Yosuke Todo

dblp:44/10381 · DBLP profile ↗
← Back
47ranked-venue papers
15as first author
17since 2021 · last 2026
0000-0002-6839-4777ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 43 · 14 first-author · 16 since 2021Systems, architecture and hardware · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial?
Akira Ito 0002, Takayuki Miura, Yosuke Todo
CRYPTO (7)3
2026 Practical committing attacks against Rocca-S
abstract
This paper shows practical committing attacks against Rocca-S, an authenticated encryption with associated data scheme designed for 6G applications. Previously, the best complexity of the attack was 2 64 by Derbez et al. in ToSC 2024(1)/FSE 2024. We show that the committing attack against Rocca by Takeuchi et al. in ToSC 2024(2)/FSE 2025 can be applied to Rocca-S, where Rocca is an earlier version of Rocca-S. We show a concrete test vector of our attack. We also point out a committing attack that exploits equivalent keys.
Ryunosuke Takeuchi, Yosuke Todo, Tetsu Iwata
Inf. Process. Lett.2
2025 Divide-and-Conquer Trail Enumeration Puncturing: Application to Salsa and ChaCha
Antonio Flórez-Gutiérrez, Yosuke Todo
ASIACRYPT (1)2
2025 Improved Cryptanalysis of ChaCha: Beating PNBs with Bit Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo
EUROCRYPT (1)2
2025 Improving Linear Key Recovery Attacks using Walsh Spectrum Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo
J. Cryptol.2
2024 Multiple-Tweak Differential Attack Against SCARF
Christina Boura, Shahram Rasoolzadeh, Dhiman Saha, Yosuke Todo
ASIACRYPT (7)4
2024 General Practical Cryptanalysis of the Sum of Round-Reduced Block Ciphers and ZIP-AES
Antonio Flórez-Gutiérrez, Lorenzo Grassi 0001, Gregor Leander, Ferdinand Sibleyras, Yosuke Todo
ASIACRYPT (9)5
2024 Improving Linear Key Recovery Attacks Using Walsh Spectrum Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo
EUROCRYPT (1)2
2023 Keyed Sum of Permutations: A Simpler RP-Based PRF
Ferdinand Sibleyras, Yosuke Todo
CT-RSA2
2023 SCARF - A Low-Latency Block Cipher for Secure Cache-Randomization
Federico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma, Yosuke Todo, Rei Ueno
USENIX Security Symposium5
2022 A Modular Approach to the Incompressibility of Block-Cipher-Based AEADs
Akinori Hosoyamada, Takanori Isobe 0001, Yosuke Todo, Kan Yasuda
ASIACRYPT (2)3
2022 New Attacks from Old Distinguishers Improved Attacks on Serpent
Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo
CT-RSA7
2022 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo
J. Cryptol.8
2021 Strong and Tight Security Guarantees Against Integral Distinguishers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo
ASIACRYPT (1)4
2021 Massive Superpoly Recovery with Nested Monomial Predictions
Kai Hu 0001, Siwei Sun, Yosuke Todo, Meiqin Wang 0001, Qingju Wang 0001
ASIACRYPT (1)3
2021 Designing S-Boxes Providing Stronger Security Against Differential Cryptanalysis for Ciphers Using Byte-Wise XOR
Yosuke Todo, Yu Sasaki 0001
SAC1
2021 Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
J. Cryptol.4
2020 Lower Bounds on the Degree of Block Ciphers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo
ASIACRYPT (1)4
2020 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Gregor Leander, Yosuke Todo
CRYPTO (3)3
2020 Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer
CRYPTO (3)10
2020 Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001
EUROCRYPT (1)4
2020 PRINCEv2 - More Security for (Almost) No Overhead
Dusan Bozilov, Maria Eichlseder, Miroslav Knezevic, Baptiste Lambin, Gregor Leander, Thorben Moos, Ventzislav Nikov, Shahram Rasoolzadeh, Yosuke Todo, Friedrich Wiemer
SAC9
2019 On the Data Limitation of Small-State Stream Ciphers: Correlation Attacks on Fruit-80 and Plantlet
Yosuke Todo, Willi Meier, Kazumaro Aoki
SAC1
2019 Nonlinear Invariant Attack: Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
J. Cryptol.1
2019 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
abstract
At CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively.
Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001
IEEE Trans. Computers6
2018 Programming the Demirci-Selçuk Meet-in-the-Middle Attack with Constraints
Danping Shi, Siwei Sun, Patrick Derbez, Yosuke Todo, Bing Sun 0001, Lei Hu 0003
ASIACRYPT (2)4
2018 Several MILP-Aided Attacks Against SNOW 2.0
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii
CANS2
2018 Fast Correlation Attack Revisited - Cryptanalysis on Full Grain-128a, Grain-128, and Grain-v1
Yosuke Todo, Takanori Isobe 0001, Willi Meier, Kazumaro Aoki, Bin Zhang 0003
CRYPTO (2)1
2018 Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier
CRYPTO (1)3
2018 On the Complexity of Impossible Differential Cryptanalysis
abstract
While impossible differential attack is one of the most well-known and familiar techniques for symmetric-key cryptanalysts, its subtlety and complicacy make the construction and verification of such attacks difficult and error-prone. We introduce a new set of notations for impossible differential analysis. These notations lead to unified formulas for estimation of data complexities of ordinary impossible differential attacks and attacks employing multiple impossible differentials. We also identify an interesting point from the new formulas: in most cases, the data complexity is only related to the form of the underlying distinguisher and has nothing to do with how the differences at the beginning and the end of the distinguisher propagate in the outer rounds. We check the formulas with some examples, and the results are all matching. Since the estimation of the time complexity is flawed in some situations, in this work, we show under which condition the formula is valid and give a simple time complexity estimation for impossible differential attack which is always achievable.
Qianqian Yang 0003, Lei Hu 0003, Danping Shi, Yosuke Todo, Siwei Sun
Secur. Commun. Networks4
2018 Tight Bounds of Differentially and Linearly Active S-Boxes and Division Property of Lilliput
abstract
This paper provides security analysis of a lightweight block cipher called LILLIPUT, which was proposed in IEEE Transactions on Computers in 2015. LILLIPUT adopts an extended generalized Feistel network (EGFN). EGFN consists of non-linear, linear, and permutation layers, and the linear layer updates a part of the state only linearly, which causes several security concerns. Our first discovery is that the lower bounds of the number of differentially active S-boxes provided by the designers are incorrect. Thus the new bounds are derived by using mixed integer linear programming (MILP). We apply a two-stage search procedure introduced by Sun et al. that leads to tight bounds even for a large number of rounds. The search tool is then converted for linear cryptanalysis. With those updates, the challenging problem of evaluating LILLIPUT's security against differential and linear cryptanalysis is closed. Another contribution is the best third-party cryptanalysis. The designers expected EGFN to efficiently enhance security against integral cryptanalysis. However, security is not as enhanced as the designers expected. In fact, division property finds a 13-round distinguisher that improves on the previous distinguisher by 4 rounds. The distinguisher is further extended to a 17-round key recovery that improves on the previous best attack by 3 rounds.
Yu Sasaki 0001, Yosuke Todo
IEEE Trans. Computers2
2018 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
abstract
The cube attack is a powerful cryptanalytic technique and is especially powerful against stream ciphers. Since we need to analyze the complicated structure of a stream cipher in the cube attack, the cube attack basically analyzes it by regarding it as a blackbox. Therefore, the cube attack is an experimental attack, and we cannot evaluate the security when the size of cube exceeds an experimental range, e.g., 40. In this paper, we propose cube attacks on non-blackbox polynomials. Our attacks are developed by using the division property, which is recently applied to various block ciphers. The clear advantage is that we can exploit large cube sizes because it never regards the cipher as a blackbox. We apply the new cube attack to Trivium, Grain128a, ACORN and Kreyvium. As a result, the secret keys of 832-round Trivium, 183-round Grain128a, 704-round ACORN and 872-round Kreyvium are recovered. These attacks are the current best key-recovery attack against these ciphers.
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
IEEE Trans. Computers1
2017 Improved Integral Attack on HIGHT
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii
ACISP (1)2
2017 GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption
Subhadeep Banik, Sumit Kumar Pandey, Thomas Peyrin, Yu Sasaki 0001, Siang Meng Sim, Yosuke Todo
CHES6
2017 Gimli : A Cross-Platform Permutation
Daniel J. Bernstein, Stefan Kölbl, Stefan Lucks, Pedro Maat Costa Massolino, Florian Mendel, Kashif Nawaz, Tobias Schneider 0002, Peter Schwabe, François-Xavier Standaert, Yosuke Todo, Benoît Viguier
CHES10
2017 Cube Attacks on Non-Blackbox Polynomials Based on Division Property
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier
CRYPTO (3)1
2017 New Impossible Differential Search Tool from Design and Cryptanalysis Aspects - Revealing Structural Properties of Several Ciphers
Yu Sasaki 0001, Yosuke Todo
EUROCRYPT (3)2
2017 Integral Cryptanalysis on Full MISTY1
Yosuke Todo
J. Cryptol.1
2016 Wide Trail Design Strategy for Binary MixColumns - Enhancing Lower Bound of Number of Active S-boxes
Yosuke Todo, Kazumaro Aoki
ACNS1
2016 Nonlinear Invariant Attack - Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
ASIACRYPT (2)1
2016 Compact Representation for Division Property
Yosuke Todo, Masakatu Morii
CANS1
2016 Bit-Based Division Property and Application to Simon Family
Yosuke Todo, Masakatu Morii
FSE1
2016 New Differential Bounds and Division Property of Lilliput: Block Cipher with Extended Generalized Feistel Network
Yu Sasaki 0001, Yosuke Todo
SAC2
2015 Integral Cryptanalysis on Full MISTY1
Yosuke Todo
CRYPTO (1)1
2015 Structural Evaluation by Generalized Integral Property
Yosuke Todo
EUROCRYPT (1)1
2014 FFT Key Recovery for Integral Attack
Yosuke Todo, Kazumaro Aoki
CANS1
2013 Upper Bounds for the Security of Several Feistel Networks
Yosuke Todo
ACISP1