Vincent Rijmen

dblp:r/VincentRijmen · DBLP profile ↗
← Back
95ranked-venue papers
11as first author
8since 2021 · last 2023
0000-0001-7401-2088ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 81 · 10 first-author · 6 since 2021Theory of computation · 7 · 1 first-author · 1 since 2021Systems, architecture and hardware · 3Databases, data management, data science and information retrieval · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2023 An Optimal Universal Construction for the Threshold Implementation of Bijective S-Boxes
abstract
Threshold implementation is a method based on secret sharing to secure cryptographic ciphers (and in particular S-boxes) against differential power analysis side-channel attacks which was proposed by Nikova, Rechberger, and Rijmen in 2006. Until now, threshold implementations were only constructed for specific types of functions and some small S-boxes, but no generic construction was ever presented. In this paper, we present the first universal threshold implementation with$t+2$shares that is applicable to any bijective S-box, where$t$is its algebraic degree (or is larger than the algebraic degree). While being universal, our construction is also optimal with respect to the number of shares, since the theoretically smallest possible number,$t+1$, is not attainable for some bijective S-boxes. Our results enable low latency secure hardware implementations without the need for additional randomness. In particular, we apply this result to find two uniform sharings of the AES S-box. The first sharing is obtained by using the threshold implementation of the inversion in$\mathbb {F}_{2^{8}}$and the second by using two threshold implementations of two cubic power permutations that decompose the inversion. Area and performance figures for hardware implementations are provided.
Enrico Piccione, Samuele Andreoli, Lilya Budaghyan, Claude Carlet, Siemen Dhooghe, Svetla Nikova, George Petrides, Vincent Rijmen
IEEE Trans. Inf. Theory8
2022 Guarding the First Order: The Rise of AES Maskings
Amund Askeland, Siemen Dhooghe, Svetla Nikova, Vincent Rijmen, Zhenda Zhang
CARDIS4
2022 Differential Cryptanalysis in the Fixed-Key Model
Tim Beyne, Vincent Rijmen
CRYPTO (3)2
2022 WARX: efficient white-box block cipher based on ARX primitives and random MDS matrix
Jun Liu 0099, Vincent Rijmen, Yupu Hu, Jie Chen 0055, Baocang Wang
Sci. China Inf. Sci.2
2022 A bit-vector differential model for the modular addition by a constant and its applications to differential and impossible-differential cryptanalysis
Seyyed Arash Azimi, Adrián Ranea, Mahmoud Salmasizadeh, Javad Mohajeri, Mohammad Reza Aref, Vincent Rijmen
Des. Codes Cryptogr.6
2022 Characteristic automated search of cryptographic algorithms for distinguishing attacks (CASCADA)
abstract
Abstract Automated search methods based on Satisfiability Modulo Theory (SMT) problems are being widely used to evaluate the security of block ciphers against distinguishing attacks. While these methods provide a systematic and generic methodology, most of their software implementations are limited to a small set of ciphers and attacks, and extending these implementations requires significant effort and expertise. In this work, the authors present cryptographic algorithms for distinguishing attacks ( CASCADA ), an open‐source Python library to evaluate the security of cryptographic primitives, specially block ciphers, against distinguishing attacks with bit‐vector SMT solvers. The tool CASCADA implements the bit‐vector property framework herein proposed and several SMT‐based automated search methods to evaluate the security of ciphers against differential, related‐key differential, rotational‐XOR, impossible‐differential, impossible‐rotational‐XOR, related‐key impossible‐differential, linear and zero‐correlation cryptanalysis. The library CASCADA is the result of a huge engineering effort, and it provides many functionalities, a modular design, an extensive documentation and a complete suite of tests.
Adrián Ranea, Vincent Rijmen
IET Inf. Secur.2
2021 Proposing an MILP-based method for the experimental verification of difference-based trails: application to SPECK, SIMECK
Sadegh Sadeghi, Vincent Rijmen, Nasour Bagheri
Des. Codes Cryptogr.2
2021 Editorial
Vincent Rijmen
J. Cryptol.1
2020 Rotational Cryptanalysis on MAC Algorithm Chaskey
Liliya Kraleva, Tomer Ashur, Vincent Rijmen
ACNS (1)3
2020 A Bit-Vector Differential Model for the Modular Addition by a Constant
Seyyed Arash Azimi, Adrián Ranea, Mahmoud Salmasizadeh, Javad Mohajeri, Mohammad Reza Aref, Vincent Rijmen
ASIACRYPT (1)6
2020 The phantom of differential characteristics
Yunwen Liu, Wenying Zhang 0001, Bing Sun 0001, Vincent Rijmen, Chao Li 0002, Shaojing Fu, Meichun Cao
Des. Codes Cryptogr.4
2020 Revisiting the Wrong-Key-Randomization Hypothesis
Tomer Ashur, Tim Beyne, Vincent Rijmen
J. Cryptol.3
2019 TIS'19: Theory of Implementation Security Workshop 2019
abstract
In this workshop, we focus on physical attacks and their countermeasures. With the advent of the Internet of Things, the interest in embedded cryptographic systems and physical attacks on these systems is steadily increasing, both in academia and industry. Sophisticated security certification and evaluation methods have been established to give assurance about the security claims by independent evaluation and testing. The certification has a drawback that it is time consuming and expensive. There is a need for further developing provably secure protection methods and automated verification tools, but also improving the efficiency and quality of certification by integrating these tools and methods. All these challenges motivate even more research on the Theory of Implementation Security.
Begül Bilgin, Svetla Nikova, Vincent Rijmen
CCS3
2019 Division cryptanalysis of block ciphers with a binary diffusion layer
abstract
In this study, the authors propose an accurate approach to model the propagation of the division property of linear layers by the smallest amount of inequalities. The solutions of the inequalities are exactly the division trails of a linear transformation. Therefore, the description is compact and optimal. As applications of their results, they present a 7‐round integral distinguisher for both Midori64 and Midori128. The designers of Midori only obtained a 3.5‐round integral characteristic. For Skinny64, they find a 10‐round integral distinguisher which was previously found by the designers. It is well to remind that their result proves that 7 rounds and 10 rounds are the upper bounds of Midori and Skinny64 correspondingly when searching for integral distinguishers based on division property. The significance of their result lies in that they shed light on how far division cryptanalysis can influence the security analysis of block ciphers with a binary diffusion layer, and their technique can be used to prove security against division cryptanalysis.
Wenying Zhang 0001, Vincent Rijmen
IET Inf. Secur.2
2019 A new matrix form to generate all 3 × 3 involutory MDS matrices over F2m
Gülsüm Gözde Yilmazgüç, Muharrem Tolga Sakalli 0001, Sedat Akleylek, Vincent Rijmen, Yasemin Cengellenmis
Inf. Process. Lett.4
2018 Guards in Action: First-Order SCA Secure Implementations of Ketje Without Additional Randomness
abstract
Recently the CAESAR competition has announced several finalists among the submitted authenticated encryption algorithms, after an open selection process during the last 5 years. Applications using these algorithms are rapidly increasing today. Devices implementing these applications are enormously susceptible to physical attacks, which are able to retrieve secret data through side-channel information such as the power consumption or the electromagnetic radiations. In this work we present a Side-Channel Analysis resistant hardware implementation of the whole family of authenticated encryption schemes Ketje. By changing just one parameter, any of the Ketje designs can be obtained, and tailored for different applications, either lightweight or high throughput. We introduce a new protected Keccak implementation, as well as unprotected and protected Ketje implementations, which allow both encryption and decryption modes in the same module. In order to secure these implementations we make use of the masking scheme known as Threshold Implementations and complement it with the technique of "Changing of the Guards", achieving a first-order Side-Channel Analysis protected implementation with zero extra randomness needed. This way, no dedicated PRNG needs to be additionally implemented, avoiding issues such as the security of the PRNG itself or the quality of the randomness.
Victor Arribas, Svetla Nikova, Vincent Rijmen
DSD3
2018 Impossible meet-in-the-middle fault analysis on the LED lightweight cipher in VANETs
Wei Li 0013, Vincent Rijmen, Qingju Wang 0001, Hua Chen 0011, Yunwen Liu, Chaoyun Li, Ya Liu 0001
Sci. China Inf. Sci.2
2018 Nonlinear diffusion layers
Yunwen Liu, Vincent Rijmen, Gregor Leander
Des. Codes Cryptogr.2
2018 Generalisation of Hadamard matrix to generate involutory MDS matrices for lightweight cryptography
abstract
In this study, the authors generalise Hadamard matrix over and propose a new form of Hadamard matrix, which they call generalised Hadamard (GHadamard) matrix. Then, they focus on generating lightweight (involutory) maximum distance separable (MDS) matrices. They also extend this idea to any matrix form, where k is not necessarily a power of 2. The new matrix form, GHadamard matrix, is used to generate new involutory MDS matrices over and , and involutory/non‐involutory MDS matrices over by considering the minimum exclusive OR (XOR) count, which is a metric defined to estimate the hardware implementation cost. In this context, they improve the best‐known results of XOR counts for involutory/non‐involutory MDS matrices over .
Meltem Kurt, Muharrem Tolga Sakalli 0001, Sedat Akleylek, Nevcihan Duru, Vincent Rijmen
IET Inf. Secur.5
2018 New observations on invariant subspace attack
Yunwen Liu, Vincent Rijmen
Inf. Process. Lett.2
2017 A new counting method to bound the number of active S-boxes in Rijndael and 3D
Mahdi Sajadieh, Arash Mirzaei, Hamid Mala, Vincent Rijmen
Des. Codes Cryptogr.4
2017 Efficient methods to generate cryptographically significant binary diffusion layers
abstract
In this study, the authors propose new methods using a divide‐and‐conquer strategy to generate n × n binary matrices (for composite n ) with a high/maximum branch number and the same Hamming weight in each row and column. They introduce new types of binary matrices: namely, ( BHwC ) t , m and ( BCwC ) q , m types, which are a combination of Hadamard and circulant matrices, and the recursive use of circulant matrices, respectively. With the help of these hybrid structures, the search space to generate a binary matrix with a high/maximum branch number is drastically reduced. By using the proposed methods, they focus on generating 12 × 12, 16 × 16 and 32 × 32 binary matrices with a maximum or maximum achievable branch number and the lowest implementation costs (to the best of their knowledge) to be used in block ciphers. Then, they discuss the implementation properties of binary matrices generated and present experimental results for binary matrices in these sizes. Finally, they apply the proposed methods to larger sizes, i.e. 48 × 48, 64 × 64 and 80 × 80 binary matrices having some applications in secure multi‐party computation and fully homomorphic encryption.
Sedat Akleylek, Vincent Rijmen, Muharrem Tolga Sakalli 0001, Emir Öztürk
IET Inf. Secur.2
2016 Automatic Search of Linear Trails in ARX with Applications to SPECK and Chaskey
Yunwen Liu, Qingju Wang 0001, Vincent Rijmen
ACNS3
2016 Theory of Implementation Security Workshop (TIs 2016)
abstract
The Internet of Things (IoT) enables a network of communication between people-to-people, people-to-things and things-to-things. The security of these communications against all possible attacks is a significant part of todays security and privacy. Due to the design nature of IoT systems, IoT devices are easily accessible by attackers which increases the importance of their security against physical attacks. This workshop is dedicated to research on the design of cryptographic algorithms and implementations secure against physical attacks.
Begül Bilgin, Svetla Nikova, Vincent Rijmen
CCS3
2016 Masking AES with d+1 Shares in Hardware
Thomas De Cnudde, Oscar Reparaz, Begül Bilgin, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
CHES6
2016 New Insights on AES-Like SPN Ciphers
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Longjiang Qu, Vincent Rijmen
CRYPTO (1)5
2016 Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Vincent Rijmen, Ruilin Li 0002
EUROCRYPT (1)4
2016 Improved Fault Analysis on SIMON Block Cipher Family
abstract
SIMON is a new family of lightweight block ciphers proposed by the National Security Agency (NSA) in 2013. Since its publication, it has attracted much research interest and a number of analysis results have been presented. As a popular kind of implementation attack method, the fault attack also works when it is applied to SIMON. In this paper, we propose an effective fault attack on SIMON under the random byte fault model. Compared with the previous attack results, our attack can successfully recover the whole master key with injecting the faults into only one intermediate round for six instances of SIMON. In our attack, we fully utilize a class of differential propagation properties of SIMON to determine the fault injection position as long as the full diffusion of the fault has not been obtained. On the basis of it, we can recover the last round key with the differential analysis technique. The differential propagation properties make it possible to inject the faults into the earlier intermediate round at the beginning than that of the previous attacks. Meanwhile, the same faulty ciphertext set can also help to recover other round keys. So we do not have to inject the faults into any other intermediate rounds to reveal the whole master key. Moreover, in this paper we also give a detailed mathematical analysis on the average number of the fault injections under the random byte fault model. The data complexity analysis shows that less fault injections are required in our attack compared with other work under the same attack model. Finally, we also verify the effectiveness and correctness of our attack with experiments.
Hua Chen 0011, Jingyi Feng, Vincent Rijmen, Yunwen Liu, Limin Fan, Wei Li 0013
FDTC3
2015 Links Among Impossible Differential, Integral and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Zhiqiang Liu 0001, Vincent Rijmen, Ruilin Li 0002, Qingju Wang 0001, Hoda Alkhzaimi, Chao Li 0002
CRYPTO (1)3
2015 A New Classification of 4-bit Optimal S-boxes and Its Application to PRESENT, RECTANGLE and SPONGENT
Zhenzhen Bao, Vincent Rijmen, Meicheng Liu
FSE3
2015 RECTANGLE: a bit-slice lightweight block cipher suitable for multiple platforms
Zhenzhen Bao, Dongdai Lin, Vincent Rijmen, Bohan Yang 0001, Ingrid Verbauwhede
Sci. China Inf. Sci.4
2015 The Rebound Attack and Subspace Distinguishers: Application to Whirlpool
Mario Lamberger, Florian Mendel, Martin Schläffer, Christian Rechberger, Vincent Rijmen
J. Cryptol.5
2015 Trade-Offs for Threshold Implementations Illustrated on AES
abstract
Embedded cryptographic devices are vulnerable to power analysis attacks. Threshold implementations (TIs) provide provable security against first-order power analysis attacks for hardware and software implementations. Like masking, the approach relies on secret sharing but it differs in the implementation of logic functions. While masking can fail to provide protection due to glitches in the circuit, TIs rely on few assumptions about the hardware and are fully compatible with standard design flows. We investigate two important properties of TIs in detail and point out interesting trade-offs between circuit area and randomness requirements. We propose two new TIs of AES that, starting from a common previously published implementation, illustrate possible trade-offs. We provide concrete ASIC implementation results for all three designs using the same library, and we evaluate the practical security of all three designs on the same FPGA platform. Our analysis allow us to directly compare the security provided by the different trade-offs, and to quantify the associated hardware cost.
Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2014 Higher-Order Threshold Implementations
Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
ASIACRYPT (2)5
2014 Collision Attack on 5 Rounds of Grøstl
Florian Mendel, Vincent Rijmen, Martin Schläffer
FSE2
2014 Linear hulls with correlation zero and linear cryptanalysis of block ciphers
Andrey Bogdanov, Vincent Rijmen
Des. Codes Cryptogr.2
2013 Key Difference Invariant Bias in Block Ciphers
Andrey Bogdanov, Christina Boura, Vincent Rijmen, Long Wen 0002
ASIACRYPT (1)3
2013 Efficient and First-Order DPA Resistant Implementations of Keccak
Begül Bilgin, Joan Daemen, Ventzislav Nikov, Svetla Nikova, Vincent Rijmen, Gilles Van Assche
CARDIS5
2013 Collisions for the WIDEA-8 Compression Function
Florian Mendel, Vincent Rijmen, Deniz Toz, Kerem Varici
CT-RSA2
2013 ALE: AES-Based Lightweight Authenticated Encryption
Andrey Bogdanov, Florian Mendel, Francesco Regazzoni 0001, Vincent Rijmen, Elmar Tischhauser
FSE4
2012 Differential Analysis of the LED Block Cipher
Florian Mendel, Vincent Rijmen, Deniz Toz, Kerem Varici
ASIACRYPT2
2012 A Simple Key-Recovery Attack on McOE-X
Florian Mendel, Bart Mennink, Vincent Rijmen, Elmar Tischhauser
CANS3
2012 Threshold Implementations of All 3 ×3 and 4 ×4 S-Boxes
Begül Bilgin, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen, Georg Stütz
CHES4
2012 Extracts from the SHA-3 Competition
Vincent Rijmen
Selected Areas in Cryptography1
2012 Memoryless near-collisions via coding theory
Mario Lamberger, Florian Mendel, Vincent Rijmen, Koen Simoens
Des. Codes Cryptogr.3
2012 Low-Data Complexity Attacks on AES
abstract
The majority of current attacks on reduced-round variants of block ciphers seeks to maximize the number of rounds that can be broken, using less data than the entire codebook and less time than exhaustive key search. In this paper, we pursue a different approach, restricting the data available to the adversary to a few plaintext/ciphertext pairs. We argue that consideration of such attacks (which received little attention in recent years) improves our understanding of the security of block ciphers and of other cryptographic primitives based on block ciphers. In particular, these attacks can be leveraged to more complex attacks, either on the block cipher itself or on other primitives (e.g., stream ciphers, MACs, or hash functions) that use a small number of rounds of the block cipher as one of their components. As a case study, we consider the Advanced Encryption Standard (AES)-the most widely used block cipher. The AES round function is used in many cryptographic primitives, such as the hash functions Lane, SHAvite-3, and Vortex or the message authentication codes ALPHA-MAC, Pelican, and Marvin. We present attacks on up to four rounds of AES that require at most three known/chosen plaintexts. We then apply these attacks to cryptanalyze an AES-based stream cipher (which follows the leak extraction methodology), and to mount the best known plaintext attack on six-round AES.
Charles Bouillaguet, Patrick Derbez, Orr Dunkelman, Pierre-Alain Fouque, Nathan Keller, Vincent Rijmen
IEEE Trans. Inf. Theory6
2011 Secure Hardware Implementation of Nonlinear Functions in the Presence of Glitches
Svetla Nikova, Vincent Rijmen, Martin Schläffer
J. Cryptol.2
2010 Rebound Attack on Reduced-Round Versions of JH
Vincent Rijmen, Deniz Toz, Kerem Varici
FSE1
2010 Whirlwind: a new cryptographic hash function
abstract
A new cryptographic hash function Whirlwind is presented. We give the full specification and explain the design rationale. We show how the hash function can be implemented efficiently in software and give first performance numbers. A detailed analysis of the security against state-of-the-art cryptanalysis methods is also provided. In comparison to the algorithms submitted to the SHA-3 competition, Whirlwind takes recent developments in cryptanalysis into account by design. Even though software performance is not outstanding, it compares favourably with the 512-bit versions of SHA-3 candidates such as LANE or the original CubeHash proposal and is about on par with ECHO and MD6.
Paulo S. L. M. Barreto, Ventzislav Nikov, Svetla Nikova, Vincent Rijmen, Elmar Tischhauser
Des. Codes Cryptogr.4
2010 Refinements of the ALRED construction and MAC security claims
abstract
The authors present three security claims for iterated message authentication codes (MAC functions). Next, they propose ALRED, a construction method for MAC functions based on a block cipher that has provable security in the absence of internal collisions. They apply this construction to advanced encryption standard (AES) resulting in two MAC functions: ALPHA-MAC and PELICAN. The authors provide a model for describing different types of internal collisions in ALRED and provide evidence that the security claims they propose are usable for MAC functions that use the ALRED construction. Finally, they provide a motivation for the security claims that accompany PELICAN.
Joan Daemen, Vincent Rijmen
IET Inf. Secur.2
2010 Algebraic cryptanalysis of a small-scale version of stream cipher Lex
abstract
In this study, the authors analyse with respect to algebraic attacks a small-scale version of the stream cipher Lex. They base it on a small-scale version of the block cipher advanced encryption standard (AES) with 16-bit state and 16-bit key. They represent the small-scale Lex and its key schedule in two alternative ways: as a system of cubic boolean equations and as a system of quadratic boolean equations. The authors use Gröbner bases to solve the two systems for different number of rounds and sizes of the leak. They obtain the best results for the quadratic representation of the cipher. For this case they are able to recover the secret key in time less than 2 min by solving a system of 374 quadratic boolean equations in 208 unknowns resulting from 5 rounds of the cipher.
Vesselin Velichkov, Vincent Rijmen, Bart Preneel
IET Inf. Secur.2
2009 Rebound Distinguishers: Results on the Full Whirlpool Compression Function
Mario Lamberger, Florian Mendel, Christian Rechberger, Vincent Rijmen, Martin Schläffer
ASIACRYPT4
2008 Rotation symmetry in algebraically generated cryptographic substitution tables
Vincent Rijmen, Paulo S. L. M. Barreto, Décio Luiz Gazzoni Filho
Inf. Process. Lett.1
2008 Analysis of the Hash Function Design Strategy Called SMASH
abstract
The hash function design strategy SMASH was recently proposed as an alternative to the MD4 family of hash functions. It can be shown that the strategy leads to designs that are vulnerable to efficient collision and (second) preimage attacks. The mathematical structure of the SMASH description facilitates the description of the weakness and the resulting attacks, but also functions with less mathematical elegance may show similar weaknesses.
Mario Lamberger, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
IEEE Trans. Inf. Theory4
2007 Second Preimages for Iterated Hash Functions and Their Implications on MACs
Norbert Pramstaller, Mario Lamberger, Vincent Rijmen
ACISP3
2007 Known-Key Distinguishers for Some Block Ciphers
Lars R. Knudsen, Vincent Rijmen
ASIACRYPT2
2007 Cryptanalysis of the Tiger Hash Function
Florian Mendel, Vincent Rijmen
ASIACRYPT2
2007 Second Preimages for SMASH
Mario Lamberger, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
CT-RSA4
2007 Plateau characteristics
abstract
Plateau characteristics are a special type of characteristics whose probability depends on the key and can have only two values. For a (usually small) subset of the keys it has a non-zero probability and for all other keys its probability is zero. For a large group of ciphers, including the AES, all two-round characteristics are plateau characteristics. For the AES and other ciphers with a similar structure, the vast majority of characteristics over four or more rounds are plateau characteristics. In the case of the AES, for most keys, there are two-round characteristics with fixed-key probability equal to 32/232, whereas the maximum expected differential probability of two-round differentials is at most 13.25/232.
Joan Daemen, Vincent Rijmen
IET Inf. Secur.2
2006 A compact FPGA implementation of the hash function whirlpool
abstract
Recent breakthroughs in cryptanalysis of standard hash functions like SHA-1 and MD5 raise the need for alternatives. A credible alternative to for instance SHA-1 or the SHA-2 family of hash functions is Whirlpool. Whirlpool is a hash function that has been evaluated and approved by NESSIE and is standardized by ISO/IEC. To the best of our knowledge only one FPGA implementation of Whirlpool has been published to date. This implementation is designed for high throughput rates requiring a considerable amount of hardware resources. In this article we present a compact hardware implementation of the hash function Whirlpool. The proposed architecture uses an innovative state representation that makes it possible to reduce the required hardware resources remarkably. The complete implementation requires 1456 CLB-slices and, most notably, no block RAMs.
Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
FPGA3
2006 Analysis of Step-Reduced SHA-256
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
FSE4
2006 The Impact of Carries on the Complexity of Collision Attacks on SHA-1
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
FSE4
2006 Threshold Implementations Against Side-Channel Attacks and Glitches
Svetla Nikova, Christian Rechberger, Vincent Rijmen
ICICS3
2006 On the Collision Resistance of RIPEMD-160
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
ISC4
2005 Update on SHA-1
Vincent Rijmen, Elisabeth Oswald
CT-RSA1
2005 A New MAC Construction ALRED and a Specific Instance ALPHA-MAC
Joan Daemen, Vincent Rijmen
FSE2
2005 A Side-Channel Analysis Resistant Description of the AES S-Box
Elisabeth Oswald, Stefan Mangard, Norbert Pramstaller, Vincent Rijmen
FSE4
2005 Exploiting Coding Theory for Collision Attacks on SHA-1
Norbert Pramstaller, Christian Rechberger, Vincent Rijmen
IMACC3
2004 Periodic Properties of Counter Assisted Stream Ciphers
Ove Scavenius, Martin Boesgaard, Thomas Pedersen, Jesper Christiansen, Vincent Rijmen
CT-RSA5
2002 AES and the Wide Trail Design Strategy
Joan Daemen, Vincent Rijmen
EUROCRYPT2
2001 Improved SQUARE Attacks against Reduced-Round HIEROCRYPT
Paulo S. L. M. Barreto, Vincent Rijmen, Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle, Hae Yong Kim
FSE2
2001 Differential Cryptanalysis of Q
Eli Biham, Vladimir Furman, Michal Misztal, Vincent Rijmen
FSE4
2001 Producing Collisions for PANAMA
Vincent Rijmen, Bart Van Rompay, Bart Preneel, Joos Vandewalle
FSE1
2001 Toward a secure public-key blockwise fragile authentication watermarking
abstract
In this paper, we describe some weaknesses of public-key blockwise fragile authentication watermarkings and the means to make them secure. Wong's (1998) original algorithm is not secure against a mere block cut-and-paste or the well-known birthday attack. To make it secure, some schemes have been proposed to make the signature of each block depend on the contents of its neighboring blocks. We attempt to maximize the change localization resolution using only one dependency per block with a scheme we call hash block chaining version 1 (HBC1). We then show that HBC1, as well as any neighbor-dependent scheme, are susceptible to another forgery technique that we have named a transplantation attack. We also show a new kind of birthday attack that can be effectively mounted against HBC1. To thwart these attacks, we propose using a nondeterministic digital signature together with a signature dependent scheme (HBC2). Finally, we discuss the advantages of using discrete logarithm signatures instead of RSA for watermarking.
Paulo S. L. M. Barreto, Hae Yong Kim, Vincent Rijmen
ICIP (2)3
2001 The Wide Trail Design Strategy
Joan Daemen, Vincent Rijmen
IMACC2
2001 The Quantum Entanglement of Binary and Bipolar Sequences
Matthew Geoffrey Parker, Vincent Rijmen
SETA2
2001 Cryptography on smart cards
Johan Borst, Bart Preneel, Vincent Rijmen
Comput. Networks3
2001 Linear Frameworks for Block Ciphers
Joan Daemen, Lars R. Knudsen, Vincent Rijmen
Des. Codes Cryptogr.3
1999 Equivalent Keys of HPC
Carl D'Halluin, Gert Bijnens, Bart Preneel, Vincent Rijmen
ASIACRYPT4
1999 Attack on Six Rounds of Crypton
Carl D'Halluin, Gert Bijnens, Vincent Rijmen, Bart Preneel
FSE3
1999 On the Decorrelated Fast Cipher (DFC) and Its Theory
Lars R. Knudsen, Vincent Rijmen
FSE2
1998 Analysis Methods for (Alleged) RC4
Lars R. Knudsen, Willi Meier, Bart Preneel, Vincent Rijmen, Sven Verdoolaege
ASIACRYPT4
1998 The Block Cipher BKSQ
Joan Daemen, Vincent Rijmen
CARDIS2
1998 The Block Cipher Rijndael
Joan Daemen, Vincent Rijmen
CARDIS2
1998 On the Design and Security of RC2
Lars R. Knudsen, Vincent Rijmen, Ronald L. Rivest, Matthew J. B. Robshaw
FSE2
1998 Differential Cryptanalysis of the ICE Encryption Algorithm
Bart Van Rompay, Lars R. Knudsen, Vincent Rijmen
FSE3
1998 Cryptanalysis of SPEED
Chris Hall, John Kelsey, Vincent Rijmen, Bruce Schneier, David A. Wagner 0001
Selected Areas in Cryptography3
1997 Two Attacks on Reduced IDEA
Johan Borst, Lars R. Knudsen, Vincent Rijmen
EUROCRYPT3
1997 The Block Cipher Square
Joan Daemen, Lars R. Knudsen, Vincent Rijmen
FSE3
1997 A Family of Trapdoor Ciphers
Vincent Rijmen, Bart Preneel
FSE1
1997 On Weaknesses of Non-surjective Round Functions
Vincent Rijmen, Bart Preneel, Erik De Win
Des. Codes Cryptogr.1
1996 The Cipher SHARK
Vincent Rijmen, Joan Daemen, Bart Preneel, Antoon Bosselaers, Erik De Win
FSE1
1994 Improved Characteristics for Differential Cryptanalysis of Hash Functions Based on Block Ciphers
Vincent Rijmen, Bart Preneel
FSE1
1994 Cryptanalysis of McGuffin
Vincent Rijmen, Bart Preneel
FSE1
1993 Cryptanalysis of the CFB Mode of the DES with a Reduced Number of Rounds
Bart Preneel, Marnix Nuttin, Vincent Rijmen, Johan Buelens
CRYPTO3