Tung Chou

dblp:21/8341 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
3since 2021 · last 2025
0000-0003-3043-6190ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 5 first-author · 3 since 2021
YearPublicationVenuePosition
2025 On linear equivalence, canonical forms, and digital signatures
Tung Chou, Edoardo Persichetti, Paolo Santini
Des. Codes Cryptogr.1
2024 CryptAttackTester: high-assurance attack analysis
Daniel J. Bernstein, Tung Chou
CRYPTO (6)2
2024 Reducing Signature Size of Matrix-Code-Based Signature Schemes
Tung Chou, Ruben Niederhagen, Lars Ran, Simona Samardjiska
PQCrypto (1)1
2017 McBits Revisited
Tung Chou
CHES1
2016 QcBits: Constant-Time Small-Key Code-Based Cryptography
Tung Chou
CHES1
2015 Sandy2x: New Curve25519 Speed Records
Tung Chou
SAC1
2014 Faster Binary-Field Multiplication and Faster Binary-Field MACs
abstract
This paper shows how to securely authenticate messages using just $$29$$ bit operations per authenticated bit, plus a constant overhead per message. The authenticator is a standard type of “universal” hash function providing information-theoretic security; what is new is computing this type of hash function at very high speed. At a lower level, this paper shows how to multiply two elements of a field of size $$2^{128}$$ using just $$9062 \approx 71\,\cdot \, 128$$ bit operations, and how to multiply two elements of a field of size $$2^{256}$$ using just $$22164 \approx 87\,\cdot \, 256$$ bit operations. This performance relies on a new representation of field elements and new FFT-based multiplication techniques. This paper’s constant-time software uses just 1.89 Core 2 cycles per byte to authenticate very long messages. On a Sandy Bridge it takes 1.43 cycles per byte, without using Intel’s PCLMULQDQ polynomial-multiplication hardware. This is much faster than the speed records for constant-time implementations of GHASH without PCLMULQDQ (over 10 cycles/byte), even faster than Intel’s best Sandy Bridge implementation of GHASH with PCLMULQDQ (1.79 cycles/byte), and almost as fast as state-of-the-art 128-bit prime-field MACs using Intel’s integer-multiplication hardware (around 1 cycle/byte).
Daniel J. Bernstein, Tung Chou
Selected Areas in Cryptography2
2013 McBits: Fast Constant-Time Code-Based Cryptography
abstract
This paper presents extremely fast algorithms for code-based public-key cryptography, including full protection against timing attacks. For example, at a 2 128 security level, this paper achieves a reciprocal decryption throughput of just 60493 cycles (plus cipher cost etc.) on a single Ivy Bridge core. These algorithms rely on an additive FFT for fast root computation, a transposed additive FFT for fast syndrome computation, and a sorting network to avoid cache-timing attacks.
Daniel J. Bernstein, Tung Chou, Peter Schwabe
CHES2
2013 Fast Exhaustive Search for Quadratic Systems in $$\mathbb {F}_{2}$$ on FPGAs
Charles Bouillaguet, Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Bo-Yin Yang
Selected Areas in Cryptography3
2012 Solving Quadratic Equations with XL on Parallel Architectures
Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Bo-Yin Yang
CHES2
2010 Fast Exhaustive Search for Polynomial Systems in F2
Charles Bouillaguet, Hsieh-Chung Chen, Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Adi Shamir, Bo-Yin Yang
CHES4