EDBT 2026 Demo / reviewers in the wild / expert
Kosei Sakamoto
dblp:246/3270
· DBLP profile ↗
22ranked-venue papers
2as first author
20since 2021 · last 2026
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 2 first-author · 19 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Analyzing Forgery Security of LeMac: Tight Bounds and Impact of Padding
Taichi Nagoya, Takuro Shiraya, Kazuma Taka, Tatsuya Ishikawa, Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001 |
ACISP (1) | 5 |
| 2026 | Automated Tool for Finding Practical Collisions on SPN-Based Hash Functions
Keita Toyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Kodai Taiyama, Takanori Isobe 0001 |
ACISP (1) | 2 |
| 2025 | Forgery Attacks on SipHash
Kosuke Sasaki, Rikuto Kurahara, Kosei Sakamoto, Takanori Isobe 0001 |
ACISP (1) | 3 |
| 2025 | Collision Attacks on SPONGENT with Grouping Method
Keita Toyama, Kosei Sakamoto, Takanori Isobe 0001 |
SAC | 2 |
| 2025 | Parallel SAT framework to find clustering of differential characteristics and its applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001 |
J. Inf. Secur. Appl. | 1 |
| 2024 | Differential Distinguishing Attacks on SNOW-V, SNOW-Vi and KCipher-2
Rikuto Kurahara, Kosei Sakamoto, Yuto Nakano, Takanori Isobe 0001 |
ACISP (1) | 2 |
| 2024 | Key Collisions on AES and Its Applications
Kodai Taiyama, Kosei Sakamoto, Ryoma Ito 0001, Kazuma Taka, Takanori Isobe 0001 |
ASIACRYPT (7) | 2 |
| 2024 | Collision Attacks on Hashing Modes of Areion
Kodai Taiyama, Kosei Sakamoto, Rentaro Shiba, Takanori Isobe 0001 |
CANS (2) | 2 |
| 2024 | Exploring the optimality of byte-wise permutations of a piccolo-type block cipherabstractPiccolo is a lightweight block cipher based on a 16-bit word 4-line generalized Feistel structure. Piccolo adopts byte-wise round permutation (RP) instead of the typical word-based RP to improve diffusion. In this paper, we explore the optimality of byte-based RP from the viewpoint of security. We evaluate the security of differential, linear, impossible differential, and integral attacks for all byte-wise RPs using mixed integer linear programming (MILP). We show that the RP of Piccolo is optimal in terms of the number of rounds required to guarantee security against such attacks. In addition, we introduce new two classes of RPs that require 7 rounds for security against impossible differential attacks, which is one round less than required by Piccolo. These new classes require 7/9 and 8/8 rounds to guarantee security against differential/linear attacks, respectively, which is more rounds than required by Piccolo. Shion Utsumi, Motoki Nakahashi, Kosei Sakamoto, Takanori Isobe 0001 |
Inf. Process. Lett. | 3 |
| 2023 | Ghidle: Efficient Large-State Block Ciphers for Post-quantum Security
Motoki Nakahashi, Rentaro Shiba, Ravi Anand, Mostafizar Rahman, Kosei Sakamoto, Fukang Liu, Takanori Isobe 0001 |
ACISP | 5 |
| 2023 | An Efficient Strategy to Construct a Better Differential on Multiple-Branch-Based Designs: Application to Orthros
Kazuma Taka, Tatsuya Ishikawa, Kosei Sakamoto, Takanori Isobe 0001 |
CT-RSA | 3 |
| 2023 | An Ultra-High Throughput AES-Based Authenticated Encryption Scheme for 6G: Design and Implementation
Ravi Anand, Subhadeep Banik, Andrea Caforio, Kazuhide Fukushima, Takanori Isobe 0001, Shinsaku Kiyomoto, Fukang Liu, Yuto Nakano, Kosei Sakamoto, Nobuyuki Takeuchi |
ESORICS (1) | 9 |
| 2023 | Parallel SAT Framework to Find Clustering of Differential Characteristics and Its Applications
Kosei Sakamoto, Ryoma Ito 0001, Takanori Isobe 0001 |
SAC | 1 |
| 2023 | MILP-based security evaluation for AEGIS/Tiaoxin-346/RoccaabstractAbstract In this paper, the security of Advanced Encryption Standard‐based authenticated encryption schemes, including AEGIS family, Tiaoxin‐346, and Rocca by mixed integer linear programming tools is examined. Specifically, for the initialisation phase of AEGIS, Tiaoxin‐346, and Rocca, the security against differential attacks and integral attacks is evaluated by estimating the lower bounds for the number of active S‐boxes and utilising division property, respectively. In addition to the estimations of initialisation phases, the security of the encryption phases of AEGIS, Tiaoxin‐346, and Rocca against distinguishing attacks on keystream is evaluated by exploiting integral properties. As a result, the authors show that the initialisation phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca are secure against differential attacks after 4/3/6, 5, and 6 rounds, respectively. Regarding integral attacks, the distinguisher is found on 6/6/7, 15, and 7 rounds in the initialisation phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca, respectively. Additionally, the integral distinguisher is presented on 2/2/4, 4, and 4 rounds in the encryption phases of AEGIS‐128/128L/256, Tiaoxin‐346, and Rocca, respectively. As far as it is known, this study’s results are the first distinguishing attacks on the keystream on AEGIS, Tiaoxin‐346, and Rocca without relying on weak keys. Takuro Shiraya, Nobuyuki Takeuchi, Kosei Sakamoto, Takanori Isobe 0001 |
IET Inf. Secur. | 3 |
| 2023 | Bit-level evaluation of piccolo block cipher by satisfiability problem solverabstractAbstract In the field of symmetric key cryptography, the security against distinguishing attacks is one of the crucial security requirements. With advancements in computing capabilities and cryptanalysis techniques in recent years, more efficient methods have been proposed for exploring distinguishers using Mixed‐Integer Linear Programing (MILP) or satisfiability problem (SAT), thereby updating the security bounds of various ciphers. Piccolo is a lightweight block cipher proposed at CHES in 2011, with support 80‐bit and 128‐bit keys. Designers have undergone a rough security evaluation against differential, impossible differential, and related‐key differential attacks, based on nibble‐wise estimations due to the limitation of computational resource. Here, the authors perform bit‐level evaluations on Piccolo block cipher against differential, integral and impossible differential attacks by leveraging SAT‐based approaches. For the first time, the authors succeed in identifying optimal differential distinguisher on 6 rounds in the single key setting, and on 10/12 rounds in the related‐key setting for 80‐bit and 128‐bit keys, respectively. For integral attacks, the authors find integral distinguisher up to 7 rounds. Although the number of attacked rounds is the same as that of the previous attack, the authors find the 56th ordered integral distinguisher, which enable reducing the data complexity for attacks from 2 63 to 2 56 . As a result, the authors find the 7‐round impossible differentials which is the same number of rounds as the previous nibble‐wise evaluation. Shion Utsumi, Kosei Sakamoto, Takanori Isobe 0001 |
IET Inf. Secur. | 2 |
| 2022 | Efficient constructions for large-state block ciphers based on AES New InstructionsabstractAbstract Large‐state block ciphers with 256 bits or 512 bits block sizes receive much attention from the viewpoint of long‐term security. Existing large‐state block ciphers, such as Haraka‐v2 and Pholkos, consist of only the AES New Instructions set (AES‐NI) and a word shuffle that can be efficiently executed by SIMD instructions for fast software implementation. In Haraka‐v2 and Pholkos, the AES round function is executed twice in parallel at each step and its outputs are shuffled (called two‐round constructions). In this study, optimal constructions based on AES‐NI and efficient word shuffles for such large‐state block ciphers in terms of the encryption speed for software are explored. Specifically, an optimal class of word shuffles that can achieve security in a smaller number of rounds from the class of word shuffles that can be efficiently implemented in SIMD to contribute to the improvement of the performance of large‐state block ciphers is identified. Their speed for each CPU architecture is measured. As a result, the authors reveal the constructions such that two rounds of the AES round function is executed in parallel at each step and its outputs are shuffled (called two‐round constructions) and are optimal in all CPUs with Skylake architecture or later versions. Furthermore, the authors reveal that there is a clear difference in word shuffle instructions with respect to the speed, even if they theoretically require the same number of cycles. Consequently, the authors clarify the optimal construction for each architecture by taking these differences into consideration. Rentaro Shiba, Kosei Sakamoto, Takanori Isobe 0001 |
IET Inf. Secur. | 2 |
| 2022 | Integral and impossible-differential attacks on the reduced-round Lesamnta-LW-BCabstractAbstract Lesamnta‐LW‐BC is the internal block cipher of the Lesamnta‐LW lightweight hash function, specified in ISO/IEC 29192‐5:2016. It is based on the unbalanced Feistel network and Advanced Encryption Standard round function. In this study, the security of Lesamnta‐LW‐BC against integral and impossible‐differential attacks is evaluated. Specifically, the authors searched for the integral distinguishers and impossible differentials with Mixed‐Integer Linear Programming‐based methods. As a result, the discovered impossible differential can reach up to 21 rounds, while three integral distinguishers reaching 18, 19 and 25 rounds are obtained, respectively. Moreover, it is also feasible to construct a 47‐round integral distinguisher in the known‐key setting. Finally, a 20‐round key‐recovery attack is proposed based on the discovered 18‐round integral distinguisher and a 19‐round key‐recovery attack using a 17‐round impossible differential. To the best of the authors' knowledge, this is the first third‐party cryptanalysis of Lesamnta‐LW‐BC. Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Kazuhiko Minematsu, Takanori Isobe 0001 |
IET Inf. Secur. | 2 |
| 2022 | Distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-ViabstractThis paper presents distinguishing and key recovery attacks on the reduced-round SNOW-V and SNOW-Vi, which are stream ciphers proposed for standard encryption schemes for the 5G mobile communication system. First, we construct a Mixed-Integer Linear Programming (MILP) model to search for integral characteristics using the division property, and find the best integral distinguisher in the 3-, 4-, 5-round SNOW-V, and 5-round SNOW-Vi with time complexities of 28, 216, 248, and 216, respectively. Next, we construct a bit-level MILP model to efficiently search for differential characteristics, and find the best differential characteristics in the 3- and 4-round versions. These characteristics lead to the 3-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 217 and 212 and the 4-round differential distinguishers for SNOW-V and SNOW-Vi with time complexities of 297 and 239, respectively. Then, we consider single-bit and dual-bit differential cryptanalysis, which is inspired by the existing study on Salsa and ChaCha. By carefully choosing the IV values and differences, we can construct practical bit-wise differential distinguishers for the 4-round SNOW-V, 4-, and 5-round SNOW-Vi with time complexities of 24.466, 21.000, and 214.670, respectively. Finally, we improve the existing differential attack based on probabilistic neutral bits, which is also inspired by the existing study on Salsa and ChaCha. As a result, we present the best key recovery attack on the 4-round SNOW-V and SNOW-Vi with time complexities of 2153.97 and 2233.99 and data complexities of 226.96 and 219.19, respectively. Consequently, we significantly improve the existing best key recovery attack in the initialization phase by the designers. Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto |
J. Inf. Secur. Appl. | 5 |
| 2021 | Distinguishing and Key Recovery Attacks on the Reduced-Round SNOW-V
Jin Hoki, Takanori Isobe 0001, Ryoma Ito 0001, Fukang Liu, Kosei Sakamoto |
ACISP | 5 |
| 2021 | Bit-wise cryptanalysis on AND-RX permutation Friet-PCabstractThis paper presents three attack vectors of bit-wise cryptanalysis including rotational, bit-wise differential, and zero-sum distinguishing attacks on the AND-RX permutation Friet-PC, which is implemented in a lightweight authenticated encryption scheme Friet. First, we propose a generic procedure for a rotational attack on AND-RX cipher with round constants. By applying the proposed attack to Friet-PC, we can construct an 8-round rotational distinguisher with a time complexity of 2102. Next, we explore single- and dual-bit differential biases, which are inspired by the existing study on Salsa and ChaCha, and observe the best bit-wise differential bias with 2−9.552. This bias allows us to practically construct a 9-round bit-wise differential distinguisher with a time complexity of 220.044. Finally, we construct 13-, 15-, and 17-round zero-sum distinguishers with time complexities of 231, 263, and 2127, respectively. To summarize our study, we apply three attack vectors of bit-wise cryptanalysis to Friet-PC and show their superiority as effective attacks on AND-RX ciphers. Ryoma Ito 0001, Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Takanori Isobe 0001 |
J. Inf. Secur. Appl. | 3 |
| 2020 | Galaxy: A Family of Stream-Cipher-Based Space-Hard Ciphers
Yuji Koike, Kosei Sakamoto, Takuya Hayashi 0001, Takanori Isobe 0001 |
ACISP | 2 |
| 2020 | WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri |
SAC | 7 |