Yunwen Liu

dblp:162/8949 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
6since 2021 · last 2023
0000-0002-6487-9785ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 7 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2023 Rotational Differential-Linear Cryptanalysis Revisited
abstract
Abstract The differential-linear attack, combining the power of the two most effective techniques for symmetric-key cryptanalysis, was proposed by Langford and Hellman at CRYPTO 1994. From the exact formula for evaluating the bias of a differential-linear distinguisher (JoC 2017), to the differential-linear connectivity table technique for dealing with the dependencies in the switch between the differential and linear parts (EUROCRYPT 2019), and to the improvements in the context of cryptanalysis of ARX primitives (CRYPTO 2020, EUROCRYPT 2021), we have seen significant development of the differential-linear attack during the last four years. In this work, we further extend this framework by replacing the differential part of the attack by rotational-XOR differentials. Along the way, we establish the theoretical link between the rotational-XOR differential and linear approximations and derive the closed formula for the bias of rotational differential-linear distinguishers, completely generalizing the results on ordinary differential-linear distinguishers due to Blondeau, Leander, and Nyberg (JoC 2017) to the case of rotational differential-linear cryptanalysis. We then revisit the rotational cryptanalysis from the perspective of differential-linear cryptanalysis and generalize Morawiecki et al.’s technique for analyzing , which leads to a practical method for estimating the bias of a (rotational) differential-linear distinguisher in the special case where the output linear mask is a unit vector. Finally, we apply the rotational differential-linear technique to the cryptographic permutations involved in , , , and . This gives significant improvements over existing cryptanalytic results, or offers explanations for previous experimental distinguishers without a theoretical foundation. To confirm the validity of our analysis, all distinguishers with practical complexities are verified experimentally. Moreover, we discuss the possibility of applying the rotational differential-linear technique to S-box-based designs or keyed primitives, and propose some open problems for future research.
Yunwen Liu, Zhongfeng Niu, Siwei Sun, Chao Li 0002, Lei Hu 0003
J. Cryptol.1
2022 Rotational Differential-Linear Distinguishers of ARX Ciphers with Arbitrary Output Linear Masks
Zhongfeng Niu, Siwei Sun, Yunwen Liu, Chao Li 0002
CRYPTO (1)3
2022 Improved nonlinear invariant attack
Haipeng Tong, Xuan Shen, Chao Li 0002, Yunwen Liu
Sci. China Inf. Sci.4
2022 On the Effect of the Key-Expansion Algorithm in Simon-like Ciphers
abstract
Abstract In this work, we investigate how the choice of the key-expansion algorithm and its interaction with the round function affect the resistance of Simon-like ciphers against rotational-XOR cryptanalysis. We observe that, among the key-expansion algorithms we consider, Simon is most resistant, while Simeck is much less so. Implications on lightweight ciphers design are discussed and open questions are proposed.
Jinyu Lu, Yunwen Liu, Tomer Ashur, Chao Li 0002
Comput. J.2
2022 Improved rotational-XOR cryptanalysis of Simon-like block ciphers
abstract
Abstract Rotational‐XOR (RX) cryptanalysis is a cryptanalytic method aimed at finding distinguishable statistical properties in Addition‐Rotation‐XOR‐C ciphers, that is, ciphers that can be described only by using modular addition, cyclic rotation, XOR and the injection of constants. In this study, we extend RX‐cryptanalysis to AND‐RX ciphers, a similar design paradigm where the modular addition is replaced by vectorial bitwise AND; such ciphers include the block cipher families Simon and Simeck. We analyse the propagation of RX‐differences through AND‐RX rounds and develop a closed form formula for their expected probability. Inspired by the MILP verification model proposed by Sadeghi et al., we develop a SAT/SMT model for searching compatible RX‐characteristics in Simon‐like ciphers, that is, that there is at least one right pair of messages/keys to satisfy the RK‐characteristics. To the best of our knowledge, this is the first model that takes the RX‐difference transitions and value transitions simultaneously into account in Simon‐like ciphers. Meanwhile, we investigate how the choice of the round constants affects the resistance of Simon‐like ciphers against RX‐cryptanalysis. Finally, we show how to use an RX‐distinguisher for a key recovery attack. Evaluating our model we find compatible RX‐characteristics of up to 20, 27 and 34 rounds with respective probabilities of 2 −26 , 2 −44 and 2 −56 for versions of Simeck with block sizes of 32, 48 and 64 bits, respectively, for large classes of weak keys in the related‐key model. In most cases, these are the longest published distinguishers for the respective variants of Simeck. In the case of Simon, we present compatible RX‐characteristics for round‐reduced versions of all 10 instances. We observe that for equal block and key sizes, the RX‐distinguishers cover fewer rounds in Simon than in Simeck. Concluding the paper, we present a key recovery attack on Simeck 64 reduced to 28 rounds using a 23‐round RX‐characteristic.
Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002
IET Inf. Secur.2
2021 Rotational Cryptanalysis from a Differential-Linear Perspective - Practical Distinguishers for Round-Reduced FRIET, Xoodoo, and Alzette
Yunwen Liu, Siwei Sun, Chao Li 0002
EUROCRYPT (1)1
2020 Rotational-XOR Cryptanalysis of Simon-Like Block Ciphers
Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002
ACISP2
2020 The phantom of differential characteristics
Yunwen Liu, Wenying Zhang 0001, Bing Sun 0001, Vincent Rijmen, Chao Li 0002, Shaojing Fu, Meichun Cao
Des. Codes Cryptogr.1
2019 Related-Key Boomerang Attacks on GIFT with Automated Trail Search Including BCT Effect
Yunwen Liu, Yu Sasaki 0001
ACISP1
2019 Improved Cryptanalysis on SipHash
Wenqian Xin, Yunwen Liu, Bing Sun 0001, Chao Li 0002
CANS2
2018 Cryptanalysis of Reduced sLiSCP Permutation in Sponge-Hash and Duplex-AE Modes
Yunwen Liu, Yu Sasaki 0001, Ling Song 0001, Gaoli Wang
SAC1
2018 Impossible meet-in-the-middle fault analysis on the LED lightweight cipher in VANETs
Wei Li 0013, Vincent Rijmen, Qingju Wang 0001, Hua Chen 0011, Yunwen Liu, Chaoyun Li, Ya Liu 0001
Sci. China Inf. Sci.6
2018 Nonlinear diffusion layers
Yunwen Liu, Vincent Rijmen, Gregor Leander
Des. Codes Cryptogr.1
2018 New observations on invariant subspace attack
Yunwen Liu, Vincent Rijmen
Inf. Process. Lett.1
2016 Automatic Search of Linear Trails in ARX with Applications to SPECK and Chaskey
Yunwen Liu, Qingju Wang 0001, Vincent Rijmen
ACNS1
2016 Improved Fault Analysis on SIMON Block Cipher Family
abstract
SIMON is a new family of lightweight block ciphers proposed by the National Security Agency (NSA) in 2013. Since its publication, it has attracted much research interest and a number of analysis results have been presented. As a popular kind of implementation attack method, the fault attack also works when it is applied to SIMON. In this paper, we propose an effective fault attack on SIMON under the random byte fault model. Compared with the previous attack results, our attack can successfully recover the whole master key with injecting the faults into only one intermediate round for six instances of SIMON. In our attack, we fully utilize a class of differential propagation properties of SIMON to determine the fault injection position as long as the full diffusion of the fault has not been obtained. On the basis of it, we can recover the last round key with the differential analysis technique. The differential propagation properties make it possible to inject the faults into the earlier intermediate round at the beginning than that of the previous attacks. Meanwhile, the same faulty ciphertext set can also help to recover other round keys. So we do not have to inject the faults into any other intermediate rounds to reveal the whole master key. Moreover, in this paper we also give a detailed mathematical analysis on the average number of the fault injections under the random byte fault model. The data complexity analysis shows that less fault injections are required in our attack compared with other work under the same attack model. Finally, we also verify the effectiveness and correctness of our attack with experiments.
Hua Chen 0011, Jingyi Feng, Vincent Rijmen, Yunwen Liu, Limin Fan, Wei Li 0013
FDTC4
2015 Optimized Interpolation Attacks on LowMC
Itai Dinur, Yunwen Liu, Willi Meier, Qingju Wang 0001
ASIACRYPT (2)2