Cihangir Tezcan

dblp:42/7079 · DBLP profile ↗
← Back
14ranked-venue papers
8as first author
6since 2021 · last 2026
0000-0002-9041-1932ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 6 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Fast and Energy-Efficient Polynomial Multiplication Using FFT, FFNT, and NTT on GPUs for Fully Homomorphic Encryption
Ali Sah Özcan, Cihangir Tezcan, Erkay Savas
WAIFI2
2026 Experimentally obtained differential-linear distinguishers for Sycon
abstract
Abstract Sycon is an authenticated encryption algorithm with associated data submitted to NIST’s recently finalized lightweight cryptography competition. Ascon won the competition, while Sycon was eliminated in the first round. Subsequently, the designers proposed an improved version of Sycon that closely resembles Ascon . In this work, we optimize the latest Sycon permutation for GPUs using CUDA, achieving a processing rate of $$2^{34.89}$$ 2 34.89 full 12-round Sycon permutations per second on an RTX 4090 GPU. This optimization enables us to experimentally derive differential-linear (DL) distinguishers, which combine differential and linear characteristics to enhance their effectiveness. We present several 2-round and 3-round probability-one truncated differential characteristics, along with 2-round, 3-round, and 4-round linear characteristics. Using these characteristics, we introduce the first 5-round DL distinguishers for Sycon with a bias of $$2^{-8.55}$$ 2 - 8.55 . We also improve the reported $$2^{-2.8}$$ 2 - 2.8 bias for the 4-round DL distinguisher to $$2^{-2.57}$$ 2 - 2.57 . Furthermore, we present 5-round practical key recovery DL biases for Sycon when used in Ascon -mode: $$2^{-15.25}$$ 2 - 15.25 for key recovery, $$2^{-15.22}$$ 2 - 15.22 for related key scenarios, and $$2^{-12.75}$$ 2 - 12.75 for IV misuse. Our observations indicate that Sycon ’s permutation, though marginally slower in software due to additional rotation operations within its linear layer, might offer better resistance to DL cryptanalysis compared to Ascon . We also address the issue of misreported test vectors for Sycon and provide corrected vectors to aid accurate analyses. Our code is available for future analyses and verification.
Aslí Basak Civek, Cihangir Tezcan
J. Supercomput.2
2024 GPU-Based Brute Force Cryptanalysis of KLEIN
abstract
KLEIN is a family of lightweight block ciphers that supports 64-bit, 80-bit, and 96-bit secret keys. In this work, we provide a CUDA optimized table-based implementation of the KLEIN family which does not contain shared memory bank conflicts. Our best optimization reach more than 45 billion 64-bit KLEIN key searches on an RTX 4090. Our results show that KLEIN block cipher is susceptible to brute force attacks via GPUs. Namely, in order to break KLEIN in a year via brute force, one needs around 13, 1.34 million, and 111 billion RTX 4090 GPUs for 64-bit, 80-bit, and 96-bit secret keys, respectively. We recommend lightweight designs to avoid short keys.
Cihangir Tezcan
ICISSP1
2022 Differential-linear Attacks on Permutation Ciphers Revisited: Experiments on Ascon and DryGASCON
abstract
Ascon and DryGASCON are very similar designs that were submitted to NIST's lightweight cryptography standardization process. While Ascon made it to the finals, DryGASCON was eliminated in the second round. We analyze these algorithms against truncated, linear and differential-linear distinguishers to compare their security. We correct 2, 3, 3.5-round truncated differentials and 5-round differential-linear distinguishers that were given for DryGASCON-128. Moreover, we provide the longest practical differential-linear distinguisher of DryGASCON-128. Finally, we compare the security of Ascon-128 and DryGASCON-128 against differential-linear cryptanalysis.
Aslí Basak Civek, Cihangir Tezcan
ICISSP2
2022 GPU accelerated 3DES encryption
abstract
Abstract Triple DES (3DES) is a NIST and ISO/IEC standard block cipher that is also used in some web browsers and several electronic payment applications. We propose an optimized bit‐level parallelization of 3DES for GPU accelerated encryption to allow processing high volumes of data. Since the block size of 3DES is 64 bits, our approach considers a kernel block as a 64‐bit 3DES block. Each kernel block performs XOR, permutation, and S‐box operations of this cipher in parallel and memory accesses are optimized by the use of constant and shared memory. Although table based and bitsliced implementations of block ciphers on GPUs outperform naive implementations, their performance vary significantly on different GPU models and architectures. Lack of publicly available source codes prohibit a fair comparison of the performance results for different implementations. In this work, we provide performance results on various GPU models and make our implementation publicly available for reproducibility and further comparisons. When compared against the baseline multi‐threaded CPU implementation, our optimization achieves an average of 15.95 speed‐up when encrypting large files using an RTX 2070 Super GPU. Moreover, when modified into a key search attack, more than 94.4 million 3DES key searches per second can be conducted on an RTX 2070 Super GPU.
Kaan Furkan Altinok, Afsin Peker, Cihangir Tezcan, Alptekin Temizel
Concurr. Comput. Pract. Exp.3
2022 Key lengths revisited: GPU-based brute force cryptanalysis of DES, 3DES, and PRESENT
Cihangir Tezcan
J. Syst. Archit.1
2020 Weak-Key Distinguishers for AES
Lorenzo Grassi 0001, Gregor Leander, Christian Rechberger, Cihangir Tezcan, Friedrich Wiemer
SAC4
2017 Brute Force Cryptanalysis of MIFARE Classic Cards on GPU
abstract
MIFARE Classic is the most widely deployed contactless smartcard on the market. However, many active and passive attacks are provided after its proprietary stream cipher CRYPTO1 was reverse engineered. The short 48-bit key of the CRYPTO1 cipher, leaked parity bits and the encrypted error code that is sent after a failed authentication (which is corrected in the hardened new cards) allow the adversary to perform offline brute force attack and avoid detection. Such an attack requires wireless interaction with a card for less than a second and then a brute force attack which was shown to take around 9 days on a single GTX280 GPU. We optimized this brute force attack on modern GPUs by using bitsliced implementation technique and observed that a brute force attack on a GTX970 GPU can be performed in less than 5 hours. Although this attack is not applicable to hardened MIFARE Classic cards, a similar attack using the short key length and the leaked parity bits can be performed when a single key is known, possibly using the default keys for unused sectors. Such an attack requires wireless interaction with a card for less than a second and then a brute force attack which was shown to take approximately one month on a single GTX460 GPU. Our bitsliced implementation of this attack takes less than 7 hours on a GTX970 GPU.
Cihangir Tezcan
ICISSP1
2016 Truncated, Impossible, and Improbable Differential Analysis of ASCON
abstract
Ascon is an authenticated encryption algorithm which is recently qualified for the second-round of the Competition for Authenticated Encryption: Security, Applicability, and Robustness. So far, successful differential, differential-linear, and cube-like attacks on the reduced-round Ascon are provided. In this work, we provide the inverse of Ascon's linear layer in terms of rotations which can be used for constructing impossible differentials. We show that Ascon's S-box contains 35 undisturbed bits and we use them to construct 4 and 5-round truncated, impossible, and improbable differential distinguishers. Our results include practical 4-round truncated, impossible, and improbable differential attacks on Ascon. Our best attacks using these techniques break 5 out of 12 rounds. These are the first successful truncated, impossible, and improbable differential attacks on the reduced-round Ascon.
Cihangir Tezcan
ICISSP1
2016 Improved improbable differential attacks on ISO standard CLEFIA: Expansion technique revisited
Cihangir Tezcan, Ali Aydin Selçuk
Inf. Process. Lett.1
2014 Improbable Differential Attacks on Serpent using Undisturbed Bits
abstract
A recently introduced S-box evaluation criteria called undisturbed bits allow the attacker to construct longer truncated, impossible or improbable differentials. In this paper, we analyze the security of Serpent against impossible and improbable differential cryptanalysis for the first time and provide a 7-round improbable differential attack by using undisturbed bits of its S-boxes. Although these cryptanalytic techniques are discovered after Serpent was designed, our analysis shows that the cipher is secure against these kind of attacks. Moreover, it was shown that every 3 × 3 S-box contains undisturbed bits and a list of ciphers were provided whose 4 × 4 S-boxes contain undisturbed bits. In this study we provide undisturbed bits for larger S-boxes for the first time. Namely, the undisturbed bits for the 5 × 5 and 6 × 6 S-boxes of Fides and the 9 × 9 S-boxes of Kasumi and Misty.
Cihangir Tezcan, Halil Kemal Taskin, Murat Demircioglu
SIN1
2013 Improbable differential cryptanalysis
abstract
Statistical attacks on block ciphers make use of a property of the cipher so that an event occurs with different probabilities depending on whether or not the correct key is used. For instance, differential cryptanalysis [3] and truncated differential cryptanalysis [5] consider characteristics or differentials which show that a particular output difference should be obtained with a relatively high probability when a particular input difference is used. Hence, when the correct key is used, the predicted differences occur more frequently.
Cihangir Tezcan
SIN1
2011 On Hiding a Plaintext Length by Preencryption
Cihangir Tezcan, Serge Vaudenay
ACNS1
2009 Lightweight Block Ciphers Revisited: Cryptanalysis of Reduced Round PRESENT and HIGHT
Onur Özen, Kerem Varici, Cihangir Tezcan, Çelebi Kocair
ACISP3