Keita Xagawa

dblp:17/5868 · DBLP profile ↗
← Back
35ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-6832-9940ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 33 · 7 first-author · 10 since 2021Theory of computation · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Strong existential unforgeability and BUFF securities of MPC-in-the-head signatures
Mukul Kulkarni, Keita Xagawa
Des. Codes Cryptogr.2
2025 The Security of ML-DSA Against Fault-Injection Attacks
Haruhisa Kosuge, Keita Xagawa
ASIACRYPT (2)2
2025 The Security of Hash-and-Sign with Retry Against Superposition Attacks
Haruhisa Kosuge, Keita Xagawa
PKC (1)2
2025 Post-Quantum Cryptographic Analysis of SSH
abstract
The Secure Shell (SSH) protocol is one of the first security protocols on the Internet to upgrade itself to resist attacks against future quantum computers, with the default adoption of the “quantum (otherwise, classically)” secure hybrid key exchange in OpenSSH from April 2022. However, there is a lack of a comprehensive security analysis of this quantum-resistant version of SSH in the literature: related works either focus on the hybrid key exchange in isolation and do not consider security of the overall protocol, or analyze the protocol in security models which are not appropriate for SSH, especially in the “post-quantum” setting. In this paper, we remedy the state of affairs by providing a thorough post-quantum cryptographic analysis of SSH. We follow a “top-down” approach wherein we first prove security of SSH in a more appropriate model, namely, our post-quantum extension of the so-called authenticated and confidential channel establishment (ACCE) protocol security model; our extension which captures “harvest now, decrypt later” attacks could be of independent interest. Then we establish the cryptographic properties of SSH's underlying primitives, as concretely instantiated in practice, based on our protocol-level ACCE security analysis: for example, we prove relevant cryptographic properties of “Streamlined NTRU Prime”, a key encapsulation mechanism (KEM) which is used in recent versions of OpenSSH and TinySSH, in the quantum random oracle model, and address open problems related to its analysis in the literature. Notably, our ACCE security analysis of post-quantum SSH relies on the weaker notion of IND-CPA security of the ephemeral KEMs used in the hybrid key exchange. This is in contrast to prior works which rely on the stronger assumption of IND-CCA secure ephemeral KEMs. Hence we conclude the paper with a discussion on potentially replacing IND-CCA secure KEMs in current post-quantum implementations of SSH with simpler and faster IND-CPA secure counterparts, and also provide the corresponding benchmarks.
Benjamin Bencina, Benjamin Dowling, Varun Maram, Keita Xagawa
SP4
2024 Signatures with Memory-Tight Security in the Quantum Random Oracle Model
Keita Xagawa
EUROCRYPT (6)1
2024 Chameleon Hashing Security Enhancement to Hierarchical Identity-Based Identification
abstract
This paper examines a security enhancement technique from a passively secure hierarchical identity-based identification (HIBI) protocol to a concurrently secure one. Two types of security enhancement techniques for the identification protocols have been proposed: one based on the OR-proof technique and the other using a chameleon hash function. The former has been examined in detail, while the latter has not been formulated in the HIBI protocol, and its close evaluation of applicability, especially in identity-selecting settings, and reduction efficiency has not been made public. We describe a transformation using a chameleon hash function and compare it with the others based on the OR-proof technique in applicability and reduction efficiency.
Atsushi Fujioka, Keisuke Saito, Taiichi Saito, Keita Xagawa
ISITA4
2022 Anonymity of NIST PQC Round 3 KEMs
Keita Xagawa
EUROCRYPT (3)1
2022 Cryptanalysis of Boyen's attribute-based encryption scheme in TCC 2013
Shweta Agrawal 0001, Rajarshi Biswas, Ryo Nishimaki, Keita Xagawa, Shota Yamada 0001
Des. Codes Cryptogr.4
2021 Fault-Injection Attacks Against NIST's Post-Quantum Cryptography Round 3 KEM Candidates
Keita Xagawa, Akira Ito 0002, Rei Ueno, Junko Takahashi, Naofumi Homma
ASIACRYPT (2)1
2021 The Boneh-Katz Transformation, Revisited: Pseudorandom/Obliviously-Samplable PKE from Lattices and Codes and Its Application
Keita Xagawa
SAC1
2020 Non-committing Encryption with Constant Ciphertext Expansion from Standard Assumptions
Yusuke Yoshida, Fuyuki Kitagawa, Keita Xagawa, Keisuke Tanaka
ASIACRYPT (2)3
2020 ModFalcon: Compact Signatures Based On Module-NTRU Lattices
abstract
Lattices lead to promising practical post-quantum digital signatures, combining asymptotic efficiency with strong theoretical security guarantees. However, tuning their parameters into practical instantiations is a delicate task. On the one hand, NIST round~2 candidates based on Lyubashevsky's design (such as dilithium and qtesla) allow several tradeoffs between security and efficiency, but at the expense of a large bandwidth consumption. On the other hand, the hash-and-sign falcon signature is much more compact and is still very efficient, but it allows only two security levels, with large compactness and security gaps between them. We introduce a new family of signature schemes based on the falcon design, which relies on module lattices. Our concrete instantiation enjoys the compactness and efficiency of falcon, and allows an intermediate security level. It leads to the most compact lattice-based signature achieving a quantum security above 128 bits.
Chitchanok Chuengsatiansup, Thomas Prest, Damien Stehlé, Alexandre Wallet, Keita Xagawa
AsiaCCS5
2020 Post-quantum Provably-Secure Authentication and MAC from Mersenne Primes
Houda Ferradi, Keita Xagawa
CT-RSA2
2020 Cryptanalysis of a rank-based signature with short public keys
Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Terry Shue Chien Lau, Chik How Tan, Keita Xagawa
Des. Codes Cryptogr.7
2020 Quantum algorithm for the multicollision problem
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa
Theor. Comput. Sci.4
2019 Quantum Random Oracle Model with Auxiliary Input
Minki Hhan, Keita Xagawa, Takashi Yamakawa
ASIACRYPT (1)2
2019 Improved Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa
PQCrypto4
2019 (Tightly) QCCA-Secure Key-Encapsulation Mechanism in the Quantum Random Oracle Model
Keita Xagawa, Takashi Yamakawa
PQCrypto1
2018 Cryptanalysis of Compact-LWE
Jonathan Bootle, Mehdi Tibouchi, Keita Xagawa
CT-RSA3
2018 Tightly-Secure Key-Encapsulation Mechanism in the Quantum Random Oracle Model
Tsunekazu Saito, Keita Xagawa, Takashi Yamakawa
EUROCRYPT (3)2
2018 Practical Cryptanalysis of a Public-Key Encryption Scheme Based on Non-linear Indeterminate Equations at SAC 2017
Keita Xagawa
PQCrypto1
2017 Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Keita Xagawa
ASIACRYPT (2)3
2017 Cryptanalysis of Comparable Encryption in SIGMOD'16
abstract
Comparable Encryption proposed by Furukawa (ESORICS 2013, CANS 2014) is a variant of order-preserving encryption (OPE) and order-revealing encryption (ORE); we cannot compare a ciphertext of v and another ciphertext of v', but we can compare a ciphertext of v and a token of b and compare a token of $b$ and another token of b'. Comparable encryption allows us to implement range and point queries while keeping the order of v's as secret as possible.
Caleb Horst, Ryo Kikuchi, Keita Xagawa
SIGMOD Conference3
2016 Public-Key Cryptosystems Resilient to Continuous Tampering and Leakage of Arbitrary Functions
Eiichiro Fujisaki, Keita Xagawa
ASIACRYPT (1)2
2015 Accumulable Optimistic Fair Exchange from Verifiably Encrypted Homomorphic Signatures
Jae Hong Seo, Keita Emura, Keita Xagawa, Kazuki Yoneyama
ACNS3
2015 Strongly secure authenticated key exchange from factoring, codes, and lattices
Atsushi Fujioka, Koutarou Suzuki, Keita Xagawa, Kazuki Yoneyama
Des. Codes Cryptogr.3
2015 Verifiably encrypted signatures with short keys based on the decisional linear problem and obfuscation for encrypted VES
Ryo Nishimaki, Keita Xagawa
Des. Codes Cryptogr.2
2013 Practical and post-quantum authenticated key exchange from one-way secure key encapsulation mechanism
abstract
This paper discusses how to realize practical post-quantum authenticated key exchange (AKE) with strong security, i.e., CK+ security (Krawczyk, CRYPTO 2005). It is known that strongly secure post-quantum AKE protocols exist on a generic construction from IND-CCA secure key encapsulation mechanisms (KEMs) in the standard model.
Atsushi Fujioka, Koutarou Suzuki, Keita Xagawa, Kazuki Yoneyama
AsiaCCS3
2012 Security Enhancements by OR-Proof in Identity-Based Identification
Atsushi Fujioka, Taiichi Saito, Keita Xagawa
ACNS3
2012 Applicability of OR-Proof Techniques to Hierarchical Identity-Based Identification
Atsushi Fujioka, Taiichi Saito, Keita Xagawa
CANS3
2012 Security Enhancement of Identity-Based Identification with Reversibility
Atsushi Fujioka, Taiichi Saito, Keita Xagawa
ICICS3
2012 Secure Hierarchical Identity-Based Identification without Random Oracles
Atsushi Fujioka, Taiichi Saito, Keita Xagawa
ISC3
2009 Efficient Public Key Encryption Based on Ideal Lattices
Damien Stehlé, Ron Steinfeld, Keisuke Tanaka, Keita Xagawa
ASIACRYPT4
2009 Zero-Knowledge Protocols for NTRU: Application to Identification and Proof of Plaintext Knowledge
Keita Xagawa, Keisuke Tanaka
ProvSec1
2008 Concurrently Secure Identification Schemes Based on the Worst-Case Hardness of Lattice Problems
Akinori Kawachi, Keisuke Tanaka, Keita Xagawa
ASIACRYPT3