Ryoma Ito 0001

dblp:157/4417-1 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0002-4929-8974ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 5 first-author · 15 since 2021
YearPublicationVenuePosition
2026 Analyzing Forgery Security of LeMac: Tight Bounds and Impact of Padding
Taichi Nagoya, Takuro Shiraya, Kazuma Taka, Tatsuya Ishikawa, Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
ACISP (1)6
2026 Automated Tool for Finding Practical Collisions on SPN-Based Hash Functions
Keita Toyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Kodai Taiyama, Takanori Isobe 0001
ACISP (1)3
2025 Gravity of the Situation: Security Analysis on Rocket.Chat E2EE
abstract
Rocket.Chat is a group chat platform widely deployed in industries and national organizations, with over 15 million users across 150 countries. One of its main features is an end-to-end encryption (E2EE) protocol; however, no cryptographic security analysis has been conducted. We conduct an in-depth cryptographic analysis of Rocket.Chat's E2EE protocol and identify multiple significant flaws that allow a malicious server or even an outsider to break the confidentiality and integrity of the group chat. Specifically, we formally model and analyze the protocol using ProVerif under the Dolev-Yao model, uncovering multiple theoretical weaknesses and verifying that some of them lead to practical attacks. Furthermore, through meticulous manual analysis, we identify additional vulnerabilities, including implementation flaws and cryptographic weaknesses such as CBC malleability, and demonstrate how they are exploitable in practical attack scenarios. To validate our findings, we develop Proof-of-Concept implementations, highlighting the real-world feasibility of these attacks. We also propose mitigation techniques and discuss the implications of our attacks.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Takanori Isobe 0001
ACSAC2
2025 Not in The Prophecies: Practical Attacks on Nostr
abstract
Distributed social networking services (SNSs) recently received significant attention as an alternative to traditional, centralized SNSs, which have inherent limitations on user privacy and freedom. We provide the first in-depth security analysis of Nostr, an open-source, distributed SNS protocol developed in 2019 with more than 1.1 million registered users. We investigate the specification of Nostr and the client implementations and present a number of practical attacks allowing forgeries on various objects, such as encrypted direct messages (DMs), by a malicious user or a malicious server. Even more, we show a confidentiality attack against encrypted DMs by a malicious user exploiting a flaw in the link preview mechanism and the CBC malleability. Our attacks are due to cryptographic flaws in the protocol specification and client implementation, some of which in combination elevate the forgery attack to a violation of confidentiality. We verify the practicality of our attacks via Proof-of-Concept implementations and discuss how to mitigate them.
Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Shogo Shiraki, Takanori Isobe 0001
EuroS&P2
2025 Security analysis of SFrame
abstract
Increasing privacy consciousness has popularized the use of end-to-end encryption (E2EE). In this paper, we discuss the security of SFrame, an E2EE mechanism proposed to the Internet Engineering Task Force for video/audio group communications over the Internet. Despite being a quite recent project, SFrame has been deployed in several real-world applications. The original specification of SFrame is evaluated herein to find critical issues that can cause impersonation (forgery) attacks with a practical complexity by a malicious group member . Further investigations have revealed that these issues are present in several publicly available SFrame implementations. Therefore, we provide several countermeasures against all the proposed attacks and considerations from performance and security perspectives towards their implementation.
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
J. Inf. Secur. Appl.2
2025 Parallel SAT framework to find clustering of differential characteristics and its applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
J. Inf. Secur. Appl.2
2025 On the effects of neural network-based output prediction attacks on the design of symmetric-key ciphers
abstract
Proving resistance to conventional attacks, e.g., differential, linear, and integral attacks, is essential for designing a secure symmetric-key cipher. Recent advances in automatic search and deep learning-based methods have made this time-consuming task relatively easy, yet concerns persist over expertise requirements and potential oversights. To overcome these concerns, Kimura et al. proposed neural network-based output prediction (NN) attacks, offering simplicity, generality, and reduced coding mistakes. NN attacks could be helpful for designing secure symmetric-key ciphers, especially the S-box-based block ciphers. Inspired by their work, we first apply NN attacks to Simon , one of the AND-Rotation-XOR-based block ciphers, and identify structures susceptible to NN attacks and the vulnerabilities detected thereby. Next, we take a closer look at the vulnerable structures. The most vulnerable structure has the lowest diffusion property compared to others. This fact implies that NN attacks may detect such a property. We then focus on a biased event of the core function in vulnerable Simon -like ciphers and build effective linear approximations caused by such an event. Finally, we use these linear approximations to reveal that the vulnerable structures are more susceptible to a linear key recovery attack than the original one. We conclude that our analysis can be a solid step toward making NN attacks a helpful tool for designing a secure symmetric-key cipher.
Hayato Watanabe, Ryoma Ito 0001, Toshihiro Ohigashi
J. Inf. Secur. Appl.2
2024 Key Collisions on AES and Its Applications
Kodai Taiyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Takanori Isobe 0001
ASIACRYPT (7)3
2023 Parallel SAT Framework to Find Clustering of Differential Characteristics and Its Applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001
SAC2
2022 PNB-Focused Differential Cryptanalysis of ChaCha Stream Cipher
Shotaro Miyashita, Ryoma Ito 0001, Atsuko Miyaji
ACISP2
2022 Distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-Vi
abstract
This paper presents distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-Vi, which are stream ciphers proposed for standard encryption schemes for the 5G mobile communication system. First, we construct a Mixed-Integer Linear Programming (MILP) model to search for integral characteristics using the division property, and find the best integral distinguisher in the 3-, 4-, 5-round SNOW-V, and 5-round SNOW-Vi with time complexities of 28, 216, 248, and 216, respectively. Next, we construct a bit-level MILP model to efficiently search for differential characteristics, and find the best differential characteristics in the 3- and 4-round versions. These characteristics lead to the 3-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 217 and 212 and the 4-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 297 and 239, respectively. Then, we consider single-bit and dual-bit differential cryptanalysis, which is inspired by the existing study on Salsa and ChaCha. By carefully choosing the IV values and differences, we can construct practical bit-wise differential distinguishers for the 4-round SNOW-V, 4-, and 5-round SNOW-Vi with time complexities of 24.466, 21.000, and 214.670, respectively. Finally, we improve the existing differential attack based on probabilistic neutral bits, which is also inspired by the existing study on Salsa and ChaCha. As a result, we present the best key recovery attack on the 4-round SNOW-V and SNOW-Vi with time complexities of 2153.97 and 2233.99 and data complexities of 226.96 and 219.19, respectively. Consequently, we significantly improve the existing best key recovery attack in the initialization phase by the designers.
Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto
J. Inf. Secur. Appl.3
2021 Distinguishing and Key Recovery Attacks on the Reduced-Round SNOW-V
Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto
ACISP3
2021 Security Analysis of End-to-End Encryption for Zoom Meetings
abstract
In the wake of the global COVID-19 pandemic, video conference systems have become essential for not only business purposes, but also private, academic, and educational uses. Among the various systems, Zoom is the most widely deployed video conference system. In October 2020, Zoom Video Communications rolled out their end-to-end encryption (E2EE) to protect conversations in a meeting from even insiders, namely, the service provider Zoom. In this study, we conduct thorough security evaluations of the E2EE of Zoom (version 2.3.1) by analyzing their cryptographic protocols. We discover several attacks more powerful than those expected by Zoom according to their whitepaper. Specifically, if insiders collude with meeting participants, they can impersonateany Zoom userin target meetings, whereas Zoom indicates that they can impersonate only the current meeting participants. Besides, even without relying on malicious participants, insiders can impersonate any Zoom user in target meetings though they cannot decrypt meeting streams. In addition, we demonstrate several impersonation attacks by meeting participants or insiders colluding with meeting participants. Although these attacks may be beyond the scope of the security claims made by Zoom or may be already mentioned in the whitepaper, we reveal the details of the attack procedures and their feasibility in the real-world setting and propose effective countermeasures in this paper. Our findings are not an immediate threat to the E2EE of Zoom; however, we believe that these security evaluations are of value for deeply understanding the security of E2EE of Zoom.
Takanori Isobe 0001, Ryoma Ito 0001
ACISP2
2021 Security Analysis of SFrame
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu
ESORICS (2)2
2021 Bit-wise cryptanalysis on AND-RX permutation Friet-PC
abstract
This paper presents three attack vectors of bit-wise cryptanalysis including rotational, bit-wise differential, and zero-sum distinguishing attacks on the AND-RX permutation Friet-PC, which is implemented in a lightweight authenticated encryption scheme Friet. First, we propose a generic procedure for a rotational attack on AND-RX cipher with round constants. By applying the proposed attack to Friet-PC, we can construct an 8-round rotational distinguisher with a time complexity of 2102. Next, we explore single- and dual-bit differential biases, which are inspired by the existing study on Salsa and ChaCha, and observe the best bit-wise differential bias with 2−9.552. This bias allows us to practically construct a 9-round bit-wise differential distinguisher with a time complexity of 220.044. Finally, we construct 13-, 15-, and 17-round zero-sum distinguishers with time complexities of 231, 263, and 2127, respectively. To summarize our study, we apply three attack vectors of bit-wise cryptanalysis to Friet-PC and show their superiority as effective attacks on AND-RX ciphers.
Ryoma Ito 0001, Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Takanori Isobe 0001
J. Inf. Secur. Appl.1
2020 Rotational Cryptanalysis of Salsa Core Function
Ryoma Ito 0001
ISC1
2018 New Iterated RC4 Key Correlations
Ryoma Ito 0001, Atsuko Miyaji
ACISP1
2015 How TKIP Induces Biases of Internal States of Generic RC4
Ryoma Ito 0001, Atsuko Miyaji
ACISP1
2015 New Linear Correlations Related to State Information of RC4 PRGA Using IV in WPA
Ryoma Ito 0001, Atsuko Miyaji
FSE1