EDBT 2026 Demo / reviewers in the wild / expert
Christof Beierle
dblp:160/3831
· DBLP profile ↗
19ranked-venue papers
18as first author
13since 2021 · last 2026
0000-0002-5558-0722ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 16 first-author · 11 since 2021Theory of computation · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks
Christof Beierle, Gregor Leander, Yevhen Perehuda |
EUROCRYPT | 1 |
| 2025 | Integral Resistance of Block Ciphers with Key Whitening by Modular Addition
Christof Beierle, Phil Hebborn, Gregor Leander, Yevhen Perehuda |
CRYPTO (5) | 1 |
| 2025 | INDIANA - Verifying (Random) Probing Security Through Indistinguishability Analysis
Christof Beierle, Jakob Feldtkeller, Anna Guinet, Tim Güneysu, Gregor Leander, Jan Richter-Brockmann, Pascal Sasdrich |
EUROCRYPT (8) | 1 |
| 2025 | Commutative cryptanalysis as a generalization of differential cryptanalysisabstractAbstract Recently, Baudrin et al. analyzed a special case of Wagner’s commutative diagram cryptanalysis, referred to as commutative cryptanalysis. For a family $$(E_k)_k$$ ( E k ) k of permutations on a finite vector space G, commutative cryptanalysis exploits the existence of affine permutations $$A,B :G \rightarrow G$$ A , B : G → G , $$I \notin \{A,B\}$$ I ∉ { A , B } such that $$E_k \circ A (x) = B \circ E_k(x)$$ E k ∘ A ( x ) = B ∘ E k ( x ) holds with high probability, taken over inputs x, for a significantly large set of weak keys k. Several attacks against symmetric cryptographic primitives can be formulated within the framework of commutative cryptanalysis, most importantly differential attacks, as well as rotational and rotational-differential attacks. Besides, the notion of c-differentials on S-boxes can be analyzed as a special case within this framework. We discuss the relations between a general notion of commutative cryptanalysis, with A and B being arbitrary functions over a finite Abelian group, and differential cryptanalysis, both from the view of conducting an attack on a symmetric cryptographic primitive, as well as from the view of a theoretical study of cryptographic S-boxes. Jules Baudrin, Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Léo Perrin, Lukas Stennes |
Des. Codes Cryptogr. | 2 |
| 2025 | Revisiting products of the form X times a linearized polynomial L(X)abstractAbstract For a q-polynomial L over a finite field $$\mathbb {F}_{q^n}$$ F q n , we characterize the differential spectrum of the function $$f_L:\mathbb {F}_{q^n} \rightarrow \mathbb {F}_{q^n}, x \mapsto x \cdot L(x)$$ f L : F q n → F q n , x ↦ x · L ( x ) and show that, for $$n \le 5$$ n ≤ 5 , it is completely determined by the image of the rational function $$r_L :\mathbb {F}_{q^n}^* \rightarrow \mathbb {F}_{q^n}, x \mapsto L(x)/x$$ r L : F q n ∗ → F q n , x ↦ L ( x ) / x . This result follows from the classification of the pairs (L, M) of q-polynomials in $$\mathbb {F}_{q^n}[X]$$ F q n [ X ] , $$n \le 5$$ n ≤ 5 , for which $$r_L$$ r L and $$r_M$$ r M have the same image, obtained in Csajbók et al. (Ars Math Contemp 16(2):585–608, 2019). For the case of $$n>5$$ n > 5 , we pose an open question on the dimensions of the kernels of $$x \mapsto L(x) - ax$$ x ↦ L ( x ) - a x for $$a \in \mathbb {F}_{q^n}$$ a ∈ F q n . We further present a link between functions $$f_L$$ f L of differential uniformity bounded above by q and scattered q-polynomials and show that, for odd values of q, we can construct CCZ-inequivalent functions $$f_M$$ f M Christof Beierle |
Des. Codes Cryptogr. | 1 |
| 2023 | On Perfect Linear Approximations and Differentials over Two-Round SPNs
Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Lukas Stennes |
CRYPTO (3) | 1 |
| 2023 | Gold functions and switched cube functions are not 0-extendable in dimension n > 5abstractAbstract In the independent works by Kalgin and Idrisova and by Beierle, Leander and Perrin, it was observed that the Gold APN functions over $$\mathbb {F}_{2^5}$$ F 2 5 give rise to a quadratic APN function in dimension 6 having maximum possible linearity of $$2^5$$ 2 5 (that is, minimum possible nonlinearity $$2^4$$ 2 4 ). In this article, we show that the case of $$n \le 5$$ n ≤ 5 is quite special in the sense that Gold APN functions in dimension $$n>5$$ n > 5 cannot be extended to quadratic APN functions in dimension $$n+1$$ n + 1 having maximum possible linearity. In the second part of this work, we show that this is also the case for APN functions of the form $$x \mapsto x^3 + \mu (x)$$ x ↦ x 3 + μ ( x ) with $$\mu $$ μ being a quadratic Boolean function. Christof Beierle, Claude Carlet |
Des. Codes Cryptogr. | 1 |
| 2022 | Constructing and Deconstructing Intentional Weaknesses in Symmetric Ciphers
Christof Beierle, Tim Beyne, Patrick Felke, Gregor Leander |
CRYPTO (3) | 1 |
| 2022 | Trims and extensions of quadratic APN functionsabstractAbstract In this work, we study functions that can be obtained by restricting a vectorial Boolean function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n to an affine hyperplane of dimension $$n-1$$ n-1 and then projecting the output to an $$n-1$$ n-1 -dimensional space. We show that a multiset of $$2 \cdot (2^n-1)^2$$ 2·(2n-1)2 EA-equivalence classes of such restrictions defines an EA-invariant for vectorial Boolean functions on $$\mathbb {F}_{2}^n$$ F2n . Further, for all of the known quadratic APN functions in dimension $$n < 10$$ n<10 , we determine the restrictions that are also APN. Moreover, we construct 6368 new quadratic APN functions in dimension eight up to EA-equivalence by extending a quadratic APN function in dimension seven. A special focus of this work is on quadratic APN functions with maximum linearity. In particular, we characterize a quadratic APN function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n with linearity of $$2^{n-1}$$ 2n-1 by a property of the ortho-derivative of its restriction to a linear hyperplane. Using the fact that all quadratic APN functions in dimension seven are classified, we are able to obtain a classification of all quadratic 8-bit APN functions with linearity $$2^7$$ 27 up to EA-equivalence. Christof Beierle, Gregor Leander, Léo Perrin |
Des. Codes Cryptogr. | 1 |
| 2022 | Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo |
J. Cryptol. | 1 |
| 2022 | New Instances of Quadratic APN FunctionsabstractIn a recent work, Beierle, Brinkmann and Leander presented a recursive tree search for finding APN permutations with linear self-equivalences in small dimensions. In this paper, we describe how this search can be adapted to find many new instances of quadratic APN functions. In particular, we found 12,921 new quadratic APN functions in dimension eight, 35 new quadratic APN functions in dimension nine and five new quadratic APN functions in dimension ten up to CCZ-equivalence. Remarkably, two of the 35 new APN functions in dimension nine are APN permutations. Among the 8-bit APN functions, there are three extended Walsh spectra that do not correspond to any of the previously-known quadratic 8-bit APN functions and, surprisingly, there exist at least four CCZ-inequivalent 8-bit APN functions with linearity 27, i.e., the highest possible non-trivial linearity for quadratic functions in dimension eight. Christof Beierle, Gregor Leander |
IEEE Trans. Inf. Theory | 1 |
| 2021 | Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes |
EUROCRYPT (2) | 1 |
| 2021 | Linearly Self-Equivalent APN Permutations in Small DimensionabstractAll almost perfect nonlinear (APN) permutations that we know to date admit a special kind of linear self-equivalence, i.e., there exists a permutation G in their CCZ-equivalence class and two linear permutations A and B, such that G °A = B °G. After providing a survey on the known APN functions with a focus on the existence of self-equivalences, we search for APN permutations in dimension 6, 7, and 8 that admit such a linear self-equivalence. In dimension six, we were able to conduct an exhaustive search and obtain that there is only one such APN permutation up to CCZ-equivalence. In dimensions 7 and 8, we performed an exhaustive search for all but a few classes of linear self-equivalences and we did not find any new APN permutation. As one interesting result in dimension 7, we obtain that all APN permutation polynomials with coefficients in \mathbb F2must be (up to CCZ-equivalence) monomial functions. Christof Beierle, Marcus Brinkmann, Gregor Leander |
IEEE Trans. Inf. Theory | 1 |
| 2020 | Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001 |
CRYPTO (3) | 1 |
| 2020 | Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Gregor Leander, Yosuke Todo |
CRYPTO (3) | 1 |
| 2017 | Proving Resistance Against Invariant Attacks: How to Choose the Round Constants
Christof Beierle, Anne Canteaut, Gregor Leander, Yann Rotella |
CRYPTO (2) | 1 |
| 2016 | The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim |
CRYPTO (2) | 1 |
| 2016 | Lightweight Multiplication in GF(2^n) with Applications to MDS Matrices
Christof Beierle, Thorsten Kranz, Gregor Leander |
CRYPTO (1) | 1 |
| 2015 | Analyzing Permutations for AES-like Ciphers: Understanding ShiftRows
Christof Beierle, Philipp Jovanovic, Martin M. Lauridsen, Gregor Leander, Christian Rechberger |
CT-RSA | 1 |