VLDB 2026 Research / reviewers in the wild / expert
Donghoon Chang
dblp:50/4733
· DBLP profile ↗
26ranked-venue papers
13as first author
5since 2021 · last 2026
0000-0003-1249-2869ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 12 first-author · 3 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CRYPTO (6) | 1 |
| 2024 | Lynx: Family of Lightweight Authenticated Encryption Schemes Based on Tweakable BlockcipherabstractThe widespread deployment of low-power and handheld devices opens an opportunity to design lightweight authenticated encryption schemes. The schemes so proposed must also prove their resilience under various security notions. Romulus-N1 is an authenticated encryption scheme with associated data based on a tweakable blockcipher, a primary variant of Romulus-N family which is National Institute of Standards and Technology (NIST) lightweight cryptography competition finalist; provides beyond birthday bound security for integrity security in nonce respecting scenario but fails to provide the integrity security in nonce misuse and release of unverified plaintext (RUP) scenarios. In this article, we propose lynx, a family with 14 members of 1-pass and rate-1 lightweight authenticated encryption schemes with associated data based on a tweakable blockcipher, that provides birthday bound security for integrity security in both nonce respecting as well as nonce misuse and RUP scenarios and birthday bound security for privacy in nonce respecting scenario. For creating such a family of schemes, we propose a family of functions called$\mathcal {F}$, that provides a total of 72 cases out of which we show that only 14 of them can be used for creating authenticated encryption schemes. We provide the implementation of one of the members of lynx family on four different hardware platforms and compare it with Romulus-N1. The comparison clearly shows that the lynx member outperforms Romulus-N1 on all the four platforms. Munawar Hasan, Donghoon Chang |
IEEE Internet Things J. | 2 |
| 2023 | A preimage attack on reduced GIMLI-HASH with unbalanced squeezing phaseabstractAbstract In Conference on Cryptographic Hardware and Embedded System 2017, Bernstein et al. proposed GIMLI , a 384‐bit permutation with 24 rounds, which aims to provide high performance on various platforms. In 2019, the full‐round (24 rounds) GIMLI permutation was used as an underlying primitive for building AEAD GIMLI‐CIPHER and hash function GIMLI‐HASH , which were submitted to the NIST Lightweight Cryptography Standardisation process and selected as one of the second‐round candidates. In Transactions on Symmetric Cryptology 2021, Liu et al. presented a preimage attack with a divide‐and‐conquer method on round‐reduced GIMLI‐HASH , which uses 5‐round GIMLI . In this paper, preimage attacks on a round‐reduced variant of GIMLI‐HASH is presented, in which the message absorbing phase uses 5‐round GIMLI and the squeezing phase uses 9‐round GIMLI . This variant is called as 5–9‐round GIMLI‐HASH . The authors’ preimage attack on 5–9‐round GIMLI‐HASH requires 2 96.44 time complexity and 2 97 memory complexity. Also, this method can be reached up to round shifted 10‐round GIMLI in the squeezing phase. The authors’ first attack requires the memory for storing several precomputation tables in GIMLI SP‐box operations. In the authors’ second attack, a time‐memory trade‐off approach is taken, reducing memory requirements for precomputation tables but increasing computing time for solving SP‐box equations by using SAT solver. This attack requires 2 66.17 memory complexity and 2 96+ ϵ time complexity, where ϵ is a time complexity for solving SP‐box equations. The authors’ experiments using CryptoMiniSat SAT solver show that the maximum time complexity for ϵ is about 2 20.57 9‐round GIMLI . Yongseong Lee, Jinkeon Kang, Donghoon Chang, Seokhie Hong |
IET Inf. Secur. | 3 |
| 2022 | On Security of Fuzzy Commitment Scheme for Biometric Authentication
Donghoon Chang, Surabhi Garg, Munawar Hasan, Sweta Mishra |
ACISP | 1 |
| 2021 | BIOFUSE: A framework for multi-biometric fusion on biocryptosystem level
Donghoon Chang, Surabhi Garg, Mohona Ghosh, Munawar Hasan |
Inf. Sci. | 1 |
| 2020 | Cancelable Multi-Biometric Approach Using Fuzzy Extractor and Novel Bit-Wise EncryptionabstractThe widespread deployment of multi-biometrics to authenticate users prompts the need for biometric systems with high recognition performance. Further, the biometric data, once leaked or stolen, remains compromised forever. Hence biometric security is of utmost importance. Existing biometric template protection schemes either degrade the recognition performance or they have issues with security and speed. We propose a cancelable multi-biometric authentication approach where a novel bit-wise encryption scheme transforms a biometric template to a protected template using a secret key generated from another biometric template. It fully preserves the number of bit-errors in the original and the protected template to ensure recognition performance equivalent to the performance of the unprotected systems. We introduce Algorithm I and Algorithm II for bit-wise encryption; both are defined over cryptographic-primitives- block cipher based encryption and keyed-hash function. We profile these algorithms on various hardware architectures to calculate the efficiency in terms of the time taken during enrolment and authentication phase. For Algorithm II, we observe that a 3.3 GHz desktop architecture takes about 18 milliseconds on an average of over 200 runs to authenticate a user. Additionally, we provide mathematical proof to show that the proposed scheme guarantees secrecy and irreversibility. The results of comparisons with the existing biometric template protection schemes on the various face and iris databases show that the proposed work provides significantly good recognition performance and efficiency, while it achieves high security. Finally, the bit-wise encryption scheme can be built over the commercial-off-the-shelf systems to achieve security with equivalent high performance. Donghoon Chang, Surabhi Garg, Munawar Hasan, Sweta Mishra |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Threshold Implementations of <tt>GIFT</tt>: A Trade-Off AnalysisabstractThreshold Implementation (TI) is one of the most widely used countermeasure for side channel attacks. Over the years several TI techniques have been proposed for randomizing cipher execution using different variations of secret-sharing and implementation techniques. For instance, sharing without decomposition (4-shares) is the most straightforward implementation of the threshold countermeasure. However, its usage is limited due to its high area requirements. On the other hand, sharing using decomposition (3-shares) countermeasure for cubic non-linear functions significantly reduces area and complexity in comparison to 4-shares. Nowadays, security of ciphers using a side channel countermeasure is of utmost importance. This is due to the wide range of security critical applications from smart cards, battery operated IoT devices, to accelerated crypto-processors. Such applications have different requirements (higher speed, energy efficiency, low latency, small area etc.) and hence need different implementation techniques. Although, many TI strategies and implementation techniques are known for different ciphers, there is no single study comparing these on a single cipher. Such a study would allow a fair comparison of the various methodologies. In this work, we present an in-depth analysis of the various ways in which TI can be implemented for a lightweight cipher. We chose GIFT for our analysis as it is currently one of the most energy-efficient lightweight ciphers. The experimental results show that different implementation techniques have distinct applications. For example, the 4-shares technique is good for applications demanding high throughput whereas 3-shares is suitable for constrained environments with less area and moderate throughput requirements. The techniques presented in the paper are also applicable to other blockciphers. For security evaluation, we performed TVLA (test vector leakage assessment) on all the design strategies. Experiments using up to 50 million traces show that the designs are protected against first-order attacks. Arpan Jati, Naina Gupta 0001, Anupam Chattopadhyay, Somitra Kumar Sanadhya, Donghoon Chang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Generation of Secure and Reliable Honeywords, Preventing False DetectionabstractBreach in password databases has been a frequent phenomena in the software industry. Often these breaches go undetected for years. Sometimes, even the companies involved are not aware of the breach. Even after they are detected, publicizing such attacks might not always be in the best interest of the companies. This calls for a strong breach detection mechanism. Juels et al. (in ACM-CCS 2013) suggest a method called ‘Honeywords’, for detecting password database breaches. Their idea is to generate multiple fake passwords, called honeywords and store them along with the real password. Any login attempt with honeywords is identified as a compromise of the password database, since legitimate users are not expected to know the honeywords corresponding to their passwords. The key components of their idea are (i) generation of honeywords, (ii) typo-safety measures for preventing false alarms, (iii) alarm policy upon detection, and (iv) testing robustness of the system against various attacks. In this work, we analyze the limitations of existing honeyword generation techniques. We propose a new attack model called ‘Multiple System Intersection attack considering Input’. We show that the ‘Paired Distance Protocol’ proposed by Chakraborty et al., is not secure in this attack model. We also propose new and more practical honeyword generation techniques and call them the ‘evolving-password model’, the ‘user-profile model’, and the ‘append-secret model’. These techniques achieve ‘approximate flatness’, implying that the honeywords generated using these techniques are indistinguishable from passwords with high probability. Our proposed techniques overcome most of the risks and limitations associated with existing techniques. We prove flatness of our ‘evolving-password model’ technique through experimental analysis. We provide a comparison of our proposed models with the existing ones under various attack models to justify our claims. Akshima, Donghoon Chang, Aarushi Goel, Sweta Mishra, Somitra Kumar Sanadhya |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Revocable Identity-Based Encryption from Codes with Rank Metric
Donghoon Chang, Amit Kumar Chauhan, Sandeep Kumar 0002, Somitra Kumar Sanadhya |
CT-RSA | 1 |
| 2018 | RCB: leakage-resilient authenticated encryption via re-keying
Megha Agrawal, Tarun Kumar Bansal, Donghoon Chang, Amit Kumar Chauhan, Seokhie Hong, Jinkeon Kang, Somitra Kumar Sanadhya |
J. Supercomput. | 3 |
| 2016 | SPF: A New Family of Efficient Format-Preserving Encryption Algorithms
Donghoon Chang, Mohona Ghosh, Kishan Chand Gupta, Arpan Jati, Abhishek Kumar 0002, Dukjae Moon, Indranil Ghosh Ray, Somitra Kumar Sanadhya |
Inscrypt | 1 |
| 2015 | sp-AELM: Sponge Based Authenticated Encryption Scheme for Memory Constrained Devices
Megha Agrawal, Donghoon Chang, Somitra Kumar Sanadhya |
ACISP | 2 |
| 2015 | Sponge Based CCA2 Secure Asymmetric Encryption for Arbitrary Length Message
Tarun Kumar Bansal, Donghoon Chang, Somitra Kumar Sanadhya |
ACISP | 2 |
| 2015 | Biclique Cryptanalysis of Full Round AES-128 Based Hashing Modes
Donghoon Chang, Mohona Ghosh, Somitra Kumar Sanadhya |
Inscrypt | 1 |
| 2015 | PPAE: Practical Parazoa Authenticated Encryption Family
Donghoon Chang, Sumesh Manjunath Ramesh, Somitra Kumar Sanadhya |
ProvSec | 1 |
| 2014 | Collision Attack on 4-Branch, Type-2 GFN Based Hash Functions Using Sliced Biclique Cryptanalysis Technique
Megha Agrawal, Donghoon Chang, Mohona Ghosh, Somitra Kumar Sanadhya |
Inscrypt | 2 |
| 2014 | Rig: A Simple, Secure and Flexible Design for Password Hashing
Donghoon Chang, Arpan Jati, Sweta Mishra, Somitra Kumar Sanadhya |
Inscrypt | 1 |
| 2011 | On the Security of Hash Functions Employing Blockcipher Postprocessing
Donghoon Chang, Mridul Nandi, Moti Yung |
FSE | 1 |
| 2008 | Improved Indifferentiability Security Analysis of chopMD Hash Function
Donghoon Chang, Mridul Nandi |
FSE | 1 |
| 2008 | Second Preimage Attack on 3-Pass HAVAL and Partial Key-Recovery Attacks on HMAC/NMAC-3-Pass HAVAL
Eunjin Lee, Donghoon Chang, Jongsung Kim, Jaechul Sung, Seokhie Hong |
FSE | 2 |
| 2007 | Preimage Attack on the Parallel FFT-Hashing Function
Donghoon Chang, Moti Yung, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002 |
ACISP | 1 |
| 2006 | Indifferentiable Security Analysis of Popular Hash Functions with Prefix-Free Padding
Donghoon Chang, Sangjin Lee 0002, Mridul Nandi, Moti Yung |
ASIACRYPT | 1 |
| 2006 | HIGHT: A New Block Cipher Suitable for Low-Resource Device
Deukjo Hong, Jaechul Sung, Seokhie Hong, Jongin Lim 0001, Sangjin Lee 0002, Bonseok Koo, Changhoon Lee, Donghoon Chang, Jesang Lee, Kitae Jeong, Jongsung Kim, Seongtaek Chee |
CHES | 8 |
| 2006 | A New Dedicated 256-Bit Hash Function: FORK-256
Deukjo Hong, Donghoon Chang, Jaechul Sung, Sangjin Lee 0002, Seokhie Hong, Jesang Lee, Dukjae Moon, Sungtaek Chee |
FSE | 2 |
| 2004 | Pseudorandomness of SPN-Type Transformations
Wonil Lee, Mridul Nandi, Palash Sarkar 0001, Donghoon Chang, Sangjin Lee 0002, Kouichi Sakurai |
ACISP | 4 |
| 2003 | New Parallel Domain Extenders for UOWHF
Wonil Lee, Donghoon Chang, Sangjin Lee 0002, Soo Hak Sung, Mridul Nandi |
ASIACRYPT | 2 |