Takanori Isobe 0001

dblp:38/7170-1 · DBLP profile ↗
← Back
74ranked-venue papers
15as first author
40since 2021 · last 2026
0000-0003-4253-5567ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 70 · 15 first-author · 38 since 2021Theory of computation · 3 · 3 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Analyzing Forgery Security of LeMac: Tight Bounds and Impact of Padding
Taichi Nagoya, Takuro Shiraya, Kazuma Taka, Tatsuya Ishikawa, Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
ACISP (1)7
2026 Automated Tool for Finding Practical Collisions on SPN-Based Hash Functions
Keita Toyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Kodai Taiyama, Takanori Isobe 0001
ACISP (1)6
2026 Finding the Inverse of some Shift Invariant Transformations
Fukang Liu, Vaibhav Dixit, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
J. Cryptol.5
2025 Strengthening Key Scheduling of AES-256 with Minimal Software Modifications
Shoma Kawakami, Kazuma Taka, Atsushi Tanaka, Tatsuya Ishikawa, Takanori Isobe 0001
ACISP (1)5
2025 Forgery Attacks on SipHash
Kosuke Sasaki, Rikuto Kurahara, Kosei Sakamoto, Takanori Isobe 0001
ACISP (1)4
2025 Gravity of the Situation: Security Analysis on Rocket.Chat E2EE
abstract
Rocket.Chat is a group chat platform widely deployed in industries and national organizations, with over 15 million users across 150 countries. One of its main features is an end-to-end encryption (E2EE) protocol; however, no cryptographic security analysis has been conducted. We conduct an in-depth cryptographic analysis of Rocket.Chat's E2EE protocol and identify multiple significant flaws that allow a malicious server or even an outsider to break the confidentiality and integrity of the group chat. Specifically, we formally model and analyze the protocol using ProVerif under the Dolev-Yao model, uncovering multiple theoretical weaknesses and verifying that some of them lead to practical attacks. Furthermore, through meticulous manual analysis, we identify additional vulnerabilities, including implementation flaws and cryptographic weaknesses such as CBC malleability, and demonstrate how they are exploitable in practical attack scenarios. To validate our findings, we develop Proof-of-Concept implementations, highlighting the real-world feasibility of these attacks. We also propose mitigation techniques and discuss the implications of our attacks.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Takanori Isobe 0001
ACSAC4
2025 Not in The Prophecies: Practical Attacks on Nostr
abstract
Distributed social networking services (SNSs) recently received significant attention as an alternative to traditional, centralized SNSs, which have inherent limitations on user privacy and freedom. We provide the first in-depth security analysis of Nostr, an open-source, distributed SNS protocol developed in 2019 with more than 1.1 million registered users. We investigate the specification of Nostr and the client implementations and present a number of practical attacks allowing forgeries on various objects, such as encrypted direct messages (DMs), by a malicious user or a malicious server. Even more, we show a confidentiality attack against encrypted DMs by a malicious user exploiting a flaw in the link preview mechanism and the CBC malleability. Our attacks are due to cryptographic flaws in the protocol specification and client implementation, some of which in combination elevate the forgery attack to a violation of confidentiality. We verify the practicality of our attacks via Proof-of-Concept implementations and discuss how to mitigate them.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Shogo Shiraki, Takanori Isobe 0001
EuroS&P5
2025 Collision Attacks on SPONGENT with Grouping Method
Keita Toyama, Kosei Sakamoto, Takanori Isobe 0001
SAC3
2025 Security analysis of SFrame
abstract
Increasing privacy consciousness has popularized the use of end-to-end encryption (E2EE). In this paper, we discuss the security of SFrame, an E2EE mechanism proposed to the Internet Engineering Task Force for video/audio group communications over the Internet. Despite being a quite recent project, SFrame has been deployed in several real-world applications. The original specification of SFrame is evaluated herein to find critical issues that can cause impersonation (forgery) attacks with a practical complexity by a malicious group member . Further investigations have revealed that these issues are present in several publicly available SFrame implementations. Therefore, we provide several countermeasures against all the proposed attacks and considerations from performance and security perspectives towards their implementation.
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
J. Inf. Secur. Appl.1
2025 Parallel SAT framework to find clustering of differential characteristics and its applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
J. Inf. Secur. Appl.3
2024 Differential Distinguishing Attacks on SNOW-V, SNOW-Vi and KCipher-2
Rikuto Kurahara, Kosei Sakamoto, Yuto Nakano, Takanori Isobe 0001
ACISP (1)4
2024 Key Collisions on AES and Its Applications
Kodai Taiyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Takanori Isobe 0001
ASIACRYPT (7)5
2024 Collision Attacks on Hashing Modes of Areion
Kodai Taiyama, Kosei Sakamoto, Rentaro Shiba, Takanori Isobe 0001
CANS (2)4
2024 Security Analysis on End-to-End Encryption of Zoom Mail
abstract
Zoom Mail, an email service provided by Zoom Video Communications, features a proprietary end-to-end encryption (E2EE) scheme, which is detailed in a whitepaper available on GitHub. To date, there has been no detailed discussion or third-party evaluation of the security of the E2EE implementation in Zoom Mail. In this paper, we conduct a comprehensive security analysis of Zoom Mail's E2EE. Specifically, we establishes four types of adversary models: insiders, outsiders, To/CC (carbon copy) members, and BCC (blind carbon copy) member. We focus on three security goals: confidentiality, integrity, and authenticity. Based on these adversary models and security goals, we present the results of security evaluation of Zoom Mail's E2EE for the first time.
Shogo Shiraki, Takanori Isobe 0001
ISITA2
2024 Quantum Key Recovery Attacks on 4-Round Iterated Even-Mansour with Two Keys
Ravi Anand, Shibam Ghosh, Takanori Isobe 0001, Rentaro Shiba
ISC (1)3
2024 Exploring the optimality of byte-wise permutations of a piccolo-type block cipher
abstract
Piccolo is a lightweight block cipher based on a 16-bit word 4-line generalized Feistel structure. Piccolo adopts byte-wise round permutation (RP) instead of the typical word-based RP to improve diffusion. In this paper, we explore the optimality of byte-based RP from the viewpoint of security. We evaluate the security of differential, linear, impossible differential, and integral attacks for all byte-wise RPs using mixed integer linear programming (MILP). We show that the RP of Piccolo is optimal in terms of the number of rounds required to guarantee security against such attacks. In addition, we introduce new two classes of RPs that require 7 rounds for security against impossible differential attacks, which is one round less than required by Piccolo. These new classes require 7/9 and 8/8 rounds to guarantee security against differential/linear attacks, respectively, which is more rounds than required by Piccolo.
Shion Utsumi, Motoki Nakahashi, Kosei Sakamoto, Takanori Isobe 0001
Inf. Process. Lett.4
2024 Revisiting the Boomerang Attack From a Perspective of 3-Differential
abstract
In this paper, inspired by the work of Beyne and Rijmen at CRYPTO 2022, we explore the accurate probability ofd-differential in the fixed-key model. The theoretical foundations of our method are based on a special matrix - quasi-d-differential transition matrix, which is a natural extension of the quasidifferential transition matrix. The role of quasi-d-differential transition matrices in polytopic cryptananlysis is analogous to that of correlation matrices in linear cryptanalysis. Therefore, the fixed-key probability of ad-differential can be exactly expressed as the sum of the correlations of its quasi-d-differential trails. Then we revisit the boomerang attack from a perspective of 3-differential. Different from previous works, the probability of a boomerang distinguisher can be exactly expressed as the sum of the correlations of its quasi-3-differential trails without any assumptions in our work. In order to illustrate our theory, we apply it to the lightweight block cipher GIFT. It is interesting to find the probability of every optimal 3-differential characteristic of an existing 2-round boomerang is zero, which can be seen as an evidence that the security of block ciphers adopting half-round key XOR might be overestimated previously to some extent in differential-like attacks.
Ling Song 0001, Baofeng Wu, Mostafizar Rahman, Takanori Isobe 0001
IEEE Trans. Inf. Theory5
2023 Ghidle: Efficient Large-State Block Ciphers for Post-quantum Security
Motoki Nakahashi, Rentaro Shiba, Ravi Anand, Mostafizar Rahman, Kosei Sakamoto, Fukang Liu, Takanori Isobe 0001
ACISP7
2023 Coefficient Grouping for Complex Affine Layers
Fukang Liu, Lorenzo Grassi 0001, Clémence Bouvier, Willi Meier, Takanori Isobe 0001
CRYPTO (3)5
2023 An Efficient Strategy to Construct a Better Differential on Multiple-Branch-Based Designs: Application to Orthros
Kazuma Taka, Tatsuya Ishikawa, Kosei Sakamoto, Takanori Isobe 0001
CT-RSA4
2023 An Ultra-High Throughput AES-Based Authenticated Encryption Scheme for 6G: Design and Implementation
Ravi Anand, Subhadeep Banik, Andrea Caforio, Kazuhide Fukushima, Takanori Isobe 0001, Shinsaku Kiyomoto, Fukang Liu, Yuto Nakano, Kosei Sakamoto, Nobuyuki Takeuchi
ESORICS (1)5
2023 Coefficient Grouping: Breaking Chaghri and More
Fukang Liu, Ravi Anand, Willi Meier, Takanori Isobe 0001
EUROCRYPT (4)5
2023 Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILP
Fukang Liu, Gaoli Wang, Santanu Sarkar 0001, Ravi Anand, Willi Meier, Yingxin Li, Takanori Isobe 0001
EUROCRYPT (4)7
2023 Parallel SAT Framework to Find Clustering of Differential Characteristics and Its Applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
SAC3
2023 Cubicle: A family of space-hard ciphers for IoT
abstract
Abstract As IoT has increasingly evolved in recent years, it has become more important to ensure security on IoT devices. Many of such devices are under the threat of attacks in the beyond black‐box model. To protect from the threat, the cryptographic implementation that can offer secure execution in the grey‐/white‐box model is important. However, such cryptographic implementations require a large number of clock cycles to execute and cannot fully cover resistance against various types of side‐channel attacks. In this paper, a new family of table‐based cipher dubbed Cubicle is proposed, which can offer efficient execution and sufficient security against side‐channel attacks on IoT devices powered by ARM Cortex‐M processors, which are widely deployed in IoT applications. To evaluate the security of Cubicle in the grey‐box model, the authors derive the bound of table leakage in the grey‐box model by applying space hardness, which is the notion to evaluate the security against code lifting attacks in the white‐box. The security of Cubicle in the grey‐box model is shown by using this bound. In addition, the security of Cubicle is also shown in the black‐box and white‐box models. Finally, the performance of Cubicle and other ciphers in some devices powered by ARM Cortex‐M3, ‐M4, and ‐M7 processors is evaluated. The authors show that Cubicle is significantly efficient compared to other grey‐/white‐box‐ model‐secure ciphers in target experiments for IoT applications.
Rentaro Shiba, Ravi Anand, Kazuhiko Minematsu, Takanori Isobe 0001
IET Inf. Secur.4
2023 MILP-based security evaluation for AEGIS/Tiaoxin-346/Rocca
abstract
Abstract In this paper, the security of Advanced Encryption Standard‐based authenticated encryption schemes, including AEGIS family, Tiaoxin‐346, and Rocca by mixed integer linear programming tools is examined. Specifically, for the initialisation phase of AEGIS, Tiaoxin‐346, and Rocca, the security against differential attacks and integral attacks is evaluated by estimating the lower bounds for the number of active S‐boxes and utilising division property, respectively. In addition to the estimations of initialisation phases, the security of the encryption phases of AEGIS, Tiaoxin‐346, and Rocca against distinguishing attacks on keystream is evaluated by exploiting integral properties. As a result, the authors show that the initialisation phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca are secure against differential attacks after 4/3/6, 5, and 6 rounds, respectively. Regarding integral attacks, the distinguisher is found on 6/6/7, 15, and 7 rounds in the initialisation phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca, respectively. Additionally, the integral distinguisher is presented on 2/2/4, 4, and 4 rounds in the encryption phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca, respectively. As far as it is known, this study’s results are the first distinguishing attacks on the keystream on AEGIS, Tiaoxin‐346, and Rocca without relying on weak keys.
Takuro Shiraya, Nobuyuki Takeuchi, Kosei Sakamoto, Takanori Isobe 0001
IET Inf. Secur.4
2023 Bit-level evaluation of piccolo block cipher by satisfiability problem solver
abstract
Abstract In the field of symmetric key cryptography, the security against distinguishing attacks is one of the crucial security requirements. With advancements in computing capabilities and cryptanalysis techniques in recent years, more efficient methods have been proposed for exploring distinguishers using Mixed‐Integer Linear Programing (MILP) or satisfiability problem (SAT), thereby updating the security bounds of various ciphers. Piccolo is a lightweight block cipher proposed at CHES in 2011, with support 80‐bit and 128‐bit keys. Designers have undergone a rough security evaluation against differential, impossible differential, and related‐key differential attacks, based on nibble‐wise estimations due to the limitation of computational resource. Here, the authors perform bit‐level evaluations on Piccolo block cipher against differential, integral and impossible differential attacks by leveraging SAT‐based approaches. For the first time, the authors succeed in identifying optimal differential distinguisher on 6 rounds in the single key setting, and on 10/12 rounds in the related‐key setting for 80‐bit and 128‐bit keys, respectively. For integral attacks, the authors find integral distinguisher up to 7 rounds. Although the number of attacked rounds is the same as that of the previous attack, the authors find the 56th ordered integral distinguisher, which enable reducing the data complexity for attacks from 2 63 to 2 56 . As a result, the authors find the 7‐round impossible differentials which is the same number of rounds as the previous nibble‐wise evaluation.
Shion Utsumi, Kosei Sakamoto, Takanori Isobe 0001
IET Inf. Secur.3
2022 A Modular Approach to the Incompressibility of Block-Cipher-Based AEADs
Akinori Hosoyamada, Takanori Isobe 0001, Yosuke Todo, Kan Yasuda
ASIACRYPT (2)2
2022 Algebraic Meet-in-the-Middle Attack on LowMC
Fukang Liu, Santanu Sarkar 0001, Gaoli Wang, Willi Meier, Takanori Isobe 0001
ASIACRYPT (1)5
2022 Efficient constructions for large-state block ciphers based on AES New Instructions
abstract
Abstract Large‐state block ciphers with 256 bits or 512 bits block sizes receive much attention from the viewpoint of long‐term security. Existing large‐state block ciphers, such as Haraka‐v2 and Pholkos, consist of only the AES New Instructions set (AES‐NI) and a word shuffle that can be efficiently executed by SIMD instructions for fast software implementation. In Haraka‐v2 and Pholkos, the AES round function is executed twice in parallel at each step and its outputs are shuffled (called two‐round constructions). In this study, optimal constructions based on AES‐NI and efficient word shuffles for such large‐state block ciphers in terms of the encryption speed for software are explored. Specifically, an optimal class of word shuffles that can achieve security in a smaller number of rounds from the class of word shuffles that can be efficiently implemented in SIMD to contribute to the improvement of the performance of large‐state block ciphers is identified. Their speed for each CPU architecture is measured. As a result, the authors reveal the constructions such that two rounds of the AES round function is executed in parallel at each step and its outputs are shuffled (called two‐round constructions) and are optimal in all CPUs with Skylake architecture or later versions. Furthermore, the authors reveal that there is a clear difference in word shuffle instructions with respect to the speed, even if they theoretically require the same number of cycles. Consequently, the authors clarify the optimal construction for each architecture by taking these differences into consideration.
Rentaro Shiba, Kosei Sakamoto, Takanori Isobe 0001
IET Inf. Secur.3
2022 Integral and impossible-differential attacks on the reduced-round Lesamnta-LW-BC
abstract
Abstract Lesamnta‐LW‐BC is the internal block cipher of the Lesamnta‐LW lightweight hash function, specified in ISO/IEC 29192‐5:2016. It is based on the unbalanced Feistel network and Advanced Encryption Standard round function. In this study, the security of Lesamnta‐LW‐BC against integral and impossible‐differential attacks is evaluated. Specifically, the authors searched for the integral distinguishers and impossible differentials with Mixed‐Integer Linear Programming‐based methods. As a result, the discovered impossible differential can reach up to 21 rounds, while three integral distinguishers reaching 18, 19 and 25 rounds are obtained, respectively. Moreover, it is also feasible to construct a 47‐round integral distinguisher in the known‐key setting. Finally, a 20‐round key‐recovery attack is proposed based on the discovered 18‐round integral distinguisher and a 19‐round key‐recovery attack using a 17‐round impossible differential. To the best of the authors' knowledge, this is the first third‐party cryptanalysis of Lesamnta‐LW‐BC.
Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Kazuhiko Minematsu, Takanori Isobe 0001
IET Inf. Secur.5
2022 Distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-Vi
abstract
This paper presents distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-Vi, which are stream ciphers proposed for standard encryption schemes for the 5G mobile communication system. First, we construct a Mixed-Integer Linear Programming (MILP) model to search for integral characteristics using the division property, and find the best integral distinguisher in the 3-, 4-, 5-round SNOW-V, and 5-round SNOW-Vi with time complexities of 28, 216, 248, and 216, respectively. Next, we construct a bit-level MILP model to efficiently search for differential characteristics, and find the best differential characteristics in the 3- and 4-round versions. These characteristics lead to the 3-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 217 and 212 and the 4-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 297 and 239, respectively. Then, we consider single-bit and dual-bit differential cryptanalysis, which is inspired by the existing study on Salsa and ChaCha. By carefully choosing the IV values and differences, we can construct practical bit-wise differential distinguishers for the 4-round SNOW-V, 4-, and 5-round SNOW-Vi with time complexities of 24.466, 21.000, and 214.670, respectively. Finally, we improve the existing differential attack based on probabilistic neutral bits, which is also inspired by the existing study on Salsa and ChaCha. As a result, we present the best key recovery attack on the 4-round SNOW-V and SNOW-Vi with time complexities of 2153.97 and 2233.99 and data complexities of 226.96 and 219.19, respectively. Consequently, we significantly improve the existing best key recovery attack in the initialization phase by the designers.
Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto
J. Inf. Secur. Appl.2
2022 The Inverse of χ and Its Applications to Rasta-Like Ciphers
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
J. Cryptol.4
2021 Distinguishing and Key Recovery Attacks on the Reduced-Round SNOW-V
Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto
ACISP2
2021 Security Analysis of End-to-End Encryption for Zoom Meetings
abstract
In the wake of the global COVID-19 pandemic, video conference systems have become essential for not only business purposes, but also private, academic, and educational uses. Among the various systems, Zoom is the most widely deployed video conference system. In October 2020, Zoom Video Communications rolled out their end-to-end encryption (E2EE) to protect conversations in a meeting from even insiders, namely, the service provider Zoom. In this study, we conduct thorough security evaluations of the E2EE of Zoom (version 2.3.1) by analyzing their cryptographic protocols. We discover several attacks more powerful than those expected by Zoom according to their whitepaper. Specifically, if insiders collude with meeting participants, they can impersonateany Zoom userin target meetings, whereas Zoom indicates that they can impersonate only the current meeting participants. Besides, even without relying on malicious participants, insiders can impersonate any Zoom user in target meetings though they cannot decrypt meeting streams. In addition, we demonstrate several impersonation attacks by meeting participants or insiders colluding with meeting participants. Although these attacks may be beyond the scope of the security claims made by Zoom or may be already mentioned in the whitepaper, we reveal the details of the attack procedures and their feasibility in the real-world setting and propose effective countermeasures in this paper. Our findings are not an immediate threat to the E2EE of Zoom; however, we believe that these security evaluations are of value for deeply understanding the security of E2EE of Zoom.
Takanori Isobe 0001, Ryoma Ito 0001
ACISP1
2021 Algebraic Attacks on Round-Reduced Keccak
Fukang Liu, Takanori Isobe 0001, Willi Meier, Zhonghao Yang 0003
ACISP2
2021 Algebraic Attacks on Rasta and Dasta Using Low-Degree Equations
Fukang Liu, Santanu Sarkar 0001, Willi Meier, Takanori Isobe 0001
ASIACRYPT (1)4
2021 Cryptanalysis of Full LowMC and LowMC-M with Algebraic Techniques
Fukang Liu, Takanori Isobe 0001, Willi Meier
CRYPTO (3)2
2021 Security Analysis of SFrame
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
ESORICS (2)1
2021 Bit-wise cryptanalysis on AND-RX permutation Friet-PC
abstract
This paper presents three attack vectors of bit-wise cryptanalysis including rotational, bit-wise differential, and zero-sum distinguishing attacks on the AND-RX permutation Friet-PC, which is implemented in a lightweight authenticated encryption scheme Friet. First, we propose a generic procedure for a rotational attack on AND-RX cipher with round constants. By applying the proposed attack to Friet-PC, we can construct an 8-round rotational distinguisher with a time complexity of 2102. Next, we explore single- and dual-bit differential biases, which are inspired by the existing study on Salsa and ChaCha, and observe the best bit-wise differential bias with 2−9.552. This bias allows us to practically construct a 9-round bit-wise differential distinguisher with a time complexity of 220.044. Finally, we construct 13-, 15-, and 17-round zero-sum distinguishers with time complexities of 231, 263, and 2127, respectively. To summarize our study, we apply three attack vectors of bit-wise cryptanalysis to Friet-PC and show their superiority as effective attacks on AND-RX ciphers.
Ryoma Ito 0001, Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Takanori Isobe 0001
J. Inf. Secur. Appl.5
2020 Galaxy: A Family of Stream-Cipher-Based Space-Hard Ciphers
Yuji Koike, Kosei Sakamoto, Takuya Hayashi 0001, Takanori Isobe 0001
ACISP4
2020 ACE in Chains: How Risky Is CBC Encryption of Binary Executable Files?
Rintaro Fujita, Takanori Isobe 0001, Kazuhiko Minematsu
ACNS (1)2
2020 Automatic Verification of Differential Characteristics: Application to Reduced Gimli
Fukang Liu, Takanori Isobe 0001, Willi Meier
CRYPTO (3)2
2020 WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri
SAC3
2019 Efficient Collision Attack Frameworks for RIPEMD-160
Fukang Liu, Christoph Dobraunig, Florian Mendel, Takanori Isobe 0001, Gaoli Wang, Zhenfu Cao
CRYPTO (2)4
2019 Plaintext Recovery Attacks Against XTS Beyond Collisions
Takanori Isobe 0001, Kazuhiko Minematsu
SAC1
2019 Iterative Differential Characteristic of TRIFLE-BC
Fukang Liu, Takanori Isobe 0001
SAC2
2019 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
abstract
At CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively.
Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001
IEEE Trans. Computers2
2018 Several MILP-Aided Attacks Against SNOW 2.0
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii
CANS3
2018 Fast Correlation Attack Revisited - Cryptanalysis on Full Grain-128a, Grain-128, and Grain-v1
Yosuke Todo, Takanori Isobe 0001, Willi Meier, Kazumaro Aoki, Bin Zhang 0003
CRYPTO (2)2
2018 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier
CRYPTO (1)5
2018 Breaking Message Integrity of an End-to-End Encryption Scheme of LINE
Takanori Isobe 0001, Kazuhiko Minematsu
ESORICS (2)1
2018 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
abstract
The cube attack is a powerful cryptanalytic technique and is especially powerful against stream ciphers. Since we need to analyze the complicated structure of a stream cipher in the cube attack, the cube attack basically analyzes it by regarding it as a blackbox. Therefore, the cube attack is an experimental attack, and we cannot evaluate the security when the size of cube exceeds an experimental range, e.g., 40. In this paper, we propose cube attacks on non-blackbox polynomials. Our attacks are developed by using the division property, which is recently applied to various block ciphers. The clear advantage is that we can exploit large cube sizes because it never regards the cipher as a blackbox. We apply the new cube attack to Trivium, Grain128a, ACORN and Kreyvium. As a result, the secret keys of 832-round Trivium, 183-round Grain128a, 704-round ACORN and 872-round Kreyvium are recovered. These attacks are the current best key-recovery attack against these ciphers.
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
IEEE Trans. Computers2
2017 Improved Integral Attack on HIGHT
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii
ACISP (1)3
2017 Conditional Differential Cryptanalysis for Kreyvium
Yuhei Watanabe, Takanori Isobe 0001, Masakatu Morii
ACISP (1)2
2017 New Key Recovery Attacks on Minimal Two-Round Even-Mansour Ciphers
Takanori Isobe 0001, Kyoji Shibutani
ASIACRYPT (1)1
2017 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
CRYPTO (3)2
2016 Towards Practical Whitebox Cryptography: Optimizing Efficiency and Space Hardness
Andrey Bogdanov, Takanori Isobe 0001, Elmar Tischhauser
ASIACRYPT (1)2
2016 Cryptanalysis of the Full Spritz Stream Cipher
Subhadeep Banik, Takanori Isobe 0001
FSE2
2015 Midori: A Block Cipher for Low Energy
Subhadeep Banik, Andrey Bogdanov, Takanori Isobe 0001, Kyoji Shibutani, Harunaga Hiwatari, Toru Akishita, Francesco Regazzoni 0001
ASIACRYPT (2)3
2015 How Secure is AES Under Leakage
Andrey Bogdanov, Takanori Isobe 0001
ASIACRYPT (2)2
2015 White-Box Cryptography Revisited: Space-Hard Ciphers
abstract
The need for software security in untrusted environments is ever increasing. White-box cryptography aims to ensure the security of cryptographic algorithms when the attacker has full access to their implementations. However, there is no secure white-box implementation of standard block ciphers such as DES and AES known to date: All published techniques have been practically broken. In this paper, we revisit white-box cryptography and propose a family of white-box secure block ciphers SPACE with several novel features. The design of SPACE is such that the key-extraction security in the white box reduces to the well-studied problem of key recovery for block ciphers (AES in our example) in the standard black-box setting. Moreover, to mitigate code lifting, we introduce the notion of space hardness. It measures the difficulty of compressing the white-box implementation of a cipher, and quantifies security against code lifting by the amount of code that needs to be extracted from the implementation by a white-box attacker to maintain its functionality. SPACE includes several variants with different white-box code sizes. Therefore, it is applicable to a wide range of environments and use cases. One of the variants called N-SPACE can be implemented with different code sizes while keeping the cipher itself unchanged.
Andrey Bogdanov, Takanori Isobe 0001
CCS2
2014 Improved All-Subkeys Recovery Attacks on FOX, KATAN and SHACAL-2 Block Ciphers
Takanori Isobe 0001, Kyoji Shibutani
FSE1
2013 Related-Key Boomerang Attacks on KATAN32/48/64
Takanori Isobe 0001, Yu Sasaki 0001, Jiageng Chen
ACISP1
2013 Generic Key Recovery Attack on Feistel Scheme
Takanori Isobe 0001, Kyoji Shibutani
ASIACRYPT (1)1
2013 Full Plaintext Recovery Attack on Broadcast RC4
Takanori Isobe 0001, Toshihiro Ohigashi, Yuhei Watanabe, Masakatu Morii
FSE1
2013 How to Recover Any Byte of Plaintext on RC4
Toshihiro Ohigashi, Takanori Isobe 0001, Yuhei Watanabe, Masakatu Morii
Selected Areas in Cryptography2
2013 A Single-Key Attack on the Full GOST Block Cipher
Takanori Isobe 0001
J. Cryptol.1
2012 Security Analysis of the Lightweight Block Ciphers XTEA, LED and Piccolo
Takanori Isobe 0001, Kyoji Shibutani
ACISP1
2012 Converting Meet-In-The-Middle Preimage Attack into Pseudo Collision Attack: Application to SHA-2
Takanori Isobe 0001, Kyoji Shibutani
FSE2
2012 All Subkeys Recovery Attack on Block Ciphers: Extending Meet-in-the-Middle Approach
Takanori Isobe 0001, Kyoji Shibutani
Selected Areas in Cryptography1
2011 Piccolo: An Ultra-Lightweight Blockcipher
Kyoji Shibutani, Takanori Isobe 0001, Harunaga Hiwatari, Atsushi Mitsuda, Toru Akishita, Taizo Shirai
CHES2
2011 A Single-Key Attack on the Full GOST Block Cipher
Takanori Isobe 0001
FSE1
2009 Preimage Attacks on Reduced Tiger and SHA-2
Takanori Isobe 0001, Kyoji Shibutani
FSE1