EDBT 2026 Demo / reviewers in the wild / expert
Qinggan Fu
dblp:358/0189
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0002-3095-5954ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Preimage and collision attacks on reduced Ascon using algebraic strategiesabstractAbstract Ascon, a family of algorithms that supports hashing and authenticated encryption, is the winner of the NIST Lightweight Cryptography Project. In this paper, we propose an improved preimage attack against 2-round Ascon-XOF-64 with a complexity of $$2^{33}$$ 2 33 via a more effective guessing strategy. Furthermore, we successfully extend our preimage attack on 2-round Ascon-XOF-64 to 2-round Ascon-XOF-128, achieving a complexity of $$2^{97}$$ 2 97 , which is currently the best preimage attack against 2-round Ascon-XOF-128. Apart from the preimage attack, we also investigate the resistance of Ascon-HASH against collision attacks. To be specific, we introduce the linearization of the inverse of S-boxes and then propose a free-start collision attack on 3-round Ascon-HASH with a complexity of $$2^{14}$$ 2 14 using a differential trail searched dedicatedly. In addition, we construct different 2-round connectors using the linearization of the inverse of S-boxes and successfully extend the collision attack to 4 rounds and 5 rounds of Ascon-HASH with complexities of $$2^{18}$$ 2 18 and $$2^{41}$$ 2 41 , respectively. Although our attacks do not compromise the security of the full 12-round Ascon-XOF and Ascon-HASH, they provide some insights into Ascon’s security. Qinggan Fu, Qianqian Yang 0003, Ling Song 0001 |
Cybersecur. | 1 |
| 2025 | Generalized impossible differential attacks on block ciphers: application to SKINNY and ForkSKINNY
Ling Song 0001, Qinggan Fu, Qianqian Yang 0003, Yin Lv, Lei Hu 0003 |
Des. Codes Cryptogr. | 2 |
| 2024 | Improving Differential-Neural Cryptanalysis for Large-State SPECK
Tianrong Huang, Yingying Li 0001, Qinggan Fu, Yincen Chen, Ling Song 0001 |
ICICS (1) | 3 |
| 2024 | Preimage Attacks on Xoodyak and Gaston Based on Algebraic StrategiesabstractAs the Internet of Things (IoT) continues to grow, the urgency to bolster IoT device security escalates, particularly in evaluating the security of lightweight ciphers. Since the inception of Keccak (also known as SHA-3), embedding a permutation within a certain operational mode has become a pivotal approach in designing lightweight cryptography. This led to numerous permutation-based lightweight ciphers tailored for IoT applications. Among them, Xoodyak and Gaston are typical examples and even incorporate Keccak’s nonlinear operation$\chi $within their round functions. This article focuses on assessing the security of Keccak-like lightweight hash functions against preimage attacks. We introduce a generic preimage attack framework from an algebraic perspective and propose a new linearization method that leverages the algebraic properties of$\chi $in the permutation. Additionally, in order to find good guessing strategies, we develop automatic tools based on bit-level mixed-integer linear programming on Xoodyak and Gaston. As a result, the complexity of finding a preimage for 2-round Xoodyak-XOF with a 128-bit digest is$2^{94.66}$while that for 3-round Xoodyak-XOF can be reduced from$2^{125.06}$to$2^{123.91}$and memory consumption from$2^{97}$to a negligible level. This marks the most efficient preimage attack against a 3-round Xoodyak-XOF to date. Furthermore, we present the first preimage attacks on 1-/2-round Gaston with complexities of$2^{90.56}$and$2^{122.15}$, respectively. Qinggan Fu, Yin Lv, Zhiquan Liu 0001, Yingying Li 0001, Ling Song 0001, Jian Weng 0001 |
IEEE Internet Things J. | 1 |
| 2023 | Generic attacks on small-state stream cipher constructions in the multi-user settingabstractAbstract Small-state stream ciphers (SSCs), which violate the principle that the state size should exceed the key size by a factor of two, still demonstrate robust security properties while maintaining a lightweight design. These ciphers can be classified into several constructions and their basic security requirement is to resist generic attacks, i.e., the time–memory–data tradeoff (TMDTO) attack. In this paper, we investigate the security of small-state constructions in the multi-user setting. Based on it, the TMDTO distinguishing attack and the TMDTO key recovery attack are developed for such a setting. It is shown that SSCs which continuously use the key can not resist the TMDTO distinguishing attack. Moreover, SSCs based on the continuous-IV-key-use construction cannot withstand the TMDTO key recovery attack when the key length is shorter than the IV length, no matter whether the keystream length is limited or not. Finally, we apply these two generic attacks to TinyJAMBU and DRACO in the multi-user setting. The TMDTO distinguishing attack on TinyJAMBU with a 128-bit key can be mounted with time, memory, and data complexities of $$2^{64}$$ 2 64 , $$2^{48}$$ 2 48 , and $$2^{32}$$ 2 32 , respectively. This attack is comparable with a recent work on ToSC 2022, where partial key bits of TinyJAMBU are recovered with more than $$2^{50}$$ 2 50 users (or keys). As DRACO’s IV length is smaller than its key length, it is vulnerable to the TMDTO key recovery attack. The resulting attack has a time and memory complexity of both $$2^{112}$$ 2 112 , which means DRACO does not provide 128-bit security in the multi-user setting. Jianfu Huang, Qinggan Fu, Yincen Chen, Ling Song 0001 |
Cybersecur. | 3 |