Atsuko Miyaji

dblp:20/5513 · DBLP profile ↗
← Back
111ranked-venue papers
18as first author
28since 2021 · last 2025
0000-0001-8822-5287ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 88 · 14 first-author · 21 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 since 2021Theory of computation · 5 · 3 since 2021Artificial intelligence and machine learning · 4 · 1 first-authorSystems, architecture and hardware · 4 · 1 first-author · 1 since 2021Computer networks · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 Efficient and Privacy-Preserving Inference for Medical Images via FHE-Enhanced Split Neural Networks
abstract
Deploying deep learning models for remote medical diagnosis presents critical privacy challenges, particularly with regard to safeguarding sensitive patient data and protecting proprietary model parameters. Existing privacy-preserving techniques, such as Multi-Party Computation (MPC) and Fully Homomorphic Encryption (FHE), often suffer from high communication overhead or inadvertent exposure of model internals, limiting their practicality in real-world applications. In response, we propose a hybrid inference framework that integrates Split Neural Networks (SplitNN) with FHE to enable secure and efficient Client-Server medical diagnosis. Our approach ensures end-to-end encryption of patient data using CKKS scheme and preserves model confidentiality through an authenticated ReLU blinding protocol, which prevents information leakage during interactive computation. Additionally, we introduce a Channel-Aligned Feature Packing scheme optimized with the H-S Diagonal method to maximize throughput and minimize latency. Empirical evaluations on complex medical imaging tasks show that our framework maintains near-plaintext accuracy (within 1 %) while reducing encrypted inference latency to under 0.9 s per image, underscoring its practicality for privacy-preserving diagnostic AI.
Junyu Lin 0001, Shanbin Li, Jiageng Chen, Atsuko Miyaji
BIBM5
2025 Dynamic Self-feedback Mechanism for Improved Privacy Budgeting in LDP-SGD
Bingchang He, Atsuko Miyaji
ProvSec2
2025 Improved Constant-Time Modular Inversion
Shogo Kuramoto, Atsuko Miyaji
ProvSec2
2025 Cross-Boundary Privacy-Preserving Image Learning
abstract
We propose a privacy-preserving machine learning framework tailored for image data, called PPML with Utility Across Trust Boundaries (UAT-Boundary). This framework supports both trusted and untrusted testing environments, where the model is trained with perturbed data to ensure privacy against an untrusted learning server. In untrusted testing, test data must also be perturbed, requiring the model to maintain high utility despite the noise. In trusted testing, test data can remain unperturbed but must be adapted to a model trained on noisy inputs to achieve even higher utility. To address these challenges, we introduce image-specific local dimension reduction at the user side, and propose CWALDP, which clusters pixels and labels based on image characteristics and allocates the privacy budget per cluster. This enables controllable utility under a fixed total privacy budget. Experiments on the MNIST and FMNIST datasets using Support Vector Machines and Random Forests demonstrate that our PPML with UAT-Boundary achieves high accuracy, even when users locally perturb their images under LDP.
Atsuko Miyaji, Tomoshi Yagishita, Yuki Hyohdoh, Pierre Boudvillain
PST1
2025 Lattice-Based Key-Value Commitment Scheme
abstract
A blockchain is an important component in the design of secure distributed file systems, such as cryptocurrencies. One of the key components of the blockchain is the key-value commitment scheme, which constructs a commitment value from two inputs: a key and a value. In a conventional commitment scheme, a single user constructs a commitment value from an input value, whereas in a key-value commitment scheme, multiple users construct a commitment value from their keys and values. Both conventional and key-value commitment schemes must satisfy binding and hiding properties. The key-binding and key-hiding properties guarantee that neither the sender nor the verifier can act maliciously. The concept of a key-value commitment scheme was first proposed by Agrawal et al. in 2020 using a strong RSA assumption. Their scheme satisfies the key-binding but not key-hiding properties. In this paper, we propose two lattice-based key-value commitment schemes, Insert-KVCm/2,n,q,βand KVCm,n,q,β, that satisfy both the key-binding and the key-hiding properties. The key-binding property of both Insert-KVCm/2,n,q,βand KVCm,n,q,βare proven under the short integer solution (SIS∞n,m,q,β) problem. The key-hiding property of both Insert-KVCm/2,n,q,βand KVCm,n,q,βare proven under the Decisional-SIS∞n,m,q,β-form problem, which is newly defined in this paper. We demonstrate the difficulty of the Decisional-SIS∞ n,m,q,β-form problem by showing that the Decisional-SIS∞n,m,q,β-form problem is secure when the SIS∞ n,m,q,β problem is secure. Finally, we analyze the computational costs of Insert-KVCm/2,n,q,βand KVCm,n,q,β. Our method is the first lattice-based key-value commitment scheme with proven the key-binding and the key-hiding properties.
Hideaki Miyaji, Atsuko Miyaji
IEEE Trans. Inf. Theory2
2024 Fast and Secure Scalar Multiplication on Elliptic Curve GLS254
abstract
Elliptic curve cryptosystems (ECCs), based on the discrete logarithm problem, give compact and fast cryptosystems with smaller key sizes than Rivest-Shamir-Adleman (RSA). It is expected to be used in$\text{IoT}$devices, where available memory is limited. In addition, it is necessary to construct ECCs secure against side-channel attacks (SCA). Therefore, more compact and fast ECCs secure against SCA is needed. Elliptic curve scalar multiplication (ECSM) is the dominant computation of ECCs, and thus, it is important to build a secure, compact, and fast ECSM. GLS254 defined over$\mathbb{F}_{q^{2}}$(with$q=2^{m}$) was proposed, which gives a fast ECSM by using an endomorphism. Recently, GLS254 is improved by newly introducing$(x,\ s)$. coordinates, where an addition formula can be executed without any exception. In this study, we further improve secure, compact, and fast GLS254 by introducing additional new coordinates and optimizing ECSM. As a result, our ECSM achieves 29371 cycles on an Intel x86 CPU, which improves the best previous records by 7.1 %.
Ryosuke Kido, Atsuko Miyaji
ISITA2
2024 Privacy-Preserving Machine Learning for Generic Data
abstract
With the increasing use of personal data in recent years, privacy protection has become increasingly important. Differential privacy (DP) is a technique that protects privacy by adding noise. While DP manages privacy on a central server, Local Differential Privacy (LDP) can manage privacy locally, and LDP is preferable in terms of user privacy protection. In existing research, SUPM, a framework for applying LDP to machine learning, was proposed, which proposed WALDP, a privacy mechanism that treats all attributes uniformly regardless of data type, but it is a method specialized for continuous values. In this study, we propose a privacy-preserving machine learning method that can be applied to databases containing discrete values.
Tomoshi Yagishita, Atsuko Miyaji
ISITA2
2024 Generic CCA Secure Key Homomorphic KEM and Updatable Public Key Encryption
Kaiming Chen, Atsuko Miyaji, Jiageng Chen
ISPEC2
2024 Secure and Compact Elliptic Curve Scalar Multiplication with Optimized Inversion
abstract
Abstract Elliptic curve cryptography (ECC) is a typical public key cryptography technique that can ensure equivalent security with considerably smaller key sizes than Rivest-Shamir-Adleman (RSA). Hence, various implementations based on ECC are recommended for block chain and Internet of Things (IoT) devices. Because elliptic curve scalar multiplication (ECSM) is a fundamental computation in ECC, enhancing the security and efficiency of ECSM is important. ECSM specifies a scalar multiplication algorithm and elliptic curve addition formulae. Elliptic curve addition formulae on affine coordinates are compact from a memory cost perspective but weak against side channel attacks. Elliptic curve complete addition (CA) formulae can achieve secure ECSMs but are inefficient. A newly proposed secure ECSM, which uses a right-to-left (RL) scalar multiplication algorithm and (extended) affine coordinates, takes advantage of elliptic curve addition formulae on affine coordinates. However, it can only scan the input scalars from right to left. We propose new ECSMs, which can scan the input scalars from left to right (LR) based on (extended) affine coordinates. We also prove that our LR ECSMs satisfy secure generality without requiring exceptional computations. We enhance the efficiency of both LR and RL ECSMs with optimized inversion. Our LR ECSM with a memory of 12 field elements reduces that of the Montgomery ladder and Joye’s LR with CA formulae by 36.84% and that of 2-ary RL with (extended) affine coordinates by 14.29%, respectively. Our compact ECSMs are fit for applications on IoT devices and block chain, with a critical memory requirement.
Yaoan Jin, Atsuko Miyaji
Comput. J.2
2024 Pay-Per-Proof: Decentralized Outsourced Multi-User PoR for Cloud Storage Payment Using Blockchain
abstract
Cloud computing has been widely applied in data storage, but cloud computing is not armed with an efficient integrity check mechanism for users to learn whether their large volumes of data have been kept intact by the cloud. The concept of proofs of retrievability (PoR) was introduced to address such an issue by enabling users to check the integrity of their data stored by the cloud. But PoR requires users to regularly send queries to the cloud, and its integrity check method cannot be extended to share the verification responsibility in the multi-user setting where different users store the same data to the cloud. With such concerns in mind, we put forth a notion called outsourced multi-user proofs of retrievability ($\mathtt {OMTPoR}$) which allows users with the same data stored by the cloud to share the information for the integrity check, and a third party is required to regularly check data integrity on behalf of users using the shared information. We give a concrete construction of$\mathtt {OMTPoR}$based on the homomorphic property of an existing property and analyze its security. To enforce honest integrity checks, we build the concrete$\mathtt {OMTPoR}$construction over the blockchain using smart contracts to guarantee the honesty of participants, yielding a decentralized outsourced multi-user PoR solution that utilizes the blockchain miners as the third parties. Furthermore, our solution enables the cloud server to obtain payment for the storage service if the PoR is verified by the miners. We fully implement the$\mathtt {OMTPoR}$scheme over the blockchain to evaluate its performance, which demonstrates obvious superiority over traditional PoR schemes without the detection of data duplication.
Hui Cui 0001, Zhiguo Wan, Tianyu Zhaolu, Huaqun Wang, Atsuko Miyaji
IEEE Trans. Cloud Comput.5
2023 A Practical Forward-Secure DualRing
Nan Li 0007, Yingjiu Li, Atsuko Miyaji, Yangguang Tian, Tsz Hon Yuen
CANS3
2023 Lattice-Based Key-Value Commitment Scheme with Key-Binding and Key-Hiding Properties
Hideaki Miyaji, Atsuko Miyaji
CANS2
2023 Isogeny-Based Multi-signature Scheme
Mathieu de Goyon, Atsuko Miyaji
ISPEC2
2023 Balanced Privacy Budget Allocation for Privacy-Preserving Machine Learning
Bingchang He, Atsuko Miyaji
ISC2
2023 Constant-Size Group Signatures with Message-Dependent Opening from Lattices
Jiageng Chen, Atsuko Miyaji, Kaiming Chen
ProvSec3
2023 Re-visited Privacy-Preserving Machine Learning
abstract
Local differential privacy is a quantitative privacy metric based on indistinguishability, and the increasing complexity of recent attacks on privacy information has fostered its adoption. WALDP is a recently proposed local differential privacy mechanism, which reduces the amount of noise using dimension reduction. We focus on this mechanism and propose another dimension reduction method DR.OR using odds ratios. It is possible to maintain the original concept, i.e., data generality, by using DR.OR as a subroutine of WALDP. Previous study focused only on support vector machines (SVMs), but we also evaluated WALDP for the logistic regression and the deep neural network, and showed that WALDP achieves high accuracy as well. In particular, the proposed DR.OR boasts high accuracy, especially for logistic regression, which has a strong relationship with odds ratios. This suggests that further performance improvements can be expected by selecting a dimension reduction method in consideration of the learning model.
Atsuko Miyaji, Tatsuhiro Yamatsuki, Bingchang He, Shintaro Yamashita, Tomoaki Mimoto
PST1
2023 Authenticated Tree-Based R-LWE Group Key Exchange
abstract
Abstract We present the first constant round, multicast, authenticated tree-based R-LWE group key exchange protocol with logarithmic communication and memory complexity. Our protocol achieves post-quantum security through a reduction to a Diffie–Hellman-like analogue to the decisional R-LWE problem. We also present a sequential version with constant memory complexity but a logarithmic number of rounds and communication complexity.
Hector Bjoljahn Hougaard, Atsuko Miyaji
Comput. J.2
2023 Revocable Policy-Based Chameleon Hash for Blockchain Rewriting
abstract
Abstract Policy-based chameleon hash is a useful primitive for blockchain rewriting systems. It allows a user to create a mutable transaction associated with an access policy, whereas a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, it lacks a revocation mechanism. The modifiers can always rewrite the mutable transactions even if their given rewriting privileges are compromised. In this work, we introduce revocable policy-based chameleon. The property of revocation allows some modifiers’ rewriting privileges to be revoked, regardless of whether their rewriting privileges are compromised or not.
Yangguang Tian, Atsuko Miyaji, Koki Matsubara, Hui Cui 0001, Nan Li 0007
Comput. J.2
2022 PNB-Focused Differential Cryptanalysis of ChaCha Stream Cipher
Shotaro Miyashita, Ryoma Ito 0001, Atsuko Miyaji
ACISP3
2022 Short-Iteration Constant-Time GCD and Modular Inversion
Yaoan Jin, Atsuko Miyaji
CARDIS2
2022 Differential Cryptanalysis of Salsa20 Based on Comprehensive Analysis of PNBs
Nasratullah Ghafoori, Atsuko Miyaji
ISPEC2
2022 On the Weakness of Ring-LWE mod Prime Ideal $\mathfrak {q}$ by Trace Map
Tomoka Takahashi, Shinya Okumura, Atsuko Miyaji
SAC3
2022 Privacy-Preserving Data Analysis without Trusted Third Party
abstract
With the spread of IoT devices, various data about our lives are being collected, such as heart rate, physical activity, number of steps, pulse, oxygen intake, calorie consumption, etc. If these data can be analyzed, it will be possible to learn the signs of disease. However, it is dangerous for a person’s activity status to be managed on an external server with the view of privacy. To solve this problem, local differential privacy (LDP), which is a technique for randomly adding local noise to data, has been proposed. While ensuring privacy by LDP is certainly important, it degrades the usefulness of the analysis of data with added noise. In this paper, we propose a new mechanism to protect data privacy in both phases of training and testing based on LDP. We also make sure feasibility of our mechanism in two cases of breast cancer screening data and ionosphere data set.
Atsuko Miyaji, Tomoka Takahashi, Ping-Lun Wang, Tatsuhiro Yamatsuki, Tomoaki Mimoto
TrustCom1
2021 Efficient FPGA Design of Exception-Free Generic Elliptic Curve Cryptosystems
Kiyofumi Tanaka, Atsuko Miyaji, Yaoan Jin
ACNS (1)2
2021 Message-Restriction-Free Commitment Scheme Based on Lattice Assumption
Hideaki Miyaji, Yuntao Wang 0002, Atsuko Miyaji
ISPEC3
2021 Group Key Exchange Compilers from Generic Key Exchanges
Hector Bjoljahn Hougaard, Atsuko Miyaji
NSS2
2021 Bidder Scalable M+1st-Price Auction with Public Verifiability
abstract
$M+ 1\text{st}$-price auction, also called Vickrey auction, is a type of sealed-bid auction to sell$M$identical goods.$B$bidders secretly choose a price from$p$bidding points as their bid. The top$M$bidders can buy the goods at the$M+ 1\text{st}$bidding price. A trusted manager is commonly used to compare these sealed-bids. In our research, trusted manager and trusted mix servers used by mix and match are removed. Instead of cooperating all managers or bidders to find out the winning bidders, winning bidders prove that they are a winner by themself. By further adopt a greedy strategy on searching the$M+ 1\text{st}$-price, the time complexity of each bidder can be reduced to$O(P)$, which is the same as most previous researches. Thus, we construct a scheme that removed the manager without increasing bidders' time complexity. The implementation shows that the gas usage reduced 87% from a manager architecture in a 3 bidder and 6 bidding price setting. The cost to participate in this auction is 12,000, 000P gas or 600P US dollars at this moment, which is enough practical.
Po-Chu Hsu, Atsuko Miyaji
TrustCom2
2021 A lightweight multi-party authentication in insecure reader-server channel in RFID-based IoT
Mohammad Saiful Islam Mamun, Atsuko Miyaji, Rongxing Lu, Chunhua Su
Peer-to-Peer Netw. Appl.2
2020 Secure and Compact Elliptic Curve LR Scalar Multiplication
Yaoan Jin, Atsuko Miyaji
ACISP2
2020 Tree-Based Ring-LWE Group Key Exchanges with Logarithmic Complexity
Hector Bjoljahn Hougaard, Atsuko Miyaji
ICICS2
2020 A Practical Privacy-Preserving Algorithm for Document Data
abstract
A huge number of documents such as news articles, public reports, and personal essays has been released on websites and social media. Once documents including privacy-sensitive information are published, the risk of privacy breaches increases; thus, documents should be carefully checked before publication. In many cases, human experts redact or sanitize documents before publishing; however, this approach is sometimes inefficient with regard to its cost and accuracy. Furthermore, critical privacy risks may remain in the documents. In this paper, we present a generalized adversary model and apply it to document data. This paper devises an attack algorithm for documents, which uses a web search engine, and proposes a privacy-preserving algorithm against the attacks. We evaluate the privacy risks for real accident reports from schools and court documents. As experiments using the real reports, we show that human-sanitized documents still include privacy risks, and our proposal would contribute to risk reduction.
Tomoaki Mimoto, Shinsaku Kiyomoto, Koji Kitamura, Atsuko Miyaji
TrustCom4
2019 Secure and Compact Elliptic Curve Cryptosystems
abstract
Elliptic curve cryptosystems (ECCs) are widely used because of their short key size. They can ensure enough security with shorter keys, and use less memory space to reduce parameters. Hence, an elliptic curve is typically used in embedded systems. The dominant computation of an ECC is scalar multiplication $$Q = kP, P \in E({\mathbb F}_{q})$$ . Thus, the security and efficiency of scalar multiplication are paramount. To render secure ECCs, complete addition formulae can be employed for a secure scalar multiplication. However, this requires significant memory and is thus not suitable for compact devices. Several coordinates exist for elliptic curves such as affine, Jacobian, projective. The complete addition formulae are not based on affine coordinates and thus require considerable memory. In this study, we achieved a compact ECC by focusing on affine coordinates. In fact, affine coordinates are highly advantageous in terms of memory but require many if statements for scalar multiplication owing to exceptional points. We improve the scalar multiplication and reduce the limitations for input k. Furthermore, we extend the affine addition formulae to delete some exceptional inputs for scalar multiplication. Our compact ECC reduces memory complexity up to 26 % and is much more efficient compared to Joye’s RL 2-ary algorithm with the complete addition of formulae when the ratio I / M of computational complexity of inversion (I) to multiplication (M) is less than 7.2.
Yaoan Jin, Atsuko Miyaji
ACISP2
2019 An Improved Security Analysis on an Indeterminate Equation Public Key Cryptosystem by Evaluation Attacks
Akifumi Muroi, Shinya Okumura, Atsuko Miyaji
SAC3
2018 New Iterated RC4 Key Correlations
Ryoma Ito 0001, Atsuko Miyaji
ACISP2
2018 Revisited Diffusion Analysis of Salsa and ChaCha
abstract
Both ChaCha and AES are standardized as symmetric ciphers in TLS 1.3; AES is a block cipher, whereas ChaCha is a stream cipher. The security of AES has been studied by many researchers. ChaCha, however, needs more security analysis because it has been proposed more recently, compared with AES. Furthermore, ChaCha is improved from Salsa from the point of view of diffusion and thus, diffusion analysis of Salsa and ChaCha is important to understand their security-design criteria. In this study, we revisit diffusion analysis and investigate weak bits and weak columns of Salsa and ChaCha. To the authors'knowledge, this is the first detailed diffusion analysis of Salsa and ChaCha.
Yusuke Matsuoka, Atsuko Miyaji
ISITA2
2018 An Experimental Analysis on Lattice Attacks against Ring-LWE over Decomposition Fields
abstract
The ring variant of learning with errors (Ring-LWE) problem has provided efficient post-quantum cryptographic schemes including homomorphic encryption (HE) schemes. Usually, cyclotomic fields are used as underlying number fields of Ring-LWE from the viewpoints of efficiency and security. However, especially in the case of HE schemes, improving the efficiency and ensuring the security are important tasks even now. Arita and Handa proposed to use decomposition fields as underlying number fields of Ring-LWE and successfully constructed a HE scheme which can encrypt many plaintexts efficiently at a time. However, there is no enough evidence that decomposition fields do not provide weak Ring-LWE instances.In this paper, we give an experimental analysis on lattice attacks against Ring-LWE over decomposition fields. More precisely, we conducted lattice attacks against Ring-LWE over decomposition fields and over the ℓ-th cyclotomic fields with some prime numbers ℓ, respectively, and compared each of the running-time, the success rate and the root hermite factor. We also compared the results of the same attacks on various decomposition fields to find decomposition fields providing weak Ring-LWE instances. As a result of our analysis, we expect that decomposition fields would provide more secure and efficient HE schemes based on Ring-LWE compared to the ℓ-th cyclotomic fields.
Shota Terada, Hideto Nakano, Shinya Okumura, Atsuko Miyaji
ISITA4
2018 The Possibility of Matrix Decomposition as Anonymization and Evaluation for Time-sequence Data
abstract
Time-sequence data is high dimensional and con- tains a lot of information, which can be utilized in various fields, such as insurance, finance, and advertising. Personal data including time-sequence data is often converted to anonymized datasets, which need to strike a balance between both privacy and utility. In this paper, we consider low-rank matrix decomposition as one of the anonymization methods and evaluate its efficiency. We convert time-sequence datasets to matrices and evaluate both privacy and utility. The record IDs in time-sequence data are changed at regular intervals to reduce re-identification risk. However, since individuals tend to behave in a similar fashion over periods of time, there remains a risk of record linkage even if record IDs are different. Hence, we evaluate the re- identification and linkage risks as privacy risks of time-sequence data. Our experimental results show that matrix decomposition is a viable anonymization method and it can achieve better utility than existing anonymization methods.
Tomoaki Mimoto, Shinsaku Kiyomoto, Seira Hidano, Anirban Basu 0001, Atsuko Miyaji
PST5
2018 Efficient and Quasi-accurate Multiparty Private Set Union
abstract
Both scalability and flexibility have become crucial for privacy-preserving protocols in the age of big data. Multiparty private set union (MPSU) is an important privacy-preserving protocol. Previous MPSU protocols for multisets based on a polynomial are not efficient, although they output a precise set union. However, the previous MPSU implementation based on a Bloom filter is efficient but only roughly estimates the number of duplicates of the set union. In this paper, we propose a new duplicated Bloom filter to increase the chances of computing the number of duplicates correctly. Using this filter, we propose a scalable and flexible MPSU for multisets.
Katsunari Shishido, Atsuko Miyaji
SMARTCOMP2
2018 SupAUTH: A new approach to supply chain authentication for the IoT
abstract
Abstract Recent advances of the Internet of Things (IoT) technologies have enhanced the use of radio‐frequency identification‐based tracking system to be widely deployed in supply chain management covering every step involved in the flow of merchandise from the supplier to the customer to ensure a trustworthy delivery environment. Such authentication system (also known as path authentication) not only guarantees the merchandise to be available in the right destination with no discrepancies and errors but also ensures the route of the merchandise progress to be valid. This paper outlines the current state‐of‐the‐art cryptographic solutions for path authentication, highlights their properties and weakness, and proposes a novel, privacy‐preserving, and efficient solution. Compared with the existing elliptic curve ElGamal re‐encryption–based solution, our homomorphic message authentication code on arithmetic circuit–based solution offers less memory storage (with limited scalability) and no computational requirement on the reader. Moreover, we allow computational ability inside the tag that articulates a new privacy direction to the state‐of‐the‐art path privacy. This privacy notion helps support the confidentiality of the tag movement in the context of IoT‐enabled cross‐organizational tracking environment where the stakeholders can be from different organizations associated together with the merchandise being delivered. As a potential extension to the path authentication protocol, we further propose a polynomial‐based mutual authentication as a security extension and batch initialization as an efficiency extension. Besides our brief security and privacy analysis, our evaluation shows that the proposed solution can significantly reduce memory requirements on tags with marginal computational overhead to ensure transmission path confidentiality. We observe that SupAUTH requires maximum 513‐bit tag memory and 57.3 ms of processing time during evaluation, which is not only practical but also suitable for any suitable low‐cost radio‐frequency identification deployment in IoT.
Mohammad Saiful Islam Mamun, Ali A. Ghorbani 0001, Atsuko Miyaji, Uyen Trang Nguyen
Comput. Intell.3
2018 OTP-IoT: An ownership transfer protocol for the Internet of Things
Mohammad Saiful Islam Mamun, Chunhua Su, Anjia Yang, Atsuko Miyaji, Ali A. Ghorbani 0001
J. Inf. Secur. Appl.4
2017 Robust ORAM: Enhancing Availability, Confidentiality and Integrity
abstract
Oblivious RAM (ORAM) is a primitive for hiding storage access patterns in the context of software protection. With the trend of cloud computing, ORAM also has important applications in privacy-preserving cloud storage applications. Many ORAMs for cloud storage have been proposed to improve efficiency and security. However, data availability, data confidentiality, and data integrity have not been simultaneously addressed. In this paper, we formalize a new concept of ORAM called RORAM (Robust ORAM by enhancing availability, confidentiality and integrity), which can deal with these three challenges. Furthermore, RORAM not only can achieve a higher security level but also is more efficient compared with previous ORAMs by using linear network coding to reduce the client's computational cost of block encryption/decryption in every read/write operation in previous ORAMs. The security and complexity analyses show that RORAM is provably secure and highly lightweight.
Tran Thao Phuong, Atsuko Miyaji, Mohammad Shahriar Rahman, Shinsaku Kiyomoto, Ayumu Kubota
PRDC2
2017 Variable message encryption through blockcipher compression function
abstract
Summary A constrained device is an emerging technology that has enormous applications in our daily life such as access control, inventory control, luggage tracking, bar‐code reader, and IoT. However, it has certain drawbacks of low memory and less computing power. Thus, one of the cracking challenges is to provide efficient and secure cryptographic solution for the constrained device in the aspect of security issue. An (n,n) blockcipher‐based cryptographic compression function is applicable to provide provable security to the constrained device. Though, there are many constructions of (n,n) blockcipher such as MDC‐2, MDC‐4, MJH, Bart‐12, and SKS‐15. However, most of the familiar schemes are not suitable for short and variable message encryption without padding because of their internal structures. Furthermore, the security margin is provided based on blocklength rather than the flexible size of message. In this paper, we present two different (n,n) blockcipher compression function schemes. The first scheme (FS) satisfies better efficiency such as less call of blockcipher, less key scheduling, and higher efficiency rate. On the contrary, the second scheme (SS) has upper security bound. Moreover, both of the schemes are suitable for small and variable message encryption (message size = tn|t < 1,n:blocklength), which is handy for the constrained device. The collision and preimage security bound of the FS are O(2tn/2) and O(2tn). In addition, the SS's collision resistance and preimage resistance are bounded by O(2tn) and O(22tn). Moreover, the efficiency rate of the proposed two schemes are respectively t and t/3. The numbers of key scheduling are 2 for the constructions of FS and SS. We use two calls of blockcipher in the FS. On the contrary, three calls of blockcipher are used in the SS. Copyright © 2016 John Wiley & Sons, Ltd.
Jiageng Chen, Mazumder Rashed, Atsuko Miyaji, Chunhua Su
Concurr. Comput. Pract. Exp.3
2017 A simple authentication encryption scheme
abstract
Summary An authentication encryption (AE) scheme satisfies to transfer an authenticated data between 2 parties or more. There are vast applications of the AE such as access control, encryption, enhancing trust between multiple parties, and assure the originality of a message. However, the main challenge of the AE is to maintain low‐cost features for its construction. Furthermore, there is another emerging issue of Internet of Things (IoT) in the field of data and network communication. The numbers of application of the IoT are increasing expeditiously, where various kinds of device have been used such as IoT‐end device, constrained device, and RfID. Moreover, the main challenge of the IoT‐end devices and resource constrained devices is to keep a certain level of security bound including minimum cost. However, the IoT‐end devices, resource constrained devices, and RfID have lack of resources such as memory, power, and processors. Interestingly, the AE can play a vital role between data acquisition (sensors, actuators) and data aggregation of usual platform of the IoT. Thus, the construction of the AE should satisfy the properties of low‐cost, least resources, and less operating‐time. Though, there are many familiar constructions of AE such as OTR, McOE, POE, OAE, APE, COPE, CLOC, and SILK but most of the schemes depend on the features of nonce and associate data. In the aspect of security, the usage of nonce and associated data are adequate. However, these 2 features increase the overhead cost. Therefore, we propose a simple construction of IV‐based AE where blockcipher compression function is used as encryption function. Our proposed scheme's efficiency‐rate is 1 with reasonable privacy‐security bound. In addition, it can encrypt arbitrary length of message in each iteration without padding.
Mazumder Rashed, Atsuko Miyaji, Chunhua Su
Concurr. Comput. Pract. Exp.2
2017 Recursive Matrix Oblivious RAM: An ORAM Construction for Constrained Storage Devices
abstract
Oblivious random access machine (ORAM) constructions can be used to hide a client's access pattern from a trusted but curious storage server. The privacy provided comes at the cost of increasing communication overhead, storage overhead, and computation overhead of the system. Recursive matrix-based ORAM (RM-ORAM) is a new ORAM construction, which is designed for constrained storage space devices. RM-ORAM significantly reduces the client storage usage by using recursion, while the computational and bandwidth overhead are slightly increased as a tradeoff. However, it can achieve better overall asymptotic performance than other existing ORAM schemes, e.g., recursive Path ORAM. In this paper, we present the construction and its theoretical analysis. In addition, we present how to select the appropriate number of data blocks, which are being downloaded per level of recursion and the appropriate size of reserved space on the client. We provide theoretical security and performance analysis, as well as experimental results to illustrate how RM-ORAM satisfies security requirements and provides improved performance compared with other ORAM schemes.
Xinyi Huang 0001, Atsuko Miyaji, Chunhua Su, Karin Sumongkayothin, Komwut Wipusitwarakun
IEEE Trans. Inf. Forensics Secur.3
2016 Secure and Traceable Framework for Data Circulation
Kaitai Liang, Atsuko Miyaji, Chunhua Su
ACISP (1)2
2016 Security and experimental performance analysis of a matrix ORAM
abstract
Oblivious RAM can hide a client's access pattern from an untrusted storage server. However current ORAM schemes incur a large communication overhead and/or client storage overhead, especially as the server storage size grows. We have proposed a matrix-based ORAM, M-ORAM, that makes the communication overhead independent of the server size. This requires selecting a height of the matrix; we present how to select the height to match the functionality of the well-known Path ORAM. We then given both theoretical models and experimental results that show M-ORAM can achieve a lower communication overhead than Path ORAM, without a significant increase in maximum client storage overhead.
Atsuko Miyaji, Chunhua Su, Karin Sumongkayothin
ICC2
2015 How TKIP Induces Biases of Internal States of Generic RC4
Ryoma Ito 0001, Atsuko Miyaji
ACISP2
2015 A New (n, 2n) Double Block Length Hash Function Based on Single Key Scheduling
abstract
In this paper we propose a double block length hash function called MR-MMO. Our scheme satisfies two calls of (n, 2n) block cipher and can compress 3n bits to 2n bits (n = 128 bits). The Collision Resistance (CR) and Preimage Resistance (PR) of MR-MMO are respectively 2126.70and 2252.5. Surprisingly, the collision security bound of our scheme is the best in compare with other existing schemes. We use a single key scheduling for each compression function which is great in respect of cost and time. Additionally, it can be said that the proof technique of Weimar-DM, Tandem-DM, Hirose-DM are based on Ideal Cipher Model (ICM) while we use Weak Cipher Model (WCM) tool. Davies Meyer (DM) mode is used in the above all schemes, we also made a change using Matyas Meyer Oseas (MMO) mode. It is also obvious that the proof technique of our scheme is very simple, straightforward and easy to understand.
Atsuko Miyaji, Mazumder Rashed
AINA1
2015 Accurate Estimation of the Full Differential Distribution for General Feistel Structures
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Je Sen Teh
Inscrypt2
2015 A Single Key Scheduling Based Compression Function
Jiageng Chen, Mazumder Rashed, Atsuko Miyaji
CRiSIS3
2015 Improved Differential Characteristic Searching Methods
abstract
The success probability of differential and linear cryptanalysis against block ciphers heavily depend on finding differential or linear paths with high statistical bias compared with uniform random distribution. For large number of rounds, it is not a trivial task to find such differential or linear paths. Matsui first investigated this problem and proposed a solution based on a branch and bound algorithm in 1994. Since then, the research on finding good concrete differential or linear path did not receive much attention. In this paper, we revisit the differential attack against several S-Box based block ciphers by carefully studying the differential characteristics. Inspired by Matsui's algorithm, we provide an improved solution with the aid of several searching strategies, which enable us to find by far the best differential characteristics for the two investigated ciphers (LBlock, TWINE) efficiently. Furthermore, we provide another way to evaluate the security of ciphers against differential attack by comparing the strength of the ciphers from differential characteristic's point of view, and we also investigate the accuracy when using the active S-Box to evaluate the security margin against differential attack, which is the common method adapted when new ciphers are designed.
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Je Sen Teh
CSCloud2
2015 New Linear Correlations Related to State Information of RC4 PRGA Using IV in WPA
Ryoma Ito 0001, Atsuko Miyaji
FSE2
2015 A New Statistical Approach for Integral Attack
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Liang Zhao 0020
NSS2
2015 A Scalable Multiparty Private Set Intersection
Atsuko Miyaji, Shohei Nishida
NSS1
2015 Self-healing wireless sensor networks
abstract
Summary Availability is very important for long‐term use of wireless sensor networks (WSNs), assuming the presence of an attacker. It is thus important to achieve secure communication among WSNs even if some sensor nodes are compromised. Self‐healing WSNs possess the feature that a network automaticallyself‐healsafter node‐capture attacks in order to achieve availability. The self‐healing means that the ratio of compromised links decreases with time, even if the attacker corrupts sensor nodes of the network. In this paper, three kinds of self‐healing schemes for WSNs are described, a polynomial‐based self‐healing scheme, a simple random key pre‐distribution scheme with self‐healing, and a proactive co‐operative link self‐healing scheme. Our contributions are the self‐healing schemes with security evaluation, in which we conduct analytical evaluation and a simulation experiment of our schemes, and results obtained from both analysis and simulations indicate that our schemes are effective in self‐healing. Furthermore, comparing three schemes, we clarify each difference and discuss optimal scheme under each different environments. © 2015 The Authors.Concurrency and Computation: Practice and ExperiencePublished by John Wiley & Sons Ltd.
Atsuko Miyaji, Kazumasa Omote
Concurr. Comput. Pract. Exp.1
2015 An efficient batch verification system and its effect in a real time VANET environment
abstract
ABSTRACT Vehicle ad hoc network (VANET) provides communication between vehicles and vehicle‐to‐infrastructure communication. High mobility, high speed of vehicles, fast topology changes, and sheer scale are some characteristics that establish VANET as an intensive research topic different from other types of mobile ad hoc network. In this paper, we improve an existing batch verification system on ID‐based group signature and also compare the performance achieved. Then, we analyze the best possible value of the number of signatures to batch at a time for large‐scale VANET. In addition, we introduce a scheduling algorithm for signature verification where batch verification cannot be implemented efficiently. Copyright © 2014 John Wiley & Sons, Ltd.
Jiageng Chen, Mohammad Saiful Islam Mamun, Atsuko Miyaji
Secur. Commun. Networks3
2015 Generic constructions of secure-channel free searchable encryption with adaptive security
abstract
Abstract For searching keywords against encrypted data, public key encryption scheme with keyword search (PEKS), and its extension secure‐channel free PEKS (SCF‐PEKS), has been proposed. In this paper, we extend the security of SCF‐PEKS, calling it adaptive SCF‐PEKS, wherein an adversary (modeled as a “malicious‐but‐legitimate” receiver) is allowed to issue test queries adaptively. We show that adaptive SCF‐PEKS can be generically constructed by anonymous identity‐based encryption only. That is, SCF‐PEKS can be constructed without any additional cryptographic primitive when compared with the Abdallaet al.PEKS construction (J. Cryptology 2008), even though adaptive SCF‐PEKS requires additional functionalities. We also propose other adaptive SCF‐PEKS construction, which is not fully generic but is efficient compared with the first one. Finally, we instantiate an adaptive SCF‐PEKS scheme (via our second construction) that achieves a similar level of efficiency for the costs of the test procedure and encryption, compared with the (non‐adaptive secure) SCF‐PEKS scheme by Fanget al.(CANS2009). Copyright © 2014 John Wiley & Sons, Ltd.
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman, Kazumasa Omote
Secur. Commun. Networks2
2014 RFID Path Authentication, Revisited
abstract
In an RFID-enabled supply chain, where items are outfitted with RFID tags, path authentication based on tag enables the destination checkpoints to validate the route that a tag has already accessed. In this work, we propose a novel, efficient, privacy-preserving path authentication system for RFID-enabled supply chains. Compared to existing Elliptic curve Elgamal Re-encryption (ECElgamal) based solution, our Homomorphic Message authentication Code on arithmetic circuit (HomMAC) based solution offers less memory storage (with limited scalability) and no computational requirement on the reader. However, unlike previous schemes, we allow computational ability inside the tag that consents a new privacy direction to path privacy proposed by Cai et al. in ACNS012. In addition, we customize a polynomial-based authentication scheme (to thwart potential tag impersonation and Denial of Service (DoS) attacks), so that it fits our new path authentication protocol.
Mohammad Saiful Islam Mamun, Atsuko Miyaji
AINA2
2014 A Scalable and Secure RFID Ownership Transfer Protocol
abstract
Ownership transfer in an RFID inventory system experiences many security and privacy oriented problems. We consider scenarios related to ownership transfer of RFID tags in a large inventory system. In this paper, we propose a new mutual authentication protocol from Ring LPN problem that leverages the reader authentication phase to incorporate Semi-Trusted Parties (STP) seamlessly in RFID ownership transfer protocol. Employing STPs could ease the ownership transfer process for the consumers in the remote location. More precisely, we introduce a new variant of Learning Parity from Noise (LPN) based mutual authentication scheme for efficient ownership transfer protocol where ownership of multiple tags can be transferred from one owner to another by taking advantages of an efficient homomorphic aggregated signature (HomSig) and pseudo-inverse matrix properties. To the best of our knowledge, this is the first RFID ownership transfer protocol from LPN problem that is secure, private and scalable under standard model.
Mohammad Saiful Islam Mamun, Atsuko Miyaji
AINA2
2014 Distributed Pseudo-Random Number Generation and Its Application to Cloud Database
Jiageng Chen, Atsuko Miyaji, Chunhua Su
ISPEC2
2014 Improving Impossible Differential Cryptanalysis with Concrete Investigation of Key Scheduling Algorithm and Its Application to LBlock
Jiageng Chen, Yuichi Futa, Atsuko Miyaji, Chunhua Su
NSS3
2014 A Provable Secure Batch Authentication Scheme for EPCGen2 Tags
Jiageng Chen, Atsuko Miyaji, Chunhua Su
ProvSec2
2014 Secure VANET applications with a refined group signature
abstract
This paper proposes an application-friendly group signature (GS) model for wireless ad hoc network like Wireless Sensor Networks (WSN) or Vehicle ad hoc Network (VANET). Our new GS properties can be used to carry out potential solution to some real life problems. We modify Boneh, Boyen and Shacham (BBS) short GS to meet a restricted, but arguably sufficient set of privacy properties. In particular, we aggregate linking, direct opening, message-dependent opening (MDO), revoking, batch-verification in a single short GS scheme. Our link manager can link messages whether they are coming from the same messages or not without colluding to the opener. It helps relaxing strong privacy properties of GS to a lightly lesser one that fit certain application requirement. We introduce a new application to the ad hoc network security, that is, value-added service provider (VSP) with the help of MDO properties and redesign the traditional GS-friendly VANET architecture. Our revocation algorithm adapts both rekeying and verifier-local revocation (VLR) approaches to revoke illegitimate signers in a constant time. Finally, we present an optional batch verification system to expedite signature verification. Note that all these properties have already been shown in the literature scatteredly. The novelty of our proposal stems from accumulating all these properties in a single GS scheme that can best fit to the application demand.
Mohammad Saiful Islam Mamun, Atsuko Miyaji
PST2
2013 How to Build Random Key Pre-distribution Schemes with Self-Healing for Multiphase WSNs
abstract
In this paper, we propose a simple random key pre-distribution (RKP) scheme with self-healing for multiphase wireless sensor networks (WSNs) without even lightweight operations such as a hash function, in which the link compromised by node-capture attack in a WSN automatically self-heals with time. Our scheme can enhance the resiliency of existing RKP schemes by only updating the key pool of a server with time. As a result, processing of each sensor is still the same as in the RKP schemes. More interestingly, round synchronization is not necessary to be implemented in a node. Our contribution is the simple scheme with security evaluation, in which we conduct analytical evaluation and a simulation experiment of our scheme, and results obtained from both analysis and simulations indicate that our scheme is effective in self-healing.
Atsuko Miyaji, Kazumasa Omote
AINA1
2012 How to Enhance the Security on the Least Significant Bit
Atsuko Miyaji, Yiren Mo
CANS1
2012 Lightweight Integrity for XOR Network Coding in Wireless Sensor Networks
Kazuya Izawa, Atsuko Miyaji, Kazumasa Omote
ISPEC2
2012 A Secure and Private RFID Authentication Protocol under SLPN Problem
Mohammad Saiful Islam Mamun, Atsuko Miyaji, Mohammad Shahriar Rahman
NSS2
2011 Toward Dynamic Attribute-Based Signcryption (Poster)
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman
ACISP2
2011 T-Robust Scalable Group Key Exchange Protocol with O(logn) Complexity
Tetsuya Hatano, Atsuko Miyaji
ACISP2
2011 Privacy-Preserving Data Mining: A Game-Theoretic Approach
Atsuko Miyaji, Mohammad Shahriar Rahman
DBSec1
2011 Non-interactive Opening for Ciphertexts Encrypted by Shared Keys
Jiageng Chen, Keita Emura, Atsuko Miyaji
ICICS3
2011 Unconditionally Secure Oblivious Transfer Based on Channel Delays
Kai-Yuen Cheong, Atsuko Miyaji
ICICS2
2011 Ideal Secret Sharing Schemes with Share Selectability
Keita Emura, Atsuko Miyaji, Akito Nomura, Mohammad Shahriar Rahman, Masakazu Soshi
ICICS2
2011 How to Find Short RC4 Colliding Key Pairs
Jiageng Chen, Atsuko Miyaji
ISC2
2011 Adaptive Secure-Channel Free Public-Key Encryption with Keyword Search Implies Timed Release Encryption
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ISC2
2011 POLISH: Proactive Co-operative LInk Self-Healing for Wireless Sensor Networks
Tatsuro Iida, Atsuko Miyaji, Kazumasa Omote
SSS2
2010 Efficient Privacy-Preserving Data Mining in Malicious Model
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman
ADMA (1)2
2010 Privacy-Preserving Data Mining in Presence of Covert Adversaries
Atsuko Miyaji, Mohammad Shahriar Rahman
ADMA (1)1
2010 Co-Z Addition Formulæ and Binary Ladders on Elliptic Curves - (Extended Abstract)
Raveen R. Goundar, Marc Joye, Atsuko Miyaji
CHES3
2010 A New Practical Key Recovery Attack on the Stream Cipher RC4 under Related-Key Model
Jiageng Chen, Atsuko Miyaji
Inscrypt2
2010 Redesigning Group Key Exchange Protocol Based on Bilinear Pairing Suitable for Various Environments
Yvo Desmedt, Atsuko Miyaji
Inscrypt2
2010 RPoK: A Strongly Resilient Polynomial-Based Random Key Pre-Distribution Scheme for Multiphase Wireless Sensor Networks
abstract
In this paper, we propose a strongly resilient polynomial-based random key pre-distribution scheme for multiphase wireless sensor networks (RPoK): a private sub-key is not directly stored in each sensor node by applying the polynomial-based scheme to the RoK scheme. Such a polynomial is linearly transformed using forward and backward keys in order to achieve the forward and backward security of polynomials. As a result, our scheme achieves a large reduction of the ratio of compromised links by enhancing the security of the previous RoK scheme. The results obtained analytically and by simulations show that our scheme can dramatically improve the ratio of compromised links compared with the RoK scheme.
Hisashige Ito, Atsuko Miyaji, Kazumasa Omote
GLOBECOM2
2010 A New Class of RC4 Colliding Key Pairs with Greater Hamming Distance
Jiageng Chen, Atsuko Miyaji
ISPEC2
2010 An Anonymous Designated Verifier Signature Scheme with Revocation: How to Protect a Company's Reputation
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ProvSec2
2010 A Timed-Release Proxy Re-encryption Scheme and Its Application to Fairly-Opened Multicast Communication
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ProvSec2
2009 A Dynamic Attribute-Based Group Signature Scheme and its Application in an Anonymous Survey for the Collection of Attribute Statistics
abstract
Recently, cryptographic schemes based on the user's attributes have been proposed. An attribute-based group signature (ABGS) scheme is a kind of group signature schemes, where a user with a set of attributes can prove anonymously whether she has these attributes or not. An access tree is applied to express the relationships among some attributes. However, previous schemes do not provide the changing an access tree. In this paper, we propose a dynamic ABGS scheme that enables an access tree to be changed. Our ABGS is efficient in that re-issuing of the attribute certificate previously issued for each user is not necessary. Moreover, calculations depending on the number of attributes are calculated on the domain of a pairing. Therefore, the number of calculations in a pairing does not depend on the number of attributes associated with a signature. Finally, we discuss how our ABGS can be applied to an anonymous survey for collection of attribute statistics.
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ARES2
2009 A Certificate Revocable Anonymous Authentication Scheme with Designated Verifier
abstract
In IEEE ISI 2008, an anonymous attribute authentication scheme has been proposed using a self-blindable certificate scheme. This scheme enables the anonymity and certificate revocation. A Certificate Revocation List (CRL) is used in the revocation check. Even if an attacker can obtain a CRL, the attacker cannot execute the revocation check. This means that this scheme enables the designated revocation. However, this scheme is not secure, namely, a user can make a forged proof using a public value. In this paper, we propose a certificate revocable anonymous authentication scheme with designated verifier. Our scheme enables the anonymity and certificate revocation. Moreover, our scheme enables a designated verification and revocation.
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ARES2
2009 New Correlations of RC4 PRGA Using Nonzero-Bit Differences
Atsuko Miyaji, Masahiro Sukegawa
ACISP1
2009 A Secure RFID Authentication Protocol with Low Communication Cost
abstract
Gene Tsudik proposed a trivial RFID authentication protocol (YA-TRAP), where a valid tag can become incapacitated after exceeding the prestored threshold value and is thus vulnerable to DoS attack. Our scheme solves the problem by allowing a tag to refresh its prestored threshold value. Moreover, our scheme is forward secure and provides reader authentication, resistance against timing, replay, tracking attacks. We show the use of aggregate hash functions in our complete scheme to reduce the reader to server communication cost. The reader uses partial authentication to keep the rogue tags out of the aggregate function.
Mohammad Shahriar Rahman, Masakazu Soshi, Atsuko Miyaji
CISIS3
2009 Elliptic curves with a pre-determined embedding degree
abstract
A pairing over an elliptic curve E(Fpm) to an extension field of Fpmkhas begun to be attractive in cryptosystems, where k is called the embedding degree. The cryptosystems using a pairing are called the pairing-based cryptosystems. The embedding degree k is also an indicator of the relationship between the elliptic curve discrete logarithm problem (ECDLP) and the discrete logarithm problem (DLP), where ECDLP over E(Fpm) is reduced to DLP over Fpmk. An elliptic curve is determined by j-invarient or order, however the explicit condition between these parameters and an embedding degree has been described only in some degrees. In this paper, we investigate a new condition of the existence of elliptic curves with pre-determined embedding degrees, and present some examples of the elliptic curves over 160-bit, 192-bit and 224-bit Fpm.
Shoujiro Hirasawa, Atsuko Miyaji
ISIT2
2009 A Ciphertext-Policy Attribute-Based Encryption Scheme with Constant Ciphertext Length
Keita Emura, Atsuko Miyaji, Akito Nomura, Kazumasa Omote, Masakazu Soshi
ISPEC2
2008 Security and Access Control for Vehicular Communications
abstract
In this paper, we present an architecture for security and access control in Intelligent Transportation Systems. The applicability of the proposed architecture is demonstrated by developing a case-study based on CVIS(collaborative vehicle infrastructure system). The proposed framework ensures maximum security for the communication infrastructure by implementing access control at both the data link layer and the network layer. The originality of the proposed framework consists on adoption of a universal security mechanism approach by using the Kerberos protocol for link layer authentication as well as for establishing IPSec security associations, which simplifies credential management and ensures reduced overhead. The operations of the EAP-Kerberos authentication method that we have designed and implemented for the purpose of this project is also presented.
Saber Zrelli, Atsuko Miyaji, Yoichi Shinoda, Thierry Ernst
WiMob2
2007 Mobile Agent Security with Efficient Oblivious Transfer
Wataru Hasegawa, Masakazu Soshi, Atsuko Miyaji
SECRYPT3
2005 On the Success Probability of chi2-attack on RC6
Atsuko Miyaji, Yuuki Takano
ACISP1
2004 Success Probability in Chi2-Attacks
Takashi Matsunaka, Atsuko Miyaji, Yuuki Takano
ACNS2
2004 A Fully-Functional Group Signature Scheme over Only Known-Order Group
Atsuko Miyaji, Kozue Umeda
ACNS1
2004 Efficient Countermeasures against RPA, DPA, and SPA
Hideyo Mamiya, Atsuko Miyaji, Hiroaki Morimoto
CHES2
2004 A Generic Construction for Intrusion-Resilient Public-Key Encryption
Yevgeniy Dodis, Matthew K. Franklin, Jonathan Katz, Atsuko Miyaji, Moti Yung
CT-RSA4
2003 Evaluation of Anonymity of Practical Anonymous Communication Networks
Shigeki Kitazawa, Masakazu Soshi, Atsuko Miyaji
ACISP3
2003 Optimized Chi2-Attack against RC6
Norihisa Isogai, Takashi Matsunaka, Atsuko Miyaji
ACNS3
2003 Anonymity-Enhanced Pseudonym System
Yuko Tamura, Atsuko Miyaji
ACNS2
2003 Intrusion-Resilient Public-Key Encryption
Yevgeniy Dodis, Matthew K. Franklin, Jonathan Katz, Atsuko Miyaji, Moti Yung
CT-RSA4
2002 Known Plaintext Correlation Attack against RC5
Atsuko Miyaji, Masao Nonaka, Yoshinori Takii
CT-RSA1
2002 Cryptanalysis of the Reduced-Round RC6
Atsuko Miyaji, Masao Nonaka
ICICS1
2001 Efficient and Unconditionally Secure Verifiable Threshold Changeable Scheme
Ayako Maeda, Atsuko Miyaji, Mitsuru Tada
ACISP2
2001 A Practical English Auction with One-Time Registration
Kazumasa Omote, Atsuko Miyaji
ACISP2
2000 A Multisignature Scheme with Message Flexibility, Order Flexibility and Order Verifiability
Shirow Mitomi, Atsuko Miyaji
ACISP2
1998 Efficient Elliptic Curve Exponentiation Using Mixed Coordinates
Henri Cohen, Atsuko Miyaji, Takatoshi Ono
ASIACRYPT2
1997 Efficient elliptic curve exponentiation
Atsuko Miyaji, Takatoshi Ono, Henri Cohen
ICICS1
1996 A Message Recovery Signature Scheme Equivalent to DSA over Elliptic Curves
Atsuko Miyaji
ASIACRYPT1
1991 On Ordinary Elliptic Curve Cryptosystems
Atsuko Miyaji
ASIACRYPT1