EDBT 2026 Demo / reviewers in the wild / expert
Chun Guo 0002
dblp:85/10076-2
· DBLP profile ↗
42ranked-venue papers
19as first author
26since 2021 · last 2026
0000-0002-8520-6301ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 40 · 18 first-author · 25 since 2021Theory of computation · 2 · 2 first-authorSystems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to Sponge
Chun Guo 0002, Kai Hu 0001, Shuntian Jiang, Yanhong Fan 0001, Bart Preneel |
CRYPTO (6) | 1 |
| 2026 | Upper Bound on Information-Theoretic Security of Permutation-Based Pseudorandom Functions
Chun Guo 0002, Jian Guo 0001, Xinnian Li, Wenjie Nan |
EUROCRYPT | 1 |
| 2026 | Hardware masking with buffer chainabstractAbstract Side-channel attacks pose a major threat to cryptographic implementations, as they can exploit physical leakages to recover secret information. Masking is one of the most widely adopted countermeasures, aiming to protect sensitive intermediate values by randomization. However, when deployed in hardware, masking faces the challenges from the glitch leakage, which can easily undermine the security integrity of masking techniques and affect the foundational independent assumptions upon which they are based. To address the intricacies of hardware implementation, circuit separation using registers has emerged as a straightforward method. In this paper, we investigate low-latency hardware masking by exploring the use of buffers (rather than registers) to prevent glitch propagation. Rather than directly inserting buffers into the circuit path, our approach involves employing a chain of buffers to generate signals that serve as controls, thereby synchronizing blocks that require sequential computation. This significantly reduces the power consumption of the shielding circuit while also decreasing latency within the circuit. Guofeng Qin, Chun Guo 0002, Hao Cheng 0009, Weijia Wang 0003 |
Cybersecur. | 3 |
| 2025 | Towards Quantum Security of Hirose Compression Function and Romulus-H
Chun Guo 0002 |
ACISP (2) | 2 |
| 2025 | Sequential Indifferentiability of 7-Round Misty Structures
Jiayi Ai, Chun Guo 0002 |
CT-RSA | 2 |
| 2025 | On tweakable correlation robust hashing against key leakages
Chun Guo 0002, Xiao Wang 0012, Kang Yang 0002, Yu Yu 0001 |
Des. Codes Cryptogr. | 1 |
| 2024 | Leakage-Resilient Circuit GarblingabstractDue to the ubiquitous requirements and performance leap in the past decade, it has become feasible to execute garbling and secure computations in settings sensitive to side-channel attacks, including smartphones, IoTs and dedicated hardwares, and the possibilities have been demonstrated by recent works. To maintain security in the presence of a moderate amount of leaked information about internal secrets, we investigate leakage-resilient garbling. We augment the classical privacy, obliviousness and authenticity notions with leakages of the garbling function, and define their leakage-resilience analogues. We examine popular garbling schemes and unveil additional side-channel weaknesses due to wire label reuse and XOR leakages. We then incorporate the idea of label refreshing into the GLNP garbling scheme of Gueron et al. and propose a variant GLNPLR that provably satisfies our leakage-resilience definitions. Performance comparison indicates that GLNPLR is 60X (using AES-NI) or 5X (without AES-NI) faster than the HalfGates garbling with second order side-channel masking, for garbling AES circuit when the bandwidth is 2Gbps. Chun Guo 0002, François-Xavier Standaert, Weijia Wang 0003, Xiao Wang 0012 |
CCS | 3 |
| 2024 | On the sequential indifferentiability of the Lai-Massey construction
Chun Guo 0002, Yiyuan Luo, Chenyu Xiao |
Des. Codes Cryptogr. | 1 |
| 2024 | CCA security for contracting (quasi-)Feistel constructions with tight round complexity
Chun Guo 0002, Ling Song 0001 |
Des. Codes Cryptogr. | 1 |
| 2024 | Improved Masking Multiplication with PRGs and Its Application to Arithmetic AdditionabstractAt Eurocrypt 2020, Coron et al. proposed a masking technique allowing the use of random numbers from pseudo‐random generators (PRGs) to largely reduce the use of expansive true‐random generators (TRNGs). For security against d probes, they describe a construction using 2 d PRGs, each of which is fed with at most 2 d random variables in a finite field, resulting in a randomness requirement of . In this paper, we improve the technique on multiple frontiers. On the theoretical level, we push the limits of the randomness requirement by providing an improved masking multiplication using only d PRGs, each of which is fed with d random variables, saving more than half random bits. On the practical level, considering that the masking of arithmetic addition usually requires more randomness (than multiplication), we apply the technique to the algorithm proposed at FSE 2015 that is a very efficient scheme performing arithmetic addition modulo 2 w . It significantly reduces the randomness cost of masked arithmetic addition, and further advocates the advantage of masking with PRGs. Furthermore, we apply our masking scheme to the Speck , XTEA , and Sparkle , and provide the first (to the best of our knowledge) higher order masked implementations for the ciphers using ARX structure. Qian Sui, Fanjie Ji, Chun Guo 0002, Weijia Wang 0003 |
IET Inf. Secur. | 4 |
| 2024 | Superposition Attacks on Pseudorandom Schemes Based on Two or Less PermutationsabstractWe study quantum superposition attacks against permutation‐based pseudorandom cryptographic schemes. We first extend Kuwakado and Morii’s attack against the Even–Mansour cipher and exhibit key recovery attacks against a large class of pseudorandom schemes based on a single call to an n ‐bit permutation, with polynomial O ( n ) (or O ( n 2 ), if the concrete cost of Hadamard transform is also taken in) quantum steps. We then consider schemes, namely, two permutation‐based pseudorandom cryptographic schemes. Using the improved Grover‐meet‐Simon method, we show that the keys of a wide class of schemes can be recovered with O ( n ) superposition queries (the complexity of the original is O ( n 2 n /2 )) and O ( n 2 n /2 ) quantum steps. We also exhibit subclasses of “degenerated” schemes that lack certain internal operations and exhibit more efficient key recovery attacks using either the Simon’s algorithm or collision searching algorithm. Further, using the all‐subkeys‐recovery idea of Isobe and Shibutani, our results give rise to key recovery attacks against several recently proposed permutation‐based PRFs, as well as the two‐round Even–Mansour ciphers with generic key schedule functions and their tweakable variants. From a constructive perspective, our results establish new quantum Q2 security upper bounds for two permutation‐based pseudorandom schemes as well as sound design choices. Chun Guo 0002, Qingju Wang 0001 |
IET Inf. Secur. | 2 |
| 2024 | ISA Extensions of Shuffling Against Side-Channel AttacksabstractShuffling is a time-randomized countermeasure against side-channel attacks. To achieve effective protections, shuffling is usually combined with other countermeasures, such as the masking. It requires the shuffling to be as efficient as possible. In this work, we describe an instruction set extensions (ISEs) for shuffling countermeasure. Our ISEs focuses on the generation of random permutations, which is the most difficult part to deploy the shuffling in microprocessors. The Thorp shuffling is implemented in hardware, enabling the instruction to generate random permutations. We design new ISEs compatible to the RISC-V standard instruction set format. Then, we present applications of our ISEs by giving two combinations of shuffling and masking, which can be regarded as promising software–hardware co-designs of side-channel countermeasures. At last, we embed the ISEs to the RISC-V core called tinyriscv, and evaluate the silicon overhead and the side-channel security of the shuffled masked AND operation. The evaluation shows that the new instruction can significantly improve the security of masking countermeasures. Jiayun Zhou, Guofeng Qin, Lu Li 0006, Chun Guo 0002, Weijia Wang 0003 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2023 | Algebraic Attacks on Round-Reduced Rain and Full AIM-III
Kaiyi Zhang 0001, Qingju Wang 0001, Yu Yu 0001, Chun Guo 0002, Hongrui Cui |
ASIACRYPT (3) | 4 |
| 2023 | Towards Minimizing Non-linearity in Type-II Generalized Feistel Networks
Chun Guo 0002, Weijia Wang 0003 |
CANS | 2 |
| 2023 | Impossibility of Indifferentiable Iterated Blockciphers from 3 or Less Primitive Calls
Chun Guo 0002, Lei Wang 0031, Dongdai Lin |
EUROCRYPT (4) | 1 |
| 2023 | Just tweak! Asymptotically optimal security for the cascaded LRW1 tweakable blockcipher
Chun Guo 0002 |
Des. Codes Cryptogr. | 3 |
| 2023 | Nonce-misuse resilience of Romulus-N and GIFT-COFBabstractAbstract Nonce‐misuse resilience (NMRL) security of Romulus‐N and GIFT‐COFB is analysed, the two finalists of NIST Lightweight Cryptography project for standardising lightweight authenticated encryption. NMRL, introduced by Ashur et al. at CRYPTO 2017, is a relaxed security notion from a stronger, nonce‐misuse resistance notion. The authors have proved that Romulus‐N and GIFT‐ COFB have nonce‐misuse resilience. For Romulus‐N, the perfect privacy (NMRL‐PRIV) and n /2‐bit authenticity (NMRL‐AUTH) with graceful degradation with respect to nonce repetition are showed. For GIFT‐COFB, n /4‐bit security for both NMRL‐PRIV and NMRL‐AUTH notions is showed. Akiko Inoue, Chun Guo 0002, Kazuhiko Minematsu |
IET Inf. Secur. | 2 |
| 2023 | Bit-Sliced Implementation of SM4 and New Performance RecordsabstractSM4 is a popular block cipher issued by the Office of State Commercial Cryptography Administration (OSCCA) of China. In this paper, we use the bit‐slicing technique that has been shown as a powerful strategy to achieve very fast software implementations of SM4. We investigate optimizations on two frontiers. First, we present a more efficient bit‐sliced representation for SM4, which enables running 64 blocks in parallel with 256‐bit registers. Second, we describe an optimized algorithm for data form transformations, also allowing efficient implementations of SM4 under Counter (CTR) mode and Galois/Counter mode. The above optimizations contribute to a significant performance gain on one core compared with the state‐of‐the‐art results. This work is an extension of the conference paper at Inscrypt 2022, awarded the best paper award. Lu Li 0006, Chun Guo 0002, Meiqin Wang 0001, Weijia Wang 0003 |
IET Inf. Secur. | 3 |
| 2023 | The Multi-User Constrained Pseudorandom Function Security of Generalized GGM Trees for MPC and Hierarchical WalletsabstractMulti-user (mu) security considers large-scale attackers that, given access to a number of cryptosystem instances, attempt to compromise at least one of them. We initiate the study of mu security of the so-called GGM tree that stems from the pseudorandom generator to pseudorandom function transformation of Goldreich, Goldwasser, and Micali, with a goal to provide references for its recently popularized use in applied cryptography. We propose a generalized model for GGM trees and analyze its mu prefix-constrained pseudorandom function security in the random oracle model. Our model allows to derive concrete bounds and improvements for various protocols, and we showcase on the Bitcoin-Improvement-Proposal standard Bip32 hierarchical wallets and function secret sharing protocols. In both scenarios, we propose improvements with better performance and concrete security bounds at the same time. Compared with the state-of-the-art designs, our SHACAL3 - and Keccak -p-based Bip32 variants reduce the communication cost of MPC-based implementations by 73.3% to 93.8%, whereas our AES -based function secret sharing substantially improves mu security while reducing computations by 50%. Chun Guo 0002, Xiao Wang 0012, Yu Yu 0001 |
ACM Trans. Priv. Secur. | 1 |
| 2022 | Provable Security of rmHADES Structure
Chun Guo 0002 |
CANS | 2 |
| 2022 | How Fast Can SM4 be in Software?
Chun Guo 0002, Weijia Wang 0003 |
Inscrypt | 2 |
| 2022 | SAND: an AND-RX Feistel lightweight block cipher supporting S-box-based security evaluations
Yanhong Fan 0001, Ling Sun 0001, Meiqin Wang 0001, Weijia Wang 0003, Chun Guo 0002 |
Des. Codes Cryptogr. | 9 |
| 2022 | New indifferentiability security proof of MDPH hash functionabstractAbstract MDPH is a double‐block‐length hash function proposed by Naito at Latincrypt 2019. This is a combination of Hirose's compression function and the domain extender called Merkle–Damgård with permutation. When instantiated with an n ‐bit block cipher, Naito proved that this achieves the (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security. In this paper, the authors first point out that the proof of the claim contains a gap, which is related to the definition of the simulator in simulating the decryption of the block cipher. The authors then show that the proof can be fixed. The authors introduce a new simulator that addresses the issue, showing that MDPH retains its (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security. Chun Guo 0002, Tetsu Iwata, Kazuhiko Minematsu |
IET Inf. Secur. | 1 |
| 2021 | Efficient Leakage-Resilient MACs Without Idealized Assumptions
Francesco Berti, Chun Guo 0002, Thomas Peters, François-Xavier Standaert |
ASIACRYPT (2) | 2 |
| 2021 | Related-Key Analysis of Generalized Feistel Networks with Expanding Round Functions
Wenqi Yu, Chun Guo 0002 |
CT-RSA | 3 |
| 2021 | Beyond-birthday security for permutation-based Feistel networks
Chun Guo 0002, Guoyan Zhang |
Des. Codes Cryptogr. | 1 |
| 2020 | Towards Closing the Security Gap of Tweak-aNd-Tweak (TNT)
Chun Guo 0002, Jian Guo 0001, Eik List, Ling Song 0001 |
ASIACRYPT (1) | 1 |
| 2020 | Packed Multiplication: How to Amortize the Cost of Side-Channel Masking?
Weijia Wang 0003, Chun Guo 0002, François-Xavier Standaert, Yu Yu 0001, Gaëtan Cassiers |
ASIACRYPT (1) | 2 |
| 2020 | Provable Related-Key Security of Contracting Feistel Networks
Wenqi Yu, Chun Guo 0002 |
Inscrypt | 3 |
| 2020 | Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance Jungle
Davide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso, Chun Guo 0002, Charles Momin, Olivier Pereira, Thomas Peters, François-Xavier Standaert |
CRYPTO (1) | 5 |
| 2020 | Better Concrete Security for Half-Gates Garbling (in the Multi-instance Setting)
Chun Guo 0002, Jonathan Katz, Xiao Wang 0012, Chenkai Weng, Yu Yu 0001 |
CRYPTO (2) | 1 |
| 2020 | TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo 0002, Jian Guo 0001, Ling Song 0001 |
EUROCRYPT (2) | 2 |
| 2020 | Efficient and Secure Multiparty Computation from Fixed-Key Block CiphersabstractMany implementations of secure computation use fixed-key AES (modeled as a random permutation); this results in substantial performance benefits due to existing hardware support for AES and the ability to avoid recomputing the AES key schedule. Surveying these implementations, however, we find that most utilize AES in a heuristic fashion; in the best case this leaves a gap in the security proof, but in many cases we show it allows for explicit attacks.Motivated by this unsatisfactory state of affairs, we initiate a comprehensive study of how to use fixed-key block ciphers for secure computation-in particular for OT extension and circuit garbling-efficiently and securely. Specifically: · Weconsider several notions of pseudorandomness for hash functions (e.g., correlation robustness), and show provably secure schemes for OT extension, garbling, and other applications based on hash functions satisfying these notions. · We provide provably secure constructions, in the (non-programmable) random-permutation model, of hash functions satisfying the different notions of pseudorandomness we consider. Taken together, our results provide end-to-end security proofs for implementations of secure-computation protocols based on fixed-key block ciphers (modeled as random permutations). Perhaps surprisingly, at the same time our work also results in noticeable performance improvements over the state-of-the-art. Chun Guo 0002, Jonathan Katz, Xiao Wang 0012, Yu Yu 0001 |
SP | 1 |
| 2019 | Collision Resistant Hashing from Sub-exponential Learning Parity with Noise
Yu Yu 0001, Jiang Zhang 0001, Jian Weng 0001, Chun Guo 0002, Xiangxue Li |
ASIACRYPT (2) | 4 |
| 2019 | Strong Authenticity with Leakage Under Weak and Falsifiable Physical Assumptions
Francesco Berti, Chun Guo 0002, Olivier Pereira, Thomas Peters, François-Xavier Standaert |
Inscrypt | 2 |
| 2019 | Beyond-birthday secure domain-preserving PRFs from a single permutation
Chun Guo 0002, Yaobin Shen, Lei Wang 0031, Dawu Gu |
Des. Codes Cryptogr. | 1 |
| 2019 | Understanding the Related-Key Security of Feistel Ciphers From a Provable PerspectiveabstractWe initiate the provable related-key security treatment for models of practical Feistel ciphers. In detail, we consider Feistel networks with four whitening keys wi(k), i = 0, 1, 2, 3, and round functions of the form f(γj(k) ⊕ X), where k is the master key, wiand γjare efficient transformations, and f is a public ideal function or permutation accessible by the adversary. We investigate the key-schedule conditions that are sufficient for security against XOR-induced related-key attacks up to 2n/2adversarial queries. When the key schedules are non-linear, we prove security for four rounds. When only affine key schedules are used, we prove security for six rounds. These also imply secure tweakable Feistel ciphers in the Random Oracle model. By shuffling the key schedules, our model unifies both the DES-like structure (known as Feistel-2 scheme in the cryptanalytic community, also known as key-alternating Feistel due to Lampe and Seurin) and the Lucifer-like model (previously analyzed by Guo and Lin). This allows us to derive concrete implications on these two (more common) models and helps understanding their related-key security difference. Chun Guo 0002 |
IEEE Trans. Inf. Theory | 1 |
| 2018 | Revisiting Key-Alternating Feistel Ciphers for Shorter Keys and Multi-user Security
Chun Guo 0002, Lei Wang 0031 |
ASIACRYPT (1) | 1 |
| 2016 | Separating invertible key derivations from non-invertible ones: sequential indifferentiability of 3-round Even-Mansour
Chun Guo 0002, Dongdai Lin |
Des. Codes Cryptogr. | 1 |
| 2015 | A Synthetic Indifferentiability Analysis of Interleaved Double-Key Even-Mansour Ciphers
Chun Guo 0002, Dongdai Lin |
ASIACRYPT (2) | 1 |
| 2015 | Estimating Differential-Linear Distinguishers and Applications to CTC2
Chun Guo 0002, Hailong Zhang 0001, Dongdai Lin |
ISPEC | 1 |
| 2015 | On the Indifferentiability of Key-Alternating Feistel Ciphers with No Key Derivation
Chun Guo 0002, Dongdai Lin |
TCC (1) | 1 |