EDBT 2026 Demo / reviewers in the wild / expert
Bin Hu 0011
dblp:00/6381-11
· DBLP profile ↗
29ranked-venue papers
0as first author
23since 2021 · last 2026
0000-0002-8294-1538ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 14 since 2021Theory of computation · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improved search models of boomerang distinguishers and application to LILLIPUTabstractAbstract Boomerang attack serves as a potent cryptanalytic tool for assessing the security of block ciphers. Over the past few years, various automatic search models for boomerang distinguishers have been proposed for block ciphers with different structures. This paper presents improved Mixed-Integer Linear Programming (MILP)-based search models for both single-key and related-key boomerang distinguishers. In the single-key scenario, we propose a method for dynamic allocation of active S-boxes. Our search model for single-key boomerang distinguishers characterizes the distinguisher probability more accurately, addressing the suboptimality issue caused by non-fixed weight assignments in prior models. In the related-key scenario, a search model for related-key boomerang distinguisher is proposed for block ciphers with bit-level key schedule algorithms, where the probability of the boomerang switch is ensured to be 1. To validate the effectiveness of our models, we apply them to the lightweight block cipher LILLIPUT based on Extended Generalized Feistel Networks (EGFN), conducting a comprehensive security analysis against boomerang attacks. Using our models, we successfully derive single-key boomerang distinguishers for 8 to 13 rounds and a 15-round related-key boomerang distinguisher. Notably, the data complexity required for 13-round single-key distinguishing attack is reduced by $${2^{ 3.172}}$$ 2 3.172 , and the 15-round related-key boomerang distinguisher with a probability of $${2^{ - 58}}$$ 2 - 58 is currently the longest-round distinguisher among all known distinguishers for LILLIPUT. The application results fully demonstrate the capability of our models in evaluating the security of block ciphers. This research not only provides new insights and methods for the design and analysis of lightweight block ciphers, but also deepens the understanding of the security characteristics for LILLIPUT. Yunong Wu, Zongsheng Zhang, Tairong Shi, Bin Hu 0011, Kai Zhang 0026, Senpeng Wang |
Cybersecur. | 5 |
| 2026 | An improved automatic framework for searching for differential-linear distinguishers with applications to SPN and Feistel block ciphers
Lin Jiao, Senpeng Wang, Yunong Wu, Bin Hu 0011, Tairong Shi, Kai Zhang 0026 |
Des. Codes Cryptogr. | 5 |
| 2026 | Enhanced Differential-Linear Cryptanalysis of ChaCha Based on Bit Puncturing
Lin Ding 0001, Zhengting Li, Jiang Wan, Bin Hu 0011 |
IEEE Internet Things J. | 6 |
| 2026 | Fully adaptive MA-ABE supporting multi-fan-in circuitsabstractAs a distributed extension of ciphertext-policy attribute-based encryption (CP-ABE), multi-authority ABE (MA-ABE) does not require the participation of a trusted central authority and has a wider application prospect in the decentralized background of the cloud computing environment. We propose the first MA-ABE scheme supporting multi-fan-in circuits and collusion-resistance on prime-order bilinear groups and prove the fully adaptive security based on the matrix decision Diffie-Hellman (MDDH) assumption. Compared with the only two fully adaptively secure MA-ABE schemes, our scheme enjoys shorter parameters, which has lower ciphertext and key size, and supports many-use of attribute. Keshuo Sun, Haiying Gao, Bin Hu 0011, Xiufeng Zhao, Aoyang Zhou |
J. Comput. Secur. | 3 |
| 2025 | Improved method of searching for boomerang distinguishers on Feistel structures-applications to WARP, TWINE, LBlock, LBlock-s, and ALLPC
Senpeng Wang, Yunong Wu, Bin Hu 0011 |
Des. Codes Cryptogr. | 4 |
| 2025 | HP-CP-ABE scheme against collusion attacks under an attribute-key security modelabstractAttribute-based encryption (ABE) is crucial for ciphertext access control in cloud settings. In this paper, we evaluate the resilience of classical ABE schemes to specific attacks, ensuring only robust schemes are employed and informing the design of secure ABE schemes. We demonstrate an attribute-key attack on two ciphertext-policy ABE (CP-ABE) schemes using illegitimate private keys. To quantify the security of private keys against collusion, we propose a novel attribute-key security model. At last, we present a hidden-policy CP-ABE (HP-CP-ABE) scheme, proving its selective security and resistance to collusion attacks. Keshuo Sun, Haiying Gao, Chao Ma 0016, Bin Hu 0011, Xiufeng Zhao |
Int. J. Inf. Comput. Secur. | 4 |
| 2024 | A Break Of Barrier To Classical Differential Fault Attack On The Nonce-Based Authenticated Encryption AlgorithmabstractAbstract It had always been believed that there was an inherent barrier to Differential Fault Attack (DFA) on the nonce-based authenticated encryption algorithm. At CHES 2016, Saha et al. proposed an Internal Differential Fault Attack on a parallelizable counter-mode algorithm. They induce the attack to classical DFA at the expense of one more fault injection in every encryption process. In this paper, we propose the DFA on HYENA, which is a nonce-based authenticated encryption mode for GIFT-128. Our work is the first pure classical DFA on a nonce-based authenticated encryption algorithm with only one fault injected in every decryption process. Firstly, we give the DFA on GIFT-128 with a fault injected into the 39th-round input. Based on this work, we inject a fault in the underlying GIFT-128 of a HYENA decryption process and make this decryption process still generate the correct tag and output plaintext. This makes the necessary conditions of DFA satisfied. Experiments show that at most 56 key bits of HYENA can be recovered with only a few faulty ciphertexts. In addition, our fault injection is easier to achieve than most other work about fault attack, because the injection location is relatively random and the fault type can be arbitrary. It should be noted that the left 72 key bits cannot be recovered in this way. Jizhou Ren, Jie Guan, Bin Hu 0011, Sudong Ma |
Comput. J. | 4 |
| 2024 | Automated Differential-Linear Cryptanalysis for AND-RX CiphersabstractDifferential and linear cryptanalysis are two important methods to evaluate the security of block ciphers. Building on these two methods, differential‐linear (DL) cryptanalysis was introduced by Langford and Hellman in 1994. This cryptanalytic method has been not only extensively researched but also proven to be effective. In this paper, a security evaluation framework for AND‐RX ciphers against DL cryptanalysis is proposed, which is denoted as . In addition to modeling the structure of all the possible differential trails and linear trails at the bit level, we introduce a method to calculate this structure round by round. Based on this approach, an automatic algorithm is proposed to construct the DL distinguisher. Unlike previous methods, uses a truncated differential and a linear hull instead of a differential characteristic and a linear approximation, which brings the bias of the DL distinguisher close to the experimental value. To validate the effectiveness of the framework, is applied to Simon and Simeck, which are two typical AND‐RX ciphers. With the automatic algorithm, we discover an 11‐round DL distinguisher of Simon32 with bias 2 −14.89 and a 12‐round DL distinguisher of Simeck32 with bias 2 −14.89 . Moreover, the 14‐round DL distinguisher of Simon48 with bias 2 −22.30 is longer than the longest DL distinguisher currently known. In addition, the framework shows advantages when analyzing ciphers with large block sizes. As far as we know, for Simon64/96/128 and Simeck48/64, the first DL distinguishers are obtained with our framework. The DL distinguishers are 16, 23, 32, 17, and 22 rounds of Simon64/96/128 and Simeck48/64 with bias 2 −24.31 , 2 −47.57 , 2 −60.75 , 2 −22.54 , and 2 −31.41 , respectively. To prove the correctness of distinguishers, experiments on Simon32 and Simeck32 have been performed. The experimental bias are 2 −13.76 and 2 −14.82 , respectively. Comparisons of the theoretical and experimental results show good agreement. Kai Zhang 0026, Bin Hu 0011 |
IET Inf. Secur. | 3 |
| 2024 | MILP/MIQCP-Based Fully Automatic Method of Searching for Differential-Linear Distinguishers for SIMON-Like CiphersabstractDifferential‐linear (DL) cryptanalysis is an important cryptanalytic method in cryptography and has received extensive attention from the cryptography community since its proposal by Langford and Hellman in 1994. At CT‐RSA 2023, Bellini et al. introduced continuous difference propagations of XOR, rotation, and modulo‐addition operations and proposed a fully automatic method using Mixed‐Integer Linear Programing (MILP) and Mixed‐Integer Quadratic Constraint Programing (MIQCP) techniques to search for DL distinguishers of Addition‐Rotation‐XOR (ARX) ciphers. In this paper, we propose continuous difference propagation of AND operation and construct an MILP/MIQCP‐based fully automatic model of searching for DL distinguishers of SIMON‐like ciphers. We apply the fully automatic model to all versions of SIMON and SIMECK. As a result, for SIMON, we find 13 and 14‐round DL distinguishers of SIMON32, 15, 16, and 17‐round DL distinguishers of SIMON48, 20‐round DL distinguishers of SIMON64, 25 and 26‐round DL distinguishers of SIMON96, 31 and 32‐round DL distinguishers of SIMON128. For SIMECK, we find 14‐round DL distinguishers of SIMECK32, 17 and 18‐round DL distinguishers of SIMECK48, 22, 23, 24, and 25‐round DL distinguishers of SIMECK64. As far as we know, our results are currently the best. Senpeng Wang, Bin Hu 0011 |
IET Inf. Secur. | 3 |
| 2024 | Ciphertext policy attribute-based encryption scheme supporting Boolean circuits over ideal lattices
Chao Ma 0016, Haiying Gao, Bin Hu 0011 |
J. Inf. Secur. Appl. | 3 |
| 2024 | Real-Time Related-Key Attack on Full-Round Shadow Designed for IoT NodesabstractWith the rapid development of the Internet of Things (IoT), many new lightweight block ciphers are designed in recent years to meet the security demand in IoT devices. Shadow is a lightweight block cipher designed for IoT Nodes (IEEE Internet of Things Journal, 2021). In this article, an efficient attack on full-round Shadow is proposed based on the idea of a related-key differential attack. First, a differential transfer property for AND operation is illustrated. This property demonstrates a link between the difference and the input value. If the difference of the input is not zero, to lead to a zero difference, there are some constraints on the input value. Furthermore, two properties for Shadow family ciphers are identified. According to these properties, some related keys on Shadow will lead to an internal collision for the subkey generator, which will eventually lead to a full-round distinguisher. Finally, with the idea of related-key differential attack, an efficient attack is applied to Shadow. For Shadow-32, with 4 related keys, 8 master key bits can be derived in about 0.044 seconds on average. For Shadow-64, with 4 related keys, 24 master key bits can be derived in about 3.9 hours on average. All our theoretical results are verified by experiments. Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
IEEE Trans. Computers | 5 |
| 2024 | Dedicated Quantum Attacks on XOR-Type Function With Applications to Beyond-Birthday- Bound MACsabstractA lot of work in the field of quantum cryptanalysis is currently devoted to finding applications of Grover-meets-Simon algorithm and its complexity is given in the form of$\mathcal {O}$, but research on how to implement the attack efficiently is still insufficient. After all, it is crucial to study quantum attacks in resource-limited situations, according to NIST’s guidance on circuit depth. This work first evaluates the parallelization of Grover-meets-Simon by drawing on the Grover’s parallel approach and shows that as the width increases by$2^{t}(t\gt 0)$, the depth decreases by a factor of$\sqrt {2^{t}}$. Further, the first dedicated quantum attack on a class of functions that appear in cryptographic scheme applications (so-called XOR-type function) is proposed. The depth, width, and the number of gates required for the attack are greatly reduced compared to the general parallelization. Then we apply the attack to various Beyond-Birthday-Bound (BBB) MACs, where the XOR function can be constructed, includingSUM-ECBCand its variants (2K-SUM-ECBC,2K-ECBC_Plus), andGCM-SIV2. In the typical case whereSUM-ECBCis based on AES-128, our attack saves at least 62.3% in depth, 19.5% in width and 22.2% in gate count simultaneously. The impact on some lightweight ciphers is further explored, and it is interesting to note that the lighter the quantum circuit implementation of the cipher is, the greater the possible impact of an attack will be. This observation may provide new insights into quantum cryptanalysis. Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Han Sui, Senpeng Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | New Methods for Bounding the Length of Impossible Differentials of SPN Block CiphersabstractHow to evaluate the security of Substitution-Permutation Network (SPN) block ciphers against impossible differential (ID) cryptanalysis is a valuable problem. In this paper, a series of methods for bounding the length of IDs of SPN block ciphers are proposed. Firstly, we propose the definitions of minimal representative set and partition table. Therefore, an improved partition-first implementation strategy for bounding the length of IDs is given. Secondly, we introduce a new definition of ladder and propose the ladder-first implementation strategy for bounding the length of IDs. In order to be able to apply ladder-first implementation strategy in practice, the methods for determining ladders and integrating a ladder into searching models are given. Thirdly, a heuristic algorithm called dynamic-ladder-partition implementation strategy is proposed. According to our experimental results, dynamic-ladder-partition implementation strategy is more suitable for SPN ciphers whose number of elements in partition tables is little. Fourthly, rotation-equivalence ID sets of ciphers are explored to reduce the number of models that need to be considered. As applications, we show that 9-round PRESENT, 5-round AES, 6-round Rijndael-160, 7-round Rijndael-192, 7-round Rijndael-224 and 7-round Rijndael-256 do not have any ID under the sole assumption that the round keys are uniformly random. What’s more, we obtain that 8-round GIFT-64, 12-round GIFT-128 and 14-round SKINNY-128 do not have any ID under the assumptions that GIFT and SKINNY are Markov ciphers and the round keys are uniformly random. Our methods fill crucial gaps on bounding the length of IDs with the differential properties of S-boxes considered. They enhance our confidence in the security and are valuable, especially for designers. Senpeng Wang, Dengguo Feng, Tairong Shi, Bin Hu 0011, Jie Guan, Kai Zhang 0026, Ting Cui |
IEEE Trans. Inf. Theory | 4 |
| 2024 | Impossible Differential Cryptanalysis and a Security Evaluation Framework for AND-RX CiphersabstractIn this paper, a security evaluation framework for AND-RX ciphers against impossible differential cryptanalysis is proposed. This framework is constructed based on three different methods towards finding the theoretical upper boundary, theoretical lower boundary, and practical boundary of impossible differential distinguishers (short for ID) respectively. The provable security boundary (upper boundary) can be calculated with two round-function-related matrices through a few matrix multiplications, this calculation is beyond actual input and output differences. For searching longer IDs (lower boundary), an automatic method is proposed. With this method, given the input and output difference, all the possible direct and indirect contradictions are detected. For the practical boundary, a method of approximating all the potential longest IDs with concrete differential trails is introduced. The three boundaries validate the correctness from each other. According to our result, on the one hand, the boundaries derived with well-designed ID-construction methods can already reach the practical boundary for some block ciphers and it is unlikely to be improved based on known construction methods or future unknown construction methods. On the other hand, for those ciphers whose current best result does not reach our boundary, longer IDs can be discovered with this framework. The correctness is validated by a series of applications. For the provable security boundary, four family ciphers-SIMON, Simeck, Friet-PC and SAND are investigated. For SIMON and Simeck, the lengths of current longest IDs have reached their provable security boundaries. For Friet-PC and SAND, there is a gap between the provable security boundary and current best results. With the automatic searching method, some longer IDs on Friet-PC and SAND are discovered. For Friet-PC, 128 11-round IDs are discovered, while the previous best differential distinguisher is 9-round. For SAND64, 256 11-round IDs are proposed. For SAND128, 456 14-round IDs are presented. Both results extend previous longest IDs by one round and all these newly proposed distinguishers reached corresponding provable security boundaries. For Simeck, the length of longest IDs has not been improved. However, more distinguishers of the same length are discovered. For Simeck64, the increased ratio for the quantity can reach 300%. Besides, the practical boundary of SIMON is investigated, the results indicate that for SIMON, the practical boundary is identical with the provable security boundary or the boundary derived with the automatic searching method. Kai Zhang 0026, Senpeng Wang, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Tairong Shi |
IEEE Trans. Inf. Theory | 6 |
| 2024 | A Boolean circuit-based revocable ciphertext policy attribute-based encryption scheme
Chao Ma 0016, Haiying Gao, Bin Hu 0011 |
J. Supercomput. | 3 |
| 2023 | A revisited security evaluation of Simeck family ciphers against impossible differential cryptanalysis
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011 |
Sci. China Inf. Sci. | 5 |
| 2023 | New method for combining Matsui's bounding conditions with sequential encoding method
Senpeng Wang, Dengguo Feng, Bin Hu 0011, Jie Guan, Kai Zhang 0026, Tairong Shi |
Des. Codes Cryptogr. | 3 |
| 2023 | Weak rotational property and its application
Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011 |
Des. Codes Cryptogr. | 4 |
| 2023 | Meet-in-the-middle attack with splice-and-cut technique and a general automatic framework
Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
Des. Codes Cryptogr. | 5 |
| 2023 | Selecting Rotation Constants on SIMON-Type CiphersabstractIn 2013, a lightweight block cipher SIMON is proposed by NSA. This paper tries to investigate this design criterion in terms of resisting against impossible differential cryptanalysis. On one hand, starting from all the possible rotation constants, this paper sieves those “bad parameters” step by step, for each step, the regular patterns for those “bad parameters” are deduced. Accordingly, basic rules for selecting rotation constants on SIMON-type ciphers to construct shorter longest impossible differentials are proposed. On the other hand, the authors categorize the optimal parameters proposed in CRYPTO 2015, according to these results, some “good parameters” in terms of differential cryptanalysis may be rather “bad parameters” while considering impossible differential cryptanalysis. Finally, a concrete attack on 26-round SIMON(13,0,10) is proposed, which is a suggested SIMON variant in CRYPTO 2015 against differential cryptanalysis and linear cryptanalysis. The result in this paper indicates that it is very important to choose appropriate rotation constants when designing a new block cipher. Kai Zhang 0026, Xuejia Lai, Jie Guan, Bin Hu 0011 |
J. Database Manag. | 4 |
| 2023 | Rotational-XOR Differential Cryptanalysis and an Automatic Framework for AND-RX CiphersabstractIn this paper, a security evaluation framework for AND-RX ciphers against rotational-XOR differential cryptanalysis is proposed. This framework first models the structure of all the possible rotational-XOR differential (abbreviated to “RXD”) trails and introduces a method to calculate this structure round by round. Based on this approach, an automatic method is proposed for searching RXD trails. In this method, four strategies are proposed to derive better result and improve the efficiency. Unlike previous automations, the time complexity for this framework can be pre-computed, which is bounded by${\mathcal{ O}}\left ({{c\cdot n\cdot R^{2}\cdot C_{n}^{n_{1}}} }\right)$(where$n$is the block size,$n_{1}$is the number of active bits for the starting point of automatic method,$R$is the length of the targeted rounds and$c$is a fixed constant). Under the given strategies and searching subspaces, the derived RXD trails are guaranteed to be optimal. To prove the correctness and efficiency, this framework is applied to all the ten variants for SIMON and three variants for Simeck. When compared with previous RXD trails, the best improvement is up to three rounds. To validate the correctness of the derived rotational-XOR differential trails, a concrete experiment on Simeck32 is conducted and the experimental result complies with the theoretical analysis. As far as we know, for all the variants of Simeck, current longest distinguishers over all the cryptanalytic methods are obtained in this paper. Kai Zhang 0026, Xuejia Lai, Lei Wang 0031, Jie Guan, Bin Hu 0011, Senpeng Wang, Tairong Shi |
IEEE Trans. Inf. Theory | 5 |
| 2022 | Fault attacks on authenticated encryption modes for GIFTabstractAbstract There are several authenticated encryption modes for block cipher GIFT in the NIST lightweight cryptography standardisation process. In this study, the authors research on the fault attacks on this kind of authenticated encryption modes and mainly complete two tasks. First, the fault attack on the nonce‐based authenticated encryption mode LOTUS/LOCUS is presented. At Asiacrypt2016, Dobraunig et al. showed the first fault attacks on several nonce‐based authenticated encryption modes. Because LOTUS/LOCUS adopts the structure similar to XEX with secret nonce‐dependent masks, their work is not applicable to LOTUS/LOCUS. A new fault attack is launched on LOTUS/LOCUS assuming that two bits can be made to reset in the fixed location during the encryption process. In this attack, neither plaintext nor ciphertext of the underlying block cipher is necessary to be known. To recover the correct key, a few hundred faulty ciphertexts are needed when transient faults are injected, while just one faulty ciphertext is sufficient for a permanent fault. Second, the Collision Fault Attack on GIFT is shown, in which 64 faulty ciphertexts are needed to recover the correct key. Based on this attack, authenticated encryption modes ESTATE_TweGIFT‐128, GIFT‐COFB and SUNDAE‐GIFT are analysed and their keys are efficiently obtained with chosen nonce. Jie Guan, Bin Hu 0011 |
IET Inf. Secur. | 3 |
| 2021 | Breaking LWC candidates: sESTATE and Elephant in quantum setting
Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Senpeng Wang |
Des. Codes Cryptogr. | 3 |
| 2020 | On the Structure Property of PCR's Adjacency Graph with a Prime Order and Its Application of Constructing M-Sequences
Congwei Zhou, Jie Guan, Bin Hu 0011, Kuan He |
Inscrypt | 3 |
| 2019 | MILP-aided Method of Searching Division Property Using Three Subsets and Applications
Senpeng Wang, Bin Hu 0011, Jie Guan, Kai Zhang 0026, Tairong Shi |
ASIACRYPT (3) | 2 |
| 2018 | The autocorrelation properties of single cycle polynomial T-functions
Senpeng Wang, Bin Hu 0011 |
Des. Codes Cryptogr. | 2 |
| 2018 | Security evaluation on Simeck against zero-correlation linear cryptanalysisabstractSince proposed by the National Security Agency in June 2013, two lightweight block ciphers‐SIMON and SPECK have attracted the attention of cryptographers from all over the world. At CHES 2015, Simeck, a new block cipher inspired from both SIMON and SPECK is proposed, which is more compact and efficient. However, the security evaluation on Simeck against zero‐correlation linear cryptanalysis seems missing from the specification. The main focus of this study is to fill this gap and evaluate the security level of Simeck against zero‐correlation linear cryptanalysis. According to the authors' study, 11‐, 13‐ and 15‐round zero‐correlation linear distinguishers on Simeck32/48/64 are proposed, respectively, then zero‐correlation linear cryptanalysis on 21‐, 24‐, 28‐round Simeck32/48/64 are first proposed. As far as they know, for Simeck32, their result is the best result up to date. Kai Zhang 0026, Jie Guan, Bin Hu 0011, Dongdai Lin |
IET Inf. Secur. | 3 |
| 2018 | Privacy Protection of IoT Based on Fully Homomorphic EncryptionabstractWith the rapid development of Internet of Things (IoT), grave questions of privacy protection are raised. This greatly impacts the large‐scale applications of IoT. Fully homomorphic encryption (FHE) can provide privacy protection for IoT. But, its efficiency needs to be greatly improved. Nowadays, Gentry’s bootstrapping technique is still the only known method of obtaining a “pure” FHE scheme. And it is also the key for the low efficiency of FHE scheme due to the complexity homomorphic decryption. In this paper, the bootstrapping technique of Halevi and Shoup (EUROCRYPT 15) is improved. Firstly, by introducing a definition of “load capacity”, we optimize the parameter range for which their bootstrapping technique works. Next we generalize their ciphertext modulus from closing to a power of two to more general situations. This enables the method to be applied in a larger number of situations. Moreover, this paper also shows how to introduce SIMD homomorphic computation techniques into the new method, to improve the efficiency of recryption. Bin Hu 0011, Xiufeng Zhao |
Wirel. Commun. Mob. Comput. | 2 |
| 2016 | Some properties of impossible differential and zero correlation linear cryptanalysis on TEA family-type ciphersabstractAbstract In lightweight cryptographic primitives, round functions with simple operations XOR, modular addition, and shift (or rotation) are widely used nowadays. Among these ciphers, TEA and XTEA are two famous lightweight block ciphers. At AFRICACRYPT 2012, Jiazhe Chen, Meiqin Wang, and Bart Preneel proposed a method to establish impossible differential distinguishers for TEA and XTEA. At FSE 2012, with similar approach, Andrey Bogdanov and Meiqin Wang identified zero correlation linear distinguishers for TEA and XTEA. We find similarities in these two kinds of distinguishers and then probe into the deeper relationship between them. In this paper, we extend the TEA and XTEA to a more general TEA family‐type ciphers and study the impossible differential distinguishers and zero correlation linear distinguishers for this kind of ciphers. More specifically, with the methods proposed in these two references earlier, firstly, we prove the longest lengths for impossible differential distinguishers and zero correlation linear distinguishers on TEA family‐type ciphers. Secondly, the number of longest impossible differential distinguishers and zero correlation linear distinguishers are calculated respectively. Then, the specific forms of their input and output differences (or linear masks) are given. Thirdly, a dual property is proposed to demonstrate the deeper relationship between these two kinds of distinguishers. Finally, we give some suggestions for algorithm designers on how to shorten these two kinds of distinguishers for TEA family‐type ciphers. Copyright © 2017 John Wiley & Sons, Ltd. Kai Zhang 0026, Jie Guan, Bin Hu 0011 |
Secur. Commun. Networks | 3 |