Alexander Maximov

dblp:45/4666 · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
2since 2021 · last 2021
0009-0007-5103-199XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 2 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2021 Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier, Hirotaka Yoshida
CANS3
2021 SNOW-Vi: an extreme performance variant of SNOW-V for lower grade CPUs
abstract
SNOW 3G is a stream cipher used as one of the standard algorithms for data confidentiality and integrity protection over the air interface in the 3G and 4G mobile communication systems. SNOW-V is a recent new version that was proposed as a candidate for inclusion in the 5G standard. In this paper, we propose a faster variant of SNOW-V, called SNOW-Vi, that can reach the targeted speeds for 5G in a software implementation on a larger variety of CPU architectures. SNOW-Vi differs in the way how the LFSR is updated and also introduces a new location of the tap T2 for stronger security, while everything else is kept the same as in SNOW-V. The throughput in a software environment is increased by around 50% in average, up to 92 Gbps. This makes the applicability of the cipher much wider and more use cases are covered. The security analyses previously done for SNOW-V are not affected in most aspects, and SNOW-Vi provides the same 256-bit security level as SNOW-V.
Patrik Ekdahl, Alexander Maximov, Thomas Johansson 0001, Jing Yang 0025
WISEC2
2008 New State Recovery Attack on RC4
Alexander Maximov, Dmitry Khovratovich
CRYPTO1
2007 A Linear Distinguishing Attack on Scream
abstract
A linear distinguishing attack on the stream cipher Scream is proposed. When the keystream is of length 298words, the distinguisher has a detectable advantage. When the keystream length is around 2120the advantage is very close to 1. This shows certain weaknesses of Scream. In the process, the paper introduces new general ideas on how to improve the performance of linear distinguishing attacks on stream ciphers.
Alexander Maximov, Thomas Johansson 0001
IEEE Trans. Inf. Theory1
2006 Cryptanalysis of the "Grain" family of stream ciphers
abstract
Let us have an NLFSR with the feedback function g(x) and an LFSR with the generating polynomial f(x). The function g(x) is a Boolean function on the state of the NLFSR and the LFSR, at any time instance t. Whenever the LFSR has good statistical properties, it is used for controlling the randomness of the NLFSR's state machine. In this paper we define and study the general class of "Grain" family of stream ciphers, where the keystream bits are generated by another Boolean function h(y) on the states of the NLFSR and the LFSR. We show that the cryptographic strength of this family is related to the general decoding problem, when a key-recovering attack is considered. A proper choice of the functions f(·), g(·) and h(·) could, potentially, give us a strong instance of a stream cipher. One of such stream ciphers Grain was recently proposed as a candidate for the European project ECRYPT in May, 2005. Grain uses the secret key of length 80 bits and its internal state is of size 160 bits. It was suggested as a fast and small primitive for efficient hardware implementation. In our work we propose the analysis of such structures in general, and, in particular, we give a linear distinguishing attack on Grain with time complexity O(254), when O(251) bits of the keystream is available. This is the first paper presenting an attack on Grain, and it reveals a leakage in the choice of the functions in this particular design instance.
Alexander Maximov
AsiaCCS1
2006 Cryptanalysis of Grain
Côme Berbain, Henri Gilbert, Alexander Maximov
FSE3
2006 A Stream Cipher Proposal: Grain-128
abstract
A new stream cipher, Grain-128, is proposed. The design is very small in hardware and it targets environments with very limited resources in gate count, power consumption, and chip area. Grain-128 supports key size of 128 bits and IV size of 96 bits. The design is very simple and based on two shift registers, one linear and one nonlinear, and an output function
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier
ISIT3
2005 Fast Computation of Large Distributions and Its Cryptographic Applications
Alexander Maximov, Thomas Johansson 0001
ASIACRYPT1
2005 Two Linear Distinguishing Attacks on VMPC and RC4A and Weakness of RC4 Family of Stream Ciphers
Alexander Maximov
FSE1
2004 On Linear Approximation of Modulo Sum
Alexander Maximov
FSE1