Kwangsu Lee

dblp:33/6549 · DBLP profile ↗
← Back
24ranked-venue papers
18as first author
4since 2021 · last 2025
0000-0003-1910-8890ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 12 first-author · 3 since 2021Theory of computation · 4 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Dynamic Threshold Key Encapsulation With Transparent Setup
abstract
A threshold key encapsulation mechanism (TKEM) facilitates the secure distribution of session keys among multiple participants, allowing key recovery through a threshold number of shares. TKEM has gained significant attention, especially for decentralized systems, including blockchains. However, existing constructions often rely on trusted setups, which pose security risks such as a single point of failure and are limited by fixed participant numbers and thresholds. To overcome this issue, we propose a dynamic TKEM with a transparent setup, allowing for a flexible selection of both recipients and thresholds without relying on trusted third parties in the setup phase. In addition, our construction does not rely on pairing operations, which are less efficient compared to exponentiation. We prove the selective chosen-ciphertext security of our construction under the decisional Diffie-Hellman assumption, zero-knowledge, and soundness of a non-interactive zero-knowledge (NIZK) proof system. We also show that our scheme satisfies decapsulation consistency when the underlying NIZK system is sound. Our proof-of-concept implementation highlights the practicality and efficiency of this approach, further advancing the field of threshold cryptography.
Joon Sik Kim, Kwangsu Lee, Jong Hwan Park, Hyoseung Kim 0002
IEEE Trans. Inf. Forensics Secur.2
2023 Decentralized multi-client functional encryption for set intersection with improved efficiency
abstract
Abstract Functional encryption (FE) is a new paradigm of public key encryption that can control the exposed information of plaintexts by supporting computation on encrypted data. In this paper, we propose efficient multi-client FE (MCFE) schemes that compute the set intersection of ciphertexts generated by two clients. First, we propose an MCFE scheme that calculates the set intersection cardinality (MCFE-SIC) and prove its static security under dynamic assumptions. Next, we extend our MCFE-SIC scheme to an MCFE scheme for set intersection (MCFE-SI) and prove its static security under dynamic assumptions. The decryption algorithm of our MCFE-SI scheme is more efficient than the existing MCFE-SI scheme because it requires fewer pairing operations to calculate the intersection of two clients. Finally, we propose a decentralized MCFE scheme for set intersection (DMCFE-SI) that decentralizes the generation of function keys. Our MCFE schemes can be effectively applied to a privacy-preserving contact tracing system to prevent the spread of recent infectious diseases.
Kwangsu Lee
Des. Codes Cryptogr.1
2022 Functional encryption for set intersection in the multi-client setting
Kwangsu Lee, Minhye Seo
Des. Codes Cryptogr.1
2021 Revocable hierarchical identity-based encryption with adaptive security
abstract
Hierarchical identity-based encryption (HIBE) can be extended to revocable HIBE (RHIBE) if a private key of a user can be revoked when the private key is revealed or expired. Previously, many selectively secure RHIBE schemes were proposed, but it is still unsolved problem to construct an adaptively secure RHIBE scheme. In this work, we propose two RHIBE schemes in composite-order bilinear groups and prove their adaptive security under simple static assumptions. To prove the adaptive security, we use the dual system encryption framework, but it is not simple to use the dual system encryption framework in RHIBE since the security model of RHIBE is quite different with that of HIBE. We show that it is possible to solve the problem of the RHIBE security proof by carefully designing hybrid games.
Kwangsu Lee
Theor. Comput. Sci.1
2020 Comments on "Secure Data Sharing in Cloud Computing Using Revocable-Storage Identity-Based Encryption"
abstract
Cloud computing can provide a flexible way to effectively share data among multiple users since it can overcome the time and location constraints of computing resource usage. However, the users of cloud computing are still reluctant to share sensitive data to a cloud server since the cloud server should be treated as an untrusted entity. In order to support secure and efficient data sharing in a cloud computing environment, Wei et al. recently extended the concept of identity-based encryption (IBE) to support key revocation and ciphertext update functionalities, and proposed a revocable-storage identity-based encryption (RS-IBE) scheme. In this article, we show that the RS-IBE scheme of Wei et al. does not satisfy the correctness property of RS-IBE. We also propose a method to modify the existing RS-IBE scheme.
Kwangsu Lee
IEEE Trans. Cloud Comput.1
2020 Tight security for the generic construction of identity-based signature (in the multi-instance setting)
Youngkyung Lee, Jong Hwan Park, Kwangsu Lee, Dong Hoon Lee 0001
Theor. Comput. Sci.3
2019 CCA Security for Self-Updatable Encryption: Protecting Cloud Data When Clients Read/Write Ciphertexts
abstract
Self-updatable encryption (SUE) is a new kind of public-key encryption, motivated by cloud computing, which enables anyone (i.e. cloud server with no access to private keys) to update a past ciphertext to a future ciphertext by using a public key. The main applications of SUE are revocable-storage attribute-based encryption (RS-ABE) that provides an efficient and secure access control to encrypted data stored in cloud storage. In this setting, there is a new threat such that a revoked user still can access past ciphertexts given to him by a storage server. RS-ABE solves this problem by combining user revocation and ciphertext updating functionalities. We propose the first SUE and RS-ABE schemes secure against a relevant form of chosen-ciphertext security (CCA). Due to the fact that some ciphertexts are easily derived from others, we employ a different notion of CCA that avoids easy challenge related messages. Specifically, we define “time extended challenge” CCA security for SUE which excludes ciphertexts that are easily derived from the challenge (over time periods) from being queried on. We then propose an efficient SUE scheme with such CCA security, and we also present an RS-ABE scheme with this CCA security.
Kwangsu Lee, Dong Hoon Lee 0001, Jong Hwan Park, Moti Yung
Comput. J.1
2018 Revocable hierarchical identity-based encryption with shorter private keys and update keys
Kwangsu Lee, Seunghwan Park
Des. Codes Cryptogr.1
2017 Efficient revocable identity-based encryption via subset difference methods
Kwangsu Lee, Dong Hoon Lee 0001, Jong Hwan Park
Des. Codes Cryptogr.1
2017 Self-updatable encryption: Time constrained access control with hidden attributes and better efficiency
Kwangsu Lee, Seung Geol Choi, Dong Hoon Lee 0001, Jong Hwan Park, Moti Yung
Theor. Comput. Sci.1
2016 Self-updatable encryption with short public parameters and its extensions
Kwangsu Lee
Des. Codes Cryptogr.1
2015 Visual Honey Encryption: Application to Steganography
abstract
Honey encryption (HE) is a new technique to overcome the weakness of conventional password-based encryption (PBE). However, conventional honey encryption still has the limitation that it works only for binary bit streams or integer sequences because it uses a fixed distribution-transforming encoder (DTE). In this paper, we propose a variant of honey encryption called visual honey encryption which employs an adaptive DTE in a Bayesian framework so that the proposed approach can be applied to more complex domains including images and videos. We applied this method to create a new steganography scheme which significantly improves the security level of traditional steganography.
Jiwon Yoon 0001, Hyoungshick Kim, Hyun-Ju Jo, Hyelim Lee, Kwangsu Lee
IH&MMSec5
2015 Anonymous HIBE with short ciphertexts: full security in prime order groups
Kwangsu Lee, Jong Hwan Park, Dong Hoon Lee 0001
Des. Codes Cryptogr.1
2015 Adaptively secure broadcast encryption under standard assumptions with better efficiency
abstract
In this study, the authors present an efficient public‐key broadcast encryption (PKBE) scheme with sub‐linear size of public keys, private keys and ciphertexts and prove its adaptive security under standard assumptions. Compared with the currently best scheme of Garg et al . (CCS 2010) that provides adaptive security under standard assumptions and sub‐linear size of various parameters, the ciphertext size of the author's scheme is 94% shorter and the encryption algorithm of their scheme is also 2.8 times faster than the scheme of Garg et al . To achieve their scheme, they adapt the dual system encryption technique of Waters. However, there is a challenging problem to use this technique for the construction of PKBE with sub‐linear size of ciphertexts such as a tag compression problem. To overcome this problem, they first devise a novel tag update technique for broadcast encryption. Using this technique, they build an efficient PKBE scheme in symmetric bilinear groups, and prove its adaptive security under standard assumptions.
Kwangsu Lee, Dong Hoon Lee 0001
IET Inf. Secur.1
2015 New chosen-ciphertext secure identity-based encryption with tight security reduction to the bilinear Diffie-Hellman problem
Jong Hwan Park, Kwangsu Lee, Dong Hoon Lee 0001
Inf. Sci.2
2015 Privacy preserving revocable predicate encryption revisited
abstract
Abstract Predicate encryption (PE) that provides both the access control of ciphertexts and the privacy of ciphertexts is a new paradigm of public‐key encryption. An important application of PE is a searchable encryption system in cloud storage, where it enables a client to securely outsource the search of a keyword on encrypted data without revealing the keyword to the cloud server. One practical issue of PE is to devise an efficient revocation method to revoke a user when the secret key of the user is compromised. Privacy preserving revocable PE (RPE) can provide not only revocation but also the privacy of revoked users. In this paper, we first define two new security models of privacy preserving RPE: the strongly full‐hiding (FH) security and the weakly FH security. Next, we propose a general RPE construction from any PE scheme and prove its security in the weakly FH security model. Our generic RPE scheme is efficient because the number of ciphertext elements is not proportional to the number of users in a receiver set. Additionally, our RPE scheme can support polynomial‐size circuits if a recently proposed functional encryption scheme for polynomial‐size circuits is used as an underlying PE scheme. Copyright © 2014 John Wiley & Sons, Ltd.
Kwangsu Lee, Intae Kim, Seong Oun Hwang
Secur. Commun. Networks1
2015 Sequential aggregate signatures with short public keys without random oracles
Kwangsu Lee, Dong Hoon Lee 0001, Moti Yung
Theor. Comput. Sci.1
2015 New Constructions of Revocable Identity-Based Encryption From Multilinear Maps
abstract
A revocable identity-based encryption (RIBE) provides an efficient revocation method in IBE that a trusted authority periodically broadcasts an update key for nonrevoked users and a user can decrypt a ciphertext if he is not revoked in the update key. Boldyreva, Goyal, and Kumar (CCS 2008) defined RIBE and proposed an RIBE scheme that uses a tree-based revocation encryption scheme to revoke users' private keys. In this paper, we devise a new technique for RIBE and propose RIBE schemes with a constant number of private key elements. We achieve the following results. We first devise a new technique for RIBE that combines a hierarchical IBE (HIBE) scheme and a public-key broadcast encryption (PKBE) scheme using multilinear maps. In contrast to the previous technique for RIBE, our technique uses a PKBE scheme in bilinear maps for revocation to achieve short private keys and update keys. Following our new technique for RIBE, we propose an RIBE scheme in three-leveled multilinear maps that combines the HIBE scheme of Boneh and Boyen (EUROCRYPT 2004) and the PKBE scheme of Boneh, Gentry, and Waters (CRYPTO 2005). The private key and update key of our scheme possess a constant number of group elements. Next, we propose another RIBE scheme with reduced public parameters and short keys by combining the HIBE scheme of Boneh and Boyen and the PKBE scheme of Boneh, Waters, and Zhandry (CRYPTO 2014), which uses multilinear maps. Compared with our first RIBE scheme, our second RIBE scheme requires high-leveled multilinear maps.
Seunghwan Park, Kwangsu Lee, Dong Hoon Lee 0001
IEEE Trans. Inf. Forensics Secur.2
2014 Public-Key Revocation and Tracing Schemes with Subset Difference Methods Revisited
Kwangsu Lee, Woo Kwon Koo, Dong Hoon Lee 0001, Jong Hwan Park
ESORICS (2)1
2014 Security analysis of an identity-based strongly unforgeable signature scheme
Kwangsu Lee, Dong Hoon Lee 0001
Inf. Sci.1
2013 Sequential Aggregate Signatures Made Shorter
Kwangsu Lee, Dong Hoon Lee 0001, Moti Yung
ACNS1
2013 Self-Updatable Encryption: Time Constrained Access Control with Hidden Attributes and Better Efficiency
Kwangsu Lee, Seung Geol Choi, Dong Hoon Lee 0001, Jong Hwan Park, Moti Yung
ASIACRYPT (1)1
2013 Fully secure hidden vector encryption under standard assumptions
Jong Hwan Park, Kwangsu Lee, Willy Susilo, Dong Hoon Lee 0001
Inf. Sci.2
2011 Improved hidden vector encryption with short ciphertexts and tokens
Kwangsu Lee, Dong Hoon Lee 0001
Des. Codes Cryptogr.1