an infinite class of non-normal bent functions (all tested ten-variable functions are non-normal but unfortunately they are weakly normal) though there are no efficient computational tools for confirming this. Fengrong Zhang, Enes Pasalic, Yongzhuang Wei, Nastja Cepak |
IEEE Trans. Inf. Theory | 3 |
| 2016 | Infinite classes of vectorial plateaued functions, permutations and complete permutations
Enes Pasalic, Nastja Cepak, Yongzhuang Wei |
Discret. Appl. Math. | 3 |
| 2015 | Constructions of Bent - Negabent Functions and Their Relation to the Completed Maiorana - McFarland ClassabstractThe problem of constructing bent-negabent functions that do not belong to the completed Maiorana-McFarland class emerges implicitly through a series of construction methods proposed recently. These approaches manage to optimize the algebraic degree of bent-negabent functions, but all of the constructed bent-negabent functions belong to the completed Maiorana-McFarland class. In this paper, we use the indirect sum construction (proposed by Carlet in 2004) for constructing the bent-negabent functions that are not provably contained in this class, which is the first significant attempt in this direction. To achieve this, we first provide a class of bent functions with certain desirable properties that does not belong to this class and demonstrate the existence of the class members. Then, embedding these functions in the framework of the indirect sum construction, we are able to specify sufficient conditions for bent-negabent functions not being contained in the completed Maiorana-McFarland class. Fengrong Zhang, Yongzhuang Wei, Enes Pasalic |
IEEE Trans. Inf. Theory | 2 |
| 2014 | Call for papers: systematic network optimizations for security parameters (security and communication networks)abstractIn network planning and design, security usually conflicts with other design objectives, such as usability, performance, and even functionality. Meanwhile, security goals have their own inherent contradictions, as confidentiality, integrity, privacy, accountability, availability, and recovery from safety attacks often conflict fundamentally. For a good network design, balancing these design objectives and cost is the prerequisite. However, it is quite difficult to satisfy all the security requirements simultaneously, let alone the multiple interacting and possibly conflicting targets. Ultimately, security comes down to using the information available best to balance the trade-offs among the competing goals of multiple factors. Considered as one of the grand challenges of the field, study the objective metric to evaluate the trade-offs of network security has draw extensive research attentions recently. In this call for papers, we would like to invite novel ideas; theoretical analysis for evaluating, modeling, and optimizing the trade-offs among network security; and other design objectives. Submissions of applications-oriented papers describing case studies and simulations are encouraged as well. High-quality original papers are solicited. Papers must be unpublished and must not be submitted for publication elsewhere. If a paper is extended from a conference paper, then the extension has to have at least 40% new materials. All papers will be peer reviewed according to the guidelines of Wiley's Security and Communication Networks Journal to ensure high quality and relevance to the Special Issue. All submissions should be prepared by following the guidelines given in Section “For Authors” at http://www.interscience.wiley.com/security. Prospective authors should submit their paper online at http://mc.manuscriptcentral.com/scn. Yongzhuang Wei, Rongxing Lu, Rose Qingyang Hu |
Secur. Commun. Networks | 2 |
| 2014 | The higher-order meet-in-the-middle attack and its application to the Camellia block cipher
Jiqiang Lu, Yongzhuang Wei, Jongsung Kim, Enes Pasalic |
Theor. Comput. Sci. | 2 |
| 2013 | Weak Keys of the Full MISTY1 Block Cipher for Related-Key Differential Cryptanalysis
Jiqiang Lu, Wun-She Yap, Yongzhuang Wei |
CT-RSA | 3 |
| 2013 | On the approximation of S-boxes via Maiorana-McFarland functionsabstractSubstitution boxes (S‐boxes) are the key components of conventional cryptographic systems. To quantify the confusion property of S‐boxes, different non‐linearity criteria are proposed such as usual non‐linearity ( N F ), unrestricted non‐linearity (UN F ), generalised non‐linearity (GN F ), higher order non‐linearity (HN F ) and so on. Although these different criteria come from the idea of linear (or non‐linear) approximation of S‐boxes, the algebraic structures of Boolean functions that are used to approximate to S‐boxes have not been considered yet. In this study, the concept of the extended non‐linearity of S‐boxes (denoted by EN F ) is introduced by measuring the distance of a given function to a subset of Maiorana–McFarland functions. This approximation appears to be appealing because of a particular structure of this class of functions, namely their representation as a concatenation of affine functions. The complexity of computing the r th order extended non‐linearity for S‐boxes over GF (2) n is less than O (( n r )2 n − r ), ( r > 1). Moreover, a theoretical upper bound for the r th order extended non‐linearity is proved, which is much lower than previous generalised non‐linearity which might give a rise to more efficient attacks that combine a generalised correlation approach with guess and determine techniques. Furthermore, the relationship between the r ‐order extended non‐linearity and the generalised non‐linearity is derived. Yongzhuang Wei, Enes Pasalic |
IET Inf. Secur. | 1 |
| 2012 | Parallelized Near-Duplicate Document Detection Algorithm for Large Scale Chinese Web PagesabstractA large scale of duplicate and near-duplicate web pages on the Internet create a lot of problems for search engines. Currently each single duplicate and near-duplicate web document detection algorithms cannot achieve both good performance and accuracy. Also most of them are designed to process English documents and not able to use for Chinese documents. This paper presents an integrated algorithm, KMatch, for near-duplicate document detection of large scale Chinese Web pages. First of all, KMatch employs Chinese segmentation algorithm to prepare Chinese words into meaningful features to compress documents. Then keywords matching technique is used to improve the accuracy of document detection. For further accuracy improvement, KMatch also combines IMatch algorithms to filter out the noise contents of a web document and retain the body text. To improve detection performance, we integrate the Shingling algorithm to compress huge datasets into smaller ones. Finally, to further improve the detection performance on large scale Chinese web pages, we design and implement KMatch algorithm in parallel with MapReduce. The experimental results show that our approach achieves both high precision and recall, and the parallelized algorithm with MapReduce achieves good performance and scalability when dealing with large scale of datasets. Yongzhuang Wei, Chunfeng Yuan, Yihua Huang 0001 |
PDCAT | 1 |
| 2012 | Cryptanalysis of reduced versions of the Camellia block cipherabstractThe Camellia block cipher has a 128-bit block length, a user key 128, 192 or 256 bits long and a total of 18 rounds for a 128-bit key and 24 rounds for a 192 or 256-bit key. It is a Japanese CRYPTREC-recommended e-government cipher, a European new European schemes for signatures, integrity and encryption (NESSIE) selected cipher and an ISO international standard. In this study, the authors describe a flaw in the approach used to choose plaintexts or ciphertexts in certain previously published square-like cryptanalytic results for Camellia and give two possible approaches to correct them. Finally, by taking advantage of the early abort technique and a few observations on the key schedule of Camellia, the authors present impossible differential attacks on 10-round Camellia with the FL/FL−1 functions under 128 key bits, 11-round Camellia with the FL/FL−1 functions under 192 key bits, 14-round Camellia without the FL/FL−1 functions under 192 key bits and 16-round Camellia without the FL/FL−1 functions under 256 key bits. Jiqiang Lu, Yongzhuang Wei, Pierre-Alain Fouque, Jongsung Kim |
IET Inf. Secur. | 2 |
| 2012 | Constructions of 1-resilient Boolean functions on odd number of variables with a high nonlinearityabstractABSTRACT In this paper, we concentrate on the design of 1‐resilient Boolean functions with desirable cryptographic properties. Firstly, we put forward a novel secondary construction to obtain 1‐resilient functions. Next, we present the relationships between the properties of these constructed 1‐resilient functions and that of the initial functions. Based on the construction and a class of bent functions on n variables, we can obtain a class of ( n + 3)‐variable 1‐resilient non‐separable cryptographic functions with a high algebraic immunity, whose nonlinearity is equal to the bent concatenation bound 2 n + 2 − 2 ( n + 2)/2 . Furthermore, we propose a set of 1‐resilient non‐separable functions on odd number of variables with an optimal algebraic degree, a high algebraic immunity, and a high nonlinearity. Copyright © 2011 John Wiley & Sons, Ltd. Fengrong Zhang, Yupu Hu, Min Xie 0003, Yongzhuang Wei |
Secur. Commun. Networks | 4 |
| 2012 | On the Construction of Cryptographically Significant Boolean Functions Using Objects in Projective Geometry SpacesabstractRecently, several construction methods of highly nonlinear Boolean functions with relatively good algebraic properties were proposed. These approaches manage in optimizing most of the relevant cryptographic criteria, but not all of them at the same time. Usually, either the nonlinearity bounds are rather loose (though the actual nonlinearity is relatively high) or the functions do not provide a good resistance to fast algebraic cryptanalysis. In this paper, we develop a theoretical framework for using objects in suitable projective geometry spaces for construction of highly nonlinear Boolean functions. This allows us to establish tight bounds on the nonlinearity using simple counting arguments, thus avoiding rather complicated estimates of certain trace sums. Our method generates a class of almost fully optimized functions, that is the functions apart from very high nonlinearity also have the maximum algebraic degree and optimal algebraic immunity. Compared to the classes of functions proposed by Carlet and Feng, Wang , and Zeng , our functions achieve a slightly better nonlinearity which is traded-off against a little worse resistance against fast algebraic attacks. On the other hand, compared to the functions by Tang and Tu and Deng, our nonlinearity is somewhat lower, but the algebraic properties are slightly better. Enes Pasalic, Yongzhuang Wei |
IEEE Trans. Inf. Theory | 2 |
| 2012 | Guess and Determine Attacks on Filter Generators - RevisitedabstractAlthough there are many different approaches used in cryptanalysis of nonlinear filter generators, the selection of tap positions has not received enough attention yet. In this paper we examine the security of nonlinear filter generators that output several bits at the time against a variant of a guess and determine attack that takes into account the tap positions of the generator. In difference to the filter state guessing attack (FSGA) introduced by Pasalic (2009), our approach further reduces the input preimage space by using a given placement of the tap positions. The new attack, though a simple generalization of the FSGA, in many cases outperforms both classical algebraic attacks and the FSGA. In particular, the new attack is much more efficiently applied against filter generators that use a vectorial Maiorana-McFarland than classical algebraic attacks or the FSGA. As a proof of the concept we apply our attack to the stream cipher SOBER-t32 without stuttering and show that our attack performs slightly better than a guess and determine attack proposed by Babbage et al. Yongzhuang Wei, Enes Pasalic, Yupu Hu |
IEEE Trans. Inf. Theory | 1 |
| 2011 | Meet-in-the-Middle Attack on 8 Rounds of the AES Block Cipher under 192 Key Bits
Yongzhuang Wei, Jiqiang Lu, Yupu Hu |
ISPEC | 1 |
| 2011 | A New Correlation Attack on Nonlinear Combining GeneratorsabstractIn this paper, the correlation properties of a nonlinear combining function over its support or zero set are investigated. Based on this characterization, a new attack on nonlinear combining generators is proposed. Our attack does not utilize traditional (non)linear statistics between the input and the output over the entire variable space, as the distinguishing process is rather applied to the restricted input space. The attack appears to be very efficient against nonlinear combining generators whose combining LFSRs are of relatively small input size. In many cases, our attack is a more favorable alternative than the known correlation attacks (but also than algebraic attacks in certain cases). To study the maximum correlation of a nonlinear combining function over its support or zero set, the notion of maximum distinguishable correlation is introduced. The relationship between the maximum distinguishable correlation and the nonlinearity of a combining function is then derived by using the normalized Walsh transform. Finally, we extend the usual notion of resiliency and discuss its implications towards the resistance against our attack. Yongzhuang Wei, Enes Pasalic, Yupu Hu |
IEEE Trans. Inf. Theory | 1 |
| 2009 | New related-key rectangle attacks on reduced AES-192 and AES-256
Yongzhuang Wei, Yupu Hu |
Sci. China Ser. F Inf. Sci. | 1 |
| 2007 | Maximum Autocorrelation Analysis of Nonlinear Combining Functions in Stream CiphersabstractThis paper investigates two new design rules of nonlinear combining functions in stream ciphers. It is shown that a combining function with high nonlinearity and high order correlation immunity is still not enough to prevent the divide and conquer attack and the BAA attack (or the best affine approximation attack) since the autocorrelation function of the combining function may also be leaked much more information about the input of the combining function. To measure the strength of nonlinear combining functions, the notion of maximum autocorrelation is introduced, which is based on the correlation between linear functions of input and the autocorrelation function of a combining function. The relationship between the maximum autocorrelation coefficient and the mutual information of the autocorrelation function of the combining function is discussed. Moreover, the upper bound of maximum autocorrelation coefficient is presented by using Walsh transform. Yongzhuang Wei, Yupu Hu |
ISIT | 1 |
| 2005 | A construction of resilient functions with satisfying synthetical cryptographic criteriaabstractIn this paper, we provide a new generalized construction method for (n, m, t) resilient functions with satisfying synthetical cryptographic criteria. These synthetical cryptographic criteria include high nonlinearity, good resiliency, high algebraic degree, and nonexistence of nonzero linear structure and so on. The construction is based on the use of linear error-correcting code. Given a linear [u, m, t + 1] code and its dual code [u, u - m, t/sup */ + 1], we show that it is possible to construct (n, m, d) resilient functions with satisfying synthetical cryptographic criteria, where d = min(t, t/sup */) and n > u > 2m. The method provides a new idea in designing cryptographic functions. Yongzhuang Wei, Yupu Hu |
ITW | 1 |