EDBT 2026 Demo / reviewers in the wild / expert
Gaëtan Leurent
dblp:30/1133
· DBLP profile ↗
62ranked-venue papers
22as first author
15since 2021 · last 2025
0000-0001-5903-9055ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 61 · 22 first-author · 15 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Transistor: a TFHE-Friendly Stream Cipher
Jules Baudrin, Sonia Belaïd, Nicolas Bon 0001, Christina Boura, Anne Canteaut, Gaëtan Leurent, Pascal Paillier, Léo Perrin, Matthieu Rivain, Yann Rotella, Samuel Tap |
CRYPTO (5) | 6 |
| 2025 | Cryptanalysis of Full SCARF
Antonio Flórez-Gutiérrez, Eran Lambooij, Gaëtan Leurent, Håvard Raddum, Tyge Tiessen, Michiel Verbauwhede |
EUROCRYPT (1) | 3 |
| 2025 | New Representations of the AES Key Schedule
Gaëtan Leurent, Clara Pernot |
J. Cryptol. | 1 |
| 2024 | Cryptanalysis of Algebraic Verifiable Delay Functions
Alex Biryukov, Ben Fisch, Gottfried Herold, Dmitry Khovratovich, Gaëtan Leurent, María Naya-Plasencia, Benjamin Wesolowski |
CRYPTO (3) | 5 |
| 2024 | Improving Generic Attacks Using Exceptional Functions
Xavier Bonnetain, Rachelle Heim Boissier, Gaëtan Leurent, André Schrottenloher |
CRYPTO (4) | 3 |
| 2024 | Partial Sums Meet FFT: Improved Attack on 6-Round AES
Orr Dunkelman, Shibam Ghosh, Nathan Keller, Gaëtan Leurent, Avichai Marmor, Victor Mollimard |
EUROCRYPT (1) | 4 |
| 2023 | Truncated Boomerang Attacks and Application to AES-Based Ciphers
Augustin Bariant, Gaëtan Leurent |
EUROCRYPT (4) | 2 |
| 2022 | Practical key recovery attacks on FlexAEAD
Orr Dunkelman, Maria Eichlseder, Daniel Kales, Nathan Keller, Gaëtan Leurent, Markus Schofnegger |
Des. Codes Cryptogr. | 5 |
| 2021 | QCB: Efficient Quantum-Secure Authenticated Encryption
Ritam Bhaumik, Xavier Bonnetain, André Chailloux, Gaëtan Leurent, María Naya-Plasencia, André Schrottenloher, Yannick Seurin |
ASIACRYPT (1) | 4 |
| 2021 | Quantum Linearization Attacks
Xavier Bonnetain, Gaëtan Leurent, María Naya-Plasencia, André Schrottenloher |
ASIACRYPT (1) | 2 |
| 2021 | Clustering Effect in Simon and Simeck
Gaëtan Leurent, Clara Pernot, André Schrottenloher |
ASIACRYPT (1) | 1 |
| 2021 | On the Cost of ASIC Hardware Crackers: A SHA-1 Case Study
Anupam Chattopadhyay, Mustafa Khairallah, Gaëtan Leurent, Zakaria Najm, Thomas Peyrin, Vesselin Velichkov |
CT-RSA | 3 |
| 2021 | Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes |
EUROCRYPT (2) | 4 |
| 2021 | New Representations of the AES Key Schedule
Gaëtan Leurent, Clara Pernot |
EUROCRYPT (1) | 1 |
| 2021 | Internal Symmetries and Linear Properties: Full-permutation Distinguishers and Improved Collisions on Gimli
Antonio Flórez-Gutiérrez, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, André Schrottenloher, Ferdinand Sibleyras |
J. Cryptol. | 2 |
| 2020 | New Results on Gimli: Full-Permutation Distinguishers and Improved Collisions
Antonio Flórez-Gutiérrez, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, André Schrottenloher, Ferdinand Sibleyras |
ASIACRYPT (1) | 2 |
| 2020 | Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer |
CRYPTO (3) | 6 |
| 2020 | Universal Forgery Attack Against GCM-RUP
Gaëtan Leurent, Meiqin Wang 0001, Wei Wang 0035, Guoyan Zhang |
CT-RSA | 2 |
| 2020 | SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of Trust
Gaëtan Leurent, Thomas Peyrin |
USENIX Security Symposium | 1 |
| 2020 | Generic Attacks on Hash CombinersabstractHash combiners are a practical way to make cryptographic hash functions more tolerant to future attacks and compatible with existing infrastructure. A combiner combines two or more hash functions in a way that is hopefully more secure than each of the underlying hash functions, or at least remains secure as long as one of them is secure. Two classical hash combiners are the exclusive-or (XOR) combiner \( \mathcal {H}_1(M) \oplus \mathcal {H}_2(M) \) and the concatenation combiner \( \mathcal {H}_1(M) \Vert \mathcal {H}_2(M) \) . Both of them process the same message using the two underlying hash functions in parallel. Apart from parallel combiners, there are also cascade constructions sequentially calling the underlying hash functions to process the message repeatedly, such as Hash-Twice \(\mathcal {H}_2(\mathcal {H}_1(IV, M), M)\) and the Zipper hash \(\mathcal {H}_2(\mathcal {H}_1(IV, M), \overleftarrow{M})\) , where \(\overleftarrow{M}\) is the reverse of the message M . In this work, we study the security of these hash combiners by devising the best-known generic attacks. The results show that the security of most of the combiners is not as high as commonly believed. We summarize our attacks and their computational complexities (ignoring the polynomial factors) as follows: Several generic preimage attacks on the XOR combiner: A first attack with a best-case complexity of \( 2^{5n/6} \) obtained for messages of length \( 2^{n/3} \) . It relies on a novel technical tool named interchange structure. It is applicable for combiners whose underlying hash functions follow the Merkle–Damgård construction or the HAIFA framework. A second attack with a best-case complexity of \( 2^{2n/3} \) obtained for messages of length \( 2^{n/2} \) . It exploits properties of functional graphs of random mappings. It achieves a significant improvement over the first attack but is only applicable when the underlying hash functions use the Merkle–Damgård construction. An improvement upon the second attack with a best-case complexity of \( 2^{5n/8} \) obtained for messages of length \( 2^{5n/8} \) . It further exploits properties of functional graphs of random mappings and uses longer messages. These attacks show a rather surprising result: regarding preimage resistance, the sum of two n -bit narrow-pipe hash functions following the considered constructions can never provide n -bit security. A generic second-preimage attack on the concatenation combiner of two Merkle–Damgård hash functions. This attack finds second preimages faster than \( 2^n \) for challenges longer than \( 2^{2n/7} \) and has a best-case complexity of \( 2^{3n/4} \) obtained for challenges of length \( 2^{3n/4} \) . It also exploits properties of functional graphs of random mappings. The first generic second-preimage attack on the Zipper hash with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{3n/5} \) , obtained for challenge messages of length \( 2^{2n/5} \) . An improved generic second-preimage attack on Hash-Twice with underlying hash functions following the Merkle–Damgård construction. The best-case complexity is \( 2^{13n/22} \) , obtained for challenge messages of length \( 2^{13n/22} \) . The last three attacks show that regarding second-preimage resistance, the concatenation and cascade of two n -bit narrow-pipe Merkle–Damgård hash functions do not provide much more security than that can be provided by a single n -bit hash function. Our main technical contributions include the following: The interchange structure, which enables simultaneously controlling the behaviours of two hash computations sharing the same input. The simultaneous expandable message, which is a set of messages of length covering a whole appropriate range and being multi-collision for both of the underlying hash functions. New ways to exploit the properties of functional graphs of random mappings generated by fixing the message block input to the underlying compression functions. Zhenzhen Bao, Itai Dinur, Jian Guo 0001, Gaëtan Leurent, Lei Wang 0031 |
J. Cryptol. | 4 |
| 2019 | Lightweight MACs from Universal Hash Functions
Sébastien Duval, Gaëtan Leurent |
CARDIS | 2 |
| 2019 | Low-Memory Attacks Against Two-Round Even-Mansour Using the 3-XOR Problem
Gaëtan Leurent, Ferdinand Sibleyras |
CRYPTO (2) | 1 |
| 2019 | From Collisions to Chosen-Prefix Collisions Application to Full SHA-1
Gaëtan Leurent, Thomas Peyrin |
EUROCRYPT (3) | 1 |
| 2018 | Cryptanalysis of MORUS
Tomer Ashur, Maria Eichlseder, Martin M. Lauridsen, Gaëtan Leurent, Brice Minaud, Yann Rotella, Yu Sasaki 0001, Benoît Viguier |
ASIACRYPT (2) | 4 |
| 2018 | Generic Attacks Against Beyond-Birthday-Bound MACs
Gaëtan Leurent, Mridul Nandi, Ferdinand Sibleyras |
CRYPTO (1) | 1 |
| 2018 | The Missing Difference Problem, and Its Applications to Counter Mode Encryption
Gaëtan Leurent, Ferdinand Sibleyras |
EUROCRYPT (2) | 1 |
| 2017 | Improved Generic Attacks Against Hash-Based MACs and HAIFA
Itai Dinur, Gaëtan Leurent |
Algorithmica | 2 |
| 2016 | On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNabstractWhile modern block ciphers, such as AES, have a block size of at least 128 bits, there are many 64-bit block ciphers, such as 3DES and Blowfish, that are still widely supported in Internet security protocols such as TLS, SSH, and IPsec. When used in CBC mode, these ciphers are known to be susceptible to collision attacks when they are used to encrypt around 232 blocks of data (the so-called birthday bound). This threat has traditionally been dismissed as impractical since it requires some prior knowledge of the plaintext and even then, it only leaks a few secret bits per gigabyte. Indeed, practical collision attacks have never been demonstrated against any mainstream security protocol, leading to the continued use of 64-bit ciphers on the Internet. Karthikeyan Bhargavan, Gaëtan Leurent |
CCS | 2 |
| 2016 | Breaking Symmetric Cryptosystems Using Quantum Period Finding
Marc Kaplan, Gaëtan Leurent, Anthony Leverrier, María Naya-Plasencia |
CRYPTO (2) | 2 |
| 2016 | Improved Differential-Linear Cryptanalysis of 7-Round Chaskey with Partitioning
Gaëtan Leurent |
EUROCRYPT (1) | 1 |
| 2016 | Key Recovery Attack Against 2.5-Round \pi -Cipher
Christina Boura, Avik Chakraborti, Gaëtan Leurent, Goutam Paul 0001, Dhiman Saha, Hadi Soleimany, Valentin Suder |
FSE | 3 |
| 2016 | Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSH
Karthikeyan Bhargavan, Gaëtan Leurent |
NDSS | 2 |
| 2015 | Collision Attacks Against CAESAR Candidates - Forgery and Key-Recovery Against AEZ and Marble
Thomas Fuhr 0001, Gaëtan Leurent, Valentin Suder |
ASIACRYPT (2) | 2 |
| 2015 | The Sum Can Be Weaker Than Each Part
Gaëtan Leurent, Lei Wang 0031 |
EUROCRYPT (1) | 1 |
| 2015 | Cryptanalysis of Feistel Networks with Secret Round Functions
Alex Biryukov, Gaëtan Leurent, Léo Perrin |
SAC | 2 |
| 2015 | Construction of Lightweight S-Boxes Using Feistel and MISTY Structures
Anne Canteaut, Sébastien Duval, Gaëtan Leurent |
SAC | 3 |
| 2015 | Differential Forgery Attack Against LAC
Gaëtan Leurent |
SAC | 1 |
| 2014 | FPGA Implementations of SPRING - And Their Countermeasures against Side-Channel Attacks
Hai Brenner, Lubos Gaspar, Gaëtan Leurent, Alon Rosen, François-Xavier Standaert |
CHES | 3 |
| 2014 | Improved Generic Attacks against Hash-Based MACs and HAIFA
Itai Dinur, Gaëtan Leurent |
CRYPTO (1) | 2 |
| 2014 | Hardware Implementation and Side-Channel Analysis of Lapin
Lubos Gaspar, Gaëtan Leurent, François-Xavier Standaert |
CT-RSA | 2 |
| 2014 | SPRING: Fast Pseudorandom Functions from Rounded Ring Products
Abhishek Banerjee 0001, Hai Brenner, Gaëtan Leurent, Chris Peikert, Alon Rosen |
FSE | 3 |
| 2014 | LS-Designs: Bitslice Encryption for Efficient Masked Software Implementations
Vincent Grosso, Gaëtan Leurent, François-Xavier Standaert, Kerem Varici |
FSE | 2 |
| 2014 | The Usage of Counter Revisited: Second-Preimage Attack on New Russian Standardized Hash Function
Jian Guo 0001, Jérémy Jean, Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031 |
Selected Areas in Cryptography | 3 |
| 2013 | New Generic Attacks against Hash-Based MACs
Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031 |
ASIACRYPT (2) | 1 |
| 2013 | Construction of Differential Characteristics in ARX Designs Application to Skein
Gaëtan Leurent |
CRYPTO (1) | 1 |
| 2013 | Cryptanalysis of WIDEA
Gaëtan Leurent |
FSE | 1 |
| 2013 | Time-Memory Trade-Offs for Near-Collisions
Gaëtan Leurent |
FSE | 1 |
| 2012 | Analysis of Differential Attacks in ARX Constructions
Gaëtan Leurent |
ASIACRYPT | 1 |
| 2012 | Boomerang Attacks on Hash Function Using Auxiliary Differentials
Gaëtan Leurent, Arnab Roy 0005 |
CT-RSA | 1 |
| 2012 | Narrow-Bicliques: Cryptanalysis of Full IDEA
Dmitry Khovratovich, Gaëtan Leurent, Christian Rechberger |
EUROCRYPT | 2 |
| 2012 | Cryptanalysis of the "Kindle" Cipher
Alex Biryukov, Gaëtan Leurent, Arnab Roy 0005 |
Selected Areas in Cryptography | 2 |
| 2011 | Practical Near-Collisions on the Compression Function of BMW
Gaëtan Leurent, Søren S. Thomsen |
FSE | 1 |
| 2010 | Practical Key Recovery Attack against Secret-IV Edon-
Gaëtan Leurent |
CT-RSA | 1 |
| 2010 | Another Look at Complementation Properties
Charles Bouillaguet, Orr Dunkelman, Gaëtan Leurent, Pierre-Alain Fouque |
FSE | 3 |
| 2010 | Cryptanalysis of ESSENCE
María Naya-Plasencia, Andrea Röck, Jean-Philippe Aumasson, Yann Laigle-Chapuy, Gaëtan Leurent, Willi Meier, Thomas Peyrin |
FSE | 5 |
| 2009 | Practical Electromagnetic Template Attack on HMAC
Pierre-Alain Fouque, Gaëtan Leurent, Denis Réal, Frédéric Valette |
CHES | 2 |
| 2009 | How Risky Is the Random-Oracle Model?
Gaëtan Leurent, Phong Q. Nguyen |
CRYPTO | 1 |
| 2008 | Cryptanalysis of a Hash Function Based on Quasi-cyclic Codes
Pierre-Alain Fouque, Gaëtan Leurent |
CT-RSA | 2 |
| 2008 | MD4 is Not One-Way
Gaëtan Leurent |
FSE | 1 |
| 2007 | Full Key-Recovery Attacks on HMAC/NMAC-MD4 and NMAC-MD5
Pierre-Alain Fouque, Gaëtan Leurent, Phong Q. Nguyen |
CRYPTO | 2 |
| 2007 | Message Freedom in MD4 and MD5 Collisions: Application to APOP
Gaëtan Leurent |
FSE | 1 |
| 2005 | An Analysis of the XSL Algorithm
Carlos Cid, Gaëtan Leurent |
ASIACRYPT | 2 |