Lin Jiao

dblp:48/8078 · DBLP profile ↗
← Back
39ranked-venue papers
18as first author
25since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 10 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 4 since 2021Theory of computation · 5 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 An improved automatic framework for searching for differential-linear distinguishers with applications to SPN and Feistel block ciphers
Lin Jiao, Senpeng Wang, Yunong Wu, Bin Hu 0011, Tairong Shi, Kai Zhang 0026
Des. Codes Cryptogr.2
2026 Fourier-enhanced semi-supervised proxy learning for ultra-fine-grained novel class discovery
Qiupu Chen, Hongkui Jiang, Lin Jiao, Taosheng Xu, Rujing Wang
Pattern Recognit.3
2026 Evaluation of the role of tourism english in the comprehensive utilization of new energy and leisure tourism
Lin Jiao
Serv. Oriented Comput. Appl.1
2026 Revisit the Propagation of States: New Construction Theory and Search Method for Impossible Differentials and Impossible Polytopic Transitions
abstract
Impossible differential cryptanalysis and impossible polytopic cryptanalysis are among the most effective techniques for evaluating the security of block ciphers. However, previous automatic search methods for their distinguishers—dimpossible differentials and impossible polytopic transitions—neither account for the influence of the key schedule in single-key settings nor are applicable to block ciphers featuring large S-boxes, variable rotations, or key-dependent permutations. Furthermore, existing approaches fail to search for clusters of impossible differentials when all details of a block cipher are considered. In contrast to previous methods that focus solely on the propagation of differences or s-difference, we redefine impossible differentials and impossible (s+ 1)-polytopic transitions based on state propagation. This redefinition enables us to overcome the limitations inherent in earlier methodologies. Theoretically, we demonstrate that traditional definitions of impossible differentials and impossible (s+ 1)-polytopic transitions correspond to subsets of our redefined concepts, which offer broader analytical perspectives. Technically, we reformulate the automatic search model and develop an SAT-based tool to efficiently evaluate our redefined impossible differentials and impossible (s+ 1)-polytopic transitions. Building upon this foundational search method, we construct a comprehensive framework for detecting clusters of impossible differentials and impossible (s+1)-polytopic transitions. This framework not only fully incorporates the details and differential properties of block ciphers but is also applicable to those employing large S-boxes while considering the full linear layer. As a result, we derive new impossible differentials for GIFT64, PRINTcipher48/96, MISTY1, RC5-32/64/128 and SPECK, as well as new clusters of impossible differentials for SPECK, DES and ARIA. In assessing resistance against impossible differentials, we apply our method to evaluate the security of GIFT64, PRINTcipher48/96, MISTY1, SPECK, SIMON, and DES while accounting for all details of the block ciphers. Moreover, we propose acceleration strategies and apply them to evaluate the security of MISTY1 and AES-128. Notably, we prove that no 5-round impossible differentials with one active input byte and one active output byte exist for AES-128, even when considering the dependencies among three consecutive round keys. Finally, in exploring new impossible (s+1)-polytopic transition, we apply our approach to PRINTcipher48, GIFT64, RC5-32/64 and SIMON32-64, successfully yielding the corresponding distinguishers for the first time.
Xichao Hu, Lin Jiao, Yongqiang Li 0001, Shizhu Tian, Zhengbin Liu, Mingsheng Wang, Dengguo Feng
IEEE Trans. Inf. Theory2
2026 A Unified Key Recovery Framework for Impossible Boomerang Attacks: Applications to Full-Round-ARADI and SKINNYe v2
abstract
The impossible boomerang attack is a powerful cryptanalytic technique, but existing key recovery methods face several limitations that restrict its applicability. Specifically, the key pre-guessing is coarse-grained, S-box details are ignored in the differential propagation, the complexity estimation and the key guessing order determination remain rudimentary. To overcome these issues, we introduce three key improvement measures. First, we propose a flexible partial key and difference pre-guessing technique based on directed graphs, enabling selective identification of required keys and differences for generating partial pairs and quartets. Second, we propose a pre-sieving technique to early eliminate invalid quartets by exploiting cipher-specific details. Third, we introduce an automatic key-guessing strategy based on the same directed graphs to efficiently determine valid guessing orders. We integrate these techniques to develop a unified key recovery framework for impossible boomerang attacks, accompanied by a formal and precise characterization of the overall complexity. This is the first framework to support flexible key and difference pre-guessing while incorporating block cipher details during key recovery for impossible boomerang attacks. Crucially, it enables the automatic generation of detailed recovery steps, a capability missing in prior work. As applications, under the four related-key/tweakey setting, we apply the framework to ARADI, a low-latency cipher proposed by the National Security Agency (NSA), and SKINNYe v2, a threshold-implementation-friendly cipher proposed at EUROCRYPT 2020. For ARADI, we achieve the first full-round attack with 2130data, 2253.78time, and 2235.75memory complexity. For SKINNYe v2, we present the first 34-round impossible boomerang attack with 266data, 2253.75time, and 2239.75memory complexity. These results demonstrate the framework’s significance and its substantial improvement in advancing the impossible boomerang attack.
Lin Jiao, Xichao Hu, Dengguo Feng, Yongqiang Li 0001, Senpeng Wang, Yonglin Hao, Xinxin Gong
IEEE Trans. Inf. Theory1
2025 Persistence of Hourglass(-like) Structure: Improved Differential-Linear Distinguishers for Several ARX Ciphers
Xinxin Gong, Qingju Wang 0001, Yonglin Hao, Lin Jiao, Xichao Hu
ASIACRYPT (1)4
2025 YuS: A FHE-Friendly Stream Cipher Based on New Quadratic Permutations
abstract
Permutations with low multiplication depth over prime fields are highly valuable in the design of symmetric ciphers that are compatible with fully homomorphic encryption (FHE). Quadratic permutations, which have the lowest depth, have been widely used in prior designs. In this paper, we propose a construction method that can give new quadratic permutations over Fpm, and cryptographic properties such as differential uniformity and Walsh spectrum of these permutations are also characterized. We give sufficient conditions for permutations over Fpnto attain a differential uniformity ofpn−1forn≥ 3. Furthermore, it is proven that for these permutations, the maximal 2-norm of Walsh coefficients remains bounded bypn−1, provided either the lastn− 1 entries of the input mask or the lastn− 1 entries of the output mask form a nonzero vector. As an application, we design a new FHE-friendly stream cipher named YuS based on a new quadratic permutation over Fp3and a fixed linear mapping. According to our implementation, achieves YuS faster evaluation times and higher throughput compared to Masta, Pasta, Pastav2and HERA in almost all instances for both BGV and BFV schemes at 80-bit and 128-bit security levels.
Yongqiang Li 0001, Fangzhen Wang, Xingwei Ren, Xichao Hu, Lin Jiao, Ya Han
IEEE Trans. Inf. Theory6
2024 LOL: a highly flexible framework for designing stream ciphers
Dengguo Feng, Lin Jiao, Yonglin Hao, Qun-Xiong Zheng, Wenling Wu, Wen-Feng Qi 0001, Siwei Sun, Tian Tian 0004
Sci. China Inf. Sci.2
2024 ESA-Net: An efficient scale-aware network for small crop pest detection
Shifeng Dong, Lin Jiao, Jianming Du, Kang Liu 0023, Rujing Wang
Expert Syst. Appl.3
2024 Differential Fault Attacks on Privacy Protocols Friendly Symmetric-Key Primitives: RAIN and HERA
abstract
As the practical applications of fully homomorphic encryption (FHE), secure multi‐party computation (MPC) and zero‐knowledge (ZK) proof continue to increase, so does the need to design and analyze new symmetric‐key primitives that can adapt to these privacy‐preserving protocols. These designs typically have low multiplicative complexity and depth with the parameter domain adapted to their application protocols, aiming to minimize the cost associated with the number of nonlinear operations or the multiplicative depth of their representation as circuits. In this paper, we propose two differential fault attacks against a one‐way function RAIN used for Rainier (CCS 2022), a signature scheme based on the MPC‐in‐the‐head approach and an FHE‐friendly cipher HERA used for the RtF framework (Eurocrypt 2022), respectively. We show that our attacks can recover the keys for both ciphers by only injecting a fault into the internal state and requiring only one normal and one faulty ciphertext blocks. Thus, we can use only the practical complexity of 2 26.6 /2 28.8 /2 30.4 bit operations to break the full‐round RAIN with 128/192/256‐bit keys. For full‐round HERA with 80/128‐bit key, our attack is practical with complexity the complexity of 2 20 encryptions with about 2 16 memory.
Lin Jiao, Yongqiang Li 0001, Yonglin Hao, Xinxin Gong
IET Inf. Secur.1
2024 An iterative correction method for practically LPN solving
Man Kang, Lin Jiao, Yongqiang Li 0001, Mingsheng Wang
Inf. Sci.2
2024 Integrating foreground-background feature distillation and contrastive feature learning for ultra-fine-grained visual classification
Qiupu Chen, Lin Jiao, Fenmei Wang, Jianming Du, Haiyun Liu, Rujing Wang
Pattern Recognit.2
2024 YuX: Finite Field Multiplication Based Block Ciphers for Efficient FHE Evaluation
abstract
With the growing practical applications of fully homomorphic encryption (FHE), secure multi-party computation (MPC), and zero-knowledge proofs (ZK), there has been an increasing need to design and analyze symmetric primitives that have low multiplication complexity and depth. In this paper, we propose a permutation constructed upon a 4-round nonlinear feedback resistor over$ \mathbb {F}_{q}^{4}$. Our proposed permutation has a multiplication depth of 2 and a multiplication complexity of 4. Significantly, its maximum differential/linear probability is bounded by$q^{-2}$. Based on this nonlinear function, we propose a new family of block ciphers over$ \mathbb {F}_{q}^{16}$called$ \mathsf {YuX}$, whose decryption circuit is highly efficient for FHE evaluation. We further provide specific instantiations, denoted as$ \mathsf {Yu_{2}X}$and$ \mathsf {Yu_{\mathrm {p}}X}$, wherein$q$takes the form of either$2^{n}$or a prime$p$, respectively. Furthermore, we conduct a comprehensive security analysis of$ \mathsf {YuX}$within certain parameters against various cryptanalysis methods employing automatic analysis tools, including the differential attack, linear attack, impossible differential attack, zero-correlation attack, and integral attack, as well as Gröbner basis and linearization attacks. Our research indicates that$ \mathsf {YuX}$maintains a robust security margin against those attacks. Finally, we present a detailed implementation of$ \mathsf {Yu_{2}X}$and$ \mathsf {Yu_{\mathrm {p}}X}$employing the BGV homomorphic encryption scheme. In comparison to ciphers over a field of characteristic 2, the outcomes evince that$ \mathsf {Yu_{2}X}$-8 (over$ \mathbb {F}_{2^{8}}^{16}$) and$ \mathsf {Yu_{2}X}$-16 (over$ \mathbb {F}_{2^{16}}^{16}$) achieve remarkably competitive throughputs, boasting performance approximately 12 times, 17 times, and 9 times superior to AES-128, CHAGHRI, and LowMC-128 (under 128-bit security), respectively. Furthermore, when juxtaposed with ciphers over a field of characteristic$p$, the outcomes affirm that the throughput of$ \mathsf {Yu_{\mathrm {p}}X}$-65537 (over$ \mathbb {F}_{65537}^{16}$) retains considerable competitiveness, registering an approximate fivefold enhancement relative to HERA. Evidently,$ \mathsf {YuX}$exhibits superior throughput compared to a majority of symmetric ciphers within this category.
Yongqiang Li 0001, Lin Jiao, Mingsheng Wang
IEEE Trans. Inf. Theory4
2023 Quantum Algorithm for Finding Impossible Differentials and Zero-Correlation Linear Hulls of Symmetric Ciphers
Yongqiang Li 0001, Parhat Abla, Zhiran Li, Lin Jiao, Mingsheng Wang
ACISP5
2023 Key Filtering in Cube Attacks from the Implementation Aspect
Yonglin Hao, Qingju Wang 0001, Xinxin Gong, Lin Jiao
CANS5
2023 OSAF-Net: A one-stage anchor-free detector for small-target crop pest detection
Rujing Wang, Shifeng Dong, Lin Jiao, Jianming Du, Ziliang Huang, Shijian Zheng, Chenrui Kang
Appl. Intell.3
2023 Guess-and-determine attacks on SNOW-Vi stream cipher
Lin Jiao, Yonglin Hao, Yongqiang Li 0001
Des. Codes Cryptogr.1
2023 An Underwater Image Restoration Method Based on Adaptive Brightness Improvement and Local Image Descattering
abstract
This letter proposes an effective underwater image restoration method that consists of a local image descattering and an adaptive brightness improvement. First, we establish an adaptive objective function for improving the brightness of underwater image according to the best-preserved channel of an image, and an augmented Lagrange multiplier based alternating direction minimization algorithm is derived to solve the optimization problem. Second, we introduce a local transmission estimation method that takes into account the different attenuation of light on the red, green and blue channels, which overcomes the limitation that existing methods heavily depend on the global transmission over the entire image. Extensive experiments on real-world underwater images demonstrate the effectiveness of the proposed method in underwater image restoration. Moreover, our method shows good generalization capability for enhancing remote sensing and nighttime images.
Zheng Liang 0001, Rui Ruan, Lin Jiao, Weidong Zhang 0007, Peixian Zhuang
IEEE Geosci. Remote. Sens. Lett.3
2023 An attention-based feature pyramid network for single-stage small object detection
Lin Jiao, Chenrui Kang, Shifeng Dong, Peng Chen 0001, Gaoqiang Li, Rujing Wang
Multim. Tools Appl.1
2022 New Division Property Propagation Table: Applications to Block Ciphers with Large S-boxes
abstract
Abstract The division property method is a technique for automatic searching integral distinguishers on block ciphers. Previous methods only use word-based division property to search integral distinguishers for block ciphers with large S-boxes. Since using bit-based division property may find longer integral distinguishers than word-based division property, we propose a method to automatically search the integral distinguishers based on bit-based division property for block ciphers with large S-boxes. To achieve this goal, we propose a new division property propagation table for S-boxes. Theoretically, we prove that using both the new table and the traditional method to describe the bit-based division property propagation rule of S-box will lead to the same integral distinguishers. Technically, we design a mixed-integer linear programming-based tool to search the integral distinguisher based on the new table, which helps to search new integral distinguishers for block ciphers with large S-boxes efficiently. As a result, we apply our tool to derive new integral distinguishers and get the tight bound on the rounds that no integral distinguishers exist for ICEBERG, KHAZAD, Camellia, CS-Cipher, ITUbee and SMS4. Besides, to show the availability of our integral distinguishers, we form the present best five-round and the first six-round integral attack for ICEBERG as an example.
Xichao Hu, Yongqiang Li 0001, Lin Jiao, Mingsheng Wang
Comput. J.3
2022 Guess-and-Determine Attacks on AEGIS
abstract
Abstract AEGIS is one of the authenticated encryption with associated data designs selected for the final portfolio of the CAESAR competition. It combines the AES round function and simple Boolean operations to update its large state and extract a keystream to achieve an excellent software performance. The AEGIS family consists of AEGIS-128, AEGIS-256 and AEGIS-128L, which use 5, 6 and 8 parallel AES round functions to process 128, 128 and 256 bits message block per step with slightly different output functions separately. Surprisingly, very few cryptanalytic results on AEGIS have been published so far. This paper presents the first guess-and-determine attacks on AEGIS family. Firstly, we propose a new observation on the structure of AEGIS that the relations of fixed variables remain in the outputs at consecutive steps under some conditions on the AND operations, and the vectorial bitwise AND operation is biased, which is able to derive the additional variables added directly. Secondly, we add several techniques, such as divide and conquer on byte-based columns, reduction by meet in the middle and simplification through constraints on variables, for each AEGIS member. Finally, we conduct guess-and-determine attacks on AEGIS-128, AEGIS-256 and AEGIS-128L and result in a complexity of $2^{309}$, $2^{437}$ and $2^{384}$ to $2^{416}$, respectively. Although neither attack threatens the practical security of AEGIS, it has great significance to evaluate the resistance of such structure compared with their large internal state exploited of 640, 768 and 1024 bits. It is also the first internal state recovery attack on AEGIS without nonce reusing, while only distinguishing attacks on AEGIS exist up to now.
Lin Jiao, Yongqiang Li 0001, Shaoyu Du
Comput. J.1
2022 On the upper bound of squared correlation of SIMON-like functions and its applications
abstract
Abstract SIMON is one of the lightweight block ciphers designed by the National Security Agency in 2013, and a technical report including security analysis was published by the design team nearly 4 years later. As for the linear attack, it is claimed that ‘the single‐path probabilities (and linear correlations) dip below 2 −block size for 12, 16, 20, 29, and 38 rounds for SIMON32, 48, 64, 96, and 128, respectively’. However, the design team does not show details on how to get the result and there are also no published papers verified the result yet. In the present paper, an upper bound of squared correlation of SIMON‐like functions is given. As an important application of this bound, how to find optimal linear characteristics of SIMON and SIMECK under the Markov assumption with Matsui's branch‐and‐bound algorithm is shown. The authors’ results confirm the claim of the design team. Furthermore, the best‐known linear‐hull distinguishers for SIMON and SIMECK is also given.
Zhengbin Liu, Yongqiang Li 0001, Lin Jiao, Mingsheng Wang
IET Inf. Secur.3
2022 Towards densely clustered tiny pest detection in the wild environment
Jianming Du, Liu Liu 0012, Rui Li 0027, Lin Jiao, Chengjun Xie, Rujing Wang
Neurocomputing4
2021 FAN: A Lightweight Authenticated Cryptographic Algorithm
Lin Jiao, Dengguo Feng, Yonglin Hao, Xinxin Gong, Shaoyu Du
CT-RSA1
2021 A New Method for Searching Optimal Differential and Linear Trails in ARX Ciphers
abstract
In this paper, we propose an automatic tool to search for optimal differential and linear trails in ARX ciphers. It’s shown that a modulo addition can be divided into sequential small modulo additions with carry bit, which turns an ARX cipher into an S-box-like cipher. From this insight, we introduce the concepts of carry-bit-dependent difference distribution table (CDDT) and carry-bit-dependent linear approximation table (CLAT). Based on them, we give efficient methods to trace all possible output differences and linear masks of a big modulo addition, with returning their differential probabilities and linear correlations simultaneously. Then an adapted Matsui’s algorithm is introduced, which can find the optimal differential and linear trails in ARX ciphers. Besides, the superiority of our tool’s potency is also confirmed by experimental results for round-reduced versions of HIGHT and SPECK. More specifically, we find the optimal differential trails for up to 10 rounds of HIGHT, reported for the first time. We also find the optimal differential trails for 10, 12, 16, 8 and 8 rounds of SPECK32/48/64/96/128, and report the provably optimal differential trails for SPECK48 and SPECK64 for the first time. The optimal linear trails for up to 9 rounds of HIGHT are reported for the first time, and the optimal linear trails for 22, 13, 15, 9 and 9 rounds of SPECK32/48/64/96/128 are also found respectively. These results evaluate the security of HIGHT and SPECK against differential and linear cryptanalysis. Also, our tool is useful to estimate the security in the design of ARX ciphers.
Zhengbin Liu, Yongqiang Li 0001, Lin Jiao, Mingsheng Wang
IEEE Trans. Inf. Theory3
2020 Mind the Propagation of States - New Automatic Search Tool for Impossible Differentials and Impossible Polytopic Transitions
Xichao Hu, Yongqiang Li 0001, Lin Jiao, Shizhu Tian, Mingsheng Wang
ASIACRYPT (1)3
2020 Stream cipher designs: a review
Lin Jiao, Yonglin Hao, Dengguo Feng
Sci. China Inf. Sci.1
2020 A Guess-And-Determine Attack On SNOW-V Stream Cipher
abstract
Abstract The 5G mobile communication system is coming with a main objective, known also as IMT-2020, that intends to increase the current data rates up to several gigabits per second. To meet an accompanying demand of the super high-speed encryption, EIA and EEA algorithms face some challenges. The 3GPP standardization organization expects to increase the security level to 256-bit key length, and the international cryptographic field responds actively in cipher designs and standard applications. SNOW-V is such a proposal offered by the SNOW family design team, with a revision of the SNOW 3G architecture in terms of linear feedback shift register (LFSR) and finite state machine (FSM), where the LFSR part is new and operates eight times the speed of the FSM, consisting of two shift registers and each feeding into the other, and the FSM increases to three 128-bit registers and employs two instances of full AES encryption round function for update. It takes a 128-bit IV, employs 896-bit internal state and produces 128-bit keystream blocks. The result is competitive in pure software environment, making use of both AES-NI and AVX acceleration instructions. Thus, the security evaluation of SNOW-V is essential and urgent, since there is scarcely any definite security bound for it. In this paper, we propose a byte-based guess-and-determine attack on SNOW-V with complexity $2^{406}$ using only seven keystream blocks. We first improve the heuristic guessing-path auto-searching algorithm based on dynamic programming by adding initial guessing set, which is iteratively modified by sieving out the unnecessary guessing variables, in order to correct the guessing path according to the cipher structure and finally launch smaller guessing basis. For the specific design, we split all the computing units into bytes and rewrite all the internal operations correspondingly. We establish a backward-clock linear equation system according to the circular construction of the LFSR part. Then we further simplify the equations to adapt to the input requirements of the heuristic guessing-path auto-searching algorithm. Finally, the derived guessing path needs modification for the pre-simplification and post-reduction. This is the first complete guess-and-determine attack on SNOW-V as well as the first specific security evaluation to the full cipher.
Lin Jiao, Yongqiang Li 0001, Yonglin Hao
Comput. J.1
2020 Specifications and improvements of LPN solving algorithms
abstract
The hardness of LPN problems serves as security source of many primitives in lightweight and post‐quantum cryptography, which enjoy extreme simplicity and efficiency for various applications. Accordingly there are several LPN solving algorithms proposed over past decade, and received quite a lot of attention recently. In this paper, we propose a new LPN solving algorithm using covering codes in the existing algorithmic framework with a new data structure of numerical value instead of vector quantity for convenience in table look‐up, integrate the optimized procedures, and further presenting four main improvements. Firstly, we apply the technique of binary tree sum in Gaussian elimination and new BKW iterations. Secondly, we propose a global BKW collision optimization with tweakable reduction length, which is proved optimized. Thirdly, we extend the covering codes scope in service for lager bias and smaller data requirement with a bias estimation strategy. Finally, we propose a detailed parameter selection principle for given LPN instances. The best known classic results are given for the (512/532/592,1/8)‐instances suggested in cryptographic schemes. Besides, we evaluate the performance on low‐noise LPN and (k,1/4)‐LPN instances, and further correct the lower length bounds of LPN instances with various bias for security levels of NIST's Post‐Quantum Call.
Lin Jiao
IET Inf. Secur.1
2020 RFP-Net: Receptive field-based proposal generation network for object detection
Lin Jiao, Shengyu Zhang 0004, Shifeng Dong
Neurocomputing1
2020 C-FCN: Corners-based fully convolutional network for visual object detection
Lin Jiao, Rujing Wang, Chengjun Xie
Multim. Tools Appl.1
2019 Improved guess-and-determine attack on TRIVIUM
abstract
TRIVIUM is a stream cipher of the finalists by eSTREAM project and has been accepted as ISO standard. Although the design has a simple structure, no attack on its full cipher has been found yet. In this study, based on Maximov and Biryukov's attack, the authors present an improved guess‐and‐determine attack on TRIVIUM. Analysis details are provided corresponding to TRIVIUM specifications for better comprehension, and errors that may lead to higher attack complexity in the original attack are pointed and corrected. They further bring in some techniques like backward‐clock equation collection, quadratic equations, linear transformation to improve the attack. In addition, they integrate with time‐memory‐data tradeoffs from the framework, based on the analysis of the coefficient matrices form of derived linear equation systems on the internal state. In this way, better use of the imposed quadratic conditions can be made, which leads to reduced attack complexity by filtering out the impossible keystreams before solving the equation systems. Their attack offers more parameter selections, and gives several borderline results compared with the key exhaustive search. The new attack behaves better in the original case. It also verifies the necessity of data requirement imposed on TRIVIUM, which is questioned in TRIVIUM specifications.
Lin Jiao, Yonglin Hao, Yongqiang Li 0001
IET Inf. Secur.1
2019 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
abstract
At CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively.
Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001
IEEE Trans. Computers3
2018 Guess-and-determine attacks on PANAMA-like stream ciphers
abstract
Guess‐and‐determine attack is a cryptanalysis method that has been applied to various stream ciphers. In this study, the authors study the guess‐and‐determine attacks on two ISO standardised, P anama ‐like stream ciphers: MUGI and Enocoro. Utilising the word‐oriented structure of the two ciphers, they are able to launch heuristic guess‐and‐determine attacks in a more efficient manner. Their first target MUGI is both an ISO standard and a Japanese‐government‐selected CRYPTREC standard. By splitting its basic 64‐bit words into 16‐bit quarter‐words, they are able to conduct a guess‐and‐determine attack with complexity 2 388 , much lower than its 1216‐bit internal state size. Enocoro is a lightweight stream cipher family. It has two versions named according to key‐length as Enocoro‐80 and Enocoro‐128v2. They provide the specific guessing paths and they are able to launch guess‐and‐determine attacks on Enocoro‐80 and Enocoro‐128v2 with complexities 2 88 and 2 144 , respectively. In addition to specific attacking results, they also find some generic rules that may help to improve the efficiency of guess‐and‐determine attacks in the future.
Lin Jiao, Yongqiang Li 0001, Yonglin Hao
IET Inf. Secur.1
2016 Faster Algorithms for Solving LPN
Lin Jiao, Mingsheng Wang
EUROCRYPT (1)2
2015 Two Generic Methods of Analyzing Stream Ciphers
Lin Jiao, Mingsheng Wang
ISC1
2014 Revised Algorithms for Computing Algebraic Immunity against Algebraic and Fast Algebraic Attacks
Lin Jiao, Mingsheng Wang
ISC1
2013 Establishing Equations: The Complexity of Algebraic and Fast Algebraic Attacks Revisited
Lin Jiao, Mingsheng Wang
ISC1
2012 An Improved Time-Memory-Data Trade-Off Attack against Irregularly Clocked and Filtered Keystream Generators
Lin Jiao, Mingsheng Wang, Yongqiang Li 0001
Inscrypt1