EDBT 2026 Demo / reviewers in the wild / expert
Alex Biryukov
dblp:09/5071
· DBLP profile ↗
85ranked-venue papers
68as first author
10since 2021 · last 2026
0000-0003-1404-6686ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 81 · 65 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorTheory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination Framework
Alex Biryukov, Pablo García Fernández, Aleksei Udovenko |
EUROCRYPT | 1 |
| 2026 | Algorithmic Toolkit for Linearization of S-Boxes
Alex Biryukov, Philip Turecek, Aleksei Udovenko |
EUROCRYPT | 1 |
| 2024 | Cryptanalysis of Algebraic Verifiable Delay Functions
Alex Biryukov, Ben Fisch, Gottfried Herold, Dmitry Khovratovich, Gaëtan Leurent, María Naya-Plasencia, Benjamin Wesolowski |
CRYPTO (3) | 1 |
| 2023 | Meet-in-the-Filter and Dynamic Counting with Applications to Speck
Alex Biryukov, Luan Cardoso dos Santos, Je Sen Teh, Aleksei Udovenko, Vesselin Velichkov |
ACNS (1) | 1 |
| 2022 | Dynamic Universal Accumulator with Batch Update over Bilinear Groups
Giuseppe Vitto, Alex Biryukov |
CT-RSA | 2 |
| 2022 | Advancing the Meet-in-the-Filter Technique: Applications to CHAM and KATAN
Alex Biryukov, Je Sen Teh, Aleksei Udovenko |
SAC | 1 |
| 2022 | Differential cryptanalysis of WARP
Je Sen Teh, Alex Biryukov |
J. Inf. Secur. Appl. | 2 |
| 2021 | Cryptanalysis of a Dynamic Universal Accumulator over Bilinear Groups
Alex Biryukov, Aleksei Udovenko, Giuseppe Vitto |
CT-RSA | 1 |
| 2021 | Dummy Shuffling Against Algebraic Attacks in White-Box Implementations
Alex Biryukov, Aleksei Udovenko |
EUROCRYPT (2) | 1 |
| 2021 | Automated Truncation of Differential Trails and Trail Clustering in ARX
Alex Biryukov, Luan Cardoso dos Santos, Daniel Feher, Vesselin Velichkov, Giuseppe Vitto |
SAC | 1 |
| 2020 | Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001 |
CRYPTO (3) | 2 |
| 2020 | ReCon: Sybil-resistant consensus from reputation
Alex Biryukov, Daniel Feher |
Pervasive Mob. Comput. | 1 |
| 2019 | FELICS-AEAD: Benchmarking of Lightweight Authenticated Encryption Algorithms
Luan Cardoso dos Santos, Johann Großschädl, Alex Biryukov |
CARDIS | 3 |
| 2019 | Privacy Aspects and Subliminal Channels in ZcashabstractIn this paper we analyze two privacy and security issues for the privacy-oriented cryptocurrency Zcash. First we study shielded transactions and show ways to fingerprint user transactions, including active attacks. We introduce two new attacks which we call Danaan-gift attack and Dust attack. Following the recent Sapling update of Zcash protocol we study the interaction between the new and the old zk-SNARK protocols and the effects of their interaction on transaction privacy. In the second part of the paper we check for the presence of subliminal channels in the zk-SNARK protocol and in Pedersen Commitments. We show presence of efficient 70-bit channels which could be used for tagging of shielded transactions which would allow the attacker (malicious transaction verifier) to link transactions issued by a maliciously modified zk-SNARK prover, while would be indistinguishable from regular transactions for the honest verifier/user. We discuss countermeasures against both of these privacy issues. Alex Biryukov, Daniel Feher, Giuseppe Vitto |
CCS | 1 |
| 2019 | Deanonymization and Linkability of Cryptocurrency Transactions Based on Network AnalysisabstractBitcoin, introduced in 2008 and launched in 2009, is the first digital currency to solve the double spending problem without relying on a trusted third party. Bitcoin provides a way to transact without any trusted intermediary, but its privacy guarantees are questionable. Despite the fact that Bitcoin addresses are not linked to any identity, multiple deanonymization attacks have been proposed. Alternative cryptocurrencies such as Dash, Monero, and Zcash aim to provide stronger privacy by using sophisticated cryptographic techniques to obfuscate transaction data. Previous work in cryptocurrency privacy mostly focused on applying data mining algorithms to the transaction graph extracted from the blockchain. We focus on a less well researched vector for privacy attacks: network analysis. We argue that timings of transaction messages leak information about their origin, which can be exploited by a well connected adversarial node. For the first time, network level attacks on Bitcoin and the three major privacy-focused cryptocurrencies have been examined. We describe the message propagation mechanics and privacy guarantees in Bitcoin, Dash, Monero, and Zcash. We propose a novel technique for linking transactions based on transaction propagation analysis. We also unpack address advertisement messages (ADDR), which under certain assumptions may help in linking transaction clusters to IP addresses of nodes. We implement and evaluate our method, deanonymizing our own transactions in Bitcoin and Zcash with a high level of accuracy. We also show that our technique is applicable to Dash and Monero. We estimate the cost of a full-scale attack on the Bitcoin mainnet at hundreds of US dollars, feasible even for a low budget adversary. Alex Biryukov, Sergei Tikhomirov |
EuroS&P | 1 |
| 2019 | Security and privacy of mobile wallet users in Bitcoin, Dash, Monero, and Zcash
Alex Biryukov, Sergei Tikhomirov |
Pervasive Mob. Comput. | 1 |
| 2018 | Attacks and Countermeasures for White-box Designs
Alex Biryukov, Aleksei Udovenko |
ASIACRYPT (2) | 1 |
| 2017 | Side-Channel Attacks Meet Secure Network Protocols
Alex Biryukov, Daniel Dinu, Yann Le Corre |
ACNS | 1 |
| 2017 | Symmetrically and Asymmetrically Hard Cryptography
Alex Biryukov, Léo Perrin |
ASIACRYPT (3) | 1 |
| 2017 | Optimal First-Order Boolean Masking for Embedded IoT Devices
Alex Biryukov, Daniel Dinu, Yann Le Corre, Aleksei Udovenko |
CARDIS | 1 |
| 2016 | Correlation Power Analysis of Lightweight Block Ciphers: From Theory to Practice
Alex Biryukov, Daniel Dinu, Johann Großschädl |
ACNS | 1 |
| 2016 | Design Strategies for ARX with Provable Bounds: Sparx and LAXabstractWe present, for the first time, a general strategy for designing ARX symmetric-key primitives with provable resistance against single-trail differential and linear cryptanalysis. The latter has been a long standing open problem in the area of ARX design. The wide-trail design strategy (WTS), that is at the basis of many S-box based ciphers, including the AES, is not suitable for ARX designs due to the lack of S-boxes in the latter. In this paper we address the mentioned limitation by proposing the long trail design strategy (LTS) – a dual of the WTS that is applicable (but not limited) to ARX constructions. In contrast to the WTS, that prescribes the use of small and efficient S-boxes at the expense of heavy linear layers with strong mixing properties, the LTS advocates the use of large (ARX-based) S-Boxes together with sparse linear layers. With the help of the so-called long-trail argument , a designer can bound the maximum differential and linear probabilities for any number of rounds of a cipher built according to the LTS. To illustrate the effectiveness of the new strategy, we propose Sparx – a family of ARX-based block ciphers designed according to the LTS. Sparx has 32-bit ARX-based S-boxes and has provable bounds against differential and linear cryptanalysis. In addition, Sparx is very efficient on a number of embedded platforms. Its optimized software implementation ranks in the top 6 of the most software-efficient ciphers along with Simon , Speck , Chaskey, LEA and RECTANGLE. As a second contribution we propose another strategy for designing ARX ciphers with provable properties, that is completely independent of the LTS. It is motivated by a challenge proposed earlier by Wallén and uses the differential properties of modular addition to minimize the maximum differential probability across multiple rounds of a cipher. A new primitive, called LAX , is designed following those principles. LAX partly solves the Wallén challenge. Daniel Dinu, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Johann Großschädl, Alex Biryukov |
ASIACRYPT (1) | 6 |
| 2016 | Cryptanalysis of a Theorem: Decomposing the Only Known Solution to the Big APN Problem
Léo Perrin, Aleksei Udovenko, Alex Biryukov |
CRYPTO (2) | 3 |
| 2016 | Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr1
Alex Biryukov, Léo Perrin, Aleksei Udovenko |
EUROCRYPT (1) | 1 |
| 2016 | Argon2: New Generation of Memory-Hard Functions for Password Hashing and Other ApplicationsabstractWe present a new hash function Argon2, which is oriented at protection of low-entropy secrets without secret keys. It requires a certain (but tunable) amount of memory, imposes prohibitive time-memory and computation-memory tradeoffs on memory-saving users, and is exceptionally fast on regular PC. Overall, it can provide ASIC-and botnet-resistance by filling the memory in 0.6 cycles per byte in the non-compressible way. Alex Biryukov, Daniel Dinu, Dmitry Khovratovich |
EuroS&P | 1 |
| 2016 | Automatic Search for the Best Trails in ARX: Application to Block Cipher Speck
Alex Biryukov, Vesselin Velichkov, Yann Le Corre |
FSE | 1 |
| 2016 | Equihash: Asymmetric Proof-of-Work Based on the Generalized Birthday Problem
Alex Biryukov, Dmitry Khovratovich |
NDSS | 1 |
| 2016 | Egalitarian Computing
Alex Biryukov, Dmitry Khovratovich |
USENIX Security Symposium | 1 |
| 2015 | Tradeoff Cryptanalysis of Memory-Hard Functions
Alex Biryukov, Dmitry Khovratovich |
ASIACRYPT (2) | 1 |
| 2015 | On Reverse-Engineering S-Boxes with Hidden Design Criteria or Structure
Alex Biryukov, Léo Perrin |
CRYPTO (1) | 1 |
| 2015 | Differential Analysis and Meet-in-the-Middle Attack Against Round-Reduced TWINE
Alex Biryukov, Patrick Derbez, Léo Perrin |
FSE | 1 |
| 2015 | Cryptanalysis of Feistel Networks with Secret Round Functions
Alex Biryukov, Gaëtan Leurent, Léo Perrin |
SAC | 1 |
| 2015 | Bitcoin over Tor isn't a Good IdeaabstractBit coin is a decentralized P2P digital currency in which coins are generated by a distributed set of miners and transactions are broadcasted via a peer-to-peer network. While Bit coin provides some level of anonymity (or rather pseudonymity) by encouraging the users to have any number of random-looking Bit coin addresses, recent research shows that this level of anonymity is rather low. This encourages users to connect to the Bit coin network through anonymizers like Tor and motivates development of default Tor functionality for popular mobile SPV clients. In this paper we show that combining Tor and Bit coin creates a new attack vector. A low-resource attacker can gain full control of information flows between all users who chose to use Bit coin over Tor. In particular the attacker can link together user's transactions regardless of pseudonyms used, control which Bit coin blocks and transactions are relayed to user and can delay or discard user's transactions and blocks. Moreover, we show how an attacker can fingerprint users and then recognize them and learn their IP addresses when they decide to connect to the Bit coin network directly. Alex Biryukov, Ivan Pustogarov |
IEEE Symposium on Security and Privacy | 1 |
| 2014 | Cryptographic Schemes Based on the ASASA Structure: Black-Box, White-Box, and Public-Key (Extended Abstract)
Alex Biryukov, Charles Bouillaguet, Dmitry Khovratovich |
ASIACRYPT (1) | 1 |
| 2014 | Deanonymisation of Clients in Bitcoin P2P NetworkabstractBitcoin is a digital currency which relies on a distributed set of miners to mint coins and on a peer-to-peer network to broadcast transactions. The identities of Bitcoin users are hidden behind pseudonyms (public keys) which are recommended to be changed frequently in order to increase transaction unlinkability. Alex Biryukov, Dmitry Khovratovich, Ivan Pustogarov |
CCS | 1 |
| 2014 | Automatic Search for Differential Trails in ARX Ciphers
Alex Biryukov, Vesselin Velichkov |
CT-RSA | 1 |
| 2014 | Differential Analysis of Block Ciphers SIMON and SPECK
Alex Biryukov, Arnab Roy 0005, Vesselin Velichkov |
FSE | 1 |
| 2014 | PAEQ: Parallelizable Permutation-Based Authenticated Encryption
Alex Biryukov, Dmitry Khovratovich |
ISC | 1 |
| 2014 | Colliding Keys for SC2000-256
Alex Biryukov, Ivica Nikolic |
Selected Areas in Cryptography | 1 |
| 2013 | Complementing Feistel Ciphers
Alex Biryukov, Ivica Nikolic |
FSE | 1 |
| 2013 | Trawling for Tor Hidden Services: Detection, Measurement, DeanonymizationabstractTor is the most popular volunteer-based anonymity network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called "hidden services". In this paper we expose flaws both in the design and implementation of Tor's hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine. Alex Biryukov, Ivan Pustogarov, Ralf-Philipp Weinmann |
IEEE Symposium on Security and Privacy | 1 |
| 2012 | TorScan: Tracing Long-Lived Connections and Differential Scanning Attacks
Alex Biryukov, Ivan Pustogarov, Ralf-Philipp Weinmann |
ESORICS | 1 |
| 2012 | Cryptanalysis of the Loiss Stream Cipher
Alex Biryukov, Aleksandar Kircanski, Amr M. Youssef |
Selected Areas in Cryptography | 1 |
| 2012 | Cryptanalysis of the "Kindle" Cipher
Alex Biryukov, Gaëtan Leurent, Arnab Roy 0005 |
Selected Areas in Cryptography | 1 |
| 2012 | Cryptanalysis of the Full AES Using GPU-Like Special-Purpose HardwareabstractThe block cipher Rijndael has undergone more than ten years of extensive cryptanalysis since its submission as a candidate for the Advanced Encryption Standard (AES) in April 1998. To date, most of the publicly-known cryptanalytic results are based o Alex Biryukov, Johann Großschädl |
Fundam. Informaticae | 1 |
| 2011 | Cryptanalysis of the Atmel Cipher in SecureMemory, CryptoMemory and CryptoRF
Alex Biryukov, Ilya Kizhvatov, Bin Zhang 0003 |
ACNS | 1 |
| 2011 | Second-Order Differential Collisions for Reduced SHA-256
Alex Biryukov, Mario Lamberger, Florian Mendel, Ivica Nikolic |
ASIACRYPT | 1 |
| 2011 | Search for Related-Key Differential Characteristics in DES-Like Ciphers
Alex Biryukov, Ivica Nikolic |
FSE | 1 |
| 2011 | Boomerang Attacks on BLAKE-32
Alex Biryukov, Ivica Nikolic, Arnab Roy 0005 |
FSE | 1 |
| 2010 | Multiset Collision Attacks on Reduced-Round SNOW 3G and SNOW 3G (+)
Alex Biryukov, Deike Priemuth-Schmid, Bin Zhang 0003 |
ACNS | 1 |
| 2010 | Key Recovery Attacks of Practical Complexity on AES-256 Variants with up to 10 Rounds
Alex Biryukov, Orr Dunkelman, Nathan Keller, Dmitry Khovratovich, Adi Shamir |
EUROCRYPT | 1 |
| 2010 | Automatic Search for Related-Key Differential Characteristics in Byte-Oriented Block Ciphers: Application to AES, Camellia, Khazad and Others
Alex Biryukov, Ivica Nikolic |
EUROCRYPT | 1 |
| 2010 | Analysis of SNOW 3G⊕ Resynchronization Mechanism
Alex Biryukov, Deike Priemuth-Schmid, Bin Zhang 0003 |
SECRYPT | 1 |
| 2010 | Structural Cryptanalysis of SASAS
Alex Biryukov, Adi Shamir |
J. Cryptol. | 1 |
| 2009 | Related-Key Cryptanalysis of the Full AES-192 and AES-256
Alex Biryukov, Dmitry Khovratovich |
ASIACRYPT | 1 |
| 2009 | Distinguisher and Related-Key Attack on the Full AES-256
Alex Biryukov, Dmitry Khovratovich, Ivica Nikolic |
CRYPTO | 1 |
| 2009 | Speeding up Collision Search for Byte-Oriented Hash Functions
Dmitry Khovratovich, Alex Biryukov, Ivica Nikolic |
CT-RSA | 2 |
| 2009 | Cryptanalysis of the LAKE Hash Family
Alex Biryukov, Praveen Gauravaram, Jian Guo 0001, Dmitry Khovratovich, San Ling, Krystian Matusiewicz, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang |
FSE | 1 |
| 2008 | Collisions for Step-Reduced SHA-256
Ivica Nikolic, Alex Biryukov |
FSE | 2 |
| 2007 | Collision Attacks on AES-Based MAC: Alpha-MAC
Alex Biryukov, Andrey Bogdanov, Dmitry Khovratovich, Timo Kasper |
CHES | 1 |
| 2007 | Two New Techniques of Side-Channel Cryptanalysis
Alex Biryukov, Dmitry Khovratovich |
CHES | 1 |
| 2006 | An introduction to Block Cipher CryptanalysisabstractSince the introduction of the Data Encryption Standard (DES) in the mid-1970s, block ciphers have played an ever-increasing role in cryptology. Because of the growing number of practical applications relying on their security,block ciphers have received, and are still receiving, a substantial amount of attention from academic cryptanalysts. This has led, over the last decades,to the development of several general techniques to analyze the security of block ciphers. This paper reviews the fundamental principles behind today's state of the art in block cipher cryptanalysis. Christophe De Cannière, Alex Biryukov, Bart Preneel |
Proc. IEEE | 2 |
| 2005 | Analysis of the Non-linear Part of Mugi
Alex Biryukov, Adi Shamir |
FSE | 1 |
| 2005 | On the Security of Encryption Modes of MD4, MD5 and HAVAL
Jongsung Kim, Alex Biryukov, Bart Preneel, Sangjin Lee 0002 |
ICICS | 2 |
| 2005 | Recent attacks on alleged SecurID and their practical implications
Alex Biryukov, Joseph Lano, Bart Preneel |
Comput. Secur. | 1 |
| 2005 | Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials
Eli Biham, Alex Biryukov, Adi Shamir |
J. Cryptol. | 2 |
| 2004 | On Multiple Linear Approximations
Alex Biryukov, Christophe De Cannière, Michaël Quisquater |
CRYPTO | 1 |
| 2003 | Cryptanalysis of 3-Pass HAVAL
Bart Van Rompay, Alex Biryukov, Bart Preneel, Joos Vandewalle |
ASIACRYPT | 2 |
| 2003 | Cryptanalysis of SAFER++
Alex Biryukov, Christophe De Cannière, Gustaf Dellkrantz |
CRYPTO | 1 |
| 2003 | A Toolbox for Cryptanalysis: Linear and Affine Equivalence Algorithms
Alex Biryukov, Christophe De Cannière, An Braeken, Bart Preneel |
EUROCRYPT | 1 |
| 2003 | Analysis of Involutional Ciphers: Khazad and Anubis
Alex Biryukov |
FSE | 1 |
| 2003 | Block Ciphers and Systems of Quadratic Equations
Alex Biryukov, Christophe De Cannière |
FSE | 1 |
| 2002 | New Weak-Key Classes of IDEA
Alex Biryukov, Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle |
ICICS | 1 |
| 2001 | Structural Cryptanalysis of SASAS
Alex Biryukov, Adi Shamir |
EUROCRYPT | 1 |
| 2000 | Cryptanalytic Time/Memory/Data Tradeoffs for Stream Ciphers
Alex Biryukov, Adi Shamir |
ASIACRYPT | 1 |
| 2000 | Advanced Slide Attacks
Alex Biryukov, David A. Wagner 0001 |
EUROCRYPT | 1 |
| 2000 | Real Time Cryptanalysis of A5/1 on a PC
Alex Biryukov, Adi Shamir, David A. Wagner 0001 |
FSE | 1 |
| 1999 | Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials
Eli Biham, Alex Biryukov, Adi Shamir |
EUROCRYPT | 2 |
| 1999 | Miss in the Middle Attacks on IDEA and Khufu
Eli Biham, Alex Biryukov, Adi Shamir |
FSE | 2 |
| 1999 | Slide Attacks
Alex Biryukov, David A. Wagner 0001 |
FSE | 1 |
| 1998 | From Differential Cryptanalysis to Ciphertext-Only Attacks
Alex Biryukov, Eyal Kushilevitz |
CRYPTO | 1 |
| 1998 | Improved Cryptanalysis of RC5
Alex Biryukov, Eyal Kushilevitz |
EUROCRYPT | 1 |
| 1998 | Initial Observations on Skipjack: Cryptanalysis of Skipjack-3XOR
Eli Biham, Alex Biryukov, Orr Dunkelman, Eran Richardson, Adi Shamir |
Selected Areas in Cryptography | 2 |
| 1997 | An Improvement of Davies' Attack on DES
Eli Biham, Alex Biryukov |
J. Cryptol. | 2 |
| 1994 | How to Strengthen DES Using Existing Hardware
Eli Biham, Alex Biryukov |
ASIACRYPT | 2 |