VLDB 2026 Research / reviewers in the wild / expert
Kirill Morozov
dblp:52/2673
· DBLP profile ↗
29ranked-venue papers
2as first author
7since 2021 · last 2026
0009-0006-4443-083XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 3 · 1 since 2021Theory of computation · 3Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trident: Efficient FPGA Acceleration of XMSS Tree in Post-Quantum Signature Scheme SLH-DSAabstractThe emergence of quantum computing poses significant threats to conventional cryptographic systems, necessitating the efficient hardware acceleration of Post-Quantum Cryptography (PQC), especially on the Field-Programmable Gate Array (FPGA) platforms. SPHINCS+, recently standardized by NIST (National Institute of Standards and Technology) as SLH-DSA (Stateless Hash-Based Digital Signature Algorithm), represents the only hash-based digital signature scheme. Its practical deployment, however, is restricted by computationally intense operations, particularly in the eXtended Merkle Signature Scheme (XMSS) tree, where WOTS+ (Winternitz One-Time Signature Plus) public key generation consumes the majority of signature generation cycles. With this background, this paper presents Trident, an innovative FPGA-based hardware accelerator that addresses critical performance and resource challenges in XMSS of SLH-DSA. First, we propose a triangle hash unit architecture that enables parallel execution of up to three hash operations simultaneously, directly addressing the computational bottleneck in XMSS tree construction and WOTS+ chain operations. Second, we develop an optimized memory caching scheme that reduces on-chip memory requirements via intermediate value management. Third, we implement the Trident on FPGAs and comprehensively evaluate it across all parameter sets at multiple security levels, i.e., up to 8.6× improvement in signature generation and up to 5.4× speed-up in verification operations. Extended Hypertree evaluation shows a 34.6× area-delay product (ADP) improvement on UltraScale+ FPGA for SLH-DSA-128s. This Trident represents a significant advancement toward practical SLH-DSA deployment in FPGA environments. Tianyou Bao, Joshua Ennis, Kirill Morozov, Jiafeng Xie |
FCCM | 3 |
| 2023 | Intrusion Detection for Additive Manufacturing Systems and NetworksabstractAdditive manufacturing (3D printing) has been seeing growth in recent years with the widespread use of 3D printers for production in different industries. As these systems become integrated into enterprise networks, the cybersecurity aspect of their functioning is gaining importance. In particular, there exist risks that these devices are exposed to a wide variety of data breaches. The latter range from unauthorized access to the printed designs to Stuxnet-like malware attacks. This research focuses on vulnerability and threat analysis for 3D Printers. Our ultimate goal is to introduce intrusion detection systems, which effectively address the current security challenges. Seemaparvez Shaik, Cihan Tunc, Kirill Morozov |
AICCSA | 3 |
| 2023 | Using Untrusted and Unreliable Cloud Providers to Obtain Private Email
Nicolas Chiapputo, Yvo Desmedt, Kirill Morozov |
SECRYPT | 3 |
| 2022 | Towards a Threat Model and Security Analysis for Data Cooperatives
Abiola Salau, Ram Dantu, Kirill Morozov, Kritagya Upadhyay, Syed Badruddoja |
SECRYPT | 3 |
| 2022 | Revisiting group oriented secret sharing schemes
Kirill Morozov, Jintai Ding |
Inf. Sci. | 3 |
| 2021 | Investing Data with Untrusted Parties using HEabstractArticle proposing the use of anonymization techniques coupled with graph algorithms over homomorphically encrypted (HE) graphs as a basis of analysis for this accumulated data. This approach ensures individuals’ privacy and anonymity while preserving the usefulness of the plaintext data. This article was originally presented at the 18th International Conference on Security and Cryptography - SECRYPT. Mark Dockendorf, Ram Dantu, Kirill Morozov, Sanjukta Bhowmick |
SECRYPT | 3 |
| 2021 | Group authentication for cloud-to-things computing: Review and improvement
Kirill Morozov |
Comput. Networks | 3 |
| 2020 | EW256357: A New Secure NIST P-256 Compatible Elliptic Curve for VoIP Applications' Security
Nilanjan Sen, Ram Dantu, Kirill Morozov |
SecureComm (2) | 3 |
| 2019 | Evolving Perfect Hash Families: A Combinatorial Viewpoint of Evolving Secret Sharing
Yvo Desmedt, Sabyasachi Dutta, Kirill Morozov |
CANS | 3 |
| 2019 | Security Analysis and Efficient Implementation of Code-based Signature Schemes
Partha Sarathi Roy 0001, Kirill Morozov, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi |
ICISSP | 2 |
| 2019 | CMCAP: Ephemeral Sandboxes for Adaptive Access ControlabstractWe present CMCAP (context-mapped capabilities), a decentralized mechanism for specifying and enforcing adaptive access control policies for resource-centric security. Policies in CMCAP express runtime constraints defined as containment domains with context-mapped capabilities, and ephemeral sandboxes for dynamically enforcing desired information flow properties while preserving functional correctness for the sandboxed programs. CMCAP is designed to remediate DAC's weakness and address the inflexibility that makes current MAC frameworks impractical to the common user. We use a Linux-based implementation of CMCAP to demonstrate how a program's dynamic profile is used for access control and intrusion prevention. Theogene Hakiza Bucuti, Ram Dantu, Kirill Morozov |
SACMAT | 3 |
| 2019 | Verifying OAuth Implementations Through Encrypted Network AnalysisabstractVerifying protocol implementations via application analysis can be cumbersome. Rapid development cycles of both the protocol and applications that use it can hinder up-to-date analysis. A better approach is to use formal models to characterize the applications platform and then verify the protocol through analysis of the network traffic tied to the models. To test this method, the popular protocol OAuth is considered. Currently, formal models of OAuth do not take into consideration the mobile environment, and implementation verification is largely based on code analysis. Our preliminary results are two fold; we sketch an extension to a formal model that incorporates the specifics of the Android platform and classify OAuth device types using machine learning on encrypted VPN traffic. Josh Talkington, Ram Dantu, Kirill Morozov |
SACMAT | 3 |
| 2018 | Hierarchical Secret Sharing Schemes Secure Against Rushing Adversary: Cheater Identification and Robustness
Partha Sarathi Roy 0001, Sabyasachi Dutta, Kirill Morozov, Avishek Adhikari, Kazuhide Fukushima, Shinsaku Kiyomoto, Kouichi Sakurai |
ISPEC | 3 |
| 2017 | CCA2 Key-Privacy for Code-Based Encryption in the Standard Model
Yusuke Yoshida, Kirill Morozov, Keisuke Tanaka |
PQCrypto | 2 |
| 2017 | Efficient outsourcing of secure k-nearest neighbour query over encrypted database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi |
Comput. Secur. | 2 |
| 2017 | Cross-group secret sharing scheme for secure usage of cloud storage over different providers and regions
Hiroaki Anada, Junpei Kawamoto, Chenyutao Ke, Kirill Morozov, Kouichi Sakurai |
J. Supercomput. | 4 |
| 2016 | Privacy-Preserving k-Nearest Neighbour Query on Outsourced Database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi |
ACISP (1) | 2 |
| 2015 | Parity Check based redistribution of secret sharesabstractIn 2002, Wong-Wang-Wing presented a verifiable redistributing secret shares protocol, where the new parties must have been honest. They used Feldman's Verifiable Secret Sharing scheme, which assumed that the discrete logarithm is hard. In 2013, Nojoumian and Stinson presented information-theoretically (unconditionally) secure schemes under assumption that at most t out of 4t+1 parties are actively corrupt, where only the threshold (but not the number of parties) can be changed. We present an unconditionally secure solution assuming that at most t out of 3t+1 parties are actively corrupt. Our protocol uses properties of the parity-check matrix of a Generalized Reed-Solomon code. Moreover, we introduce a new open problem in the area of Reed-Solomon decoding. Yvo Desmedt, Kirill Morozov |
ISIT | 2 |
| 2014 | LR-FEAD: leakage-tolerating and attribute-hiding functional encryption mechanism with delegation in affine subspaces
Mingwu Zhang, Kirill Morozov |
J. Supercomput. | 3 |
| 2013 | Proof of plaintext knowledge for code-based public-key encryption revisitedabstractIn a recent paper at Asiacrypt'2012, Jain et al point out that Veron code-based identification scheme is not perfect zero-knowledge. In particular, this creates a gap in security arguments of proof of plaintext knowledge (PPK) and verifiable encryption for the McEliece public key encryption (PKE) proposed by Morozov and Takagi at ACISP'2012. We fix the latter result by showing that PPK for the code-based Niederreiter and McEliece PKE's can be constructed using Stern zero-knowledge identification scheme, which is unaffected by the above mentioned problem. Since code-based verifiable encryption uses PPK as a main ingredient, our proposal presents a fix for the McEliece verifiable encryption as well. In addition, we present the Niederreiter verifiable encryption. Kirill Morozov, Tsuyoshi Takagi |
AsiaCCS | 2 |
| 2012 | Zero-Knowledge Protocols for the McEliece Encryption
Kirill Morozov, Tsuyoshi Takagi |
ACISP | 1 |
| 2011 | Efficient computational oblivious transfer using interactive hashingabstractWe present two protocols for reducing oblivious transfer (OT) to the security of trapdoor permutations and to the hardness of some coding problems, respectively. The first protocol is the most efficient known to date, while the second one is a theoretical proof-of-concept. Our constructions leverage the power of Interactive Hashing (IH). The first protocol can be viewed as a simple modification of the well-known OT construction by Even, Goldreich and Lem-pel (1985), in which a receiver must send a random domain element to a sender through IH. Alternatively, our protocol can be viewed as a simple modification of the construction by Ostrovsky, Venkatesan and Yung (1993), in which the players substitute the one-way permutation with a trapdoor permutation. We use a similar approach to derive a second OT protocol based on coding assumptions related to security of the McEliece cryptosystem. In our second construction, the receiver inputs a public key into IH while privately keeping the corresponding secret key. Two different versions of IH are used: the computationally secure one in the first protocol, and the information-theoretically secure one in the second. Kirill Morozov, George Savvides |
AsiaCCS | 1 |
| 2011 | Improvement on Secrecy Capacity of Wireless LAN Using Matched FilterabstractWire-tap channel coding allows information-theoretically secure communication between legitimate sender and receiver in presence of an eavesdropper Eve, whose channel is subject to noise. A secrecy capacity for their communication is equal to capacity of the channel connecting them, minus capacity of Eve's channel, when the channels are assumed independent and affected by additive white Gaussian noise. In order to increase the secrecy capacity, we propose to employ a coding scheme using matched filter. The legitimate parties are assumed to share a pre-shared key of the matched filter, secretly from Eve. Hereby, the legitimate parties can use it to increase the capacity of their channel, while Eve cannot. We propose to apply this scheme to indoor wireless communication over IEEE 802.11 wireless LAN, analyze advantages of our construction and discuss an appropriate selection of coding scheme fitting the IEEE 802.11 protocol specification. Ryuzou Nishi, Kirill Morozov, Yoshiaki Hori, Kouichi Sakurai |
MSN | 2 |
| 2011 | Achieving Oblivious Transfer Capacity of Generalized Erasure Channels in the Malicious ModelabstractInformation-theoretically secure string oblivious transfer (OT) can be constructed based on discrete memoryless channel (DMC). The oblivious transfer capacity of a channel characterizes - similarly to the (standard) information capacity - how efficiently it can be exploited for secure oblivious transfer of strings. The OT capacity of a generalized erasure channel (GEC) - which is a combination of a (general) DMC with the erasure channel - has been established by Ahlswede and Csizar at ISIT'07 in the case of passive adversaries. In this paper, we present the protocol that achieves this capacity against malicious adversaries for GEC with erasure probability at least 1/2. Our construction is based on the protocol of Crepeau and Savvides from Eurocrypt'06 which uses interactive hashing (IH). We solve an open question posed by the above paper, by basing it upon a constant round IH scheme (previously proposed by Ding et al. at TCC'04). As a side result, we show that the Ding et al. IH protocol can deal with transmission errors. Adriana C. B. Pinto, Rafael Dowsley, Kirill Morozov, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 3 |
| 2008 | A practical scheme for string commitment based on the Gaussian channelabstractWe consider the problem of information-theoretically secure string commitment using a channel with additive white Gaussian noise. While the current results in the literature mainly present existence results for such schemes, we present here a practical scheme using lattice codes and analyze its security parameters for finite code lengths. Frédérique E. Oggier, Kirill Morozov |
ITW | 2 |
| 2008 | Semantic security for the McEliece cryptosystem without random oracles
Ryo Nojima, Hideki Imai, Kazukuni Kobara, Kirill Morozov |
Des. Codes Cryptogr. | 4 |
| 2006 | On the Oblivious Transfer Capacity of the Erasure ChannelabstractOne of the most important primitives in two-party distrustful cryptography is oblivious transfer, a complete primitive for two-party computation. Recently introduced, the oblivious transfer capacity of a noisy channel measures an efficiency of information theoretical reductions from 1-out-of-k, l-string oblivious transfer to noisy channels. It is defined as the maximal achievable ratio l/n, where l is the length of the strings which are to be transferred and n is the number of times the noisy channel is invoked. This quantity is unknown in a general case. For discrete memoryless channels, it is known to be nonnegligible for honest-but-curious players, but the non-zero rates have not ever been proved achievable in the case of malicious players. Here, we show that in the particular case of the erasure channel, more precise answers can be obtained. We compute the OT capacity of the erasure channel for the case of honest-but-curious players and, for the fully malicious players, we give its lower bound. Hideki Imai, Kirill Morozov, Anderson C. A. Nascimento |
ISIT | 2 |
| 2006 | Efficient Protocols Achieving the Commitment Capacity of Noisy CorrelationsabstractBit commitment is an important tool for constructing zero-knowledge proofs and multi-party computation. Unconditionally secure bit commitment can be based, in particular, on noisy channel or correlation where noise considered a valuable resource. Recently, Winter, Nascimento and Imai introduced the concept of commitment capacity, the maximal ratio between the length of a string which the sender commits to and the number of times the noisy channel/correlation is used. They also proved that for any discrete memoryless channel there exists a secure protocol achieving its commitment capacity however, no particular construction was given. Solving their open question, we provide an efficient protocol for achieving the commitment capacity of discrete memoryless systems (noisy channels and correlations). Hideki Imai, Kirill Morozov, Anderson C. A. Nascimento, Andreas J. Winter 0002 |
ISIT | 2 |
| 2004 | Unfair Noisy Channels and Oblivious Transfer
Ivan Damgård, Serge Fehr, Kirill Morozov, Louis Salvail |
TCC | 3 |