Yohei Watanabe 0001

dblp:03/10316 · DBLP profile ↗
← Back
34ranked-venue papers
8as first author
22since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 7 first-author · 15 since 2021Theory of computation · 8 · 1 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Efficient Additive Randomized Encodings for String Oblivious Transfer: A Core Primitive for General Functions
Masaya Yoshimura, Kyoichi Asano, Yugo Kasashima, Mitsugu Iwamoto, Yohei Watanabe 0001
ACISP (3)5
2025 Anonymous Credentials with Credential Redaction and Its Application to SSI-Based Plug&Charge for Shared Vehicles
Kyosuke Hatsugai, Kyoichi Asano, Yuki Sawai, Yohei Watanabe 0001, Mitsugu Iwamoto
ACISP (3)4
2025 Updatable Public Key Encryption with Strong CCA Security: Security Analysis and Efficient Generic Construction
Kyoichi Asano, Yohei Watanabe 0001
CT-RSA2
2025 Correcting the Record on Leakage Abuse Attacks: Revisiting the Subgraph Attacks with Sound Evaluation
Takumi Namiki, Takumi Amada, Mitsugu Iwamoto, Yohei Watanabe 0001
ESORICS (4)4
2025 Key Revocation in Registered Attribute-Based Encryption
Kyoichi Asano, Nuttapong Attrapadung, Keisuke Hara, Keitaro Hashimoto, Yohei Watanabe 0001
PKC (3)5
2024 On the Attack Detection Performance of Information-theoretic method in Industrial Control System
abstract
Several relative entropy-based methods have been studied in cyber-attack detection of control systems. Most existing studies set the threshold values of relative entropy by trial and error such that their error probabilities become small. Meanwhile, the relationship between threshold values and error probabilities in likelihood ratio tests is clarified by Information theory. Information theory also clarifies the relationship between relative entropy and likelihood ratio test. To theoretically set the threshold, the authors have investigated the relationship between relative entropy and the likelihood ratio test using experimental data from DoS attacks and man-in-the-middle attacks on control communication (Modbus TCP). This paper investigates the relationship between threshold values and error probabilities in actual experiments. Error probabilities are classified as false positive rates and false negative rates. Neyman-Pearson lemma shows how to construct a detector that considers the trade-off between false positive and false negative rates. Stein’s lemma shows how to give optimal threshold values. We build a detector from the two lemmas that consider the trade-off with probability models of delay time between Response and ACK of Modbus TCP. We conduct experiments and discuss optimal threshold-setting methods in the sense that the false positive rates cannot be further reduced when false positive rates are fixed.
Tatsuya Nishiuchi, Yoshiki Abe, Yohei Watanabe 0001, Mitsugu Iwamoto, Kenji Sawada, Seiichi Shin
IECON3
2024 Multi-user Dynamic Searchable Encryption for Prefix-Fixing Predicates from Symmetric-Key Primitives
Takato Hirano, Yutaka Kawai, Yoshihiro Koseki, Satoshi Yasuda, Yohei Watanabe 0001, Takumi Amada, Mitsugu Iwamoto, Kazuo Ohta
SAC (1)5
2023 The Two Sheriffs Problem: Cryptographic Formalization and Generalization
Kota Sugimoto, Takeshi Nakai, Yohei Watanabe 0001, Mitsugu Iwamoto
COCOA (1)3
2023 Packet Analysis and Information Theory on Attack Detection for Modbus TCP
abstract
Cyber attacks on control system communication are increasing. In information systems, a lot of security counter-measure focusing on the distribution of communication packets has been studied so far. Such attack detection methods evaluate normal and abnormal packets based on the likelihood and the relative entropy. Whether the methods for information systems are also effective for control systems is another question. Then, this paper conducts attack detection experiments based on the likelihood and the relative entropy of DoS and spoofing attacks on Modbus TCP communication used in industrial control systems.
Tatsuya Nishiuchi, Shintaro Fujita, Yohei Watanabe 0001, Mitsugu Iwamoto, Kenji Sawada
IECON3
2023 IoT-REX: A Secure Remote-Control System for IoT Devices from Centralized Multi-designated Verifier Signatures
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata
ISPEC1
2023 Tight lower bounds and optimal constructions of anonymous broadcast encryption and authentication
abstract
Abstract Broadcast Encryption (BE) is public-key encryption allowing a sender to encrypt a message by specifing recipients, and only the specified recipients can decrypt the message. In several BE applications, since the privacy of recipients allowed to access the message is often as important as the confidentiality of the message, anonymity is introduced as an additional but important security requirement for BE. Kiayias and Samari (IH 2013) presented an asymptotic lower bound on the ciphertext sizes in BE schemes satisfying anonymity (ANO-BE for short). More precisely, their lower bound is derived under the assumption that ANO-BE schemes have a special property. However, it is insufficient to show their lower bound is asymptotically tight since it is unclear whether existing ANO-BE schemes meet the special property. In this work, we derive asymptotically tight lower bounds on the ciphertext size in ANO-BE by assuming only properties that most existing ANO-BE schemes satisfy. With a similar technique, we first derive asymptoticallyPlease provide MSC codes. For more details, please visit http://www.ams.org/msc/. tight lower bounds on the authenticator sizes in Anonymous Broadcast Authentication (ABA). Furthermore, we extend the above result and present (non-asymptotically) tight lower and upper bounds on thePlease check and confirm the Running title. ciphertext sizes in ANO-BE. We show that a variant of ANO-BE scheme proposed by Li and Gong (ACNS 2018) is optimal. We also provide tight bounds on the authenticator sizes in ABA via the same approach as ANO-BE, and propose an optimal construction for ABA.
Hirokazu Kobayashi, Yohei Watanabe 0001, Kazuhiko Minematsu, Junji Shikata
Des. Codes Cryptogr.2
2022 Efficient Dynamic Searchable Encryption with Forward Privacy under the Decent Leakage
abstract
Dynamic searchable symmetric encryption (SSE) enables clients to update and search encrypted data stored on a server and provides efficient search operations instead of leakages of inconsequential information. The amount of permitted leakage is a crucial factor of dynamic SSE; more leakage allows us to design an efficient scheme, while leakage attacks tell us that the leakage has a real-world impact. Leakage-abuse attacks (NDSS 2012) and subsequent works suggest that dynamic SSE schemes should not unnecessarily reveal extra information during the search procedure, and in particular, file-injection attacks (USENIX Security 2016) showed that forward privacy, which restricts the leakage during the addition procedure, is a vital security notion for dynamic SSE. In this paper, we propose a new dynamic SSE scheme with a good balance of efficiency and security levels; our scheme achieves both high efficiency and forward-privacy and only requires the decent leakage, i.e., only allows the leakage of search and access patterns during search operations. Specifically, we first show there is still no such scheme by uncovering a flaw in the security proof of Etemad et al.'s scheme (PoPETs 2018) and showing that extra leakage is required to fix it. We then propose the first forward-private dynamic SSE scheme that only requires symmetric-key primitives and the standard, decent leakage to prove the security. Although the client's information is slightly larger than existing schemes, our experimental results show that our scheme is comparable to Etemad et al.'s scheme, which is the most-efficient-ever scheme with forward privacy, in terms of efficiency.
Yohei Watanabe 0001, Kazuma Ohara, Mitsugu Iwamoto, Kazuo Ohta
CODASPY1
2022 Card-based Cryptographic Protocols for Private Set Intersection
Anastasiia Doi, Tomoki Ono, Takeshi Nakai, Kazumasa Shinagawa, Yohei Watanabe 0001, Koji Nuida, Mitsugu Iwamoto
ISITA5
2022 An Improvement of Multi-Party Private Set Intersection Based on Oblivious Programmable PRFs
Seiya Shimizu, Takeshi Nakai, Yohei Watanabe 0001, Mitsugu Iwamoto
ISITA3
2022 A Generic Construction of CCA-Secure Attribute-Based Encryption with Equality Test
Kyoichi Asano, Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
ProvSec4
2022 Identity-based encryption with security against the KGC: A formal model and its instantiations
abstract
The key escrow problem is one of the main barriers to the widespread real-world use of identity-based encryption (IBE). Specifically, a key generation center (KGC), which generates secret keys for a given identity, has the power to decrypt all ciphertexts. At PKC 2009, Chow defined a notion of security against the KGC, that relies on assuming that it cannot discover the underlying identities behind ciphertexts. However, this is not a realistic assumption since, in practice, the KGC manages an identity list, and hence it can easily guess the identities corresponding to given ciphertexts. Chow later amended this issue by introducing a new entity called an identity-certifying authority (ICA) and proposed an anonymous key-issuing protocol. Essentially, this allows the users, KGC, and ICA to interactively generate secret keys without users ever having to reveal their identities to the KGC. Unfortunately, since Chow separately defined the security of IBE and that of the anonymous key-issuing protocol, his IBE definition did not provide any formal treatment when the ICA is used to authenticate the users. Effectively, all of the subsequent works following Chow lack the formal proofs needed to determine whether or not it delivers a secure solution to the key escrow problem. In this paper, based on Chow's work, we formally define an IBE scheme that resolves the key escrow problem and provide formal definitions of security against corrupted users, KGC, and ICA. Along the way, we observe that if we are allowed to assume a fully trusted ICA, as in Chow's work, then we can construct a trivial (and meaningless) IBE scheme that is secure against the KGC. Finally, we present two instantiations in our new security model: a lattice-based construction based on the Gentry–Peikert–Vaikuntanathan IBE scheme (STOC 2008) and Rückert's lattice-based blind signature scheme (ASIACRYPT 2010), and a pairing-based construction based on the Boneh–Franklin IBE scheme (CRYPTO 2001) and Boldyreva's blind signature scheme (PKC 2003).
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001
Theor. Comput. Sci.3
2021 Anonymous Broadcast Authentication for Securely Remote-Controlling IoT Devices
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata
AINA (2)1
2021 Asymptotically Tight Lower Bounds in Anonymous Broadcast Encryption and Authentication
Hirokazu Kobayashi, Yohei Watanabe 0001, Junji Shikata
IMACC2
2021 Adaptively secure revocable hierarchical IBE from k-linear assumption
Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
Des. Codes Cryptogr.3
2021 Efficient identity-based encryption with Hierarchical key-insulation from HIBE
abstract
Abstract Hierarchical key-insulated identity-based encryption (HKIBE) is identity-based encryption (IBE) that allows users to update their secret keys to achieve (hierarchical) key-exposure resilience, which is an important notion in practice. However, existing HKIBE constructions have limitations in efficiency: sizes of ciphertexts and secret keys depend on the hierarchical depth. In this paper, we first triumph over the barrier by proposing simple but effective design methodologies to construct efficient HKIBE schemes. First, we show a generic construction from any hierarchical IBE (HIBE) scheme that satisfies a special requirement, called MSK evaluatability introduced by Emura et al. (Des. Codes Cryptography 89(7):1535–1574, 2021). It provides several new and efficient instantiations since most pairing-based HIBE schemes satisfy the requirement. It is worth noting that it preserves all parameters’ sizes of the underlying HIBE scheme, and hence we obtain several efficient HKIBE schemes under the k-linear assumption in the standard model. Since MSK evaluatability is dedicated to pairing-based HIBE schemes, the first construction restricts pairing-based instantiations. To realize efficient instantiation from various assumptions, we next propose a generic construction of an HKIBE scheme from any plain HIBE scheme. It is based on Hanaoka et al.’s HKIBE scheme (Asiacrypt 2005), and does not need any special properties. Therefore, we obtain new efficient instantiations from various assumptions other than pairing-oriented ones. Though the sizes of secret keys and ciphertexts are larger than those of the first construction, it is more efficient than Hanaoka et al.’s scheme in the sense of the sizes of master public/secret keys.
Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
Des. Codes Cryptogr.3
2021 Efficient revocable identity-based encryption with short public parameters
abstract
Revocation functionality is vital to real-world cryptographic systems for managing their reliability. In the context of identity-based encryption (IBE), Boldyreva, Goyal, and Kumar (ACM CCS 2008) first showed an efficient revocation method for IBE, and such an IBE scheme with the scalable revocation method is called revocable IBE (RIBE). Seo and Emura (PKC 2013) introduced a new security notion, called decryption key exposure resistance (DKER), which is a desirable security notion for RIBE. However, all existing RIBE schemes that achieve adaptive security with DKER require long public parameters or composite-order bilinear groups. In this paper, we first show an RIBE scheme that (1) satisfies adaptive security; (2) achieves DKER; (3) realizes constant-size public parameters; and (4) is constructed over prime-order bilinear groups. Our core technique relies on Seo and Emura's one (PKC 2013), which transform the Waters IBE (EUROCRYPT 2005) to the corresponding RIBE scheme. Specifically, we construct an IBE scheme that satisfies constant-size public parameters over prime-order groups and some requirements for the Seo-Emura technique, and then transform the IBE scheme to an RIBE scheme. We also discuss how to extend the proposed RIBE scheme to a chosen-ciphertext secure one and server-aided one (ESORICS 2015).
Keita Emura, Jae Hong Seo, Yohei Watanabe 0001
Theor. Comput. Sci.3
2021 Revocable identity-based encryption with bounded decryption key exposure resistance: Lattice-based construction and more
abstract
In general, identity-based encryption (IBE) does not support an efficient revocation procedure. In ACM CCS'08, Boldyreva et al. proposed revocable identity-based encryption (RIBE), which enables us to efficiently revoke (malicious) users in IBE. In PKC 2013, Seo and Emura introduced an additional security notion for RIBE, called decryption key exposure resistance (DKER). Roughly speaking, RIBE with DKER guarantees that the security is not compromised even if an adversary gets (a number of) short-term decryption keys. Therefore, DKER captures realistic scenarios and is an important notion. In this paper, we introduce bounded decryption key exposure resistance (B-DKER), where an adversary is allowed to get a-priori bounded number of short-term decryption keys in the security game. B-DKER is a weak version of DKER, but it seems to be sufficient for practical use. We obtain the following results: We propose a lattice-based (anonymous) RIBE scheme with B-DKER, which is the first lattice-based construction resilient to decryption key exposure. Our lattice-based construction is secure under the learning with errors assumption. A previous lattice-based construction satisfies anonymity but is vulnerable even with a single decryption key exposure. We propose the first pairing-based RIBE scheme that simultaneously realizes anonymity and B-DKER. Our pairing-based construction is adaptively secure under the symmetric external Diffie-Hellman assumption. Our two constructions rely on cover free families to satisfy B-DKER, whereas all the existing works rely on the key re-randomization property to achieve DKER.
Atsushi Takayasu, Yohei Watanabe 0001
Theor. Comput. Sci.2
2020 On the Power of Interaction in Signcryption
Junichi Ida, Junji Shikata, Yohei Watanabe 0001
ISITA3
2020 A Key Recovery Algorithm Using Random Key Leakage from AES Key Schedule
Tomoki Uemura, Yohei Watanabe 0001, Yang Li 0001, Noriyuki Miura, Mitsugu Iwamoto, Kazuo Sakiyama, Kazuo Ohta
ISITA2
2019 Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001
ESORICS (2)3
2019 Identity-based encryption with hierarchical key-insulation in the standard model
Junji Shikata, Yohei Watanabe 0001
Des. Codes Cryptogr.2
2018 Key-Updatable Public-Key Encryption with Keyword Search: Models and Generic Constructions
Hiroaki Anada, Akira Kanaoka, Natsume Matsuzaki, Yohei Watanabe 0001
ACISP4
2018 Card-Based Majority Voting Protocols with Three Inputs Using Three Cards
abstract
Private operations (private permutations) were independently introduced by Nakai et al. and Marcedone et al. for implementing card-based cryptographic protocols efficiently. Recently, Nakai et al. showed that, if the private operations are available, secure computations of AND and OR operations for two inputs can be realized simultaneously by using four cards, and the protocol is applied to four-card majority voting protocol with three inputs. In this paper, it is shown that only three cards are sufficient to construct the majority voting protocol with three inputs. Specifically, we propose two constructions of three-input majority voting protocols. First, assuming that players are allowed to announce their outputs, we show that one card can be reduced from Nakai et al.'s protocol without any additional private operations and communications. Our second construction requires two more private operations and communications, whereas it removes the assumption on announcement from the first construction.
Yohei Watanabe 0001, Yoshihisa Kuroki, Shinnosuke Suzuki, Yuta Koga, Mitsugu Iwamoto, Kazuo Ohta
ISITA1
2018 Timed-release computational secret sharing and threshold encryption
Yohei Watanabe 0001, Junji Shikata
Des. Codes Cryptogr.1
2017 Lattice-Based Revocable Identity-Based Encryption with Bounded Decryption Key Exposure Resistance
Atsushi Takayasu, Yohei Watanabe 0001
ACISP (1)2
2017 New Revocable IBE in Prime-Order Groups: Adaptively Secure, Decryption Key Exposure Resistant, and with Short Public Parameters
Yohei Watanabe 0001, Keita Emura, Jae Hong Seo
CT-RSA1
2015 Constructions of CCA-Secure Revocable Identity-Based Encryption
Yuu Ishida, Yohei Watanabe 0001, Junji Shikata
ACISP2
2015 Constructions of Unconditionally Secure Broadcast Encryption from Key Predistribution Systems with Trade-Offs Between Communication and Storage
Yohei Watanabe 0001, Junji Shikata
ProvSec1
2014 Timed-Release Computational Secret Sharing Scheme and Its Applications
Yohei Watanabe 0001, Junji Shikata
ProvSec1