EDBT 2026 Demo / reviewers in the wild / expert
Qianqian Yang 0003
dblp:10/9659-3
· DBLP profile ↗
20ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0002-2062-1344ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 4 first-author · 14 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploiting Strong Key Bridges: Full-Fledged Automatic Rectangle Attacks on Deoxys-BC and SKINNY
Ling Song 0001, Yincen Chen, Qianqian Yang 0003, Lei Wang 0031, Lei Hu 0003, Jian Weng 0001 |
CRYPTO (6) | 3 |
| 2026 | Practical weak-key attack against full-round Loong: an involutional lightweight block cipherabstractAbstract In lightweight block cipher designs, involutory components are often employed to minimize circuit area. However, these components can also introduce security vulnerabilities. Loong is a family of lightweight block ciphers based on the Substitution-Permutation Network (SPN) structure. Each round of Loong incorporates two involutory MDS matrices and two involutory S-boxes, resulting in a fully involutory round function. While these operations provide high diffusion and a substantial algebraic degree, the involutory nature of the design makes Loong vulnerable to weak-key attacks. In this paper, we present several notable observations regarding the round function of Loong. By exploiting the unique properties of its involutory round function, we identify weak-key differential characteristics for all three full-round variants of Loong. Specifically, the probabilities of weak-key differential characteristics for Loong-64, Loong-80, and Loong-128 are $$2^{-26.83}$$ 2 - 26.83 , $$2^{-37.42}$$ 2 - 37.42 and $$2^{-46.66}$$ 2 - 46.66 , respectively. The corresponding weak-key spaces are of sizes $$2^{36}$$ 2 36 , $$2^{52}$$ 2 52 and $$2^{96}$$ 2 96 . These findings effectively compromise the security of Loong. Furthermore, we conducted experiments on a personal computer and identified practical differential characteristics for Loong-64. Additionally, we analyze the security of block ciphers with involutory round functions in general. Our findings indicate that such designs are more prone to weak-key attacks and are even more vulnerable to general differential cryptanalysis. While the use of involutory round functions reduces circuit area and improves cipher efficiency, it also introduces significant security weaknesses. Caibing Wang, Qianqian Yang 0003, Lei Hu 0003 |
Cybersecur. | 3 |
| 2025 | Preimage and collision attacks on reduced Ascon using algebraic strategiesabstractAbstract Ascon, a family of algorithms that supports hashing and authenticated encryption, is the winner of the NIST Lightweight Cryptography Project. In this paper, we propose an improved preimage attack against 2-round Ascon-XOF-64 with a complexity of $$2^{33}$$ 2 33 via a more effective guessing strategy. Furthermore, we successfully extend our preimage attack on 2-round Ascon-XOF-64 to 2-round Ascon-XOF-128, achieving a complexity of $$2^{97}$$ 2 97 , which is currently the best preimage attack against 2-round Ascon-XOF-128. Apart from the preimage attack, we also investigate the resistance of Ascon-HASH against collision attacks. To be specific, we introduce the linearization of the inverse of S-boxes and then propose a free-start collision attack on 3-round Ascon-HASH with a complexity of $$2^{14}$$ 2 14 using a differential trail searched dedicatedly. In addition, we construct different 2-round connectors using the linearization of the inverse of S-boxes and successfully extend the collision attack to 4 rounds and 5 rounds of Ascon-HASH with complexities of $$2^{18}$$ 2 18 and $$2^{41}$$ 2 41 , respectively. Although our attacks do not compromise the security of the full 12-round Ascon-XOF and Ascon-HASH, they provide some insights into Ascon’s security. Qinggan Fu, Qianqian Yang 0003, Ling Song 0001 |
Cybersecur. | 3 |
| 2025 | Generalized impossible differential attacks on block ciphers: application to SKINNY and ForkSKINNY
Ling Song 0001, Qinggan Fu, Qianqian Yang 0003, Yin Lv, Lei Hu 0003 |
Des. Codes Cryptogr. | 3 |
| 2024 | Generic Differential Key Recovery Attacks and Beyond
Ling Song 0001, Qianqian Yang 0003, Yincen Chen, Lei Hu 0003, Jian Weng 0001 |
ASIACRYPT (7) | 3 |
| 2024 | A Note on Neutral Bits for ARX Ciphers from the Perspective of BCT
Qianqian Yang 0003, Ling Song 0001, Lei Hu 0003 |
Inscrypt (2) | 2 |
| 2024 | Probabilistic Extensions: A One-Step Framework for Finding Rectangle Attacks and Beyond
Ling Song 0001, Qianqian Yang 0003, Yincen Chen, Lei Hu 0003, Jian Weng 0001 |
EUROCRYPT (1) | 2 |
| 2024 | Revisiting the shuffle of generalized Feistel structureabstractAbstract The Generalized Feistel Structure ( $$\texttt{GFS}$$ GFS ) is one of the most widely used frameworks in symmetric cipher design. In FES 2010, Suzaki and Minematsu strengthened the cryptanalysis security of $$\texttt{GFS}$$ GFS by searching for shuffles with the best diffusion property. In ASIACRYPT 2018, Shi et al. suggested a set of shuffles, which makes $$\texttt{GFS}$$ GFS a better resistance against Demirci–Selcuk meet-in-the-middle cryptanalysis. Since these shuffles are different from the currently known good ones and also different from the shuffles used in $$\texttt{TWINE}$$ TWINE and $$\texttt{LBlock}$$ LBlock , our research focuses on a more comprehensive evaluation of $$\texttt{GFS}$$ GFS with different shuffles, including diffusion property of shuffle, differential, linear, impossible differential, zero-correlation linear, integral and Demirci–Selcuk meet-in-the-middle cryptanalysis, to find the best one. Such evaluations entail significant time consumption. Thus, we utilize Mixed Integral Linear Programming models and introduce an evaluate-and-filter strategy to achieve it efficiently. Our results verify that the shuffles discovered by Suzaki and Minematsu and those used in $$\texttt{TWINE}$$ TWINE and $$\texttt{LBlock}$$ LBlock are the best so far. We also find that the cryptanalysis resistances of $$\texttt{GFS}$$ GFS are not necessarily consistent. It is this finding that makes the necessity of our more comprehensive evaluation self-evident. Yincen Chen, Xuanyu Liang, Ling Song 0001, Qianqian Yang 0003 |
Cybersecur. | 5 |
| 2024 | Optimizing Rectangle and Boomerang Attacks: A Unified and Generic Framework for Key Recovery
Qianqian Yang 0003, Ling Song 0001, Danping Shi, Lei Hu 0003, Jian Weng 0001 |
J. Cryptol. | 1 |
| 2023 | Improved Differential Cryptanalysis on SPECK Using Plaintext Structures
Zhuohui Feng, Qianqian Yang 0003, Zhiquan Liu 0001, Ling Song 0001 |
ACISP | 4 |
| 2023 | Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNY
Danping Shi, Siwei Sun, Ling Song 0001, Lei Hu 0003, Qianqian Yang 0003 |
EUROCRYPT (4) | 5 |
| 2023 | Improved Related-Key Rectangle Attack Against the Full AES-192
Xuanyu Liang, Yincen Chen, Ling Song 0001, Qianqian Yang 0003, Zhuohui Feng, Tianrong Huang |
ICICS | 4 |
| 2023 | Improving the Rectangle Attack on GIFT-64
Yincen Chen, Xuanyu Liang, Ling Song 0001, Qianqian Yang 0003, Zhuohui Feng |
SAC | 5 |
| 2023 | A New Method To Find All The High-Probability Word-Oriented Truncated Differentials: Application To <tt>Midori</tt>, <tt>SKINNY</tt> And <tt>CRAFT</tt>abstractAbstract This paper proposes a new method to find high-probability truncated differentials using matrix muliplication. For Markov cipher with similar round function, suppose that the transition probability matrix of round function is $\mathcal{D}$, then $\mathcal{D}^{r}$ contains all the differential probabilities of an $r$-round block cipher. To reduce the matrix dimension, we consider the word-oriented truncated differential and the truncated transition probability matrix $\mathcal{T}$. Regardless of the effect of the $S$-box, we focus on whether there is a non-zero difference on one cell instead of the value of the difference. In this case, the matrix dimension reduces significantly and we can calculate $\mathcal{T}^{r}$ using a workstation. Then all the $r$-round truncated differential probabilities can be found from $\mathcal{T}^{r}$. And the probability in $\mathcal{T}^{r}$ is the probability of the whole truncated differential hull but not a single or several truncated differential characteristics. Besides, we make a more accurate probability estimation of the truncated differential of lightweight block cipher. Combined with the truncated differential hull, we found some longer truncated differential distinguishers. And as $\mathcal{T}^{r}$ stores all the truncated differential probabilities, we can also find all the impossible truncated differentials. Zhiyu Zhang 0009, Qianqian Yang 0003, Lei Hu 0003, Yiyuan Luo |
Comput. J. | 3 |
| 2022 | Optimizing Rectangle Attacks: A Unified and Generic Framework for Key Recovery
Ling Song 0001, Qianqian Yang 0003, Danping Shi, Lei Hu 0003, Jian Weng 0001 |
ASIACRYPT (1) | 3 |
| 2018 | On the Complexity of Impossible Differential CryptanalysisabstractWhile impossible differential attack is one of the most well-known and familiar techniques for symmetric-key cryptanalysts, its subtlety and complicacy make the construction and verification of such attacks difficult and error-prone. We introduce a new set of notations for impossible differential analysis. These notations lead to unified formulas for estimation of data complexities of ordinary impossible differential attacks and attacks employing multiple impossible differentials. We also identify an interesting point from the new formulas: in most cases, the data complexity is only related to the form of the underlying distinguisher and has nothing to do with how the differences at the beginning and the end of the distinguisher propagate in the outer rounds. We check the formulas with some examples, and the results are all matching. Since the estimation of the time complexity is flawed in some situations, in this work, we show under which condition the formula is valid and give a simple time complexity estimation for impossible differential attack which is always achievable. Qianqian Yang 0003, Lei Hu 0003, Danping Shi, Yosuke Todo, Siwei Sun |
Secur. Commun. Networks | 1 |
| 2016 | Automatic Differential Analysis of ARX Block Ciphers with Application to SPECK and LEA
Ling Song 0001, Zhangjie Huang, Qianqian Yang 0003 |
ACISP (2) | 3 |
| 2016 | Extension of Meet-in-the-Middle Technique for Truncated Differential and Its Application to RoadRunneR
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Ling Song 0001 |
NSS | 1 |
| 2015 | Improved Differential Analysis of Block Cipher PRIDE
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Kexin Qiao, Ling Song 0001, Jinyong Shan, Xiaoshuang Ma |
ISPEC | 1 |
| 2015 | Extending the Applicability of the Mixed-Integer Programming Technique in Automatic Differential Cryptanalysis
Siwei Sun, Lei Hu 0003, Qianqian Yang 0003, Kexin Qiao, Xiaoshuang Ma, Ling Song 0001, Jinyong Shan |
ISC | 4 |