Kaisa Nyberg

dblp:46/2601 · DBLP profile ↗
← Back
38ranked-venue papers
13as first author
1since 2021 · last 2022
0000-0003-2885-6364ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 10 first-authorTheory of computation · 4 · 2 first-author · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2022 Structural and Statistical Analysis of Multidimensional Linear Approximations of Random Functions and Permutations
abstract
The goal of this paper is to investigate linear approximations of random functions and permutations. Our motivation is twofold. First, before the distinguishability of a practical cipher from an ideal one can be analysed, the cryptanalyst must have an accurate understanding of the statistical behaviour of the ideal cipher. Secondly, this issue has been neglected both in old and in more recent studies, particularly when multiple linear approximations are being used simultaneously. Traditional models have been based on the average behaviour and simplified using other assumptions such as independence of the linear approximations. Multidimensional cryptanalysis was introduced to avoid making artificial assumptions about statistical independence of linear approximations. On the other hand, it has the drawback of including many trivial approximations that do not contribute to the attack but just cause a waste of time and memory. We show for the first time in this paper that the trivial approximations reduce the degree of freedom of the related χ2 distribution. Previously, the affine linear cryptanalysis was proposed to allow removing trivial approximations and, at the same time, admitting a solid statistical model. In this paper, we identify another type of multidimensional linear approximation, called Davies-Meyer approximation, which has similar advantages, and present full statistical models for both the affine and the Davies-Meyer type of multidimensional linear approximations. The new models given in this paper are realistic, accurate and easy to use. They are backed up by standard statistical tools such as Pearson’s χ2 test and finite population correction and demonstrated to work accurately using practical examples.
Tomer Ashur, Kaisa Nyberg
IEEE Trans. Inf. Theory3
2019 Multidimensional Linear Cryptanalysis
abstract
Linear cryptanalysis introduced by Matsui is a statistical attack which exploits a binary linear relation between plaintext, ciphertext and key, either in Algorithm 1 for recovering one bit of information of the secret key of a block cipher, or in Algorithm 2 for ranking candidate values for a part of the key. The statistical model is based on the expected and observed bias of a single binary value. Multiple linear approximations have been used with the goal to make the linear attack more efficient. More bits of information of the key can potentially be recovered possibly using less data. But then also more elaborated statistical models are needed to capture the joint behaviour of several not necessarily independent binary variables. Also more options are available for generalising the statistics of a single variable to several variables. The multidimensional extension of linear cryptanalysis to be introduced in this paper considers using multiple linear approximations that form a linear subspace. Different extensions of Algorithm 1 and Algorithm 2 will be presented and studied. The methods will be based on known statistical tools such as goodness-of-fit test and log-likelihood ratio. The efficiency of the different methods will be measured and compared in theory and experiments using the concept of advantage introduced by Selçuk. The block cipher Serpent with a reduced number of rounds will be used as test bed. The multidimensional linear cryptanalysis will also be compared with previous methods that use biasedness of multiple linear approximations. It will be shown in the simulations that the multidimensional method is potentially more powerful. Its main theoretical advantage is that the statistical model can be given without the assumption about statistical independence of the linear approximations.
Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg
J. Cryptol.3
2017 Joint data and key distribution of simple, multiple, and multidimensional linear cryptanalysis test statistic and its impact to data complexity
Céline Blondeau, Kaisa Nyberg
Des. Codes Cryptogr.2
2017 Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg
J. Cryptol.3
2015 Capacity and Data Complexity in Multidimensional Linear Attack
Jialin Huang, Serge Vaudenay, Xuejia Lai, Kaisa Nyberg
CRYPTO (1)4
2015 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
J. Cryptol.5
2014 Links between Truncated Differential and Multidimensional Linear Properties of Block Ciphers and Underlying Attack Complexities
Céline Blondeau, Kaisa Nyberg
EUROCRYPT2
2014 Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg
FSE3
2014 Zero-correlation linear cryptanalysis of reduced-round LBlock
Hadi Soleimany, Kaisa Nyberg
Des. Codes Cryptogr.2
2013 New Links between Differential and Linear Cryptanalysis
Céline Blondeau, Kaisa Nyberg
EUROCRYPT2
2013 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
FSE5
2013 Generalization of Matsui's Algorithm 1 to linear hull for key-alternating block ciphers
Andrea Röck, Kaisa Nyberg
Des. Codes Cryptogr.2
2012 Integral and Multidimensional Linear Distinguishers with Correlation Zero
Andrey Bogdanov, Gregor Leander, Kaisa Nyberg
ASIACRYPT3
2012 Estimating Resistance against Multidimensional Linear Attacks: An Application on DEAN
Risto M. Hakala, Atle Kivelä, Kaisa Nyberg
Inscrypt3
2012 "Provable" Security against Differential and Linear Cryptanalysis
Kaisa Nyberg
FSE1
2010 Dependent Linear Approximations: The Algorithm of Biryukov and Others Revisited
Miia Hermelin, Kaisa Nyberg
CT-RSA2
2010 Consecutive S-box Lookups: A Timing Attack on SNOW 3G
Billy Bob Brumley, Risto M. Hakala, Kaisa Nyberg, Sampo Sovio
ICICS3
2010 On the Nonlinearity of Discrete Logarithm in \mathbb F2n\mathbb F_{2^n}
Risto M. Hakala, Kaisa Nyberg
SETA2
2010 A practical distinguisher for the Shannon cipher
Zahra Ahmadian, Javad Mohajeri, Mahmoud Salmasizadeh, Risto M. Hakala, Kaisa Nyberg
J. Syst. Softw.5
2009 Multidimensional Extension of Matsui's Algorithm 2
Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg
FSE3
2008 Linear Distinguishing Attack on Shannon
Risto M. Hakala, Kaisa Nyberg
ACISP2
2008 Multidimensional Linear Cryptanalysis of Reduced Round Serpent
Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg
ACISP3
2008 Message from the SecPri Workshop Organizing Technical Co-chairs
abstract
Presents the introductory welcome message from the conference proceedings.
Peter Mueller, Kaisa Nyberg, Stefanos Gritzalis, Costas Lambrinoudakis
WiMob2
2008 Random Beacon for Privacy and Group Security
abstract
Most contemporary security mechanisms and protocols include exchange of random or time-variant nonces as an essential means of protection against replay and other threats or as a seed for randomness. In many cases, it would be beneficial to have such nonces available from a trusted common source, such as a satellite. The goal of this paper is to present a protocol by which a loosely connected network of devices can agree on a common piece of randomness, and show how it can be applied to improve efficiency of a privacy protection system and group session key exchange for PAN/LAN devices.
Aleksi Saarela, Jan-Erik Ekberg, Kaisa Nyberg
WiMob3
2007 Differential Properties of Elliptic Curves and Blind Signatures
Billy Bob Brumley, Kaisa Nyberg
ISC2
2007 Multidimensional Walsh Transform and a Characterization of Bent Functions
abstract
In this paper, a multidimensional Walsh transform is used to obtain a characterization of vector-valued bent function in terms of the value distributions of the translates of the function by linear functions.
Kaisa Nyberg, Miia Hermelin
ITW1
2007 Wireless Group Security Using MAC Layer Multicast
abstract
In a small PAN, devices are typically connected together over wireless or wired link layer technology and communication between devices is point-to-point or point-to-multipoint. In this paper, we discuss some common methods to negotiate unicast and multicast keys on MAC layer. We also present an upper layer group key management framework to facilitate flexible and secure group communication in a PAN. Our main observation is that the current MAC layer security solutions do not support well multicast communications. For improved efficiency, we propose to enhance the MAC layer security solutions with a multiparty handshake procedure.
Kaisa Nyberg, Jukka Valkonen
WOWMOM1
2006 Efficient Mutual Data Authentication Using Manually Authenticated Strings
Sven Laur, Kaisa Nyberg
CANS2
2006 Improved Linear Distinguishers for SNOW 2.0
Kaisa Nyberg, Johan Wallén
FSE1
2001 Correlation theorems in cryptanalysis
Kaisa Nyberg
Discret. Appl. Math.1
1996 Generalized Feistel Networks
Kaisa Nyberg
ASIACRYPT1
1996 Fast Accumulated Hashing
Kaisa Nyberg
FSE1
1996 Message Recovery for Signature Schemes Based on the Discrete Logarithm Problem
Kaisa Nyberg, Rainer A. Rueppel
Des. Codes Cryptogr.1
1995 Provable Security Against a Differential Attack
Kaisa Nyberg, Lars R. Knudsen
J. Cryptol.1
1994 S-boxes and Round Functions with Controllable Linearity and Differential Uniformity
Kaisa Nyberg
FSE1
1993 A New Signature Scheme Based on the DSA Giving Message Recovery
abstract
In this paper we present a modification of the DSA which allows signatures with message recovery. The new public key signature scheme is then applied to create (a) an identity-based public key system without restrictions in trust and (b) a one-pass key exchange protocol with mutual authentication.
Kaisa Nyberg, Rainer A. Rueppel
CCS1
1993 New Bent Mappings Suitable for Fast Implementation
Kaisa Nyberg
FSE1
1992 Provable Security Against Differential Cryptanalysis
Kaisa Nyberg, Lars R. Knudsen
CRYPTO1