EDBT 2026 Demo / reviewers in the wild / expert
Seokhie Hong
dblp:45/1848
· DBLP profile ↗
59ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-7506-4023ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 2 first-author · 5 since 2021Systems, architecture and hardware · 11 · 2 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-authorTheory of computation · 6 · 1 first-authorComputer networks · 4 · 3 since 2021Software engineering, systems software and programming languages · 3Graphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 2Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PentaPassBreaker: Intelligent Password Prediction via Neural Networks by Analyzing Password Update PatternsabstractDespite advancements in password policy enforcement and user awareness, individuals continue to follow predictable patterns when updating or creating new passwords across different sites-often making minor changes such as appending digits, capitalizing letters, or adding special characters. To model and exploit such behavioral regularities, we presentPentaPassBreaker, a novel sequence-to-sequence generative model for password prediction. As a foundation for learning real-world update patterns, we introduce a large-scale lexical similarity filtering of leaked credentials, extracting 307 million high-similarity password pairs through noise cleaning and similarity-based clustering. Our analysis reveals that users reuse an average of 3.2 closely related passwords per account, highlighting the prevalence of fine-grained reuse behavior. Experimental results show that PentaPassBreaker achieves an average top-5 accuracy of 22.1%, with simple transformation paths exceeding 35% in top-25 accuracy. Qualitative analysis further reveals that even incorrect guesses often resemble plausible user updates, demonstrating strong behavioral fidelity. Moreover, PPB consistently outperforms strong rule-based baselines such as John the Ripper (JTR), particularly on structural and multi-edit transformation paths under strict top-$k$budgets. These findings highlight the overlooked risks associated with incremental password reuse and emphasize the need for stronger user awareness and authentication safeguards. Dongho Jeon, Seokhie Hong |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Recovering S-Box Design Structures and Quantifying Distances Between S-Boxes Using Deep Learning
Donggeun Kwon, Deukjo Hong, Jaechul Sung, Seokhie Hong |
ACNS (3) | 4 |
| 2025 | ProbeShooter: A New Practical Approach for Probe Aiming
Daehyeon Bae, Minsig Choi, Changmin Jeong, Seokhie Hong |
AsiaCCS | 7 |
| 2025 | Redefining Security in Shadow Cipher for IoT Nodes: New Full-Round Practical Distinguisher and the Infeasibility of Key-Recovery AttacksabstractShadow is a block cipher for Internet of Things (IoT) Nodes proposed in the IEEE IoT Journal in 2021. The primary design principle of shadow is the adoption of a variant 4-branch Feistel structure to ensure a fast diffusion. We refer to this structure as the shadow structure and prove that it is almost identical to the Feistel structure, which invalidates the design principle. We also present a new structural distinguisher that can distinguish the shadow structure from a random permutation with only two plaintext/ciphertext pairs. Additionally, we demonstrate that the key-recovery attacks utilizing the impossible differential proposed by Liu et al. in the Cybersecurity Journal in 2023 and the integral characteristic proposed by Mirzaie et al. in the IEEE IoT Journal are infeasible. Instead, we extend our distinguisher to a key-recovery attack using only one plaintext/ciphertext pair by exploiting the key schedule. Moreover, upon investigating shadow’s round function, we observe that only specific forms of monomials can appear in the ciphertext, leading to an integral distinguisher involving four plaintext/ciphertext pairs. Notably, the algebraic degree does not exceed 12 for shadow-32 and 20 for shadow-64, regardless of the number of rounds used. Our results show that shadow is highly vulnerable to algebraic attacks, emphasizing the need for careful consideration of algebraic attacks when incorporating AND, rotation, and xor operations in cipher design. Sunyeop Kim, Myoungsu Shin, Seonkyu Kim, Hanbeom Shin, Insung Kim, Donggeun Kwon, Seonggyeom Kim, Deukjo Hong, Jaechul Sung, Seokhie Hong |
IEEE Internet Things J. | 11 |
| 2025 | Improved Frobenius FFT for Code-Based Cryptography on Cortex-M4abstractPolynomial multiplication over finite fields is one of the most significant operations in code-based cryptography, including HQC, which has been selected as a standardized algorithm in the NIST PQC round 4 process. In the standardization process, the performance of an algorithm is important not only in general-purpose systems but also in embedded systems. In particular, NIST has recommended the ARM Cortex-M4 as the benchmark platform for embedded systems. In CHES2021, Chen et al. optimized BIKE on the ARM Cortex-M4, using the Frobenius Additive FFT as the polynomial multiplication algorithm. However, although HQC was finally selected as a standard algorithm in March 2025, an efficient implementation for the ARM Cortex-M4 platform, which NIST recommends as the benchmark for embedded systems, has not yet been reported. In this paper, we propose an optimized implementation of the Frobenius Additive FFT to accelerate polynomial multiplication in BIKE and HQC on the ARM Cortex-M4 platform. Our approach exploits the fact that one operand of field multiplications in the Frobenius Additive FFT is fixed, allowing the transformation of these operations into binary matrix-vector products. We then apply XOR-efficient linear layer techniques combined with a register scheduling strategy specifically designed for the constraints of the Cortex-M4 architecture. We evaluate our implementation on the Nucleo-L4R5ZI evaluation board and compare it against existing state-of-the-art implementations. Our results demonstrate an 8% improvement in polynomial multiplication for BIKE, leading to up to 6% performance gains in key generation, encapsulation, and decapsulation. Moreover, we achieve an 80%–92% speedup in polynomial multiplication for HQC compared to the PQClean implementation, resulting in overall performance gains of up to 84% in key generation, encapsulation, and decapsulation. MyeongHoon Lee, Suhri Kim, Seokhie Hong |
IEEE Internet Things J. | 4 |
| 2025 | SAECHAM: Secure and Efficient Lightweight Block Cipher CHAM VariantabstractThe ARX structure, which comprises three fundamental operations—Addition, Rotation, and XOR—makes it well-suited for lightweight cryptography. To design a secure and efficient ARX cipher, it is necessary to find the optimal structure by properly combining the order, number of operations, and rotation amounts. CHAM64 is an ARX block cipher with a 64-bit block size, which is proposed as an attempt to enhance the lightweight characteristics of LEA. In this paper, we present Secure And Efficient CHAM (SAECHAM), a variant of CHAM64 with a rearranged order of operations and adjusted rotation amounts. By changing the order of the operations in CHAM64, six different CHAM-like structures can be created. We propose the properties that can be eliminated in the implementation process depending on the rotation amount in each structure. To improve suitability for constrained environments such as 8-bit and 16-bit microcontrollers, we reduce the search space for rotation amounts and analyze the number of instructions. Using an SMT solver-based automatic search method, we analyze the security of 62 CHAM64 variants through differential and linear analysis. Among them, we find four variants with equal or better resistance to differential and linear cryptanalysis compared to CHAM64. As a result, we propose the variant with the fewest instructions among them as SAECHAM. Through software implementations on 8-bit AVR, 16-bit MSP430, 32-bit ARM Cortex-M3 and Cortex-M4 platforms, we demonstrate that SAECHAM is efficient in terms of encryption speed and also performs efficiently when implemented using SIMD operations in high-performance CPUs. Myoungsu Shin, Hanbeom Shin, Insung Kim, Sunyeop Kim, Deukjo Hong, Jaechul Sung, Seokhie Hong |
IEEE Internet Things J. | 8 |
| 2024 | Fault Attack on SQIsign
Jeonghwan Lee 0002, Donghoe Heo, Hyeonhak Kim, GyuSang Kim, Suhri Kim, Seokhie Hong |
PQCrypto (2) | 7 |
| 2023 | A preimage attack on reduced GIMLI-HASH with unbalanced squeezing phaseabstractAbstract In Conference on Cryptographic Hardware and Embedded System 2017, Bernstein et al. proposed GIMLI , a 384‐bit permutation with 24 rounds, which aims to provide high performance on various platforms. In 2019, the full‐round (24 rounds) GIMLI permutation was used as an underlying primitive for building AEAD GIMLI‐CIPHER and hash function GIMLI‐HASH , which were submitted to the NIST Lightweight Cryptography Standardisation process and selected as one of the second‐round candidates. In Transactions on Symmetric Cryptology 2021, Liu et al. presented a preimage attack with a divide‐and‐conquer method on round‐reduced GIMLI‐HASH , which uses 5‐round GIMLI . In this paper, preimage attacks on a round‐reduced variant of GIMLI‐HASH is presented, in which the message absorbing phase uses 5‐round GIMLI and the squeezing phase uses 9‐round GIMLI . This variant is called as 5–9‐round GIMLI‐HASH . The authors’ preimage attack on 5–9‐round GIMLI‐HASH requires 2 96.44 time complexity and 2 97 memory complexity. Also, this method can be reached up to round shifted 10‐round GIMLI in the squeezing phase. The authors’ first attack requires the memory for storing several precomputation tables in GIMLI SP‐box operations. In the authors’ second attack, a time‐memory trade‐off approach is taken, reducing memory requirements for precomputation tables but increasing computing time for solving SP‐box equations by using SAT solver. This attack requires 2 66.17 memory complexity and 2 96+ ϵ time complexity, where ϵ is a time complexity for solving SP‐box equations. The authors’ experiments using CryptoMiniSat SAT solver show that the maximum time complexity for ϵ is about 2 20.57 9‐round GIMLI . Yongseong Lee, Jinkeon Kang, Donghoon Chang, Seokhie Hong |
IET Inf. Secur. | 4 |
| 2022 | Enhanced Side-Channel Analysis on ECDSA Employing Fixed-Base Comb MethodabstractTable-based scalar multiplication provides practical security for ECDSA signature generation. However, a novel key recovery attack against this form of ECDSA signature generation that exploits the collisions between entries was recently proposed at CHES 2021. This attack is possible even if table entries are unknown, such as with random permutated entry ordering. In this paper, we enhance the efficiency of the key recovery attack against secure ECDSA signature generation based on fixed-base comb scalar multiplication. We significantly reduce the required number of traces by compressing collision information using the mathematical relationship between table entry collisions. We verify this is a practical threat by performing an experiment on fixed-base comb method with window width$w=4$. Using our method, up to 27 traces are needed, much fewer than 1,019 traces required in the CHES publication. We cluster real traces measured using 32-bit STM32F4 microcontroller. In the experiment, we provide a selection method of points of interest using variance traces and unsupervised clustering-based leakage detection. With the selection method, we succeed in clustering leakages into 16 classes with a 100% success rate with 32-bit MCU. This represents the first experiment to cluster the more leakage classes with a 32-bit MCU than in literature. Sunghyun Jin, Sung Min Cho, Seokhie Hong |
IEEE Trans. Computers | 4 |
| 2021 | Efficient implementation of modular multiplication over 192-bit NIST prime for 8-bit AVR-based sensor nodeabstractAbstract Modular multiplication is one of the most time-consuming operations that account for almost 80% of computational overhead in a scalar multiplication in elliptic curve cryptography. In this paper, we present a new speed record for modular multiplication over 192-bit NIST prime P-192 on 8-bit AVR ATmega microcontrollers. We propose a new integer representation named Range Shifted Representation (RSR) which enables an efficient merging of the reduction operation into the subtractive Karatsuba multiplication. This merging results in a dramatic optimization in the intermediate accumulation of modular multiplication by reducing a significant amount of unnecessary memory access as well as the number of addition operations. Our merged modular multiplication on RSR is designed to have two duplicated groups of 96-bit intermediate values during accumulation. Hence, only one accumulation of the group is required and the result can be used twice. Consequently, we significantly reduce the number of load/store instructions which are known to be one of the most time-consuming operations for modular multiplication on constrained devices. Our implementation requires only 2888 cycles for the modular multiplication of 192-bit integers and outperforms the previous best result for modular multiplication over P-192 by a factor of 17%. In addition, our modular multiplication is even faster than the Karatsuba multiplication (without reduction) which achieved a speed record for multiplication on AVR processor. Dong-won Park, Seokhie Hong, Nam Su Chang, Sung Min Cho |
J. Supercomput. | 2 |
| 2020 | New Hybrid Method for Isogeny-Based Cryptosystems Using Edwards CurvesabstractAlong with the resistance against quantum computers, isogeny-based cryptography offers attractive cryptosystems due to small key sizes and compatibility with the current elliptic curve primitives. While the state-of-the-art implementation uses Montgomery curves, which facilitates efficient elliptic curve arithmetic and isogeny computations, other forms of elliptic curves can be used to produce an efficient result. In this paper, we present the new hybrid method for isogeny-based cryptosystem using Edwards curves. Unlike the previous hybrid methods, we exploit Edwards curves for recovering the curve coefficients and Montgomery curves for other operations. To this end, we first carefully examine and compare the computational cost of Montgomery and Edwards isogenies. Then, we fine-tune and tailor Edwards isogenies in order to blend with Montgomery isogenies efficiently. Additionally, we present the implementation results of Supersingular Isogeny Diffie-Hellman (SIDH) key exchange using the proposed method. We demonstrate that our method outperforms the previously proposed hybrid method, and is as fast as Montgomery-only implementation. Our results show that proper use of Edwards curves for isogeny-based cryptosystem can be quite practical. Suhri Kim, Kisoon Yoon, Jihoon Kwon, Young-Ho Park 0001, Seokhie Hong |
IEEE Trans. Inf. Theory | 5 |
| 2019 | Optimized Method for Computing Odd-Degree Isogenies on Edwards Curves
Suhri Kim, Kisoon Yoon, Young-Ho Park 0001, Seokhie Hong |
ASIACRYPT (2) | 4 |
| 2018 | Low complexity bit-parallel multiplier for F2n defined by repeated polynomials
Nam Su Chang, Eun Sook Kang, Seokhie Hong |
Discret. Appl. Math. | 3 |
| 2018 | Efficient Isogeny Computations on Twisted Edwards CurvesabstractThe isogeny-based cryptosystem is the most recent category in the field of postquantum cryptography. However, it is widely studied due to short key sizes and compatibility with the current elliptic curve primitives. The main building blocks when implementing the isogeny-based cryptosystem are isogeny computations and point operations. From isogeny construction perspective, since the cryptosystem moves along the isogeny graph, isogeny formula cannot be optimized for specific coefficients of elliptic curves. Therefore, Montgomery curves are used in the literature, due to the efficient point operation on an arbitrary elliptic curve. In this paper, we propose formulas for computing 3 and 4 isogenies on twisted Edwards curves. Additionally, we further optimize our isogeny formulas on Edwards curves and compare the computational cost of Montgomery curves. We also present the implementation results of our isogeny computations and demonstrate that isogenies on Edwards curves are as efficient as those on Montgomery curves. Suhri Kim, Kisoon Yoon, Jihoon Kwon, Seokhie Hong, Young-Ho Park 0001 |
Secur. Commun. Networks | 4 |
| 2018 | RCB: leakage-resilient authenticated encryption via re-keying
Megha Agrawal, Tarun Kumar Bansal, Donghoon Chang, Amit Kumar Chauhan, Seokhie Hong, Jinkeon Kang, Somitra Kumar Sanadhya |
J. Supercomput. | 5 |
| 2018 | An efficient implementation of pairing-based cryptography on MSP430 processor
Jihoon Kwon, Seog Chung Seo, Seokhie Hong |
J. Supercomput. | 3 |
| 2018 | Correction to: An efficient implementation of pairing-based cryptography on MSP430 processor
Jihoon Kwon, Seog Chung Seo, Seokhie Hong |
J. Supercomput. | 3 |
| 2016 | Binary decision diagram to design balanced secure logic stylesabstractEmbedded implementations of cryptographic algorithms require countermeasures against side-channel attacks (SCAs), that exploit physical variables measured during the computation. These countermeasures increase cost, power consumption and latency of the device. One class of countermeasures, hiding, consists of a balanced circuit style, including balancing of the capacitances and delays; it requires full connection to avoid memory effect that is an effect caused by repeatedly recharged energy after being only partially discharged at the internal parasitic capacitance. This paper proposes binary decision diagrams (BDDs) to derive complex pull-down networks that fulfill all these requirements while being compact at the same time; it uses sense amplifier-based logic (SABL) to obtain well-balanced pre-charge circuits. An attack based on mutual information analysis (MIA) is applied to the AES S-boxes implemented in our novel secure logic style. After the evaluation at pre-layout SPICE level, the balanced circuit with BDD leaks less information than comparable logic styles, even though the implementation area is reduced by 40.6%, the power consumption up to 46.1% and the delay by 35.2% compared to the classic SABL approach. Seokhie Hong, Bart Preneel, Ingrid Verbauwhede |
IOLTS | 2 |
| 2016 | Faster elliptic curve arithmetic for triple-base chain by reordering sequences of field operations
Sung Min Cho, Seung Gyu Gwak, Chang Han Kim, Seokhie Hong |
Multim. Tools Appl. | 4 |
| 2015 | Accelerating elliptic curve scalar multiplication over GF(2m) on graphic hardwares
Seog Chung Seo, Taehong Kim, Seokhie Hong |
J. Parallel Distributed Comput. | 3 |
| 2015 | Weakness of lightweight block ciphers mCrypton and LED against biclique cryptanalysis
Kitae Jeong, HyungChul Kang, Changhoon Lee, Jaechul Sung, Seokhie Hong, Jongin Lim 0001 |
Peer-to-Peer Netw. Appl. | 5 |
| 2014 | Formulas for cube roots in F3m using shifted polynomial basis
Young In Cho, Nam Su Chang, Seokhie Hong |
Inf. Process. Lett. | 3 |
| 2014 | Message blinding method requiring no multiplicative inversion for RSAabstractThis article proposes a new message blinding methods requiring no multiplicative inversion for RSA. Most existing message blinding methods for RSA additionally require the multiplicative inversion, even though computational complexity of this operation is O ( n 3 ) which is equal to that of the exponentiation. Thus, this additional operation is known to be the main drawback of the existing message blinding methods for RSA. In addition to requiring no additional multiplicative inversion, our new countermeasure provides the security against various power analysis attacks as well as general differential power analysis. Dong-Guk Han, Seokhie Hong, JaeCheol Ha |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2013 | Extended elliptic curve Montgomery ladder algorithm over binary fields with resistance to simple power analysis
Sung Min Cho, Seog Chung Seo, Tae Hyun Kim 0003, Young-Ho Park 0001, Seokhie Hong |
Inf. Sci. | 5 |
| 2013 | Fiat-shamir identification scheme immune to the hardware fault attacksabstractThe Fiat-Shamir identification scheme is popular for “light” consumer devices, such as smart cards, in a wide range of consumer services. However, it can be vulnerable to fault attacks, even though a cryptographic algorithm is theoretically secure. Thus, a study on cryptanalysis and countermeasures to fault attacks is crucial. This article proposes a secure and practical modification of the Fiat-Shamir identification scheme resistant against fault attacks. A straightforward protection is to check integrity of the intermediate values and outputs at each step. However, this approach may be a bottleneck of the entire scheme and are attained at the expense of increased computational overhead that is similar to the overhead of the identification scheme. The proposed scheme is designed to propagate faults induced in a target variable to other parts without conditional branches. Therefore, a relatively small overhead enables implementation of the proposed scheme in small cryptographic devices such as smart cards. Sung-Kyoung Kim, Tae Hyun Kim 0003, Seokhie Hong |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2012 | Side-channel attacks on HIGHT with reduced masked rounds suitable for the protection of multimedia computing system
Yuseop Lee, Jongsung Kim, Seokhie Hong |
Multim. Tools Appl. | 3 |
| 2012 | Related-Key Boomerang and Rectangle Attacks: Theory and Experimental AnalysisabstractIn 2004, we introduced the related-key boomerang/ rectangle attacks, which allow us to enjoy the benefits of the boomerang attack and the related-key technique, simultaneously. The new attacks were used since then to attack numerous block ciphers. While the claimed applications are significant, most of them have a major drawback. Their validity cannot be verified experimentally due to their high complexity. Together with the lack of rigorous justification of the probabilistic assumptions underlying the technique, this lead Murphy to claim that attacks using the related-key boomerang/rectangle technique are not legitimate. This paper contains two contributions. The first is a rigorous analysis of the related-key boomerang/rectangle attacks, including devising provably optimal distinguishers and computing their success rate, and discussing the underlying independence assumptions. The second contribution is an extensive experimental verification of the related-key boomerang attack against the GSM block cipher, KASUMI. Our experiments reveal that the success probability of the distinguisher, when averaged over different choices of the keys, is close to the theoretical prediction. However, the exact probability depends on the key, such that for some por- tion of the keys, the distinguisher holds with a higher probability than expected, while for the rest of the keys, the distinguisher fails completely. Jongsung Kim, Seokhie Hong, Bart Preneel, Eli Biham, Orr Dunkelman, Nathan Keller |
IEEE Trans. Inf. Theory | 2 |
| 2012 | New Bit Parallel Multiplier With Low Space Complexity for All Irreducible Trinomials Over GF(2n)abstractKoç and Sunar proposed an architecture of the Mastrovito multiplier for the irreducible trinomial$f(x)=x^{n}+x^{k}+1$, where$k\neq n/2$to reduce the time complexity. Also, many multipliers based on the Karatsuba-Ofman algorithm (KOA) was proposed that sacrificed time efficiency for low space complexity. In this paper, a new multiplication formula which is a variant of KOA presented. We also provide a straightforward architecture of a non-pipelined bit-parallel multiplier using the new formula. The proposed multiplier has lower space complexity than and comparable time complexity to previous Mastrovito multipliers' for all irreducible trinomials. Young In Cho, Nam Su Chang, Chang Han Kim, Young-Ho Park 0001, Seokhie Hong |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |
| 2011 | A Fast and Provably Secure Higher-Order Masking of AES S-Box
Seokhie Hong, Jongin Lim 0001 |
CHES | 2 |
| 2011 | Fault Injection Attack on A5/3abstractIn this paper, we propose a fault injection attack on A5/3 used in GSM. This attack is based on the fault assumption in. That is, it is assumed that we can decrease the number of rounds in block cipher KASUMI of A5/3 by injecting some faults. With small number of fault injections, we can recover the session key of A5/3 supporting a 64-bit session key. This is the first known cryptanalytic result on A5/3 so far. Kitae Jeong, Yuseop Lee, Jaechul Sung, Seokhie Hong |
ISPA | 4 |
| 2011 | First-order side channel attacks on Zhang's countermeasures
Dong-Guk Han, Seokhie Hong |
Inf. Sci. | 3 |
| 2011 | An efficient CRT-RSA algorithm secure against power and fault attacks
Sung-Kyoung Kim, Tae Hyun Kim 0003, Dong-Guk Han, Seokhie Hong |
J. Syst. Softw. | 4 |
| 2010 | Side-Channel Attack Using Meet-in-the-Middle TechniqueabstractIn this paper, we introduce a new side-channel attack using block cipher cryptanalysis named a meet-in-the-middle attack. Using our new side-channel technique we show that advanced encryption standard (AES) with reduced 10 masked rounds is broken, which is faster than the exhaustive key search attack. This implies that one has to mask the entire rounds of the 12-round 192-bit key AES to prevent our attacks. Our result is the first one to analyse AES with reduced 10 masked rounds, while the previous best known side-channel attack is on AES with reduced eight masked rounds. Jongsung Kim, Seokhie Hong |
Comput. J. | 2 |
| 2009 | Security analysis of the SCO-family using key schedules
Kitae Jeong, Changhoon Lee, Jongsung Kim, Seokhie Hong |
Inf. Sci. | 4 |
| 2008 | Related-Key Chosen IV Attacks on Grain-v1 and Grain-128
Yuseop Lee, Kitae Jeong, Jaechul Sung, Seokhie Hong |
ACISP | 4 |
| 2008 | Second Preimage Attack on 3-Pass HAVAL and Partial Key-Recovery Attacks on HMAC/NMAC-3-Pass HAVAL
Eunjin Lee, Donghoon Chang, Jongsung Kim, Jaechul Sung, Seokhie Hong |
FSE | 5 |
| 2008 | Extraction of Residual Information in the Microsoft PowerPoint file from the Viewpoint of Digital Forensics considering PerCom EnvironmentabstractElectronic documents made by some application (e.g. Microsoft PowerPoint application) have traces of work like editing, and these traces exist in the format of electronic documents. In digital forensic investigation, examiners have failed to notice traces of past work. It is because of that the traces of the past work cannot be identified by its application easily. However, identifying traces of the past work is important for digital forensic investigation because this data can be essential information which is created by culprit's intention not appeared in electronic document. This paper focuses on analyzing the Microsoft PowerPoint application (version 97 ~ 2003) which has the feature that it has traces of past work. In case of Microsoft PowerPoint file, it is possible to identify traces of past work by analyzing saving algorithm of application. To detect the traces automatically, PRIX (PPT residual information extractor) tool is developed. Jungheum Park, Bora Park, Sangjin Lee 0002, Seokhie Hong, Jong Hyuk Park 0001 |
PerCom | 4 |
| 2008 | Security analysis of the full-round DDO-64 block cipher
Changhoon Lee, Jongsung Kim, Seokhie Hong, Jaechul Sung, Sangjin Lee 0002 |
J. Syst. Softw. | 3 |
| 2007 | Preimage Attack on the Parallel FFT-Hashing Function
Donghoon Chang, Moti Yung, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002 |
ACISP | 4 |
| 2007 | Related-Key Amplified Boomerang Attacks on the Full-Round Eagle-64 and Eagle-128
Kitae Jeong, Changhoon Lee, Jaechul Sung, Seokhie Hong, Jongin Lim 0001 |
ACISP | 4 |
| 2007 | Related-Key Rectangle Attacks on Reduced AES-192 and AES-256
Jongsung Kim, Seokhie Hong, Bart Preneel |
FSE | 2 |
| 2007 | Cryptanalysis of an involutional block cipher using cellular automata
Jaechul Sung, Deukjo Hong, Seokhie Hong |
Inf. Process. Lett. | 3 |
| 2006 | Forgery and Key Recovery Attacks on PMAC and Mitchell's TMAC Variant
Changhoon Lee, Jongsung Kim, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002 |
ACISP | 4 |
| 2006 | HIGHT: A New Block Cipher Suitable for Low-Resource Device
Deukjo Hong, Jaechul Sung, Seokhie Hong, Jongin Lim 0001, Sangjin Lee 0002, Bonseok Koo, Changhoon Lee, Donghoon Chang, Jesang Lee, Kitae Jeong, Jongsung Kim, Seongtaek Chee |
CHES | 3 |
| 2006 | A New Dedicated 256-Bit Hash Function: FORK-256
Deukjo Hong, Donghoon Chang, Jaechul Sung, Sangjin Lee 0002, Seokhie Hong, Jesang Lee, Dukjae Moon, Sungtaek Chee |
FSE | 5 |
| 2006 | Provable Security for an RC6-like Structure and a MISTY-FO-like Structure Against Differential Cryptanalysis
Changhoon Lee, Jongsung Kim, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002 |
ICCSA (3) | 4 |
| 2006 | Known-IV, Known-in-Advance-IV, and Replayed-and-Known-IV Attacks on Multiple Modes of Operation of Block Ciphers
Deukjo Hong, Seokhie Hong, Wonil Lee, Sangjin Lee 0002, Jongin Lim 0001, Jaechul Sung, Okyeon Yi |
J. Cryptol. | 2 |
| 2005 | Related-Key Rectangle Attacks on Reduced Versions of SHACAL-1 and AES-192
Seokhie Hong, Jongsung Kim, Sangjin Lee 0002, Bart Preneel |
FSE | 1 |
| 2005 | Related-Key Differential Attacks on Cobra-H64 and Cobra-H128
Changhoon Lee, Jongsung Kim, Jaechul Sung, Seokhie Hong, Sangjin Lee 0002, Dukjae Moon |
IMACC | 4 |
| 2004 | The Related-Key Rectangle Attack - Application to SHACAL-1
Jongsung Kim, Guil Kim, Seokhie Hong, Sangjin Lee 0002, Dowon Hong |
ACISP | 3 |
| 2004 | Related Key Differential Cryptanalysis of Full-Round SPECTR-H64 and CIKS-1
Youngdai Ko, Changhoon Lee, Seokhie Hong, Sangjin Lee 0002 |
ACISP | 3 |
| 2004 | Differential-Linear Type Attacks on Reduced Rounds of SHACAL-2
YongSup Shin, Jongsung Kim, Guil Kim, Seokhie Hong, Sangjin Lee 0002 |
ACISP | 4 |
| 2004 | Related Key Differential Attacks on 27 Rounds of XTEA and Full-Round GOST
Youngdai Ko, Seokhie Hong, Wonil Lee, Sangjin Lee 0002, Ju-Sung Kang |
FSE | 2 |
| 2002 | Amplified Boomerang Attack against Reduced-Round SHACAL
Jongsung Kim, Dukjae Moon, Wonil Lee, Seokhie Hong, Sangjin Lee 0002, Seok Won Jung |
ASIACRYPT | 4 |
| 2002 | Provable security for 13 round Skipjack-like structure
Seokhie Hong, Jaechul Sung, Sangjin Lee 0002, Jongin Lim 0001, Jongsu Kim |
Inf. Process. Lett. | 1 |
| 2001 | Known-IV Attacks on Triple Modes of Operation of Block Ciphers
Deukjo Hong, Jaechul Sung, Seokhie Hong, Wonil Lee, Sangjin Lee 0002, Jongin Lim 0001, Okyeon Yi |
ASIACRYPT | 3 |
| 2000 | A Proposal of a New Public Key Cryptosystem Using Matrices over a Ring
Heajoung Yoo, Seokhie Hong, Sangjin Lee 0002, Jongin Lim 0001, Okyeon Yi, Maenghee Sung |
ACISP | 2 |
| 2000 | Provable Security for the Skipjack-like Structure against Differential Cryptanalysis and Linear Cryptanalysis
Jaechul Sung, Sangjin Lee 0002, Jongin Lim 0001, Seokhie Hong, Sangjoon Park |
ASIACRYPT | 4 |
| 2000 | Provable Security against Differential and Linear Cryptanalysis for the SPN Structure
Seokhie Hong, Sangjin Lee 0002, Jongin Lim 0001, Jaechul Sung, Dong Hyeon Cheon, Inho Cho |
FSE | 1 |