Crypto in the Real World
Junfeng Fan
OSR Technology
Academic exchange · 2026
A small gathering for cryptography research and exchange, welcoming Joan Daemen and Lejla Batina to Shandong University.
01 /
Junfeng Fan
OSR Technology
Fukang Liu
Institute of Science Tokyo
Zhongfeng Niu
Nanyang Technological University
20 minutes
Chun Guo
Shandong University
Shiyao Chen
Shandong University
Kai Hu
Shandong University
02 /

Speaker 0109:00 – 09:20
01 / SPEAKER
Founder and CEO, OSR Technology · Distinguished Researcher, Tsinghua University
Talk
How far is cryptography from the real world?
From the Internet and financial systems to chip security, artificial intelligence, privacy-preserving computing, and post-quantum cryptography, cryptography has become an essential part of our digital infrastructure. Yet outside papers and laboratories, reality is far more complicated. In some applications, cryptography creates enormous value; in others, it is seen simply as a cost or an engineering burden. Sometimes systems use cryptography without actually achieving the security people expect.
This talk shares observations from industry about where cryptography is genuinely needed, how it is actually used, and what happens when cryptographic technology meets real-world constraints. It explores the opportunities, compromises, and challenges that exist in between.
Junfeng Fan is the founder and CEO of Shenzhen OSR Technology Co., Ltd. and a Distinguished Researcher at Tsinghua University. He received his Ph.D. from KU Leuven, where he studied under Ingrid Verbauwhede and subsequently worked as a postdoctoral researcher. He later served as Director of the Security Chip Laboratory and a chip security architect at Nationz Technologies.
His work spans cryptographic hardware, chip security, side-channel analysis, and fully homomorphic encryption. He co-designed the BFV fully homomorphic encryption scheme, now a candidate for ISO 28033. He served on the CHES program committee from 2014 to 2018, chaired CHES 2021, and currently serves as Vice Chair of the Cryptographic Evaluation Committee of the Chinese Association for Cryptologic Research.

Speaker 0209:20 – 09:40
02 / SPEAKER
Assistant Professor, Institute of Science Tokyo
Talk
Efficiently evaluating a Boolean polynomial on a large set of structured inputs is an important tool in algebraic cryptanalysis and the polynomial method. While efficient techniques such as the Möbius transform and Fast Exhaustive Search are known for the full Boolean space, less is known for structured sets defined by Hamming-weight constraints.
This talk introduces FESG (Fast Exhaustive Search over a more General input set), an efficient algorithm for evaluating Boolean polynomials over Cartesian products of bounded-Hamming-weight sets. The approach extends the derivative-based framework of Fast Exhaustive Search and resolves a key efficiency issue in previous approaches, reducing the initialization cost from quadratic to linear in the number of monomials.
We give the time and memory complexity of FESG, together with an efficient implementation. As an application, FESG provides a rigorous and practical solution to a critical polynomial-evaluation step in Dinur’s polynomial method, without increasing its overall complexity. The talk focuses on the main ideas behind the algorithm and why they lead to efficient evaluation on these structured input sets.
Fukang Liu obtained his Ph.D. from East China Normal University in 2021 and is an Assistant Professor at the Institute of Science Tokyo. His research focuses on hash functions and symmetric-key primitives designed for MPC, FHE, and zero-knowledge applications. His work has appeared at leading IACR conferences including FSE, CHES, ASIACRYPT, EUROCRYPT, and CRYPTO. He received Best Paper Awards at FSE 2022 and ASIACRYPT 2024.

Speaker 0309:40 – 10:00
03 / SPEAKER
Postdoctoral Researcher, Nanyang Technological University
Talk
We extend the framework of Beyne, Leander, and Schütt (BLS) for proving almost pairwise independence from MDS to near-MDS diffusion. The near-MDS branch conditions no longer determine all difference-pair counts required by the BLS analysis, and spectral contributions that vanish for MDS diffusion may survive. We establish new truncated-differential and spectral estimates within the BLS framework, using minimum-support difference-pair counts and support locations to derive an explicit norm bound for near-MDS diffusion.
For the near-MDS applications, we combine numerical approximations with exact arithmetic to prove upper bounds on the third singular values of key-averaged superbox difference-distribution matrices. Assuming independent uniform keys at each key addition and independent input and output whitening, we prove 2−64-pairwise independence for 52 rounds of Midori64, 34 rounds of PRINCE, and 44 rounds of QARMA-64. The QARMA-64 bound holds for every fixed tweak.
We first account for a missing term in the BLS spectral estimate. Our counting argument works in word coordinates and refines the general MDS estimates of the BLS framework. Together, these give a refined proof for AES-like ciphers. Although the previously claimed round guarantee for independently keyed AES remains unchanged, the refined estimates reduce the number of rounds sufficient for 2−64-pairwise independence of the LED variant with an independent uniform key in every round from 32 to 28.
Zhongfeng Niu is a postdoctoral researcher at Nanyang Technological University. His research focuses on the design and analysis of symmetric-key cryptographic algorithms. In recent years, he has published six papers in leading cryptography venues, including the Journal of Cryptology, CRYPTO, and EUROCRYPT. His doctoral dissertation was selected for the 2024 Doctoral Dissertation Incentive Program of the Chinese Association for Cryptologic Research.

Speaker 0410:20 – 10:40
04 / SPEAKER
Professor, School of Cyber Science and Technology, Shandong University
Talk
The hash-based Leighton–Micali Signature (LMS) has been standardized by the IETF, NIST, and ISO. State-of-the-art non-quantum security proofs for LMS were given by Katz (SSR 2016) and Fluhrer (IACR ePrint 2017/553). However, SHA-256(/192) uses a (chopped) Merkle–Damgård construction with a block-cipher-based Davies–Meyer function. Precise bounds for SHA-256-based LMS_SHA256_M32 and SHA-256/192-based LMS_SHA256_M24 should therefore be derived in the ideal-cipher model. This structure was not considered in the earlier proofs.
By exploiting structural properties of (chopped) Merkle–Damgård, we exhibit forgery attacks against LMS_SHA256_M32 and LMS_SHA256_M24 that show why the earlier random-oracle bounds do not apply directly to the concrete SHA-256 constructions. We then provide ideal-cipher-model security proofs for additive-Davies–Meyer abstractions of both schemes.
The security level of LMS_SHA256_M32 is roughly 256 − log₂ B bits, where B is the number of message blocks processed by its internal SHA-256 calls and B ≪ 2¹²⁸. For LMS_SHA256_M24, it is roughly min{192 − log₂ Γ, 256 − log₂ B} bits, where Γ is the number of internal SHA-256/192 calls, B is their total number of blocks, B ≪ 2¹²⁸, and BΓ ≪ 2¹⁹². Thus both schemes provide a moderate, though not full, security level.
Chun Guo works on the provable security of symmetric cryptography. He has published 13 papers at CRYPTO, EUROCRYPT, and ASIACRYPT. A multi-instance-secure tweakable correlation-robust hash function that he co-designed has been included in an ISO/IEC draft, while Romulus, an AEAD scheme that he co-designed, was selected as a finalist in the NIST Lightweight Cryptography competition.

Speaker 0510:40 – 11:00
05 / SPEAKER
Professor, School of Cyber Science and Technology, Shandong University
Talk
AES-based hashing and one-way functions have applications ranging from resource-constrained systems to zero-knowledge-based signatures. This talk presents four recent works on the cryptanalysis of reduced-round AES-like constructions, focusing on meet-in-the-middle and rebound attacks. It explains how S-box linearization, distributed initial structures, and single-color initial structures improve the treatment of nonlinear constraints and the use of internal degrees of freedom.
We then discuss two approaches to chosen-prefix collisions: related-key rebound and the conversion of partial-target MITM. Further improvements arise from using constants as neutral words, with applications to collision, preimage, and herding attacks. Representative results include preimage attacks on 10-round AES-192 hashing, classical collisions on 7-round AES-MMO/MP, and improved attacks on Whirlpool, Streebog, and Saturnin.
Shiyao Chen is a Professor at the School of Cyber Science and Technology, Shandong University. He received his Ph.D. from Shandong University in 2021 and was a postdoctoral researcher at Nanyang Technological University from 2021 to 2025. His research focuses on the analysis and design of symmetric ciphers, including block ciphers and hash functions. He has served as General Co-Chair of FSE 2026 and as a member of the ASIACRYPT 2025 program committee.

Speaker 0611:00 – 11:20
06 / SPEAKER
Professor, School of Cyber Science and Technology, Shandong University
Talk
Probabilities and correlations averaged over all keys and data can hide substantial input dependence. We study difference-wise cryptanalytic properties under linear conditions on keys, data, or both. We identify the Fourier coefficients of their coset averages with two-wise transition matrix coordinates of the studied function. Exact evaluation on a chosen mask subspace recovers all corresponding coset averages, without computing the spectrum outside that subspace.
We provide three applications that cover differential probabilities and differential-linear correlations, including higher-order variants, as examples of how the framework can be used. First, under independent full-state round keys, we establish partial plateaus for Midori64, Scream, and iScream. These give exact key-coset averages for characteristic families with internal inactive S-boxes, including families whose fixed-key probabilities are not constant on the supporting coset. We also construct plateau cores that yield probability lower bounds for every key in specified cosets. These results partially answer the open question of Canteaut and Fruchon (ASIACRYPT 2025) on extending fixed-key analysis to characteristics with internal inactive S-boxes.
Second, for a fixed characteristic under independent full-state round keys, we compute complete coefficients by searching for a basis of quasidifferential trails and evaluating its span directly, without further trail search. For two 14-round RECTANGLE characteristics, this gives exact distributions over 230 expanded-key cosets, refining the previous partitions of 216 and 219 cosets by Hu et al. (ToSC 2026-3), respectively. We also identify a full-round differential for Blink-64. By combining the complete local spectra under its long master key, we obtain a maximum coset probability of 2−54.14 on 3 · 2105 joint key-plaintext cosets.
Third, using the same spectral analysis, we estimate the dependence on keys and data of first- and second-order differential-linear correlations for Ascon and first-order correlations for Xoodoo. The fixed-key analysis of these permutation-based constructions uses the same theoretical framework as fixed-key differential analysis. For a differential-linear distinguisher of Ascon-128a with −2−24.89 correlation, we find that it has zero correlation in 917,504 cosets, while it has a larger correlation of −2−19.21 for 210 cosets.
Kai Hu is a Professor at the School of Cyber Science and Technology, Shandong University. He received his bachelor’s degree from the School of Mathematics at Shandong University in 2016 and his Ph.D. from the School of Cyber Science and Technology at Shandong University in 2021 under the supervision of Prof. Meiqin Wang. From 2021 to 2023, he was a postdoctoral researcher at Nanyang Technological University under the supervision of Prof. Thomas Peyrin.
He has published more than 30 papers, including 25 papers at the IACR conferences CRYPTO, EUROCRYPT, ASIACRYPT, and FSE. He has served on the program or editorial committees of EUROCRYPT 2027, ASIACRYPT 2025, and ToSC 2025/2026. His honors include the Chinese Association for Cryptologic Research Outstanding Doctoral Dissertation Award, its Outstanding Young Researcher Honor Award, and the First Prize of the Shandong Provincial Technological Invention Award, for which he was the second-ranked contributor.