Lei Wang 0031

dblp:w/LeiWang31 · DBLP profile ↗
← Back
68ranked-venue papers
4as first author
16since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 59 · 4 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Theory of computation · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNY
Ling Song 0001, Yincen Chen, Qianqian Yang 0003, Lei Wang 0031, Lei Hu 0003, Jian Weng 0001
CRYPTO (6)5
2024 Multi-User Security of CCM Authenticated Encryption Mode
abstract
The CCM authenticated encryption mode has gained widespread usage and standardization. Notably, in conjunction with GCM and ChaCha20-Poly1305, CCM is recommended to be used in TLS 1.3 that underlies in https. Since TLS 1.3 is currently utilized by a large number of users, it is imperative to assess the security of these schemes in the multi-user model. Concrete multi-user security analysis for GCM and ChaCha20-Poly1305 have been scrutinized in literature. However, the formal multi-user security analysis for CCM falls behind that for GCM and ChaCha20-Poly1305. Furthermore, in the associated IETF document, the multi-user security bound for CCM is derived by naive generic reduction and falls considerably short of our expectations. In this paper, we bridge the gap by establishing a concrete multi-user security bound for CCM. Our new bound surpasses that derived from generic reduction and it indicates that CCM maintains birthday-bound security in the multi-user model as in the single-user model.
Yaobin Shen, Lei Wang 0031
CCS3
2024 Security Analysis of CMAC in the Multi-user Model
Yaobin Shen, Lei Wang 0031
ISC (1)3
2024 Real-Time Related-Key Attack on Full-Round Shadow Designed for IoT Nodes
abstract
With the rapid development of the Internet of Things (IoT), many new lightweight block ciphers are designed in recent years to meet the security demand in IoT devices. Shadow is a lightweight block cipher designed for IoT Nodes (IEEE Internet of Things Journal, 2021). In this article, an efficient attack on full-round Shadow is proposed based on the idea of a related-key differential attack. First, a differential transfer property for AND operation is illustrated. This property demonstrates a link between the difference and the input value. If the difference of the input is not zero, to lead to a zero difference, there are some constraints on the input value. Furthermore, two properties for Shadow family ciphers are identified. According to these properties, some related keys on Shadow will lead to an internal collision for the subkey generator, which will eventually lead to a full-round distinguisher. Finally, with the idea of related-key differential attack, an efficient attack is applied to Shadow. For Shadow-32, with 4 related keys, 8 master key bits can be derived in about 0.044 seconds on average. For Shadow-64, with 4 related keys, 24 master key bits can be derived in about 3.9 hours on average. All our theoretical results are verified by experiments.
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
IEEE Trans. Computers3
2024 DeCloak: Enable Secure and Cheap Multi-Party Transactions on Legacy Blockchains by a Minimally Trusted TEE Network
abstract
The crucial blockchain privacy and scalability demand has boosted off-chain contract execution frameworks for years. Some have recently extended their capabilities to transition blockchain states by off-chain multi-party computation while ensuring public verifiability. This new capability is defined as acrfull mpt. However, existing MPT solutions lack at least one of the following properties crucially valued by communities: data availability, financial fairness, delivery fairness, and delivery atomicity. This paper proposes a novel MPT-enabled off-chain contract execution framework, Decloak. Using TEEs, Decloak solves identified properties with lower gas costs and a weaker assumption. Notably, Decloak is the first to achieve data availability and also achieve all of the above properties. This achievement is coupled with its ability to tolerate all-but-one Byzantine parties and TEE executors. Evaluating 10 MPTs in different businesses, Decloak reduces the gas cost of the SOTA, Cloak, by 65.6%. This efficiency advantage further amplifies with an increasing number of MPT’s parties. Consequently, we establish an elevated level of secure and cheap MPT, being the first to demonstrate the feasibility of achieving gas costs comparable to Ethereum transactions while evaluating MPTs.
Qian Ren, Yue Li 0037, Yingjun Wu, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
IEEE Trans. Inf. Forensics Secur.6
2024 Impossible Differential Cryptanalysis and a Security Evaluation Framework for AND-RX Ciphers
abstract
In this paper, a security evaluation framework for AND-RX ciphers against impossible differential cryptanalysis is proposed. This framework is constructed based on three different methods towards finding the theoretical upper boundary, theoretical lower boundary, and practical boundary of impossible differential distinguishers (short for ID) respectively. The provable security boundary (upper boundary) can be calculated with two round-function-related matrices through a few matrix multiplications, this calculation is beyond actual input and output differences. For searching longer IDs (lower boundary), an automatic method is proposed. With this method, given the input and output difference, all the possible direct and indirect contradictions are detected. For the practical boundary, a method of approximating all the potential longest IDs with concrete differential trails is introduced. The three boundaries validate the correctness from each other. According to our result, on the one hand, the boundaries derived with well-designed ID-construction methods can already reach the practical boundary for some block ciphers and it is unlikely to be improved based on known construction methods or future unknown construction methods. On the other hand, for those ciphers whose current best result does not reach our boundary, longer IDs can be discovered with this framework. The correctness is validated by a series of applications. For the provable security boundary, four family ciphers-SIMON, Simeck, Friet-PC and SAND are investigated. For SIMON and Simeck, the lengths of current longest IDs have reached their provable security boundaries. For Friet-PC and SAND, there is a gap between the provable security boundary and current best results. With the automatic searching method, some longer IDs on Friet-PC and SAND are discovered. For Friet-PC, 128 11-round IDs are discovered, while the previous best differential distinguisher is 9-round. For SAND64, 256 11-round IDs are proposed. For SAND128, 456 14-round IDs are presented. Both results extend previous longest IDs by one round and all these newly proposed distinguishers reached corresponding provable security boundaries. For Simeck, the length of longest IDs has not been improved. However, more distinguishers of the same length are discovered. For Simeck64, the increased ratio for the quantity can reach 300%. Besides, the practical boundary of SIMON is investigated, the results indicate that for SIMON, the practical boundary is identical with the provable security boundary or the boundary derived with the automatic searching method.
Kai Zhang 0026, Senpeng Wang, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Tairong Shi
IEEE Trans. Inf. Theory4
2023 Forgery Attacks on Several Beyond-Birthday-Bound Secure MACs
Yaobin Shen, François-Xavier Standaert, Lei Wang 0031
ASIACRYPT (3)3
2023 Impossibility of Indifferentiable Iterated Blockciphers from 3 or Less Primitive Calls
Chun Guo 0002, Lei Wang 0031, Dongdai Lin
EUROCRYPT (4)2
2023 A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011
Sci. China Inf. Sci.3
2023 Meet-in-the-middle attack with splice-and-cut technique and a general automatic framework
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
Des. Codes Cryptogr.3
2023 Rotational-XOR Differential Cryptanalysis and an Automatic Framework for AND-RX Ciphers
abstract
In this paper, a security evaluation framework for AND-RX ciphers against rotational-XOR differential cryptanalysis is proposed. This framework first models the structure of all the possible rotational-XOR differential (abbreviated to “RXD”) trails and introduces a method to calculate this structure round by round. Based on this approach, an automatic method is proposed for searching RXD trails. In this method, four strategies are proposed to derive better result and improve the efficiency. Unlike previous automations, the time complexity for this framework can be pre-computed, which is bounded by${\mathcal{ O}}\left ({{c\cdot n\cdot R^{2}\cdot C_{n}^{n_{1}}} }\right)$(where$n$is the block size,$n_{1}$is the number of active bits for the starting point of automatic method,$R$is the length of the targeted rounds and$c$is a fixed constant). Under the given strategies and searching subspaces, the derived RXD trails are guaranteed to be optimal. To prove the correctness and efficiency, this framework is applied to all the ten variants for SIMON and three variants for Simeck. When compared with previous RXD trails, the best improvement is up to three rounds. To validate the correctness of the derived rotational-XOR differential trails, a concrete experiment on Simeck32 is conducted and the experimental result complies with the theoretical analysis. As far as we know, for all the variants of Simeck, current longest distinguishers over all the cryptanalytic methods are obtained in this paper.
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi
IEEE Trans. Inf. Theory3
2022 Cloak: Transitioning States on Legacy Blockchains Using Secure and Publicly Verifiable Off-Chain Multi-Party Computation
abstract
In recent years, the confidentiality of smart contracts has become a fundamental requirement for practical applications. While many efforts have been made to develop architectural capabilities for enforcing confidential smart contracts, a few works arise to extend confidential smart contracts to Multi-Party Computation (MPC), i.e., multiple parties jointly evaluate a transaction off-chain and commit the outputs on-chain without revealing their secret inputs/outputs to each other. However, existing solutions lack public verifiability and require O(n) transactions to enable negotiation or resist adversaries, thus suffering from inefficiency and compromised security.
Qian Ren, Yingjun Wu, Han Liu 0010, Yue Li 0037, Anne Victor, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
ACSAC7
2021 Revisiting the Security of DbHtS MACs: Beyond-Birthday-Bound in the Multi-user Setting
Yaobin Shen, Lei Wang 0031, Dawu Gu, Jian Weng 0001
CRYPTO (3)2
2021 Improved Guess and Determine attack on the MASHA stream cipher
Lin Ding 0001, Dawu Gu, Lei Wang 0031, Chenhui Jin, Jie Guan
Sci. China Inf. Sci.3
2021 Secure key-alternating Feistel ciphers without key schedule
Yaobin Shen, Hailun Yan, Lei Wang 0031, Xuejia Lai
Sci. China Inf. Sci.3
2021 A real-time related key attack on the WG-16 stream cipher for securing 4G-LTE networks
Lin Ding 0001, Dawu Gu, Lei Wang 0031, Chenhui Jin, Jie Guan
J. Inf. Secur. Appl.3
2020 Tweaking Key-Alternating Feistel Block Ciphers
Hailun Yan, Lei Wang 0031, Yaobin Shen, Xuejia Lai
ACNS (1)2
2020 SafePay on Ethereum: A Framework For Detecting Unfair Payments in Smart Contracts
abstract
Smart contracts on the Ethereum blockchain are notoriously known as vulnerable to external attacks. Many of their issues led to a considerably large financial loss as they resulted from broken payments by digital assets, e.g., cryptocurrency. Existing research focused on specific patterns to find such problems, e.g., reentrancy bug, nondeterministic recipient etc., yet may lead to false alarms or miss important issues. To mitigate these limitations, we designed the SafePay analysis framework to find unfair payments in Ethereum smart contracts. Compared to existing analyzers, SafePay can detect potential blockchain transactions with feasible exploits thus effectively avoid false reports. Specifically, the detection is driven by a systematic search for violations on fair value exchange (FVE), i.e., a new security invariant introduced in SafePay to indicate that each party “fairly” pays to others. The preliminary evaluation validated the efficacy of SafePay by reporting previously unknown issues and decreasing the number of false alarms.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
ICDCS5
2020 A New General Method of Searching for Cubes in Cube Attacks
Lin Ding 0001, Lei Wang 0031, Dawu Gu, Chenhui Jin, Jie Guan
ICICS2
2020 Protect Your Smart Contract Against Unfair Payment
abstract
While smart contracts have enabled a wide range of applications in many public blockchains, e.g., Ethereum, their security issues have been raising an increasing number of threats on the stability of blockchain ecosystem. In practice, many external attacks on smart contracts result from broken payments with digital assets, e.g., cryptocurrencies. While an increasing number of research works have been focusing on such problems, many of them adopted pattern-based heuristics (e.g., reentrancy) to find payment-related attacks thus can incur a considerably large portion of both false positives and negatives. To overcome these limitations and achieve better payment security on blockchain, we introduced a new class of payment attacks in this paper, i.e., unfair payment (UP). Compared to existing heuristics, UP semantically captures a wider range of payment attacks. Furthermore, we highlighted the general framework SAFEPAY to systematically detect UP. The key insight behind is a novel security invariant, i.e., fair value exchange (FVE), which models the fairness for blockchain payments between multiple parties. More specifically, SAFEPAY systematically explores the transaction space of a given smart contract and generates a bounded set of transaction sequences. For each of the sequence, SAFEPAY reports a UP attack once a violation on FVE is confirmed. We have further instantiated SAFEPAY for Ethereum and applied it in real-world smart contracts. In the empirical evaluation, SAFEPAY managed to identify previously unreported UP attacks and effectively avoid false alarms compared to analyzers in the literature as well.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
SRDS6
2020 Generic Attacks on Hash Combiners
abstract
Hash combiners are a practical way to make cryptographic hash functions more tolerant to future attacks and compatible with existing infrastructure. A combiner combines two or more hash functions in a way that is hopefully more secure than each of the underlying hash functions, or at least remains secure as long as one of them is secure. Two classical hash combiners are the exclusive-or (XOR) combiner \( \mathcal {H}_1(M) \oplus \mathcal {H}_2(M) \) and the concatenation combiner \( \mathcal {H}_1(M) \Vert \mathcal {H}_2(M) \) . Both of them process the same message using the two underlying hash functions in parallel. Apart from parallel combiners, there are also cascade constructions sequentially calling the underlying hash functions to process the message repeatedly, such as Hash-Twice \(\mathcal {H}_2(\mathcal {H}_1(IV, M), M)\) and the Zipper hash \(\mathcal {H}_2(\mathcal {H}_1(IV, M), \overleftarrow{M})\) , where \(\overleftarrow{M}\) is the reverse of the message M . In this work, we study the security of these hash combiners by devising the best-known generic attacks. The results show that the security of most of the combiners is not as high as commonly believed. We summarize our attacks and their computational complexities (ignoring the polynomial factors) as follows: Several generic preimage attacks on the XOR combiner: A first attack with a best-case complexity of \( 2^{5n/6} \) obtained for messages of length \( 2^{n/3} \) . It relies on a novel technical tool named interchange structure. It is applicable for combiners whose underlying hash functions follow the Merkle–Damgård construction or the HAIFA framework. A second attack with a best-case complexity of \( 2^{2n/3} \) obtained for messages of length \( 2^{n/2} \) . It exploits properties of functional graphs of random mappings. It achieves a significant improvement over the first attack but is only applicable when the underlying hash functions use the Merkle–Damgård construction. An improvement upon the second attack with a best-case complexity of \( 2^{5n/8} \) obtained for messages of length \( 2^{5n/8} \) . It further exploits properties of functional graphs of random mappings and uses longer messages. These attacks show a rather surprising result: regarding preimage resistance, the sum of two n -bit narrow-pipe hash functions following the considered constructions can never provide n -bit security. A generic second-preimage attack on the concatenation combiner of two Merkle–Damgård hash functions. This attack finds second preimages faster than \( 2^n \) for challenges longer than \( 2^{2n/7} \) and has a best-case complexity of \( 2^{3n/4} \) obtained for challenges of length \( 2^{3n/4} \) . It also exploits properties of functional graphs of random mappings. The first generic second-preimage attack on the Zipper hash with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{3n/5} \) , obtained for challenge messages of length \( 2^{2n/5} \) . An improved generic second-preimage attack on Hash-Twice with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{13n/22} \) , obtained for challenge messages of length \( 2^{13n/22} \) . The last three attacks show that regarding second-preimage resistance, the concatenation and cascade of two n -bit narrow-pipe Merkle–Damgård hash functions do not provide much more security than that can be provided by a single n -bit hash function. Our main technical contributions include the following: The interchange structure, which enables simultaneously controlling the behaviours of two hash computations sharing the same input. The simultaneous expandable message, which is a set of messages of length covering a whole appropriate range and being multi-collision for both of the underlying hash functions. New ways to exploit the properties of functional graphs of random mappings generated by fixing the message block input to the underlying compression functions.
Zhenzhen Bao, Itai Dinur, Jian Guo 0001, Gaëtan Leurent, Lei Wang 0031
J. Cryptol.5
2020 Improved Cloud-Assisted Privacy-Preserving Profile-Matching Scheme in Mobile Social Networks
abstract
Due to the transparency of the wireless channel, users in multiple-key environment are vulnerable to eavesdropping during the process of uploading personal data and re-encryption keys. Besides, there is additional burden of key management arising from multiple keys of users. In addition, profile matching using inner product between vectors cannot effectively filter out users with ulterior motives. To tackle the above challenges, we first improve a homomorphic re-encryption system (HRES) to support a single homomorphic multiplication and arbitrarily many homomorphic additions. The public key negotiated by the clouds is used to encrypt the users’ data, thereby avoiding the issues of key leakage and key management, and the privacy of users’ data is also protected. Furthermore, our scheme utilizes the homomorphic multiplication property of the improved HRES algorithm to compute the cosine result between the normalized vectors as the standard for measuring the users’ proximity. Thus, we can effectively improve the social experience of users.
Ying Zou 0008, Yanting Chai, Sha Shi, Lei Wang 0031, Yuan Ping 0003, Baocang Wang
Secur. Commun. Networks4
2020 Highly Secure Privacy-Preserving Outsourced k-Means Clustering under Multiple Keys in Cloud Computing
abstract
Data clustering is the unsupervised classification of data records into groups. As one of the steps in data analysis, it has been widely researched and applied in practical life, such as pattern recognition, image processing, information retrieval, geography, and marketing. In addition, the rapid increase of data volume in recent years poses a huge challenge for resource-constrained data owners to perform computation on their data. This leads to a trend that users authorize the cloud to perform computation on stored data, such as keyword search, equality test, and outsourced data clustering. In outsourced data clustering, the cloud classifies users’ data into groups according to their similarities. Considering the sensitive information in outsourced data and multiple data owners in practical application, it is necessary to develop a privacy-preserving outsourced clustering scheme under multiple keys. Recently, Rong et al. proposed a privacy-preserving outsourced k-means clustering scheme under multiple keys. However, in their scheme, the assistant server (AS) is able to extract the ratio of two underlying data records, and key management server (KMS) can decrypt the ciphertexts of owners’ data records, which break the privacy security. AS can even reduce all data records if it knows one of the data records. To solve the aforementioned problem, we propose a highly secure privacy-preserving outsourced k-means clustering scheme under multiple keys in cloud computing. In this paper, noncolluded cloud computing service (CCS) and KMS jointly perform clustering over the encrypted data records without exposing data privacy. Specifically, we use BCP encryption which has additive homomorphic property and AES encryption to double encrypt data records, where the former cryptosystem prevents CCS from obtaining any useful information from received ciphertexts and the latter one protects data records from being decrypted by KMS. We first define five protocols to realize different functions and then present our scheme based on these protocols. Finally, we give the security and performance analyses which show that our scheme is comparable with the existing schemes on functionality and security.
Ying Zou 0008, Zhen Zhao 0005, Sha Shi, Lei Wang 0031, Yuan Ping 0003, Baocang Wang
Secur. Commun. Networks4
2019 Pseudo random oracle of Merkle-Damgård hash functions revisited
Kamel Ammour, Lei Wang 0031, Dawu Gu
Sci. China Inf. Sci.2
2019 Beyond-birthday secure domain-preserving PRFs from a single permutation
Chun Guo 0002, Yaobin Shen, Lei Wang 0031, Dawu Gu
Des. Codes Cryptogr.3
2019 New zero-sum distinguishers on full 24-round Keccak-f using the division property
abstract
The authors analyse the security of K eccak (the winner in SHA‐3 competition) by focusing on the zero‐sum distinguishers of its underlying permutation (named K eccak ‐ f ). The authors’ analyses are developed by using the division property, a generalised integral property that was initially used in the integral cryptanalysis of symmetric‐key algorithms. Following the work pioneered by Todo at CRYPTO 2015, they first formalise and prove a more delicate propagation rule of the division property under the assumption that the S‐box's specification is known to attackers. Then, they apply this rule to the inverse S‐box in K eccak ‐ f with a further study on properties of its algebraic degree. They find that the rate of decline in the division property is gentler than that of a randomly chosen S‐box. Meanwhile, they get the same results for the S‐box in A scon permutation. Thanks to this vulnerable property, they can improve the higher‐order differential characteristics against the inverse of K eccak ‐ f in terms of the required number of chosen plaintexts. As an application, they give new zero‐sum distinguishers on full 24‐round K eccak ‐ f of size . To the authors’ knowledge, this is currently the best zero‐sum distinguishers of full‐round K eccak ‐ f permutation. Incidentally, they give the corresponding results for 12‐round A scon permutation.
Hailun Yan, Xuejia Lai, Lei Wang 0031, Yu Yu 0001, Yiran Xing
IET Inf. Secur.3
2019 Algebraic Degree Estimation of ACORN v3 Using Numeric Mapping
abstract
ACORN v3 is a lightweight authenticated encryption cipher, which was selected as one of the seven finalists of CAESAR competition in March 2018. It is intended for lightweight applications (resource-constrained environments). By using the technique numeric mapping proposed at CRYPTO 2017, an efficient algorithm for algebraic degree estimation of ACORN v3 is proposed. As a result, new distinguishing attacks on 647, 649, 670, 704, and 721 initialization rounds of ACORN v3 are obtained, respectively. So far, as we know, all of our distinguishing attacks on ACORN v3 are the best. The effectiveness and accuracy of our algorithm is confirmed by the experimental results.
Lin Ding 0001, Lei Wang 0031, Dawu Gu, Chenhui Jin, Jie Guan
Secur. Commun. Networks2
2018 Revisiting Key-Alternating Feistel Ciphers for Shorter Keys and Multi-user Security
Chun Guo 0002, Lei Wang 0031
ASIACRYPT (1)2
2018 Improved Indifferentiability Security Bound for the Prefix-Free Merkle-Damgård Hash Function
Kamel Ammour, Lei Wang 0031
Inscrypt2
2018 Length-Preserving Encryption Based on Single-Key Tweakable Block Cipher
Yaobin Shen, Hailun Yan, Ying Zou 0008, Zheyi Wu, Lei Wang 0031
ProvSec7
2018 Similar operation template attack on RSA-CRT as a case study
Xiangjun Lu, Yang Li 0022, Lei Wang 0031, Weijia Wang 0003, Haihua Gu, Zheng Guo 0001, Dawu Gu
Sci. China Inf. Sci.5
2017 Functional Graph Revisited: Updates on (Second) Preimage Attacks on Hash Combiners
Zhenzhen Bao, Lei Wang 0031, Jian Guo 0001, Dawu Gu
CRYPTO (2)2
2016 How to Build Fully Secure Tweakable Blockciphers from Classical Blockciphers
Lei Wang 0031, Jian Guo 0001, Guoyan Zhang, Dawu Gu
ASIACRYPT (1)1
2016 Replacing SHA-2 with SHA-3 Enhances Generic Security of HMAC
Yusuke Naito 0001, Lei Wang 0031
CT-RSA2
2015 Known-Key Distinguisher on Full PRESENT
Céline Blondeau, Thomas Peyrin, Lei Wang 0031
CRYPTO (1)3
2015 The Sum Can Be Weaker Than Each Part
Gaëtan Leurent, Lei Wang 0031
EUROCRYPT (1)2
2015 Cryptanalysis of JAMBU
Thomas Peyrin, Siang Meng Sim, Lei Wang 0031, Guoyan Zhang
FSE3
2015 Analysis of the CAESAR Candidate Silver
Jérémy Jean, Yu Sasaki 0001, Lei Wang 0031
SAC3
2014 Message Extension Attack against Authenticated Encryptions: Application to PANDA
Yu Sasaki 0001, Lei Wang 0031
CANS2
2014 Updates on Generic Attacks against HMAC and NMAC
Jian Guo 0001, Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031
CRYPTO (1)4
2014 Analysis of BLAKE2
Jian Guo 0001, Pierre Karpman, Ivica Nikolic, Lei Wang 0031, Shuang Wu 0004
CT-RSA4
2014 An Automated Evaluation Tool for Improved Rebound Attack: New Distinguishers and Proposals of ShiftBytes Parameters for Grøstl
Yu Sasaki 0001, Yuuki Tokushige, Lei Wang 0031, Mitsugu Iwamoto, Kazuo Ohta
CT-RSA3
2014 Generic Universal Forgery Attack on Iterative Hash-Based MACs
Thomas Peyrin, Lei Wang 0031
EUROCRYPT2
2014 Equivalent Key Recovery Attacks Against HMAC and NMAC with Whirlpool Reduced to 7 Rounds
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Long Wen 0002
FSE3
2014 Impact of ANSI X9.24-1: 2009 Key Check Value on ISO/IEC 9797-1: 2011 MACs
Tetsu Iwata, Lei Wang 0031
FSE2
2014 The Usage of Counter Revisited: Second-Preimage Attack on New Russian Standardized Hash Function
Jian Guo 0001, Jérémy Jean, Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031
Selected Areas in Cryptography5
2014 Practical Cryptanalysis of PAES
Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography4
2013 Cryptanalysis of HMAC/NMAC-Whirlpool
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004
ASIACRYPT (2)3
2013 New Generic Attacks against Hash-Based MACs
Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031
ASIACRYPT (2)3
2013 Improved Cryptanalysis of Reduced RIPEMD-160
Florian Mendel, Thomas Peyrin, Martin Schläffer, Lei Wang 0031, Shuang Wu 0004
ASIACRYPT (2)4
2013 Security Analysis of PRINCE
Jérémy Jean, Ivica Nikolic, Thomas Peyrin, Lei Wang 0031, Shuang Wu 0004
FSE4
2013 Cryptanalysis of Round-Reduced \mathttLED
Ivica Nikolic, Lei Wang 0031, Shuang Wu 0004
FSE2
2013 Improved Single-Key Distinguisher on HMAC-MD5 and Key Recovery Attacks on Sandwich-MAC-MD5
Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography2
2013 Meet-in-the-Middle Preimage Attacks Revisited - New Results on MD5 and HAVAL
Yu Sasaki 0001, Wataru Komatsubara, Yasuhide Sakai, Lei Wang 0031, Mitsugu Iwamoto, Kazuo Sakiyama, Kazuo Ohta
SECRYPT4
2012 Distinguishers beyond Three Rounds of the RIPEMD-128/-160 Compression Functions
Yu Sasaki 0001, Lei Wang 0031
ACNS2
2012 Generic Related-Key Attacks for HMAC
Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031
ASIACRYPT3
2012 Investigating Fundamental Security Requirements on Whirlpool: Improved Preimage and Collision Attacks
Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004, Wenling Wu
ASIACRYPT2
2012 New Truncated Differential Cryptanalysis on 3D Block Cipher
Takuma Koyama, Lei Wang 0031, Yu Sasaki 0001, Kazuo Sakiyama, Kazuo Ohta
ISPEC2
2012 Meet-in-the-Middle Technique for Integral Attacks against Feistel Ciphers
Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography2
2011 (Second) Preimage Attacks on Step-Reduced RIPEMD/RIPEMD-128 with a New Local-Collision Approach
Lei Wang 0031, Yu Sasaki 0001, Wataru Komatsubara, Kazuo Ohta, Kazuo Sakiyama
CT-RSA1
2011 Security of Practical Cryptosystems Using Merkle-Damgård Hash Function in the Ideal Cipher Model
Yusuke Naito 0001, Kazuki Yoneyama, Lei Wang 0031, Kazuo Ohta
ProvSec3
2010 Non-full-active Super-Sbox Analysis: Applications to ECHO and Grøstl
Yu Sasaki 0001, Yang Li 0001, Lei Wang 0031, Kazuo Sakiyama, Kazuo Ohta
ASIACRYPT3
2010 Finding Preimages of Tiger Up to 23 Steps
Lei Wang 0031, Yu Sasaki 0001
FSE1
2009 Preimages for Step-Reduced SHA-2
Kazumaro Aoki, Jian Guo 0001, Krystian Matusiewicz, Yu Sasaki 0001, Lei Wang 0031
ASIACRYPT5
2009 How to Confirm Cryptosystems Security: The Original Merkle-Damgård Is Still Alive!
Yusuke Naito 0001, Kazuki Yoneyama, Lei Wang 0031, Kazuo Ohta
ASIACRYPT3
2008 Security of MD5 Challenge and Response: Extension of APOP Password Recovery Attack
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro
CT-RSA2
2008 New Key-Recovery Attacks on HMAC/NMAC-MD4 and NMAC-MD5
Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro
EUROCRYPT1
2007 New Message Difference for MD4
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro
FSE2