Tsutomu Matsumoto

dblp:58/4020 · DBLP profile ↗
← Back
47ranked-venue papers
12as first author
13since 2021 · last 2025
0000-0002-7965-4888ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 7 first-author · 8 since 2021Artificial intelligence and machine learning · 5 · 2 first-authorHuman-computer interaction and ubiquitous computing · 4 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 3 · 1 since 2021Computer networks · 3 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2025 Uncovering Suspicious Posts on Abandoned Blogs
abstract
As the Internet evolves, the diversification of information dissemination has led to the growth of various social media platforms and an increase in abandoned blogs. These abandoned blogs, if not properly managed, present a significant security risk. In this study, we introduce “Zombified Blogs,” defined as blogs deserted by their administrators and targeted for continuous submissions of unsolicited malicious content. We explore the causes and effects of this global phenomenon on a large scale, using data from multiple blog services over the past 18 years for the first time. To this end, we propose an innovative method for the continuous identification and collection of Zombified Blogs using a search engine. We analyzed data spanning 18 years, encompassing approximately 1.5 million blog posts, including 258, 547 malicious posts, across 1,141 Zombified Blogs on six different blog services. Our findings show a significant rise in malicious posts, primarily social engineering attacks, over the past four years on previously active blogs. We identify the email posting function as a critical area exploited by attackers, leading to the unintended posting of content. Finally, we provide an overview of the current challenges facing blog services and administrators, and discuss potential content management solutions.
Hiroki Nakano, Takashi Koide, Daiki Chiba 0001, Katsunari Yoshioka, Tsutomu Matsumoto
ICC5
2025 Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service
Takayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Simon Edward Parkin, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
USENIX Security Symposium7
2024 Customized Malware: Identifying Target Systems Using Personally Identifiable Information
abstract
Given the increasing popularity of sandbox analysis, malware authors have adapted sandbox evasion functionalities into modern malware. In addition, attackers can create Customized Malware that hide their malicious payload until the identifier of the target-specific system can be verified. In this paper, we propose an attack scenario in which adversaries can leverage publicly available personally identifiable information present in the target system as specific identifiers. The proposed attack scenario can be used in targeted attacks, especially against hosts that store business email addresses on personal computers (PCs). We investigated a set of desktop applications and specified 18 popular applications that store email addresses in their related files or directories. We also implemented a survey tool to access these applications and record whether email addresses were found. We then asked nine laboratory members and staff if the target-specific email address was found and if we could extract the same email address from each PC with 16 applications. Finally, we implemented a dummy malware sample that searches for the target host's email address from the executing environment and denies unpacking the malicious payload if the mark does not exist. The experiment results demonstrate that two modern mal ware security appliances did not detect the prototype sample. To defend against the proposed attack, we discuss countermeasures from both the sandbox and user perspective. We contacted security vendors to allow them to prepare for such attacks and provided POC programs.
Rui Tanabe, Yuta Inoue, Daigo Ichikawa, Takahiro Kasama, Katsunari Yoshioka, Tsutomu Matsumoto
COMPSAC7
2024 VT-SOS: A Cost-effective URL Warning utilizing VirusTotal as a Second Opinion Service
abstract
The menace of malicious websites, such as online scams or phishing, has exhibited a noteworthy surge. While URL-based blocklists are still used as the primary security solution, previous studies show that the range of protection provided by these lists has little overlap, and the demand to have a second opinion is growing. In this paper, we design a system that aggregates information from multiple security engines in VirusTotal and warns users with malicious URLs that a single antivirus product would dismiss. We introduce VT-SOS, a system utilizing VirusTotal to provide a Second Opinion. Using 47 days of web access logs of real users, we implemented VT-SOS and evaluated effectiveness, affordability, and usability. By simulation, we show that VT-SOS could warn more than 100 users/day and provide a second opinion for more than 30 URLs/day even under a tight budget. We compared VT-SOS with three popular security services and confirmed that it could cover a wider range of malicious websites than those services. By investigating the worst-case user with the most access and warning, we demonstrate that VT-SOS will not deeply affect user experience in practice.
Kyohei Takao, Chika Hiraishi, Rui Tanabe, Kazuki Takada, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
NOMS10
2024 Who Left the Door Open? Investigating the Causes of Exposed IoT Devices in an Academic Network
abstract
Many studies have discovered internet-facing systems exposing services that are vulnerable to attack. These are often assumed to be misconfigured systems that are not meant to expose these services to the network, especially not in an enterprise network. In this study, we clarify the causes of the presence of IoT devices exposing Telnet and FTP in a university enterprise network. This also helps us to understand who is responsible. We scanned the network and found 185 IoT devices consisting of 30 device models exposing Telnet and 49 models exposing FTP. We sent out a security notification and a survey to device owners. The survey demonstrated that 2 out of 21 and 8 out of 41 owners intentionally enabled Telnet and FTP, respectively, on all their devices. After receiving the notification, 38 out of 47 owners said they were willing to take measures on at least one of their IoT devices. All except one of the devices of these willing owners were successfully remediated. When we investigated the manuals of the devices, we were able to confirm that there was no disclosure whatsoever of the exposed service in 15 out of 30 manuals for models with Telnet and 10 out of 49 manuals for models with FTP. We also confirmed, by combining a survey of the manufacturers with the device manuals, that 22 out of 30 and 29 out of 49 devices enabled Telnet and FTP by default, respectively. From the above results, we conclude that the presence of misconfigured devices was less driven by human errors of the owners and more by the choices of the manufacturers. The majority of owners were motivated to remediate the security risks once made aware of them.
Takayuki Sasaki, Takaya Noma, Yudai Morii, Toshiya Shimura, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
SP7
2024 High-Throughput Bilinear Pairing Processor for Server-Side FPGA Applications
abstract
This study focuses on the acceleration of cryptographic pairing operations on field-programmable gate arrays (FPGAs) for server-side applications. Previous studies on FPGA pairing implementations focused on area efficiency for embedded devices, trying to achieve maximum performance with minimal circuit resources. However, their architectures are likely to be inefficient for server-side applications, where the primary interest is maximum performance when FPGA resources are finished. Their architectures are inefficient for two reasons: low utilization of the digital signal processor (DSP) and low operation frequency. In this study, we propose a high-throughput pairing processor architecture for server-side FPGAs, taking full advantage of DSPs. First, we propose a loop-unrolled modular multiplication algorithm that is suitable for a server-side FPGA. The algorithm shows the highest throughput and area efficiency compared to algorithms from previous studies. Second, we design a pairing processor architecture that embeds the proposed modular multiplier, thus, maintaining its high throughput by supporting redundant adders and interleaved executions. We evaluate BN254 and BLS12_381 pairings on the proposed processor architecture and the evaluation results show that it achieves good throughput that is approximately two and five times faster than that from previous studies, respectively.
Junichi Sakamoto, Daisuke Fujimoto, Riku Anzai, Naoki Yoshida, Tsutomu Matsumoto
IEEE Trans. Very Large Scale Integr. Syst.5
2023 Canary in Twitter Mine: Collecting Phishing Reports from Experts and Non-experts
abstract
The rise in phishing attacks via e-mail and short message service (SMS) has not slowed down at all. The first thing we need to do to combat the ever-increasing number of phishing attacks is to collect and characterize more phishing cases that reach end users. Without understanding these characteristics, anti-phishing countermeasures cannot evolve. In this study, we propose an approach using Twitter as a new observation point to immediately collect and characterize phishing cases via e-mail and SMS that evade countermeasures and reach users. Specifically, we propose CrowdCanary, a system capable of structurally and accurately extracting phishing information (e.g., URLs and domains) from tweets about phishing by users who have actually discovered or encountered it. In our three months of live operation, CrowdCanary identified 35,432 phishing URLs out of 38,935 phishing reports, 31,960 (90.2%) of these phishing URLs were later detected by the anti-virus engine. We analyzed users who shared phishing threats by categorizing them into two groups: experts and non-experts. As a results, we discovered that CrowdCanary extracts non-expert report-specific information, like company brand name in tweets, phishing attack details from tweet images, and pre-redirect landing page information.
Hiroki Nakano, Daiki Chiba 0001, Takashi Koide, Naoki Fukushi, Takeshi Yagi, Takeo Hariu, Katsunari Yoshioka, Tsutomu Matsumoto
ARES8
2023 Signature for Objects: Formalizing How to Authenticate Physical Data and More
Ryuya Hayashi, Taiki Asano, Junichiro Hayata, Takahiro Matsuda 0002, Shota Yamada 0001, Shuichi Katsumata, Yusuke Sakai 0001, Tadanori Teruya, Jacob C. N. Schuldt, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Tsutomu Matsumoto
FC (1)13
2022 An Internet-Wide View of Connected Cars: Discovery of Exposed Automotive Devices
abstract
As the number of connected cars increases, cyber-attacks targeting them become significant risks. Especially, On-Board Equipment (OBE) that is directly accessible from the Internet can be an immediate target. However, it is not known what kind of and how many connected automotive devices can be remotely accessed from the Internet and, if compromised, become an entry point for further attacks on in-vehicle networks. In this study, we investigate the prevalence of such exposed vehicular devices. We propose a discovery method that utilizes an Internet-wide scan engine and a regular web search engine to find Internet-facing OBE. Using the proposed method, we discovered 2,532 devices of 12 different OBE products across 27 countries. We also investigated the potential cyber-attack risks against the discovered devices. 11 out of the 12 products have security concerns for remote compromises, such as running Telnet or outdated server programs. Moreover, we found that nine products have the capability to connect to the in-vehicle network. We could confirm from the information displayed in their user interface that at least two of them indeed connected to the in-vehicle network. Additionally, we noticed three products expose privacy-sensitive information such as GPS location. We believe this result provides a lower bound of the security risk of Internet-facing vehicular devices.
Takahiro Ueda, Takayuki Sasaki, Katsunari Yoshioka, Tsutomu Matsumoto
ARES4
2022 Amplification Chamber: Dissecting the Attack Infrastructure of Memcached DRDoS Attacks
Mizuki Kondo, Rui Tanabe, Natsuo Shintani, Daisuke Makita, Katsunari Yoshioka, Tsutomu Matsumoto
DIMVA6
2022 Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management Devices
abstract
Geographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device.
Takayuki Sasaki, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
SP6
2021 Adaptive Observation of Emerging Cyber Attacks targeting Various IoT Devices
Seiya Kato, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto
IM4
2021 Evaluation Framework for Performance Limitation of Autonomous Systems Under Sensor Attack
Koichi Shimizu, Daisuke Suzuki, Ryo Muramatsu, Hisashi Mori, Tomoyuki Nagatsuka, Tsutomu Matsumoto
SAFECOMP6
2020 Disposable botnets: examining the anatomy of IoT botnet infrastructure
abstract
Large botnets made up of Internet-of-Things (IoT) devices have been a steady presence in the threat landscape since 2016. Earlier research has found preliminary evidence that the IoT binaries and C&C infrastructure were only seen for very brief periods. It has not explained how attackers maintain control over their botnets. We present a more comprehensive analysis of the infrastructure of IoT botnets based on 23 months of data gathered via honeypots and the monitoring of botnet infrastructure. We collected 59,884 IoT malware samples, 35,494 download servers, and 2,747 C&C servers. We focuse on three dominant families: Bashlite, Mirai, and Tsunami. The picture that emerges is that of highly disposable botnets. IoT botnet are not so much maintained as reconstituted from scratch all the time. Not only are most binaries distributed for less than three days, the connection of bots to the rest of the botnet is also short-lived. To reach the C&C server, the binaries typically contain only a single hard-coded IP address or domain. The C&C servers themselves also have a short lifespan. Long-term dynamic analysis finds no mechanism for the attackers to migrate the bots to a new C&C server. In other words, bots are used only immediately after capture and then abandoned---perhaps to be recaptured again via the aggressive scanning practices that these botnets are known for. While IoT botnets appear less advanced than Windows-based botnets, the advantage of being disposable means that they are very resistant to blacklisting and C&C takedown. Most IP addresses are used only once and never seen again. The question that arises is how attackers source these addresses. We speculate that they might be abusing the IP address allocation practices of cloud providers.
Rui Tanabe, Tatsuya Tamai, Akira Fujita, Ryoichi Isawa, Katsunari Yoshioka, Tsutomu Matsumoto, Carlos Gañán, Michel van Eeten
ARES6
2020 How to Code Data Integrity Verification Secure Against Single-Spot-Laser-Induced Instruction Manipulation Attacks
abstract
Fault injection attacks (FIA), which cause information leakage by injecting intentional faults into the data or operations of devices, are one of the most powerful methods compromising the security of confidential data stored on these devices. Previous studies related to FIA on software report that attackers can skip instructions running on many kinds of devices through many means of fault injection. Most existing anti-FIA countermeasures on software are designed to secure against instruction skip (IS). On the other hand, recent studies report that attackers can use laser fault injection to manipulate instructions running on devices as they want. Although the previous studies show that instruction manipulation (IM) can attack the existing countermeasures against IS, no effective countermeasures against IM have been proposed yet to the best of our knowledge. In this paper, we define an attacker's model under the assumption that the attacker injects IM using a single-spot laser, and propose a coding method to verify data integrity secure against the assumed IM model in ARM 16-bit Thumb instruction set.
Junichi Sakamoto, Shungo Hayashi, Daisuke Fujimoto, Tsutomu Matsumoto
AICCSA4
2020 It Never Rains but It Pours: Analyzing and Detecting Fake Removal Information Advertisement Sites
Takashi Koide, Daiki Chiba 0001, Mitsuaki Akiyama, Katsunari Yoshioka, Tsutomu Matsumoto
DIMVA5
2019 Detect Me If You... Oh Wait. An Internet-Wide View of Self-Revealing Honeypots
Shun Morishita, Takuya Hoizumi, Wataru Ueno, Rui Tanabe, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
IM8
2018 Evasive Malware via Identifier Implanting
abstract
To cope with the increasing number of malware attacks that organizations face, anti-malware appliances and sandboxes have become an integral security defense. In particular, appliances have become the de facto standard in the fight against targeted attacks. Yet recent incidents have demonstrated that malware can effectively detect and thus evade sandboxes, resulting in an ongoing arms race between sandbox developers and malware authors. We show how attackers can escape this arms race with what we call customized malware , i.e., malware that only exposes its malicious behavior on a targeted system. We present a web-based reconnaissance strategy, where an actor leaves marks on the target system such that the customized malware can recognize this particular system in a later stage, and only then exposes its malicious behavior. We propose to implant identifiers into the target system, such as unique entries in the browser history, cache, cookies, or the DNS stub resolver cache. We then prototype a customized malware that searches for these implants on the executing environment and denies execution if implants do not exist as expected. This way, sandboxes can be evaded without the need to detect artifacts that witness the existence of sandboxes or a real system environment. Our results show that this prototype remains undetected on commercial malware security appliances, while only exposing its real behavior on the targeted system. To defend against this novel attack, we discuss countermeasures and a responsible disclosure process to allow appliances vendors to prepare for such attacks.
Rui Tanabe, Wataru Ueno, Kou Ishii, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Christian Rossow
DIMVA5
2016 Attribute Based Encryption with Direct Efficiency Tradeoff
Nuttapong Attrapadung, Goichiro Hanaoka, Tsutomu Matsumoto, Tadanori Teruya, Shota Yamada 0001
ACNS3
2016 SandPrint: Fingerprinting Malware Sandboxes to Provide Intelligence for Sandbox Evasion
Akira Yokoyama, Kou Ishii, Rui Tanabe, Yinmin Papa, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Michael Brengel, Michael Backes 0001, Christian Rossow
RAID6
2016 ASIC implementation of random number generators using SR latches and its evaluation
abstract
A true random number generator (TRNG) is proposed and evaluated by field-programmable gate arrays (FPGA) implementation that generates random numbers by exclusive-ORing (XORing) the outputs of many SR latches (Hata and Ichikawa, IEICE Trans. Inf. Syst. E95-D(2):426–436, 2012). This enables compact implementation and generates high-entropy random numbers. In this paper, we fabricate and evaluate 39 TRNGs using SR latches on 0.18 μ m ASICs. Random numbers are generated by XORing the outputs of 256 SR latches. Our TRNGs pass the SP800-90B health tests and the AIS20/31 statistical tests in changing temperatures (from −20 to 60 °C) and voltages (1.80 ± 0.15 V). We also perform an independent and identically distributed (IID) test and calculate min-entropy according to the SP800-90B. With these tests, we are able to confirm that our TRNGs are highly robust against environmental stress. The power consumption and circuit scale of our TRNGs are 0.27 mW and 1240.5 gates, respectively. Our TRNGs that use SR latches are small enough to be implemented in embedded devices.
Naoya Torii, Hirotaka Kokubo, Dai Yamamoto, Kouichi Itoh, Masahiko Takenaka, Tsutomu Matsumoto
EURASIP J. Inf. Secur.6
2012 A Method of Preventing Unauthorized Data Transmission in Controller Area Network
abstract
There is a strong demand for the security of Controller Area Network (CAN), a major in-vehicle network. A number of methods to detect unauthorized data transmission, such as anomaly detection and misuse detection, have already been proposed. However, all of them have no capability of preventing unauthorized data transmission itself. In this paper, we propose a novel method that realizes the prevention as well as detection. Our method can be effectively implemented with minimal changes in the current architecture of Electronic Control Unit. The method works even in a CAN with multiple buses interconnected by gateways.
Tsutomu Matsumoto, Masato Hata, Masato Tanabe, Katsunari Yoshioka, Kazuomi Oishi
VTC Spring1
2011 Self destructive tamper response for software protection
abstract
A method of creating tamper resistant software that is resistant to unauthorized modification is proposed. It utilizes a primitive that combines self-modifying based instruction camouflage and self integrity verification, and a method to construct a structure in which the multiple primitives are interlocked each other. Tamper resistant software created by the proposed method contains multiple camouflaged instructions in the object program, so that it is difficult for attacker to correctly understand the content of processing using static analysis. When attacker tries to do dynamic analysis, anti-debugging techniques prevent the attempt. The tamper resistant software, at runtime, continuously executes detecting and preventing dynamic analysis, verifying its integrity, and self-modifying itself in such a way that target of self-modifying is dynamically determined according to result of self integrity verification. If unauthorized modification is detected, then it self-modifies a part of instruction which is different from the part of camouflaged instruction to be self-modified, and executes different instructions from its original. As a result, it generates a series of unpredictable abnormal self destructive behaviors such as error or termination, so that attacker's analysis and modification are strongly disturbed. Cost of analysis is increased as the numbers of self integrity verification and instruction camouflage are increased, hence, the tamper resistance can be strengthened quantitatively.
Kazuomi Oishi, Tsutomu Matsumoto
AsiaCCS2
2008 A Design of Information System Improving Dietary Habit Based on Individual Clinical Data and Life Style
abstract
Currently, metabolic syndrome is one of the most all-too-common terms in Japan and it has been pointed out that the number of patients afflicted with lifestyle diseases such as hypertension, diabetes and hyperlipemia is rapidly growing. It takes many days to heal from lifestyle diseases completely, and prevention is the best way to keep us healthy. Furthermore it is well-known that dietary cure is one of effective methods to prevent from lifestyle diseases. This paper describes a designing and implementation of alimentary therapy assist system. The system records user's meal history and provide the user with healthy menu based on medical information, body condition, user's meal history individual taste and market price of cooking materials.
Tsutomu Matsumoto, Yasuyuki Shimada, Thimoty Teo, Shigeyasu Kawaji
CBMS1
2008 Prototyping security test objects for use with advanced biometric authentication systems
abstract
The state-of-art methodology to measure or assess security of advanced biometric authentication systems is updated.
Tsutomu Matsumoto
AsiaCCS1
2008 Unconditionally Secure Steganography Against Active Attacks
abstract
In this paper, we study unconditionally secure stegosystems against active attacks over an insecure channel in which an adversary can read and write a message. More specifically, we propose an information-theoretic model for steganography in the presence of active adversaries by extending both Simmons' and Cachin's works; and we show a generic construction of stegosystems secure against active attacks by using authenticated encryption in unconditional setting. Although the idea behind this construction is already used in different models (i.e., computational models and/or information-theoretic models with passive adversaries) of steganography, our contribution lies in showing the construction methodology provides provable and unconditional security against active adversaries.
Junji Shikata, Tsutomu Matsumoto
IEEE Trans. Inf. Theory2
2005 Method of Hiding Information in Agglutinative Language Documents Using Adjustment to New Line Positions
Osamu Takizawa, Kyoko Makino, Tsutomu Matsumoto, Hiroshi Nakagawa, Ichiro Murase
KES (3)3
2003 A study toward cognitive action with environment recognition by a learning space robot
abstract
This paper addresses an experimental system simulating a free-flying space robot, which has been constructed to study autonomous space robots. The experimental system consists of a space robot model, a frictionless table system, a computer system, and a vision sensor system. The robot model is composed of two manipulators and a satellite vehicle, and can move freely on a two-dimensional planar table, without friction, using air-bearings. The robot model has successfully performed the automatic truss structure assembly, including many jobs, e.g., manipulator berthing, component manipulation, arm trajectory control collision avoidance, assembly using force control, etc. Moreover, even if the robot fails in a task planned in advance, the robot re-plans the task by using reinforcement learning, and obtains the task goal for basically kinematic problems. But, for a class of complicated dynamic problems, the computational periods and efforts are infeasible for on-line learning. Some approaches are proposed to accelerate the learning speed, which also give models of cognitive actions and approaches to so-called a frame problem. The experiment demonstrates the possibility of the autonomous construction and the usefulness of space robots.
Kei Senda, Tsutomu Matsumoto, Yuzo Okano
ICRA2
2003 Systematic Treatment of Collusion Secure Codes: Security Definitions and Their Relations
Katsunari Yoshioka, Junji Shikata, Tsutomu Matsumoto
ISC3
2002 Gummy and Conductive Silicone Rubber Fingers
Tsutomu Matsumoto
ASIACRYPT1
2002 A Software System for Giving Clues of Medical Diagnosis to Clinician
abstract
The importance of developing a support system for medical decision-making in the clinical field has been pointed out for improving the accuracy and objectivity of the judgment of clinicians, and for early detection of disease. In this paper, we notice that signs, symptoms and clinical laboratory data are essential information which show the functional depression and failure of the ecosystem, and a practical software system is presented that provides physicians with clues to clinical diagnosis. First, by analysing the medical task and the structuralization of patient information, a medical modelling method is provided, where diagnosis can be considered as the identification of a patient who corresponds to the controlled object. Secondly, by using the concept of a patient model and a disease model, a system identification algorithm is proposed, and an actual system constructed for medical diagnosis is described in order to confirm the usefulness of the proposed method.
Tsutomu Matsumoto, Yuki Ueda, Shigeyasu Kawaji
CBMS1
2002 Designing and Implementation of Mobile Terminal for Telehealth Care Life Support System
abstract
This paper describes the design and implementation of a handy terminal for the telehealth care support system. The telehealth care life support modeling is proposed. The system is able to set up automatically the communication channel among the client, nursing staff and clinician. To construct the telehealth care life support modeling, the analysis of task and information for health care is discussed. The structure of the proposed telehealth care life support model is based on the feedback control system. The clinician and nursing staff play the role as a controller and the client as a controlled object in the model. The role of information technology plays in supporting the model is discussed. The design and implementation of collaboration among the client, clinician and comedical including the family and establishment of communication channels are explained using an actual example based on the proposed telehealth care life support model. The software is designed to work on cellular phone.
Tsutomu Matsumoto, Shin'ichi Ogata, Shigeyasu Kawaji
CSCWD1
2001 Designing and Implementation of Tele-Health Care Information System based on Health Care Model
abstract
This paper describes a concept and system implementation of a tele-health care support system. Traditional medical consultation is carried out face to face. The tele-health care support system should make up the physical distance between the client and clinician. The medical consultation model is proposed based on analyzing the task and information of medical consultation for creating a design methodology for a tele-health care system. The structure of the proposed medical consultation model is created by the idea of a feedback control system. The clinician takes the part of a controller and the client is regarded as a controlled system in the model. How and which parts of the model could be supported by computer and communication technology are discussed. The design and implementation of collaboration among the client, clinician and co-medical staff including family and the establishment of the communication channel are explained as one actual example based on the proposed medical consultation model.
Tsutomu Matsumoto, Toshikatsu Mori, Hirofumi Ohtsuka, Yasuyuki Shimada, Shigeyasu Kawaji
CSCWD1
2001 Security of Camellia against Truncated Differential Cryptanalysis
Masayuki Kanda, Tsutomu Matsumoto
FSE2
2000 Light Weight Broadcast Exclusion Using Secret Sharing
Natsume Matsuzaki, Jun Anzai, Tsutomu Matsumoto
ACISP3
2000 Truss assembly by space robot and task error recovery via reinforcement learning
abstract
This paper addresses an experimental system simulating a free-flying space robot, which has been constructed to study autonomous space robots. The experimental system consists of a space robot model, a frictionless table system, a computer system, and a vision sensor system. The robot model composed of two manipulators and a satellite vehicle can move freely on a two-dimensional planar table without friction by using air-bearings. The robot model has successfully performed the automatic truss structure construction including many jobs, e.g., manipulator berthing, component manipulation, arm trajectory control avoiding collision, assembly considering contact with the environment, etc. Moreover, even if the robot fails in a task planned in advance, the robot accomplishes it by task re-planning through reinforcement learning. The experiment demonstrates the possibility of the automatic construction and the usefulness of space robots.
Kei Senda, Tsutomu Matsumoto
IROS2
1999 A Quick Group Key Distribution Scheme with "Entity Revocation"
Jun Anzai, Natsume Matsuzaki, Tsutomu Matsumoto
ASIACRYPT3
1998 A Strategy for Constructing Fast Round Functions with Practical Security Against Differential and Linear Cryptanalysis
Masayuki Kanda, Youichi Takashima, Tsutomu Matsumoto, Kazumaro Aoki, Kazuo Ohta
Selected Areas in Cryptography3
1998 Human-Computer Cryptography: An Attempt
abstract
Can you securely prove your identity to a host computer by using no dedicated software at your terminal and no dedicated token at your hands? Conventional password checking schemes do not need such a software and hardware but have a disadvantage that an attacker who has correctly observed an input password by peeping or wiretapping can perfectly impersonate the corresponding user. Conventional dynamic (one-time) password schemes or zero-knowledge identification schemes can be securely implemented but require special software or hardware or memorandums. This paper develops human-friendly identification schemes such that a human prover knowing a secret key in her or his brain is asked a visual question by a machine verifier, who then checks if an answer sent from the prover matches the question with respect to the key. The novelty of these schemes lies in their ways of displaying questions. This paper also examines an application of the human identification schemes to human–computer cryptographic communication protocols.
Tsutomu Matsumoto
J. Comput. Secur.1
1996 Human-Computer Cryptography: An Attempt
abstract
Can you securely prove your identity to a host computer by using no dedicated software at your terminal and no dedicated token at your hands ?Conventional password checking schemes don't need 8uch a software and hardware but have a disadvantage that an attacker who has correctly observed an input password by peeping or wiretapping can perfectly impersonate the corresponding user.Conventional dynamic (one-time) password schemes or zero-knowledge identification schemes can be securely implemented but require special software or hardwar(~ or memorandums.This paper develops human-friendly identification schemes such that a human prover knowing a secret key in her or his brain is asked a visual question by a machine verifier, who then checks if an answer sent from the prover matches the question with respect to the key.The novelty of these schemes lies in their ways of displaying questions.This paper also examines an application of the human identification schemes to humancomputer cryptographic communication protocols.
Tsutomu Matsumoto
CCS1
1994 Incidence Structures for Key Sharing (Extended Abstract)
Tsutomu Matsumoto
ASIACRYPT1
1991 A Multi-Purpose Proof System - for Identity and Membership Proofs
Chaosheng Shu, Tsutomu Matsumoto, Hideki Imai
ASIACRYPT2
1990 A Recursive Construction Method of S-boxes Satisfying Strict Avalanche Criterion
Kwangjo Kim, Tsutomu Matsumoto, Hideki Imai
CRYPTO2
1990 Structural Properties of One-way Hash Functions
Yuliang Zheng 0001, Tsutomu Matsumoto, Hideki Imai
CRYPTO2
1989 On the Construction of Block Ciphers Provably Secure and Not Relying on Any Unproved Hypotheses
Yuliang Zheng 0001, Tsutomu Matsumoto, Hideki Imai
CRYPTO2
1988 Speeding Up Secret Computations with Insecure Auxiliary Devices
Tsutomu Matsumoto, Koki Kato, Hideki Imai
CRYPTO1
1987 On the Key Predistribution System: A Practical Solution to the Key Distribution Problem
Tsutomu Matsumoto, Hideki Imai
CRYPTO1