EDBT 2026 Demo / reviewers in the wild / expert
Kazuhiko Minematsu
dblp:72/3032
· DBLP profile ↗
65ranked-venue papers
19as first author
27since 2021 · last 2026
0000-0002-3427-6772ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 59 · 19 first-author · 25 since 2021Systems, architecture and hardware · 3Theory of computation · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Sugawara 0001 |
CRYPTO (6) | 4 |
| 2026 | A Formal Security Proof of Masking - Reduction from Strong Noisy Leakage to Probing Model Without Random Probing and Application to LR Primitive
Rei Ueno, Akiko Inoue, Kazuhiko Minematsu, Akira Ito 0002, Naofumi Homma |
CRYPTO (7) | 3 |
| 2026 | Two-key variant of the four-round cascading sfLRW1
Shreya Dey, Avijit Dutta, Kazuhiko Minematsu |
Des. Codes Cryptogr. | 3 |
| 2025 | Generic Security of GCM-SST
Akiko Inoue, Ashwin Jha 0001, Bart Mennink, Kazuhiko Minematsu |
ACNS (2) | 4 |
| 2025 | Gravity of the Situation: Security Analysis on Rocket.Chat E2EEabstractRocket.Chat is a group chat platform widely deployed in industries and national organizations, with over 15 million users across 150 countries. One of its main features is an end-to-end encryption (E2EE) protocol; however, no cryptographic security analysis has been conducted. We conduct an in-depth cryptographic analysis of Rocket.Chat's E2EE protocol and identify multiple significant flaws that allow a malicious server or even an outsider to break the confidentiality and integrity of the group chat. Specifically, we formally model and analyze the protocol using ProVerif under the Dolev-Yao model, uncovering multiple theoretical weaknesses and verifying that some of them lead to practical attacks. Furthermore, through meticulous manual analysis, we identify additional vulnerabilities, including implementation flaws and cryptographic weaknesses such as CBC malleability, and demonstrate how they are exploitable in practical attack scenarios. To validate our findings, we develop Proof-of-Concept implementations, highlighting the real-world feasibility of these attacks. We also propose mitigation techniques and discuss the implications of our attacks. Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Takanori Isobe 0001 |
ACSAC | 3 |
| 2025 | Cryptographic Treatment of Key Control Security - In Light of NIST SP 800-108
Ritam Bhaumik, Avijit Dutta, Akiko Inoue, Tetsu Iwata, Ashwin Jha 0001, Kazuhiko Minematsu, Mridul Nandi, Yu Sasaki 0001, Meltem Sönmez Turan, Stefano Tessaro |
CRYPTO (5) | 6 |
| 2025 | Comprehensive Robustness Analysis of GCM, CCM, and OCB3
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu |
CT-RSA | 3 |
| 2025 | Not in The Prophecies: Practical Attacks on NostrabstractDistributed social networking services (SNSs) recently received significant attention as an alternative to traditional, centralized SNSs, which have inherent limitations on user privacy and freedom. We provide the first in-depth security analysis of Nostr, an open-source, distributed SNS protocol developed in 2019 with more than 1.1 million registered users. We investigate the specification of Nostr and the client implementations and present a number of practical attacks allowing forgeries on various objects, such as encrypted direct messages (DMs), by a malicious user or a malicious server. Even more, we show a confidentiality attack against encrypted DMs by a malicious user exploiting a flaw in the link preview mechanism and the CBC malleability. Our attacks are due to cryptographic flaws in the protocol specification and client implementation, some of which in combination elevate the forgery attack to a violation of confidentiality. We verify the practicality of our attacks via Proof-of-Concept implementations and discuss how to mitigate them. Hayato Kimura 0002, Ryoma Ito 0001, Kazuhiko Minematsu, Shogo Shiraki, Takanori Isobe 0001 |
EuroS&P | 3 |
| 2025 | Lightweight Yet Nonce-Misuse Secure Authenticated Encryption for Very Short InputsabstractWe study authenticated encryption (AE) modes dedicated to very short messages, which are crucial for Internet of Things applications. One of the most popular class of AE is built on block ciphers, namely a mode of operation. The computational cost of a mode is typically measured by its rate, indicating the number of input blocks processed per block cipher call in asymptotic terms. While certain modes demonstrate efficiency in terms of rate, such as$\mathsf { OCB}$, this metric does not always accurately portray the total computational burden as it ignores overhead. Consequently, modes efficient in terms of rate may not always perform optimally with short messages. This observation motivates us to study modes that are efficient on short inputs rather than focusing on rate. Since the existing general-purpose AE modes need at least three block cipher calls for nonempty messages, we explore the design space for AE modes that use at most two calls. We propose a family of AE modes, dubbed$ \mathsf {Manx}$, which work when the total input length is less than$2n$bits, using an n-bit block cipher. Notably, the second construction of$ \mathsf {Manx}$can encrypt almost n-bit plaintexts and saves one or two block cipher calls compared to standard modes, such as$\mathsf { GCM}$or$\mathsf { OCB}$, while preserving comparable provable security. In addition to the conventional security against nonce-respecting adversary, we prove that$ \mathsf {Manx}$have security against nonce-misusing adversary with a different security level for each family member. We also present benchmarks on popular 8/32-bit microprocessors, namely 8-bit AVR, 32-bit ARM Cortex-M0, and ARM Cortex-M4, using AES and lightweight block ciphers. Our results show the clear advantage of$ \mathsf {Manx}$over the previous modes for such short messages. In particular,$ \mathsf {Manx2}$has significant performance gain from the existing representative schemes thanks to the simple structure and parallelizability. For example, using AES-128,$ \mathsf {Manx2}$is faster than$\mathsf { OCB}$by a factor of 1.5 to 1.7 to process a 64-bit nonce and a 120-bit plaintext. Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata |
IEEE Internet Things J. | 2 |
| 2025 | Security analysis of SFrameabstractIncreasing privacy consciousness has popularized the use of end-to-end encryption (E2EE). In this paper, we discuss the security of SFrame, an E2EE mechanism proposed to the Internet Engineering Task Force for video/audio group communications over the Internet. Despite being a quite recent project, SFrame has been deployed in several real-world applications. The original specification of SFrame is evaluated herein to find critical issues that can cause impersonation (forgery) attacks with a practical complexity by a malicious group member . Further investigations have revealed that these issues are present in several publicly available SFrame implementations. Therefore, we provide several countermeasures against all the proposed attacks and considerations from performance and security perspectives towards their implementation. Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu |
J. Inf. Secur. Appl. | 3 |
| 2024 | Crystalor: Recoverable Memory Encryption Mechanism with Optimized Metadata Structure
Rei Ueno, Hiromichi Haneda, Naofumi Homma, Akiko Inoue, Kazuhiko Minematsu |
CCS | 5 |
| 2024 | Interactive aggregate message authentication equipped with detecting functionality from adaptive group testing
Kazuhiko Minematsu, Shingo Sato, Junji Shikata |
Des. Codes Cryptogr. | 1 |
| 2023 | Authenticated Encryption for Very Short Inputs
Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata |
CT-RSA | 2 |
| 2023 | XOCB: Beyond-Birthday-Bound Secure Authenticated Encryption Mode with Rate-One Computation
Zhenzhen Bao, Seongha Hwang, Akiko Inoue, ByeongHak Lee, Jooyoung Lee 0001, Kazuhiko Minematsu |
EUROCRYPT (4) | 6 |
| 2023 | Compactly Committing Authenticated Encryption Using Encryptment and Tweakable Block Cipher
Shoichi Hirose, Kazuhiko Minematsu |
SAC | 2 |
| 2023 | Tight lower bounds and optimal constructions of anonymous broadcast encryption and authenticationabstractAbstract Broadcast Encryption (BE) is public-key encryption allowing a sender to encrypt a message by specifing recipients, and only the specified recipients can decrypt the message. In several BE applications, since the privacy of recipients allowed to access the message is often as important as the confidentiality of the message, anonymity is introduced as an additional but important security requirement for BE. Kiayias and Samari (IH 2013) presented an asymptotic lower bound on the ciphertext sizes in BE schemes satisfying anonymity (ANO-BE for short). More precisely, their lower bound is derived under the assumption that ANO-BE schemes have a special property. However, it is insufficient to show their lower bound is asymptotically tight since it is unclear whether existing ANO-BE schemes meet the special property. In this work, we derive asymptotically tight lower bounds on the ciphertext size in ANO-BE by assuming only properties that most existing ANO-BE schemes satisfy. With a similar technique, we first derive asymptoticallyPlease provide MSC codes. For more details, please visit http://www.ams.org/msc/. tight lower bounds on the authenticator sizes in Anonymous Broadcast Authentication (ABA). Furthermore, we extend the above result and present (non-asymptotically) tight lower and upper bounds on thePlease check and confirm the Running title. ciphertext sizes in ANO-BE. We show that a variant of ANO-BE scheme proposed by Li and Gong (ACNS 2018) is optimal. We also provide tight bounds on the authenticator sizes in ABA via the same approach as ANO-BE, and propose an optimal construction for ABA. Hirokazu Kobayashi, Yohei Watanabe 0001, Kazuhiko Minematsu, Junji Shikata |
Des. Codes Cryptogr. | 3 |
| 2023 | Nonce-misuse resilience of Romulus-N and GIFT-COFBabstractAbstract Nonce‐misuse resilience (NMRL) security of Romulus‐N and GIFT‐COFB is analysed, the two finalists of NIST Lightweight Cryptography project for standardising lightweight authenticated encryption. NMRL, introduced by Ashur et al. at CRYPTO 2017, is a relaxed security notion from a stronger, nonce‐misuse resistance notion. The authors have proved that Romulus‐N and GIFT‐ COFB have nonce‐misuse resilience. For Romulus‐N, the perfect privacy (NMRL‐PRIV) and n /2‐bit authenticity (NMRL‐AUTH) with graceful degradation with respect to nonce repetition are showed. For GIFT‐COFB, n /4‐bit security for both NMRL‐PRIV and NMRL‐AUTH notions is showed. Akiko Inoue, Chun Guo 0002, Kazuhiko Minematsu |
IET Inf. Secur. | 3 |
| 2023 | Cubicle: A family of space-hard ciphers for IoTabstractAbstract As IoT has increasingly evolved in recent years, it has become more important to ensure security on IoT devices. Many of such devices are under the threat of attacks in the beyond black‐box model. To protect from the threat, the cryptographic implementation that can offer secure execution in the grey‐/white‐box model is important. However, such cryptographic implementations require a large number of clock cycles to execute and cannot fully cover resistance against various types of side‐channel attacks. In this paper, a new family of table‐based cipher dubbed Cubicle is proposed, which can offer efficient execution and sufficient security against side‐channel attacks on IoT devices powered by ARM Cortex‐M processors, which are widely deployed in IoT applications. To evaluate the security of Cubicle in the grey‐box model, the authors derive the bound of table leakage in the grey‐box model by applying space hardness, which is the notion to evaluate the security against code lifting attacks in the white‐box. The security of Cubicle in the grey‐box model is shown by using this bound. In addition, the security of Cubicle is also shown in the black‐box and white‐box models. Finally, the performance of Cubicle and other ciphers in some devices powered by ARM Cortex‐M3, ‐M4, and ‐M7 processors is evaluated. The authors show that Cubicle is significantly efficient compared to other grey‐/white‐box‐ model‐secure ciphers in target experiments for IoT applications. Rentaro Shiba, Ravi Anand, Kazuhiko Minematsu, Takanori Isobe 0001 |
IET Inf. Secur. | 3 |
| 2022 | Fast Skinny-128 SIMD Implementations for Sequential Modes of Operation
Alexandre Adomnicai, Kazuhiko Minematsu, Maki Shigeri |
ACISP | 2 |
| 2022 | Analyzing the Provable Security Bounds of GIFT-COFB and Photon-Beetle
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu |
ACNS | 3 |
| 2022 | Efficient Word Size Modular Multiplication over Signed IntegersabstractAs an efficient multiplication method for polynomial rings, Number Theoretic Transform (NTT) is a fundamental algorithm that is both practically useful and theoretically established. Chung et al. proposed a method to perform NTT-based polynomial multiplication for NTT-unfriendly rings that do not have suitable primitive roots. They applied their proposal to lattice-based cryptography using NTT-unfriendly rings and speeded up several schemes. At ARITH 2021, Plantard proposed a modular multiplication algorithm that improves the speed of NTT if moduli are not large (a few dozen of bits), which is the case for typical lattice-based cryptography. It is natural to expect that Plantard's method improves Chung et al.‘s NTT when applied to them, however, this is not possible as Chung et al. requires the use of signed integers while Plantard's method assumes unsigned integers. A simple fix would cause a slowdown and a non-constant-time operation. To overcome this problem, we propose an efficient method for calculating the modular multiplication for signed integers based on Plantard's method. Our proposal generally incurs no overhead from the original and works in a constant-time fashion. To show the effectiveness of our proposal, we provide experimental implementation results on a lattice-based cryptographic scheme Saber. Currently, NIST is selecting candidates for standardization of post-quantum cryp-tography in preparation for the compromise of current public key cryptography by quantum computers, and has completed the selection of the final candidates. Saber is one of the finalists for the NIST standardization project, Daichi Aoki, Kazuhiko Minematsu, Toshihiko Okamura, Tsuyoshi Takagi |
ARITH | 2 |
| 2022 | New indifferentiability security proof of MDPH hash functionabstractAbstract MDPH is a double‐block‐length hash function proposed by Naito at Latincrypt 2019. This is a combination of Hirose's compression function and the domain extender called Merkle–Damgård with permutation. When instantiated with an n ‐bit block cipher, Naito proved that this achieves the (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security. In this paper, the authors first point out that the proof of the claim contains a gap, which is related to the definition of the simulator in simulating the decryption of the block cipher. The authors then show that the proof can be fixed. The authors introduce a new simulator that addresses the issue, showing that MDPH retains its (nearly) optimal indifferentiable security bound of O ( n − log n )‐bit security. Chun Guo 0002, Tetsu Iwata, Kazuhiko Minematsu |
IET Inf. Secur. | 3 |
| 2022 | Matching attacks on Romulus-MabstractAbstract This paper considers a problem of identifying matching attacks against Romulus‐M, one of the 10 finalists of National Institute of Standards and Technology Lightweight Cryptography standardisation project. Romulus‐M is provably secure, that is, there is a theorem statement showing the upper bound on the success probability of attacking the scheme as a function of adversaries' resources. If there exists an attack that matches the provable security bound, then this implies that the attack is optimal and that the bound is tight in the sense that it cannot be improved. It is shown that the security bounds of Romulus‐M are tight for a large class of parameters by presenting concrete matching attacks. Makoto Habu, Kazuhiko Minematsu, Tetsu Iwata |
IET Inf. Secur. | 2 |
| 2022 | Integral and impossible-differential attacks on the reduced-round Lesamnta-LW-BCabstractAbstract Lesamnta‐LW‐BC is the internal block cipher of the Lesamnta‐LW lightweight hash function, specified in ISO/IEC 29192‐5:2016. It is based on the unbalanced Feistel network and Advanced Encryption Standard round function. In this study, the security of Lesamnta‐LW‐BC against integral and impossible‐differential attacks is evaluated. Specifically, the authors searched for the integral distinguishers and impossible differentials with Mixed‐Integer Linear Programming‐based methods. As a result, the discovered impossible differential can reach up to 21 rounds, while three integral distinguishers reaching 18, 19 and 25 rounds are obtained, respectively. Moreover, it is also feasible to construct a 47‐round integral distinguisher in the known‐key setting. Finally, a 20‐round key‐recovery attack is proposed based on the discovered 18‐round integral distinguisher and a 19‐round key‐recovery attack using a 17‐round impossible differential. To the best of the authors' knowledge, this is the first third‐party cryptanalysis of Lesamnta‐LW‐BC. Rentaro Shiba, Kosei Sakamoto, Fukang Liu, Kazuhiko Minematsu, Takanori Isobe 0001 |
IET Inf. Secur. | 4 |
| 2022 | ELM: A Low-Latency and Scalable Memory Encryption SchemeabstractMemory encryption (ME) with authentication is becoming a key security feature of modern processors, as evident by the adoption of ME by Intel’s SGX. Recently ME is actively studied from the viewpoint of system architecture. This paper studies ME from the viewpoint of symmetric-key cryptographic designs, with a primal focus on latency. A significant progress in such a direction can be observed in the SGX Integrity Tree (SIT). Using a variant of AES-GCM, SIT achieves an excellent latency. However, it has a scalability issue. By carefully examining SIT, we develop a new ME scheme dubbed ELM. We present an AES-based instantiation of ELM, and show that ELM significantly reduces latency from SIT for large memories, and achieves the provable security and equivalent hardware-protected (on-chip) area. We also present preliminary hardware implementations to substantiate our advantages. Akiko Inoue, Kazuhiko Minematsu, Maya Oda, Rei Ueno, Naofumi Homma |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Security Analysis of SFrame
Takanori Isobe 0001, Ryoma Ito 0001, Kazuhiko Minematsu |
ESORICS (2) | 3 |
| 2021 | Parallel Verification of Serial MAC and AE Modes
Kazuhiko Minematsu, Akiko Inoue, Katsuya Moriwaki, Maki Shigeri, Hiroyasu Kubo |
SAC | 1 |
| 2020 | ACE in Chains: How Risky Is CBC Encryption of Binary Executable Files?
Rintaro Fujita, Takanori Isobe 0001, Kazuhiko Minematsu |
ACNS (1) | 3 |
| 2020 | PMAC++: Incremental MAC Scheme Adaptable to Lightweight Block CiphersabstractThis paper presents a new incremental parallelizable message authentication code (MAC) scheme adaptable to lightweight block ciphers for memory integrity verification. The highlight of the proposed scheme is to achieve both incremental update capability and sufficient security bound with lightweight block ciphers, which is a novel feature. We extend the conventional parallelizable MAC to realize the incremental update capability while keeping the original security bound. We prove that a comparable security bound can be obtained even if this change is incorporated. We also present a hardware architecture for the proposed MAC scheme with lightweight block ciphers and demonstrate the effectiveness through FPGA implementation. The evaluation results indicate that the proposed MAC hardware achieves 3.4 times improvement in the latency-area product for the tag update compared with the conventional MAC. Maya Oda, Rei Ueno, Akiko Inoue, Kazuhiko Minematsu, Naofumi Homma |
ISCAS | 4 |
| 2020 | WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri |
SAC | 6 |
| 2020 | Blockcipher-Based Authenticated Encryption: How Small Can We Go?
Avik Chakraborti, Tetsu Iwata, Kazuhiko Minematsu, Mridul Nandi |
J. Cryptol. | 3 |
| 2020 | Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering |
J. Cryptol. | 3 |
| 2019 | Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering |
CRYPTO (1) | 3 |
| 2019 | Symmetric-Key Corruption Detection: When XOR-MACs Meet Combinatorial Group Testing
Kazuhiko Minematsu, Norifumi Kamiya |
ESORICS (1) | 1 |
| 2019 | High Throughput/Gate FN-Based Hardware Architectures for AES-OTRabstractThis paper presents high throughput/gates Feistel network (FN)-based AES-OTR hardware architectures. AES-OTR is an authenticated encryption (AE) scheme as a block cipher mode of operation using AES. While AES-OTR is one of the most theoretically efficient AEs using AES and has superior features, its practical efficiency in hardware is unclear due to no known reports of its hardware implementation. In this paper, we present efficient AES-OTR hardware architectures. In contrast to conventional AE architectures, our architecture forms the 2-round FN of OTR, which makes it easy to integrate the peripheral into hardware for OTR operations. The proposed architectures had 2.4 and 13.5 times higher throughput/gates than the de facto standard AE (i.e., AES-GCM) core on FPGA and ASIC, respectively, through logic syntheses. Rei Ueno, Naofumi Homma, Tomonori Iida, Kazuhiko Minematsu |
ISCAS | 4 |
| 2019 | Plaintext Recovery Attacks Against XTS Beyond Collisions
Takanori Isobe 0001, Kazuhiko Minematsu |
SAC | 2 |
| 2019 | Parallelizable Authenticated Encryption with Small State Size
Akiko Inoue, Kazuhiko Minematsu |
SAC | 2 |
| 2019 | A Lightweight Alternative to PMAC
Kazuhiko Minematsu |
SAC | 1 |
| 2018 | Count-then-Permute: A Precision-Free Alternative to Inversion Sampling
Kazuhiko Minematsu, Kentarou Sasaki |
CT-RSA | 1 |
| 2018 | Breaking Message Integrity of an End-to-End Encryption Scheme of LINE
Takanori Isobe 0001, Kazuhiko Minematsu |
ESORICS (2) | 2 |
| 2018 | Connecting tweakable and multi-key blockcipher securityabstractThe significance of understanding blockcipher security in the multi-key setting is highlighted by the extensive literature on attacks, and how effective key size can be significantly reduced. Nevertheless, little attention has been paid in formally understanding the design of multi-key secure blockciphers. In this work, we formalize the multi-key security of tweakable blockciphers in case of general key derivation functions. We show an equivalence between blockcipher multi-key security and tweakable blockcipher security. Our equivalence connects two objects of study, the iterated Even–Mansour (EUROCRYPT 2012) and the iterated Tweakable Even–Mansour (CRYPTO 2015), which establishes that results in both areas are, to a certain extent, transferable. Using our novel equivalence relation, we derive new bounds for both constructions, pave the path towards the solution of two well-studied conjectures, and show that, contrary to common knowledge, key derivation functions need not necessarily be pseudorandom functions in order to provide security: for the iterated Even–Mansour universal hash functions suffice. Jooyoung Lee 0001, Atul Luykx, Bart Mennink, Kazuhiko Minematsu |
Des. Codes Cryptogr. | 4 |
| 2017 | Blockcipher-Based Authenticated Encryption: How Small Can We Go?
Avik Chakraborti, Tetsu Iwata, Kazuhiko Minematsu, Mridul Nandi |
CHES | 3 |
| 2017 | ZMAC: A Fast Tweakable Block Cipher Mode for Highly Secure Message Authentication
Tetsu Iwata, Kazuhiko Minematsu, Thomas Peyrin, Yannick Seurin |
CRYPTO (3) | 2 |
| 2016 | Authenticated Encryption with Small Stretch (or, How to Accelerate AERO)
Kazuhiko Minematsu |
ACISP (2) | 1 |
| 2016 | Integrity Analysis of Authenticated Encryption Based on Stream Ciphers
Kazuya Imamura, Kazuhiko Minematsu, Tetsu Iwata |
ProvSec | 2 |
| 2015 | Efficient Message Authentication Codes with Combinatorial Group TestingabstractMessage authentication code, MAC for short, is a symmetric-key cryptographic function for authenticity. A standard MAC verification only tells whether the message is valid or invalid, and thus we can not identify which part is corrupted in case of invalid message. In this paper we study a class of MAC functions that enables to identify the part of corruption, which we call group testing MAC (GTM). This can be seen as an application of a classical (non-adaptive) combinatorial group testing to MAC. Although the basic concept of GTM (or its keyless variant) has been proposed in various application areas, such as data forensics and computer virus testing, they rather treat the underlying MAC function as a black box, and exact computation cost for GTM seems to be overlooked. In this paper, we study the computational aspect of GTM, and show that a simple yet non-trivial extension of parallelizable MAC (PMAC) enables $$O(m+t)$$ computation for m data items and t tests, irrespective of the underlying test matrix we use, under a natural security model. This greatly improves efficiency from naively applying a black-box MAC for each test, which requires O(mt) time. Based on existing group testing methods, we also present experimental results of our proposal and observe that ours runs as fast as taking single MAC tag, with speed-up from the conventional method by factor around 8 to 15 for $$m=10^4$$ to $$10^5$$ items. Kazuhiko Minematsu |
ESORICS (1) | 1 |
| 2015 | GCM Security Bounds Reconsidered
Yuichi Niwa, Keisuke Ohashi, Kazuhiko Minematsu, Tetsu Iwata |
FSE | 3 |
| 2015 | Tweak-Length Extension for Tweakable Blockciphers
Kazuhiko Minematsu, Tetsu Iwata |
IMACC | 1 |
| 2015 | Building blockcipher from small-block tweakable blockcipher
Kazuhiko Minematsu |
Des. Codes Cryptogr. | 1 |
| 2014 | A smaller and faster variant of RSMabstractMasking is one of the major countermeasures against side-channel attacks to cryptographic modules. Nassar et al. recently proposed a highly efficient masking method, called Rotating S-boxes Masking (RSM), which can be applied to a block cipher based on Substitution-Permutation Network. It arranges multiple masked S-boxes in parallel, which are rotated in each round. This rotation requires remasking process for each round to adjust current masks to those of the S-boxes. In this paper, we propose a method for reducing the complexity of RSM further by omitting the remasking process when the linear diffusion layer of the encryption algorithm has a certain algebraic property. Our method can be applied to AES with a reduced complexity from RSM, while keeping the equivalent security level. Noritaka Yamashita, Kazuhiko Minematsu, Toshihiko Okamura, Yukiyasu Tsunoo |
DATE | 2 |
| 2014 | Parallelizable Rate-1 Authenticated Encryption from Pseudorandom Functions
Kazuhiko Minematsu |
EUROCRYPT | 1 |
| 2014 | CLOC: Authenticated Encryption for Short Input
Tetsu Iwata, Kazuhiko Minematsu, Jian Guo 0001, Sumio Morioka |
FSE | 2 |
| 2013 | Attacks and Security Proofs of EAX-Prime
Kazuhiko Minematsu, Stefan Lucks, Hiraku Morita, Tetsu Iwata |
FSE | 1 |
| 2013 | A Short Universal Hash Function from Bit Rotation, and Applications to Blockcipher Modes
Kazuhiko Minematsu |
ProvSec | 1 |
| 2013 | Improved Authenticity Bound of EAX, and Refinements
Kazuhiko Minematsu, Stefan Lucks, Tetsu Iwata |
ProvSec | 1 |
| 2012 | Breaking and Repairing GCM Security Proofs
Tetsu Iwata, Keisuke Ohashi, Kazuhiko Minematsu |
CRYPTO | 3 |
| 2012 | $\textnormal{\textsc{TWINE}}$ : A Lightweight Block Cipher for Multiple Platforms
Tomoyasu Suzaki, Kazuhiko Minematsu, Sumio Morioka, Eita Kobayashi |
Selected Areas in Cryptography | 2 |
| 2011 | On Maximum Differential Probability of Generalized Feistel
Kazuhiko Minematsu, Tomoyasu Suzaki, Maki Shigeri |
ACISP | 1 |
| 2011 | Building Blockcipher from Tweakable Blockcipher: Extending FSE 2009 Proposal
Kazuhiko Minematsu, Tetsu Iwata |
IMACC | 1 |
| 2010 | How to Thwart Birthday Attacks against MACs via Small Randomness
Kazuhiko Minematsu |
FSE | 1 |
| 2010 | Improving the Generalized Feistel
Tomoyasu Suzaki, Kazuhiko Minematsu |
FSE | 2 |
| 2009 | Beyond-Birthday-Bound Security Based on Tweakable Block Cipher
Kazuhiko Minematsu |
FSE | 1 |
| 2007 | New Bounds for PMAC, TMAC, and XCBC
Kazuhiko Minematsu, Toshiyasu Matsushima |
FSE | 1 |
| 2006 | Provably Secure MACs from Differentially-Uniform Permutations and AES-Based Implementations
Kazuhiko Minematsu, Yukiyasu Tsunoo |
FSE | 1 |
| 2005 | Shorter bit sequence is enough to break stream cipher LILI-128abstractLILI-128 is the stream cipher proposed as a candidate cipher for the New European Schemes for Signatures, Integrity, and Encryption (NESSIE) Project. Some methods of breaking it more efficiently than an exhaustive search for its secret key have been found already. The authors propose a new method, which uses shorter bit sequence to break LILI-128 successfully. An attack that can be made with less data can be a more practical threat. With only 2/sup 7/ bits of keystream, this method can break LILI-128 successfully. The efficiency of our attack depends on the memory size. For example, with 2/sup 99.1/ computations, our attack breaks LILI-128, if 2/sup 28.6/-bit memory is available. Yukiyasu Tsunoo, Teruo Saito, Maki Shigeri, Hiroyasu Kubo, Kazuhiko Minematsu |
IEEE Trans. Inf. Theory | 5 |