EDBT 2026 Demo / reviewers in the wild / expert
Nasour Bagheri
dblp:44/7270
· DBLP profile ↗
39ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0002-6818-5342ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 6 first-author · 6 since 2021Systems, architecture and hardware · 7 · 1 first-author · 4 since 2021Computer networks · 7 · 6 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improved polytopic differential neural distinguishers for SIMON, SIMECK, and SPECK block ciphersabstractAbstract In recent years, the application of deep learning in cryptanalysis has gained significant attention, particularly with the emergence of neural network-based distinguishers. At CRYPTO’19, Gohr demonstrated that neural networks could develop differential distinguishers capable of producing highly competitive attacks against existing methods. Building on this foundation, we propose multiple input polytopic differential neural distinguishers ( PDND s) for the lightweight block ciphers SIMON, SIMECK, and SPECK. Our approach incorporates a novel data generation method that utilizes two polytope differences, resulting in more precise training data and enhanced model accuracy. Through extensive experiments in single-key and related-key scenarios, we evaluate and validate the intrinsic performance of our neural distinguishers. Our results show that PDND s significantly outperform the baseline, polytopic, multiple, and mixture differential neural distinguishers, utilizing a single input difference, in accuracy across various cipher rounds. Notably, our PDND s achieved $$100\%$$ 100 % accuracy for up to 7 rounds of SIMON32 and SIMECK32, and $$99.39\%$$ 99.39 % accuracy for 5 rounds of SPECK32 in the single-key scenario. Additionally, for extended rounds, we achieved accuracy levels of up to 12 rounds for SIMON32, 13 for SIMECK32, and 8 for SPECK32 without requiring staged training. In the related-key scenario, our method further improved performance, introducing 13-round and 15-round RK-PDND s for SIMON32 and SIMECK32, respectively, underscoring the enhanced capabilities of our approach. Furthermore, we demonstrate the effectiveness of our neural distinguishers through a key recovery test, where they successfully distinguish between correct and incorrect keys, confirming the practical applicability of our approach in cryptanalysis. Iman Mirzaali, Sadegh Sadeghi, Nasour Bagheri |
Cybersecur. | 3 |
| 2025 | Securing Industrial IoT: A Novel Approach with MQTT AuthenticationabstractAs Message Queuing Telemetry Transport (MQTT) becomes a widely adopted protocol for IoT communication, the use of traditional Transport Layer Security (TLS) encryption poses challenges due to its high computational demands on resource-constrained devices and one-way authentication. In this paper, we propose a novel lightweight mutual authentication protocol designed for MQTT-based communication in Industrial Internet of Things (IIoT) environments. Our protocol ensures message integrity without the high computational overhead associated with TLS encryption. By leveraging an alternative Authenticated Encryption (AE) method optimized for resourceconstrained devices, we enhance both security and efficiency. To evaluate the performance, we conducted experiments using three Raspberry Pi devices, comparing our protocol to both non-encrypted and TLS-secured MQTT. The results demonstrate a significant reduction in system run-time, from 139 ms to 108 ms, when using the proposed protocol for mutual authentication, compared to default TLS, which only supports oneway authentication. Additionally, simulations conducted in NS3, across various practical scenarios, reveal notable improvements in authentication success rates and reduced delays. Our findings suggest that this protocol offers a promising solution for secure and efficient communication in IIoT systems. Samad Rostampour, Alireza Javadi, Sadegh Sadeghi, Ygal Bendavid, Nasour Bagheri, Peyman Pahlevani |
ICC | 5 |
| 2025 | An Enhanced Security Protocol for Vehicular Ad Hoc NetworksabstractThe present work aims to address key security vulnerabilities in Vehicular Ad Hoc Networks (VANETs) through an enhanced authentication scheme. This study evaluates the effectiveness of utilizing Elliptic Curve Cryptography (ECC) for improving security efficiency and compares it with conventional techniques used in state-of-the-art authentication protocols. The results demonstrate improvements in both computational and communication efficiency. A rigorous formal analysis using the Tamarin Prover confirms the robustness of the proposed security processes. Real-world implementation of the proposed protocol using Raspberry Pi devices is conducted and empirical performance tests using NS-3 (Network Simulator 3) show a 30% improvement in computational efficiency and a 25% reduction in authentication delay compared to conventional techniques, along with a 98% success rate in evading impersonation attacks and a 95% success rate in preventing replay attacks while maintaining similar efficiency levels. Hossein Geranfar, Bahman Abolhassani, Nasour Bagheri, Alireza Javadi, Pedro Peris-Lopez, Carmen Camara, Saru Kumari |
IEEE Internet Things J. | 3 |
| 2025 | Evaluating security pitfalls of ultra-lightweight IoT authentication: A critical analysis of permutation functions
Iman Mirzaali, Alireza Javadi, Sadegh Sadeghi, Peyman Pahlevani, Nasour Bagheri, Ygal Bendavid, Samad Rostampour |
J. Inf. Secur. Appl. | 5 |
| 2024 | Cryptanalysis of DBST, a lightweight block cipher
Sadegh Sadeghi, Nasour Bagheri |
Frontiers Comput. Sci. | 2 |
| 2024 | Toward designing a lightweight RFID authentication protocol for constrained environmentsabstractAbstract In present times, Radio‐Frequency Identification (RFID) systems have seen a significant rise in their usage. There has been an increasing interest in developing even lighter RFID protocols suitable for resource‐constrained environments. Ensuring security and privacy remain critical challenges in RFID‐based systems. Recently proposed lightweight authentication schemes, namely LRSAS+ and LRARP+, are ideally suited for constrained devices. However, this article investigates these schemes and reveals certain vulnerabilities: LRSAS+ is susceptible to tag impersonation, desynchronization, and traceability attacks, while LRARP+ can fall prey to traceability and secret disclosure attacks. An enhanced version of these authentication systems is proposed that tackles their inherent weaknesses by leveraging the function. To verify the security of the proposed scheme, a formal analysis is conducted using Gong–Needham–Yahalom logic (GNY logic) and an automated security protocol verification tool, ProVerif. The improved scheme's effectiveness is also compared with multiple contemporary lightweight systems. The results indicate that the enhanced scheme not only meets the security requirements for lightweight authentication schemes but also achieves this with minimal computational overhead. Nasser Zarbi, Ali Zaeembashi, Nasour Bagheri, Morteza Adeli |
IET Commun. | 3 |
| 2024 | A Post-Quantum Compliant Authentication Scheme for IoT Healthcare SystemsabstractIn an Internet of Things (IoT)-based healthcare system, medical IoT devices gather and transmit critical patient data. Ensuring the security and privacy of medical data is paramount. One of the most critical challenges in this regard is the authentication of participating entities. The literature proposes specific authentication approaches for healthcare systems based on integer factorization and discrete logarithm problems. However, the advent of quantum computers would fundamentally break all of these protocols. In this study, we conducted an analysis of a recently proposed authentication and access control scheme for e-health systems, which is based on lattice-based cryptography and was developed by Gupta et al. Our analysis revealed that the scheme is vulnerable to several types of attacks, including impersonation, de-synchronization, and smart card stolen attacks, which could compromise the confidentiality and integrity of sensitive medical data. To address these security challenges, we propose an alternative authentication and access control scheme that uses Saber, a finalist lattice-based key encapsulation algorithm from round three of the NIST post-quantum cryptography standardization. One of the biggest advantages of Saber is its simplicity and efficiency. Our proposed scheme is designed specifically for e-health systems and provides robust protection against the vulnerabilities identified in Gupta et al.’s scheme. We believe that our proposed scheme represents a significant improvement over existing approaches and could help to enhance the security and privacy of e-health systems. Upon completion of our improved protocol, we proceeded to implement it within the Vivado 2018.3 environment for Zynq UltraScale FPGAs. To gather insight into its performance, we conducted a performance comparison study with various related protocols. Morteza Adeli, Nasour Bagheri, Hamid Reza Maimani, Saru Kumari, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 2 |
| 2024 | Using a privacy-enhanced authentication process to secure IoT-based smart grid infrastructures
Samad Rostampour, Nasour Bagheri, Behnam Ghavami, Ygal Bendavid, Saru Kumari, Honorio Martín, Carmen Camara |
J. Supercomput. | 2 |
| 2024 | Correction to: Using a privacy‑enhanced authentication process to secure IoT‑based smart grid infrastructures
Samad Rostampour, Nasour Bagheri, Behnam Ghavami, Ygal Bendavid, Saru Kumari, Honorio Martín, Carmen Camara |
J. Supercomput. | 2 |
| 2023 | Exploiting statistical effective fault attack in a blind settingabstractAbstract In order to obtain the secret key, the majority of physical attacks require knowledge of the plaintext or ciphertext, which may be unavailable or cannot be exploited. Blind attacks are introduced to do key recovery in circumstances where the adversary has no direct access to plaintext and ciphertext. A combination of fault and power attacks can circumvent typical countermeasures in this setting, for example, Fault Template Attack (FTA). However, FTA relies on bit fault injection, which is difficult to implement in practice. The SIFA‐blind, a framework for executing the Statistical Ineffective Fault Attack, is more flexible, but sensitivity to setup noise and missed faults is its main drawback. To address this deficiency, we suggest two ways to use Statistical Effective Fault Attack in a blind setting that are much less affected by missed faults and noise when measuring power traces, even though they do not use fault injection at the bit level. In order to demonstrate the viability and adaptability of our proposed attacks, we injected a fault via glitch frequency onto the ChipWhisperer board. While SEFA‐blind does not need a bit‐level fault, our results demonstrate that it is better than SIFA‐blind when the number of missed faults increases. Navid Vafaei, Hadi Soleimany, Nasour Bagheri |
IET Inf. Secur. | 3 |
| 2023 | χperbp: a cloud-based lightweight mutual authentication protocol
Morteza Adeli, Nasour Bagheri, Sadegh Sadeghi, Saru Kumari |
Peer Peer Netw. Appl. | 2 |
| 2022 | An Authentication Protocol for Next Generation of Constrained IoT SystemsabstractWith the exponential growth of connected Internet of Things (IoT) devices around the world, security protection and privacy preservation have risen to the forefront of design and development of innovative systems and services. For low-value IoT devices that identify and track billion of goods in various industries—such as radio-frequency identification (RFID) tags—this involves multiple challenges in very constrained environments. IoT devices aim to design low-cost, low-complexity infrastructure while enabling robust authentication protocols with reduced latency and energy consumption. Given these challenges, in this article, we present a new lightweight authentication protocol for IoT applications, employing an authenticated-encryption (AE) cryptosystem with associated data (AEAD). Since AEAD algorithms provide data confidentiality and message integrity simultaneously, security analysis [Real-or-Random (RoR) and Scyther] results prove the robustness of the proposed protocol against IoT threats. Furthermore, to measure the computation and communication cost, FPGA and ASIC simulations using four different AEAD candidates of National Institute of Standards and Technology (NIST) lightweight cryptography competition are executed. The implementation results [e.g., 4744 gate equivalent (GE) and 0.87-mw power] clearly show that our novel design can be applied to a wide range of constrained IoT devices complying with low-cost, lightweight, and high-speed requirements. Samad Rostampour, Nasour Bagheri, Ygal Bendavid, Masoumeh Safkhani, Saru Kumari, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 2 |
| 2022 | Improving RFID/IoT-based generalized ultra-lightweight mutual authentication protocols
Masoumeh Safkhani, Samad Rostampour, Ygal Bendavid, Sadegh Sadeghi, Nasour Bagheri |
J. Inf. Secur. Appl. | 5 |
| 2022 | Challenging the security of "A PUF-based hardware mutual authentication protocol"
Morteza Adeli, Nasour Bagheri, Honorio Martín, Pedro Peris-Lopez |
J. Parallel Distributed Comput. | 2 |
| 2022 | Statistical Effective Fault Attacks: The Other Side of the CoinabstractThe introduction of Statistical Ineffective Fault Attacks (SIFA) has led to a renewed interest in fault attacks. SIFA requires minimal knowledge of the concrete implementation and is effective even in the presence of common fault or power analysis countermeasures. However, further investigations reveal that undesired and frequent ineffective events, which we refer to as the noise phenomenon, are the bottleneck of SIFA that can considerably diminish its strength. This includes noise associated with the attack’s setup and caused by the countermeasures utilized in the implementation. This research aims to address this significant drawback. We present two novel statistical fault attack variants that are far more successful in dealing with these noisy conditions. The first variant is the Statistical Effective Fault Attack (SEFA), which exploits the non-uniform distribution of intermediate variables in circumstances when the induced faults are effective. The idea behind the second proposed method, dubbed Statistical Hybrid Fault Attacks (SHFA), is to take advantage of the biased distributions of both effective and ineffective cases simultaneously. Our experimental results in various case studies, including noise-free and noisy setups, back up our reasoning that SEFA surpasses SIFA in several instances and that SHFA outperforms both or is at least as efficient as the best of them. For example, in the case of a 4-bits random-AND fault injected into the AES with a 35% missed fault rate, utilizing SEFA reduces the number of needed ciphertexts by 50%. In the same case study, SHFA can yield 10% and 55% reductions compared to SEFA and SIFA. Navid Vafaei, Sara Zarei 0001, Nasour Bagheri, Maria Eichlseder, Robert Primas, Hadi Soleimany |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Proposing an MILP-based method for the experimental verification of difference-based trails: application to SPECK, SIMECK
Sadegh Sadeghi, Vincent Rijmen, Nasour Bagheri |
Des. Codes Cryptogr. | 3 |
| 2021 | MDSbSP: a search protocol based on MDS codes for RFID-based Internet of vehicle
Morteza Adeli, Nasour Bagheri |
J. Supercomput. | 2 |
| 2020 | IoT in medical & pharmaceutical: Designing lightweight RFID security protocols for ensuring supply chain integrity
Masoumeh Safkhani, Samad Rostampour, Ygal Bendavid, Nasour Bagheri |
Comput. Networks | 4 |
| 2020 | Modification and hardware implementation of cortex-like object recognition modelabstractObject recognition in the visual cortex of mammals and humans has inspired many computational object recognition models. Hierarchical model and X (HMAX) is a well‐known biologically motivated object recognition model with scale and position tolerance and high accuracy. Due to the computational intensive nature, hardware implementation with massive parallel processing is suggested for real‐time applications. However, it is important to explore algorithmic trade‐offs when mapping an algorithm to are configurable hardware. A direct conversion of the software implementation of an algorithm generally results inefficient hardware resource usage. In this study, the authors propose a novel modification into the HMAX model which makes it suitable for hardware implementation. More precisely, to reduce the number of memory blocks and multipliers of the S2 layer of HMAX produces, they replace the first norm by the second norm, which critically affects the silicon area in an application‐specific integrated circuit implementation or the required resources in field‐programmable gate array (FPGA). To evaluate the proposed model, they implement a pipelined version of the revised model on a mid‐range commercial Xilinx FPGA, i.e. XC6VLX240T platform from a Virtex 6 family of Xilinx using ISE. Compared to the recent hardware implementation of HMAX, the proposed model offers 83% resource degradation in DSP48 slices and 3% in memory blocks. Alireza Mohammadi Anbaran, Pooya Torkzadeh, Reza Ebrahimpour, Nasour Bagheri |
IET Image Process. | 4 |
| 2020 | ECCbAP: A secure ECC-based authentication protocol for IoT edge devices
Samad Rostampour, Masoumeh Safkhani, Ygal Bendavid, Nasour Bagheri |
Pervasive Mob. Comput. | 4 |
| 2019 | Security analysis of SIMECK block cipher against related-key impossible differential
Sadegh Sadeghi, Nasour Bagheri |
Inf. Process. Lett. | 2 |
| 2018 | Improved zero-correlation and impossible differential cryptanalysis of reduced-round SIMECK block cipherabstractSIMECK is a family of three lightweight block ciphers designed by Yang et al ., following the framework used by Beaulieu et al . from the United States National Security Agency to design SIMON and SPECK. In this study, the authors employ an improved miss‐in‐the‐middle approach to find zero correlation linear distinguishers and impossible differentials on SIMECK48 and SIMECK64. Based on this novel technique, they will be able to present zero‐correlation linear approximations for 15‐round SIMECK48 and 17‐round SIMECK64 and these zero‐correlation linear approximations improve the previous best result by two rounds for SIMECK48 and SIMECK64. Moreover, they attack 27‐round SIMECK48 and 31‐round SIMECK64 based on these zero‐correlation linear distinguishers. In addition, due to the duality of zero‐correlation and impossible differential, they search for the impossible differential characteristics for SIMECK48 and SIMECK64 so that they will be able to present 15‐round SIMECK48 and 17‐round SIMECK64 while the best previously known results were 13‐round impossible differentials for SIMECK48 and 15‐round impossible differentials for SIMECK64. Moreover, they propose impossible differential attacks on 22‐round SIMECK48 and 24‐round SIMECK64 based on these impossible differential characteristics. The results significantly improve the previous zero correlation attack and impossible differential characteristic results for these variants of SIMECK to the best of the authors’ knowledge. Sadegh Sadeghi, Nasour Bagheri |
IET Inf. Secur. | 2 |
| 2018 | An improved low-cost yoking proof protocol based on Kazahaya's flaws
Nasour Bagheri, Masoumeh Safkhani, Mojtaba Eslamnezhad Namin, Samad Rostampour |
J. Supercomput. | 1 |
| 2018 | A Scalable and Lightweight Grouping Proof Protocol for Internet of Things Applications
Samad Rostampour, Nasour Bagheri, Mehdi Hosseinzadeh 0001, Ahmad Khademzadeh |
J. Supercomput. | 2 |
| 2017 | Passive secret disclosure attack on an ultralightweight authentication protocol for Internet of Things
Masoumeh Safkhani, Nasour Bagheri |
J. Supercomput. | 2 |
| 2016 | Improved Rebound Attacks on AESQ: Core Permutation of CAESAR Candidate PAEQ
Nasour Bagheri, Florian Mendel, Yu Sasaki 0001 |
ACISP (2) | 1 |
| 2016 | Cryptanalysis of Reduced NORX
Nasour Bagheri, Tao Huang 0015, Keting Jia, Florian Mendel, Yu Sasaki 0001 |
FSE | 1 |
| 2016 | Building indifferentiable compression functions from the PGV compression functions
Praveen Gauravaram, Nasour Bagheri, Lars R. Knudsen |
Des. Codes Cryptogr. | 2 |
| 2016 | An authenticated encryption based grouping proof protocol for RFID systemsabstractAbstract Radio frequency identification grouping proof authentication protocol is an approach to identify a set of tagged objects simultaneously. Over the past decade, several protocols in this domain have been presented, but each was weak with flawed attributes. It is essential that a grouping proof protocol be both scalable and affordable, considering its use for applications with large quantities of tags and the high level of security. In this paper, we present a secure and scalable grouping proof protocol by utilizing an encryption method that is called authenticated encryption. This encryption method provides both confidentiality and message integrity simultaneously. In addition, it can satisfy the resource limitation of passive tags. The proposed protocol eliminates the dependency among the tags' responses and provides the scalability with minimum message broadcasting. We evaluate the proposed protocol based on formal and informal security methods, and the results prove that it is robust against radio frequency identification attacks and suitable for low‐power and low‐cost devices. Copyright © 2017 John Wiley & Sons, Ltd. Samad Rostampour, Nasour Bagheri, Mehdi Hosseinzadeh 0001, Ahmad Khademzadeh |
Secur. Commun. Networks | 2 |
| 2015 | Weaknesses of fingerprint-based mutual authentication protocolabstractAbstract The Internet of Things is an emerging paradigm, which is used to link physical objects with Internet. One of the most common ways of communicating and identifying objects on Internet of Things is using Radio Frequency IDentification (RFID) systems between different objects. Researchers have focused on developing improvements of RFID authentication protocols that stave off privacy threats and well‐known security problems. Recently, Khor et al. have proposed a new authentication protocol that conforms to the Electronic Product Code Class‐1 Generation‐2 standard (ISO/IEC 18000‐6C for RFID systems). In this paper, we show the vulnerabilities of this authentication protocol concerning to full disclosure, impersonation, traceability, de‐synchronization, and Denial‐of‐Service attacks. These attacks make the protocol unfeasible to introduce it with an adequate security and sufficient privacy protection level. Finally, we present a new protocol, called Fingerprint+ protocol, which is based on ISO/IEC 9798‐2 and ISO/IEC 18000‐6C and whose security is formally verified using BAN logic. Copyright © 2014 John Wiley & Sons, Ltd. Pablo Picazo-Sanchez, Lara Ortiz-Martin, Pedro Peris-Lopez, Nasour Bagheri |
Secur. Commun. Networks | 4 |
| 2014 | Cryptanalysis of a new EPC class-1 generation-2 standard compliant RFID protocol
Nasour Bagheri, Masoumeh Safkhani, Majid Naderi |
Neural Comput. Appl. | 1 |
| 2014 | Weaknesses in a new ultralightweight RFID authentication protocol with permutation - RAPPabstractABSTRACT Tian et al. proposed a novel ultralightweight RFID mutual authentication protocol [1] that has recently been analyzed in several articles. In this letter, we first propose a desynchronization attack that succeeds with probability almost 1, which improves upon the 0.25 given in a previous analysis by Ahmadian et al. We also show that the bad properties of the proposed permutation function can be exploited to disclose several bits of the tag's secret (rather than just 1 bit as previously shown by Avoine et al.), which increases the power of a traceability attack. Finally, we show how to extend the aforementioned attack to run a full disclosure attack, which requires to eavesdrop less protocol runs than the proposed attack by Wang et al. (i.e., 192 < < 2 30). Copyright © 2013 John Wiley & Sons, Ltd. Nasour Bagheri, Masoumeh Safkhani, Pedro Peris-Lopez, Juan Tapiador |
Secur. Commun. Networks | 1 |
| 2013 | Multiple classifier system for EEG signal classification with application to brain-computer interfaces
Amir Ahangi, Mehdi Karamnejad, Nima Mohammadi, Reza Ebrahimpour, Nasour Bagheri |
Neural Comput. Appl. | 5 |
| 2012 | Another Fallen Hash-Based RFID Authentication Protocol
Julio César Hernández Castro, Pedro Peris-Lopez, Masoumeh Safkhani, Nasour Bagheri, Majid Naderi |
WISTP | 4 |
| 2011 | Tag Impersonation Attack on Two RFID Mutual Authentication ProtocolsabstractSecurity concerns of RFID systems engaged a lot of researchers to design and to cryptanalyze RFID mutual authentication protocols. A suitable mutual authentication protocol for an RFID system should provide mutual authentication along with user privacy. In addition, such protocol must be resistant to active and passive attacks, e.g. man-in-the-middle attack, reply attack, reader-/tag-impersonation, denial of service and traceability attack. Among them, tag-impersonation refers to a process that the adversary's tag fools the legitimate reader to authenticate it as a valid tag. In this paper we exam the security of two RFID mutual authentication protocols, i.e., [6] and [17], under tag impersonation attack. We found that these two protocols share a same vulnerability in each session, the tag and the reader generates a random value respectively and they use the exclusive or (XOR) of those random values in the authentication process. We exploit this vulnerability to present two effective and efficient tag impersonation attacks against these protocols, e.g., the success probabilities of our attacks are "1" and the complexity is at most two runs of each protocol. At last, we exhibit the improved version of these protocols, which are immune from tag impersonation attacks. Masoumeh Safkhani, Nasour Bagheri, Majid Naderi, Yiyuan Luo, Qi Chai |
ARES | 2 |
| 2011 | Improved Security Analysis of Fugue-256 (Poster)
Praveen Gauravaram, Lars R. Knudsen, Nasour Bagheri, Lei Wei 0001 |
ACISP | 3 |
| 2010 | On the Collision and Preimage Resistance of Certain Two-Call Hash Functions
Nasour Bagheri, Praveen Gauravaram, Majid Naderi, Søren S. Thomsen |
CANS | 1 |
| 2009 | Cryptanalysis of an iterated halving-based hash function: CRUSHabstractIterated Halving has been suggested as a replacement to the Merkle–Damgård (MD) construction in 2004 anticipating the attacks on the MDx family of hash functions. The CRUSH hash function provides a specific instantiation of the block cipher for Iterated Halving. The authors identify structural problems with the scheme and show that they can trivially identify collisions and second preimages on many equal-length messages of length ten blocks or more. The cost is ten decryptions of the block cipher, this being less than the generation of a single digest. In addition, these attacks can be used to differentiate CRUSH from a random oracle in O(1). The authors show that the complexity of finding a preimage in the unpadded CRUSH with the length encoding is negligible and extend this attack on CRUSH with the length encoding in cost O(232). This attack is a multi-preimage attack, since the attacker can produce a large number of messages for a given message digest for the cost of O(232). Hence, this attack can be used as a multi-collision and a multi-second-preimage as well. They show that if the attacker knows the last 64-bits of the message digest in advance, he can do the time-consuming part of the attack off-line. The authors show that even if Iterated Halving is repaired, the construction has practical issues that means it is not suitable for general deployment. Nasour Bagheri, Matt Henricksen, Lars R. Knudsen, Majid Naderi, B. Sadeghyian |
IET Inf. Secur. | 1 |
| 2008 | Multi-Collisions Attack in Ring Hash Structure
Nasour Bagheri, Babak Sadeghiyan, Majid Naderi |
SECRYPT | 1 |