Institution profile

Faculty of Mathematics

Academic institution
Research library1linked papers
Opportunities0open roles
Selected work

Representative Papers

Cryptanalysis of Gleeok-128

Dec 04, 2025

This work conducts a third-party cryptanalysis of Gleeok-128, a low-latency multi-branch pseudorandom function (PRF), focusing on deficiencies in linear security evaluation under its multi-branch structure and the feasibility of key recovery. We propose a two-stage Mixed-Integer Linear Programming (MILP) modeling framework that unifies differential-linear and integral distinguisher construction while tightening algebraic degree bounds. Our analysis reveals, for the first time, a full linear distinguishability vulnerability in Branch 3; leveraging this, we optimize the linear layer parameters to enhance resistance. Experimentally, we achieve a 7-round integral distinguisher for the full PRF and an 8-round key-recovery attack, improving distinguisher rounds for individual branches by 3 and 2, respectively, with a data complexity of only $2^{48}$. These results significantly surpass prior security bounds and advance automated analysis frameworks for multi-branch primitives.

0 citationsRead paper
Recent publications

Latest Papers

Cryptanalysis of Gleeok-128

Dec 04, 2025

This work conducts a third-party cryptanalysis of Gleeok-128, a low-latency multi-branch pseudorandom function (PRF), focusing on deficiencies in linear security evaluation under its multi-branch structure and the feasibility of key recovery. We propose a two-stage Mixed-Integer Linear Programming (MILP) modeling framework that unifies differential-linear and integral distinguisher construction while tightening algebraic degree bounds. Our analysis reveals, for the first time, a full linear distinguishability vulnerability in Branch 3; leveraging this, we optimize the linear layer parameters to enhance resistance. Experimentally, we achieve a 7-round integral distinguisher for the full PRF and an 8-round key-recovery attack, improving distinguisher rounds for individual branches by 3 and 2, respectively, with a data complexity of only $2^{48}$. These results significantly surpass prior security bounds and advance automated analysis frameworks for multi-branch primitives.

0 citationsRead paper