{"id":237229,"updated":"2025-01-19T08:57:01.860341+00:00","links":{},"created":"2025-01-19T01:39:44.464294+00:00","metadata":{"_oai":{"id":"oai:ipsj.ixsq.nii.ac.jp:00237229","sets":["1164:3925:11477:11663"]},"path":["11663"],"owner":"44499","recid":"237229","title":["AESのDavies-Meyerハッシュモードに対する衝突攻撃評価"],"pubdate":{"attribute_name":"公開日","attribute_value":"2024-07-15"},"_buckets":{"deposit":"dded61a9-fc19-464f-906a-80d4573d9e43"},"_deposit":{"id":"237229","pid":{"type":"depid","value":"237229","revision_id":0},"owners":[44499],"status":"published","created_by":44499},"item_title":"AESのDavies-Meyerハッシュモードに対する衝突攻撃評価","author_link":["649076","649070","649068","649069","649071","649072","649074","649073","649067","649075"],"item_titles":{"attribute_name":"タイトル","attribute_value_mlt":[{"subitem_title":"AESのDavies-Meyerハッシュモードに対する衝突攻撃評価"},{"subitem_title":"Collision Attack on DM-AES","subitem_title_language":"en"}]},"item_keyword":{"attribute_name":"キーワード","attribute_value_mlt":[{"subitem_subject":"ISEC","subitem_subject_scheme":"Other"}]},"item_type_id":"4","publish_date":"2024-07-15","item_4_text_3":{"attribute_name":"著者所属","attribute_value_mlt":[{"subitem_text_value":"兵庫県立大学大学院情報科学研究科"},{"subitem_text_value":"兵庫県立大学大学院情報科学研究科/三菱電機株式会社"},{"subitem_text_value":"国立研究開発法人情報通信研究機構"},{"subitem_text_value":"兵庫県立大学大学院情報科学研究科"},{"subitem_text_value":"兵庫県立大学大学院情報科学研究科/国立研究開発法人情報通信研究機構"}]},"item_4_text_4":{"attribute_name":"著者所属(英)","attribute_value_mlt":[{"subitem_text_value":"University of Hyogo","subitem_text_language":"en"},{"subitem_text_value":"University of Hyogo / Mitsubishi Electric Corporation","subitem_text_language":"en"},{"subitem_text_value":"National Institute of Information and Communications Technology","subitem_text_language":"en"},{"subitem_text_value":"University of Hyogo","subitem_text_language":"en"},{"subitem_text_value":"University of Hyogo / National Institute of Information and Communications Technology","subitem_text_language":"en"}]},"item_language":{"attribute_name":"言語","attribute_value_mlt":[{"subitem_language":"jpn"}]},"item_publisher":{"attribute_name":"出版者","attribute_value_mlt":[{"subitem_publisher":"情報処理学会","subitem_publisher_language":"ja"}]},"publish_status":"0","weko_shared_id":-1,"item_file_price":{"attribute_name":"Billing file","attribute_type":"file","attribute_value_mlt":[{"url":{"url":"https://ipsj.ixsq.nii.ac.jp/record/237229/files/IPSJ-CSEC24106023.pdf","label":"IPSJ-CSEC24106023.pdf"},"format":"application/pdf","billing":["billing_file"],"filename":"IPSJ-CSEC24106023.pdf","filesize":[{"value":"1.3 MB"}],"mimetype":"application/pdf","priceinfo":[{"tax":["include_tax"],"price":"0","billingrole":"30"},{"tax":["include_tax"],"price":"0","billingrole":"44"}],"accessrole":"open_login","version_id":"4f24c3a4-a4c5-4aea-ba76-e3e7306f3558","displaytype":"detail","licensetype":"license_note","license_note":"Copyright (c) 2024 by the Institute of Electronics, Information and Communication Engineers This SIG report is only available to those in membership of the SIG."}]},"item_4_creator_5":{"attribute_name":"著者名","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"泰山, 幸大"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"阪本, 光星"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"伊藤, 竜馬"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"髙, 和真"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"五十部, 孝典"}],"nameIdentifiers":[{}]}]},"item_4_creator_6":{"attribute_name":"著者名(英)","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"Kodai, Taiyama","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Kosei, Sakamoto","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Ryoma, Ito","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Kazuma, Taka","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Takanori, Isobe","creatorNameLang":"en"}],"nameIdentifiers":[{}]}]},"item_4_source_id_9":{"attribute_name":"書誌レコードID","attribute_value_mlt":[{"subitem_source_identifier":"AA11235941","subitem_source_identifier_type":"NCID"}]},"item_4_textarea_12":{"attribute_name":"Notice","attribute_value_mlt":[{"subitem_textarea_value":"SIG Technical Reports are nonrefereed and hence may later appear in any journals, conferences, symposia, etc."}]},"item_resource_type":{"attribute_name":"資源タイプ","attribute_value_mlt":[{"resourceuri":"http://purl.org/coar/resource_type/c_18gh","resourcetype":"technical report"}]},"item_4_source_id_11":{"attribute_name":"ISSN","attribute_value_mlt":[{"subitem_source_identifier":"2188-8655","subitem_source_identifier_type":"ISSN"}]},"item_4_description_7":{"attribute_name":"論文抄録","attribute_value_mlt":[{"subitem_description":"AES-DM (Davies-Meyer) はブロック暗号 AES を用いて暗号学的ハッシュ関数を構築するモードである.既存研究では,初期化ベクトルに差分を入れることができる free-start collision 条件での安全性評価が実施されている.一方,ハッシュ関数の安全性に直接関係する collision や semi-free-start collision 条件での衝突攻撃評価は行われていない.これらの条件では初期化ベクトルに差分を入れることができないため,メッセージ差分のみで衝突を起こす必要があり,適切な差分パスの探索や内部状態のコントロールが非常に困難になるためである.本研究では,AES のハッシュモードである AES-256-DM に対して,collision および semi-free-start collision の条件での初めての衝突攻撃評価を行う.具体的には,SAT ソルバーを用いて AES の鍵のみに差分が入力されているようなビット単位の差分パスを探索し,AES ベースのハッシュ関数に対して有効な攻撃手法であるリバウンド攻撃を適用する.評価の結果として collision の条件では 6 ラウンド,semi-free-start の条件では 9 ラウンドまで攻撃が成功することを示す.特に,semi-free collision 条件に関しては,現実的な計算量で攻撃可能であり,実際に 9 ラウンドの AES-256-DM で衝突ペアを示す.","subitem_description_type":"Other"}]},"item_4_description_8":{"attribute_name":"論文抄録(英)","attribute_value_mlt":[{"subitem_description":"AES-DM is a hashing mode used to construct a cryptographic hash function from AES. There are numerous results of free-start collision, which introduces differences in the initialization vector. However, collision and semi-free-start collision attacks have not yet been investigated for AES, which are directly related to the security of hash functions. Under these conditions, differences cannot be inserted into the initialization vector, so it is necessary to cause collisions using only message differences. This makes finding appropriate differential paths and controlling internal states extremely difficult. In this study, we introduce collision and semi-free-start collision attacks on AES-256-DM, a hashing mode of AES. Specifically, we explore bit-level differential paths where differences are inserted solely into the key of AES using a SAT solver. Additionally, we apply a rebound attack, an effective method against AES-based hash functions. As a result, we show the 6-round collision attak and 9-round semi-free-start collision attack. Furthermore, we show a collision pair for 9-round AES-256-DM for the evaluation results under the semi-free-start condition.\n","subitem_description_type":"Other"}]},"item_4_biblio_info_10":{"attribute_name":"書誌情報","attribute_value_mlt":[{"bibliographicPageEnd":"8","bibliographic_titles":[{"bibliographic_title":"研究報告コンピュータセキュリティ(CSEC)"}],"bibliographicPageStart":"1","bibliographicIssueDates":{"bibliographicIssueDate":"2024-07-15","bibliographicIssueDateType":"Issued"},"bibliographicIssueNumber":"23","bibliographicVolumeNumber":"2024-CSEC-106"}]},"relation_version_is_last":true,"weko_creator_id":"44499"}}