EDBT 2026 Demo / reviewers in the wild / expert
Tung Chou
dblp:21/8341
· DBLP profile ↗
11ranked-venue papers
5as first author
3since 2021 · last 2025
0000-0003-3043-6190ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | On linear equivalence, canonical forms, and digital signatures
Tung Chou, Edoardo Persichetti, Paolo Santini |
Des. Codes Cryptogr. | 1 |
| 2024 | CryptAttackTester: high-assurance attack analysis
Daniel J. Bernstein, Tung Chou |
CRYPTO (6) | 2 |
| 2024 | Reducing Signature Size of Matrix-Code-Based Signature Schemes
Tung Chou, Ruben Niederhagen, Lars Ran, Simona Samardjiska |
PQCrypto (1) | 1 |
| 2017 | McBits Revisited
Tung Chou |
CHES | 1 |
| 2016 | QcBits: Constant-Time Small-Key Code-Based Cryptography
Tung Chou |
CHES | 1 |
| 2015 | Sandy2x: New Curve25519 Speed Records
Tung Chou |
SAC | 1 |
| 2014 | Faster Binary-Field Multiplication and Faster Binary-Field MACsabstractThis paper shows how to securely authenticate messages using just $$29$$ bit operations per authenticated bit, plus a constant overhead per message. The authenticator is a standard type of “universal” hash function providing information-theoretic security; what is new is computing this type of hash function at very high speed. At a lower level, this paper shows how to multiply two elements of a field of size $$2^{128}$$ using just $$9062 \approx 71\,\cdot \, 128$$ bit operations, and how to multiply two elements of a field of size $$2^{256}$$ using just $$22164 \approx 87\,\cdot \, 256$$ bit operations. This performance relies on a new representation of field elements and new FFT-based multiplication techniques. This paper’s constant-time software uses just 1.89 Core 2 cycles per byte to authenticate very long messages. On a Sandy Bridge it takes 1.43 cycles per byte, without using Intel’s PCLMULQDQ polynomial-multiplication hardware. This is much faster than the speed records for constant-time implementations of GHASH without PCLMULQDQ (over 10 cycles/byte), even faster than Intel’s best Sandy Bridge implementation of GHASH with PCLMULQDQ (1.79 cycles/byte), and almost as fast as state-of-the-art 128-bit prime-field MACs using Intel’s integer-multiplication hardware (around 1 cycle/byte). Daniel J. Bernstein, Tung Chou |
Selected Areas in Cryptography | 2 |
| 2013 | McBits: Fast Constant-Time Code-Based CryptographyabstractThis paper presents extremely fast algorithms for code-based public-key cryptography, including full protection against timing attacks. For example, at a 2 128 security level, this paper achieves a reciprocal decryption throughput of just 60493 cycles (plus cipher cost etc.) on a single Ivy Bridge core. These algorithms rely on an additive FFT for fast root computation, a transposed additive FFT for fast syndrome computation, and a sorting network to avoid cache-timing attacks. Daniel J. Bernstein, Tung Chou, Peter Schwabe |
CHES | 2 |
| 2013 | Fast Exhaustive Search for Quadratic Systems in $$\mathbb {F}_{2}$$ on FPGAs
Charles Bouillaguet, Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Bo-Yin Yang |
Selected Areas in Cryptography | 3 |
| 2012 | Solving Quadratic Equations with XL on Parallel Architectures
Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Bo-Yin Yang |
CHES | 2 |
| 2010 | Fast Exhaustive Search for Polynomial Systems in F2
Charles Bouillaguet, Hsieh-Chung Chen, Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Adi Shamir, Bo-Yin Yang |
CHES | 4 |