Zhu Wang 0005

dblp:03/6588-5 · DBLP profile ↗
← Back
17ranked-venue papers
0as first author
8since 2021 · last 2026
0000-0003-2193-0015ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Securing Storage Instructions: A Hamming Weight Balancing Approach to Prevent Secret Leaks Through Side Channels
abstract
Cryptographic devices are sensitive to side-channel attacks, which inevitably leak electromagnetic radiation, power consumption, time, and other physical information during execution. The side-channel storage vulnerability caused by storage instructions has become one of the main targets for attackers, posing a serious threat to the implementation security of cryptographic algorithms. In this paper, following revealing the essence of the side-channel storage vulnerability at the computer architecture level, two novel technologies, by reducing the correlation between the processed data and emissions, are proposed to defend such attacks, namely the randomizing Hamming weight scheme and the balancing Hamming weight scheme. Furthermore, we apply the proposed scheme to AES and CRYSTALS-Kyber on the Cortex-M4 CPU. The experimental results show that this strategy can effectively eliminate the side-channel storage vulnerability at a low cost of time and space, thereby ensuring the secure implementation of cryptographic algorithms.
Jianfeng Du, Zhu Wang 0005
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2025 Bit-By-Bit Total Collapse: A Novel Side-Channel Attack on HQC-128 Decapsulation
Zhu Wang 0005, Jianfeng Du
Inscrypt (1)2
2025 Revisiting the Masking Strategy: A Side-Channel Attack on CRYSTALS-Kyber
abstract
As the sole NIST-standardized quantum-resistant key encapsulation mechanism, CRYSTALS-Kyber demands rigorous scrutiny of its side-channel countermeasures. However, there is a lack of research on side-channel security for the message decoding module in masked CRYSTALS-Kyber. In this paper, we seek to address this gap. First, we conduct a side-channel security evaluation of the first-order masked message decoding function in mkm4 of CRYSTALS-Kyber, finding that an incremental storage vulnerability still exists. Then, we implement a practical experiment in the Cortex-M4 CPU using the sum-of-squared difference method, with the accuracy of the message recovery reaching 90.6% and the secret key recovery achieving 77.2%. Furthermore, we theoretically analyze that any order of masking strategy cannot effectively protect the message decoding function, except by increasing the attack difficulty to a limited extent. We also provide our idea for solving this problem by emulating the data behavior of the dual-rail pre-charge logic circuit at the software level, which can effectively ensure the implementation security of CRYSTALS-Kyber.
Jianfeng Du, Zhu Wang 0005
IEEE Trans. Inf. Forensics Secur.2
2025 The Mysteries of LRA: Roots and Progress in Side-Channel Applications
abstract
Evaluating cryptographic implementations with respect to side-channel analysis (SCA) has been mandated at high security levels. Typically, the evaluation involves four stages: detection, modeling, certification and recovery. In pursuit of a specific goal at each stage, inherently different techniques were previously considered necessary. However, since the recent Eurocrypt 2022 and Eurocrypt 2024, linear regression analysis (LRA) has become the unique technique well-applied throughout all the stages. In this paper, we concentrate on this “silver bullet” technique within the field of SCA. In the first part of this paper, we answer three fundamental questions organized progressively. The first one relates to “why use LRA?”. Our discussion of the nominal and binary nature elucidates its critical role in underpinning the state-of-the-art techniques. Having understood the merits, a natural follow-up is “how to use it (correctly and effectively)?”. A theoretical analysis of the design matrix is provided, regarding the sample distribution of plaintext and the chosen degree of polynomial. We summarize the conditions for eliminating multicollinearity, a problem that can be harmful to all LRA-based techniques. The last question “who should use LRA?” reveals an intriguing evaluator-advantageous property: LRA can only unleash its full potential when the key is known. In the second part of this paper, we clarify the connections between LRA and traditional SCA techniques. Our proofs provide new insights into the prior investigation of SCA reduction, fostering a comprehensive understanding of this linear family. The conclusions suggest that the core working mechanisms of the state-of-the-art techniques can be traced back to those of earlier differential side-channel analyses. Experimental results are in line with the theory, confirming its correctness in practice.
Jiangshan Long, Changhai Ou, Yukun Cheng, Tingting Wang 0010, Zhu Wang 0005, Fan Zhang 0010
IEEE Trans. Inf. Forensics Secur.5
2024 When Is Multi-channel Better Than Single-Channel: A Case Study of Product-Based Multi-channel Fusion Attacks
Shilong You, Jianfeng Du, Zhu Wang 0005
Inscrypt (1)3
2024 Missing Data Completion for Network Traffic with Continuous Mutation Based on Tensor Ring Decomposition
abstract
The completion of missing network traffic is of great significance for network operation and maintenance. In recent years, the low-rank tensor completion (LRTC) techniques based on tensor ring (TR) decomposition have attracted much attention. In general, the LRTC model requires the stability of the whole tensor space. However, continuous mutation of network traffic is very common in real networks. At this time, existing completion work has difficulty in capturing the global low-rank feature of normal data and ignores the local continuous feature of mutation data, leading to a decrease in completion performance. To solve the above problems, we propose a low-rank tensor completion model that can adapt to various continuous mutation patterns of network traffic. The original tensor is represented as the sum of a normal tensor and a mutation tensor to extract their features respectively. Then, an algorithm based on the alternating direction method of multipliers (ADMM) is developed to solve the proposed model. Finally, our experimental results on both synthetic and real datasets indicate that our model can adapt to various missing data completion under different continuous mutation patterns, and has more accurate completion performance compared to advanced models.
Fanfan Hao, Zhu Wang 0005, Yaobing Xu, Siyuan Leng, Liang Fang 0009, Fenghua Li 0001
CSCWD2
2024 What Is Now Possible? Security Evaluation on Univariate DPA Attacks With Inaccurate Leakage Models
abstract
Success Rate (SR) is one of the most popular side-channel security metrics measuring the efficiency of key recovery. Theoretical expression of success rate reveals the functional dependency between relevant parameters such as number of measurements and Signal-to-Noise Ratio (SNR), helping researchers understand the resistance of a given implementation rapidly. However so far, existing works have exposed fundamental problems: (1) Evaluation is confined to a very limited range of distinguishers and specialized methods; (2) Evaluation assumes a perfect leakage model that is detached from reality. It is widely observed that an inaccurate leakage model will lead to a degraded or even distorted success rate. In this paper, we tackle above problems by introducing a novel framework which is able to evaluate seven side-channel distinguishers with a unified expression. Among them, we explore four new distinguishers that have not been investigated in the existing literature. Within the framework, DPA distinguishers are intuitively understood as linear maximum likelihood attack testing closeness between vectors with some easy-to-comprehend geometric metrics. Our evaluation is able to deal with profiled models of any quality and is agnostic to model profiling techniques. It uniquely enables the evaluation of success rates under inaccurate leakage models, whilst providing an (indirect) answer to the open question “how much information is lost due to the model biases” through quantifying the degradation of success rates. Finally, we formulate a set of criterion values for quantitative analyses of the model biases. It provides theoretical evidences for a more thorough explanation for the various behaviors of DPA attacks. Experimental results are inline with the theory, confirming its practical applicability.
Jiangshan Long, Changhai Ou, Zhu Wang 0005, Yongbin Zhou
IEEE Trans. Inf. Forensics Secur.4
2022 Message Recovery Attack of Kyber Based on Information Leakage in Decoding Operation
Mengyao Shi, Zhu Wang 0005, Tingting Peng, Fenghua Li 0001
SecureComm2
2019 Group Collision Attack
abstract
Key enumeration schemes are used to post-process the scores given by side channel distinguishers and enumerate the key candidates from the most possible one to the least possible one, which can be regarded as optimal tools of key search. However, the application of them is limited by very large key candidate space and computing power consumption. For example, the attacker may spend several weeks or months enumerating the whole 245key candidates. Unlike the former literature that try to propose a more efficient algorithm to process the distinguishers, scores of key candidates directly, we focus on pre-processing and reducing the key candidate space. To achieve this goal, a new divide and conquer strategy named group collision attack (GCA) is proposed in this paper. The GCA works as follows in brief. The key candidates are first divided into groups on which intra-group collision attack is used to remove the impossible key combinations in each group. Then, the inter-group collision attack is performed to further remove the impossible key combinations between groups. Thus, the complexity of key enumeration is reduced significantly. A series of practical experiments are carried out by using our GCA and the experimental results verify its efficiency.
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou
IEEE Trans. Inf. Forensics Secur.2
2017 A Novel Use of Kernel Discriminant Analysis as a Higher-Order Side-Channel Distinguisher
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005
CARDIS5
2017 Categorising and Comparing Cluster-Based DPA Distinguishers
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005
SAC5
2016 Error Tolerance based Single Interesting Point Side Channel CPA Distinguisher
abstract
The efficiency can be significantly improved if the attacker uses interesting points to perform Correlation Power Analysis (CPA). The prerequisite for this is that the attacker knows the positions of interesting points. However, it is difficult for the attacker to accurately find the locations of interesting points if he only has a small number of power traces. In this paper, we propose a Frequency based Interesting Points Selection algorithm (FIPS) to select interesting points under the condition that the attacker only has a very small number of power traces. Moreover, an error tolerant Single Interesting Point based CPA (SIP-CPA) is proposed. Experiments on AES algorithm implemented on an AT89S52 single chip and power trace set of DPA contest v1 of DES algorithm implemented on the Side Channel Attack Standard Evaluation Board (SASEBO) show that, our SIP-CPA can significantly improve the efficiency of CPA.
Changhai Ou, Zhu Wang 0005, Juan Ai, Xinping Zhou, Degang Sun, Victor E. DeBrunner
AsiaCCS2
2016 Group Verification Based Multiple-Differential Collision Attack
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai
ICICS2
2016 Enhanced Correlation Power Analysis by Biasing Power Traces
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai, Na Pang
ISC2
2016 Uncertain? No, It's Very Certain! - Recovering the Key from Guessing Entropy Enhanced CPA
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai
SEC2
2016 POSTER: A Novel Wavelet Denoising Method Based on Robust Principal Component Analysis in Side Channel Attacks
Juan Ai, Zhu Wang 0005, Xinping Zhou, Changhai Ou
SecureComm2
2015 POSTER: Using Improved Singular Value Decomposition to Enhance Correlation Power Analysis
Degang Sun, Xinping Zhou, Zhu Wang 0005, Changhai Ou, Wei-qing Huang, Juan Ai
SecureComm3