EDBT 2026 Demo / reviewers in the wild / expert
Tomer Ashur
dblp:54/9778
· DBLP profile ↗
22ranked-venue papers
16as first author
12since 2021 · last 2026
0000-0001-6091-4857ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 13 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Generalized indifferentiable sponge and its application to Polygon Miden VM
Tomer Ashur, Amit Singh Bhati |
Des. Codes Cryptogr. | 1 |
| 2026 | The XHash family for ZK-friendly hash functions
Tomer Ashur, Amit Singh Bhati, Al Kindi, Mohammad Mahzoun, Léo Perrin, Sundas Tariq |
Des. Codes Cryptogr. | 1 |
| 2025 | A New Linear Distinguisher for Four-Round AES
Tomer Ashur, Erik Takke |
J. Cryptol. | 1 |
| 2024 | Algebraic Cryptanalysis of the HADES Design Strategy: Application to Poseidon and Poseidon2
Tomer Ashur, Thomas Buschman, Mohammad Mahzoun |
ACISP (2) | 1 |
| 2023 | A New Approach to Garbled Circuits
Anasuya Acharya, Tomer Ashur, Efrat Cohen, Carmit Hazay, Avishay Yanai |
ACNS | 2 |
| 2023 | Special Issue on Failed Approaches and Insightful Losses in Cryptology - ForewordabstractThe importance of the notion of Publish or Perish for academic research is indisputable. This message, cynical as it may sound, guides students and researchers alike in planning their career path, and as a consequence shapes scientific progress as a whole. Opting for rational behavior, many researchers choose to work on topics that are uncontroversial, incremental and easily published, and stay away from riskier areas. Yet science, as the reader surely knows, advances most through adversity and failure. CFail, The Conference for Failed Approaches and Insightful Losses in Cryptology, has since 2019 been a venue for the cryptography community to share scientific progress that has not come to fruition in the traditional sense. Encouraged by the high engagement and positive feedback, the CFail 2021 team sought to better align the conference’s vision with traditional academic incentives. Partnering with The Computer Journal, authors of eligible submissions to the conference were invited to submit a full version of their work to be considered for inclusion in a special issue. Tomer Ashur, Chris J. Mitchell |
Comput. J. | 1 |
| 2023 | How Not To Design An Efficient FHE-Friendly Block Cipher: SeljukabstractAbstract With the rapid increase in the practical applications of secure computation protocols, increasingly more research is focused on the efficiency of the symmetric-key primitives underlying them. Whereas traditional block ciphers have evolved to be efficient with respect to certain performance metrics, secure computation protocols call for a different efficiency metric: arithmetic complexity. Arithmetic complexity is viewed through the number and layout of nonlinear operations in the circuit implemented by the protocol. Symmetric-key algorithms that are optimized for this metric are said to be algebraic ciphers. It has been shown that recently proposed algebraic ciphers are greatly efficient in ZK and MPC protocols. However, there has not been many algebraic ciphers proposed targeting Fully Homomorphic Encryption (FHE). In this paper, we evaluate the behavior of Vision when implemented as a circuit in an FHE protocol. To this end, we present a state-of-the-art comparison of AES and Vision implemented using HElib. Counterintuitively, Vision does not deliver a better performance than AES in this setting. Then, by attempting to improve a bottleneck of the FHE implementation evaluating Vision we present a new cipher: Seljuk. Despite the improvement with respect to Vision, Seljuk does not deliver the expected performance. Tomer Ashur, Mohammad Mahzoun, Dilara Toprakhisar |
Comput. J. | 1 |
| 2022 | Chaghri - A FHE-friendly Block CipherabstractThe Recent progress in practical applications of secure computation protocols has also attracted attention to the symmetric-key primitives underlying them. Whereas traditional ciphers have evolved to be efficient with respect to certain performance metrics, advanced cryptographic protocols call for a different focus. The so called arithmetic complexity is viewed through the number and layout of non-linear operations in the circuit implemented by the protocol. Symmetric-key algorithms that are optimized with respect to this metric are said to be algebraic ciphers. Previous work targeting ZK and MPC protocols delivered great improvement in the performance of these applications both in lab and in practical use. Interestingly, despite its apparent benefits to privacy-aware cloud computing, algebraic ciphers targeting FHE did not attract similar attention. Tomer Ashur, Mohammad Mahzoun, Dilara Toprakhisar |
CCS | 1 |
| 2022 | Differential Cryptanalysis of K-CipherabstractK-Cipher is an ultra low latency block cipher with variable-length parameters designed by Intel Labs. In this work, we analyze the security of K-Cipher and propose a differential cryptanalysis attack with the complexity of$2^{29.7}$for a variant of K-Cipher with state size$n=24$bits state and block size$m=8$bits. Our attack recovers the secret key and secret randomizer values with a total length of 240 bits in$\sim 30$minutes on a standard desktop machine. We show that it is possible to extend the same attack for an arbitrary set of parameters. Mohammad Mahzoun, Liliya Kraleva, Raluca Posteuca, Tomer Ashur |
ISCC | 4 |
| 2022 | On the Effect of the Key-Expansion Algorithm in Simon-like CiphersabstractAbstract In this work, we investigate how the choice of the key-expansion algorithm and its interaction with the round function affect the resistance of Simon-like ciphers against rotational-XOR cryptanalysis. We observe that, among the key-expansion algorithms we consider, Simon is most resistant, while Simeck is much less so. Implications on lightweight ciphers design are discussed and open questions are proposed. Jinyu Lu, Yunwen Liu, Tomer Ashur, Chao Li 0002 |
Comput. J. | 3 |
| 2022 | Improved rotational-XOR cryptanalysis of Simon-like block ciphersabstractAbstract Rotational‐XOR (RX) cryptanalysis is a cryptanalytic method aimed at finding distinguishable statistical properties in Addition‐Rotation‐XOR‐C ciphers, that is, ciphers that can be described only by using modular addition, cyclic rotation, XOR and the injection of constants. In this study, we extend RX‐cryptanalysis to AND‐RX ciphers, a similar design paradigm where the modular addition is replaced by vectorial bitwise AND; such ciphers include the block cipher families Simon and Simeck. We analyse the propagation of RX‐differences through AND‐RX rounds and develop a closed form formula for their expected probability. Inspired by the MILP verification model proposed by Sadeghi et al., we develop a SAT/SMT model for searching compatible RX‐characteristics in Simon‐like ciphers, that is, that there is at least one right pair of messages/keys to satisfy the RK‐characteristics. To the best of our knowledge, this is the first model that takes the RX‐difference transitions and value transitions simultaneously into account in Simon‐like ciphers. Meanwhile, we investigate how the choice of the round constants affects the resistance of Simon‐like ciphers against RX‐cryptanalysis. Finally, we show how to use an RX‐distinguisher for a key recovery attack. Evaluating our model we find compatible RX‐characteristics of up to 20, 27 and 34 rounds with respective probabilities of 2 −26 , 2 −44 and 2 −56 for versions of Simeck with block sizes of 32, 48 and 64 bits, respectively, for large classes of weak keys in the related‐key model. In most cases, these are the longest published distinguishers for the respective variants of Simeck. In the case of Simon, we present compatible RX‐characteristics for round‐reduced versions of all 10 instances. We observe that for equal block and key sizes, the RX‐distinguishers cover fewer rounds in Simon than in Simeck. Concluding the paper, we present a key recovery attack on Simeck 64 reduced to 28 rounds using a 23‐round RX‐characteristic. Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002 |
IET Inf. Secur. | 3 |
| 2022 | Structural and Statistical Analysis of Multidimensional Linear Approximations of Random Functions and PermutationsabstractThe goal of this paper is to investigate linear approximations of random functions and permutations. Our motivation is twofold. First, before the distinguishability of a practical cipher from an ideal one can be analysed, the cryptanalyst must have an accurate understanding of the statistical behaviour of the ideal cipher. Secondly, this issue has been neglected both in old and in more recent studies, particularly when multiple linear approximations are being used simultaneously. Traditional models have been based on the average behaviour and simplified using other assumptions such as independence of the linear approximations. Multidimensional cryptanalysis was introduced to avoid making artificial assumptions about statistical independence of linear approximations. On the other hand, it has the drawback of including many trivial approximations that do not contribute to the attack but just cause a waste of time and memory. We show for the first time in this paper that the trivial approximations reduce the degree of freedom of the related χ2 distribution. Previously, the affine linear cryptanalysis was proposed to allow removing trivial approximations and, at the same time, admitting a solid statistical model. In this paper, we identify another type of multidimensional linear approximation, called Davies-Meyer approximation, which has similar advantages, and present full statistical models for both the affine and the Davies-Meyer type of multidimensional linear approximations. The new models given in this paper are realistic, accurate and easy to use. They are backed up by standard statistical tools such as Pearson’s χ2 test and finite population correction and demonstrated to work accurately using practical examples. Tomer Ashur, Kaisa Nyberg |
IEEE Trans. Inf. Theory | 1 |
| 2020 | Rotational-XOR Cryptanalysis of Simon-Like Block Ciphers
Jinyu Lu, Yunwen Liu, Tomer Ashur, Bing Sun 0001, Chao Li 0002 |
ACISP | 3 |
| 2020 | Rotational Cryptanalysis on MAC Algorithm Chaskey
Liliya Kraleva, Tomer Ashur, Vincent Rijmen |
ACNS (1) | 2 |
| 2020 | Revisiting the Wrong-Key-Randomization Hypothesis
Tomer Ashur, Tim Beyne, Vincent Rijmen |
J. Cryptol. | 1 |
| 2018 | Cryptanalysis of MORUS
Tomer Ashur, Maria Eichlseder, Martin M. Lauridsen, Gaëtan Leurent, Brice Minaud, Yann Rotella, Yu Sasaki 0001, Benoît Viguier |
ASIACRYPT (2) | 1 |
| 2017 | A Privacy-Preserving Device Tracking System Using a Low-Power Wide-Area Network
Tomer Ashur, Jeroen Delvaux, Sanghan Lee, Pieter Maene, Eduard Marin, Svetla Nikova, Oscar Reparaz, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Bart Preneel |
CANS | 1 |
| 2017 | Boosting Authenticated Encryption Robustness with Minimal Modifications
Tomer Ashur, Orr Dunkelman, Atul Luykx |
CRYPTO (3) | 1 |
| 2016 | Damaging, Simplifying, and Salvaging p-OMD
Tomer Ashur, Bart Mennink |
ISC | 1 |
| 2013 | A Practical Related-Key Boomerang Attack for the Full MMB Block Cipher
Tomer Ashur, Orr Dunkelman |
CANS | 1 |
| 2013 | On the anonymity of Israel's general electionsabstractThis work presents an attack on the privacy of some voting systems. We show that by combining information from several sources, some of it publicly available, and some of it can be easily collected ad-hoc, an adversary can greatly reduce the size of a voter's anonymity set. In many cases the obtained information is sufficient to deduce the content of a vote (or approximate a small set of possible values). Tomer Ashur, Orr Dunkelman |
CCS | 1 |
| 2011 | Linear Analysis of Reduced-Round CubeHash
Tomer Ashur, Orr Dunkelman |
ACNS | 1 |