Siwei Sun

dblp:94/10123 · DBLP profile ↗
← Back
60ranked-venue papers
6as first author
30since 2021 · last 2026
0000-0002-3058-2377ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 51 · 5 first-author · 24 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Computer networks · 2Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Permutation-Based Hashing with Stronger (Second) Preimage Resistance
Siwei Sun, Shun Li 0004, Zhiyu Zhang 0009, Charlotte Lefevre, Bart Mennink, Dengguo Feng
CRYPTO (6)1
2026 New Records in Collision Attacks on SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian, Xiaoyang Dong 0001, Siwei Sun, Danping Shi
J. Cryptol.6
2026 Link Between the Differential Cryptanalysis and Linear Approximations over Finite Abelian Groups And Its Applications
abstract
Abstract In recent years, progress in practical applications of multi-party computation (MPC), fully homomorphic encryption (FHE), and zero-knowledge proofs (ZKP) motivates people to explore symmetric-key cryptographic algorithms, as well as corresponding cryptanalysis techniques (such as differential cryptanalysis, linear cryptanalysis), over finite Abelian groups or prime fields $${\mathbb {F}}_p$$ F p for large p . In this paper, we establish the links between linear cryptanalysis and differential cryptanalysis over general finite Abelian groups. As the first application, we revisit linear cryptanalysis and give general results of linear approximations over arbitrary finite Abelian groups. More precisely, we consider the linearity , which is the maximal non-trivial linear approximation, to characterize the resistance of a function against linear cryptanalysis. This thereby generalizes the work of Pott in 2004 and completes the generalization of Sidelnikov–Chabaud–Vaudenay’s bound from $${\mathbb {F}}_2^n$$ F 2 n to finite Abelian groups. As the second application, we give an exact expression for the correlation of differential-linear approximations over arbitrary finite Abelian groups ( $${\mathbb {F}}_p^n$$ F p n ) under the sole assumption that the two parts of the cipher are independent of each other. In particular, we completely generalize the differential-linear cryptanalysis from $${\mathbb {F}}_2^n$$ F 2 n to arbitrary finite Abelian groups ( $${\mathbb {F}}_p^n$$ F p n ).
Zhongfeng Niu, Siwei Sun, Hailun Yan, Qi Wang 0012
J. Cryptol.2
2026 A Generalized χn-Function
abstract
The mappingχnfrom Fn2to itself defined byy=χn(x) withyi=xi+xi+2(1 +xi+1), where the indices are computed modulo n, has been widely studied for its applications in lightweight cryptography. However,χnis bijective on Fn2only whennis odd, restricting its use to odd-dimensional vector spaces over F2. To address this limitation, we introduce and analyze the generalized mappingχn,mdefined byy=χn,m(x) withyi=xi+xi+m(xi+m−1+ 1)(xi+m−2+ 1) · · · (xi+1+ 1), wheremis a fixed integer withm∤n. To investigate such mappings, we further generalizeχn,mto θm,k, where θm,kis given byyi=xi+mkПmk−1j=1, m∤j(xi+j+ 1) , fori∈ {0, 1, . . . ,n− 1}. We prove that these mappings generate an abelian group isomorphic to the group of units in F2[z]/(z⌊n/m⌋+1). This structural insight enables us to construct a broad class of permutations over Fn2for any positive integern, along with their inverses. We rigorously analyze algebraic properties of these mappings, including their iterations, fixed points, and cycle structures. Additionally, we provide a comprehensive database of the cryptographic properties for iterates ofχn,mfor small values ofnandm. Finally, we conduct a comparative security and implementation cost analysis amongχn,m,χn,χχn(EUROCRYPT 2025 [3]) and their variants, and prove Conjecture 1 proposed in [3] as a by-product of our study. Our results lead to generalizations ofχn, providing alternatives toχnandχχn.
Mu Yuan, Dabin Zheng, Siwei Sun, Shun Li 0004
IEEE Trans. Inf. Theory4
2025 Vectorial Fast Correlation Attacks
Bin Zhang 0003, Ruitao Liu, Willi Meier, Siwei Sun, Dengguo Feng, Wenling Wu
ASIACRYPT (1)4
2025 ChiLow and ChiChi: New Constructions for Code Encryption
Yanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander, Silvia Mella, Léo Perrin, Shahram Rasoolzadeh, Lukas Stennes, Siwei Sun, Gilles Van Assche, Damian Vizár
EUROCRYPT (1)9
2025 Exploiting output bits and the χ operation in MitM preimage attacks on Keccak
Tianling Weng, Gaoli Wang, Keting Jia, Xiaoyang Dong 0001, Siwei Sun, Tingting Cui
Des. Codes Cryptogr.5
2024 The First Practical Collision for 31-Step SHA-256
Yingxin Li, Fukang Liu, Gaoli Wang, Xiaoyang Dong 0001, Siwei Sun
ASIACRYPT (7)5
2024 Speeding Up Preimage and Key-Recovery Attacks with Highly Biased Differential-Linear Approximations
Zhongfeng Niu, Kai Hu 0001, Siwei Sun, Zhiyu Zhang 0009, Meiqin Wang 0001
CRYPTO (4)3
2024 LOL: a highly flexible framework for designing stream ciphers
Dengguo Feng, Lin Jiao, Yonglin Hao, Qun-Xiong Zheng, Wenling Wu, Wen-Feng Qi 0001, Siwei Sun, Tian Tian 0004
Sci. China Inf. Sci.9
2024 A closer look at the belief propagation algorithm in side-channel attack on CCA-secure PQC KEM
Kexin Qiao, Heng Chang, Siwei Sun, Zehan Wu, Junjie Cheng, Changhai Ou, An Wang 0001, Liehuang Zhu
Sci. China Inf. Sci.4
2024 A New (Related-Key) Neural Distinguisher Using Two Differences for Differential Cryptanalysis
abstract
At CRYPTO 2019, Gohr showed the significant advantages of neural distinguishers over traditional distinguishers in differential cryptanalysis. At fast software encryption (FSE) 2024, Bellini et al. provided a generic tool to automatically train the (related‐key) differential neural distinguishers for different block ciphers. In this paper, based on the intrinsic principle of differential cryptanalysis and neural distinguisher, we propose a superior (related‐key) differential neural distinguisher that uses the ciphertext pairs generated by two different differences. In addition, we give a framework to automatically train our (related‐key) differential neural distinguisher with four steps: difference selection, sample generation, training pipeline, and evaluation scheme. To demonstrate the effectiveness of our approach, we apply it to the block ciphers: Simon, Speck, Simeck, and Hight. Compared to the existing results, our method can provide improved accuracy and even increase the number of rounds that can be analyzed. The source codes are available in https://github.com/differentialdistinguisher/AutoND_New .
Gaoli Wang, Siwei Sun
IET Inf. Secur.3
2023 Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNY
Danping Shi, Siwei Sun, Ling Song 0001, Lei Hu 0003, Qianqian Yang 0003
EUROCRYPT (4)2
2023 A Closer Look at the S-Box: Deeper Analysis of Round-Reduced ASCON-HASH
Xiaorui Yu, Fukang Liu, Gaoli Wang, Siwei Sun, Willi Meier
SAC4
2023 New cryptanalysis of LowMC with algebraic techniques
abstract
Abstract LowMC is a family of block ciphers proposed by Albrecht et al. at EUROCRYPT 2015, which is tailored specifically for FHE and MPC applications. At ToSC 2018, a difference enumeration attack was given for the cryptanalysis of low-data instances of full LowMCv2 with few applied S-boxes per round. Recently at CRYPTO 2021, an efficient algebraic technique was proposed to attack 4-round LowMC adopting a full S-box layer. Following these works, we present a new difference enumeration attack framework, which is based on our new observations on the LowMC S-box, to analyze LowMC instances with a full S-box layer. As a result, with only 3 chosen plaintexts, we can attack 4-round LowMC instances which adopt a full S-box layer with block size of 129, 192, and 255 bits, respectively. We show that all these attacks have either a lower time complexity or a higher success probability than those reported in the CRYPTO paper.
Wenxiao Qiao, Hailun Yan, Siwei Sun, Lei Hu 0003, Jiwu Jing
Des. Codes Cryptogr.3
2023 Searching the space of tower field implementations of the 픽28 inverter - with applications to AES, Camellia and SM4
Zihao Wei, Siwei Sun, Lei Hu 0003, Man Wei, René Peralta 0001
Int. J. Inf. Comput. Secur.2
2023 Rotational Differential-Linear Cryptanalysis Revisited
abstract
Abstract The differential-linear attack, combining the power of the two most effective techniques for symmetric-key cryptanalysis, was proposed by Langford and Hellman at CRYPTO 1994. From the exact formula for evaluating the bias of a differential-linear distinguisher (JoC 2017), to the differential-linear connectivity table technique for dealing with the dependencies in the switch between the differential and linear parts (EUROCRYPT 2019), and to the improvements in the context of cryptanalysis of ARX primitives (CRYPTO 2020, EUROCRYPT 2021), we have seen significant development of the differential-linear attack during the last four years. In this work, we further extend this framework by replacing the differential part of the attack by rotational-XOR differentials. Along the way, we establish the theoretical link between the rotational-XOR differential and linear approximations and derive the closed formula for the bias of rotational differential-linear distinguishers, completely generalizing the results on ordinary differential-linear distinguishers due to Blondeau, Leander, and Nyberg (JoC 2017) to the case of rotational differential-linear cryptanalysis. We then revisit the rotational cryptanalysis from the perspective of differential-linear cryptanalysis and generalize Morawiecki et al.’s technique for analyzing , which leads to a practical method for estimating the bias of a (rotational) differential-linear distinguisher in the special case where the output linear mask is a unit vector. Finally, we apply the rotational differential-linear technique to the cryptographic permutations involved in , , , and . This gives significant improvements over existing cryptanalytic results, or offers explanations for previous experimental distinguishers without a theoretical foundation. To confirm the validity of our analysis, all distinguishers with practical complexities are verified experimentally. Moreover, we discuss the possibility of applying the rotational differential-linear technique to S-box-based designs or keyed primitives, and propose some open problems for future research.
Yunwen Liu, Zhongfeng Niu, Siwei Sun, Chao Li 0002, Lei Hu 0003
J. Cryptol.3
2022 Synthesizing Quantum Circuits of AES with Lower T-depth and Less Qubits
Zhenyu Huang 0004, Siwei Sun
ASIACRYPT (3)2
2022 Rotational Differential-Linear Distinguishers of ARX Ciphers with Arbitrary Output Linear Masks
Zhongfeng Niu, Siwei Sun, Yunwen Liu, Chao Li 0002
CRYPTO (1)2
2022 Key Guessing Strategies for Linear Key-Schedule Algorithms in Rectangle Attacks
Xiaoyang Dong 0001, Lingyue Qin, Siwei Sun, Xiaoyun Wang 0001
EUROCRYPT (3)3
2022 A small first-order DPA resistant AES implementation with no fresh randomness
Man Wei, Siwei Sun, Zihao Wei, Lei Hu 0003
Sci. China Inf. Sci.2
2021 Automatic Classical and Quantum Rebound Attacks on AES-Like Hashing by Exploiting Related-Key Differentials
Xiaoyang Dong 0001, Zhiyu Zhang 0009, Siwei Sun, Congming Wei, Xiaoyun Wang 0001, Lei Hu 0003
ASIACRYPT (1)3
2021 Massive Superpoly Recovery with Nested Monomial Predictions
Kai Hu 0001, Siwei Sun, Yosuke Todo, Meiqin Wang 0001, Qingju Wang 0001
ASIACRYPT (1)2
2021 Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage Attacks
Xiaoyang Dong 0001, Jialiang Hua, Siwei Sun, Zheng Li 0008, Xiaoyun Wang 0001, Lei Hu 0003
CRYPTO (3)3
2021 Zero-Correlation Linear Cryptanalysis with Equal Treatment for Plaintexts and Tweakeys
Muzhou Li, Siwei Sun
CT-RSA3
2021 Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like Hashing
Zhenzhen Bao, Xiaoyang Dong 0001, Jian Guo 0001, Zheng Li 0008, Danping Shi, Siwei Sun, Xiaoyun Wang 0001
EUROCRYPT (1)6
2021 Rotational Cryptanalysis from a Differential-Linear Perspective - Practical Distinguishers for Round-Reduced FRIET, Xoodoo, and Alzette
Yunwen Liu, Siwei Sun, Chao Li 0002
EUROCRYPT (1)2
2021 Automatic Key Recovery of Feistel Ciphers: Application to SIMON and SIMECK
Lijun Lyu, Kexin Qiao, Zhiyu Zhang 0009, Siwei Sun, Lei Hu 0003
ISPEC5
2021 Unbalanced sharing: a threshold implementation of SM4
Man Wei, Siwei Sun, Zihao Wei, Lei Hu 0003
Sci. China Inf. Sci.2
2021 Motivators of Researchers' Knowledge Sharing and Community Promotion in Online Multi-Background Community
abstract
As an essential group in knowledge innovation, researchers are encouraged to exchange ideas with each other for further brainstorm through advanced communication technology. However, efficient online knowledge sharing among researchers is still limited. Although past literature proposes a series of motivators of online knowledge sharing, the differences in the effects of motivators remain in dispute. Thus, it is time to understand how motivators influence each other and inspire scientists to share knowledge and promote virtual communities. Based on the self-determination theory, this study proposes a model with several factors and analyze 301 Chinese researchers' data in an online WeChat cross-disciplinary research community by adopting SmartPls 2.0 and SPSS 22. The results reveal the effects of several antecedents and mediating effects of altruism and knowledge sharing behavior and report the differences of results among different demographic groups. This study enriches the literature in knowledge sharing on social media and proposes further research points to researchers and useful advice to practitioners.
Siwei Sun, Fangyu Zhang, Victor Chang 0001
Int. J. Knowl. Manag.1
2020 Quantum Collision Attacks on AES-Like Hashing with Low Quantum Random Access Memories
Xiaoyang Dong 0001, Siwei Sun, Danping Shi, Xiaoyun Wang 0001, Lei Hu 0003
ASIACRYPT (2)2
2020 An Algebraic Formulation of the Division Property: Revisiting Degree Evaluations, Cube Attacks, and Key-Independent Sums
Kai Hu 0001, Siwei Sun, Meiqin Wang 0001, Qingju Wang 0001
ASIACRYPT (1)2
2020 Quantum Circuit Implementations of AES with Fewer Qubits
Jian Zou 0002, Zihao Wei, Siwei Sun, Ximeng Liu, Wenling Wu
ASIACRYPT (2)3
2020 Fail-safe Watchtowers and Short-lived Assertions for Payment Channels
abstract
The recent development of payment channels and their extensions (e.g., state channels) provides a promising scalability solution for blockchains which allows untrusting parties to transact off-chain and resolve potential disputes via on-chain smart contracts. To protect participants who have no constant access to the blockchain, a watching service named as watchtower is proposed -- a third-party entity obligated to monitor channel states (on behalf of the participants) and correct them on-chain if necessary. Unfortunately, currently proposed watchtower schemes suffer from multiple security and efficiency drawbacks.
Bowen Liu 0005, Pawel Szalachowski, Siwei Sun
AsiaCCS3
2020 SMACS: Smart Contract Access Control Service
abstract
Although blockchain-based smart contracts promise a "trustless" way of enforcing agreements even with monetary consequences, they suffer from multiple security issues. Many of these issues could be mitigated via an effective access control system, however, its realization is challenging due to the properties of current blockchain platforms (like lack of privacy, costly on-chain resources, or latency). To address this problem, we propose the SMACS framework, where updatable and sophisticated Access Control Rules (ACRs) for smart contracts can be realized with low cost. SMACS shifts the burden of expensive ACRs validation and management operations to an off-chain infrastructure, while implementing on-chain only lightweight token-based access control. SMACS is flexible and in addition to simple access control lists can easily implement rules enhancing the runtime security of smart contracts. With dedicated ACRs backed by vulnerability-detection tools, SMACS can protect vulnerable contracts after deployment. We fully implement SMACS and evaluate it.
Bowen Liu 0005, Siwei Sun, Pawel Szalachowski
DSN2
2019 Correlation of Quadratic Boolean Functions: Cryptanalysis of All Versions of Full \mathsf MORUS
Danping Shi, Siwei Sun, Yu Sasaki 0001, Chaoyun Li, Lei Hu 0003
CRYPTO (2)2
2019 Automatic Demirci-Selçuk Meet-in-the-Middle Attack on SKINNY with Key-Bridging
Qiu Chen, Danping Shi, Siwei Sun, Lei Hu 0003
ICICS3
2019 Convolutional Neural Network Based Side-Channel Attacks with Customized Filters
Man Wei, Danping Shi, Siwei Sun, Peng Wang 0009, Lei Hu 0003
ICICS3
2019 Zero-sum Distinguishers for Round-reduced GIMLI Permutation
abstract
GIMLI is a 384-bit permutation proposed by Bernstein et al. at CHES 2017. It is designed with the goal of achieving both high security and high performance across a wide range of hardware and software platforms. Since GIMLI can be used as a building block for many cryptographic schemes, it is important to understand its concrete security. To the best of our knowledge, third party cryptanalysis of GIMLI is limited. In this paper, we identify some zero-sum distinguishers for 14-round GIMLI with the inside-out technique, which are one-round longer than the integral distinguishers presented by the designers. Although we obtain improved cryptanalysis results, these zero-sum distinguishers are far from threatening the full version of GIMLI.
Jiahao Cai, Zihao Wei, Siwei Sun, Lei Hu 0003
ICISSP4
2019 StrongChain: Transparent and Collaborative Proof-of-Work Consensus
Pawel Szalachowski, Daniël Reijsbergen, Ivan Homoliak, Siwei Sun
USENIX Security Symposium4
2018 Programming the Demirci-Selçuk Meet-in-the-Middle Attack with Constraints
Danping Shi, Siwei Sun, Patrick Derbez, Yosuke Todo, Bing Sun 0001, Lei Hu 0003
ASIACRYPT (2)2
2018 Speeding up MILP Aided Differential Characteristic Search with Matsui's Strategy
Siwei Sun, Jiahao Cai, Lei Hu 0003
ISC2
2018 On the Complexity of Impossible Differential Cryptanalysis
abstract
While impossible differential attack is one of the most well-known and familiar techniques for symmetric-key cryptanalysts, its subtlety and complicacy make the construction and verification of such attacks difficult and error-prone. We introduce a new set of notations for impossible differential analysis. These notations lead to unified formulas for estimation of data complexities of ordinary impossible differential attacks and attacks employing multiple impossible differentials. We also identify an interesting point from the new formulas: in most cases, the data complexity is only related to the form of the underlying distinguisher and has nothing to do with how the differences at the beginning and the end of the distinguisher propagate in the outer rounds. We check the formulas with some examples, and the results are all matching. Since the estimation of the time complexity is flawed in some situations, in this work, we show under which condition the formula is valid and give a simple time complexity estimation for impossible differential attack which is always achievable.
Qianqian Yang 0003, Lei Hu 0003, Danping Shi, Yosuke Todo, Siwei Sun
Secur. Commun. Networks5
2017 Improved linear (hull) cryptanalysis of round-reduced versions of SIMON
Danping Shi, Lei Hu 0003, Siwei Sun, Ling Song 0001, Kexin Qiao, Xiaoshuang Ma
Sci. China Inf. Sci.3
2016 MILP-Based Automatic Search Algorithms for Differential and Linear Trails for Speck
Yinghua Guo, Siwei Sun, Lei Hu 0003
FSE4
2016 Differential Security Evaluation of Simeck with Dynamic Key-guessing Techniques
Kexin Qiao, Lei Hu 0003, Siwei Sun
ICISSP3
2016 Linear(hull) Cryptanalysis of Round-reduced Versions of KATAN
Danping Shi, Lei Hu 0003, Siwei Sun, Ling Song 0001
ICISSP3
2016 Extension of Meet-in-the-Middle Technique for Truncated Differential and Its Application to RoadRunneR
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Ling Song 0001
NSS3
2015 Improved Differential Analysis of Block Cipher PRIDE
Qianqian Yang 0003, Lei Hu 0003, Siwei Sun, Kexin Qiao, Ling Song 0001, Jinyong Shan, Xiaoshuang Ma
ISPEC3
2015 Extending the Applicability of the Mixed-Integer Programming Technique in Automatic Differential Cryptanalysis
Siwei Sun, Lei Hu 0003, Qianqian Yang 0003, Kexin Qiao, Xiaoshuang Ma, Ling Song 0001, Jinyong Shan
ISC1
2015 Differential fault attack on Zorro block cipher
abstract
Abstract Zorro is a 24‐round block cipher presented at the CHES 2013 conference. In this paper, we propose a differential fault attack on Zorro under a byte fault model, in which faults are injected in the 20th round of Zorro at arbitrary positions. With two fault injections on average, a candidate set for the key of the cipher with at most 224 elements can be efficiently obtained in a low time complexity with a probability of at least 96.29%. In this attack, the position of the fault can be easily determined by the difference of the correct and faulty ciphertexts. Copyright © 2015 John Wiley & Sons, Ltd.
Danping Shi, Lei Hu 0003, Ling Song 0001, Siwei Sun
Secur. Commun. Networks4
2014 Automatic Security Evaluation and (Related-key) Differential Characteristic Search: Application to SIMON, PRESENT, LBlock, DES(L) and Other Bit-Oriented Block Ciphers
Siwei Sun, Lei Hu 0003, Peng Wang 0009, Kexin Qiao, Xiaoshuang Ma, Ling Song 0001
ASIACRYPT (1)1
2014 Error-Tolerant Algebraic Side-Channel Attacks Using BEE
Ling Song 0001, Lei Hu 0003, Siwei Sun, Danping Shi, Ronglin Hao
ICICS3
2014 Tighter Security Bound of MIBS Block Cipher against Differential Attack
Xiaoshuang Ma, Lei Hu 0003, Siwei Sun, Kexin Qiao, Jinyong Shan
NSS3
2014 Cryptanalysis of two cryptosystems based on multiple intractability assumptions
abstract
Two public key cryptosystems based on the two intractable number‐theoretic problems, integer factorisation and simultaneous Diophantine approximation, were proposed in 2005 and 2009, respectively. In this study, the authors break these two cryptosystems for the recommended minimum parameters by solving the corresponding modular linear equations with small unknowns. For the first scheme, the public modulus is factorised and the secret key is recovered with the Gauss algorithm. By using the LLL basis reduction algorithm for a seven‐dimensional lattice, the public modulus in the second scheme is also factorised and the plaintext is recovered from a ciphertext. The author's attacks are efficient and verified by experiments which were done within 5s.
Jun Xu 0022, Lei Hu 0003, Siwei Sun
IET Commun.3
2014 Cryptanalysis of countermeasures against multiple transmission attacks on NTRU
abstract
The original Number Theory Research Unit (NTRU) public key cryptosystem is vulnerable to multiple transmission attacks, and the designers of NTRU presented two countermeasures to prevent such attacks. In this study, the authors show that the first countermeasure is still not secure, the plaintext can be revealed by a linearisation attack technique. Moreover, they demonstrate that the first countermeasure is even not secure for broadcast attacks, a class of more general attacks than multiple transmission attacks. For the second countermeasure, they show that one special case of its padding function for the plaintext is also insecure and the original plaintext can be obtained by lattice methods.
Jun Xu 0022, Lei Hu 0003, Siwei Sun, Yonghong Xie
IET Commun.3
2013 Automatic Security Evaluation of Block Ciphers with S-bP Structures Against Related-Key Differential Attacks
Siwei Sun, Lei Hu 0003, Ling Song 0001, Yonghong Xie, Peng Wang 0009
Inscrypt1
2012 Cryptanalysis of a Lattice-Knapsack Mixed Public Key Cryptosystem
Jun Xu 0022, Lei Hu 0003, Siwei Sun
CANS3
2012 Implicit Polynomial Recovery and Cryptanalysis of a Combinatorial Key Cryptosystem
Jun Xu 0022, Lei Hu 0003, Siwei Sun
ICICS3
2011 Cube Cryptanalysis of Hitag2 Stream Cipher
Siwei Sun, Lei Hu 0003, Yonghong Xie, Xiangyong Zeng
CANS1