Taechan Kim 0001

dblp:51/11043-1 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0003-1683-8484ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 6 first-author · 3 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2025 Can we beat three halves lower bound? (Im)possibility of reducing communication cost for garbled circuits
Chunghun Baek, Taechan Kim 0001
Des. Codes Cryptogr.2
2024 Analysis on Sliced Garbling via Algebraic Approach
Taechan Kim 0001
ASIACRYPT (8)1
2023 Asymptotically Faster Multi-Key Homomorphic Encryption from Homomorphic Gadget Decomposition
abstract
Homomorphic Encryption (HE) is a cryptosytem that allows us to perform an arbitrary computation on encrypted data. The standard HE, however, has a disadvantage in that the authority is concentrated in the secret key owner since computations can only be performed on ciphertexts encrypted under the same secret key. To resolve this issue, research is underway on Multi-Key Homomorphic Encryption (MKHE), which is a variant of HE supporting computations on ciphertexts possibly encrypted under different keys. Despite its ability to provide privacy for multiple parties, existing MKHE schemes suffer from poor performance due to the cost of multiplication which grows at least quadratically with the number of keys involved.
Taechan Kim 0001, Hyesun Kwak, Dongwon Lee 0010, Jinyeong Seo, Yongsoo Song
CCS1
2017 Lattice Reductions over Euclidean Rings with Applications to Cryptanalysis
Taechan Kim 0001, Changmin Lee 0001
IMACC1
2017 Improved elliptic curve hashing and point representation
Mehdi Tibouchi, Taechan Kim 0001
Des. Codes Cryptogr.2
2016 Extended Tower Number Field Sieve: A New Complexity for the Medium Prime Case
Taechan Kim 0001, Razvan Barbulescu
CRYPTO (1)1
2015 Multiple Discrete Logarithm Problems with Auxiliary Inputs
Taechan Kim 0001
ASIACRYPT (1)1
2014 Bit-Flip Faults on Elliptic Curve Base Fields, Revisited
Taechan Kim 0001, Mehdi Tibouchi
ACNS1
2013 A Group Action on ℤp˟ and the Generalized DLP with Auxiliary Inputs
Jung Hee Cheon, Taechan Kim 0001, Yongsoo Song
Selected Areas in Cryptography2
2013 On the Final Exponentiation in Tate Pairing Computations
abstract
The Tate pairing computation consists of two parts: Miller step and final exponentiation step. In this paper, we investigate the structure of the final exponentiation step. Consider an orderrsubgroup of an elliptic curve defined over Fqwith embedding degreek. The final exponentiation in the Tate pairing is an exponentiation of an element in Fqkby (qk-1)/r. The hardest part of this computation is to raise to the power λ:=Φk(q)/r, where Φk(·) denotes thekth cyclotomic polynomial. Write it as λ = λ0+λ1q+⋯+λφ(k)-1qφ(k)-1in theq-ary representation. The final exponentiation cost mostly depends on κ(λ), the size of the maximum of |λi|. In many parameterized pairing-friendly curves, the value κ is about (1-1/ρφ(k))log2qwhere ρ = log2q/log2r, while random curves will have κ ≈ log2q. We investigate how this small κ is obtained for parameterized pairing-friendly elliptic curves, and show that (1-1/ρφ(k))log2qis the lower bound for all known construction methods of parameterized pairing-friendly curves. In the second part of our paper, we propose a method to obtain a modified Tate pairing with small κ for any pairing-friendly elliptic curves including those not belonging to parameterized families. More precisely, our method finds an integermusing the lattice basis reduction such that κ(mλ)=(1-1/ρφ(k))log2q. Using this modified Tate pairing, we can reduce the number of squarings in the final exponentiation by a factor of (1-1/ρφ(k)) from the usual Tate pairing. We apply our method to several known pairing-friendly curves to verify the expected speedup.
Taechan Kim 0001, Sungwook Kim 0001, Jung Hee Cheon
IEEE Trans. Inf. Theory1