Kirill Morozov

dblp:52/2673 · DBLP profile ↗
← Back
29ranked-venue papers
2as first author
7since 2021 · last 2026
0009-0006-4443-083XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 3 · 1 since 2021Theory of computation · 3Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Trident: Efficient FPGA Acceleration of XMSS Tree in Post-Quantum Signature Scheme SLH-DSA
abstract
The emergence of quantum computing poses significant threats to conventional cryptographic systems, necessitating the efficient hardware acceleration of Post-Quantum Cryptography (PQC), especially on the Field-Programmable Gate Array (FPGA) platforms. SPHINCS+, recently standardized by NIST (National Institute of Standards and Technology) as SLH-DSA (Stateless Hash-Based Digital Signature Algorithm), represents the only hash-based digital signature scheme. Its practical deployment, however, is restricted by computationally intense operations, particularly in the eXtended Merkle Signature Scheme (XMSS) tree, where WOTS+ (Winternitz One-Time Signature Plus) public key generation consumes the majority of signature generation cycles. With this background, this paper presents Trident, an innovative FPGA-based hardware accelerator that addresses critical performance and resource challenges in XMSS of SLH-DSA. First, we propose a triangle hash unit architecture that enables parallel execution of up to three hash operations simultaneously, directly addressing the computational bottleneck in XMSS tree construction and WOTS+ chain operations. Second, we develop an optimized memory caching scheme that reduces on-chip memory requirements via intermediate value management. Third, we implement the Trident on FPGAs and comprehensively evaluate it across all parameter sets at multiple security levels, i.e., up to 8.6× improvement in signature generation and up to 5.4× speed-up in verification operations. Extended Hypertree evaluation shows a 34.6× area-delay product (ADP) improvement on UltraScale+ FPGA for SLH-DSA-128s. This Trident represents a significant advancement toward practical SLH-DSA deployment in FPGA environments.
Tianyou Bao, Joshua Ennis, Kirill Morozov, Jiafeng Xie
FCCM3
2023 Intrusion Detection for Additive Manufacturing Systems and Networks
abstract
Additive manufacturing (3D printing) has been seeing growth in recent years with the widespread use of 3D printers for production in different industries. As these systems become integrated into enterprise networks, the cybersecurity aspect of their functioning is gaining importance. In particular, there exist risks that these devices are exposed to a wide variety of data breaches. The latter range from unauthorized access to the printed designs to Stuxnet-like malware attacks. This research focuses on vulnerability and threat analysis for 3D Printers. Our ultimate goal is to introduce intrusion detection systems, which effectively address the current security challenges.
Seemaparvez Shaik, Cihan Tunc, Kirill Morozov
AICCSA3
2023 Using Untrusted and Unreliable Cloud Providers to Obtain Private Email
Nicolas Chiapputo, Yvo Desmedt, Kirill Morozov
SECRYPT3
2022 Towards a Threat Model and Security Analysis for Data Cooperatives
Abiola Salau, Ram Dantu, Kirill Morozov, Kritagya Upadhyay, Syed Badruddoja
SECRYPT3
2022 Revisiting group oriented secret sharing schemes
Kirill Morozov, Jintai Ding
Inf. Sci.3
2021 Investing Data with Untrusted Parties using HE
abstract
Article proposing the use of anonymization techniques coupled with graph algorithms over homomorphically encrypted (HE) graphs as a basis of analysis for this accumulated data. This approach ensures individuals’ privacy and anonymity while preserving the usefulness of the plaintext data. This article was originally presented at the 18th International Conference on Security and Cryptography - SECRYPT.
Mark Dockendorf, Ram Dantu, Kirill Morozov, Sanjukta Bhowmick
SECRYPT3
2021 Group authentication for cloud-to-things computing: Review and improvement
Kirill Morozov
Comput. Networks3
2020 EW256357: A New Secure NIST P-256 Compatible Elliptic Curve for VoIP Applications' Security
Nilanjan Sen, Ram Dantu, Kirill Morozov
SecureComm (2)3
2019 Evolving Perfect Hash Families: A Combinatorial Viewpoint of Evolving Secret Sharing
Yvo Desmedt, Sabyasachi Dutta, Kirill Morozov
CANS3
2019 Security Analysis and Efficient Implementation of Code-based Signature Schemes
Partha Sarathi Roy 0001, Kirill Morozov, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi
ICISSP2
2019 CMCAP: Ephemeral Sandboxes for Adaptive Access Control
abstract
We present CMCAP (context-mapped capabilities), a decentralized mechanism for specifying and enforcing adaptive access control policies for resource-centric security. Policies in CMCAP express runtime constraints defined as containment domains with context-mapped capabilities, and ephemeral sandboxes for dynamically enforcing desired information flow properties while preserving functional correctness for the sandboxed programs. CMCAP is designed to remediate DAC's weakness and address the inflexibility that makes current MAC frameworks impractical to the common user. We use a Linux-based implementation of CMCAP to demonstrate how a program's dynamic profile is used for access control and intrusion prevention.
Theogene Hakiza Bucuti, Ram Dantu, Kirill Morozov
SACMAT3
2019 Verifying OAuth Implementations Through Encrypted Network Analysis
abstract
Verifying protocol implementations via application analysis can be cumbersome. Rapid development cycles of both the protocol and applications that use it can hinder up-to-date analysis. A better approach is to use formal models to characterize the applications platform and then verify the protocol through analysis of the network traffic tied to the models. To test this method, the popular protocol OAuth is considered. Currently, formal models of OAuth do not take into consideration the mobile environment, and implementation verification is largely based on code analysis. Our preliminary results are two fold; we sketch an extension to a formal model that incorporates the specifics of the Android platform and classify OAuth device types using machine learning on encrypted VPN traffic.
Josh Talkington, Ram Dantu, Kirill Morozov
SACMAT3
2018 Hierarchical Secret Sharing Schemes Secure Against Rushing Adversary: Cheater Identification and Robustness
Partha Sarathi Roy 0001, Sabyasachi Dutta, Kirill Morozov, Avishek Adhikari, Kazuhide Fukushima, Shinsaku Kiyomoto, Kouichi Sakurai
ISPEC3
2017 CCA2 Key-Privacy for Code-Based Encryption in the Standard Model
Yusuke Yoshida, Kirill Morozov, Keisuke Tanaka
PQCrypto2
2017 Efficient outsourcing of secure k-nearest neighbour query over encrypted database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi
Comput. Secur.2
2017 Cross-group secret sharing scheme for secure usage of cloud storage over different providers and regions
Hiroaki Anada, Junpei Kawamoto, Chenyutao Ke, Kirill Morozov, Kouichi Sakurai
J. Supercomput.4
2016 Privacy-Preserving k-Nearest Neighbour Query on Outsourced Database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi
ACISP (1)2
2015 Parity Check based redistribution of secret shares
abstract
In 2002, Wong-Wang-Wing presented a verifiable redistributing secret shares protocol, where the new parties must have been honest. They used Feldman's Verifiable Secret Sharing scheme, which assumed that the discrete logarithm is hard. In 2013, Nojoumian and Stinson presented information-theoretically (unconditionally) secure schemes under assumption that at most t out of 4t+1 parties are actively corrupt, where only the threshold (but not the number of parties) can be changed. We present an unconditionally secure solution assuming that at most t out of 3t+1 parties are actively corrupt. Our protocol uses properties of the parity-check matrix of a Generalized Reed-Solomon code. Moreover, we introduce a new open problem in the area of Reed-Solomon decoding.
Yvo Desmedt, Kirill Morozov
ISIT2
2014 LR-FEAD: leakage-tolerating and attribute-hiding functional encryption mechanism with delegation in affine subspaces
Mingwu Zhang, Kirill Morozov
J. Supercomput.3
2013 Proof of plaintext knowledge for code-based public-key encryption revisited
abstract
In a recent paper at Asiacrypt'2012, Jain et al point out that Veron code-based identification scheme is not perfect zero-knowledge. In particular, this creates a gap in security arguments of proof of plaintext knowledge (PPK) and verifiable encryption for the McEliece public key encryption (PKE) proposed by Morozov and Takagi at ACISP'2012. We fix the latter result by showing that PPK for the code-based Niederreiter and McEliece PKE's can be constructed using Stern zero-knowledge identification scheme, which is unaffected by the above mentioned problem. Since code-based verifiable encryption uses PPK as a main ingredient, our proposal presents a fix for the McEliece verifiable encryption as well. In addition, we present the Niederreiter verifiable encryption.
Kirill Morozov, Tsuyoshi Takagi
AsiaCCS2
2012 Zero-Knowledge Protocols for the McEliece Encryption
Kirill Morozov, Tsuyoshi Takagi
ACISP1
2011 Efficient computational oblivious transfer using interactive hashing
abstract
We present two protocols for reducing oblivious transfer (OT) to the security of trapdoor permutations and to the hardness of some coding problems, respectively. The first protocol is the most efficient known to date, while the second one is a theoretical proof-of-concept. Our constructions leverage the power of Interactive Hashing (IH). The first protocol can be viewed as a simple modification of the well-known OT construction by Even, Goldreich and Lem-pel (1985), in which a receiver must send a random domain element to a sender through IH. Alternatively, our protocol can be viewed as a simple modification of the construction by Ostrovsky, Venkatesan and Yung (1993), in which the players substitute the one-way permutation with a trapdoor permutation. We use a similar approach to derive a second OT protocol based on coding assumptions related to security of the McEliece cryptosystem. In our second construction, the receiver inputs a public key into IH while privately keeping the corresponding secret key. Two different versions of IH are used: the computationally secure one in the first protocol, and the information-theoretically secure one in the second.
Kirill Morozov, George Savvides
AsiaCCS1
2011 Improvement on Secrecy Capacity of Wireless LAN Using Matched Filter
abstract
Wire-tap channel coding allows information-theoretically secure communication between legitimate sender and receiver in presence of an eavesdropper Eve, whose channel is subject to noise. A secrecy capacity for their communication is equal to capacity of the channel connecting them, minus capacity of Eve's channel, when the channels are assumed independent and affected by additive white Gaussian noise. In order to increase the secrecy capacity, we propose to employ a coding scheme using matched filter. The legitimate parties are assumed to share a pre-shared key of the matched filter, secretly from Eve. Hereby, the legitimate parties can use it to increase the capacity of their channel, while Eve cannot. We propose to apply this scheme to indoor wireless communication over IEEE 802.11 wireless LAN, analyze advantages of our construction and discuss an appropriate selection of coding scheme fitting the IEEE 802.11 protocol specification.
Ryuzou Nishi, Kirill Morozov, Yoshiaki Hori, Kouichi Sakurai
MSN2
2011 Achieving Oblivious Transfer Capacity of Generalized Erasure Channels in the Malicious Model
abstract
Information-theoretically secure string oblivious transfer (OT) can be constructed based on discrete memoryless channel (DMC). The oblivious transfer capacity of a channel characterizes - similarly to the (standard) information capacity - how efficiently it can be exploited for secure oblivious transfer of strings. The OT capacity of a generalized erasure channel (GEC) - which is a combination of a (general) DMC with the erasure channel - has been established by Ahlswede and Csizar at ISIT'07 in the case of passive adversaries. In this paper, we present the protocol that achieves this capacity against malicious adversaries for GEC with erasure probability at least 1/2. Our construction is based on the protocol of Crepeau and Savvides from Eurocrypt'06 which uses interactive hashing (IH). We solve an open question posed by the above paper, by basing it upon a constant round IH scheme (previously proposed by Ding et al. at TCC'04). As a side result, we show that the Ding et al. IH protocol can deal with transmission errors.
Adriana C. B. Pinto, Rafael Dowsley, Kirill Morozov, Anderson C. A. Nascimento
IEEE Trans. Inf. Theory3
2008 A practical scheme for string commitment based on the Gaussian channel
abstract
We consider the problem of information-theoretically secure string commitment using a channel with additive white Gaussian noise. While the current results in the literature mainly present existence results for such schemes, we present here a practical scheme using lattice codes and analyze its security parameters for finite code lengths.
Frédérique E. Oggier, Kirill Morozov
ITW2
2008 Semantic security for the McEliece cryptosystem without random oracles
Ryo Nojima, Hideki Imai, Kazukuni Kobara, Kirill Morozov
Des. Codes Cryptogr.4
2006 On the Oblivious Transfer Capacity of the Erasure Channel
abstract
One of the most important primitives in two-party distrustful cryptography is oblivious transfer, a complete primitive for two-party computation. Recently introduced, the oblivious transfer capacity of a noisy channel measures an efficiency of information theoretical reductions from 1-out-of-k, l-string oblivious transfer to noisy channels. It is defined as the maximal achievable ratio l/n, where l is the length of the strings which are to be transferred and n is the number of times the noisy channel is invoked. This quantity is unknown in a general case. For discrete memoryless channels, it is known to be nonnegligible for honest-but-curious players, but the non-zero rates have not ever been proved achievable in the case of malicious players. Here, we show that in the particular case of the erasure channel, more precise answers can be obtained. We compute the OT capacity of the erasure channel for the case of honest-but-curious players and, for the fully malicious players, we give its lower bound.
Hideki Imai, Kirill Morozov, Anderson C. A. Nascimento
ISIT2
2006 Efficient Protocols Achieving the Commitment Capacity of Noisy Correlations
abstract
Bit commitment is an important tool for constructing zero-knowledge proofs and multi-party computation. Unconditionally secure bit commitment can be based, in particular, on noisy channel or correlation where noise considered a valuable resource. Recently, Winter, Nascimento and Imai introduced the concept of commitment capacity, the maximal ratio between the length of a string which the sender commits to and the number of times the noisy channel/correlation is used. They also proved that for any discrete memoryless channel there exists a secure protocol achieving its commitment capacity however, no particular construction was given. Solving their open question, we provide an efficient protocol for achieving the commitment capacity of discrete memoryless systems (noisy channels and correlations).
Hideki Imai, Kirill Morozov, Anderson C. A. Nascimento, Andreas J. Winter 0002
ISIT2
2004 Unfair Noisy Channels and Oblivious Transfer
Ivan Damgård, Serge Fehr, Kirill Morozov, Louis Salvail
TCC3