Nobuyuki Sugio

dblp:92/4122 · DBLP profile ↗
← Back
7ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0001-7313-1755ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 7 first-author · 3 since 2021Theory of computation · 3 · 3 first-author
YearPublicationVenuePosition
2025 Impossible Differential Attack on SAND-128
Nobuyuki Sugio
CANS1
2024 Bit-Based Evaluation of Lightweight Block Ciphers SLIM, LBC-IoT, and SLA by Mixed Integer Linear Programming
abstract
Many lightweight block ciphers have been proposed for IoT devices that have limited resources. SLIM, LBC‐IoT, and SLA are lightweight block ciphers developed for IoT systems. The designer of SLIM presented a 7‐round differential distinguisher and an 11‐round linear trail using a heuristic method. We have comprehensively sought the longest distinguisher for linear cryptanalysis, zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack using the mixed integer linear Programming (MILP) on SLIM, LBC‐IoT, and SLA. The search led to discovery of a 16‐round linear trail on SLIM, which is 5‐round longer than the earlier result. We have also discovered 7‐, 7‐, and 9‐round distinguishers for zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack, which are new results for SLIM. We have revealed 9‐, 8‐, and 11‐round distinguishers on LBC‐IoT for zero‐correlation linear cryptanalysis, impossible differential attack, and integral attack. We have presented full‐round distinguishers on SLA for integral attack using only two chosen plaintexts. We performed a key recovery attack on 16‐round SLIM with an experimental verification. This verification took 106 s with a success rate of 93%. Moreover, we present a key recovery attack on 19‐round SLIM using 16‐round linear trail with correlation 2 −15 : the necessary number of known plaintext–ciphertext pairs is 2 31 ; the time complexity is 2 64.4 encryptions; and the memory complexity is 2 38 bytes. Results show that this is the current best key recovery attack on SLIM. Because the recommended number of rounds is 32, SLIM is secure against linear cryptanalysis, as demonstrated herein.
Nobuyuki Sugio
IET Inf. Secur.1
2023 Differential, Linear, and Meet-in-the-Middle Attacks on the Lightweight Block Cipher RBFK
abstract
Randomized butterfly architecture of fast Fourier transform for key cipher (RBFK) is the lightweight block cipher for Internet of things devices in an edge computing environment. Although the authors claimed that RBFK is secure against differential cryptanalysis, linear cryptanalysis, impossible differential attack, and zero correlation linear cryptanalysis, the details were not explained in the literature. Therefore, we have evaluated the security of RBFK by application of differential cryptanalysis, linear cryptanalysis, and meet‐in‐the‐middle (MITM) attack and have found that RBFK is not secure against these attacks. This paper introduces not only a distinguish attack but also key recovery attacks on full‐round RBFK. In the distinguish attack scenario, data for differential cryptanalysis are two, and the time complexity is one for an exclusive‐OR operation. In the key recovery attack scenario, the data for linear cryptanalysis are one pair of known plaintext–ciphertext. The time complexity is one operation for a linear sum. Data for an MITM attack are two. The time complexity is 2 48 encryptions; the memory complexity is 2 45 bytes. Because the vulnerabilities are identified in the round function and the key scheduling part, we propose some improvements for RBFK against these attacks.
Nobuyuki Sugio
IET Inf. Secur.1
2018 Integral Cryptanalysis of Reduced-round KASUMI
abstract
Integral cryptanalysis, which was introduced by Knudsen and Wagner, is one of the most powerful attacks on symmetric key ciphers. Attackers preliminarily search integral characteristics of a target cipher for the key-recovery attack. Todo proposed a novel technique named the division property to find them efficiently. In this paper, we apply this technique to the symmetric key block cipher KASUMI which was developed by modifying MISTY1. It has been used worldwide in the 3rd generation mobile communication networks. As a result, we found new 4.5-round characteristics of KASUMI for the first time. We show that 7-round KASUMI is attackable with 263data complexity and 263.3encryptions under the weak key conditions.
Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko
ISITA1
2016 A Practical-time Attack on Reduced-round MISTY1
Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko, Kenichi Higuchi
ICISSP1
2016 Integral characteristics of MISTY2 derived by division property
Nobuyuki Sugio, Yasutaka Igarashi, Toshinobu Kaneko
ISITA1
2014 A new higher order differential of Camellia
Nobuyuki Sugio, Hiroshi Aono, Kimihiko Sekino, Toshinobu Kaneko
ISITA1