VLDB 2026 Research / reviewers in the wild / expert
Kazuo Sakiyama
dblp:04/4429
· DBLP profile ↗
57ranked-venue papers
10as first author
9since 2021 · last 2025
0000-0002-4414-815XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 3 first-author · 4 since 2021Systems, architecture and hardware · 22 · 5 first-author · 2 since 2021Software engineering, systems software and programming languages · 5Artificial intelligence and machine learning · 2Computer networks · 2 · 1 first-author · 1 since 2021Theory of computation · 2Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Key-Recovery Attack Against Ascon Using 1-Bit Random Fault Model
Soki Nakamura, Daiki Miyahara, Kazuo Sakiyama |
AINA (5) | 4 |
| 2025 | Parimutuel Betting on Blockchain: A Case Study on Horse Racing
Hiroki Uedan, Yang Li 0001, Kazuo Sakiyama, Daiki Miyahara |
AINA (2) | 3 |
| 2025 | Impossibility of Four-Card AND Protocols with a Single Closed Shuffle
Shizuru Iino, Shota Ikeda, Kazumasa Shinagawa, Yang Li 0022, Kazuo Sakiyama, Daiki Miyahara |
CANS | 5 |
| 2024 | Balance-Based ZKP Protocols for Pencil-and-Paper Puzzles
Shohei Kaneko, Pascal Lafourcade 0001, Lola-Baie Mallordy, Daiki Miyahara, Maxime Puys, Kazuo Sakiyama |
ISC (1) | 6 |
| 2024 | Multiplicative Masked M&M: An Attempt at Combined Countermeasures with Reduced RandomnessabstractWith the advancement of hardware security, combined attacks with techniques such as side-channel analysis (SCA) and fault analysis (FA) have prompted the development of combined countermeasures. However, these countermeasures often come with significant overhead. In this paper, we explore a solution to reduce the randomness requirement while maintaining security claims. We demonstrate the approach with Mask & Macs (M&M), a scheme that combines Boolean masking and MAC tag redundancy to provide SCA and DFA protection, addressing the challenge of high randomness requirement. We introduce a novel multiplicative masking scheme as a replacement for threshold implementation (TI) modules partially, leading to a reduction of over 50% in randomness requirement with minor increased FPGA resource overhead and latency. While the trade-off is beneficial, other limitations remain, and further research is needed to address these problems. This work provides a new perspective on improving combined countermeasures by exploring ways to reduce system overhead. Haruka Hirata, Daiki Miyahara, Kazuo Sakiyama, Yuko Hara-Azumi, Yang Li 0001 |
TrustCom | 4 |
| 2024 | Hardware/Software Cooperative Design Against Power Side-Channel Attacks on IoT DevicesabstractWith the growth of Internet of Things (IoT) era, the protection of secret information on IoT devices is becoming increasingly important. For IoT devices, attacks that target information leakage through physical side-channels (e.g., a power side-channel) are a major threat in many use cases because IoT devices can be accessed easily by a hostile third party. However, securing resource-constrained IoT devices against side-channel attacks is a challenging issue. Generally, it is difficult to satisfy the requirements on side-channel protection while maintaining the low-power and real-time constrains of IoT devices. In this paper, we propose a hardware/software cooperative design for cryptosystems that is suitable for resource-constrained IoT devices. Combining a security-oriented processor design (i.e., an instruction set architecture definition and its architectural structure) and careful implementations of masked software implementation for cipher algorithms can effectively improve the power-performance-area (PPA) while suppressing power side-channel leakage. In our evaluation, for three ciphers (Chaskey, Simon, and AES), we demonstrate that our work is superior to state-of-the-art works (two RISC-V processors and a small-scale low-power processor) in terms of both PPA and power side-channel protection. Mingyu Yang 0001, Tanvir Ahmed 0004, Saya Inagaki, Kazuo Sakiyama, Yang Li 0022, Yuko Hara-Azumi |
IEEE Internet Things J. | 4 |
| 2023 | Power Side-channel Countermeasures for ARX Ciphers using High-level SynthesisabstractIn the era of Internet of Things (IoT), edge devices are considerably diversified and are often designed using high-level synthesis (HLS) to improve design-productivity. A problem here is that HLS tools were originally developed in a security-unaware fashion, inducing vulnerabilities to power side-channel attacks (PSCA), which is a serious threat in IoT. Although PSCA vulnerabilities induced by HLS tools recently started to be discussed, the effects and applicability of existing methods for PSCA-resistant designs using HLS are limited so far. In this paper, we propose a novel HLS-based design method for PSCA-resistant ciphers in hardware. Particularly focusing on lightweight block ciphers composed of Addition-Rotation-XOR (ARX)-based permutations, we studied the effects of applying ''threshold implementation'', one of the provably secure countermeasures against PSCA, to behavioral descriptions of the ciphers. In addition, we tuned the scheduling optimization of HLS tools that might cause power side-channel leakage. In our experiment, using ARX-based ciphers (Chaskey, Simon, and Speck) as benchmarks, we implemented the unprotected and protected circuit on FPGA and evaluated the PSCA vulnerability using Welch's t-test. The results demonstrated that our proposed method can successfully mitigate vulnerabilities to PSCA for all benchmarks. From these results, we provide further discussion on the direction of PSCA countermeasures based on HLS. Saya Inagaki, Mingyu Yang 0001, Yang Li 0001, Kazuo Sakiyama, Yuko Hara-Azumi |
FPGA | 4 |
| 2023 | Power Side-channel Attack Resistant Circuit Designs of ARX Ciphers Using High-level SynthesisabstractIn the Internet of Things (IoT) era, edge devices have been considerably diversified and are often designed using high-level synthesis (HLS) for improved design productivity. However, HLS tools were originally developed in a security-unaware manner, resulting in vulnerabilities to power side-channel attacks (PSCAs), which are a serious threat to IoT systems. Currently, the impact and applicability of existing methods to PSCA-resistant designs using HLS are limited. In this article, we propose an effective HLS-based design method for PSCA-resistant ciphers implemented in hardware. In particular, we focus on lightweight block ciphers composed of addition/rotation/XOR (ARX)-based permutations to study the effects of the threshold implementation (which is one of the provably secure countermeasures against PSCAs) to the behavioral descriptions of ciphers along with the changes in HLS scheduling. The results obtained using Welch’s t-test demonstrate that our proposed method can successfully improve the resistance against PSCAs for all ARX-based ciphers used as benchmarks. Saya Inagaki, Mingyu Yang 0001, Yang Li 0022, Kazuo Sakiyama, Yuko Hara-Azumi |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2021 | More Accurate and Robust PRNU-Based Source Camera Identification with 3-Step 3-Class Approach
Annjhih Hsiao, Takao Takenouchi, Hiroaki Kikuchi, Kazuo Sakiyama, Noriyuki Miura |
IWDW | 4 |
| 2020 | A Key Recovery Algorithm Using Random Key Leakage from AES Key Schedule
Tomoki Uemura, Yohei Watanabe 0001, Yang Li 0001, Noriyuki Miura, Mitsugu Iwamoto, Kazuo Sakiyama, Kazuo Ohta |
ISITA | 6 |
| 2019 | Side-Channel Leakage of Alarm Signal for a Bulk-Current-Based Laser Sensor
Yang Li 0001, Ryota Hatano, Sho Tada, Kohei Matsuda, Noriyuki Miura, Takeshi Sugawara 0001, Kazuo Sakiyama |
Inscrypt | 7 |
| 2019 | Single-Round Pattern Matching Key Generation Using Physically Unclonable FunctionabstractParal and Devadas introduced a simple key generation scheme with a physically unclonable function (PUF) that requires no error correction, e.g., by using a fuzzy extractor. Their scheme, called a pattern matching key generation (PMKG) scheme, is based on pattern matching between auxiliary data, assigned at the enrollment in advance, and a substring of PUF output, to reconstruct a key. The PMKG scheme repeats a round operation, including the pattern matching, to derive a key with high entropy. Later, to enhance the efficiency and security, a circular PMKG (C-PMKG) scheme was proposed. However, multiple round operations in these schemes make them impractical. In this paper, we propose a single-round circular PMKG (SC-PMKG) scheme. Unlike the previous schemes, our scheme invokes the PUF only once. Hence, there is no fear of information leakage by invoking the PUF with the (partially) same input multiple times in different rounds, and, therefore, the security consideration can be simplified. Moreover, we introduce another hash function to generate a check string which ensures the correctness of the key reconstruction. The string enables us not only to defeat manipulation attacks but also to prove the security theoretically. In addition to its simple construction, the SC-PMKG scheme can use a weak PUF like the SRAM-PUF as a building block if our system is properly implemented so that the PUF is directly inaccessible from the outside, and, therefore, it is suitable for tiny devices in the IoT systems. We discuss its security and show its feasibility by simulations and experiments. Yuichi Komano, Kazuo Ohta, Kazuo Sakiyama, Mitsugu Iwamoto, Ingrid Verbauwhede |
Secur. Commun. Networks | 3 |
| 2018 | Sensor CON-Fusion: Defeating Kalman Filter in Signal Injection AttackabstractIn recent years, information systems have become increasingly able to interact with the real world by using relatively cheap connected embedded devices. In such systems, sensors are crucial components because systems can observe the real world only through sensors. Recently, there have been emerging threats to sensors, which involve the injection of false information in the physical/analog domain. To counter such attacks, sensor fusion is considered a promising approach because the robustness of a measurement can be improved by combining data from redundant sensors. However, sensor fusion algorithms were not originally designed to consider security, and thus their effectiveness is unclear. For this reason, in this paper, we evaluate in detail the security of sensor fusion. Notably, we consider a sensor fusion scenario that involves measuring inclination, with a combination of an accelerometer, gyroscope, and magnetometer using Kalman filter. Based on a theoretical analysis of the algorithm, two concrete attacks that defeat the sensor fusion are proposed. The feasibility of the proposed attacks is verified by performing experiments in emulated and real environments. We also propose a countermeasure that thwarts the new attacks. Furthermore, we logically prove that the proposed countermeasure detects all possible attacks. Shoei Nashimoto, Daisuke Suzuki, Takeshi Sugawara 0001, Kazuo Sakiyama |
AsiaCCS | 4 |
| 2018 | Analysis of Mixed PUF-TRNG Circuit Based on SR-Latches in FD-SOI TechnologyabstractAn SR-latch can be regarded as primitive to build a True Random Number Generation (TRNG) or Physically Unclonable Function (PUF). Indeed, when the SR inputs of the latch are tied together and go from an unknown state (i.e. S=R=1) to a memory state (i.e. S=R=0), the behaviour depends on the balance between the NAND or NOR gates composing the latch. With the process mismatch, there is a great chance that the latch converges towards the same state, thus creating a PUF equivalent to a SRAM-PUF or latch-PUF. However, if the latch is well-balanced, it can enter a metastable state and converges to a stable state depending on the input noise, thus making a TRNG. In order to make sure some latches are able to behave like a TRNG, and some like a PUF, we consider a set of latches driven by the same SR signal. A test-chip in 28nm UTBB-FDSOI technology has been designed with 1024 latches in order to analyze the behavior. The FD-SOI technology enables easy change of the performances of gates using the body biasing, which consists in applying a specific body voltage to each gate. Hence, the two NOR gates composing the SR-latch can be tuned individually to get the optimality, i.e. the maximum entropy, for both PUF and TRNG. The results show that the optimal point is the same for both PUF and TRNG, and that the proposed structure can generate concurrently a PUF with high reliability, and a TRNG with high speed. Jean-Luc Danger, Risa Yashiro, Tarik Graba, Yves Mathieu, Abdelmalek Si-Merabet, Kazuo Sakiyama, Noriyuki Miura, Makoto Nagata |
DSD | 6 |
| 2018 | Recovering Memory Access Sequence with Differential Flush+Reload Attack
Zhiwei Yuan, Yang Li 0001, Kazuo Sakiyama, Takeshi Sugawara 0001, Jian Wang 0038 |
ISPEC | 3 |
| 2017 | Exploiting Bitflip Detector for Non-invasive Probing and its Application to Ineffective Fault AnalysisabstractMatsuda et al. proposed a countermeasure against laser fault injection that uses distributed on-chip sensors. The sensor raises an alarm by detecting an electrical phenomenon caused in conjunction with a bitflip. A cryptographic module can stop releasing a faulty ciphertext by using the alarm. In this paper, security and limitation of the countermeasure by Matsuda et al. is rigorously evaluated. We show that an attacker can get side-channel information by observing how the sensors react to laser fault injection. That enables the attacker to probe intermediate values in a chip non-invasively. On the one hand, under a chosen-plaintext setting, the laser-based probing enables to run the conventional probing attack on AES by Schmidt and Kim. On the other hand, under a ciphertext-only setting, the laser-based probing raises a new challenge: the attacker is given correct ciphertexts and corresponding single-bit probing results. We propose a new ineffective fault analysis against AES based on linear cryptanalysis that can be used in the above setting. Takeshi Sugawara 0001, Natsu Shoji, Kazuo Sakiyama, Kohei Matsuda, Noriyuki Miura, Makoto Nagata |
FDTC | 3 |
| 2015 | Implementation of double arbiter PUF and its performance evaluation on FPGAabstractLow uniqueness and vulnerability to machine-learning attacks are known as two major problems of Arbiter-Based Physically Unclonable Function (APUF) implemented on FPGAs. In this paper, we implement Double APUF (DAPUF) that duplicates the original APUF in order to overcome the problems. From the experimental results on Xilinx Virtex-5, we show that the uniqueness of DAPUF becomes almost ideal, and the prediction rate of the machine-learning attack decreases from 86% to 57%. Takanori Machida, Dai Yamamoto, Mitsugu Iwamoto, Kazuo Sakiyama |
ASP-DAC | 4 |
| 2015 | A Silicon-Level Countermeasure Against Fault Sensitivity Analysis and Its EvaluationabstractIn this paper, we present an efficient countermeasure against fault sensitivity analysis (FSA) based on configurable delay blocks (CDBs). FSA is a new type of fault attack, which exploits the relationship between fault sensitivity (FS) and secret information. Previous studies reported that it could break cryptographic modules equipped with conventional countermeasures against differential fault analysis (DFA), such as redundancy calculation, masked and-or, and wave dynamic differential logic. The proposed countermeasure can thwart both DFA and FSA attacks based on setup time violation faults. The proposed ideas are to use a CDB as a time base for detection and to combine the technique with Li's countermeasure concept that removes the dependency between FSs and secret data. The postmanufacture configuration of the CDBs allows minimization of the overhead in operating frequency that comes from manufacture variability. In this paper, we also present an implementation of the proposed countermeasure in application-specified integrated circuit, and describe its configuration method. We then investigate the hardware overhead of the proposed countermeasure for an advanced encryption standard processor and demonstrate its validity through an experiment. Sho Endo, Yang Li 0001, Naofumi Homma, Kazuo Sakiyama, Kazuo Ohta, Daisuke Fujimoto, Makoto Nagata, Toshihiro Katashita, Jean-Luc Danger, Takafumi Aoki |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2014 | A New Mode of Operation for Arbiter PUF to Improve Uniqueness on FPGAabstractArbiter-basedPhysically Unclonable Function (PUF) is one kind of the delay-based PUFs that use the time difference of two delay-line signals.One of the previous work suggests that Arbiter PUFs implemented on Xilinx Virtex-5 FPGAs generate responses with almost no difference, i.e. with low uniqueness.In order to overcome this problem, Double Arbiter PUF was proposed, which is based on a novel technique for generating responses with high uniqueness from duplicated Arbiter PUFs on FPGAs.It needs the same costs as 2-XOR Arbiter PUF that XORs outputs of two Arbiter PUFs.Double Arbiter PUF is different from 2-XOR Arbiter PUF in terms of mode of operation for Arbiter PUF: the wire assignment between an arbiter and output signals from the final selectors located just before the arbiter.In this paper, we evaluate these PUFs as for uniqueness, randomness, and steadiness.We consider finding a new mode of operation for Arbiter PUF that can be realized on FPGA.In order to improve the uniqueness of responses, we propose 3-1 Double Arbiter PUF that has another duplicated Arbiter PUF, i.e. having 3 Arbiter PUFs and output 1-bit response.We compare 3-1 Double Arbiter PUF to 3-XOR Arbiter PUF according to the uniqueness, randomness, and steadiness, and show the difference between these PUFs by considering the mode of operation for Arbiter PUF.From our experimental results, the uniqueness of responses from 3-1 Double Arbiter PUF is approximately 50%, which is better than that from 3-XOR Arbiter PUF.We show that we can improve the uniqueness by using a new mode of operation for Arbiter PUF. Takanori Machida, Dai Yamamoto, Mitsugu Iwamoto, Kazuo Sakiyama |
FedCSIS | 4 |
| 2014 | Security Evaluation of Bistable Ring PUFs on FPGAs using Differential and Linear AnalysisabstractAbstract—Physically Unclonable Function (PUF) is expected to be an innovation for anti-counterfeiting devices for secure ID generation, authentication, etc. In this paper, we propose novel methods of evaluating the difficulty of predicting PUF responses (i.e. PUF outputs), inspired by well-known differential and linear cryptanalysis. According to the proposed methods, we perform a first third-party evaluation for Bistable Ring PUF (BR-PUF), proposed in 2011. The BR-PUFs have been claimed that they have a resistance against the response predictions. Through our experiments using FPGAs, we demonstrate, however, that BR-PUFs have two types of correlations between challenges and responses, which may cause the easy prediction of PUF responses. First, the same responses are frequently generated for two challenges (i.e. PUF inputs) with small Hamming distance. A number of randomly-generated challenges and their variants with Hamming distance of one generate the same responses with the probability of 0.88, much larger than 0.5 in ideal PUFs. Second, particular bits of challenges in BR-PUFs have a great impact on the responses. The value of responses becomes ‘1 ’ with the high probability of 0.71 (> 0.5) when just particular 5 bits of 64-bit random challenges are forced to be zero or one. In conclusion, the proposed evaluation methods reveal that BR-PUFs on FPGAs have some correlations of challenge-response pairs, which helps an attacker to predict the responses. I. Dai Yamamoto, Masahiko Takenaka, Kazuo Sakiyama, Naoya Torii |
FedCSIS | 3 |
| 2013 | Meet-in-the-Middle Preimage Attacks Revisited - New Results on MD5 and HAVAL
Yu Sasaki 0001, Wataru Komatsubara, Yasuhide Sakai, Lei Wang 0031, Mitsugu Iwamoto, Kazuo Sakiyama, Kazuo Ohta |
SECRYPT | 6 |
| 2012 | An Extension of Fault Sensitivity Analysis Based on Clockwise Collision
Yang Li 0001, Kazuo Ohta, Kazuo Sakiyama |
Inscrypt | 3 |
| 2012 | An Efficient Countermeasure against Fault Sensitivity Analysis Using Configurable Delay BlocksabstractIn this paper, we present an efficient countermeasure against Fault Sensitivity Analysis (FSA) based on a configurable delay blocks (CDBs). FSA is a new type of fault attack which exploits the relationship between fault sensitivity and secret information. Previous studies reported that it could break cryptographic modules equipped with conventional countermeasures against Differential Fault Analysis (DFA) such as redundancy calculation, Masked AND-OR and Wave Dynamic Differential Logic (WDDL). The proposed countermeasure can detect both DFA and FSA attacks based on setup time violation faults. The proposed ideas are to use a CDB as a time base for detection and to combine the technique with Li's countermeasure concept which removes the dependency between fault sensitivities and secret data. Post-manufacture configuration of the delay blocks allows minimization of the overhead in operating frequency which comes from manufacture variability. In this paper, we present an implementation of the proposed countermeasure, and describe its configuration method. We also investigate the hardware overhead of the proposed countermeasure implemented in ASIC for an AES module and demonstrate its validity through an experiment using a prototype FPGA implementation. Sho Endo, Yang Li 0001, Naofumi Homma, Kazuo Sakiyama, Kazuo Ohta, Takafumi Aoki |
FDTC | 4 |
| 2012 | New Truncated Differential Cryptanalysis on 3D Block Cipher
Takuma Koyama, Lei Wang 0031, Yu Sasaki 0001, Kazuo Sakiyama, Kazuo Ohta |
ISPEC | 4 |
| 2012 | New Fault-Based Side-Channel Attack Using Fault SensitivityabstractThis paper proposes a new fault-based attack called fault sensitivity analysis (FSA) attack. In the FSA attack, fault injections are used to test out the sensitive information leakage called fault sensitivity. Fault sensitivity means the critical fault injection intensity that corresponds to the threshold between devices' normal and abnormal behaviors. We demonstrate that without using the values of the faulty outputs, attackers can obtain the information of the secret key based on the data-dependency of the collected fault sensitivity data. This paper explains the successful FSA attacks against three Advanced Encryption Standard (AES) hardware implementations, where two of them are resistant to the differential fault analysis. This paper also discusses the countermeasures against the proposed FSA attacks. Yang Li 0001, Kazuo Ohta, Kazuo Sakiyama |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2012 | Information-Theoretic Approach to Optimal Differential Fault AnalysisabstractThis paper presents a comprehensive analysis of differential fault analysis (DFA) attacks on the Advanced Encryption Standard (AES) from an information-theoretic perspective. Injecting faults into cryptosystems is categorized as an active at tack where attackers induce an error in operations to retrieve the secret internal information, e.g., the secret key of ciphers. Here, we consider DFA attacks as equivalent to a special kind of passive attack where attackers can obtain leaked information without measurement noise. The DFA attacks are regarded as a conversion process from the leaked information to the secret key. Each fault model defines an upper bound for the amount of leaked information. The optimal DFA attacks should be able to exploit fully the leaked information in order to retrieve the secret key with a practical level of complexity. This paper discusses a new DFA methodology to achieve the optimal DFA attack by deriving the amount of the leaked information for various fault models from an information-theoretic perspective. We review several previous DFA at tacks on AES variants to check the optimality of their attacks. We also propose improved DFA attacks on AES-192 and AES-256 that reach the theoretical limits. Kazuo Sakiyama, Yang Li 0001, Mitsugu Iwamoto, Kazuo Ohta |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | Fair and Consistent Hardware Evaluation of Fourteen Round Two SHA-3 CandidatesabstractThe first contribution of our paper is that we propose a platform, a design strategy, and evaluation criteria for a fair and consistent hardware evaluation of the second-round SHA-3 candidates. Using a SASEBO-GII field-programmable gate array (FPGA) board as a common platform, combined with well defined hardware and software interfaces, we compare all 256-bit version candidates with respect to area, throughput, latency, power, and energy consumption. Our approach defines a standard testing harness for SHA-3 candidates, including the interface specification for the SHA-3 module on our testing platform. The second contribution is that we provide both FPGA and 90-nm CMOS application-specific integrated circuit (ASIC) synthesis results and thereby are able to compare the results. Our third contribution is that we release the source code of all the candidates and by using a common, fixed, publicly available platform, our claimed results become reproducible and open for a public verification. Miroslav Knezevic, Kazuyuki Kobayashi, Jun Ikegami, Shin'ichiro Matsuo, Akashi Satoh, Ünal Koçabas, Junfeng Fan, Toshihiro Katashita, Takeshi Sugawara 0001, Kazuo Sakiyama, Ingrid Verbauwhede, Kazuo Ohta, Naofumi Homma, Takafumi Aoki |
IEEE Trans. Very Large Scale Integr. Syst. | 10 |
| 2011 | On the Power of Fault Sensitivity Analysis and Collision Side-Channel Attacks in a Combined Setting
Amir Moradi 0001, Oliver Mischke, Christof Paar, Yang Li 0001, Kazuo Ohta, Kazuo Sakiyama |
CHES | 6 |
| 2011 | Uniqueness Enhancement of PUF Responses Based on the Locations of Random Outputting RS Latches
Dai Yamamoto, Kazuo Sakiyama, Mitsugu Iwamoto, Kazuo Ohta, Takao Ochiai, Masahiko Takenaka, Kouichi Itoh |
CHES | 2 |
| 2011 | (Second) Preimage Attacks on Step-Reduced RIPEMD/RIPEMD-128 with a New Local-Collision Approach
Lei Wang 0031, Yu Sasaki 0001, Wataru Komatsubara, Kazuo Ohta, Kazuo Sakiyama |
CT-RSA | 5 |
| 2011 | Fault Sensitivity Analysis Against Elliptic Curve CryptosystemsabstractIn this paper, we present a fault-based security evaluation for an Elliptic Curve Cryptography (ECC) implementation using the Montgomery Powering Ladder (MPL). We focus in particular on the Lopez-Dahab algorithm, which is used to calculate a point on an elliptic curve efficiently without using the y - coordinate. Several previous fault analysis attacks cannot be applied to the ECC implementation employing the Lopez-Dahab algorithm in a straight-forward manner. In this paper, we evaluate the security of the Lopez-Dahab algorithm using Fault Sensitivity Analysis (FSA). Although the initial work on FSA was applied only to an Advanced Encryption Standard (AES) implementation, we apply the technique to the ECC implementation. Consequently, we found a vulnerability to FSA for the ECC implementation using the Lopez-Dahab algorithm. Hikaru Sakamoto, Yang Li 0001, Kazuo Ohta, Kazuo Sakiyama |
FDTC | 4 |
| 2011 | Tripartite modular multiplication
Kazuo Sakiyama, Miroslav Knezevic, Junfeng Fan, Bart Preneel, Ingrid Verbauwhede |
Integr. | 1 |
| 2010 | Non-full-active Super-Sbox Analysis: Applications to ECHO and Grøstl
Yu Sasaki 0001, Yang Li 0001, Lei Wang 0031, Kazuo Sakiyama, Kazuo Ohta |
ASIACRYPT | 4 |
| 2010 | Fault Sensitivity Analysis
Yang Li 0001, Kazuo Sakiyama, Shigeto Gomisawa, Toshinori Fukunaga, Junko Takahashi, Kazuo Ohta |
CHES | 2 |
| 2010 | Improving Efficiency of an ‘On the Fly' Identification Scheme by Perfecting Zero-Knowledgeness
Bagus Santoso, Kazuo Ohta, Kazuo Sakiyama, Goichiro Hanaoka |
CT-RSA | 3 |
| 2010 | Improved countermeasure against Address-bit DPA for ECC scalar multiplicationabstractMesserges, Dabbish and Sloan proposed a DPA attack which analyzes the address values of registers. This attack is called the Address-bit DPA (ADPA) attack. As countermeasures against ADPA, Itoh, Izu and Takenaka proposed algorithms that randomizes address bits. In this paper, we point out that one of their countermeasures has vulnerability even if the address bits are uniformly randomized. When a register is overwritten by the same data as one stored in the register during a data move process, the power consumption is lower than the case of being overwritten by the different data. This fact enables us to separate the power traces. As a result, in the case of the algorithm proposed in, we could invalidate the randomness of the random bits and perform ADPA to retrieve a secret key. Moreover, for the purpose of overcoming the vulnerability, we propose a new countermeasure algorithm. Masami Izumi, Jun Ikegami, Kazuo Sakiyama, Kazuo Ohta |
DATE | 3 |
| 2010 | Power Variance Analysis breaks a masked ASIC implementation of AESabstractTo obtain a better trade-off between cost and security, practical DPA countermeasures are not likely to deploy full masking that uses one distinct mask bit for each signal. A common approach is to use the same mask on several instances of an algorithm. This paper proposes a novel power analysis method called Power Variance Analysis (PVA) to reveal the danger of such implementations. PVA uses the fact that the side-channel leakage of parallel circuits has a big variance when they are given the same but random inputs. This paper introduces the basic principle of PVA and a series of PVA experiments including a successful PVA attack against a prototype RSL-AES implemented on SASEBO-R. Yang Li 0001, Kazuo Sakiyama, Lejla Batina, Daisuke Nakatsu, Kazuo Ohta |
DATE | 2 |
| 2009 | A New Approach for Implementing the MPL Method toward Higher SPA ResistanceabstractThe information security is emphasized with a development of Internet systems. In the measures as securing digital information, there are cryptosystems that protect secrecy of digital documents and digital signature scheme that ensure validity of digital documents. In the case of reality, i.e. hardware devices are used in cryptosystems, there is a possibility that secret information leaks via side-channel. Simple power analysis (SPA) attacks are one of the side-channel attacks. To prevent a SPA, one of the side-channel attacks, the Montgomery powering ladder (MPL) method has been considered as one of the countermeasures. In this paper, we show that a naive implementation of the MPL method is vulnerable for SPA attacks by observing the power consumption of the controller block of the RSA hardware. Furthermore, in order to avoid such information leakage, we propose a new hardware architecture for RSA using the MPL method to enhance SPA resistance. Masami Izumi, Kazuo Sakiyama, Kazuo Ohta |
ARES | 2 |
| 2009 | Fault Analysis Attack against an AES Prototype Chip Using RSL
Kazuo Sakiyama, Tatsuya Yagi, Kazuo Ohta |
CT-RSA | 1 |
| 2009 | Security Evaluation of a DPA-Resistant S-Box Based on the Fourier Transform
Yang Li 0001, Kazuo Sakiyama, Shin-ichi Kawamura, Yuichi Komano, Kazuo Ohta |
ICICS | 2 |
| 2008 | On the high-throughput implementation of RIPEMD-160 hash algorithmabstractIn this paper we present two new architectures of the RIPEMD-160 hash algorithm for high throughput implementations. The first architecture achieves the iteration bound of RIPEMD-160, i.e. it achieves a theoretical upper bound on throughput at the micro-architecture level. The second architecture is designed by performing a gate level optimization and achieves a better performance than the first one at the cost of a larger gate area. Throughputs of 3.122 Gbps and 624 Mbps are achieved, with and without pipelining, respectively. Miroslav Knezevic, Kazuo Sakiyama, Yong Ki Lee, Ingrid Verbauwhede |
ASAP | 2 |
| 2008 | FPGA Design for Algebraic Tori-Based Public-Key CryptographyabstractAlgebraic torus-based cryptosystems are an alternative for Public-Key Cryptography (PKC). It maintains the security of a larger group while the actual computations are performed in a subgroup. Compared with RSA for the same security level, it allows faster exponentiation and much shorter bandwidth for the transmitted data. In this work we implement a torus-based cryptosystem, the so-called CEILIDH, on a multicore platform with an FPGA. This platform consists of a Xilinx MicroBlaze core and a multicore coprocessor. The platform supports CEILIDH, RSA and ECC over prime fields. The results show that one 170-bit torus T6exponentiation requires 20 ms, which is 5 times faster than 1024-bit RSA implementation on the same platform. Junfeng Fan, Lejla Batina, Kazuo Sakiyama, Ingrid Verbauwhede |
DATE | 3 |
| 2008 | Modular Reduction in GF(2n) without Pre-computational Phase
Miroslav Knezevic, Kazuo Sakiyama, Junfeng Fan, Ingrid Verbauwhede |
WAIFI | 2 |
| 2008 | Elliptic-Curve-Based Security Processor for RFIDabstractRFID (Radio Frequency IDentification) tags need to include security functions, yet at the same time their resources are extremely limited. Moreover, to provide privacy, authentication and protection against tracking of RFID tags without loosing the system scalability, a public-key based approach is inevitable, which is shown by M. Burmester et al. In this paper, we present an architecture of a state-of-the-art processor for RFID tags with an Elliptic Curve (EC) processor over GF(2^163). It shows the plausibility of meeting both security and efficiency requirements even in a passive RFID tag. The proposed processor is able to perform EC scalar multiplications as well as general modular arithmetic (additions and multiplications) which are needed for the cryptographic protocols. As we work with large numbers, the register file is the most critical component in the architecture. By combining several techniques, we are able to reduce the number of registers from 9 to 6 resulting in EC processor of 10.1K gates. To obtain an efficient modulo arithmetic, we introduce a redundant modular operation. Moreover the proposed architecture can support multiple cryptographic protocols. The synthesis results with a 0.13 um CMOS technology show that the gate area of the most compact version is 12.5K gates. Yong Ki Lee, Kazuo Sakiyama, Lejla Batina, Ingrid Verbauwhede |
IEEE Trans. Computers | 2 |
| 2007 | Efficient pipelining for modular multiplication architectures in prime fieldsabstractThis paper presents a pipelined architecture of a modular Montgomery multiplier, which is suitable to be used in public key coprocessors. Starting from a baseline implementation of the Montgomery algorithm, a more compact pipelined version is derived. The design makes use of 16-bit integer multiplication blocks that are available on recently manufactured FPGAs. The critical path is optimized by omitting the exact computation of intermediate results in the Montgomery algorithm using a 6-2 carry-save notation. This results in a high-speed architecture,which outperforms previously designed Montgomery multipliers. Because a very popular application of Montgomery multiplication is public key cryptography, we compare our implementation to the state-of-the-art in Montgomery multipliers on the basis of performance results for 1024-bit RSA. Nele Mentens, Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede |
ACM Great Lakes Symposium on VLSI | 2 |
| 2007 | Side-channel resistant system-level design flow for public-key cryptographyabstractIn this paper, we propose a new design methodology to assess the risk for side-channel attacks, more specifically timing analysis and simple power analysis, at an early design stage. This method is illustrated with the design of an elliptic curve cryptographic processor. It also allows to evaluate the quality of countermeasures against these attacks by evaluating hamming distances for eachsignal and each register in a partial functional domain (e.g. datapath or controller). Thus a first order side-channel-resistant design can be obtained with system-level design in which the simulation can run faster than conventional HDL simulations. Kazuo Sakiyama, Elke De Mulder, Bart Preneel, Ingrid Verbauwhede |
ACM Great Lakes Symposium on VLSI | 1 |
| 2007 | Public-Key Cryptography on the Top of a NeedleabstractThis work describes the smallest known hardware implementation for Elliptic/Hyperelliptic Curve Cryptography (ECC/HECC). We propose two solutions for Public-key Cryptography (PKC), which are based on arithmetic on elliptic/hyperelliptic curves. One solution relies on ECC over binary fields 𝔽2𝓃where 𝓃 is a composite number of the form2𝑝(𝑝is a prime) and another on HECC on curves of genus 2 over 𝔽2𝑝. This implies the same arithmetic unit for both cases which supports arithmetic in a field 𝔽2𝑝. Our best solution that still results in a feasible performance features less than 5 kgates with an average power consumption smaller than 10μW. Lejla Batina, Nele Mentens, Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede |
ISCAS | 3 |
| 2007 | High-performance Public-key Cryptoprocessor for Wireless Mobile Applications
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
Mob. Networks Appl. | 1 |
| 2007 | Multicore Curve-Based Cryptoprocessor with Reconfigurable Modular Arithmetic Logic Units over GF(2n)abstractThis paper presents a reconfigurable curve-based cryptoprocessor that accelerates scalar multiplication of Elliptic Curve Cryptography (ECC) and HyperElliptic Curve Cryptography (HECC) of genus 2 over GF(2n). By allocating a copies of processing cores that embed reconfigurable Modular Arithmetic Logic Units (MALUs) over GF(2n), the scalar multiplication of ECC/HECC can be accelerated by exploiting Instruction-Level Parallelism (ILP). The supported field size can be arbitrary up to a(n + 1) - 1. The superscaling feature is facilitated by defining a single instruction that can be used for all field operations and point/divisor operations. In addition, the cryptoprocessor is fully programmable and it can handle various curve parameters and arbitrary irreducible polynomials. The cost, performance, and security trade-offs are thoroughly discussed for different hardware configurations and software programs. The synthesis results with a 0.13-mum CMOS technology show that the proposed reconfigurable cryptoprocessor runs at 292 MHz, whereas the field sizes can be supported up to 587 bits. The compact and fastest configuration of our design is also synthesized with a fixed field size and irreducible polynomial. The results show that the scalar multiplication of ECC over GF(2163) and HECC over GF(283) can be performed in 29 and 63 mus, respectively. Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
IEEE Trans. Computers | 1 |
| 2006 | Superscalar Coprocessor for High-Speed Curve-Based Cryptography
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
CHES | 1 |
| 2006 | Reconfigurable Architectures for Curve-Based Cryptography on Embedded Micro-ControllersabstractThis paper discusses architectures for embedded security to enable various cryptographic services at low cost. To realize the large bit-lengths and complex arithmetic on an 8-bit embedded micro-controller, several hardware acceleration options for elliptic and hyperelliptic curve cryptography (ECC and HECC) are studied and systematically evaluated. Two key factors influence the performance: one is the communication interface i.e. I/O transfers between processor and co-processor and the other one is the boundary between hardware and software. Our experiments are run on an 8051 and an AVR micro-controller with the crypto co-processors implemented on a FPGA Lejla Batina, Alireza Hodjat, David Hwang 0001, Kazuo Sakiyama, Ingrid Verbauwhede |
FPL | 4 |
| 2006 | Fpga-Oriented Secure Data Path Design: Implementation of a Public Key CoprocessorabstractThis paper introduces a secure FPGA implementation of a coprocessor for public key cryptography. It supports Elliptic Curve Cryptography (ECC) as well as the older RSA standard. When choosing adequate key lengths, RSA and ECC are assumed to be secure from an algorithmic point of view. On the other hand, an implementation of these algorithms should also guarantee side-channel security. This feature does not only cause an inevitable performance degradation, but also an area increase. We overcome these drawbacks by fitting the public key architecture and algorithms into a coprocessor that optimally exploites the dedicated features on a Spartan XC3S4000. Although this is a very low-cost FPGA, the performance results of our implementation meet the requirements of a broad range of high-end applications. Nele Mentens, Kazuo Sakiyama, Lejla Batina, Ingrid Verbauwhede, Bart Preneel |
FPL | 2 |
| 2006 | A Parallel Processing Hardware Architecture for Elliptic Curve CryptosystemsabstractWe propose a parallel processing crypto-processor for elliptic curve cryptography (ECC) to speed up EC point multiplication. The processor consists of a controller that dynamically checks instruction-level parallelism (ILP) and multiple sets of modular arithmetic logic units accelerating modular operations. A case study of HW design with the proposed architecture shows that EC point multiplication over GF(p) and GF(2m) can be improved by a factor of 1.6 compared to the case of using single processing element Kazuo Sakiyama, Elke De Mulder, Bart Preneel, Ingrid Verbauwhede |
ICASSP (3) | 1 |
| 2006 | A fast dual-field modular arithmetic logic unit and its hardware implementationabstractWe propose a fast modular arithmetic logic unit (MALU) that is scalable in the digit size (d) and the field size (k). The datapath of MALU has chains of carry save adders (CSAs) to speed up the large integer arithmetic operations over GF(p) and GF(2m). It is well suited and very efficient for the modular multiplication and addition/subtraction which are the computational kernels of elliptic curve and hyperelliptic curve cryptography (H/ECC). While maintaining the scalability and multi-function, we obtain a throughput of 205 Mbps and 388 Mbps with a clock rate of 110 MHz for 256-bit GF(p) and GF(2239) respectively on FPGA prototyping Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede |
ISCAS | 1 |
| 2004 | Embedded Software Integration for Coarse-Grain Reconfigurable SystemsabstractSummary form only given. Coarse-grain reconfigurable systems offer high performance and energy-efficiency, provided an efficient run-time reconfiguration mechanism is available. Using an embedded software vantage point, we define three levels of reconfigurability for such systems, each with a different degree of coupling between embedded software and reconfigurable hardware. We classify reconfigurable systems starting with tightly-coupled coprocessors and evolving to processor networks. This results in a gradual increase of energy-efficiency when compared to software-only systems, at the cost of increasing programming complexity. Using several sample applications including signal-, crypto-, and network-processing acceleration units, we demonstrate energy-efficiency improvements of 12 times over software for tightly-coupled systems up to 84 times for network-on-chip systems. Patrick Schaumont, Kazuo Sakiyama, Alireza Hodjat, Ingrid Verbauwhede |
IPDPS | 2 |
| 2003 | Finding the best system design flow for a high-speed JPEG encoderabstract26 students at the University of California, Los Angeles (UCLA) studied system level design methodologies through the design of a high-speed JPEG encoder. The results produced by 5 different design flows onto various target platforms demonstrate the high impact of tools on design quality. Kazuo Sakiyama, Patrick Schaumont, Ingrid Verbauwhede |
ASP-DAC | 1 |
| 2003 | Design flow for HW / SW acceleration transparency in the thumbpod secure embedded systemabstractThis paper describes a case study and design flow of a secure embedded system called ThumbPod, which uses cryptographic and biometric signal processing acceleration. It presents the concept of HW/SW acceleration transparency, a systematic method to accelerate Java functions in both software and hardware. An example of acceleration transparency for a Rijndael encryption function is presented. The embedded prototype hardware platform is also described. Acceleration transparency yields software and hardware performance gains of 333X. David Hwang 0001, Bo-Cheng Lai, Patrick Schaumont, Kazuo Sakiyama, Shenglin Yang, Alireza Hodjat, Ingrid Verbauwhede |
DAC | 4 |