Kan Yasuda

dblp:00/2463 · DBLP profile ↗
← Back
34ranked-venue papers
10as first author
5since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 34 · 10 first-author · 5 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2024 $k^{m}$-Anonymization Meets Differential Privacy Under Sampling
abstract
Various models for evaluating anonymity have been proposed so far. Among them,$k$-anonymity is widely known as a typical anonymity measure, guaranteeing that at least$k$individuals in a database have the same values. Unfortunately, it is difficult to create highly useful anonymized data satisfying$k$-anonymity for high-dimensional data because of the curse of dimensionality. Several approaches relaxing$k$-anonymity have been proposed, such as$k^{m}$-anonymity, to overcome the problem. On the other hand, we have another privacy protection metric, developed by Dwork et al., and it is differential privacy. However, the full protection index for differential privacy, i.e., the level of noise that can satisfy the desired privacy, has not been clarified. This paper shows relationships between$k^{m}$-anonymity and differential privacy under sampling, proposed by Li et al., that is, a weak notion of differential privacy. Numerical experiments are then performed to give relations among the parameters of$k^{m}$-anonymity and differential privacy under sampling. These experiments also show relationships between$k$-anonymity and$k^{m}$-anonymity as$k$-anonymity is a special case of$k^{m}$-anonymity in some sense.
Masaya Kobayashi, Atsushi Fujioka, Koji Chida, Akira Nagai, Kan Yasuda
ISITA5
2024 Pk-Anonymization Meets Differential Privacy
abstract
This paper explores the relationships between two privacy protection measures:$P$k-anonymity and$\varepsilon$-differential privacy.$P$k-anonymity and$\varepsilon$-differential privacy are proposed by Ikarashi et al. and Dwork et al., respectively, and they are independent privacy measures. The previous research has indicated the relationships between k-anonymity and$(\beta,\ \epsilon,\ \delta)$-differential privacy under sampling, and precisely, have shown that a k-anonymization algorithm can satisfy$(\beta,\ \epsilon,\ \delta)$-differential privacy under sampling within a range of parameters. Although k-anonymity is a stronger notion than Pk-anonymity,$(\beta,\ \epsilon,\ \delta)$-differential privacy under sampling is a weaker one than$\varepsilon$-differential privacy. We introduce a property of anonymization, named record-independence where the processing of one record is not af-fected by the values of other records, and show that a P k- anonymization algorithm can satisfy$\varepsilon$-differential privacy within a range of parameters under the condition where the an-onymization algorithm is record-independent. With the fact that k-anonymity implies Pk-anonymity, k-anonymity meets$\varepsilon{-}$differential privacy. Then, it implies that an algorithm with a strong privacy notion can satisfy a strong one in another privacy measure. Numerical experiments are then performed to give relations among the parameters of$P$k-anonymity and$\varepsilon$-differential privacy.
Masaya Kobayashi, Atsushi Fujioka, Koji Chida, Akira Nagai, Kan Yasuda
PST5
2024 The COLM Authenticated Encryption Scheme
Elena Andreeva 0001, Andrey Bogdanov, Nilanjan Datta, Atul Luykx, Bart Mennink, Mridul Nandi, Elmar Tischhauser, Kan Yasuda
J. Cryptol.8
2022 A Modular Approach to the Incompressibility of Block-Cipher-Based AEADs
Akinori Hosoyamada, Takanori Isobe 0001, Yosuke Todo, Kan Yasuda
ASIACRYPT (2)4
2022 The Multi-User Security of Triple Encryption, Revisited: Exact Security, Strengthening, and Application to TDES
abstract
We study the security of triple encryption in the multi-user setting with its application to Triple DES (TDES) in mind. Although depreciation of TDES is a global trend, the migration will take the next decade, considering the billions of TDES hardware the industry has invested so far. The multi-user security captures the reality of practical systems with multiple users, substantially impacts security, and is already considered in practical protocols such as TLS 1.3. The best multi-user lower bound of TDES is 43-(3/2) \cdot łog_2 u bits with u users, which is tractable with a standard PC and is unacceptably low. We devise a new proof to improve the multi-user security and show its tightness by giving a concrete attack. The new bound with the TDES parameters is 79-(1/2) \cdot łog_2 u bits. We also propose TEFX that strengthens triple encryption with the FX construction while preserving the compatibility with legacy hardware. TDES with TEFX achieves the multi-user security of 114-(1/2) \cdot łog_2 q bits with q TEFX calls: it achieves 84.5 bits with 2^40 users and 2^21 TEFX calls for each user, which is comparable to that of AES (128-40=88 bits).
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001, Kan Yasuda
CCS4
2019 Beyond Conventional Security in Sponge-Based Authenticated Encryption Modes
abstract
The Sponge function is known to achieve $$2^{c/2}$$ security, where c is its capacity. This bound was carried over to its keyed variants, such as SpongeWrap, to achieve a $$\min \{2^{c/2},2^\kappa \}$$ security bound, with $$\kappa $$ the key length. Similarly, many CAESAR competition submissions were designed to comply with the classical $$2^{c/2}$$ security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of $$\min \{2^{b/2},2^c,2^\kappa \}$$ , with $$b>c$$ the permutation size, by proving that the CAESAR submission NORX achieves this bound. The proof relies on rigorous computation of multi-collision probabilities, which may be of independent interest. We additionally derive a generic attack based on multi-collisions that matches the bound. We show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of some of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. We finally consider the remaining one of the three PRIMATEs, APE, and derive a blockwise adaptive attack in the nonce-respecting setting with complexity $$2^{c/2}$$ , therewith demonstrating that the techniques cannot be applied to APE.
Philipp Jovanovic, Atul Luykx, Bart Mennink, Yu Sasaki 0001, Kan Yasuda
J. Cryptol.5
2018 Building Quantum-One-Way Functions from Block Ciphers: Davies-Meyer and Merkle-Damgård Constructions
Akinori Hosoyamada, Kan Yasuda
ASIACRYPT (1)2
2018 Encrypt or Decrypt? To Make a Single-Key Beyond Birthday Secure Nonce-Based MAC
Nilanjan Datta, Avijit Dutta, Mridul Nandi, Kan Yasuda
CRYPTO (1)4
2017 Optimizing Online Permutation-Based AE Schemes for Lightweight Applications
Yu Sasaki 0001, Kan Yasuda
ISPEC2
2017 Rate-One AE with Security Under RUP
Shoichi Hirose, Yu Sasaki 0001, Kan Yasuda
ISC3
2016 On the Influence of Message Length in PMAC's Security Bounds
Atul Luykx, Bart Preneel, Alan Szepieniec, Kan Yasuda
EUROCRYPT (1)4
2016 A MAC Mode for Lightweight Block Ciphers
Atul Luykx, Bart Preneel, Elmar Tischhauser, Kan Yasuda
FSE4
2016 New Bounds for Keyed Sponges with Extendable Output: Independence Between Capacity and Message Length
Yusuke Naito 0001, Kan Yasuda
FSE2
2015 Generalizing PMAC Under Weaker Assumptions
Nilanjan Datta, Kan Yasuda
ACISP2
2015 How to Incorporate Associated Data in Sponge-Based Authenticated Encryption
Yu Sasaki 0001, Kan Yasuda
CT-RSA2
2015 A New Mode of Operation for Incremental Authenticated Encryption with Associated Data
Yu Sasaki 0001, Kan Yasuda
SAC2
2014 How to Securely Release Unverified Plaintext in Authenticated Encryption
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda
ASIACRYPT (1)6
2014 APE: Authenticated Permutation-Based Encryption for Lightweight Cryptography
Elena Andreeva 0001, Begül Bilgin, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda
FSE7
2014 COBRA: A Parallelizable Authenticated Online Cipher Without Block Cipher Inverse
Elena Andreeva 0001, Atul Luykx, Bart Mennink, Kan Yasuda
FSE4
2013 Parallelizable and Authenticated Online Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan Yasuda
ASIACRYPT (1)6
2013 The Security of the OCB Mode of Operation without the SPRP Assumption
Kazumaro Aoki, Kan Yasuda
ProvSec2
2012 The Security and Performance of "GCM" when Short Multiplications Are Used Instead
Kazumaro Aoki, Kan Yasuda
Inscrypt2
2012 PMAC with Parity: Minimizing the Query-Length Influence
Kan Yasuda
CT-RSA1
2011 A New Variant of PMAC: Beyond the Birthday Bound
Kan Yasuda
CRYPTO1
2011 Known-Key Distinguishers on 11-Round Feistel and Collision Attacks on Its Hashing Modes
Yu Sasaki 0001, Kan Yasuda
FSE2
2010 The Sum of CBC MACs Is a Secure PRF
Kan Yasuda
CT-RSA1
2009 A Double-Piped Mode of Operation for MACs, PRFs and PROs: Security beyond the Birthday Barrier
Kan Yasuda
EUROCRYPT1
2009 HBS: A Single-Key Mode of Operation for Deterministic Authenticated Encryption
Tetsu Iwata, Kan Yasuda
FSE2
2009 HMAC without the "Second" Key
Kan Yasuda
ISC1
2008 How to Fill Up Merkle-Damgård Hash Functions
Kan Yasuda
ASIACRYPT1
2008 A One-Pass Mode of Operation for Deterministic Message Authentication- Security beyond the Birthday Barrier
Kan Yasuda
FSE1
2007 "Sandwich" Is Indeed Secure: How to Authenticate a Message with Just One Hashing
Kan Yasuda
ACISP1
2007 Boosting Merkle-Damgård Hashing for Message Authentication
Kan Yasuda
ASIACRYPT1
2006 Forward-Secure Authenticated-Encryption in Multi-Receiver Setting
Kan Yasuda, Kazumaro Aoki, Eiichiro Fujisaki, Atsushi Fujioka
SECRYPT1