Alex Biryukov

dblp:09/5071 · DBLP profile ↗
← Back
85ranked-venue papers
68as first author
10since 2021 · last 2026
0000-0003-1404-6686ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 81 · 65 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorTheory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination Framework
Alex Biryukov, Pablo García Fernández, Aleksei Udovenko
EUROCRYPT1
2026 Algorithmic Toolkit for Linearization of S-Boxes
Alex Biryukov, Philip Turecek, Aleksei Udovenko
EUROCRYPT1
2024 Cryptanalysis of Algebraic Verifiable Delay Functions
Alex Biryukov, Ben Fisch, Gottfried Herold, Dmitry Khovratovich, Gaëtan Leurent, María Naya-Plasencia, Benjamin Wesolowski
CRYPTO (3)1
2023 Meet-in-the-Filter and Dynamic Counting with Applications to Speck
Alex Biryukov, Luan Cardoso dos Santos, Je Sen Teh, Aleksei Udovenko, Vesselin Velichkov
ACNS (1)1
2022 Dynamic Universal Accumulator with Batch Update over Bilinear Groups
Giuseppe Vitto, Alex Biryukov
CT-RSA2
2022 Advancing the Meet-in-the-Filter Technique: Applications to CHAM and KATAN
Alex Biryukov, Je Sen Teh, Aleksei Udovenko
SAC1
2022 Differential cryptanalysis of WARP
Je Sen Teh, Alex Biryukov
J. Inf. Secur. Appl.2
2021 Cryptanalysis of a Dynamic Universal Accumulator over Bilinear Groups
Alex Biryukov, Aleksei Udovenko, Giuseppe Vitto
CT-RSA1
2021 Dummy Shuffling Against Algebraic Attacks in White-Box Implementations
Alex Biryukov, Aleksei Udovenko
EUROCRYPT (2)1
2021 Automated Truncation of Differential Trails and Trail Clustering in ARX
Alex Biryukov, Luan Cardoso dos Santos, Daniel Feher, Vesselin Velichkov, Giuseppe Vitto
SAC1
2020 Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001
CRYPTO (3)2
2020 ReCon: Sybil-resistant consensus from reputation
Alex Biryukov, Daniel Feher
Pervasive Mob. Comput.1
2019 FELICS-AEAD: Benchmarking of Lightweight Authenticated Encryption Algorithms
Luan Cardoso dos Santos, Johann Großschädl, Alex Biryukov
CARDIS3
2019 Privacy Aspects and Subliminal Channels in Zcash
abstract
In this paper we analyze two privacy and security issues for the privacy-oriented cryptocurrency Zcash. First we study shielded transactions and show ways to fingerprint user transactions, including active attacks. We introduce two new attacks which we call Danaan-gift attack and Dust attack. Following the recent Sapling update of Zcash protocol we study the interaction between the new and the old zk-SNARK protocols and the effects of their interaction on transaction privacy. In the second part of the paper we check for the presence of subliminal channels in the zk-SNARK protocol and in Pedersen Commitments. We show presence of efficient 70-bit channels which could be used for tagging of shielded transactions which would allow the attacker (malicious transaction verifier) to link transactions issued by a maliciously modified zk-SNARK prover, while would be indistinguishable from regular transactions for the honest verifier/user. We discuss countermeasures against both of these privacy issues.
Alex Biryukov, Daniel Feher, Giuseppe Vitto
CCS1
2019 Deanonymization and Linkability of Cryptocurrency Transactions Based on Network Analysis
abstract
Bitcoin, introduced in 2008 and launched in 2009, is the first digital currency to solve the double spending problem without relying on a trusted third party. Bitcoin provides a way to transact without any trusted intermediary, but its privacy guarantees are questionable. Despite the fact that Bitcoin addresses are not linked to any identity, multiple deanonymization attacks have been proposed. Alternative cryptocurrencies such as Dash, Monero, and Zcash aim to provide stronger privacy by using sophisticated cryptographic techniques to obfuscate transaction data. Previous work in cryptocurrency privacy mostly focused on applying data mining algorithms to the transaction graph extracted from the blockchain. We focus on a less well researched vector for privacy attacks: network analysis. We argue that timings of transaction messages leak information about their origin, which can be exploited by a well connected adversarial node. For the first time, network level attacks on Bitcoin and the three major privacy-focused cryptocurrencies have been examined. We describe the message propagation mechanics and privacy guarantees in Bitcoin, Dash, Monero, and Zcash. We propose a novel technique for linking transactions based on transaction propagation analysis. We also unpack address advertisement messages (ADDR), which under certain assumptions may help in linking transaction clusters to IP addresses of nodes. We implement and evaluate our method, deanonymizing our own transactions in Bitcoin and Zcash with a high level of accuracy. We also show that our technique is applicable to Dash and Monero. We estimate the cost of a full-scale attack on the Bitcoin mainnet at hundreds of US dollars, feasible even for a low budget adversary.
Alex Biryukov, Sergei Tikhomirov
EuroS&P1
2019 Security and privacy of mobile wallet users in Bitcoin, Dash, Monero, and Zcash
Alex Biryukov, Sergei Tikhomirov
Pervasive Mob. Comput.1
2018 Attacks and Countermeasures for White-box Designs
Alex Biryukov, Aleksei Udovenko
ASIACRYPT (2)1
2017 Side-Channel Attacks Meet Secure Network Protocols
Alex Biryukov, Daniel Dinu, Yann Le Corre
ACNS1
2017 Symmetrically and Asymmetrically Hard Cryptography
Alex Biryukov, Léo Perrin
ASIACRYPT (3)1
2017 Optimal First-Order Boolean Masking for Embedded IoT Devices
Alex Biryukov, Daniel Dinu, Yann Le Corre, Aleksei Udovenko
CARDIS1
2016 Correlation Power Analysis of Lightweight Block Ciphers: From Theory to Practice
Alex Biryukov, Daniel Dinu, Johann Großschädl
ACNS1
2016 Design Strategies for ARX with Provable Bounds: Sparx and LAX
abstract
We present, for the first time, a general strategy for designing ARX symmetric-key primitives with provable resistance against single-trail differential and linear cryptanalysis. The latter has been a long standing open problem in the area of ARX design. The wide-trail design strategy (WTS), that is at the basis of many S-box based ciphers, including the AES, is not suitable for ARX designs due to the lack of S-boxes in the latter. In this paper we address the mentioned limitation by proposing the long trail design strategy (LTS) – a dual of the WTS that is applicable (but not limited) to ARX constructions. In contrast to the WTS, that prescribes the use of small and efficient S-boxes at the expense of heavy linear layers with strong mixing properties, the LTS advocates the use of large (ARX-based) S-Boxes together with sparse linear layers. With the help of the so-called long-trail argument , a designer can bound the maximum differential and linear probabilities for any number of rounds of a cipher built according to the LTS. To illustrate the effectiveness of the new strategy, we propose Sparx – a family of ARX-based block ciphers designed according to the LTS. Sparx has 32-bit ARX-based S-boxes and has provable bounds against differential and linear cryptanalysis. In addition, Sparx is very efficient on a number of embedded platforms. Its optimized software implementation ranks in the top 6 of the most software-efficient ciphers along with Simon , Speck , Chaskey, LEA and RECTANGLE. As a second contribution we propose another strategy for designing ARX ciphers with provable properties, that is completely independent of the LTS. It is motivated by a challenge proposed earlier by Wallén and uses the differential properties of modular addition to minimize the maximum differential probability across multiple rounds of a cipher. A new primitive, called LAX , is designed following those principles. LAX partly solves the Wallén challenge.
Daniel Dinu, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Johann Großschädl, Alex Biryukov
ASIACRYPT (1)6
2016 Cryptanalysis of a Theorem: Decomposing the Only Known Solution to the Big APN Problem
Léo Perrin, Aleksei Udovenko, Alex Biryukov
CRYPTO (2)3
2016 Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr1
Alex Biryukov, Léo Perrin, Aleksei Udovenko
EUROCRYPT (1)1
2016 Argon2: New Generation of Memory-Hard Functions for Password Hashing and Other Applications
abstract
We present a new hash function Argon2, which is oriented at protection of low-entropy secrets without secret keys. It requires a certain (but tunable) amount of memory, imposes prohibitive time-memory and computation-memory tradeoffs on memory-saving users, and is exceptionally fast on regular PC. Overall, it can provide ASIC-and botnet-resistance by filling the memory in 0.6 cycles per byte in the non-compressible way.
Alex Biryukov, Daniel Dinu, Dmitry Khovratovich
EuroS&P1
2016 Automatic Search for the Best Trails in ARX: Application to Block Cipher Speck
Alex Biryukov, Vesselin Velichkov, Yann Le Corre
FSE1
2016 Equihash: Asymmetric Proof-of-Work Based on the Generalized Birthday Problem
Alex Biryukov, Dmitry Khovratovich
NDSS1
2016 Egalitarian Computing
Alex Biryukov, Dmitry Khovratovich
USENIX Security Symposium1
2015 Tradeoff Cryptanalysis of Memory-Hard Functions
Alex Biryukov, Dmitry Khovratovich
ASIACRYPT (2)1
2015 On Reverse-Engineering S-Boxes with Hidden Design Criteria or Structure
Alex Biryukov, Léo Perrin
CRYPTO (1)1
2015 Differential Analysis and Meet-in-the-Middle Attack Against Round-Reduced TWINE
Alex Biryukov, Patrick Derbez, Léo Perrin
FSE1
2015 Cryptanalysis of Feistel Networks with Secret Round Functions
Alex Biryukov, Gaëtan Leurent, Léo Perrin
SAC1
2015 Bitcoin over Tor isn't a Good Idea
abstract
Bit coin is a decentralized P2P digital currency in which coins are generated by a distributed set of miners and transactions are broadcasted via a peer-to-peer network. While Bit coin provides some level of anonymity (or rather pseudonymity) by encouraging the users to have any number of random-looking Bit coin addresses, recent research shows that this level of anonymity is rather low. This encourages users to connect to the Bit coin network through anonymizers like Tor and motivates development of default Tor functionality for popular mobile SPV clients. In this paper we show that combining Tor and Bit coin creates a new attack vector. A low-resource attacker can gain full control of information flows between all users who chose to use Bit coin over Tor. In particular the attacker can link together user's transactions regardless of pseudonyms used, control which Bit coin blocks and transactions are relayed to user and can delay or discard user's transactions and blocks. Moreover, we show how an attacker can fingerprint users and then recognize them and learn their IP addresses when they decide to connect to the Bit coin network directly.
Alex Biryukov, Ivan Pustogarov
IEEE Symposium on Security and Privacy1
2014 Cryptographic Schemes Based on the ASASA Structure: Black-Box, White-Box, and Public-Key (Extended Abstract)
Alex Biryukov, Charles Bouillaguet, Dmitry Khovratovich
ASIACRYPT (1)1
2014 Deanonymisation of Clients in Bitcoin P2P Network
abstract
Bitcoin is a digital currency which relies on a distributed set of miners to mint coins and on a peer-to-peer network to broadcast transactions. The identities of Bitcoin users are hidden behind pseudonyms (public keys) which are recommended to be changed frequently in order to increase transaction unlinkability.
Alex Biryukov, Dmitry Khovratovich, Ivan Pustogarov
CCS1
2014 Automatic Search for Differential Trails in ARX Ciphers
Alex Biryukov, Vesselin Velichkov
CT-RSA1
2014 Differential Analysis of Block Ciphers SIMON and SPECK
Alex Biryukov, Arnab Roy 0005, Vesselin Velichkov
FSE1
2014 PAEQ: Parallelizable Permutation-Based Authenticated Encryption
Alex Biryukov, Dmitry Khovratovich
ISC1
2014 Colliding Keys for SC2000-256
Alex Biryukov, Ivica Nikolic
Selected Areas in Cryptography1
2013 Complementing Feistel Ciphers
Alex Biryukov, Ivica Nikolic
FSE1
2013 Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
abstract
Tor is the most popular volunteer-based anonymity network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called "hidden services". In this paper we expose flaws both in the design and implementation of Tor's hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine.
Alex Biryukov, Ivan Pustogarov, Ralf-Philipp Weinmann
IEEE Symposium on Security and Privacy1
2012 TorScan: Tracing Long-Lived Connections and Differential Scanning Attacks
Alex Biryukov, Ivan Pustogarov, Ralf-Philipp Weinmann
ESORICS1
2012 Cryptanalysis of the Loiss Stream Cipher
Alex Biryukov, Aleksandar Kircanski, Amr M. Youssef
Selected Areas in Cryptography1
2012 Cryptanalysis of the "Kindle" Cipher
Alex Biryukov, Gaëtan Leurent, Arnab Roy 0005
Selected Areas in Cryptography1
2012 Cryptanalysis of the Full AES Using GPU-Like Special-Purpose Hardware
abstract
The block cipher Rijndael has undergone more than ten years of extensive cryptanalysis since its submission as a candidate for the Advanced Encryption Standard (AES) in April 1998. To date, most of the publicly-known cryptanalytic results are based o
Alex Biryukov, Johann Großschädl
Fundam. Informaticae1
2011 Cryptanalysis of the Atmel Cipher in SecureMemory, CryptoMemory and CryptoRF
Alex Biryukov, Ilya Kizhvatov, Bin Zhang 0003
ACNS1
2011 Second-Order Differential Collisions for Reduced SHA-256
Alex Biryukov, Mario Lamberger, Florian Mendel, Ivica Nikolic
ASIACRYPT1
2011 Search for Related-Key Differential Characteristics in DES-Like Ciphers
Alex Biryukov, Ivica Nikolic
FSE1
2011 Boomerang Attacks on BLAKE-32
Alex Biryukov, Ivica Nikolic, Arnab Roy 0005
FSE1
2010 Multiset Collision Attacks on Reduced-Round SNOW 3G and SNOW 3G (+)
Alex Biryukov, Deike Priemuth-Schmid, Bin Zhang 0003
ACNS1
2010 Key Recovery Attacks of Practical Complexity on AES-256 Variants with up to 10 Rounds
Alex Biryukov, Orr Dunkelman, Nathan Keller, Dmitry Khovratovich, Adi Shamir
EUROCRYPT1
2010 Automatic Search for Related-Key Differential Characteristics in Byte-Oriented Block Ciphers: Application to AES, Camellia, Khazad and Others
Alex Biryukov, Ivica Nikolic
EUROCRYPT1
2010 Analysis of SNOW 3G⊕ Resynchronization Mechanism
Alex Biryukov, Deike Priemuth-Schmid, Bin Zhang 0003
SECRYPT1
2010 Structural Cryptanalysis of SASAS
Alex Biryukov, Adi Shamir
J. Cryptol.1
2009 Related-Key Cryptanalysis of the Full AES-192 and AES-256
Alex Biryukov, Dmitry Khovratovich
ASIACRYPT1
2009 Distinguisher and Related-Key Attack on the Full AES-256
Alex Biryukov, Dmitry Khovratovich, Ivica Nikolic
CRYPTO1
2009 Speeding up Collision Search for Byte-Oriented Hash Functions
Dmitry Khovratovich, Alex Biryukov, Ivica Nikolic
CT-RSA2
2009 Cryptanalysis of the LAKE Hash Family
Alex Biryukov, Praveen Gauravaram, Jian Guo 0001, Dmitry Khovratovich, San Ling, Krystian Matusiewicz, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang
FSE1
2008 Collisions for Step-Reduced SHA-256
Ivica Nikolic, Alex Biryukov
FSE2
2007 Collision Attacks on AES-Based MAC: Alpha-MAC
Alex Biryukov, Andrey Bogdanov, Dmitry Khovratovich, Timo Kasper
CHES1
2007 Two New Techniques of Side-Channel Cryptanalysis
Alex Biryukov, Dmitry Khovratovich
CHES1
2006 An introduction to Block Cipher Cryptanalysis
abstract
Since the introduction of the Data Encryption Standard (DES) in the mid-1970s, block ciphers have played an ever-increasing role in cryptology. Because of the growing number of practical applications relying on their security,block ciphers have received, and are still receiving, a substantial amount of attention from academic cryptanalysts. This has led, over the last decades,to the development of several general techniques to analyze the security of block ciphers. This paper reviews the fundamental principles behind today's state of the art in block cipher cryptanalysis.
Christophe De Cannière, Alex Biryukov, Bart Preneel
Proc. IEEE2
2005 Analysis of the Non-linear Part of Mugi
Alex Biryukov, Adi Shamir
FSE1
2005 On the Security of Encryption Modes of MD4, MD5 and HAVAL
Jongsung Kim, Alex Biryukov, Bart Preneel, Sangjin Lee 0002
ICICS2
2005 Recent attacks on alleged SecurID and their practical implications
Alex Biryukov, Joseph Lano, Bart Preneel
Comput. Secur.1
2005 Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials
Eli Biham, Alex Biryukov, Adi Shamir
J. Cryptol.2
2004 On Multiple Linear Approximations
Alex Biryukov, Christophe De Cannière, Michaël Quisquater
CRYPTO1
2003 Cryptanalysis of 3-Pass HAVAL
Bart Van Rompay, Alex Biryukov, Bart Preneel, Joos Vandewalle
ASIACRYPT2
2003 Cryptanalysis of SAFER++
Alex Biryukov, Christophe De Cannière, Gustaf Dellkrantz
CRYPTO1
2003 A Toolbox for Cryptanalysis: Linear and Affine Equivalence Algorithms
Alex Biryukov, Christophe De Cannière, An Braeken, Bart Preneel
EUROCRYPT1
2003 Analysis of Involutional Ciphers: Khazad and Anubis
Alex Biryukov
FSE1
2003 Block Ciphers and Systems of Quadratic Equations
Alex Biryukov, Christophe De Cannière
FSE1
2002 New Weak-Key Classes of IDEA
Alex Biryukov, Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle
ICICS1
2001 Structural Cryptanalysis of SASAS
Alex Biryukov, Adi Shamir
EUROCRYPT1
2000 Cryptanalytic Time/Memory/Data Tradeoffs for Stream Ciphers
Alex Biryukov, Adi Shamir
ASIACRYPT1
2000 Advanced Slide Attacks
Alex Biryukov, David A. Wagner 0001
EUROCRYPT1
2000 Real Time Cryptanalysis of A5/1 on a PC
Alex Biryukov, Adi Shamir, David A. Wagner 0001
FSE1
1999 Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials
Eli Biham, Alex Biryukov, Adi Shamir
EUROCRYPT2
1999 Miss in the Middle Attacks on IDEA and Khufu
Eli Biham, Alex Biryukov, Adi Shamir
FSE2
1999 Slide Attacks
Alex Biryukov, David A. Wagner 0001
FSE1
1998 From Differential Cryptanalysis to Ciphertext-Only Attacks
Alex Biryukov, Eyal Kushilevitz
CRYPTO1
1998 Improved Cryptanalysis of RC5
Alex Biryukov, Eyal Kushilevitz
EUROCRYPT1
1998 Initial Observations on Skipjack: Cryptanalysis of Skipjack-3XOR
Eli Biham, Alex Biryukov, Orr Dunkelman, Eran Richardson, Adi Shamir
Selected Areas in Cryptography2
1997 An Improvement of Davies' Attack on DES
Eli Biham, Alex Biryukov
J. Cryptol.2
1994 How to Strengthen DES Using Existing Hardware
Eli Biham, Alex Biryukov
ASIACRYPT2