VLDB 2026 Research / reviewers in the wild / expert
Hyang-Sook Lee
dblp:03/1163
· DBLP profile ↗
21ranked-venue papers
5as first author
3since 2021 · last 2023
0000-0001-9506-5760ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 1 since 2021Theory of computation · 8 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Practical Randomized Lattice Gadget Decomposition with Application to FHE
Sohyun Jeon, Hyang-Sook Lee, Jeongeun Park 0001 |
ESORICS (1) | 2 |
| 2022 | On Insecure Uses of BGN for Privacy Preserving Data Aggregation ProtocolsabstractThe notion of aggregator oblivious (AO) security for privacy preserving data aggregation was formalized with a specific construction of AO-secure blinding technique over a cyclic group by Shi et al. Some of proposals of data aggregation protocols use the blinding technique of Shi et al. for BGN cryptosystem, an additive homomorphic encryption. Previously, there have been some security analysis on some of BGN based data aggregation protocols in the context of integrity or authenticity of data. Even with such security analysis, the BGN cryptosystem has been a popular building block of privacy preserving data aggregation protocol. In this paper, we study the privacy issues in the blinding technique of Shi et al. used for BGN cryptosystem. We show that the blinding techniques for the BGN cryptosystem used in several protocols are not privacy preserving against the recipient, the decryptor. Our analysis is based on the fact that the BGN cryptosystem uses a pairing e : G × G → G T and the existence of the pairing makes the DDH problem on G easy to solve. We also suggest how to prevent such privacy leakage in the blinding technique of Shi et al. used for BGN cryptosystem. Hyang-Sook Lee, Seongan Lim, Ikkwon Yie, Aaram Yun |
Fundam. Informaticae | 1 |
| 2021 | Analysis on Yu et al.'s dynamic algorithm for canonic DBC
Soo-Kyung Eom, Hyang-Sook Lee, Seongan Lim, Kyunghwan Song |
Discret. Appl. Math. | 2 |
| 2020 | New orthogonality criterion for shortest vector of lattices and its applications
Hyang-Sook Lee, Seongan Lim, Kyunghwan Song, Ikkwon Yie |
Discret. Appl. Math. | 1 |
| 2020 | Algorithms for the Generalized NTRU Equations and their Storage AnalysisabstractIn LATTE, a lattice based hierarchical identity-based encryption (HIBE) scheme, each hierarchical level user delegates a trapdoor basis to the next level by solving a generalized NTRU equation of level ℓ ≥ 3. For ℓ = 2, Howgrave-Graham, Pipher, Silverman, and Whyte presented an algorithm using resultant and Pornin and Prest presented an algorithm using a field norm with complexity analysis. Even though their ideas of solving NTRU equations can be conceptually extended for ℓ ≥ 3, no explicit algorithmic extensions with the storage analysis are known so far. In this paper, we interpret the generalized NTRU equation as the determinant of a matrix. By using the mathematical properties of the determinant, we show that how to construct algorithms for solving the generalized NTRU equation either using resultant or a field norm for any ℓ ≥ 3. We also obtain an upper bound of the size of solutions by using the properties of the determinant. From our analysis, the storage requirement of the algorithm using resultant is O(ℓ 2 n 2 log B) and that of the algorithm using a field norm is O(ℓ 2 n log B), where B is an upper bound of the coefficients of the input polynomials of the generalized NTRU equations. We present examples of our algorithms for ℓ = 3 and the average storage requirements for ℓ = 3; 4. Gook Hwa Cho, Seongan Lim, Hyang-Sook Lee |
Fundam. Informaticae | 3 |
| 2019 | On the Security of Multikey Homomorphic Encryption
Hyang-Sook Lee, Jeongeun Park 0001 |
IMACC | 1 |
| 2018 | Towards Round-Optimal Secure Multiparty Computations: Multikey FHE Without a CRS
Eunkyung Kim 0002, Hyang-Sook Lee, Jeongeun Park 0001 |
ACISP | 2 |
| 2018 | On the Non-repudiation of Isogeny Based Signature Scheme
Soo-Kyung Eom, Hyang-Sook Lee, Seongan Lim |
WISTP | 2 |
| 2018 | Key Substitution Attacks on Lattice Signature Schemes Based on SIS ProblemabstractThe notion of key substitution security on digital signatures in the multiuser setting has been proposed by Menezes and Smart in 2004. Along with the unforgeability of signature, the key substitution security is very important since it is a critical requirement for the nonrepudiation and the authentication of the signature. Lattice-based signature is a promising candidate for post-quantum cryptography, and the unforgeability of each scheme has been relatively well studied. In this paper, we present key substitution attacks on BLISS, Lyubashevsky’s signature scheme, and GPV and thus show that these signature schemes do not provide nonrepudiation. We also suggest how to avoid key substitution attack on these schemes. Youngjoo An, Hyang-Sook Lee, Juhee Lee, Seongan Lim |
Secur. Commun. Networks | 2 |
| 2017 | A Lattice Attack on Homomorphic NTRU with Non-invertible Public Keys
Soyoung Ahn, Hyang-Sook Lee, Seongan Lim, Ikkwon Yie |
ICICS | 2 |
| 2017 | Security Analysis of a Certificateless Signature from LatticesabstractTian and Huang proposed a lattice-based CLS scheme based on the hardness of the SIS problem and proved, in the random oracle model, that the scheme is existentially unforgeable against strong adversaries. Their security proof uses the general forking lemma under the assumption that the underlying hash function H is a random oracle. We show that the hash function in the scheme is neither one-way nor collision-resistant in the view of a strong Type 1 adversary. We point out flaws in the security arguments and present attack algorithms that are successful in the strong Type 1 adversarial model using the weak properties of the hash function. Seunghwan Chang, Hyang-Sook Lee, Juhee Lee, Seongan Lim |
Secur. Commun. Networks | 2 |
| 2016 | An efficient lattice reduction using reuse technique blockwisely on NTRU
Kyungmi Chung, Hyang-Sook Lee, Seongan Lim |
Discret. Appl. Math. | 2 |
| 2014 | An Efficient Decoding of Goppa Codes for the McEliece CryptosystemabstractThe McEliece cryptosystem is defined using a Goppa code, and decoding the Goppa code is a crucial step of its decryption. Patterson's decoding algorithm is the best known algorithm for decoding Goppa codes. Currently, the most efficient implementation of Patterson's algorithm uses a precomputation. In this paper, we modify Patterson's decoding algorithm so that one can remove the precomputation part while sustaining the best efficiency. Precomputations yield additional storage requirement to store the precomputed value which increases as the security level increases in McEliece cryptosystem. In the original decoding algorithm of Patterson, computing square root in a quotient field of polynomial ring over a finite field is necessary. In our modification, the computations are involved only in the arithmetics of polynomial ring over a finite field, not in the quotient field. This achieves better efficiency because one can remove polynomial reductions in the computations of quotient field. Seongan Lim, Hyang-Sook Lee, Mijin Choi |
Fundam. Informaticae | 2 |
| 2013 | Pairing Inversion via Non-degenerate Auxiliary Pairings
Seunghwan Chang, Hoon Hong, Eunjeong Lee, Hyang-Sook Lee |
Pairing | 4 |
| 2013 | Simple and exact formula for minimum loop length in Ate i pairing based on Brezing-Weng curves
Hoon Hong, Eunjeong Lee, Hyang-Sook Lee, Cheol-Min Park |
Des. Codes Cryptogr. | 3 |
| 2011 | An efficient incomparable public key encryption scheme
Hyang-Sook Lee, Seongan Lim |
Inf. Sci. | 1 |
| 2009 | Generating Pairing-Friendly Curves with the CM Equation of Degree 1
Hyang-Sook Lee, Cheol-Min Park |
Pairing | 1 |
| 2009 | Efficient and Generalized Pairing Computation on Abelian VarietiesabstractIn this paper, we propose a new method for constructing a bilinear pairing over (hyper)elliptic curves, which we call the R-ate pairing. This pairing is a generalization of the Ate and Ateipairing, and can be computed more efficiently. Using the R-ate pairing, the loop length in Miller's algorithm can be as small as log (r1/phi(k)) some pairing-friendly elliptic curves which have not reached this lower bound. Therefore, we obtain savings of between 29% and 69% in overall costs compared to the Ateipairing. On supersingular hyperelliptic curves of genus 2, we show that this approach makes the loop length in Miller's algorithm shorter than that of the Ate pairing. Eunjeong Lee, Hyang-Sook Lee, Cheol-Min Park |
IEEE Trans. Inf. Theory | 2 |
| 2008 | Eta pairing computation on general divisors over hyperelliptic curves y
Eunjeong Lee, Hyang-Sook Lee, Yoonjin Lee |
J. Symb. Comput. | 2 |
| 2007 | Eta Pairing Computation on General Divisors over Hyperelliptic Curves y2 = x7-x+/-1
Eunjeong Lee, Hyang-Sook Lee, Yoonjin Lee |
Pairing | 2 |
| 2003 | Tate Pairing Implementation for Hyperelliptic Curves y2 = xp-x + d
Iwan M. Duursma, Hyang-Sook Lee |
ASIACRYPT | 2 |