Kazuhiko Minematsu

dblp:72/3032 · DBLP profile ↗
← Back
65ranked-venue papers
19as first author
27since 2021 · last 2026
0000-0002-3427-6772ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 59 · 19 first-author · 25 since 2021Systems, architecture and hardware · 3Theory of computation · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CRYPTO (6)4
2026 A Formal Security Proof of Masking - Reduction from Strong Noisy Leakage to Probing Model Without Random Probing and Application to LR Primitive
Rei Ueno, Akiko Inoue, Kazuhiko Minematsu, Akira Ito 0002, Naofumi Homma
CRYPTO (7)3
2026 Two-key variant of the four-round cascading sfLRW1
Shreya Dey, Avijit Dutta, Kazuhiko Minematsu
Des. Codes Cryptogr.3
2025 Generic Security of GCM-SST
Akiko Inoue, Ashwin Jha 0001, Bart Mennink, Kazuhiko Minematsu
ACNS (2)4
2025 Gravity of the Situation: Security Analysis on Rocket.Chat E2EE
abstract
Rocket.Chat is a group chat platform widely deployed in industries and national organizations, with over 15 million users across 150 countries. One of its main features is an end-to-end encryption (E2EE) protocol; however, no cryptographic security analysis has been conducted. We conduct an in-depth cryptographic analysis of Rocket.Chat's E2EE protocol and identify multiple significant flaws that allow a malicious server or even an outsider to break the confidentiality and integrity of the group chat. Specifically, we formally model and analyze the protocol using ProVerif under the Dolev-Yao model, uncovering multiple theoretical weaknesses and verifying that some of them lead to practical attacks. Furthermore, through meticulous manual analysis, we identify additional vulnerabilities, including implementation flaws and cryptographic weaknesses such as CBC malleability, and demonstrate how they are exploitable in practical attack scenarios. To validate our findings, we develop Proof-of-Concept implementations, highlighting the real-world feasibility of these attacks. We also propose mitigation techniques and discuss the implications of our attacks.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Takanori Isobe 0001
ACSAC3
2025 Cryptographic Treatment of Key Control Security - In Light of NIST SP 800-108
Ritam Bhaumik, Avijit Dutta, Akiko Inoue, Tetsu Iwata, Ashwin Jha 0001, Kazuhiko Minematsu, Mridul Nandi, Yu Sasaki 0001, Meltem Sönmez Turan, Stefano Tessaro
CRYPTO (5)6
2025 Comprehensive Robustness Analysis of GCM, CCM, and OCB3
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu
CT-RSA3
2025 Not in The Prophecies: Practical Attacks on Nostr
abstract
Distributed social networking services (SNSs) recently received significant attention as an alternative to traditional, centralized SNSs, which have inherent limitations on user privacy and freedom. We provide the first in-depth security analysis of Nostr, an open-source, distributed SNS protocol developed in 2019 with more than 1.1 million registered users. We investigate the specification of Nostr and the client implementations and present a number of practical attacks allowing forgeries on various objects, such as encrypted direct messages (DMs), by a malicious user or a malicious server. Even more, we show a confidentiality attack against encrypted DMs by a malicious user exploiting a flaw in the link preview mechanism and the CBC malleability. Our attacks are due to cryptographic flaws in the protocol specification and client implementation, some of which in combination elevate the forgery attack to a violation of confidentiality. We verify the practicality of our attacks via Proof-of-Concept implementations and discuss how to mitigate them.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Shogo Shiraki, Takanori Isobe 0001
EuroS&P3
2025 Lightweight Yet Nonce-Misuse Secure Authenticated Encryption for Very Short Inputs
abstract
We study authenticated encryption (AE) modes dedicated to very short messages, which are crucial for Internet of Things applications. One of the most popular class of AE is built on block ciphers, namely a mode of operation. The computational cost of a mode is typically measured by its rate, indicating the number of input blocks processed per block cipher call in asymptotic terms. While certain modes demonstrate efficiency in terms of rate, such as$\mathsf { OCB}$, this metric does not always accurately portray the total computational burden as it ignores overhead. Consequently, modes efficient in terms of rate may not always perform optimally with short messages. This observation motivates us to study modes that are efficient on short inputs rather than focusing on rate. Since the existing general-purpose AE modes need at least three block cipher calls for nonempty messages, we explore the design space for AE modes that use at most two calls. We propose a family of AE modes, dubbed$ \mathsf {Manx}$, which work when the total input length is less than$2n$bits, using an n-bit block cipher. Notably, the second construction of$ \mathsf {Manx}$can encrypt almost n-bit plaintexts and saves one or two block cipher calls compared to standard modes, such as$\mathsf { GCM}$or$\mathsf { OCB}$, while preserving comparable provable security. In addition to the conventional security against nonce-respecting adversary, we prove that$ \mathsf {Manx}$have security against nonce-misusing adversary with a different security level for each family member. We also present benchmarks on popular 8/32-bit microprocessors, namely 8-bit AVR, 32-bit ARM Cortex-M0, and ARM Cortex-M4, using AES and lightweight block ciphers. Our results show the clear advantage of$ \mathsf {Manx}$over the previous modes for such short messages. In particular,$ \mathsf {Manx2}$has significant performance gain from the existing representative schemes thanks to the simple structure and parallelizability. For example, using AES-128,$ \mathsf {Manx2}$is faster than$\mathsf { OCB}$by a factor of 1.5 to 1.7 to process a 64-bit nonce and a 120-bit plaintext.
Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata
IEEE Internet Things J.2
2025 Security analysis of SFrame
abstract
Increasing privacy consciousness has popularized the use of end-to-end encryption (E2EE). In this paper, we discuss the security of SFrame, an E2EE mechanism proposed to the Internet Engineering Task Force for video/audio group communications over the Internet. Despite being a quite recent project, SFrame has been deployed in several real-world applications. The original specification of SFrame is evaluated herein to find critical issues that can cause impersonation (forgery) attacks with a practical complexity by a malicious group member . Further investigations have revealed that these issues are present in several publicly available SFrame implementations. Therefore, we provide several countermeasures against all the proposed attacks and considerations from performance and security perspectives towards their implementation.
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
J. Inf. Secur. Appl.3
2024 Crystalor: Recoverable Memory Encryption Mechanism with Optimized Metadata Structure
Rei Ueno, Hiromichi Haneda, Naofumi Homma, Akiko Inoue, Kazuhiko Minematsu
CCS5
2024 Interactive aggregate message authentication equipped with detecting functionality from adaptive group testing
Kazuhiko Minematsu, Shingo Sato, Junji Shikata
Des. Codes Cryptogr.1
2023 Authenticated Encryption for Very Short Inputs
Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata
CT-RSA2
2023 XOCB: Beyond-Birthday-Bound Secure Authenticated Encryption Mode with Rate-One Computation
Zhenzhen Bao, Seongha Hwang, Akiko Inoue, ByeongHak Lee, Jooyoung Lee 0001, Kazuhiko Minematsu
EUROCRYPT (4)6
2023 Compactly Committing Authenticated Encryption Using Encryptment and Tweakable Block Cipher
Shoichi Hirose, Kazuhiko Minematsu
SAC2
2023 Tight lower bounds and optimal constructions of anonymous broadcast encryption and authentication
abstract
Abstract Broadcast Encryption (BE) is public-key encryption allowing a sender to encrypt a message by specifing recipients, and only the specified recipients can decrypt the message. In several BE applications, since the privacy of recipients allowed to access the message is often as important as the confidentiality of the message, anonymity is introduced as an additional but important security requirement for BE. Kiayias and Samari (IH 2013) presented an asymptotic lower bound on the ciphertext sizes in BE schemes satisfying anonymity (ANO-BE for short). More precisely, their lower bound is derived under the assumption that ANO-BE schemes have a special property. However, it is insufficient to show their lower bound is asymptotically tight since it is unclear whether existing ANO-BE schemes meet the special property. In this work, we derive asymptotically tight lower bounds on the ciphertext size in ANO-BE by assuming only properties that most existing ANO-BE schemes satisfy. With a similar technique, we first derive asymptoticallyPlease provide MSC codes. For more details, please visit http://www.ams.org/msc/. tight lower bounds on the authenticator sizes in Anonymous Broadcast Authentication (ABA). Furthermore, we extend the above result and present (non-asymptotically) tight lower and upper bounds on thePlease check and confirm the Running title. ciphertext sizes in ANO-BE. We show that a variant of ANO-BE scheme proposed by Li and Gong (ACNS 2018) is optimal. We also provide tight bounds on the authenticator sizes in ABA via the same approach as ANO-BE, and propose an optimal construction for ABA.
Hirokazu Kobayashi, Yohei Watanabe 0001, Kazuhiko Minematsu, Junji Shikata
Des. Codes Cryptogr.3
2023 Nonce-misuse resilience of Romulus-N and GIFT-COFB
abstract
Abstract Nonce‐misuse resilience (NMRL) security of Romulus‐N and GIFT‐COFB is analysed, the two finalists of NIST Lightweight Cryptography project for standardising lightweight authenticated encryption. NMRL, introduced by Ashur et al. at CRYPTO 2017, is a relaxed security notion from a stronger, nonce‐misuse resistance notion. The authors have proved that Romulus‐N and GIFT‐ COFB have nonce‐misuse resilience. For Romulus‐N, the perfect privacy (NMRL‐PRIV) and n /2‐bit authenticity (NMRL‐AUTH) with graceful degradation with respect to nonce repetition are showed. For GIFT‐COFB, n /4‐bit security for both NMRL‐PRIV and NMRL‐AUTH notions is showed.
Akiko Inoue, Chun Guo 0002, Kazuhiko Minematsu
IET Inf. Secur.3
2023 Cubicle: A family of space-hard ciphers for IoT
abstract
Abstract As IoT has increasingly evolved in recent years, it has become more important to ensure security on IoT devices. Many of such devices are under the threat of attacks in the beyond black‐box model. To protect from the threat, the cryptographic implementation that can offer secure execution in the grey‐/white‐box model is important. However, such cryptographic implementations require a large number of clock cycles to execute and cannot fully cover resistance against various types of side‐channel attacks. In this paper, a new family of table‐based cipher dubbed Cubicle is proposed, which can offer efficient execution and sufficient security against side‐channel attacks on IoT devices powered by ARM Cortex‐M processors, which are widely deployed in IoT applications. To evaluate the security of Cubicle in the grey‐box model, the authors derive the bound of table leakage in the grey‐box model by applying space hardness, which is the notion to evaluate the security against code lifting attacks in the white‐box. The security of Cubicle in the grey‐box model is shown by using this bound. In addition, the security of Cubicle is also shown in the black‐box and white‐box models. Finally, the performance of Cubicle and other ciphers in some devices powered by ARM Cortex‐M3, ‐M4, and ‐M7 processors is evaluated. The authors show that Cubicle is significantly efficient compared to other grey‐/white‐box‐ model‐secure ciphers in target experiments for IoT applications.
Rentaro Shiba, Ravi Anand, Kazuhiko Minematsu, Takanori Isobe 0001
IET Inf. Secur.3
2022 Fast Skinny-128 SIMD Implementations for Sequential Modes of Operation
Alexandre Adomnicai, Kazuhiko Minematsu, Maki Shigeri
ACISP2
2022 Analyzing the Provable Security Bounds of GIFT-COFB and Photon-Beetle
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu
ACNS3
2022 Efficient Word Size Modular Multiplication over Signed Integers
abstract
As an efficient multiplication method for polynomial rings, Number Theoretic Transform (NTT) is a fundamental algorithm that is both practically useful and theoretically established. Chung et al. proposed a method to perform NTT-based polynomial multiplication for NTT-unfriendly rings that do not have suitable primitive roots. They applied their proposal to lattice-based cryptography using NTT-unfriendly rings and speeded up several schemes. At ARITH 2021, Plantard proposed a modular multiplication algorithm that improves the speed of NTT if moduli are not large (a few dozen of bits), which is the case for typical lattice-based cryptography. It is natural to expect that Plantard's method improves Chung et al.‘s NTT when applied to them, however, this is not possible as Chung et al. requires the use of signed integers while Plantard's method assumes unsigned integers. A simple fix would cause a slowdown and a non-constant-time operation. To overcome this problem, we propose an efficient method for calculating the modular multiplication for signed integers based on Plantard's method. Our proposal generally incurs no overhead from the original and works in a constant-time fashion. To show the effectiveness of our proposal, we provide experimental implementation results on a lattice-based cryptographic scheme Saber. Currently, NIST is selecting candidates for standardization of post-quantum cryp-tography in preparation for the compromise of current public key cryptography by quantum computers, and has completed the selection of the final candidates. Saber is one of the finalists for the NIST standardization project,
Daichi Aoki, Kazuhiko Minematsu, Toshihiko Okamura, Tsuyoshi Takagi
ARITH2
2022 New indifferentiability security proof of MDPH hash function
abstract
Abstract MDPH is a double‐block‐length hash function proposed by Naito at Latincrypt 2019. This is a combination of Hirose's compression function and the domain extender called Merkle–Damgård with permutation. When instantiated with an n ‐bit block cipher, Naito proved that this achieves the (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security. In this paper, the authors first point out that the proof of the claim contains a gap, which is related to the definition of the simulator in simulating the decryption of the block cipher. The authors then show that the proof can be fixed. The authors introduce a new simulator that addresses the issue, showing that MDPH retains its (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security.
Chun Guo 0002, Tetsu Iwata, Kazuhiko Minematsu
IET Inf. Secur.3
2022 Matching attacks on Romulus-M
abstract
Abstract This paper considers a problem of identifying matching attacks against Romulus‐M, one of the 10 finalists of National Institute of Standards and Technology Lightweight Cryptography standardisation project. Romulus‐M is provably secure, that is, there is a theorem statement showing the upper bound on the success probability of attacking the scheme as a function of adversaries' resources. If there exists an attack that matches the provable security bound, then this implies that the attack is optimal and that the bound is tight in the sense that it cannot be improved. It is shown that the security bounds of Romulus‐M are tight for a large class of parameters by presenting concrete matching attacks.
Makoto Habu, Kazuhiko Minematsu, Tetsu Iwata
IET Inf. Secur.2
2022 Integral and impossible-differential attacks on the reduced-round Lesamnta-LW-BC
abstract
Abstract Lesamnta‐LW‐BC is the internal block cipher of the Lesamnta‐LW lightweight hash function, specified in ISO/IEC 29192‐5:2016. It is based on the unbalanced Feistel network and Advanced Encryption Standard round function. In this study, the security of Lesamnta‐LW‐BC against integral and impossible‐differential attacks is evaluated. Specifically, the authors searched for the integral distinguishers and impossible differentials with Mixed‐Integer Linear Programming‐based methods. As a result, the discovered impossible differential can reach up to 21 rounds, while three integral distinguishers reaching 18, 19 and 25 rounds are obtained, respectively. Moreover, it is also feasible to construct a 47‐round integral distinguisher in the known‐key setting. Finally, a 20‐round key‐recovery attack is proposed based on the discovered 18‐round integral distinguisher and a 19‐round key‐recovery attack using a 17‐round impossible differential. To the best of the authors' knowledge, this is the first third‐party cryptanalysis of Lesamnta‐LW‐BC.
Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Kazuhiko Minematsu, Takanori Isobe 0001
IET Inf. Secur.4
2022 ELM: A Low-Latency and Scalable Memory Encryption Scheme
abstract
Memory encryption (ME) with authentication is becoming a key security feature of modern processors, as evident by the adoption of ME by Intel’s SGX. Recently ME is actively studied from the viewpoint of system architecture. This paper studies ME from the viewpoint of symmetric-key cryptographic designs, with a primal focus on latency. A significant progress in such a direction can be observed in the SGX Integrity Tree (SIT). Using a variant of AES-GCM, SIT achieves an excellent latency. However, it has a scalability issue. By carefully examining SIT, we develop a new ME scheme dubbed ELM. We present an AES-based instantiation of ELM, and show that ELM significantly reduces latency from SIT for large memories, and achieves the provable security and equivalent hardware-protected (on-chip) area. We also present preliminary hardware implementations to substantiate our advantages.
Akiko Inoue, Kazuhiko Minematsu, Maya Oda, Rei Ueno, Naofumi Homma
IEEE Trans. Inf. Forensics Secur.2
2021 Security Analysis of SFrame
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
ESORICS (2)3
2021 Parallel Verification of Serial MAC and AE Modes
Kazuhiko Minematsu, Akiko Inoue, Katsuya Moriwaki, Maki Shigeri, Hiroyasu Kubo
SAC1
2020 ACE in Chains: How Risky Is CBC Encryption of Binary Executable Files?
Rintaro Fujita, Takanori Isobe 0001, Kazuhiko Minematsu
ACNS (1)3
2020 PMAC++: Incremental MAC Scheme Adaptable to Lightweight Block Ciphers
abstract
This paper presents a new incremental parallelizable message authentication code (MAC) scheme adaptable to lightweight block ciphers for memory integrity verification. The highlight of the proposed scheme is to achieve both incremental update capability and sufficient security bound with lightweight block ciphers, which is a novel feature. We extend the conventional parallelizable MAC to realize the incremental update capability while keeping the original security bound. We prove that a comparable security bound can be obtained even if this change is incorporated. We also present a hardware architecture for the proposed MAC scheme with lightweight block ciphers and demonstrate the effectiveness through FPGA implementation. The evaluation results indicate that the proposed MAC hardware achieves 3.4 times improvement in the latency-area product for the tag update compared with the conventional MAC.
Maya Oda, Rei Ueno, Akiko Inoue, Kazuhiko Minematsu, Naofumi Homma
ISCAS4
2020 WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri
SAC6
2020 Blockcipher-Based Authenticated Encryption: How Small Can We Go?
Avik Chakraborti, Tetsu Iwata, Kazuhiko Minematsu, Mridul Nandi
J. Cryptol.3
2020 Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering
J. Cryptol.3
2019 Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering
CRYPTO (1)3
2019 Symmetric-Key Corruption Detection: When XOR-MACs Meet Combinatorial Group Testing
Kazuhiko Minematsu, Norifumi Kamiya
ESORICS (1)1
2019 High Throughput/Gate FN-Based Hardware Architectures for AES-OTR
abstract
This paper presents high throughput/gates Feistel network (FN)-based AES-OTR hardware architectures. AES-OTR is an authenticated encryption (AE) scheme as a block cipher mode of operation using AES. While AES-OTR is one of the most theoretically efficient AEs using AES and has superior features, its practical efficiency in hardware is unclear due to no known reports of its hardware implementation. In this paper, we present efficient AES-OTR hardware architectures. In contrast to conventional AE architectures, our architecture forms the 2-round FN of OTR, which makes it easy to integrate the peripheral into hardware for OTR operations. The proposed architectures had 2.4 and 13.5 times higher throughput/gates than the de facto standard AE (i.e., AES-GCM) core on FPGA and ASIC, respectively, through logic syntheses.
Rei Ueno, Naofumi Homma, Tomonori Iida, Kazuhiko Minematsu
ISCAS4
2019 Plaintext Recovery Attacks Against XTS Beyond Collisions
Takanori Isobe 0001, Kazuhiko Minematsu
SAC2
2019 Parallelizable Authenticated Encryption with Small State Size
Akiko Inoue, Kazuhiko Minematsu
SAC2
2019 A Lightweight Alternative to PMAC
Kazuhiko Minematsu
SAC1
2018 Count-then-Permute: A Precision-Free Alternative to Inversion Sampling
Kazuhiko Minematsu, Kentarou Sasaki
CT-RSA1
2018 Breaking Message Integrity of an End-to-End Encryption Scheme of LINE
Takanori Isobe 0001, Kazuhiko Minematsu
ESORICS (2)2
2018 Connecting tweakable and multi-key blockcipher security
abstract
The significance of understanding blockcipher security in the multi-key setting is highlighted by the extensive literature on attacks, and how effective key size can be significantly reduced. Nevertheless, little attention has been paid in formally understanding the design of multi-key secure blockciphers. In this work, we formalize the multi-key security of tweakable blockciphers in case of general key derivation functions. We show an equivalence between blockcipher multi-key security and tweakable blockcipher security. Our equivalence connects two objects of study, the iterated Even–Mansour (EUROCRYPT 2012) and the iterated Tweakable Even–Mansour (CRYPTO 2015), which establishes that results in both areas are, to a certain extent, transferable. Using our novel equivalence relation, we derive new bounds for both constructions, pave the path towards the solution of two well-studied conjectures, and show that, contrary to common knowledge, key derivation functions need not necessarily be pseudorandom functions in order to provide security: for the iterated Even–Mansour universal hash functions suffice.
Jooyoung Lee 0001, Atul Luykx, Bart Mennink, Kazuhiko Minematsu
Des. Codes Cryptogr.4
2017 Blockcipher-Based Authenticated Encryption: How Small Can We Go?
Avik Chakraborti, Tetsu Iwata, Kazuhiko Minematsu, Mridul Nandi
CHES3
2017 ZMAC: A Fast Tweakable Block Cipher Mode for Highly Secure Message Authentication
Tetsu Iwata, Kazuhiko Minematsu, Thomas Peyrin, Yannick Seurin
CRYPTO (3)2
2016 Authenticated Encryption with Small Stretch (or, How to Accelerate AERO)
Kazuhiko Minematsu
ACISP (2)1
2016 Integrity Analysis of Authenticated Encryption Based on Stream Ciphers
Kazuya Imamura, Kazuhiko Minematsu, Tetsu Iwata
ProvSec2
2015 Efficient Message Authentication Codes with Combinatorial Group Testing
abstract
Message authentication code, MAC for short, is a symmetric-key cryptographic function for authenticity. A standard MAC verification only tells whether the message is valid or invalid, and thus we can not identify which part is corrupted in case of invalid message. In this paper we study a class of MAC functions that enables to identify the part of corruption, which we call group testing MAC (GTM). This can be seen as an application of a classical (non-adaptive) combinatorial group testing to MAC. Although the basic concept of GTM (or its keyless variant) has been proposed in various application areas, such as data forensics and computer virus testing, they rather treat the underlying MAC function as a black box, and exact computation cost for GTM seems to be overlooked. In this paper, we study the computational aspect of GTM, and show that a simple yet non-trivial extension of parallelizable MAC (PMAC) enables $$O(m+t)$$ computation for m data items and t tests, irrespective of the underlying test matrix we use, under a natural security model. This greatly improves efficiency from naively applying a black-box MAC for each test, which requires O(mt) time. Based on existing group testing methods, we also present experimental results of our proposal and observe that ours runs as fast as taking single MAC tag, with speed-up from the conventional method by factor around 8 to 15 for $$m=10^4$$ to $$10^5$$ items.
Kazuhiko Minematsu
ESORICS (1)1
2015 GCM Security Bounds Reconsidered
Yuichi Niwa, Keisuke Ohashi, Kazuhiko Minematsu, Tetsu Iwata
FSE3
2015 Tweak-Length Extension for Tweakable Blockciphers
Kazuhiko Minematsu, Tetsu Iwata
IMACC1
2015 Building blockcipher from small-block tweakable blockcipher
Kazuhiko Minematsu
Des. Codes Cryptogr.1
2014 A smaller and faster variant of RSM
abstract
Masking is one of the major countermeasures against side-channel attacks to cryptographic modules. Nassar et al. recently proposed a highly efficient masking method, called Rotating S-boxes Masking (RSM), which can be applied to a block cipher based on Substitution-Permutation Network. It arranges multiple masked S-boxes in parallel, which are rotated in each round. This rotation requires remasking process for each round to adjust current masks to those of the S-boxes. In this paper, we propose a method for reducing the complexity of RSM further by omitting the remasking process when the linear diffusion layer of the encryption algorithm has a certain algebraic property. Our method can be applied to AES with a reduced complexity from RSM, while keeping the equivalent security level.
Noritaka Yamashita, Kazuhiko Minematsu, Toshihiko Okamura, Yukiyasu Tsunoo
DATE2
2014 Parallelizable Rate-1 Authenticated Encryption from Pseudorandom Functions
Kazuhiko Minematsu
EUROCRYPT1
2014 CLOC: Authenticated Encryption for Short Input
Tetsu Iwata, Kazuhiko Minematsu, Jian Guo 0001, Sumio Morioka
FSE2
2013 Attacks and Security Proofs of EAX-Prime
Kazuhiko Minematsu, Stefan Lucks, Hiraku Morita, Tetsu Iwata
FSE1
2013 A Short Universal Hash Function from Bit Rotation, and Applications to Blockcipher Modes
Kazuhiko Minematsu
ProvSec1
2013 Improved Authenticity Bound of EAX, and Refinements
Kazuhiko Minematsu, Stefan Lucks, Tetsu Iwata
ProvSec1
2012 Breaking and Repairing GCM Security Proofs
Tetsu Iwata, Keisuke Ohashi, Kazuhiko Minematsu
CRYPTO3
2012 $\textnormal{\textsc{TWINE}}$ : A Lightweight Block Cipher for Multiple Platforms
Tomoyasu Suzaki, Kazuhiko Minematsu, Sumio Morioka, Eita Kobayashi
Selected Areas in Cryptography2
2011 On Maximum Differential Probability of Generalized Feistel
Kazuhiko Minematsu, Tomoyasu Suzaki, Maki Shigeri
ACISP1
2011 Building Blockcipher from Tweakable Blockcipher: Extending FSE 2009 Proposal
Kazuhiko Minematsu, Tetsu Iwata
IMACC1
2010 How to Thwart Birthday Attacks against MACs via Small Randomness
Kazuhiko Minematsu
FSE1
2010 Improving the Generalized Feistel
Tomoyasu Suzaki, Kazuhiko Minematsu
FSE2
2009 Beyond-Birthday-Bound Security Based on Tweakable Block Cipher
Kazuhiko Minematsu
FSE1
2007 New Bounds for PMAC, TMAC, and XCBC
Kazuhiko Minematsu, Toshiyasu Matsushima
FSE1
2006 Provably Secure MACs from Differentially-Uniform Permutations and AES-Based Implementations
Kazuhiko Minematsu, Yukiyasu Tsunoo
FSE1
2005 Shorter bit sequence is enough to break stream cipher LILI-128
abstract
LILI-128 is the stream cipher proposed as a candidate cipher for the New European Schemes for Signatures, Integrity, and Encryption (NESSIE) Project. Some methods of breaking it more efficiently than an exhaustive search for its secret key have been found already. The authors propose a new method, which uses shorter bit sequence to break LILI-128 successfully. An attack that can be made with less data can be a more practical threat. With only 2/sup 7/ bits of keystream, this method can break LILI-128 successfully. The efficiency of our attack depends on the memory size. For example, with 2/sup 99.1/ computations, our attack breaks LILI-128, if 2/sup 28.6/-bit memory is available.
Yukiyasu Tsunoo, Teruo Saito, Maki Shigeri, Hiroyasu Kubo, Kazuhiko Minematsu
IEEE Trans. Inf. Theory5