Yu Sasaki 0001

dblp:46/2899 · DBLP profile ↗
← Back
98ranked-venue papers
28as first author
19since 2021 · last 2026
0000-0002-1273-2394ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 96 · 27 first-author · 19 since 2021Systems, architecture and hardware · 1 · 1 first-authorTheory of computation · 1
YearPublicationVenuePosition
2026 Related-Key Cryptanalysis of FUTURE - The Full Round Distinguishing Attack
Amit Jana, Smita Das, Ayantika Chatterjee, Debdeep Mukhopadhyay, Yu Sasaki 0001
ACNS (3)5
2026 Tight Multi-user Security of CCM and Enhancement by Tag-Based Key Derivation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ACNS (1)2
2026 Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CRYPTO (6)7
2026 Generic Committing Attacks - Zero-Padded Ascon is Less Secure than Expected
Nilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki 0001, Patrick Struck, Maximiliane Weishäupl
CRYPTO (6)4
2026 AESpoly: Symmetric-Key Cryptographic Designs Using Instruction-Level Parallelism Between AES and Polynomial Hash
Yukihito Hiraga, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
SP3
2025 Beyond-Birthday-Bound Security with HCTR2: Cascaded Construction and Tweak-Based Key Derivation
Yu Long Chen, Yukihito Hiraga, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ASIACRYPT (1)5
2025 Cryptographic Treatment of Key Control Security - In Light of NIST SP 800-108
Ritam Bhaumik, Avijit Dutta, Akiko Inoue, Tetsu Iwata, Ashwin Jha 0001, Kazuhiko Minematsu, Mridul Nandi, Yu Sasaki 0001, Meltem Sönmez Turan, Stefano Tessaro
CRYPTO (5)8
2025 The Exact Multi-User Security of Key-Alternating Feistel Ciphers with a Single Permutation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CRYPTO (5)2
2025 The Multi-user Security of GCM-SST and Further Enhancements
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ISC2
2025 Breaking the Twinkle Authenticated Encryption Scheme and Analyzing Its Underlying Permutation
Debasmita Chakraborty, Hosein Hadipour, Anup Kumar Kundu, Mostafizar Rahman, Prathamesh Ram, Yu Sasaki 0001, Dilip Sau
SAC6
2024 KIVR: Committing Authenticated Encryption Using Redundancy and Application to GCM, CCM, and More
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ACNS (1)2
2024 The Exact Multi-user Security of 2-Key Triple DES
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CT-RSA2
2024 The Exact Multi-user Security of (Tweakable) Key Alternating Ciphers with a Single Permutation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
EUROCRYPT (1)2
2023 Permutation-Based Deterministic Authenticated Encryption with Minimum Memory Size
Yukihito Hiraga, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ISC3
2022 The Multi-User Security of Triple Encryption, Revisited: Exact Security, Strengthening, and Application to TDES
abstract
We study the security of triple encryption in the multi-user setting with its application to Triple DES (TDES) in mind. Although depreciation of TDES is a global trend, the migration will take the next decade, considering the billions of TDES hardware the industry has invested so far. The multi-user security captures the reality of practical systems with multiple users, substantially impacts security, and is already considered in practical protocols such as TLS 1.3. The best multi-user lower bound of TDES is 43-(3/2) \cdot łog_2 u bits with u users, which is tractable with a standard PC and is unacceptably low. We devise a new proof to improve the multi-user security and show its tightness by giving a concrete attack. The new bound with the TDES parameters is 79-(1/2) \cdot łog_2 u bits. We also propose TEFX that strengthens triple encryption with the FX construction while preserving the compatibility with legacy hardware. TDES with TEFX achieves the multi-user security of 114-(1/2) \cdot łog_2 q bits with q TEFX calls: it achieves 84.5 bits with 2^40 users and 2^21 TEFX calls for each user, which is comparable to that of AES (128-40=88 bits).
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001, Kan Yasuda
CCS2
2022 Secret Can Be Public: Low-Memory AEAD Mode for High-Order Masking
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
CRYPTO (3)2
2021 Double-Block-Length Hash Function for Minimum Memory Size
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
ASIACRYPT (3)2
2021 Quantum Collision Attacks on Reduced SHA-256 and SHA-512
Akinori Hosoyamada, Yu Sasaki 0001
CRYPTO (1)2
2021 Designing S-Boxes Providing Stronger Security Against Differential Cryptanalysis for Ciphers Using Byte-Wise XOR
Yosuke Todo, Yu Sasaki 0001
SAC2
2020 Lesamnta-LW Revisited: Improved Security Analysis of Primitive and New PRF Mode
Shoichi Hirose, Yu Sasaki 0001, Hirotaka Yoshida
ACNS (1)2
2020 Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer
CRYPTO (3)9
2020 Lightweight Authenticated Encryption Mode Suitable for Threshold Implementation
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001
EUROCRYPT (2)2
2020 Finding Hash Collisions with Quantum Computers by Using Differential Trails with Smaller Probability than Birthday Bound
Akinori Hosoyamada, Yu Sasaki 0001
EUROCRYPT (2)2
2020 A Practical Forgery Attack on Lilliput-AE
Orr Dunkelman, Nathan Keller, Eran Lambooij, Yu Sasaki 0001
J. Cryptol.4
2020 Quantum algorithm for the multicollision problem
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa
Theor. Comput. Sci.2
2019 Related-Key Boomerang Attacks on GIFT with Automated Trail Search Including BCT Effect
Yunwen Liu, Yu Sasaki 0001
ACISP2
2019 Cryptanalysis of ForkAES
Subhadeep Banik, Jannis Bossert, Amit Jana, Eik List, Stefan Lucks, Willi Meier, Mostafizar Rahman, Dhiman Saha, Yu Sasaki 0001
ACNS9
2019 Quantum Attacks Without Superposition Queries: The Offline Simon's Algorithm
Xavier Bonnetain, Akinori Hosoyamada, María Naya-Plasencia, Yu Sasaki 0001, André Schrottenloher
ASIACRYPT (1)4
2019 Correlation of Quadratic Boolean Functions: Cryptanalysis of All Versions of Full \mathsf MORUS
Danping Shi, Siwei Sun, Yu Sasaki 0001, Chaoyun Li, Lei Hu 0003
CRYPTO (2)3
2019 Quantum Chosen-Ciphertext Attacks Against Feistel Ciphers
Gembu Ito, Akinori Hosoyamada, Ryutaroh Matsumoto, Yu Sasaki 0001, Tetsu Iwata
CT-RSA4
2019 Universal Forgery and Multiple Forgeries of MergeMAC and Generalized Constructions
Tetsu Iwata, Virginie Lallemand, Gregor Leander, Yu Sasaki 0001
CT-RSA4
2019 Improved Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa
PQCrypto2
2019 Beyond Conventional Security in Sponge-Based Authenticated Encryption Modes
abstract
The Sponge function is known to achieve $$2^{c/2}$$ security, where c is its capacity. This bound was carried over to its keyed variants, such as SpongeWrap, to achieve a $$\min \{2^{c/2},2^\kappa \}$$ security bound, with $$\kappa $$ the key length. Similarly, many CAESAR competition submissions were designed to comply with the classical $$2^{c/2}$$ security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of $$\min \{2^{b/2},2^c,2^\kappa \}$$ , with $$b>c$$ the permutation size, by proving that the CAESAR submission NORX achieves this bound. The proof relies on rigorous computation of multi-collision probabilities, which may be of independent interest. We additionally derive a generic attack based on multi-collisions that matches the bound. We show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of some of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. We finally consider the remaining one of the three PRIMATEs, APE, and derive a blockwise adaptive attack in the nonce-respecting setting with complexity $$2^{c/2}$$ , therewith demonstrating that the techniques cannot be applied to APE.
Philipp Jovanovic, Atul Luykx, Bart Mennink, Yu Sasaki 0001, Kan Yasuda
J. Cryptol.4
2019 Nonlinear Invariant Attack: Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
J. Cryptol.3
2018 Related-Key Boomerang Attacks on Full ANU Lightweight Block Cipher
Yu Sasaki 0001
ACNS1
2018 Cryptanalysis of MORUS
Tomer Ashur, Maria Eichlseder, Martin M. Lauridsen, Gaëtan Leurent, Brice Minaud, Yann Rotella, Yu Sasaki 0001, Benoît Viguier
ASIACRYPT (2)7
2018 Cryptanalysis Against Symmetric-Key Schemes with Online Classical Queries and Offline Quantum Computations
Akinori Hosoyamada, Yu Sasaki 0001
CT-RSA2
2018 Boomerang Connectivity Table: A New Cryptanalysis Tool
Carlos Cid, Tao Huang 0015, Thomas Peyrin, Yu Sasaki 0001, Ling Song 0001
EUROCRYPT (2)4
2018 Cryptanalysis of Reduced sLiSCP Permutation in Sponge-Hash and Duplex-AE Modes
Yunwen Liu, Yu Sasaki 0001, Ling Song 0001, Gaoli Wang
SAC2
2018 Tight Bounds of Differentially and Linearly Active S-Boxes and Division Property of Lilliput
abstract
This paper provides security analysis of a lightweight block cipher called LILLIPUT, which was proposed in IEEE Transactions on Computers in 2015. LILLIPUT adopts an extended generalized Feistel network (EGFN). EGFN consists of non-linear, linear, and permutation layers, and the linear layer updates a part of the state only linearly, which causes several security concerns. Our first discovery is that the lower bounds of the number of differentially active S-boxes provided by the designers are incorrect. Thus the new bounds are derived by using mixed integer linear programming (MILP). We apply a two-stage search procedure introduced by Sun et al. that leads to tight bounds even for a large number of rounds. The search tool is then converted for linear cryptanalysis. With those updates, the challenging problem of evaluating LILLIPUT's security against differential and linear cryptanalysis is closed. Another contribution is the best third-party cryptanalysis. The designers expected EGFN to efficiently enhance security against integral cryptanalysis. However, security is not as enhanced as the designers expected. In fact, division property finds a 13-round distinguisher that improves on the previous distinguisher by 4 rounds. The distinguisher is further extended to a 17-round key recovery that improves on the previous best attack by 3 rounds.
Yu Sasaki 0001, Yosuke Todo
IEEE Trans. Computers1
2017 Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Keita Xagawa
ASIACRYPT (2)2
2017 GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption
Subhadeep Banik, Sumit Kumar Pandey, Thomas Peyrin, Yu Sasaki 0001, Siang Meng Sim, Yosuke Todo
CHES4
2017 New Impossible Differential Search Tool from Design and Cryptanalysis Aspects - Revealing Structural Properties of Several Ciphers
Yu Sasaki 0001, Yosuke Todo
EUROCRYPT (3)1
2017 Optimizing Online Permutation-Based AE Schemes for Lightweight Applications
Yu Sasaki 0001, Kan Yasuda
ISPEC1
2017 Rate-One AE with Security Under RUP
Shoichi Hirose, Yu Sasaki 0001, Kan Yasuda
ISC2
2016 Improved Rebound Attacks on AESQ: Core Permutation of CAESAR Candidate PAEQ
Nasour Bagheri, Florian Mendel, Yu Sasaki 0001
ACISP (2)3
2016 On the Design Rationale of Simon Block Cipher: Integral Attacks and Impossible Differential Attacks against Simon Variants
Kota Kondo, Yu Sasaki 0001, Tetsu Iwata
ACNS2
2016 A New Algorithm for the Unbalanced Meet-in-the-Middle Problem
Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (1)2
2016 Nonlinear Invariant Attack - Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001
ASIACRYPT (2)3
2016 The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim
CRYPTO (2)7
2016 Cryptanalysis of Reduced NORX
Nasour Bagheri, Tao Huang 0015, Keting Jia, Florian Mendel, Yu Sasaki 0001
FSE5
2016 New Differential Bounds and Division Property of Lilliput: Block Cipher with Extended Generalized Feistel Network
Yu Sasaki 0001, Yosuke Todo
SAC1
2016 Extended meet-in-the-middle attacks on some Feistel constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001
Des. Codes Cryptogr.4
2015 Refinements of the k-tree Algorithm for the Generalized Birthday Problem
Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (2)2
2015 How to Incorporate Associated Data in Sponge-Based Authenticated Encryption
Yu Sasaki 0001, Kan Yasuda
CT-RSA1
2015 Analysis of the CAESAR Candidate Silver
Jérémy Jean, Yu Sasaki 0001, Lei Wang 0031
SAC2
2015 A New Mode of Operation for Incremental Authenticated Encryption with Associated Data
Yu Sasaki 0001, Kan Yasuda
SAC1
2014 Memoryless Unbalanced Meet-in-the-Middle Attacks: Impossible Results and Applications
Yu Sasaki 0001
ACNS1
2014 Meet-in-the-Middle Attacks on Generic Feistel Constructions
Jian Guo 0001, Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001
ASIACRYPT (1)4
2014 Message Extension Attack against Authenticated Encryptions: Application to PANDA
Yu Sasaki 0001, Lei Wang 0031
CANS1
2014 Updates on Generic Attacks against HMAC and NMAC
Jian Guo 0001, Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031
CRYPTO (1)3
2014 An Automated Evaluation Tool for Improved Rebound Attack: New Distinguishers and Proposals of ShiftBytes Parameters for Grøstl
Yu Sasaki 0001, Yuuki Tokushige, Lei Wang 0031, Mitsugu Iwamoto, Kazuo Ohta
CT-RSA1
2014 Equivalent Key Recovery Attacks Against HMAC and NMAC with Whirlpool Reduced to 7 Rounds
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Long Wen 0002
FSE2
2014 Practical Cryptanalysis of PAES
Jérémy Jean, Ivica Nikolic, Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography3
2013 Related-Key Boomerang Attacks on KATAN32/48/64
Takanori Isobe 0001, Yu Sasaki 0001, Jiageng Chen
ACISP2
2013 Preimage Attacks on Feistel-SP Functions: Impact of Omitting the Last Network Twist
Yu Sasaki 0001
ACNS1
2013 Cryptanalysis of HMAC/NMAC-Whirlpool
Jian Guo 0001, Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004
ASIACRYPT (2)2
2013 Limited-Birthday Distinguishers for Hash Functions - Collisions beyond the Birthday Bound Can Be Meaningful
Mitsugu Iwamoto, Thomas Peyrin, Yu Sasaki 0001
ASIACRYPT (2)3
2013 Improved Single-Key Distinguisher on HMAC-MD5 and Key Recovery Attacks on Sandwich-MAC-MD5
Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography1
2013 Meet-in-the-Middle Preimage Attacks Revisited - New Results on MD5 and HAVAL
Yu Sasaki 0001, Wataru Komatsubara, Yasuhide Sakai, Lei Wang 0031, Mitsugu Iwamoto, Kazuo Sakiyama, Kazuo Ohta
SECRYPT1
2012 Improved Known-Key Distinguishers on Feistel-SP Ciphers and Application to Camellia
Yu Sasaki 0001, Sareh Emami, Deukjo Hong
ACISP1
2012 Distinguishers beyond Three Rounds of the RIPEMD-128/-160 Compression Functions
Yu Sasaki 0001, Lei Wang 0031
ACNS1
2012 Generic Related-Key Attacks for HMAC
Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031
ASIACRYPT2
2012 Investigating Fundamental Security Requirements on Whirlpool: Improved Preimage and Collision Attacks
Yu Sasaki 0001, Lei Wang 0031, Shuang Wu 0004, Wenling Wu
ASIACRYPT1
2012 Cryptanalyses on a Merkle-Damgård Based MAC - Almost Universal Forgery and Distinguishing-H Attacks
Yu Sasaki 0001
EUROCRYPT1
2012 New Truncated Differential Cryptanalysis on 3D Block Cipher
Takuma Koyama, Lei Wang 0031, Yu Sasaki 0001, Kazuo Sakiyama, Kazuo Ohta
ISPEC3
2012 Meet-in-the-Middle Technique for Integral Attacks against Feistel Ciphers
Yu Sasaki 0001, Lei Wang 0031
Selected Areas in Cryptography1
2011 Preimage Attacks on Full-ARIRANG (Poster)
Chiaki Ohtahara, Keita Okada, Yu Sasaki 0001, Takeshi Shimoyama
ACISP3
2011 (Second) Preimage Attacks on Step-Reduced RIPEMD/RIPEMD-128 with a New Local-Collision Approach
Lei Wang 0031, Yu Sasaki 0001, Wataru Komatsubara, Kazuo Ohta, Kazuo Sakiyama
CT-RSA2
2011 Meet-in-the-Middle Preimage Attacks on AES Hashing Modes and an Application to Whirlpool
Yu Sasaki 0001
FSE1
2011 Known-Key Distinguishers on 11-Round Feistel and Collision Attacks on Its Hashing Modes
Yu Sasaki 0001, Kan Yasuda
FSE1
2011 Byte Slicing Grøstl - Optimized Intel AES-NI and 8-bit Implementations of the SHA-3 Finalist Grøstl
Kazumaro Aoki, Günther Roland, Yu Sasaki 0001, Martin Schläffer
SECRYPT3
2010 Non-full-active Super-Sbox Analysis: Applications to ECHO and Grøstl
Yu Sasaki 0001, Yang Li 0001, Lei Wang 0031, Kazuo Sakiyama, Kazuo Ohta
ASIACRYPT1
2010 Preimage Attacks on Step-Reduced RIPEMD-128 and RIPEMD-160
Chiaki Ohtahara, Yu Sasaki 0001, Takeshi Shimoyama
Inscrypt2
2010 Finding Preimages of Tiger Up to 23 Steps
Lei Wang 0031, Yu Sasaki 0001
FSE2
2009 Meet-in-the-Middle Preimage Attacks on Double-Branch Hash Functions: Application to RIPEMD and Others
Yu Sasaki 0001, Kazumaro Aoki
ACISP1
2009 Preimages for Step-Reduced SHA-2
Kazumaro Aoki, Jian Guo 0001, Krystian Matusiewicz, Yu Sasaki 0001, Lei Wang 0031
ASIACRYPT4
2009 Rebound Attack on the Full Lane Compression Function
Krystian Matusiewicz, María Naya-Plasencia, Ivica Nikolic, Yu Sasaki 0001, Martin Schläffer
ASIACRYPT4
2009 Meet-in-the-Middle Preimage Attacks Against Reduced SHA-0 and SHA-1
Kazumaro Aoki, Yu Sasaki 0001
CRYPTO2
2009 Finding Preimages in Full MD5 Faster Than Exhaustive Search
Yu Sasaki 0001, Kazumaro Aoki
EUROCRYPT1
2009 Meet-in-the-Middle Attacks Using Output Truncation in 3-Pass HAVAL
Yu Sasaki 0001
ISC1
2008 Preimage Attacks on Step-Reduced MD5
Yu Sasaki 0001, Kazumaro Aoki
ACISP1
2008 Preimage Attacks on 3, 4, and 5-Pass HAVAL
Yu Sasaki 0001, Kazumaro Aoki
ASIACRYPT1
2008 A strict evaluation method on the number of conditions for the SHA-1 collision search
abstract
This paper proposes a new algorithm for evaluating the number of chaining variable conditions(CVCs) in the selecting step of a distrubance vector (DV) for the analysis of SHA-1 collision attack. The algorithm is constructed by combining the following four strategies, Strict Bit Compression, DV expansion, Precise Counting Rules in Every Step and Differential Path Confirmation for Rounds 2 to 4, that can evaluate the number of CVCs morestrictly compared with the previous approach.
Jun Yajima, Terutoshi Iwasaki, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Shimoyama, Noboru Kunihiro, Kazuo Ohta
AsiaCCS4
2008 Security of MD5 Challenge and Response: Extension of APOP Password Recovery Attack
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro
CT-RSA1
2007 A New Strategy for Finding a Differential Path of SHA-1
Jun Yajima, Yu Sasaki 0001, Yusuke Naito 0001, Terutoshi Iwasaki, Takeshi Shimoyama, Noboru Kunihiro, Kazuo Ohta
ACISP2
2007 New Message Difference for MD4
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro
FSE1
2006 Improved Collision Search for SHA-0
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Shimoyama, Jun Yajima, Noboru Kunihiro, Kazuo Ohta
ASIACRYPT2