EDBT 2026 Demo / reviewers in the wild / expert
Weiqiong Cao
dblp:176/9300
· DBLP profile ↗
9ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0000-2387-8332ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Secret in OnePiece: Single-Bit Fault Attack on Kyber
Jian Wang 0136, Weiqiong Cao, Hua Chen 0011 |
SAC | 2 |
| 2024 | Blink: Breaking Parallel Implementation of Crystals-Kyber with Side-Channel AttackabstractThe post-quantum key encapsulation mechanism, CRYSTALS-Kyber, has recently been selected by the National Institute of Standards and Technology (NIST) for standardization. Consequently, it becomes crucial to assess the resistance of CRYSTALS-Kyber implementations to physical attacks. While side-channel attacks on embedded software platforms have been well studied, this work introduces a novel attack on hardware implementations of CRYSTALS-Kyber. Initially, we propose a multi-ciphertext message recovery attack that is capable of extracting messages from side-channel measurements of parallel message encoding. Building upon this, we further develop a key recovery attack based on an optimal ciphertext-choosing strategy that maximizes key recovery accuracy, as well as a lattice reduction attack capable of solving the entire secret key even when confronted with an imperfect side-channel distinguisher. To evaluate the effectiveness of our attack, we conducted experiments on a Xilinx FPGA board. Our results demonstrate that our attack is capable of successfully recovering the secret key using 96 power traces, with a success rate of$100 \%$. This study reveals that parallel implementations remain vulnerable to sidechannel attacks, underscoring the necessity of additional analysis and countermeasures for lattice-based schemes implemented in parallel. Jian Wang 0136, Weiqiong Cao, Hua Chen 0011 |
ICCD | 2 |
| 2023 | Easily Overlooked Vulnerability in Implementation: Practical Fault Attack on ECDSA Round CounterabstractElliptic curve cryptographic is a widely used public-key cryptosystem. Though it has good theoretical security, it is still vulnerable to some physical attacks due to the implementation weakness. To resist the attacks, a number of physical countermeasures have been proposed. However, there are still some implementation vulnerabilities that may be overlooked, leading to more practical and effective attacks. In this article, we construct a new fault attack on round counter which is a component of scalar multiplications in ECDSA. The attack is divided into two parts. In the first part, the partial bits of nonce in each signature can be recovered by the fault injection on round counter. In the second part, an efficient lattice attack can be constructed to recover the private key by combining the recovered bits. Compared with other lattice-based fault attacks, our attack has the advantage of practicability and effectiveness. Especially, it has less requirement of moment precision and wide applicability of scalar multiplications, which is the critical factors for practicability and effectiveness. To verify the strength of our attack, we carry on the laser injection experiments, respectively, on an AVR MCU (ATmega163L) and a Kintex-7 FPGA (XC7K325T). The experimental results verify the practicability and effectiveness of the attack in both software and hardware platforms. Finally, we also propose two directions for efficient countermeasures against our attack. Hua Chen 0011, Xucang Han, Weiqiong Cao, Huilong Jiang, Jian Wang 0136 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2022 | Lattice-Based Fault Attacks on Deterministic Signature Schemes of ECDSA and EdDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen, Limin Fan, Wenling Wu |
CT-RSA | 1 |
| 2022 | Practical Side-Channel Attack on Message Encoding in Masked KyberabstractSince the message encoding in lattice-based schemes is vulnerable to side-channel attacks, a first-order masked message encoder has been proposed and applied to multiple masked implementations. However, the security of the masked encoder still lacks enough evaluation. In this paper, we investigate the security of the masked message encoder in a masked Kyber implementation. First, we give a detailed side-channel leakage analysis of the masked implementation in a specific platform, and we explain the technical challenges of designing a key recovery attack for the masked implementations. Even so, we still found a new 2-stage key recovery attack, which overcomes the difficulties and can recover the whole private key of the masked Kyber implementation with only 9 traces. In our experiments, we validate the attack on a Cortex-M4-based development board and the success rate of key recovery is almost up to 100% in 1000 experiments. According to the experiment results, the masked encoder can not prevent side-channel attacks efficiently and newer masking techniques are needed. Jian Wang 0136, Weiqiong Cao, Hua Chen 0011 |
TrustCom | 2 |
| 2021 | Lattice-Based Weak Curve Fault Attack on ECDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen |
SEC | 1 |
| 2021 | Do multiple infections lead to better security? A new study on CHES 2014 infective countermeasure
Jingyi Feng, Hua Chen 0011, Weiqiong Cao, Limin Fan, Dengguo Feng |
Sci. China Inf. Sci. | 3 |
| 2017 | My Traces Learn What You Did in the Dark: Recovering Secret Signals Without Key Guesses
Hua Chen 0011, Wenling Wu, Limin Fan, Weiqiong Cao, Xiangliang Ma |
CT-RSA | 5 |
| 2015 | Practical Lattice-Based Fault Attack and Countermeasure on SM2 Signature Algorithm
Weiqiong Cao, Jingyi Feng, Shaofeng Zhu, Hua Chen 0011, Wenling Wu, Xucang Han, Xiaoguang Zheng |
ICICS | 1 |