VLDB 2026 Research / reviewers in the wild / expert
Nobuyuki Sugio
dblp:92/4122
· DBLP profile ↗
7ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0001-7313-1755ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 7 first-author · 3 since 2021Theory of computation · 3 · 3 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Impossible Differential Attack on SAND-128
Nobuyuki Sugio |
CANS | 1 |
| 2024 | Bit-Based Evaluation of Lightweight Block Ciphers SLIM, LBC-IoT, and SLA by Mixed Integer Linear ProgrammingabstractMany lightweight block ciphers have been proposed for IoT devices that have limited resources. SLIM, LBC‐IoT, and SLA are lightweight block ciphers developed for IoT systems. The designer of SLIM presented a 7‐round differential distinguisher and an 11‐round linear trail using a heuristic method. We have comprehensively sought the longest distinguisher for linear cryptanalysis, zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack using the mixed integer linear Programming (MILP) on SLIM, LBC‐IoT, and SLA. The search led to discovery of a 16‐round linear trail on SLIM, which is 5‐round longer than the earlier result. We have also discovered 7‐, 7‐, and 9‐round distinguishers for zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack, which are new results for SLIM. We have revealed 9‐, 8‐, and 11‐round distinguishers on LBC‐IoT for zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack. We have presented full‐round distinguishers on SLA for integral attack using only two chosen plaintexts. We performed a key recovery attack on 16‐round SLIM with an experimental verification. This verification took 106 s with a success rate of 93%. Moreover, we present a key recovery attack on 19‐round SLIM using 16‐round linear trail with correlation 2 −15 : the necessary number of known plaintext–ciphertext pairs is 2 31 ; the time complexity is 2 64.4 encryptions; and the memory complexity is 2 38 bytes. Results show that this is the current best key recovery attack on SLIM. Because the recommended number of rounds is 32, SLIM is secure against linear cryptanalysis, as demonstrated herein. Nobuyuki Sugio |
IET Inf. Secur. | 1 |
| 2023 | Differential, Linear, and Meet-in-the-Middle Attacks on the Lightweight Block Cipher RBFKabstractRandomized butterfly architecture of fast Fourier transform for key cipher (RBFK) is the lightweight block cipher for Internet of things devices in an edge computing environment. Although the authors claimed that RBFK is secure against differential cryptanalysis, linear cryptanalysis, impossible differential attack, and zero correlation linear cryptanalysis, the details were not explained in the literature. Therefore, we have evaluated the security of RBFK by application of differential cryptanalysis, linear cryptanalysis, and meet‐in‐the‐middle (MITM) attack and have found that RBFK is not secure against these attacks. This paper introduces not only a distinguish attack but also key recovery attacks on full‐round RBFK. In the distinguish attack scenario, data for differential cryptanalysis are two, and the time complexity is one for an exclusive‐OR operation. In the key recovery attack scenario, the data for linear cryptanalysis are one pair of known plaintext–ciphertext. The time complexity is one operation for a linear sum. Data for an MITM attack are two. The time complexity is 2 48 encryptions; the memory complexity is 2 45 bytes. Because the vulnerabilities are identified in the round function and the key scheduling part, we propose some improvements for RBFK against these attacks. Nobuyuki Sugio |
IET Inf. Secur. | 1 |
| 2018 | Integral Cryptanalysis of Reduced-round KASUMIabstractIntegral cryptanalysis, which was introduced by Knudsen and Wagner, is one of the most powerful attacks on symmetric key ciphers. Attackers preliminarily search integral characteristics of a target cipher for the key-recovery attack. Todo proposed a novel technique named the division property to find them efficiently. In this paper, we apply this technique to the symmetric key block cipher KASUMI which was developed by modifying MISTY1. It has been used worldwide in the 3rd generation mobile communication networks. As a result, we found new 4.5-round characteristics of KASUMI for the first time. We show that 7-round KASUMI is attackable with 263data complexity and 263.3encryptions under the weak key conditions. Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko |
ISITA | 1 |
| 2016 | A Practical-time Attack on Reduced-round MISTY1
Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko, Kenichi Higuchi |
ICISSP | 1 |
| 2016 | Integral characteristics of MISTY2 derived by division property
Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko |
ISITA | 1 |
| 2014 | A new higher order differential of Camellia
Nobuyuki Sugio, Hiroshi Aono, Kimihiko Sekino, Toshinobu Kaneko |
ISITA | 1 |