EDBT 2026 Demo / reviewers in the wild / expert
Willi Meier
dblp:47/6600
· DBLP profile ↗
71ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0003-4594-1501ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 61 · 5 first-author · 15 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Systems, architecture and hardware · 4Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Finding the Inverse of some Shift Invariant Transformations
Fukang Liu, Vaibhav Dixit, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001 |
J. Cryptol. | 4 |
| 2025 | Vectorial Fast Correlation Attacks
Bin Zhang 0003, Ruitao Liu, Willi Meier, Siwei Sun, Dengguo Feng, Wenling Wu |
ASIACRYPT (1) | 3 |
| 2024 | Modelling Ciphers with Overdefined Systems of Quadratic Equations: Application to Friday, Vision, RAIN and Biscuit
Fukang Liu, Mohammad Mahzoun, Willi Meier |
ASIACRYPT (7) | 3 |
| 2023 | Near Collision Attack Against Grain V1
Subhadeep Banik, Daniel Collins 0001, Willi Meier |
ACNS (1) | 3 |
| 2023 | Coefficient Grouping for Complex Affine Layers
Fukang Liu, Lorenzo Grassi 0001, Clémence Bouvier, Willi Meier, Takanori Isobe 0001 |
CRYPTO (3) | 4 |
| 2023 | Coefficient Grouping: Breaking Chaghri and More
Fukang Liu, Ravi Anand, Willi Meier, Takanori Isobe 0001 |
EUROCRYPT (4) | 4 |
| 2023 | Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILP
Fukang Liu, Gaoli Wang, Santanu Sarkar 0001, Ravi Anand, Willi Meier, Yingxin Li, Takanori Isobe 0001 |
EUROCRYPT (4) | 5 |
| 2023 | Differential cryptanalysis of Mod-2/Mod-3 constructions of binary weak PRFsabstractPseudo-random functions are a fundamental building block in many cryptographic applications. In certain scenarios, a weaker notion (where security is restricted to uniformly random input), but more computationally efficient, called weak pseudo-random functions, is sufficient. In this work, we present new differential attacks on the main binary weak pseudo-random function constructions, namely the so-called Alternative Mod-2/Mod-3. For the Alternative Mod-2/Mod-3 wPRF, the best distinguisher proposed by Cheon et al. achieves O(20.21n) complexity, where n is the input length. We show that our attack asymptotically outperforms this and requires far fewer samples that can be applied in restricted oracle settings. By minimizing computational complexity, we can achieve O(20.166n) complexity. Additionally, in a small experiment, we indicate that their proposed fix of using keys with large Hamming weight is even more vulnerable to our attack. Thomas Johansson 0001, Willi Meier |
ISIT | 2 |
| 2023 | A Closer Look at the S-Box: Deeper Analysis of Round-Reduced ASCON-HASH
Xiaorui Yu, Fukang Liu, Gaoli Wang, Siwei Sun, Willi Meier |
SAC | 5 |
| 2023 | Differential-Aided Preimage Attacks On Round-Reduced KeccakabstractAbstract At FSE 2008, Leurent introduced the preimage attack on MD4 by exploiting differential trails. In this paper, we apply the differential-aided preimage attack to Keccak with the message modification techniques. Instead of directly finding the preimage, we exploit differential characteristics to modify the messages, so that the differences of their hashing values and the changes of given target can be controlled. By adding some constraints, a trail can be used to change one bit at a time and reduce the time complexity by a factor of 2. When the number of rounds increases, we introduce two-stage modification techniques to satisfy part of constraints as well. In order to solve other constraints, we also combine the linear-structure technique and accordingly give a preimage attack on 5-round Keccak[$r=1440,c=160,l=80$]. Congming Wei, Xiaoyang Dong 0001, Willi Meier, Lingyue Qin, Ximing Fu |
Comput. J. | 3 |
| 2022 | Algebraic Meet-in-the-Middle Attack on LowMC
Fukang Liu, Santanu Sarkar 0001, Gaoli Wang, Willi Meier, Takanori Isobe 0001 |
ASIACRYPT (1) | 4 |
| 2022 | The Inverse of χ and Its Applications to Rasta-Like Ciphers
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001 |
J. Cryptol. | 3 |
| 2022 | Revisiting Cryptanalysis on ChaCha From Crypto 2020 and Eurocrypt 2021abstractChaCha has been one of the most prominent ARX designs of the last few years because of its use in several systems. The cryptanalysis of ChaCha involves a differential attack that exploits the idea of Probabilistic Neutral Bits (PNBs). For a long period, the single-bit distinguisher in this differential attack was found up to 3rd round. At Crypto 2020, Beierle et al. introduced for the first time the single bit distinguishers for 3.5th round, which contributed significantly to regaining the flow of the research work in this direction. This discovery became the primary factor behind the huge improvement in the key recovery attack complexity in that work. This was followed by another work at Eurocrypt 2021, where a single bit distinguisher at 3.5th round helped to produce a 7th round distinguisher of ChaCha and a further improvement in the key recovery. In this paper, first, we provide the theoretical framework for the distinguisher given by Beierle et al. We mathematically derive the observed differential correlation for the particular position where the output difference is observed at 3.5th round. Also, Beierle et al. mentioned the issue of the availability of proper IVs to produce such distinguishers, and pointed out that not all keys have such IVs available. Here we provide a theoretical insight of this issue. Next, we revisit the work of Coutinhoet al.(Eurocrypt 2021). Using Differential-Linear attacks against ChaCha, they claimed the distinguisher and the key recovery with complexities 2218and$2^{228.51}$respectively. We show that the differential correlation for the 3.5th round is much smaller than the claim of Coutinho et al. This makes the attack complexities much higher than their claim. Sabyasachi Dey 0001, Chandan Dey, Santanu Sarkar 0001, Willi Meier |
IEEE Trans. Inf. Theory | 4 |
| 2021 | Algebraic Attacks on Round-Reduced Keccak
Fukang Liu, Takanori Isobe 0001, Willi Meier, Zhonghao Yang 0003 |
ACISP | 3 |
| 2021 | Algebraic Attacks on Rasta and Dasta Using Low-Degree Equations
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001 |
ASIACRYPT (1) | 3 |
| 2021 | Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier, Hirotaka Yoshida |
CANS | 4 |
| 2021 | Cryptanalysis of Full LowMC and LowMC-M with Algebraic Techniques
Fukang Liu, Takanori Isobe 0001, Willi Meier |
CRYPTO (3) | 3 |
| 2021 | Interpolation Attacks on Round-Reduced Elephant, Kravatte and XoofffabstractAbstract We introduce an interpolation attack using the Moebius Transform. This can reduce the time complexity to get a linear system of equations for specified intermediate state bits, which is general to cryptanalysis of some ciphers with update function of low algebraic degree. Along this line, we perform an interpolation attack against Elephant-Delirium, a round 2 submission of the ongoing national institute of standards and technology (NIST) lightweight cryptography project. This is the first third-party cryptanalysis on this cipher. Moreover, we promote the interpolation attack by applying it to the Farfalle pseudo-random constructions Kravatte and Xoofff. Our attacks turn out to be the most efficient method for these ciphers thus far. Rui Zong, Xiaoyang Dong 0001, Keting Jia, Willi Meier |
Comput. J. | 5 |
| 2021 | Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
J. Cryptol. | 3 |
| 2020 | Automatic Verification of Differential Characteristics: Application to Reduced Gimli
Fukang Liu, Takanori Isobe 0001, Willi Meier |
CRYPTO (3) | 3 |
| 2020 | Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
EUROCRYPT (1) | 3 |
| 2020 | Practical Key-Recovery Attacks On Round-Reduced Ketje Jr, Xoodoo-AE And XoodyakabstractAbstract A new conditional cube attack was proposed by Li et al. at ToSC 2019 for cryptanalysis of Keccak keyed modes. In this paper, we find a new property of Li et al.’s method. The conditional cube attack is modified and applied to cryptanalysis of 5-round Ketje Jr, 6-round Xoodoo-AE and Xoodyak, where Ketje Jr is among the third round CAESAR competition candidates and Xoodyak is a Round 2 submission of the ongoing NIST lightweight cryptography project. For the updated conditional cube attack, all our results are shown to be of practical time complexity with negligible memory cost, and test codes are provided. Notably, our results on Xoodyak represent the first third-party cryptanalysis for Xoodyak. Zheng Li 0008, Xiaoyang Dong 0001, Keting Jia, Willi Meier |
Comput. J. | 5 |
| 2020 | New cube distinguishers on NFSR-based stream ciphers
Abhishek Kesarwani 0002, Dibyendu Roy 0001, Santanu Sarkar 0001, Willi Meier |
Des. Codes Cryptogr. | 4 |
| 2020 | Generalized related-key rectangle attacks on block ciphers with linear key schedule: applications to SKINNY and GIFT
Boxin Zhao, Xiaoyang Dong 0001, Willi Meier, Keting Jia, Gaoli Wang |
Des. Codes Cryptogr. | 3 |
| 2019 | Cryptanalysis of ForkAES
Subhadeep Banik, Jannis Bossert, Amit Jana, Eik List, Stefan Lucks, Willi Meier, Mostafizar Rahman, Dhiman Saha, Yu Sasaki 0001 |
ACNS | 6 |
| 2019 | On the Data Limitation of Small-State Stream Ciphers: Correlation Attacks on Fruit-80 and Plantlet
Yosuke Todo, Willi Meier, Kazumaro Aoki |
SAC | 2 |
| 2019 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of SuperpolyabstractAt CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively. Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
IEEE Trans. Computers | 5 |
| 2019 | A New Cube Attack on MORUS by Using Division PropertyabstractMORUS is an authenticated encryption algorithm and one of the candidates in the CAESAR competition. Currently, the security of MORUS received extensive attention. In this paper, a new existence terms detection method in superpoly recovery phase in cube attack is proposed. More precisely, the upper bounding degree of superpoly is first estimated by using the cube attack based on the division property with Mixed Integer Linear Programming tool. Moreover, the t-degree monomials that may be involved in the superpoly are divided into two groups, where the elements of the first group can be directly determined without using the solver via the embedded property. Compared with previous methods, the time consumption by the solvers of our new method is reduced significantly. In particular, the truth table from only the existent terms can be used to recover the superpoly in the offline phase of the cube attack. Therefore, the time complexity of cube attack can be further reduced. As illustrative example, the security of the reduced-step variants of MORUS-640-128 against cube attack is evaluated by using this new method. It is demonstrated that the key recovery attacks can be applied to 6/7-step MORUS-640-128. Furthermore, some integral distinguishers of 7-step MORUS-640-128/MORUS-1280-256 are achieved. Yongzhuang Wei, Willi Meier |
IEEE Trans. Computers | 3 |
| 2018 | A Key-Recovery Attack on 855-round Trivium
Ximing Fu, Xiaoyun Wang 0001, Xiaoyang Dong 0001, Willi Meier |
CRYPTO (2) | 4 |
| 2018 | Fast Correlation Attack Revisited - Cryptanalysis on Full Grain-128a, Grain-128, and Grain-v1
Yosuke Todo, Takanori Isobe 0001, Willi Meier, Kazumaro Aoki, Bin Zhang 0003 |
CRYPTO (2) | 3 |
| 2018 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier |
CRYPTO (1) | 6 |
| 2018 | Fast Near Collision Attack on the Grain v1 Stream Cipher
Bin Zhang 0003, Willi Meier |
EUROCRYPT (2) | 3 |
| 2018 | Cube Attacks on Non-Blackbox Polynomials Based on Division PropertyabstractThe cube attack is a powerful cryptanalytic technique and is especially powerful against stream ciphers. Since we need to analyze the complicated structure of a stream cipher in the cube attack, the cube attack basically analyzes it by regarding it as a blackbox. Therefore, the cube attack is an experimental attack, and we cannot evaluate the security when the size of cube exceeds an experimental range, e.g., 40. In this paper, we propose cube attacks on non-blackbox polynomials. Our attacks are developed by using the division property, which is recently applied to various block ciphers. The clear advantage is that we can exploit large cube sizes because it never regards the cipher as a blackbox. We apply the new cube attack to Trivium, Grain128a, ACORN and Kreyvium. As a result, the secret keys of 832-round Trivium, 183-round Grain128a, 704-round ACORN and 872-round Kreyvium are recovered. These attacks are the current best key-recovery attack against these ciphers. Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier |
IEEE Trans. Computers | 4 |
| 2017 | Cube Attacks on Non-Blackbox Polynomials Based on Division Property
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier |
CRYPTO (3) | 4 |
| 2017 | Truncated differential based known-key attacks on round-reduced SIMON
Yonglin Hao, Willi Meier |
Des. Codes Cryptogr. | 2 |
| 2015 | Optimized Interpolation Attacks on LowMC
Itai Dinur, Yunwen Liu, Willi Meier, Qingju Wang 0001 |
ASIACRYPT (2) | 3 |
| 2015 | Fast Correlation Attacks over Extension Fields, Large-Unit Linear Approximation and Cryptanalysis of SNOW 2.0
Bin Zhang 0003, Willi Meier |
CRYPTO (1) | 3 |
| 2014 | Dependence in IV-Related Bytes of RC4 Key Enhances Vulnerabilities in WPA
Sourav Sen Gupta 0001, Subhamoy Maitra, Willi Meier, Goutam Paul 0001, Santanu Sarkar 0001 |
FSE | 3 |
| 2013 | Quark: A Lightweight Hash
Jean-Philippe Aumasson, Luca Henzen, Willi Meier, María Naya-Plasencia |
J. Cryptol. | 3 |
| 2012 | Conditional Differential Cryptanalysis of Grain-128a
Michael Lehmann, Willi Meier |
CANS | 2 |
| 2011 | Cryptanalysis of the Knapsack Generator
Simon Knellwolf, Willi Meier |
FSE | 2 |
| 2011 | Fast Correlation Attacks: Methods and Countermeasures
Willi Meier |
FSE | 1 |
| 2011 | VLSI Characterization of the Cryptographic Hash Function BLAKEabstractCryptographic hash functions are used to protect information integrity and authenticity in a wide range of applications. After the discovery of weaknesses in the current deployed standards, the U.S. Institute of Standards and Technology started a public competition to develop the future standard SHA-3, which will be implemented in a multitude of environments, after its selection in 2012. In this paper, we investigate high-speed and low-area hardware architectures of one of the 14 “second-round” candidates in this competition: BLAKE. VLSI performance results of the proposed high-speed designs indicate a throughput improvement between 16% and 36% compared to the current standard SHA-2. Additionally, we propose a compact implementation of BLAKE with memory optimization that fits in 0.127 mm2of a 0.18 μ m CMOS. Measurements reveal a minimal power dissipation of 9.59 μW/MHz at 0.65 V, which suggests that BLAKE is suitable for resource-limited systems. Luca Henzen, Jean-Philippe Aumasson, Willi Meier, Raphael C.-W. Phan |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2010 | Conditional Differential Cryptanalysis of NLFSR-Based Cryptosystems
Simon Knellwolf, Willi Meier, María Naya-Plasencia |
ASIACRYPT | 2 |
| 2010 | Quark: A Lightweight Hash
Jean-Philippe Aumasson, Luca Henzen, Willi Meier, María Naya-Plasencia |
CHES | 3 |
| 2010 | Differential and Invertibility Properties of BLAKE
Jean-Philippe Aumasson, Jian Guo 0001, Simon Knellwolf, Krystian Matusiewicz, Willi Meier |
FSE | 5 |
| 2010 | Cryptanalysis of ESSENCE
María Naya-Plasencia, Andrea Röck, Jean-Philippe Aumasson, Yann Laigle-Chapuy, Gaëtan Leurent, Willi Meier, Thomas Peyrin |
FSE | 6 |
| 2009 | Inside the Hypercube
Jean-Philippe Aumasson, Eric Brier, Willi Meier, María Naya-Plasencia, Thomas Peyrin |
ACISP | 3 |
| 2009 | Improved Cryptanalysis of Skein
Jean-Philippe Aumasson, Çagdas Çalik, Willi Meier, Onur Özen, Raphael C.-W. Phan, Kerem Varici |
ASIACRYPT | 3 |
| 2009 | Linearization Framework for Collision Attacks: Application to CubeHash and MD6
Eric Brier, Shahram Khazaei, Willi Meier, Thomas Peyrin |
ASIACRYPT | 3 |
| 2009 | Cube Testers and Key Recovery Attacks on Reduced-Round MD6 and Trivium
Jean-Philippe Aumasson, Itai Dinur, Willi Meier, Adi Shamir |
FSE | 3 |
| 2008 | New Features of Latin Dances: Analysis of Salsa, ChaCha, and Rumba
Jean-Philippe Aumasson, Simon Fischer 0002, Shahram Khazaei, Willi Meier, Christian Rechberger |
FSE | 4 |
| 2008 | The Hash Function Family LAKE
Jean-Philippe Aumasson, Willi Meier, Raphael C.-W. Phan |
FSE | 2 |
| 2007 | TCHo: A Hardware-Oriented Trapdoor Cipher
Jean-Philippe Aumasson, Matthieu Finiasz, Willi Meier, Serge Vaudenay |
ACISP | 3 |
| 2007 | Algebraic Immunity of S-Boxes and Augmented Functions
Simon Fischer 0002, Willi Meier |
FSE | 2 |
| 2006 | Efficient Computation of Algebraic Immunity for Algebraic and Fast Algebraic Attacks
Frederik Armknecht, Claude Carlet, Philippe Gaborit, Simon Fischer 0002, Willi Meier, Olivier Ruatta |
EUROCRYPT | 5 |
| 2006 | Cryptanalysis of Achterbahn
Thomas Johansson 0001, Willi Meier, Frédéric Muller |
FSE | 2 |
| 2006 | A Stream Cipher Proposal: Grain-128abstractA new stream cipher, Grain-128, is proposed. The design is very small in hardware and it targets environments with very limited resources in gate count, power consumption, and chip area. Grain-128 supports key size of 128 bits and IV size of 96 bits. The design is very simple and based on two shift registers, one linear and one nonlinear, and an output function Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier |
ISIT | 4 |
| 2005 | The Conditional Correlation Attack: A Practical Attack on Bluetooth Encryption
Yi Lu 0002, Willi Meier, Serge Vaudenay |
CRYPTO | 2 |
| 2004 | Algebraic Attacks and Decomposition of Boolean Functions
Willi Meier, Enes Pasalic, Claude Carlet |
EUROCRYPT | 1 |
| 2003 | Algebraic Attacks on Stream Ciphers with Linear Feedback
Nicolas T. Courtois, Willi Meier |
EUROCRYPT | 2 |
| 2003 | Predicting the Shrinking Generator with Fixed Connections
Patrik Ekdahl, Willi Meier, Thomas Johansson 0001 |
EUROCRYPT | 2 |
| 2001 | Analysis of SSC2
Daniel Bleichenbacher, Willi Meier |
FSE | 2 |
| 2000 | Correlations in RC6 with a Reduced Number of Rounds
Lars R. Knudsen, Willi Meier |
FSE | 2 |
| 1999 | Cryptanalysis of an Identification Scheme Based on the Permuted Perceptron Problem
Lars R. Knudsen, Willi Meier |
EUROCRYPT | 2 |
| 1998 | Analysis Methods for (Alleged) RC4
Lars R. Knudsen, Willi Meier, Bart Preneel, Vincent Rijmen, Sven Verdoolaege |
ASIACRYPT | 2 |
| 1996 | Improved Differential Attacks on RC5
Lars R. Knudsen, Willi Meier |
CRYPTO | 2 |
| 1992 | Efficient Multiplication on Certain Nonsupersingular Elliptic Curves
Willi Meier, Othmar Staffelbach |
CRYPTO | 1 |
| 1992 | Correlation Properties of Combiners with Memory in Stream Ciphers
Willi Meier, Othmar Staffelbach |
J. Cryptol. | 1 |
| 1990 | Cryptographic Significance of the Carry for Ciphers Based on Integer Addition
Othmar Staffelbach, Willi Meier |
CRYPTO | 2 |
| 1989 | Fast Correlation Attacks on Certain Stream Ciphers
Willi Meier, Othmar Staffelbach |
J. Cryptol. | 1 |