Meicheng Liu

dblp:25/7479 · DBLP profile ↗
← Back
36ranked-venue papers
12as first author
14since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 7 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 1 since 2021Theory of computation · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5
Jian Guo 0001, Meicheng Liu, Shichang Wang, Tianyu Zhang 0004
EUROCRYPT3
2026 BONC: a framework for automatic cryptanalysis using the implementation code
abstract
Abstract The security analysis of symmetric ciphers is a time-consuming and labor-intensive process that traditionally relies on manual derivation and mathematical modeling for specific algorithms. This paper introduces a fully automated analysis software framework designed to evaluate the security of any round-based symmetric cipher constructed from common primitives like S-boxes, bit permutations, and XOR operations. Our approach leverages the LLVM compiler infrastructure and the KLEE symbolic execution engine to automatically convert C implementations of cryptographic algorithms into a structured representation of state bits and update functions. By employing a frontend that uses custom annotations to identify round functions, it translates the algorithm into a series of Bit Expressions, and we introduce multiple modular backends that process those Expressions to applicable form of performing various types of analyzing methods. We demonstrate the tool’s effectiveness by implementing a differential and linear cryptanalysis backend with help of SAT solver, Division Property integral cryptanalysis backend with help of MILP solver, and a degree estimation backend based on Numeric Mapping method. As an experimental result, we apply these automated analysis techniques to several finalists from the NIST Lightweight Cryptography (LWC) competition, successfully reproducing and improving some existing cryptanalytic results. This work significantly lowers the barrier for cryptographic research by providing a powerful and adaptable platform for automatically assessing the security of both existing and newly designed symmetric ciphers.
Meicheng Liu
Cybersecur.2
2026 Differential-Linear Cryptanalysis from an Algebraic Perspective
Meicheng Liu, Chengan Hou, Xiaojuan Lu, Shichang Wang, Dongdai Lin
J. Cryptol.1
2025 Preimage Attacks on up to 5 Rounds of SHA-3 Using Internal Differentials
Chengan Hou, Meicheng Liu
EUROCRYPT (1)3
2024 Probabilistic Linearization: Internal Differential Collisions in up to 6 Rounds of SHA-3
Chengan Hou, Meicheng Liu
CRYPTO (4)3
2023 Moving a Step of ChaCha in Syncopated Rhythm
Shichang Wang, Meicheng Liu, Shiqi Hou, Dongdai Lin
CRYPTO (3)2
2023 Collision Attacks on Round-Reduced SHA-3 Using Conditional Internal Differentials
Chengan Hou, Meicheng Liu
EUROCRYPT (4)3
2023 On Grain-Like Small State Stream Ciphers Against Fast Correlation Attacks: Cryptanalysis of Plantlet, Fruit-v2 and Fruit-80
abstract
Abstract The fast correlation attack (FCA) is one of the most important cryptanalytic techniques against LFSR-based stream ciphers. In CRYPTO 2018, Todo et al. found a new property for the FCA and proposed a novel algorithm which was successfully applied to the Grain family of stream ciphers. Nevertheless, these techniques cannot be directly applied to Grain-like small state stream ciphers with keyed update, such as Plantlet, Fruit-v2 and Fruit80. In this paper, we study the security of Grain-like small state stream ciphers by the FCA. We first observe that the number of required parity-check equations can be reduced when there are multiple different parity-check equations. With exploiting the Skellam distribution, we introduce a sufficient condition to identify the correct LFSR initial state and derive a new relationship between the number and bias of the required parity-check equations. Then, a modified algorithm is presented based on this new relationship, which can recover the LFSR initial state no matter what the round key bits are. Under the condition that the LFSR initial state is known, an algorithm is given against the degraded system and to recover the NFSR state at some time instant, along with the round key bits. As cases study, we apply our cryptanalytic techniques to Plantlet, Fruit-v2 and Fruit-80. As a result, for Plantlet, our attack takes $ 2^{73.75} $ time complexity and $ 2^{73.06} $ keystream bits to recover the full 80-bit key. Regarding Fruit-v2, $ 2^{55.34} $ time complexity and $ 2^{55.62} $ keystream bits are needed to determine the secret key. As for Fruit-80, $2^{64.47}$ time complexity and $2^{62.82}$ keystream bits are required to recover the secret key. More flexible attacks can be obtained with lower data complexity at the cost of increasing the attack time. Especially, for Fruit-v2, a key recovery attack can be launched with data complexity of $2^{42.38}$ and time complexity of $2^{73.31}$. Moreover, we have implemented our attack methods on a toy version of Fruit-v2. The attack matches the expected complexities predicted by our theoretical analysis quite well, which proves the validity of our cryptanalytic techniques.
Shichang Wang, Meicheng Liu, Dongdai Lin
Comput. J.2
2022 Enhancing Differential-Neural Cryptanalysis
Zhenzhen Bao, Jian Guo 0001, Meicheng Liu
ASIACRYPT (1)3
2022 Cryptanalysis of Ciminion
Meicheng Liu, Dongdai Lin
Inscrypt2
2022 A Three-Stage MITM Attack on LowMC from a Single Plaintext-Ciphertext Pair
Meicheng Liu, Dongdai Lin
SAC2
2022 Improved conditional differential attacks on lightweight hash family QUARK
abstract
Abstract Nonlinear feedback shift register (NFSR) is one of the most important cryptographic primitives in lightweight cryptography. At ASIACRYPT 2010, Knellwolf et al. proposed conditional differential attack to perform a cryptanalysis on NFSR-based cryptosystems. The main idea of conditional differential attack is to restrain the propagation of the difference and obtain a detectable bias of the difference of the output bit. QUARK is a lightweight hash function family which is designed by Aumasson et al. at CHES 2010. Then the extended version of QUARK was published in Journal of Cryptology 2013. In this paper, we propose an improved conditional differential attack on QUARK. One improvement is that we propose a method to select the input difference. We could obtain a set of good input differences by this method. Another improvement is that we propose an automatic condition imposing algorithm to deal with the complicated conditions efficiently and easily. It is shown that with the improved conditional differential attack on QUARK, we can detect the bias of output difference at a higher round of QUARK. Compared to the current literature, we find a distinguisher of U-QUARK/D-QUARK/S-QUARK/C-QUARK up to 157/171/292/460 rounds with increasing 2/5/33/8 rounds respectively. We have performed the attacks on each instance of QUARK on a 3.30 GHz Intel Core i5 CPU, and all these attacks take practical complexities which have been fully verified by our experiments. As far as we know, all of these results have been the best thus far.
Xiaojuan Lu, Bohan Li 0004, Meicheng Liu, Dongdai Lin
Cybersecur.3
2021 Differential-Linear Cryptanalysis of the Lightweight Crytographic Algorithm KNOT
Shichang Wang, Shiqi Hou, Meicheng Liu, Dongdai Lin
Inscrypt3
2021 Differential-Linear Cryptanalysis from an Algebraic Perspective
Meicheng Liu, Xiaojuan Lu, Dongdai Lin
CRYPTO (3)1
2020 Practical Collision Attacks against Round-Reduced SHA-3
Jian Guo 0001, Guohong Liao, Guozhen Liu, Meicheng Liu, Kexin Qiao, Ling Song 0001
J. Cryptol.4
2019 Cube Cryptanalysis of Round-Reduced ACORN
Jingchun Yang, Meicheng Liu, Dongdai Lin
ISC2
2018 Correlation Cube Attacks: From Weak-Key Distinguisher to Key Recovery
Meicheng Liu, Jingchun Yang, Wenhao Wang 0001, Dongdai Lin
EUROCRYPT (2)1
2018 Conditional Cube Searching and Applications on Trivium-Variant Ciphers
Xiaojuan Zhang 0003, Meicheng Liu, Dongdai Lin
ISC2
2017 Degree Evaluation of NFSR-Based Cryptosystems
Meicheng Liu
CRYPTO (3)1
2017 New Collision Attacks on Round-Reduced Keccak
Kexin Qiao, Ling Song 0001, Meicheng Liu, Jian Guo 0001
EUROCRYPT (3)3
2017 A distinguisher on PRESENT-like permutations with application to SPONGENT
Guoyan Zhang, Meicheng Liu
Sci. China Inf. Sci.2
2017 Results on highly nonlinear Boolean functions with provably good immunity to fast algebraic attacks
Meicheng Liu, Dongdai Lin
Inf. Sci.1
2016 Linear Structures: Applications to Cryptanalysis of Round-Reduced Keccak
Jian Guo 0001, Meicheng Liu, Ling Song 0001
ASIACRYPT (1)2
2016 New Insights on AES-Like SPN Ciphers
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Longjiang Qu, Vincent Rijmen
CRYPTO (1)2
2016 Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Vincent Rijmen, Ruilin Li 0002
EUROCRYPT (1)2
2016 Lightweight MDS Generalized Circulant Matrices
Meicheng Liu, Siang Meng Sim
FSE1
2015 A New Classification of 4-bit Optimal S-boxes and Its Application to PRESENT, RECTANGLE and SPONGENT
Zhenzhen Bao, Vincent Rijmen, Meicheng Liu
FSE4
2015 Searching cubes for testing Boolean functions and its application to Trivium
abstract
In this paper, we describe a sub-maximal degree monomial test and propose a heuristic algorithm for searching favourable cubes, for testing Boolean functions formed by stream ciphers. We apply them to Trivium, and mount a distinguisher on Trivium reduced to 839 rounds with 237complexity, which is so far the best distinguisher on reduced Trivium.
Meicheng Liu, Dongdai Lin, Wenhao Wang 0001
ISIT1
2015 Construction of cubic rotation symmetric bent functions in power-of-two variables
abstract
In this paper, we for the first time construct three cubic rotation symmetric bent functions in 2k+3, k ≥ 0, variables. Our work solves the open problem left by Gao et al. (IEEE TIT 58(7): 4908–4913, 2012).
Tianze Wang, Meicheng Liu, Shangwei Zhao, Dongdai Lin
ISIT2
2014 Almost perfect algebraic immune functions with good nonlinearity
abstract
In this paper, it is proven that a family of 2k-variable Boolean functions, including the function recently constructed by Tang et al. [IEEE TIT 59(1): 653-664, 2013], are almost perfect algebraic immune for any integer k ≥ 3. More exactly, they achieve optimal algebraic immunity and almost perfect immunity to fast algebraic attacks. The functions of such family are balanced and have optimal algebraic degree. A lower bound on their nonlinearity is obtained based on the work of Tang et al., which is better than that of Carlet-Feng function. It is also checked for 3 ≤ k ≤ 9 that the exact nonlinearity of such functions is very good, which is slightly smaller than that of Carlet-Feng function, and some functions of this family even have a slightly larger nonlinearity than Tang et al.'s function. To sum up, among the known functions with provable good immunity against fast algebraic attacks, the functions of this family make a trade-off between the exact value and the lower bound of nonlinearity.
Meicheng Liu, Dongdai Lin
ISIT1
2014 On the immunity of rotation symmetric Boolean functions against fast algebraic attacks
Meicheng Liu, Dongdai Lin
Discret. Appl. Math.2
2012 Perfect Algebraic Immune Functions
Meicheng Liu, Dongdai Lin
ASIACRYPT1
2012 Construction of Resilient and Nonlinear Boolean Functions with Almost Perfect Immunity to Algebraic and Fast Algebraic Attacks
Tianze Wang, Meicheng Liu, Dongdai Lin
Inscrypt2
2011 Results on the Immunity of Boolean Functions against Probabilistic Algebraic Attacks
Meicheng Liu, Dongdai Lin, Dingyi Pei
ACISP1
2011 Fast Algebraic Attacks and Decomposition of Symmetric Boolean Functions
abstract
In this correspondence, first we give a decomposition of symmetric Boolean functions, then we show that almost all symmetric Boolean functions, including these functions with good algebraic immunity, behave badly against fast algebraic attacks. Besides, we improve the relations between algebraic degree and algebraic immunity of symmetric Boolean functions.
Meicheng Liu, Dongdai Lin, Dingyi Pei
IEEE Trans. Inf. Theory1
2010 Identification and construction of Boolean functions with maximum algebraic immunity
Meicheng Liu, Dingyi Pei, Yusong Du
Sci. China Inf. Sci.1