EDBT 2026 Demo / reviewers in the wild / expert
Xianhui Lu
dblp:40/7264
· DBLP profile ↗
80ranked-venue papers
9as first author
52since 2021 · last 2026
0000-0001-7091-5810ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 75 · 8 first-author · 48 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HetAKE: Heterogeneous Authenticated Key Exchange for Post-quantum Migration
Xianhui Lu, Jingnan He, Haiyang Xue, Yamin Liu 0002 |
ACISP (3) | 1 |
| 2026 | Sub-Millisecond Gate BootstrappingabstractGate bootstrapping is a core primitive that enables arbitrary circuit evaluation in fully homomorphic encryption (FHE), where blind rotation remains the dominant performance bottleneck. In this work, we present a sub-millisecond NTRU-based gate bootstrapping scheme that achieves state-of-the-art performance through coordinated algorithmic, software, and hardware-level optimizations. Chunling Chen, Zhihao Li 0001, Qingyun Niu, Xianhui Lu, Ruida Wang, Lutan Zhao, Rui Hou 0001 |
AsiaCCS | 4 |
| 2026 | sfTalonG: Bandwidth-Efficient Two-Round Threshold Signatures from Lattices
Guofeng Tang, Dingding Jia, Xianhui Lu, Kunpeng Wang 0001, Yongjian Yin |
EUROCRYPT (1) | 6 |
| 2026 | Computational wiretap coding: framework and practical constructionabstractAbstract Wiretap coding, evolving in parallel with cryptography for nearly 50 years, focuses on secure transmission under the assumption that the wiretap channel is no less noisy than the main channel. Most provably secure schemes rely on information-theoretic security but often achieve limited practical rates. This paper proposes a framework for computationally secure modular wiretap coding. We integrate error correction encoding with the channel transition process to define the wiretap channel function, which consists of an invertible function and a lossy function. Secure encoding is then modeled as a computational entropy extractor. A detailed analysis of the lossy function for symmetric wiretap channels is presented. To leverage this lossiness, we design two computational extractors: the invertible fooling extractor (IFE) and the compressed randomness extractor (CRE). For practical implementation, we demonstrate that a 4-round optimal asymmetric encryption padding serves as an IFE in the random oracle model. Experimental comparisons show that our scheme achieves approximately 3 times and 2.7 times the code rates of the Invert-then-Encode and code-based schemes—classical information-theoretic schemes—under equivalent channel conditions. By instantiating IFE and CRE with hash algorithms such as SHAKE-128/256, we develop a practical wiretap coding scheme that achieves high rates with reasonable computational overhead. Mengjie Huang, Xianhui Lu, Chen An, Ziyi Li 0002, Ziyao Liu, Dongchi Han |
Cybersecur. | 2 |
| 2026 | A survey of optimization techniques for bootstrapping algorithms in FHEabstractAbstract Fully Homomorphic Encryption (FHE) enables arbitrary computation on encrypted data without decryption, making it a cornerstone of privacy-preserving outsourcing, such as cloud computing. However, homomorphic operations cause ciphertext noise to grow until decryption fails. The efficient solution is bootstrapping, which refreshes the noise in FHE ciphertexts to sustain arbitrary deep homomorphic evaluation. But in practice, bootstrapping consumes over 50% of total execution time, posing a serious obstacle to FHE adoption. This paper presents a systematic survey of FHE bootstrapping algorithms and their optimizations. We organize existing works into three main paradigms: word-wise bootstrapping for BGV, BFV, and CKKS schemes; bit-wise bootstrapping for FHEW and TFHE schemes; and hybrid bootstrapping, which leverages both word-wise schemes and bit-wise schemes. We analyze the evolution of crucial techniques, highlight latest advances in reducing latency, enhancing parallelism, and controlling noise growth, and compare the advantages and limitations of different schemes. Finally, we discuss emerging research trends. Lutan Zhao, Ruida Wang, Qingyun Niu, Xianhui Lu, Dan Meng 0002, Rui Hou 0001 |
Cybersecur. | 6 |
| 2026 | Tlcp hardening with formal analysis and post-quantum designabstractAbstract Transport Layer Cryptography Protocol (TLCP) is a secure communication protocol developed in China, featuring a dual-certificate architecture and incorporating ShangMi cryptographic algorithms. It has been widely deployed in security-critical domains such as finance, government, and energy. Despite its practical significance, TLCP did not undergo comprehensive formal analysis during its standardization process, leaving potential design-level vulnerabilities insufficiently explored. Moreover, the advent of quantum computing poses fundamental challenges to the classical cryptographic primitives employed by TLCP, motivating the need for both systematic security evaluation and post-quantum enhancements. To address these gaps, we first construct the comprehensive formal model of TLCP, covering certificate-based and identity-based cipher suites as well as its distinctive dual-certificate mechanism, under a realistic threat model and security assumptions that capture both classical and quantum adversaries. Based on this model, we conduct an automated security analysis using ProVerif, identifying nine potential attack vectors and deriving five concrete mitigation recommendations. Finally, motivated by the analysis results and the limitations of incremental fixes against quantum threats, we propose KEMTLCP, a post-quantum secure variant of TLCP that leverages key encapsulation mechanisms (KEMs) for both key exchange and authentication while preserving TLCP’s architectural principles through a novel explicit authentication mechanism. We further provide a security proof for the core authentication mechanism, show that KEMTLCP effectively mitigates the majority of identified vulnerabilities through formal analysis, and evaluate its practical performance. Jingnan He, Jiangxia Ge, Zhaoxuan Li, Qionglu Zhang, Li Zhou 0013, Xianhui Lu, Senlin Liu, Wenhua Gao |
Cybersecur. | 7 |
| 2025 | Refined Error Management for Gate Bootstrapping
Chunling Chen, Xianhui Lu, Binwu Xiang, Ruida Wang |
ACISP (2) | 2 |
| 2025 | Ideal Transformations for Public Key Encryption
Xianhui Lu, Ziyi Li 0002 |
ACISP (1) | 2 |
| 2025 | Indifferentiability Separations in Ideal Public Key Encryption: Explicit vs. Implicit Rejection
Xianhui Lu, Ziyi Li 0002, Yongjian Yin |
ACISP (1) | 2 |
| 2025 | Compact Lifting for NTT-Unfriendly Modulus
Ying Liu 0078, Xianhui Lu, Yu Zhang 0036, Ruida Wang, Ziyao Liu, Kunpeng Wang 0001 |
ACISP (2) | 2 |
| 2025 | Fiat-Shamir with Rejection and Rotation
Xianhui Lu, Yongjian Yin, Dingding Jia, Jingnan He, Yamin Liu 0002 |
ACISP (2) | 1 |
| 2025 | DAWN: Smaller and Faster NTRU Encryption via Double Encoding
Yu Zhang 0036, Xianhui Lu, Yongjian Yin |
ASIACRYPT (3) | 3 |
| 2025 | Refined TFHE Leveled Homomorphic Evaluation and Its ApplicationabstractTFHE is a fully homomorphic encryption scheme over the torus that supports fast bootstrapping. Its primary evaluation mechanism is based on gate bootstrapping and programmable bootstrapping (PBS), which computes functions while simultaneously refreshing noise. PBS-based evaluation is user-friendly and efficient for small circuits; however, the number of bootstrapping operations increases exponentially with the circuit depth. To address the challenge of efficiently evaluating large-scale circuits, Chillotti et al. introduced a leveled homomorphic evaluation (LHE) mode at Asiacrypt 2017. This mode decouples circuit evaluation from bootstrapping, resulting in a speedup of hundreds of times over PBS-based methods. However, the remaining circuit bootstrapping (CBS) becomes a performance bottleneck, even though its frequency is linear with the circuit depth. Ruida Wang, Jincheol Ha, Xuan Shen, Xianhui Lu, Chunling Chen, Kunpeng Wang 0001, Jooyoung Lee 0001 |
CCS | 4 |
| 2025 | Phalanx: An FHE-Friendly SNARK for Verifiable Computation on Encrypted DataabstractVerifiable Computation over encrypted data (VCoed) has two popular paradigms: SNARK-FHE (applying SNARKs to prove FHE operations) and FHE-SNARK (homomorphically evaluating SNARK proofs). For the existing works, FHE-SNARK has a much better efficiency compared to SNARK-FHE. Xinxuan Zhang, Ruida Wang, Zeyu Liu 0004, Binwu Xiang, Yi Deng 0002, Ben Fisch, Xianhui Lu |
CCS | 7 |
| 2025 | FH-TEE: Single Enclave for All Applications
Jikang Bai, Ruida Wang, Xianhui Lu, Chunling Chen, Kunpeng Wang 0001 |
Inscrypt (3) | 3 |
| 2025 | Min-Entropy Estimation for Physical Layer Key Generation: An Empirical Study
Dongchi Han, Tianyu Chen 0016, Liliang Guan, Xianhui Lu |
Inscrypt (3) | 5 |
| 2025 | PolarKyber: Polished Kyber with Smaller Ciphertexts, Greater Security Redundancy, and Lower Decryption Failure Rate
Chen An, Ziyao Liu, Xianhui Lu, Jingnan He |
ICICS (1) | 3 |
| 2025 | Channel Capacity Under Exponentially Decreasing Error ProbabilityabstractWe study the capacity of a general channel under the requirement that the error probability decreases exponentially to zero. A formula of this capacity is established by using information spectrum methods. Specifically, we show that this capacity equals to the supremum, over all input processes, of the input-output inf-information rate under exponential decreasing constraint. We also show that, when the code rate is below the capacity, the probability for a random code not having exponentially decreasing error probability is double exponentially small. Ming Li 0033, Xianhui Lu |
ISIT | 3 |
| 2025 | Keyless Physical-Layer Cryptography
Senlin Liu, Dongshu Cai, Dongchi Han, Xianhui Lu |
ISC | 5 |
| 2025 | Memory-Efficient BKW Algorithm for Solving the LWE Problem
Lei Bi 0002, Xianhui Lu, Kunpeng Wang 0001 |
PKC (2) | 3 |
| 2025 | Theoretical Min-Entropy Bounds for Physical-Layer Key Generation over Weibull Fading ChannelsabstractIn physical-layer key generation (PLKG), researchers often assess key security using randomness tests or secret key capacity analysis. However, randomness tests can be misleading, as low-entropy inputs may still pass when obscured by hash functions or extractors. While key capacity captures the theoretical upper limit of secret bits from raw channels, it overlooks the impact of practical preprocessing. Recent studies have explored min-entropy as a more practical security metric. However, commonly used min-entropy estimators, such as those in NIST SP 800-90B (90B), may yield inaccurate results for complex sources, even overestimating entropy and thereby undermining security. Their applicability to PLKG also remains unverified. To address the above research gap, this paper focuses on modeling the received signal envelope, a common feature extracted for key generation. Leveraging typical wireless fading scenarios considered in key capacity analysis, we adopt the more general Weibull distribution to characterize the envelope statistics, which generalizes the Rayleigh model and better captures diverse propagation conditions. We first derive an explicit expression for the min-entropy in the absence of preprocessing, and then systematically analyze the impact of typical preprocessing operations on the statistical properties of the observed channel. Building on this foundation, we further establish theoretical upper and lower bounds on the min-entropy under representative preprocessing strategies. We further evaluate all 90B entropy estimators using both simulations and real-world channel measurements, comparing their estimates with our analytical results. While some estimators work well on raw data, they often fail or overestimate entropy after preprocessing, compromising security. In contrast, our conservative lower bound remains robust across all tested scenarios and preprocessing conditions. It offers a reliable fallback when standard estimators break down, providing a stronger theoretical foundation for secure key extraction in PLKG systems. Dongchi Han, Xianhui Lu |
TrustCom | 3 |
| 2025 | An improved BKW algorithm on the learning with rounding problemabstractAbstract The Blum-Kalai-Wasserman (BKW) algorithm is a significant combinatorial algorithm used to tackle the Learning with Errors (LWE) and Learning with Rounding (LWR) problems. In 2015, Duc et al. (in: Oswald and Fischlin (eds) EUROCRYPT 2015, Springer, Berlin, 2015) proposed the first BKW algorithm applied directly to LWR, which consists of the reduction phase and the solving phase. In this paper, we propose an improved LWR-solving BKW algorithm. For the reduction phase, we design a novel coding method with relaxed collision conditions and introduce a post-processing stage and for the solving phase, we switch to a more efficient Fast Fourier Transform (FFT) distinguisher with pruning. Compared to previous LWR-solving BKW algorithms, our new BKW algorithm achieves a time complexity improvement of 4.0–48.5 bits for the instances considered. Additionally, by incorporating a novel heuristic method in the reduction phase, our algorithm further improves the sample complexity by 3.7–48.7 bits. Lei Bi 0002, Kunpeng Wang 0001, Xianhui Lu |
Cybersecur. | 4 |
| 2025 | Full domain functional bootstrapping using the prime cyclotomic ring
Ruida Wang, Xianhui Lu, Yundi Wen, Zhihao Li 0001, Benqiang Wei, Kunpeng Wang 0001, Lixia Luo |
Theor. Comput. Sci. | 2 |
| 2025 | Revisiting Prediction-Based Min-Entropy Estimation: Toward Interpretability, Reliability, and Applicability
Dongchi Han, Tianyu Chen 0016, Shijie Jia 0001, Fangyu Zheng, Xianhui Lu |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | TFHE Bootstrapping: Faster, Smaller and Time-Space Trade-Offs
Ruida Wang, Benqiang Wei, Zhihao Li 0001, Xianhui Lu, Kunpeng Wang 0001 |
ACISP (1) | 4 |
| 2024 | Physical-Layer Public Key Encryption Through Massive MIMOabstractWe propose a new physical-layer public key encryption scheme and establish a trapdoor one-way function through Massive MIMO techniques and precoding designs. Under standard arguments, we show that the eavesdropper's decoding complexity grows exponentially with the number of antennas, while the legitimate receiver's decoding complexity grows only quadratically. The proposed scheme builds a bridge between information-theoretic security and cryptographic security. Compared to the traditional physical-layer security, the proposed scheme is secure when the number of the eavesdropper's antennas is infinite or much larger than the number of transmitter/receiver antennas, provided that the eavesdropper's distance from the legitimate receiver is less than one-half of the wavelength, or that the channel estimation process between the sender-receiver pair is broken by the eavesdropper. Because the scheme is based on lattice, not on channel reciprocity, it can be applied to both time-division duplex and frequency-division duplex channels, and utilizes the simple physical layer characteristics of Massive MIMO to resist the currently known quantum attacks. The proposed scheme is adapted to the future requirements of 6G for the security of communication, and provides a new idea for the post-quantum cryptosystem. The simulation results show that the proposed scheme has a decoding bit error rate (BER) close to 0.5 at the eavesdropper and almost 0 at the legitimate receiver. Senlin Liu, Xianhui Lu |
AsiaCCS | 4 |
| 2024 | From Signature with Re-randomizable Keys: Generic Construction of PDPKS
Ziyi Li 0002, Ruida Wang, Xianhui Lu |
Inscrypt (1) | 3 |
| 2024 | Circuit Bootstrapping: Faster and Smaller
Ruida Wang, Yundi Wen, Zhihao Li 0001, Xianhui Lu, Benqiang Wei, Kunpeng Wang 0001 |
EUROCRYPT (2) | 4 |
| 2024 | Efficient Blind Rotation in FHEW Using Refined Decomposition and NTT
Ying Liu 0078, Zhihao Li 0001, Ruida Wang, Xianhui Lu, Kunpeng Wang 0001 |
ISC (1) | 4 |
| 2024 | Revisiting Anonymity in Post-quantum Public Key Encryption
Xianhui Lu, Ziyi Li 0002, Bao Li 0001 |
PQCrypto (2) | 2 |
| 2024 | Ideal Public Key Encryption, Revisited
Xianhui Lu, Ziyi Li 0002 |
ProvSec (1) | 2 |
| 2024 | ROM Reduction Failures: Reasons and Solutions
Ziyi Li 0002, Xianhui Lu |
ProvSec (2) | 2 |
| 2024 | eBiBa: A Post-Quantum Hash-Based Signature With Small Signature Size in the Continuous Communication of Large-Scale DataabstractAbstract We present eBiBa (enhanced BiBa), a hash-based signature scheme with the smallest possible signature size, while ensuring high feasibility and security in a specific application model. Our scheme is tailored to address the communication requirement of a large-scale public data stream continuously disseminated between two participants while ensuring data source and data integrity authentication. To achieve these goals, firstly, we optimized the classical hash tree mode into a hybrid mode to efficiently perform public key authentication and eliminate the need for an authenticated channel to transmit large amounts of data, unlike the initial BiBa-based broadcast authentication protocol. Secondly, we employed a specific tweakable hash chain function to digest a batch of messages, reducing the required conditions for post-quantum existential unforgeability under adaptive chosen message attack (EUCMA) of eBiBa to a second-pre-image-resistance-like property instead of collision resistance. This results in reduced pre-computation in both key and signature generations. Thirdly, we utilized a forward-secure pseudorandom function to achieve forward-secure of the proposed scheme. Finally, we minimize the signature size through a series of procedures. Firstly, we select BiBa few-time signature as the underlying signature scheme since it is currently the few-time hash-based signature with the smallest signature size that we are aware of; in addition, the hybrid approach we employed can also significantly reduce the signature size compared to using a hash tree solely; for the hash tree structure, we design a specific authentication path in combination with the related communication model to further minimize the signature size; finally, we optimize the authentication approach to achieve the minimum signature size in a single transmission. Our construction minimizes the signature size in the aforementioned model, achieving a compression rate of 0.017 to 0.828 based on distinct values of parameters, as compared to XMSS-256. We also demonstrated that eBiBa can achieve post-quantum forward-secure and EUCMA security. Xianhui Lu, Kunpeng Wang 0001 |
Comput. J. | 2 |
| 2024 | Polar code-based secure transmission with higher message rate combining channel entropy and computational entropyabstractAbstract The existing physical layer security schemes, which are based on the key generation model and the wire-tap channel model, achieve security by utilizing channel reciprocity entropy and noise entropy, respectively. In contrast, we propose a novel secure transmission framework that combines noise entropy with reciprocity entropy, achieved by inserting reciprocity entropy into the frozen bits of polar codes. Note that in real-world scenarios, when eavesdroppers employ polynomial-time attacks, the bit error rate (BER) increases due to the introduction of computational entropy. To achieve indistinguishability security, we convert the practical physical layer security metric, BER, into the average min-entropy, a widely accepted concept in cryptography. The simulation results demonstrate that the eavesdropper’s BER can be significantly increased without compromising the communication performance of the legitimate receiver. Under concrete parameters we selected, when compared to the joint scheme of physical layer key generation and one time pad, the modular semantically-secure scheme based on the wire-tap channel model, and the simple channel entropy combination scheme, our scheme achieves a message rate approximately 1.2 times, 3.8 times, and 1.4 times better, respectively. Experimental testing validates the feasibility of our scheme. Chen An, Mengjie Huang, Xianhui Lu, Lei Bi 0002 |
Cybersecur. | 3 |
| 2024 | Key derivable signature and its application in blockchain stealth addressabstractAbstract Stealth address protocol (SAP) is widely used in blockchain to achieve anonymity. In this paper, we formalize a key derivable signature scheme (KDS) to capture the functionality and security requirements of SAP. We then propose a framework to construct key separation KDS, which follows the key separation principle as all existing SAP solutions to avoid the reuse of the master keys in the derivation and signature component. We also study the joint security in KDS and construct a key reusing KDS framework, which implies the first compact stealth address protocol using a single key pair. Finally, we provide instantiations based on the elliptic curve (widely used in cryptocurrencies) and on the lattice (with quantum resistance), respectively. Ruida Wang, Ziyi Li 0002, Xianhui Lu, Zhenfei Zhang, Kunpeng Wang 0001 |
Cybersecur. | 3 |
| 2024 | Improved homomorphic evaluation for hash function based on TFHEabstractAbstract Homomorphic evaluation of hash functions offers a solution to the challenge of data integrity authentication in the context of homomorphic encryption. The earliest attempt to achieve homomorphic evaluation of SHA-256 hash function was proposed by Mella and Susella (in: Cryptography and coding—14th IMA international conference, IMACC 2013. Lecture notes in computer science, vol 8308. Springer, Heidelberg, pp 28–44, 2013. https://doi.org/10.1007/978-3-642-45239-0_3 .) based on the BGV scheme. Unfortunately, their implementation faced significant limitations due to the exceedingly high multiplicative depth, rendering it impractical. Recently, a homomorphic implementation of SHA-256 based on the TFHE scheme (Homomorphic evaluation of SHA-256. https://github.com/zama-ai/tfhe-rs/tree/main/tfhe/examples/sha256_bool ) brings it from theory to reality, however, its current efficiency remains insufficient. In this paper, we revisit the homomorphic evaluation of the SHA-256 hash function in the context of TFHE, further reducing the reliance on gate bootstrapping and enhancing evaluation latency. Specifically, we primarily utilize ternary gates to reduce the number of gate bootstrappings required for logic functions in message expansion and addition of modulo $$2^{32}$$ 2 32 in iterative compression. Furthermore, we demonstrate that our optimization techniques are applicable to the Chinese commercial cryptographic hash SM3. Finally, we give specific comparative implementations based on the TFHE-rs library. Experiments demonstrate that our optimization techniques lead to an improvement of approximately 35–50% compared with the state-of-the-art result under different cores. Benqiang Wei, Xianhui Lu |
Cybersecur. | 2 |
| 2024 | Efficient FHE-Based Privacy-Enhanced Neural Network for Trustworthy AI-as-a-ServiceabstractAI-as-a-Service has emerged as an important trend for supporting the growth of the digital economy. Digital service providers make use of their vast amount of customer data to train AI models (such as image recognition, financial modelling and pandemic modelling etc) and offer them as a service on the cloud. While there are convincing advantages for using such third-party models, the fact that model users are required to upload their data to the cloud is bound to raise serious privacy concerns, especially in the face of increasingly stringent privacy regulations and legislation. To promote the adoption of AI-as-a-Service while addressing privacy issues, we propose a practical approach for constructing privacy-enhanced neural networks by designing an efficient implementation of fully homomorphic encryption. With this approach, an existing neural network can be converted to process FHE-encrypted data and produce encrypted output which are only accessible by the model users, and more importantly, within an operationally acceptable time (e.g. within 1 second for facial recognition in typical border control systems). Experimental results show that in many practical tasks such as facial recognition, text classification and so on, we obtained the state-of-the-art inference accuracy in less than one second on a 16 cores CPU. Kwok-Yan Lam, Xianhui Lu, Linru Zhang, Xiangning Wang, Huaxiong Wang, Si Qi Goh |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | ALT: Area-Efficient and Low-Latency FPGA Design for Torus Fully Homomorphic EncryptionabstractThe homomorphic encryption over the torus (TFHE) is a promising fully homomorphic encryption (FHE) scheme that allows arbitrary homomorphic computations with the programmable bootstrapping (PBS) algorithm. However, PBS suffers from prohibitive computation complexity and latency, which hinders the practical applications of TFHE. To address these challenges, we propose ALT, a field-programmable gate array (FPGA) accelerator for PBS that exhibits high area efficiency and low latency. Our approach involves modifying the parameters of the PBS algorithm to strike a balance between the computation complexity and the decryption failure rate (DFR). In addition, we leverage the Chinese residue theorem (CRT) to exploit the inherent parallelism and construct the primes to eliminate the need of CRT process and facilitate fast modular arithmetic. The ALT design comprises several carefully designed computation units, including inverse CRT (ICRT), divide-and-round (DR) operation, and monomial number theoretic transform (MNTT). We employ algorithmic and architectural co-optimization techniques to optimize these units. Notably, ALT features a low-complexity MNTT module, enabling the utilization of the bootstrapping key unrolling (BKU) technique with reduced latency and minimal hardware resources. Furthermore, all submodules of ALT are parameterized and scalable, allowing the entire design to be configurable according to varying requirements across different application scenarios. Experimental results on FPGA demonstrate that ALT significantly outperforms a similar configurable work in terms of latency, throughput, and efficiency. In comparison with the fastest FPGA implementation, ALT can realize lower latency while reducing digital signal processor (DSP) reduction by over$50\%$, leading to enhanced area efficiency and energy efficiency. Xiao Hu 0007, Zhihao Li 0001, Zhongfeng Wang 0001, Xianhui Lu |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2023 | Power of Randomness Recovery: Tighter CCA-Secure KEM in the QROM
Ziyi Li 0002, Xianhui Lu, Bao Li 0001 |
Inscrypt (2) | 2 |
| 2023 | Full Domain Functional Bootstrapping with Least Significant Bit Encoding
Zhihao Li 0001, Benqiang Wei, Ruida Wang, Xianhui Lu, Kunpeng Wang 0001 |
Inscrypt (1) | 4 |
| 2023 | Improved Homomorphic Evaluation for Hash Function Based on TFHE
Benqiang Wei, Xianhui Lu |
Inscrypt (2) | 2 |
| 2023 | An Improved BKW Algorithm for Solving LWE with Small Secrets
Lei Bi 0002, Kunpeng Wang 0001, Xianhui Lu |
ISC | 4 |
| 2023 | Fregata: Faster Homomorphic Evaluation of AES via TFHE
Benqiang Wei, Ruida Wang, Zhihao Li 0001, Qinju Liu, Xianhui Lu |
ISC | 5 |
| 2023 | Physical Layer Secure Communication based on MIMO Channel Constellation FlippingabstractWe proposed a physical layer secure communication system for massive MIMO systems, utilizing channel entropy as the foundation. Our approach involves extracting a mask key and a flip key from the singular value decomposition (SVD) of the channel matrix. The mask key ensures the protection of the flip key during transmission. By applying a random flip to the constellation diagram of the transmitted message based on the flip key, we introduce a scrambling effect that cannot be deciphered by eavesdroppers. The flip key is securely delivered to the receiver, allowing for the proper demodulation of the message by eliminating the constellation flip. To address the computational burden associated with estimating massive MIMO channels, we employ precoding of the downlink channel guide signal in the system design. This reduces the channel estimation overhead at the terminal. However, it also creates an equivalent channel for the eavesdropper, enabling them to correctly decode the precoded signal and compromise communication security. Our scheme counters this by introducing the constellation diagram flipping, which cannot be extracted by eavesdroppers, thereby preventing correct decoding. Simulation experiments confirm even with a large number of antennas, the eavesdropper is unable to completely counteract the effects of constellation flipping, thus ensuring communication security. In summary, by exploiting the singular value decomposition and employing constellation diagram flipping, our physical layer secure MIMO communication system based on channel entropy achieves secure communication even in the presence of powerful eavesdroppers. Xianhui Lu |
TrustCom | 2 |
| 2023 | Security estimation of LWE via BKW algorithmsabstractAbstract The Learning With Errors (LWE) problem is widely used in lattice-based cryptography, which is the most promising post-quantum cryptography direction. There are a variety of LWE-solving methods, which can be classified into four groups: lattice methods, algebraic methods, combinatorial methods, and exhaustive searching. The Blum–Kalai–Wasserman (BKW) algorithm is an important variety of combinatorial algorithms, which was first presented for solving the Learning Parity With Noise (LPN) problem and then extended to solve LWE. In this paper, we give an overview of BKW algorithms for solving LWE. We introduce the framework and key techniques of BKW algorithms and make comparisons between different BKW algorithms and also with lattice methods by estimating concrete security of specific LWE instances. We also briefly discuss the current problems and potential future directions of BKW algorithms. Lei Bi 0002, Xianhui Lu, Kunpeng Wang 0001 |
Cybersecur. | 3 |
| 2022 | Hybrid Dual and Meet-LWE Attack
Lei Bi 0002, Xianhui Lu, Junjie Luo 0001, Kunpeng Wang 0001 |
ACISP | 2 |
| 2022 | IND-CCA Security of Kyber in the Quantum Random Oracle Model, Revisited
Xianhui Lu, Dingding Jia, Bao Li 0001 |
Inscrypt | 2 |
| 2022 | Implicit Rejection in Fujisaki-Okamoto: Framework and a Novel Realization
Xianhui Lu, Dingding Jia, Bao Li 0001 |
ISC | 2 |
| 2022 | Hybrid dual attack on LWE with arbitrary secretsabstractAbstract In this paper, we study the hybrid dual attack over learning with errors (LWE) problems for any secret distribution. Prior to our work, hybrid attacks are only considered for sparse and/or small secrets. A new and interesting result from our analysis shows that for most cryptographic use cases a hybrid dual attack outperforms a standalone dual attack, regardless of the secret distribution. We formulate our results into a framework of predicting the performance of the hybrid dual attacks. We also present a few tricks that further improve our attack. To illustrate the effectiveness of our result, we re-evaluate the security of all LWE related proposals in round 3 of NIST’s post-quantum cryptography process, and improve the state-of-the-art cryptanalysis results by 2-15 bits, under the BKZ-core-SVP model. Lei Bi 0002, Xianhui Lu, Junjie Luo 0001, Kunpeng Wang 0001, Zhenfei Zhang |
Cybersecur. | 2 |
| 2022 | Hash-based signature revisitedabstractAbstract The current development toward quantum attack has shocked our confidence on classical digital signature schemes. As one of the mainstreams of post quantum cryptography primitives, hash-based signature has attracted more and more concern in both cryptographic research and application in recent years. The goal of this paper is to present, classify and discuss different solutions for hash-based signature. Firstly, this paper discusses the research progress in the component of hash-based signature, i.e., one-time signature and few-time signature; then classifies the tree-based public key authentication schemes of hash-based signature into limited number and stateful schemes, unlimited number and stateful schemes and unlimited number and stateless schemes. The above discussion aims to analyze the overall design idea of different categories of hash-based signatures, as well as the construction, security reduction and performance efficiency of specific schemes. Finally, the perspectives and possible development directions of hash-based signature are briefly discussed. Xianhui Lu, Kunpeng Wang 0001 |
Cybersecur. | 2 |
| 2021 | Attacking ECDSA Leaking Discrete Bits with a More Efficient Lattice
Shuaigang Li, Shuqin Fan, Xianhui Lu |
Inscrypt | 3 |
| 2021 | Predicting the Concrete Security of LWE Against the Dual Attack Using Binary Search
Shuaigang Li, Xianhui Lu, Bao Li 0001, Lei Bi 0002 |
ICICS (2) | 2 |
| 2020 | SecureBP from Homomorphic EncryptionabstractWe present a secure backpropagation neural network training model (SecureBP), which allows a neural network to be trained while retaining the confidentiality of the training data, based on the homomorphic encryption scheme. We make two contributions. The first one is to introduce a method to find a more accurate and numerically stable polynomial approximation of functions in a certain interval. The second one is to find a strategy of refreshing ciphertext during training, which keeps the order of magnitude of noise at O˜e33 . Qinju Liu, Xianhui Lu, Shuai Zhou 0001, Jingnan He, Kunpeng Wang 0001 |
Secur. Commun. Networks | 2 |
| 2019 | Deterministic Identity-Based Encryption from Lattice-Based Programmable Hash Functions with High Min-EntropyabstractThere only exists one deterministic identity-based encryption (DIBE) scheme which is adaptively secure in the auxiliary-input setting, under the learning with errors (LWE) assumption. However, the master public key consists of O(λ) basic matrices. In this paper, we consider to construct adaptively secure DIBE schemes with more compact public parameters from the LWE problem. (i) On the one hand, we gave a generic DIBE construction from lattice-based programmable hash functions with high min-entropy. (ii) On the other hand, when instantiating our generic DIBE construction with four LPHFs with high min-entropy, we can get four adaptively secure DIBE schemes with more compact public parameters. In one of our DIBE schemes, the master public key only consists of ω(logλ) basic matrices. Daode Zhang, Bao Li 0001, Xianhui Lu, Haiyang Xue, Dingding Jia, Yamin Liu 0002 |
Secur. Commun. Networks | 4 |
| 2018 | Lattice-Based Dual Receiver Encryption and More
Daode Zhang, Kai Zhang 0016, Bao Li 0001, Xianhui Lu, Haiyang Xue |
ACISP | 4 |
| 2018 | Understanding and Constructing AKE via Double-Key Key Encapsulation Mechanism
Haiyang Xue, Xianhui Lu, Bao Li 0001, Bei Liang, Jingnan He |
ASIACRYPT (2) | 2 |
| 2018 | Preprocess-then-NTT Technique and Its Applications to Kyber and NewHope
Shuai Zhou 0001, Haiyang Xue, Daode Zhang, Kunpeng Wang 0001, Xianhui Lu, Bao Li 0001, Jingnan He |
Inscrypt | 5 |
| 2017 | Dual-Mode Cryptosystem Based on the Learning with Errors Problem
Jingnan He, Wenpan Jing, Bao Li 0001, Xianhui Lu, Dingding Jia |
ACISP (2) | 4 |
| 2017 | Constructions Secure Against Receiver Selective Opening and Chosen Ciphertext Attacks
Dingding Jia, Xianhui Lu, Bao Li 0001 |
CT-RSA | 2 |
| 2017 | Compact (Targeted Homomorphic) Inner Product Encryption from LWE
Daode Zhang, Xianhui Lu, Kunpeng Wang 0001 |
ICICS | 3 |
| 2017 | Towards Tightly Secure Deterministic Public Key Encryption
Daode Zhang, Bao Li 0001, Yamin Liu 0002, Haiyang Xue, Xianhui Lu, Dingding Jia |
ICICS | 5 |
| 2016 | (Deterministic) Hierarchical Identity-based Encryption from Learning with Rounding over Small ModulusabstractIn this paper, we propose a hierarchical identity-based encryption (HIBE) scheme in the random oracle (RO) model based on the learning with rounding (LWR) problem over small modulus $q$. Compared with the previous HIBE schemes based on the learning with errors (LWE) problem, the ciphertext expansion ratio of our scheme can be decreased to 1/2. Then, we utilize the HIBE scheme to construct a deterministic hierarchical identity-based encryption (D-HIBE) scheme based on the LWR problem over small modulus. Finally, with the technique of binary tree encryption (BTE) we can construct HIBE and D-HIBE schemes in the standard model based on the LWR problem over small modulus. Fuyang Fang, Bao Li 0001, Xianhui Lu, Yamin Liu 0002, Dingding Jia, Haiyang Xue |
AsiaCCS | 3 |
| 2016 | Leakage-Resilient IND-CCA KEM from the Extractable Hash Proofs with Indistinguishability Obfuscation
Wenpan Jing, Xianhui Lu, Bao Li 0001 |
Inscrypt | 2 |
| 2016 | A Secure and Fast Dispersal Storage Scheme Based on the Learning with Errors Problem
Fuyang Fang, Xianhui Lu, Wen Tao Zhu, Qiongxiao Wang, Shen Yan 0007, Shiran Pan |
SecureComm | 3 |
| 2015 | CCA Secure Public Key Encryption Scheme Based on LWE Without Gaussian Sampling
Xiaochao Sun, Bao Li 0001, Xianhui Lu, Fuyang Fang |
Inscrypt | 3 |
| 2015 | KDM-CCA Security from RKA Secure Authenticated Encryption
Xianhui Lu, Bao Li 0001, Dingding Jia |
EUROCRYPT (1) | 1 |
| 2015 | Cramer-Shoup Like Chosen Ciphertext Security from LPN
Xiaochao Sun, Bao Li 0001, Xianhui Lu |
ISPEC | 3 |
| 2014 | On the Lossiness of 2 k -th Power and the Instantiability of Rabin-OAEP
Haiyang Xue, Bao Li 0001, Xianhui Lu, Kunpeng Wang 0001, Yamin Liu 0002 |
CANS | 3 |
| 2014 | Related-Key Security for Hybrid Encryption
Xianhui Lu, Bao Li 0001, Dingding Jia |
ISC | 1 |
| 2014 | Lossy Trapdoor Relation and Its Applications to Lossy Encryption and Adaptive Trapdoor Relation
Haiyang Xue, Xianhui Lu, Bao Li 0001, Yamin Liu 0002 |
ProvSec | 2 |
| 2013 | Efficient Lossy Trapdoor Functions Based on Subgroup Membership Assumptions
Haiyang Xue, Bao Li 0001, Xianhui Lu, Dingding Jia, Yamin Liu 0002 |
CANS | 3 |
| 2013 | RSA-OAEP is RKA Secure
Dingding Jia, Bao Li 0001, Xianhui Lu, Yamin Liu 0002 |
Inscrypt | 3 |
| 2013 | RKA Secure PKE Based on the DDH and HR Assumptions
Dingding Jia, Xianhui Lu, Bao Li 0001, Qixiang Mei |
ProvSec | 2 |
| 2013 | How to Remove the Exponent GCD in HK09
Xianhui Lu, Bao Li 0001, Yamin Liu 0002 |
ProvSec | 1 |
| 2012 | Improved Efficiency of Chosen Ciphertext Secure Encryption from Factoring
Xianhui Lu, Bao Li 0001, Qixiang Mei, Yamin Liu 0002 |
ISPEC | 1 |
| 2011 | Efficient CCA-Secure CDH Based KEM Balanced between Ciphertext and Key
Yamin Liu 0002, Bao Li 0001, Xianhui Lu, Dingding Jia |
ACISP | 3 |
| 2011 | Improved Tradeoff between Encapsulation and Decapsulation of HK09
Xianhui Lu, Bao Li 0001, Qixiang Mei, Yamin Liu 0002 |
Inscrypt | 1 |
| 2011 | Encryption Simulatability Reconsidered
Yamin Liu 0002, Bao Li 0001, Xianhui Lu, Xiaoying Jia 0002 |
ISPEC | 3 |
| 2011 | Key-Dependent Message Security for Division Function: Discouraging Anonymous Credential Sharing
Xianhui Lu, Bao Li 0001, Qixiang Mei, Haixia Xu 0002 |
ProvSec | 1 |
| 2009 | Improved efficiency of Kiltz07-KEM
Xianhui Lu, Xuejia Lai, Dake He |
Inf. Process. Lett. | 1 |