EDBT 2026 Demo / reviewers in the wild / expert
Wenling Wu
dblp:74/2464
· DBLP profile ↗
105ranked-venue papers
10as first author
30since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 84 · 5 first-author · 22 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 5 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3Theory of computation · 3Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security analysis of the P-SPN structure with a class of linear layer matrix against invariant subspace attack
Ee Duan, Wenling Wu |
Des. Codes Cryptogr. | 2 |
| 2026 | Construction of correctors using resilient fragmentary Boolean functions
Yaoda Hu, Yu Zhang 0216, Wenling Wu |
Des. Codes Cryptogr. | 3 |
| 2026 | Research on constructing integral distinguishers for block ciphers via the division property
Yu Zhang 0216, Wenling Wu, Yafei Zheng, Lei Zhang 0186, Yongxia Mao |
Des. Codes Cryptogr. | 2 |
| 2025 | Vectorial Fast Correlation Attacks
Bin Zhang 0003, Ruitao Liu, Willi Meier, Siwei Sun, Dengguo Feng, Wenling Wu |
ASIACRYPT (1) | 6 |
| 2025 | Quantum IND-CPA Security Notions for AEAD
Wenling Wu, Han Sui |
PQCrypto (2) | 2 |
| 2025 | A new automatic framework for searching rotational-XOR differential characteristics in ARX ciphers
Yafei Zheng, Wenling Wu |
Des. Codes Cryptogr. | 4 |
| 2024 | Efficient Search for Optimal Permutations of Refined Type-II Generalized Feistel Structures
Wenling Wu, Ee Duan |
ACISP (1) | 2 |
| 2024 | LOL: a highly flexible framework for designing stream ciphers
Dengguo Feng, Lin Jiao, Yonglin Hao, Qun-Xiong Zheng, Wenling Wu, Wen-Feng Qi 0001, Siwei Sun, Tian Tian 0004 |
Sci. China Inf. Sci. | 5 |
| 2024 | New Integral Distinguishers On Permutation Of WhirlpoolabstractAbstract Whirlpool is a hash function that has been standardized by ISO/IEC. In this paper, we develop a new type of distinguishing property for its underlying permutation $ W $. Division property proposed by Todo at EUROCRYPT 2015 was initially used in the integral cryptanalysis of symmetric-key algorithms. This work for the first time utilizes the MILP method to search for the integral distinguishers of $ W $ in both the forward and backward directions while concentrating on word-based division property. Under the known-key model, the fact that the permutation used in the hash function does not depend on any secret parameters allows the previous properties to be exploited from the middle, i.e. from an intermediate internal state. Therefore, we apply the inside-out strategy which is the essential step in the zero-sum property to connect the trails in opposite directions. Consequently, we obtain new distinguishers up to full rounds for the $ W $. To further reduce the complexity of the integral distinguishers, we add one round in the middle with the help of subspace trails. Finally, we succeed in extending the length and improving the complexity of the integral distinguishers. To the best of our knowledge, all the results in this paper are competitive with the previous work in both computational cost and memory complexity. It is worth mentioning that the methods presented in this paper are applicable to a broad class of hash functions. Wenling Wu, Yuhan Zhang 0009 |
Comput. J. | 2 |
| 2024 | Explicit Upper Bound Of Impossible Differentials For AES-Like Ciphers: Application To uBlock And MidoriabstractAbstract Whether a block cipher can resist impossible differential attack is an important basis to evaluate the security of a block cipher. However, the length of impossible differentials is important for the security evaluation of block ciphers. Most of the previous studies are based on structural cryptanalysis to find the impossible differential, and the structural cryptanalysis covers a lot of specific cryptanalytic vectors which are independent of the nonlinear S-boxes. In this paper, we study the maximum length of the impossible differential of an Advanced Encryption Standard-like cipher in the setting with the details of S-boxes. Inspired by the ‘Divide-and-Conquer’ technique, we propose a new technique called Reduced Block, which combines the details of the S-box. With this tool, the maximum length of impossible differentials can be proven under reasonable assumptions. As applications, we use this tool on uBlock and Midori. Consequently, we prove that for uBlock-128, uBlock-256 and Midori-64, there are no impossible five-round, six-round and seven-round differentials with one active input nibble and one active output nibble, even when considering the details of S-boxes. Furthermore, we reveal some properties of the uBlock S-box and linear layer and demonstrate theoretically that there are no impossible differentials longer than four rounds for uBlock-128 under the assumption that the round keys are independent and uniformly random. This study might provide some insight into the bounds of the length of impossible differentials. Yu Zhang 0216, Wenling Wu, Yongxia Mao, Yafei Zheng |
Comput. J. | 3 |
| 2024 | Yoyo attack on 4-round Lai-Massey scheme with secret round functions
Danxun Zhang, Wenling Wu |
Des. Codes Cryptogr. | 4 |
| 2024 | Security analysis of P-SPN schemes against invariant subspace attack with inactive S-boxes
Wenling Wu |
Des. Codes Cryptogr. | 2 |
| 2024 | New Differential-Based Distinguishers for Ascon via Constraint ProgrammingabstractAs the winner of the NIST lightweight cryptography project, Ascon has undergone extensive self‐evaluation and third‐party cryptanalysis. In this paper, we use constraint programming (CP) as a tool to analyze the Ascon permutation and propose several differential‐based distinguishers. We first propose a search methodology for finding truncated differentials for Ascon with CP, the core of which is modeling with the undisturbed bits of the S‐box. By using this method, we find the five‐ and six‐round truncated differentials with a probability of 2 −44 and 2 −162 , respectively. Considering the application of permutation in the context, we also provide the five‐ and six‐round truncated differential distinguishers under the weak‐key setting. Then, inspired by our five‐round truncated differentials, we propose a six‐round boomerang characteristic, and based on this, we obtain the five‐ and six‐round sandwich distinguishers with a complexity of 2 70 and 2 134 , respectively. Using the CP tool again and specifying that the “3‐3” differential pattern is satisfied in the middle rounds, we propose a six‐round differential characteristic with a probability of 2 −280 , which increases the probability by 2 25 compared to the best known six‐round differential characteristic. Chan Song, Wenling Wu, Lei Zhang 0186 |
IET Inf. Secur. | 2 |
| 2024 | Single-Key Attack on Full-Round Shadow Designed for IoT NodesabstractWith the rapid advancement of the Internet of Things (IoT), many innovative lightweight block ciphers have been introduced to meet the stringent security demands of IoT devices. Among these, the Shadow cipher stands out for its compactness, making it particularly well-suited for deployment in resource-constrained IoT nodes (IEEE Internet of Things Journal, 2021). This paper demonstrates two real-time attacks on Shadow for the first time: real-time plaintext recovery and key recovery. Firstly, numerous properties of Shadow are discussed, illustrating an equivalent representation of the two-round Shadow and the relationship between the round keys. Secondly, we introduce multiple two-round iterative linear approximations. Employing these approximations enables the derivation of full-round linear distinguishers. Moreover, we have uncovered numerous linear relationships between plaintext and ciphertext. Real-time plaintext recovery is achievable based on these established relationships. On average, it takes 5 seconds to recover the plaintext for a fixed ciphertext of Shadow-32. Thirdly, many properties of the propagation of difference through SIMON-like function are illustrated. According to these properties, various differential distinguishers up to full rounds are presented, allowing real-time key recovery. Specifically, the 64-bit master key of Shadow-32 can be retrieved in around two days on average. Experiments verify all our results. Yuhan Zhang 0009, Wenling Wu, Lei Zhang 0186, Yafei Zheng |
IEEE Trans. Computers | 2 |
| 2024 | Dedicated Quantum Attacks on XOR-Type Function With Applications to Beyond-Birthday- Bound MACsabstractA lot of work in the field of quantum cryptanalysis is currently devoted to finding applications of Grover-meets-Simon algorithm and its complexity is given in the form of$\mathcal {O}$, but research on how to implement the attack efficiently is still insufficient. After all, it is crucial to study quantum attacks in resource-limited situations, according to NIST’s guidance on circuit depth. This work first evaluates the parallelization of Grover-meets-Simon by drawing on the Grover’s parallel approach and shows that as the width increases by$2^{t}(t\gt 0)$, the depth decreases by a factor of$\sqrt {2^{t}}$. Further, the first dedicated quantum attack on a class of functions that appear in cryptographic scheme applications (so-called XOR-type function) is proposed. The depth, width, and the number of gates required for the attack are greatly reduced compared to the general parallelization. Then we apply the attack to various Beyond-Birthday-Bound (BBB) MACs, where the XOR function can be constructed, includingSUM-ECBCand its variants (2K-SUM-ECBC,2K-ECBC_Plus), andGCM-SIV2. In the typical case whereSUM-ECBCis based on AES-128, our attack saves at least 62.3% in depth, 19.5% in width and 22.2% in gate count simultaneously. The impact on some lightweight ciphers is further explored, and it is interesting to note that the lighter the quantum circuit implementation of the cipher is, the greater the possible impact of an attack will be. This observation may provide new insights into quantum cryptanalysis. Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Han Sui, Senpeng Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Related-Cipher Attacks: Applications to Ballet and ANT
Yongxia Mao, Wenling Wu, Yafei Zheng, Lei Zhang 0186 |
ACISP | 2 |
| 2023 | Constructing Binary Matrices with Good Implementation Properties for Low-Latency Block Ciphers based on Lai-Massey StructureabstractAbstract Diffusion layers are crucial components for lightweight cryptographic schemes. Optimal binary matrices are widely used diffusion layers that can be easier to achieve the best security/performance trade-off. However, most of the constructions of binary matrices are concentrated in smaller dimensions. Besides, to maximize the number of branches, the performance is often neglected. In this paper, we investigate the diffusion of the Lai-Massey (L-M) structures and propose a series of binary diffusion layers with the best possible branch number and efficient software/hardware implementations as well for feasible parameters (up to 64). Firstly, we prove the lower bound of the circuit depth of a binary matrix with a fixed branch number. Then, we construct binary matrices by L-M structure with cyclic shift as round functions because of taking account of the improvement of software performance and demonstrate that this construction can not get the diffusion layers with branch number >4. Then, we get some 4 $\times $ 4 and 6 $\times $ 6 optimal binary matrices with branch number 4 by one-round L-M structure. Note that the depth of these results is optimal, i. e. they achieve the lowest hardware costs without loss of software efficiency. Secondly, we construct diffusion layers by extended L-M structures to obtain binary matrices with large sizes. We give a list of software/hardware friendly optimal binary matrices with large dimensions, especially for dimensions 48 and 64. In particular, some of the solutions are Maximum Distance Binary Linear matrices. Finally, we also present diffusion layers constructed by the extended generalized L-M structure to improve their applicabilities on other platforms. Wenling Wu |
Comput. J. | 2 |
| 2023 | Cryptanalysis on Reduced-Round 3D and SaturninabstractAbstract 3D is an Advanced Encryption Standard (AES)-like cipher employed 3D structure proposed in 2008. The main innovation of 3D is the multi-dimensional state, generalizing the design of Rijndael and allowing block sizes beyond the 256-bit boundary. Saturnin, a lightweight block cipher has been selected as a second-round candidate in the National Institute of Standards and Technology standardization for lightweight cryptography. It also employs a 3D structure and provides high security against quantum and classic attacks. The exchange-equivalence attacks proposed by Bardeh and Rønjom consider how quadruples of plaintexts confirm distinguishable properties for AES. It is similar to the principle of yoyo attack, but it can find a longer number of rounds of distinguisher. In this paper, we investigate the exchange-equivalence attack on 3D and yoyo attack on Saturnin. Our new results turn out to be the first secret-key chosen plaintext distinguisher for 10-round 3D. The complexity of the distinguisher is about $2^{364.2}$ in terms of data, memory and computational complexity. For Saturnin, we propose the first six-super-round impossible differential yoyo attack, which is suitable for the two-S-layer version. Compared with the previous impossible differential attacks in the design report of Saturnin, the attacks presented here are the best in terms of the complexity under the chosen-plaintext scenario. Li Zhang 0108, Wenling Wu, Yafei Zheng |
Comput. J. | 2 |
| 2023 | Post-quantum security on the Lai-Massey scheme
Zhongya Zhang, Wenling Wu, Han Sui |
Des. Codes Cryptogr. | 2 |
| 2023 | Similarity Property and Slide Attack of Block Cipher FESHabstractThis paper focuses on similarity properties and extension of the classical slide property of block ciphers. Taking FESH, an award‐winning block cipher of the National Cryptographic Algorithm Design Competition 2019, as an example, similarity properties of the encryption and key transformation are found, owing to the similar structures that the encryption and key transformation adopted, and the constants generation. Based on the similarity properties, extended slide properties can be constructed for FESH. Slide attacks of FESH are then proposed. The similarity properties and extended slide property are immune to the increasing of iterated rounds, i.e., it cannot be avoided by increasing the round number of FESH. Furthermore, extended slide property helps relaxing the strict requirements of the subkeys in slide attacks. Taking Feistel and SPN structures as examples, frameworks of slide attacks based on the extended slide properties are presented. Slide attack of FESH is exactly a concrete example of SPN structure. Yafei Zheng, Wenling Wu |
IET Inf. Secur. | 2 |
| 2023 | New Key-Independent Structural Properties of AES-Like PermutationsabstractThe Internet of Things (IoT) technology makes our lives very simple and convenient by interacting with sensors/devices around the world and using the smart data collected from them. However, IoT devices typically have a resource-constrained architecture, rendering them vulnerable to cyberattacks. The advent of lightweight cryptography provides an opportunity to meet the challenges of IoT. With the promotion of 5G (5th generation wireless systems) technology, the amount of data in IoT devices is bound to grow rapidly. The design and analysis of lightweight block cipher is still a hot issue that needs to be solved in the coming period of time, as it responds to the strong push of many national governments to adopt IoT systems in the management of public affairs. MANTIS is a new tweakable block cipher suitable for IoT with the goal of low-latency implementations and it has drawn lots of attention in the form of prior cryptanalysis. This work first reveals a novel property of MANTIS. The characteristic is established under the condition that there is a certain equivalence relation between the input pairs in a particular subspace and it is evidenced by the first introduction of a key-independent distinguisher for 6-round MANTIS. We obtain that the number of input plaintext pairs in the same equivalence class is always divisible by 8. Then, we demonstrate a general and comprehensive proof as why it has to exist. Additionally, we have successfully verified the validity of the distinguisher. Only 216 chosen plaintexts and 222 table lookups computational cost are required to guarantee that the success probability exceeds 99%. Moreover, we discover that the same kind of property holds for other AES-like permutations with the example of the lightweight hash function PHOTON. Finally, we put forward some future explorations in this promising field. Wenling Wu |
IEEE Internet Things J. | 2 |
| 2022 | Improved Division Property for Ciphers with Complex Linear Layers
Yongxia Mao, Wenling Wu, Li Zhang 0108 |
ACISP | 2 |
| 2022 | Improved Differential Attack on Round-Reduced LEA
Yuhan Zhang 0009, Wenling Wu, Lei Zhang 0186 |
ACISP | 2 |
| 2022 | LLLWBC: A New Low-Latency Light-Weight Block Cipher
Lei Zhang 0186, Ruichen Wu, Yuhan Zhang 0009, Yafei Zheng, Wenling Wu |
Inscrypt | 5 |
| 2022 | Lattice-Based Fault Attacks on Deterministic Signature Schemes of ECDSA and EdDSA
Weiqiong Cao, Hongsong Shi, Hua Chen 0011, Jiazhe Chen, Limin Fan, Wenling Wu |
CT-RSA | 6 |
| 2022 | Effective approximation of high-dimensional space using neural networks
Jian Zheng 0004, Shuping Chen, Jingjin Chen, Wenlong Zhong, Wenling Wu |
J. Supercomput. | 7 |
| 2021 | Constructions of Iterative Near-MDS Matrices with the Lowest XOR Count
Wenling Wu |
ACISP | 2 |
| 2021 | On Characterization of Transparency Order for (n, m)-functions
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu |
Inscrypt | 6 |
| 2021 | Transparency Order of (n, m)-Functions - Its Further Characterization and Applications
Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Enes Pasalic, Wenling Wu |
ISC | 6 |
| 2021 | Breaking LWC candidates: sESTATE and Elephant in quantum setting
Tairong Shi, Wenling Wu, Bin Hu 0011, Jie Guan, Senpeng Wang |
Des. Codes Cryptogr. | 2 |
| 2020 | Quantum Circuit Implementations of AES with Fewer Qubits
Jian Zou 0002, Zihao Wei, Siwei Sun, Ximeng Liu, Wenling Wu |
ASIACRYPT (2) | 5 |
| 2019 | New method to describe the differential distribution table for large S-boxes in MILP and its applicationabstractBased on the method of the H‐representation of the convex hull, the linear inequalities of all possible differential patterns of 4‐bit S‐boxes in the mix integer linear programming (MILP) model can be generated easily by the SAGE software. Whereas this method cannot be apply to 8‐bit S‐boxes. In this study, the authors propose a new method to obtain the inequalities for large S‐boxes with the coefficients belonging to integer. The relationship between the coefficients of the inequalities and the corresponding excluded impossible differential patterns is obtained. As a result, the number of inequalities can be lower than 4000 for the AES S‐box. Then, the new method for finding the best probability of the differential characteristics of 4–15 rounds SM4 in the single‐key setting is presented. Especially, the authors found that the 15‐round SM4 exists four differential characteristics with 12 active S‐boxes. The exact lower bound of the number of differentially active S‐boxes of the 16‐round SM4 is 15. The authors also found eight differential characteristics of the 19‐round SM4 with the probability . Lingchen Li, Wenling Wu, Lei Zhang 0012, Yafei Zheng |
IET Inf. Secur. | 2 |
| 2019 | On the extension and security of key schedule of GOSTabstractA type of simple key schedule especially suitable for lightweight block ciphers is defined as straightforward key schedule in this study. As a typical example, GOST‐type key schedule, which is an extension of the key schedules of Russian Standard GOST and its newly modified version GOST2, is introduced and classified. GOST2 is designed based on the GOST encryption structure with different but the same type of key schedule to overcome the weakness of GOST against self‐similarity properties‐based attacks. However, it has been shown in Fast Software Encryption 2017, the simple change in the key schedule is insufficient to offer 256‐bit security. By constructing an evaluation framework combining self‐similarity properties and meet‐in‐the‐middle attack, properties of GOST‐type key schedules are evaluated, and candidate key schedules are provided in this work. These candidate key schedules are able to provide much better security for GOST and GOST2 ciphers than their original key schedules, and the pre‐existing self‐similarity properties‐based attacks of full round GOST and GOST2 can be avoided. The designers of GOST and GOST2 should have been more cautious choosing the parameters of key schedules. The evaluation framework proposed can be used for reference in the design of other Feistel ciphers with straightforward key schedules. Yafei Zheng, Wenling Wu |
IET Inf. Secur. | 2 |
| 2018 | Improved meet-in-the-middle attacks on reduced-round Kalyna-128/256 and Kalyna-256/512
Li Lin 0003, Wenling Wu |
Des. Codes Cryptogr. | 2 |
| 2018 | New algorithms for the unbalanced generalised birthday problemabstractIn this study, the authors present some new algorithms for the unbalanced generalised birthday problem (UGBP), which was proposed by Nikolić and Sasaki in their attacks on the generalised birthday problem (GBP). The authors’ first idea is simple, which uses some precomputing to convert UGBP into GBP. After the precomputing, they just adopt Wagner's k ‐tree algorithm or the algorithms of Bernstein et al . to solve UGBP. Their second idea combines the technique for the unbalanced meet‐in‐the‐middle problem with the improved time–memory trade‐off algorithm for GBP to solve UGBP. Besides, they will utilise the inactive technique and the rearrangement technique to improve the time complexities of their algorithms. The inactive technique is used to neglect the effect of some costly functions, and the rearrangement technique is adopted to balance the time costs between different functions. When k is not a power of 2, the time complexity of their algorithms for UGBP can also be improved by using the multicollision technique. Jian Zou 0002, Wenling Wu |
IET Inf. Secur. | 3 |
| 2017 | My Traces Learn What You Did in the Dark: Recovering Secret Signals Without Key Guesses
Hua Chen 0011, Wenling Wu, Limin Fan, Weiqiong Cao, Xiangliang Ma |
CT-RSA | 3 |
| 2017 | Improved Automatic Search Tool for Bit-Oriented Block Ciphers and Its Applications
Lingchen Li, Wenling Wu, Lei Zhang 0012 |
ICICS | 2 |
| 2017 | Improved Automatic Search Tool for Related-Key Differential Characteristics on Byte-Oriented Block Ciphers
Li Lin 0003, Wenling Wu, Yafei Zheng |
ISC | 2 |
| 2017 | Analysis of permutation choices for enhanced generalised Feistel structure with SP-type round functionabstractSince the proposition of improved generalised Feistel structure (GFS), many researches and applications have been published. In this study, the authors further enhance the improved GFS with SP‐type round function by extending the sub‐block‐wise permutation to word‐wise permutation which can have better diffusion and security effect. Then, they study the security effect of different permutation choices for this kind of enhanced GFS cipher with SP‐type round function. By proving several propositions about the equivalent situation, they can eliminate isomorphic permutations so as to narrow down the candidate space notably and propose a method to compute the number of effective permutation candidates. Finally, they take three typical scenes as example, and for each experimental scene, they compute the number of effective permutation candidates and exhaustively evaluate their security results. They also give an optimum permutation as example for each scene. Lei Zhang 0012, Wenling Wu |
IET Inf. Secur. | 2 |
| 2017 | New constructions of resilient functions with strictly almost optimal nonlinearity via non-overlap spectra functions
Yongzhuang Wei, Enes Pasalic, Fengrong Zhang, Wenling Wu, Cheng-Xiang Wang 0001 |
Inf. Sci. | 4 |
| 2016 | Linear Regression Attack with F-test: A New SCARE Technique for Secret Block Ciphers
Hua Chen 0011, Wenling Wu, Limin Fan, Jingyi Feng, Xiangliang Ma |
CANS | 3 |
| 2016 | Biclique Attack of Block Cipher SKINNY
Yafei Zheng, Wenling Wu |
Inscrypt | 2 |
| 2016 | New Observations on Piccolo Block Cipher
Wenling Wu |
CT-RSA | 2 |
| 2016 | Automatic Search for Key-Bridging Technique: Applications to LBlock and TWINE
Li Lin 0003, Wenling Wu, Yafei Zheng |
FSE | 2 |
| 2016 | Structural Evaluation for Simon-Like Designs Against Integral Attack
Wenling Wu |
ISPEC | 2 |
| 2016 | Security of SM4 Against (Related-Key) Differential Cryptanalysis
Wenling Wu, Yafei Zheng |
ISPEC | 2 |
| 2016 | Collision Attacks on CAESAR Second-Round Candidate: ELmD
Wenling Wu, Yafei Zheng |
ISPEC | 2 |
| 2016 | New criterion for diffusion property and applications to improved GFS and EGFN
Wenling Wu |
Des. Codes Cryptogr. | 2 |
| 2016 | Utilizing Probabilistic Linear Equations in Cube Attacks
Bin Zhang 0003, Wenling Wu |
J. Comput. Sci. Technol. | 3 |
| 2015 | A Single Query Forgery Attack on Raviyoyla v1abstractRaviyoyla v1 is an authenticated encryption algorithm submitted to the first round of the CAESAR competition which is a grand occasion launched recently to identify efficient, flexible and secure authenticated encryption primitives. Raviyoyla v1 is composed by an additive stream cipher motivated by the eSTREAM candidate MAG v2 and a keyed hash function. The designer declares $128$ bit security for authentication. In this paper, we propose a method to construct forgeries using a single query and the complexity is negligible. Indeed, we introduce differential of specific form to the public message and try to canceling it before outputting any authenticated tags. Specially, the differential is not restricted to any particular value and thus multiple forgeries may be made through a single query. Our theoretical analysis shows that the probability for a randomly selected differential of our form to be canceled out is at least $0.307143$. Therefore, it is sufficient to have three trials to obtain a forgery. Moreover, the probability can approaches one for some specialized values. Furthermore, the revised Raviyoyla v1 is vulnerable from our attack as well. Bin Zhang 0003, Wenling Wu |
AsiaCCS | 3 |
| 2015 | Practical Lattice-Based Fault Attack and Countermeasure on SM2 Signature Algorithm
Weiqiong Cao, Jingyi Feng, Shaofeng Zhu, Hua Chen 0011, Wenling Wu, Xucang Han, Xiaoguang Zheng |
ICICS | 5 |
| 2015 | Automatic Search for Linear Trails of the SPECK Family
Bin Zhang 0003, Wenling Wu |
ISC | 3 |
| 2015 | Constructing Lightweight Optimal Diffusion Primitives with Feistel Structure
Wenling Wu |
SAC | 2 |
| 2015 | Improved Meet-in-the-Middle Distinguisher on Feistel Schemes
Li Lin 0003, Wenling Wu, Yafei Zheng |
SAC | 2 |
| 2015 | The DBlock family of block ciphers
Wenling Wu, Lei Zhang 0012, Xiaoli Yu |
Sci. China Inf. Sci. | 1 |
| 2015 | Known-key distinguishers on 15-round 4-branch type-2 generalised Feistel networks with single substitution-permutation functions and near-collision attacks on its hashing modesabstractGeneralised Feistel network (GFN) is a popular design for block ciphers and hash functions. The round function of the network often chooses a substitution–permutation (SP) transformation (consists of a subkey XOR, an S‐boxes layer and a linear layer). In 2011, Bogdanov and Shibutani provided another choice to build round functions, namely the double SP‐functions, which has two SP‐layers in series. They showed that a 4‐branch type‐2 GFN with double SP‐functions was stronger than the one with single SP‐function in terms of the number of active S‐boxes in a differential or linear cryptanalysis, but some subsequent results showed that the double SP‐function is the weaker one in some known‐key scenarios and hashing modes. In this study, the authors present a new result of the 4‐branch type‐2 GFN, whose round function is a single SP‐function. They show some 15‐round truncated differential distinguishers for this network with four usual parameters by utilising some rebound attack techniques. Based on these distinguishers, they construct some 15‐round near‐collision attacks on the Matyas–Meyer–Oseas and Miyaguchi–Preneel compression function modes in which the 4‐branch type‐2 GFN with the single SP‐function is used. Wenling Wu, Jian Zou 0002 |
IET Inf. Secur. | 3 |
| 2015 | Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012 |
J. Cryptol. | 4 |
| 2014 | Improved Multidimensional Zero-Correlation Linear Cryptanalysis and Applications to LBlock and TWINE
Wenling Wu |
ACISP | 2 |
| 2014 | Differential Cryptanalysis and Linear Distinguisher of Full-Round Zorro
Wenling Wu, Xiaoli Yu |
ACNS | 2 |
| 2014 | Known-key distinguishers on type-1 Feistel scheme and near-collision attacks on its hashing modes
Wenling Wu, Shuang Wu 0004, Jian Zou 0002 |
Frontiers Comput. Sci. | 2 |
| 2014 | Differential analysis of the Extended Generalized Feistel Networks
Lei Zhang 0012, Wenling Wu |
Inf. Process. Lett. | 2 |
| 2013 | Leaked-State-Forgery Attack against the Authenticated Encryption Algorithm ALE
Shengbao Wu, Hongjun Wu 0001, Tao Huang 0015, Mingsheng Wang, Wenling Wu |
ASIACRYPT (1) | 5 |
| 2013 | LHash: A Lightweight Hash Function
Wenling Wu, Shuang Wu 0004, Lei Zhang 0012, Jian Zou 0002 |
Inscrypt | 1 |
| 2013 | Cryptanalysis of the Round-Reduced GOST Hash Function
Jian Zou 0002, Wenling Wu, Shuang Wu 0004 |
Inscrypt | 2 |
| 2013 | Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012 |
FSE | 4 |
| 2013 | Attacking and Fixing the CS Mode
Han Sui, Wenling Wu, Peng Wang 0009 |
ICICS | 2 |
| 2013 | Cryptanalysis of the OKH Authenticated Encryption Scheme
Peng Wang 0009, Wenling Wu |
ISPEC | 2 |
| 2012 | Extending Higher-Order Integral: An Efficient Unified Algorithm of Constructing Integral Distinguishers for Block Ciphers
Wentao Zhang 0006, Bozhan Su, Wenling Wu, Dengguo Feng, Chuankun Wu |
ACNS | 3 |
| 2012 | Investigating Fundamental Security Requirements on Whirlpool: Improved Preimage and Collision Attacks
Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004, Wenling Wu |
ASIACRYPT | 4 |
| 2012 | 3kf9: Enhancing 3GPP-MAC beyond the Birthday Bound
Wenling Wu, Han Sui, Peng Wang 0009 |
ASIACRYPT | 2 |
| 2012 | (Pseudo) Preimage Attack on Round-Reduced Grøstl Hash Function and Others
Shuang Wu 0004, Dengguo Feng, Wenling Wu, Jian Guo 0001, Jian Zou 0002 |
FSE | 3 |
| 2012 | Biclique Cryptanalysis of Reduced-Round Piccolo Block Cipher
Wenling Wu, Xiaoli Yu |
ISPEC | 2 |
| 2012 | Recursive Diffusion Layers for (Lightweight) Block Ciphers and Hash Functions
Shengbao Wu, Mingsheng Wang, Wenling Wu |
Selected Areas in Cryptography | 3 |
| 2012 | TrCBC: Another look at CBC-MAC
Wenling Wu, Peng Wang 0009 |
Inf. Process. Lett. | 2 |
| 2011 | LBlock: A Lightweight Block Cipher
Wenling Wu, Lei Zhang 0012 |
ACNS | 1 |
| 2011 | Cryptanalysis of Reduced-Round KLEIN Block Cipher
Xiaoli Yu, Wenling Wu, Lei Zhang 0012 |
Inscrypt | 2 |
| 2011 | BCBC: A More Efficient MAC Algorithm
Wenling Wu |
ISPEC | 2 |
| 2011 | PolyE+CTR: A Swiss-Army-Knife Mode for Block Ciphers
Wenling Wu, Peng Wang 0009 |
ProvSec | 2 |
| 2011 | CBCR: CBC MAC with rotating transformations
Wenling Wu, Lei Zhang 0012, Peng Wang 0009 |
Sci. China Inf. Sci. | 2 |
| 2010 | Near-Collisions on the Reduced-Round Compression Functions of Skein and BLAKE
Bozhan Su, Wenling Wu, Shuang Wu 0004 |
CANS | 2 |
| 2010 | Hyper-Sbox View of AES-like Permutations: A Generalized Distinguisher
Shuang Wu 0004, Dengguo Feng, Wenling Wu, Bozhan Su |
Inscrypt | 3 |
| 2010 | Constructing Rate-1 MACs from Related-Key Unpredictable Block Ciphers: PGV Model Revisited
Wenling Wu, Peng Wang 0009, Lei Zhang 0012, Shuang Wu 0004 |
FSE | 2 |
| 2010 | Integral Attacks on Reduced-Round ARIA Block Cipher
Wenling Wu, Lei Zhang 0012 |
ISPEC | 2 |
| 2009 | A note on Cook's elastic block cipherabstract"VIL Block Cipher" is a kind of block cipher that supports Variable Input-Lengths. It was first proposed by Bellare, etc. and since then several constructions have been given, among which Cook's elastic block cipher is a special one. In this paper we present a security model called "MIL model" for VIL block ciphers, investigating their security when a fixed secret key is used for multiple input-lengths. Our results show that if the key schedule is not well designed, Cook's elastic block cipher is vulnerable when processing multiple-length inputs under a fixed secret key. Thus, further considerations are needed to use Cook's elastic block cipher safely in practice. Wenling Wu, Lei Zhang 0012 |
AsiaCCS | 2 |
| 2009 | Proposition of Two Cipher Structures
Lei Zhang 0012, Wenling Wu |
Inscrypt | 2 |
| 2009 | Security Analysis of the GF-NLFSR Structure and Four-Cell Block Cipher
Wenling Wu, Lei Zhang 0012, Wentao Zhang 0006 |
ICICS | 1 |
| 2009 | On the Correctness of an Approach against Side-Channel Attacks
Peng Wang 0009, Dengguo Feng, Wenling Wu |
ISPEC | 3 |
| 2009 | Some New Observations on the SMS4 Block Cipher in the Chinese WAPI Standard
Wentao Zhang 0006, Wenling Wu, Dengguo Feng, Bozhan Su |
ISPEC | 2 |
| 2008 | On the Unprovable Security of 2-Key XCBC
Peng Wang 0009, Dengguo Feng, Wenling Wu |
ACISP | 3 |
| 2008 | Cryptanalysis of Reduced-Round SMS4 Block Cipher
Lei Zhang 0012, Wentao Zhang 0006, Wenling Wu |
ACISP | 3 |
| 2008 | Security of Truncated MACs
Peng Wang 0009, Dengguo Feng, Changlu Lin, Wenling Wu |
Inscrypt | 4 |
| 2008 | Analysis of Zipper as a Hash Function
Pin Lin, Wenling Wu, Chuankun Wu |
ISPEC | 2 |
| 2008 | Improved Impossible Differential Attacks on Large-Block Rijndael
Lei Zhang 0012, Wenling Wu, Je Hong Park, Bonwook Koo, Yongjin Yeom |
ISC | 2 |
| 2007 | Differential Fault Analysis on CLEFIA
Hua Chen 0011, Wenling Wu, Dengguo Feng |
ICICS | 2 |
| 2007 | Constructing parallel long-message signcryption scheme from trapdoor permutation
ZhenYu Hu, Dongdai Lin, Wenling Wu, Dengguo Feng |
Sci. China Ser. F Inf. Sci. | 3 |
| 2007 | Impossible Differential Cryptanalysis of Reduced-Round ARIA and Camellia
Wenling Wu, Wentao Zhang 0006, Dengguo Feng |
J. Comput. Sci. Technol. | 1 |
| 2006 | An Improved Poly1305 MAC
Dayin Wang, Dongdai Lin, Wenling Wu |
ACNS | 3 |
| 2006 | OPMAC: One-Key Poly1305 MAC
Dayin Wang, Dongdai Lin, Wenling Wu |
Inscrypt | 3 |
| 2006 | Pseudorandomness of Camellia-Like Scheme
Wenling Wu |
J. Comput. Sci. Technol. | 1 |
| 2006 | Incomplete exponential sums over galois rings with applications to some binary sequences derived from Z2labstractAn upper bound for the incomplete exponential sums over Galois rings is derived explicitly. Based on the incomplete exponential sums, we analyze the partial period properties of some binary sequences derived from Z/sub 2//sup l/ in detail, such as the Kerdock-code binary sequences and the highest level sequences of primitive sequences over Z/sub 2//sup l/. The results show that the partial period distributions and the partial period independent r-pattern distributions of these binary sequences are asymptotically uniform. Nontrivial upper bounds for the aperiodic autocorrelation of these sequences are also given. Honggang Hu, Dengguo Feng, Wenling Wu |
IEEE Trans. Inf. Theory | 3 |
| 2005 | On the Security of Tweakable Modes of Operation: TBC and TAE
Peng Wang 0009, Dengguo Feng, Wenling Wu |
ISC | 3 |
| 2005 | Collision attack on reduced-round CamelliaabstractCamellia is the final winner of 128-bit block cipher in NESSIE.In this paper, we construct some efficient distinguishers between 4-round Camellia and a random permutation of the blocks space.By using collision-searching techniques, the distinguishers are used to attack on 6,7,8 and 9 rounds of Camellia with 128bit key and 8,9 and 10 rounds of Camellia with 192/256-bit key.The 128-bit key of 6 rounds Camellia can be recovered with 2 10 chosen plaintexts and 2 15 encryptions.The 128-bit key of 7 rounds Camellia can be recovered with 2 12 chosen plaintexts and 2 54.5 encryptions.The 128-bit key of 8 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 112.1 encryptions.The 128-bit key of 9 rounds Camellia can be recovered with 2 113.6 chosen plaintexts and 2 121 encryptions.The 192/256-bit key of 8 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 111.1 encryptions.The 192/256-bit key of 9 rounds Camellia can be recovered with 2 13 chosen plaintexts and 2 175.6 encryptions.The 256-bit key of 10 rounds Camellia can be recovered with 2 14 chosen plaintexts and 2 239.9 encryptions. Wenling Wu, Dengguo Feng |
Sci. China Ser. F Inf. Sci. | 1 |
| 2002 | Linear cryptanalysis of NUSH block cipherabstractNUSH is a block cipher as a candidate for NESSIE. NUSH is analyzed by linear crypt-analysis. The complexity δ=(ε, η) of the attack consists of data complexity ε and time complexity η. Three linear approximations are used to analyze NUSH with 64-bit block. When | K |=128 bits, the complexities of three attacks are (2 58 , 2 124 ), (2 60 , 2 78 ) and (2 62 , 2 55 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 58 , 2 157 ) (2 60 , 2 96 ) and (2 62 , 2 58 ) respectively. When | K | =256 bits, the complexities of three attacks are (2 58 , 2 125 ), (2 60 , 2 78 ) and (2 62 , 2 53 ) respectively. Three linear approximations are used to analyze NUSH with 128-bit block. When | K |=128 bits, the complexities of three attacks are (2 122 , 2 95 ), (2 124 , 2 57 ) and (2 126 , 2 52 ) respectively. When | K |=192 bits, the complexities of three attacks are (2 122 , 2 142 ), (2 124 , 2 75 ) and (2 126 , 2 58 ) respectively. When | K |=256 bits, the complexities of three attacks are (2 122 , 2 168 ), (2 124 , 2 81 ) and (2 126 , 2 64 ) respectively. Two linear approximations are used to analyze NUSH with 256-bit block. When | K |=128 bits, the complexities of two attacks are (2 252 , 2 122 ) and (2 254 , 2 119 ) respectively. When | K |=192 bits, the complexities of two attacks are (2 252 , 2 181 ) and (2 254 , 2 177 ) respectively. When | K |=256 bits, the complexities of two attacks are (2 252 , 2 240 ) and (2 254 , 2 219 ) respectively. These results show that NUSH is not immune to linear cryptanalysis, and longer key cannot enhance the security of NUSH. Wenling Wu, Dengguo Feng |
Sci. China Ser. F Inf. Sci. | 1 |
| 2000 | Power Analysis of RC6 and Serpent
Wenling Wu, Dengguo Feng, Sihan Qing |
SEC | 1 |
| 1999 | Cryptanalysis of some AES Candidate Algorithms
Wenling Wu, Bao Li 0001, Dengguo Feng, Sihan Qing |
ICICS | 1 |