VLDB 2026 Research / reviewers in the wild / expert
Kaisa Nyberg
dblp:46/2601
· DBLP profile ↗
38ranked-venue papers
13as first author
1since 2021 · last 2022
0000-0003-2885-6364ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 10 first-authorTheory of computation · 4 · 2 first-author · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Structural and Statistical Analysis of Multidimensional Linear Approximations of Random Functions and PermutationsabstractThe goal of this paper is to investigate linear approximations of random functions and permutations. Our motivation is twofold. First, before the distinguishability of a practical cipher from an ideal one can be analysed, the cryptanalyst must have an accurate understanding of the statistical behaviour of the ideal cipher. Secondly, this issue has been neglected both in old and in more recent studies, particularly when multiple linear approximations are being used simultaneously. Traditional models have been based on the average behaviour and simplified using other assumptions such as independence of the linear approximations. Multidimensional cryptanalysis was introduced to avoid making artificial assumptions about statistical independence of linear approximations. On the other hand, it has the drawback of including many trivial approximations that do not contribute to the attack but just cause a waste of time and memory. We show for the first time in this paper that the trivial approximations reduce the degree of freedom of the related χ2 distribution. Previously, the affine linear cryptanalysis was proposed to allow removing trivial approximations and, at the same time, admitting a solid statistical model. In this paper, we identify another type of multidimensional linear approximation, called Davies-Meyer approximation, which has similar advantages, and present full statistical models for both the affine and the Davies-Meyer type of multidimensional linear approximations. The new models given in this paper are realistic, accurate and easy to use. They are backed up by standard statistical tools such as Pearson’s χ2 test and finite population correction and demonstrated to work accurately using practical examples. Tomer Ashur, Kaisa Nyberg |
IEEE Trans. Inf. Theory | 3 |
| 2019 | Multidimensional Linear CryptanalysisabstractLinear cryptanalysis introduced by Matsui is a statistical attack which exploits a binary linear relation between plaintext, ciphertext and key, either in Algorithm 1 for recovering one bit of information of the secret key of a block cipher, or in Algorithm 2 for ranking candidate values for a part of the key. The statistical model is based on the expected and observed bias of a single binary value. Multiple linear approximations have been used with the goal to make the linear attack more efficient. More bits of information of the key can potentially be recovered possibly using less data. But then also more elaborated statistical models are needed to capture the joint behaviour of several not necessarily independent binary variables. Also more options are available for generalising the statistics of a single variable to several variables. The multidimensional extension of linear cryptanalysis to be introduced in this paper considers using multiple linear approximations that form a linear subspace. Different extensions of Algorithm 1 and Algorithm 2 will be presented and studied. The methods will be based on known statistical tools such as goodness-of-fit test and log-likelihood ratio. The efficiency of the different methods will be measured and compared in theory and experiments using the concept of advantage introduced by Selçuk. The block cipher Serpent with a reduced number of rounds will be used as test bed. The multidimensional linear cryptanalysis will also be compared with previous methods that use biasedness of multiple linear approximations. It will be shown in the simulations that the multidimensional method is potentially more powerful. Its main theoretical advantage is that the statistical model can be given without the assumption about statistical independence of the linear approximations. Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg |
J. Cryptol. | 3 |
| 2017 | Joint data and key distribution of simple, multiple, and multidimensional linear cryptanalysis test statistic and its impact to data complexity
Céline Blondeau, Kaisa Nyberg |
Des. Codes Cryptogr. | 2 |
| 2017 | Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg |
J. Cryptol. | 3 |
| 2015 | Capacity and Data Complexity in Multidimensional Linear Attack
Jialin Huang, Serge Vaudenay, Xuejia Lai, Kaisa Nyberg |
CRYPTO (1) | 4 |
| 2015 | Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012 |
J. Cryptol. | 5 |
| 2014 | Links between Truncated Differential and Multidimensional Linear Properties of Block Ciphers and Underlying Attack Complexities
Céline Blondeau, Kaisa Nyberg |
EUROCRYPT | 2 |
| 2014 | Differential-Linear Cryptanalysis Revisited
Céline Blondeau, Gregor Leander, Kaisa Nyberg |
FSE | 3 |
| 2014 | Zero-correlation linear cryptanalysis of reduced-round LBlock
Hadi Soleimany, Kaisa Nyberg |
Des. Codes Cryptogr. | 2 |
| 2013 | New Links between Differential and Linear Cryptanalysis
Céline Blondeau, Kaisa Nyberg |
EUROCRYPT | 2 |
| 2013 | Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012 |
FSE | 5 |
| 2013 | Generalization of Matsui's Algorithm 1 to linear hull for key-alternating block ciphers
Andrea Röck, Kaisa Nyberg |
Des. Codes Cryptogr. | 2 |
| 2012 | Integral and Multidimensional Linear Distinguishers with Correlation Zero
Andrey Bogdanov, Gregor Leander, Kaisa Nyberg |
ASIACRYPT | 3 |
| 2012 | Estimating Resistance against Multidimensional Linear Attacks: An Application on DEAN
Risto M. Hakala, Atle Kivelä, Kaisa Nyberg |
Inscrypt | 3 |
| 2012 | "Provable" Security against Differential and Linear Cryptanalysis
Kaisa Nyberg |
FSE | 1 |
| 2010 | Dependent Linear Approximations: The Algorithm of Biryukov and Others Revisited
Miia Hermelin, Kaisa Nyberg |
CT-RSA | 2 |
| 2010 | Consecutive S-box Lookups: A Timing Attack on SNOW 3G
Billy Bob Brumley, Risto M. Hakala, Kaisa Nyberg, Sampo Sovio |
ICICS | 3 |
| 2010 | On the Nonlinearity of Discrete Logarithm in \mathbb F2n\mathbb F_{2^n}
Risto M. Hakala, Kaisa Nyberg |
SETA | 2 |
| 2010 | A practical distinguisher for the Shannon cipher
Zahra Ahmadian, Javad Mohajeri, Mahmoud Salmasizadeh, Risto M. Hakala, Kaisa Nyberg |
J. Syst. Softw. | 5 |
| 2009 | Multidimensional Extension of Matsui's Algorithm 2
Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg |
FSE | 3 |
| 2008 | Linear Distinguishing Attack on Shannon
Risto M. Hakala, Kaisa Nyberg |
ACISP | 2 |
| 2008 | Multidimensional Linear Cryptanalysis of Reduced Round Serpent
Miia Hermelin, Joo Yeon Cho, Kaisa Nyberg |
ACISP | 3 |
| 2008 | Message from the SecPri Workshop Organizing Technical Co-chairsabstractPresents the introductory welcome message from the conference proceedings. Peter Mueller, Kaisa Nyberg, Stefanos Gritzalis, Costas Lambrinoudakis |
WiMob | 2 |
| 2008 | Random Beacon for Privacy and Group SecurityabstractMost contemporary security mechanisms and protocols include exchange of random or time-variant nonces as an essential means of protection against replay and other threats or as a seed for randomness. In many cases, it would be beneficial to have such nonces available from a trusted common source, such as a satellite. The goal of this paper is to present a protocol by which a loosely connected network of devices can agree on a common piece of randomness, and show how it can be applied to improve efficiency of a privacy protection system and group session key exchange for PAN/LAN devices. Aleksi Saarela, Jan-Erik Ekberg, Kaisa Nyberg |
WiMob | 3 |
| 2007 | Differential Properties of Elliptic Curves and Blind Signatures
Billy Bob Brumley, Kaisa Nyberg |
ISC | 2 |
| 2007 | Multidimensional Walsh Transform and a Characterization of Bent FunctionsabstractIn this paper, a multidimensional Walsh transform is used to obtain a characterization of vector-valued bent function in terms of the value distributions of the translates of the function by linear functions. Kaisa Nyberg, Miia Hermelin |
ITW | 1 |
| 2007 | Wireless Group Security Using MAC Layer MulticastabstractIn a small PAN, devices are typically connected together over wireless or wired link layer technology and communication between devices is point-to-point or point-to-multipoint. In this paper, we discuss some common methods to negotiate unicast and multicast keys on MAC layer. We also present an upper layer group key management framework to facilitate flexible and secure group communication in a PAN. Our main observation is that the current MAC layer security solutions do not support well multicast communications. For improved efficiency, we propose to enhance the MAC layer security solutions with a multiparty handshake procedure. Kaisa Nyberg, Jukka Valkonen |
WOWMOM | 1 |
| 2006 | Efficient Mutual Data Authentication Using Manually Authenticated Strings
Sven Laur, Kaisa Nyberg |
CANS | 2 |
| 2006 | Improved Linear Distinguishers for SNOW 2.0
Kaisa Nyberg, Johan Wallén |
FSE | 1 |
| 2001 | Correlation theorems in cryptanalysis
Kaisa Nyberg |
Discret. Appl. Math. | 1 |
| 1996 | Generalized Feistel Networks
Kaisa Nyberg |
ASIACRYPT | 1 |
| 1996 | Fast Accumulated Hashing
Kaisa Nyberg |
FSE | 1 |
| 1996 | Message Recovery for Signature Schemes Based on the Discrete Logarithm Problem
Kaisa Nyberg, Rainer A. Rueppel |
Des. Codes Cryptogr. | 1 |
| 1995 | Provable Security Against a Differential Attack
Kaisa Nyberg, Lars R. Knudsen |
J. Cryptol. | 1 |
| 1994 | S-boxes and Round Functions with Controllable Linearity and Differential Uniformity
Kaisa Nyberg |
FSE | 1 |
| 1993 | A New Signature Scheme Based on the DSA Giving Message RecoveryabstractIn this paper we present a modification of the DSA which allows signatures with message recovery. The new public key signature scheme is then applied to create (a) an identity-based public key system without restrictions in trust and (b) a one-pass key exchange protocol with mutual authentication. Kaisa Nyberg, Rainer A. Rueppel |
CCS | 1 |
| 1993 | New Bent Mappings Suitable for Fast Implementation
Kaisa Nyberg |
FSE | 1 |
| 1992 | Provable Security Against Differential Cryptanalysis
Kaisa Nyberg, Lars R. Knudsen |
CRYPTO | 1 |