Nagoya University · 컴퓨터과학
Akinori Hosoyamada 교수의 연구실은 양자 환경에서의 암호 보안을 중심으로, 기존에 안전하다고 여겨졌던 대칭키 암호 기법들이 양자 공격에 취약해질 수 있음을 밝혀내는 데 초점을 맞추고 있습니다. 특히, 양자 컴퓨터가 가능한 초월적 공격 방식(예: 양자 슈퍼포지션 공격, 양자 구별 공격)을 통해 Feistel 구조, Even-Mansour, CBC-MAC 등 주요 블록 시프어의 키 복구나 위조 공격을 다항식 시간 내에 수행할 수 있음을 분석합니다. 연구는 양자 환경에서도 안전한 암호 설계와 보안 보증의 이론적 틀을 마련하는 데 기여하며, NIST의 경량 암호 표준화 과정에 영향을 미치는 실용적 응용도 포함됩니다.
표시된 성과는 수집된 데이터 기준으로 산출되며, 일부 차이가 있을 수 있습니다.
It has been said that security of symmetric key schemes is not so much affected by quantum computers, compared to public key schemes. However, recent works revealed that, in some specific situations, symmetric key schemes are also broken in polynomial time by adversaries with quantum computers. These works contain a quantum distinguishing attack on 3-round Feistel ciphers and a quantum key recovery attack on the Even-Mansour cipher by Kuwakado and Morii, in addition to the quantum forgery attack
Recent results on quantum cryptanalysis show that some symmetric key schemes can be broken in polynomial time even if they are proven to be secure in the classical setting. Liskov, Rivest, and Wagner showed that secure tweakable block ciphers can be constructed from secure block ciphers in the classical setting. However, Kaplan et al. showed that their scheme can be broken by polynomial time quantum superposition attacks, even if underlying block ciphers are quantum-secure. Since then, it remain
Rocca is an authenticated encryption with associated data scheme for beyond 5G/6G systems. It was proposed at FSE 2022/ToSC 2021(2), and the designers make a security claim of achieving 256-bit security against key-recovery and distinguishing attacks, and 128-bit security against forgery attacks (the security claim regarding distinguishing attacks was subsequently weakened in the full version in ePrint 2022/116). A notable aspect of the claim is the gap between the privacy and authenticity secur