Donghoon Chang

dblp:50/4733 · DBLP profile ↗
← Back
26ranked-venue papers
13as first author
5since 2021 · last 2026
0000-0003-1249-2869ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 12 first-author · 3 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CRYPTO (6)1
2024 Lynx: Family of Lightweight Authenticated Encryption Schemes Based on Tweakable Blockcipher
abstract
The widespread deployment of low-power and handheld devices opens an opportunity to design lightweight authenticated encryption schemes. The schemes so proposed must also prove their resilience under various security notions. Romulus-N1 is an authenticated encryption scheme with associated data based on a tweakable blockcipher, a primary variant of Romulus-N family which is National Institute of Standards and Technology (NIST) lightweight cryptography competition finalist; provides beyond birthday bound security for integrity security in nonce respecting scenario but fails to provide the integrity security in nonce misuse and release of unverified plaintext (RUP) scenarios. In this article, we propose lynx, a family with 14 members of 1-pass and rate-1 lightweight authenticated encryption schemes with associated data based on a tweakable blockcipher, that provides birthday bound security for integrity security in both nonce respecting as well as nonce misuse and RUP scenarios and birthday bound security for privacy in nonce respecting scenario. For creating such a family of schemes, we propose a family of functions called$\mathcal {F}$, that provides a total of 72 cases out of which we show that only 14 of them can be used for creating authenticated encryption schemes. We provide the implementation of one of the members of lynx family on four different hardware platforms and compare it with Romulus-N1. The comparison clearly shows that the lynx member outperforms Romulus-N1 on all the four platforms.
Munawar Hasan, Donghoon Chang
IEEE Internet Things J.2
2023 A preimage attack on reduced GIMLI-HASH with unbalanced squeezing phase
abstract
Abstract In Conference on Cryptographic Hardware and Embedded System 2017, Bernstein et al. proposed GIMLI , a 384‐bit permutation with 24 rounds, which aims to provide high performance on various platforms. In 2019, the full‐round (24 rounds) GIMLI permutation was used as an underlying primitive for building AEAD GIMLI‐CIPHER and hash function GIMLI‐HASH , which were submitted to the NIST Lightweight Cryptography Standardisation process and selected as one of the second‐round candidates. In Transactions on Symmetric Cryptology 2021, Liu et al. presented a preimage attack with a divide‐and‐conquer method on round‐reduced GIMLI‐HASH , which uses 5‐round GIMLI . In this paper, preimage attacks on a round‐reduced variant of GIMLI‐HASH is presented, in which the message absorbing phase uses 5‐round GIMLI and the squeezing phase uses 9‐round GIMLI . This variant is called as 5–9‐round GIMLI‐HASH . The authors’ preimage attack on 5–9‐round GIMLI‐HASH requires 2 96.44 time complexity and 2 97 memory complexity. Also, this method can be reached up to round shifted 10‐round GIMLI in the squeezing phase. The authors’ first attack requires the memory for storing several precomputation tables in GIMLI SP‐box operations. In the authors’ second attack, a time‐memory trade‐off approach is taken, reducing memory requirements for precomputation tables but increasing computing time for solving SP‐box equations by using SAT solver. This attack requires 2 66.17 memory complexity and 2 96+ ϵ time complexity, where ϵ is a time complexity for solving SP‐box equations. The authors’ experiments using CryptoMiniSat SAT solver show that the maximum time complexity for ϵ is about 2 20.57 9‐round GIMLI .
Yongseong Lee, Jinkeon Kang, Donghoon Chang, Seokhie Hong
IET Inf. Secur.3
2022 On Security of Fuzzy Commitment Scheme for Biometric Authentication
Donghoon Chang, Surabhi Garg, Munawar Hasan, Sweta Mishra
ACISP1
2021 BIOFUSE: A framework for multi-biometric fusion on biocryptosystem level
Donghoon Chang, Surabhi Garg, Mohona Ghosh, Munawar Hasan
Inf. Sci.1
2020 Cancelable Multi-Biometric Approach Using Fuzzy Extractor and Novel Bit-Wise Encryption
abstract
The widespread deployment of multi-biometrics to authenticate users prompts the need for biometric systems with high recognition performance. Further, the biometric data, once leaked or stolen, remains compromised forever. Hence biometric security is of utmost importance. Existing biometric template protection schemes either degrade the recognition performance or they have issues with security and speed. We propose a cancelable multi-biometric authentication approach where a novel bit-wise encryption scheme transforms a biometric template to a protected template using a secret key generated from another biometric template. It fully preserves the number of bit-errors in the original and the protected template to ensure recognition performance equivalent to the performance of the unprotected systems. We introduce Algorithm I and Algorithm II for bit-wise encryption; both are defined over cryptographic-primitives- block cipher based encryption and keyed-hash function. We profile these algorithms on various hardware architectures to calculate the efficiency in terms of the time taken during enrolment and authentication phase. For Algorithm II, we observe that a 3.3 GHz desktop architecture takes about 18 milliseconds on an average of over 200 runs to authenticate a user. Additionally, we provide mathematical proof to show that the proposed scheme guarantees secrecy and irreversibility. The results of comparisons with the existing biometric template protection schemes on the various face and iris databases show that the proposed work provides significantly good recognition performance and efficiency, while it achieves high security. Finally, the bit-wise encryption scheme can be built over the commercial-off-the-shelf systems to achieve security with equivalent high performance.
Donghoon Chang, Surabhi Garg, Munawar Hasan, Sweta Mishra
IEEE Trans. Inf. Forensics Secur.1
2020 Threshold Implementations of <tt>GIFT</tt>: A Trade-Off Analysis
abstract
Threshold Implementation (TI) is one of the most widely used countermeasure for side channel attacks. Over the years several TI techniques have been proposed for randomizing cipher execution using different variations of secret-sharing and implementation techniques. For instance, sharing without decomposition (4-shares) is the most straightforward implementation of the threshold countermeasure. However, its usage is limited due to its high area requirements. On the other hand, sharing using decomposition (3-shares) countermeasure for cubic non-linear functions significantly reduces area and complexity in comparison to 4-shares. Nowadays, security of ciphers using a side channel countermeasure is of utmost importance. This is due to the wide range of security critical applications from smart cards, battery operated IoT devices, to accelerated crypto-processors. Such applications have different requirements (higher speed, energy efficiency, low latency, small area etc.) and hence need different implementation techniques. Although, many TI strategies and implementation techniques are known for different ciphers, there is no single study comparing these on a single cipher. Such a study would allow a fair comparison of the various methodologies. In this work, we present an in-depth analysis of the various ways in which TI can be implemented for a lightweight cipher. We chose GIFT for our analysis as it is currently one of the most energy-efficient lightweight ciphers. The experimental results show that different implementation techniques have distinct applications. For example, the 4-shares technique is good for applications demanding high throughput whereas 3-shares is suitable for constrained environments with less area and moderate throughput requirements. The techniques presented in the paper are also applicable to other blockciphers. For security evaluation, we performed TVLA (test vector leakage assessment) on all the design strategies. Experiments using up to 50 million traces show that the designs are protected against first-order attacks.
Arpan Jati, Naina Gupta 0001, Anupam Chattopadhyay, Somitra Kumar Sanadhya, Donghoon Chang
IEEE Trans. Inf. Forensics Secur.5
2019 Generation of Secure and Reliable Honeywords, Preventing False Detection
abstract
Breach in password databases has been a frequent phenomena in the software industry. Often these breaches go undetected for years. Sometimes, even the companies involved are not aware of the breach. Even after they are detected, publicizing such attacks might not always be in the best interest of the companies. This calls for a strong breach detection mechanism. Juels et al. (in ACM-CCS 2013) suggest a method called ‘Honeywords’, for detecting password database breaches. Their idea is to generate multiple fake passwords, called honeywords and store them along with the real password. Any login attempt with honeywords is identified as a compromise of the password database, since legitimate users are not expected to know the honeywords corresponding to their passwords. The key components of their idea are (i) generation of honeywords, (ii) typo-safety measures for preventing false alarms, (iii) alarm policy upon detection, and (iv) testing robustness of the system against various attacks. In this work, we analyze the limitations of existing honeyword generation techniques. We propose a new attack model called ‘Multiple System Intersection attack considering Input’. We show that the ‘Paired Distance Protocol’ proposed by Chakraborty et al., is not secure in this attack model. We also propose new and more practical honeyword generation techniques and call them the ‘evolving-password model’, the ‘user-profile model’, and the ‘append-secret model’. These techniques achieve ‘approximate flatness’, implying that the honeywords generated using these techniques are indistinguishable from passwords with high probability. Our proposed techniques overcome most of the risks and limitations associated with existing techniques. We prove flatness of our ‘evolving-password model’ technique through experimental analysis. We provide a comparison of our proposed models with the existing ones under various attack models to justify our claims.
Akshima, Donghoon Chang, Aarushi Goel, Sweta Mishra, Somitra Kumar Sanadhya
IEEE Trans. Dependable Secur. Comput.2
2018 Revocable Identity-Based Encryption from Codes with Rank Metric
Donghoon Chang, Amit Kumar Chauhan, Sandeep Kumar 0002, Somitra Kumar Sanadhya
CT-RSA1
2018 RCB: leakage-resilient authenticated encryption via re-keying
Megha Agrawal, Tarun Kumar Bansal, Donghoon Chang, Amit Kumar Chauhan, Seokhie Hong, Jinkeon Kang, Somitra Kumar Sanadhya
J. Supercomput.3
2016 SPF: A New Family of Efficient Format-Preserving Encryption Algorithms
Donghoon Chang, Mohona Ghosh, Kishan Chand Gupta, Arpan Jati, Abhishek Kumar 0002, Dukjae Moon, Indranil Ghosh Ray, Somitra Kumar Sanadhya
Inscrypt1
2015 sp-AELM: Sponge Based Authenticated Encryption Scheme for Memory Constrained Devices
Megha Agrawal, Donghoon Chang, Somitra Kumar Sanadhya
ACISP2
2015 Sponge Based CCA2 Secure Asymmetric Encryption for Arbitrary Length Message
Tarun Kumar Bansal, Donghoon Chang, Somitra Kumar Sanadhya
ACISP2
2015 Biclique Cryptanalysis of Full Round AES-128 Based Hashing Modes
Donghoon Chang, Mohona Ghosh, Somitra Kumar Sanadhya
Inscrypt1
2015 PPAE: Practical Parazoa Authenticated Encryption Family
Donghoon Chang, Sumesh Manjunath Ramesh, Somitra Kumar Sanadhya
ProvSec1
2014 Collision Attack on 4-Branch, Type-2 GFN Based Hash Functions Using Sliced Biclique Cryptanalysis Technique
Megha Agrawal, Donghoon Chang, Mohona Ghosh, Somitra Kumar Sanadhya
Inscrypt2
2014 Rig: A Simple, Secure and Flexible Design for Password Hashing
Donghoon Chang, Arpan Jati, Sweta Mishra, Somitra Kumar Sanadhya
Inscrypt1
2011 On the Security of Hash Functions Employing Blockcipher Postprocessing
Donghoon Chang, Mridul Nandi, Moti Yung
FSE1
2008 Improved Indifferentiability Security Analysis of chopMD Hash Function
Donghoon Chang, Mridul Nandi
FSE1
2008 Second Preimage Attack on 3-Pass HAVAL and Partial Key-Recovery Attacks on HMAC/NMAC-3-Pass HAVAL
Eunjin Lee, Donghoon Chang, Jongsung Kim, Jaechul Sung, Seokhie Hong
FSE2
2007 Preimage Attack on the Parallel FFT-Hashing Function
Donghoon Chang, Moti Yung, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002
ACISP1
2006 Indifferentiable Security Analysis of Popular Hash Functions with Prefix-Free Padding
Donghoon Chang, Sangjin Lee 0002, Mridul Nandi, Moti Yung
ASIACRYPT1
2006 HIGHT: A New Block Cipher Suitable for Low-Resource Device
Deukjo Hong, Jaechul Sung, Seokhie Hong, Jongin Lim 0001, Sangjin Lee 0002, Bonseok Koo, Changhoon Lee, Donghoon Chang, Jesang Lee, Kitae Jeong, Jongsung Kim, Seongtaek Chee
CHES8
2006 A New Dedicated 256-Bit Hash Function: FORK-256
Deukjo Hong, Donghoon Chang, Jaechul Sung, Sangjin Lee 0002, Seokhie Hong, Jesang Lee, Dukjae Moon, Sungtaek Chee
FSE2
2004 Pseudorandomness of SPN-Type Transformations
Wonil Lee, Mridul Nandi, Palash Sarkar 0001, Donghoon Chang, Sangjin Lee 0002, Kouichi Sakurai
ACISP4
2003 New Parallel Domain Extenders for UOWHF
Wonil Lee, Donghoon Chang, Sangjin Lee 0002, Soo Hak Sung, Mridul Nandi
ASIACRYPT2