Xavier Boyen

dblp:53/4957 · DBLP profile ↗
← Back
62ranked-venue papers
38as first author
15since 2021 · last 2026
0009-0003-7554-490XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 53 · 33 first-author · 11 since 2021Artificial intelligence and machine learning · 4 · 4 first-authorTheory of computation · 4 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Efficient Identity-Based Matchmaking Encryption with Enhanced Privacy and Chosen-Ciphertext Security
Qinyi Li, Xavier Boyen
ACISP (2)3
2026 Two-Factor Authentication Can Harden Servers Against Offline Password Search
Xavier Boyen, Stanislaw Jarecki, Phillip Nazarian, Jiayu Xu 0001, Tianyu Zheng
EUROCRYPT (2)1
2026 Proofs of Information Symmetry for Meeting of the Minds in E-Commerce Transactions
abstract
Distributed Ledger Technology (DLT) has gained significant attention due to its potential for enabling secure and decentralised systems. However, this premise can only be achieved if information asymmetry is eliminated and there is equal and simultaneous access to consistent and transparent data by all participants in the network. In this article, we explore various DLT information symmetry challenges, including theoretical fundamentals and practical hurdles in relation to the technology stack. We explore the potential of using DLT to facilitate mutual knowledge sharing in E-Commerce scenarios via Proofs of Information Symmetry (PoIS). We found that PoIS have the ability to significantly improve trust between transacting parties, specifically in the context of producer-consumer relationships and associated investor-asset management and contract obligations. In addition, we discovered that the effectiveness of PoIS strongly depends on the presence of a reliable notification system. Our study found that the utilisation of Zero-Knowledge (ZK) proofs can improve confidence among transaction partners, particularly in situations where safeguarding trade secrets or maintaining the privacy of agents is necessary. Our results are demonstrated by deriving from testing PoIS in a commercial context that includes a vehicle under a short-term lease management setup. This evaluation demonstrates the benefit of a contextual ZK proof that maintains the individual privacy of trading partners.
Xavier Boyen, Shoufeng Cao, Marcus Foth, Warwick Powell
Distributed Ledger Technol. Res. Pract.2
2025 Predicate-Private Asymmetric Searchable Encryption for Conjunctions from Lattices
Qinyi Li, Xavier Boyen
ESORICS (2)2
2024 A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected Vehicles
abstract
Wireless broadcast transmission technology enables vehicles to communicate with other nearby vehicles and with nearby fixed equipment. Vehicles and equipment within transmission range establish a self-organizing network called Vehicular Ad-hoc Network (VANET). The communication in VANETs is vulnerable to message manipulation attacks. Thus, mechanisms should be applied to ensure both the authenticity and integrity of the data broadcast. Any cryptographic technique employed for authentication requires the use of a cryptographic key, and mechanisms to restore the system quickly when either long-term and short-term cryptographic keying material are leaked or expired. Such mechanisms must be carefully designed to satisfy both perfect-forward-secrecy and security against known-key attacks. To achieve this, there should be no direct dependencies among keying material. Unfortunately, many existing proposals for authentication are not fully effective in VANETs, since many of them do not take a key-management mechanism into consideration or they fail to satisfy the requirements for secure key-update. In this paper, we first present a case study demonstrating that dependency among keying material is an exploitable vulnerability that violates perfect-forward-secrecy, and results in known-key attacks and message forgery attacks. Secondly, we propose a new cryptographic-key update protocol that consists of two sub-protocols: a long-term-key update protocol (for updating the long-term cryptographic keying material) and a short-term-key update protocol (for session-key establishment). Our scheme is accompanied by both security and efficiency analysis: we provide a formal security proof and demonstrate efficiency by conducting extensive performance analysis. This is compared with the security and efficiency of existing schemes in public literature.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Dependable Secur. Comput.3
2023 Identity-Based Matchmaking Encryption with Enhanced Privacy - A Generic Construction with Practical Instantiations
Xavier Boyen, Qinyi Li
ESORICS (2)1
2023 ALI: Anonymous Lightweight Inter-Vehicle Broadcast Authentication With Encryption
abstract
Wireless broadcast transmission enables Inter-vehicle or Vehicle-to-Vehicle (V2V) communication among nearby vehicles. This communication supports latency-critical applications for improved safety and maybe optimized traffic. However, V2V communication is vulnerable to cyber attacks involving message manipulation. Mechanisms are required to ensure both authenticity and integrity of broadcast data, while maintaining drivers privacy against surveillance. Considering the limited computational resources of vehicles and the possibility of high traffic density scenarios, authentication processes should have low computational overhead. Prior research has produced multiple authentication protocol proposals based on digital signatures, hash functions, or Message Authentication Codes (MACs). To date, there is no computationally efficient secure broadcast authentication scheme tolerable by the vehicles resource-constrained On-Board Units (OBUs) for latency-critical applications in heavy traffic conditions. This paper provides a new secure, efficient, and privacy-preserving scheme proposing Anonymous Lightweight Inter-vehicle (ALI) broadcast authentication with encryption. ALI provides a high level of anonymity by combining a message authentication scheme with beacon encryption. The cryptographic overhead for V2V communication in the ALI scheme is only 149 bytes, and can handle authentication of approximately 700 broadcast messages every 100 milliseconds. This demonstrates the suitability of the ALI scheme in heavy traffic scenarios. We show the security and efficiency of our proposal by conducting security proof and performance analysis.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Dependable Secur. Comput.3
2022 Zero-History Confidential Chains with Zero-Knowledge Contracts: A New Normal for Decentralized Ledgers?
Jayamine Alupotha, Xavier Boyen, Matthew McKague
ESORICS (1)2
2021 Anonymous Lattice Identity-Based Encryption with Traceable Identities
Xavier Boyen, Ernest Foo, Qinyi Li
ACISP1
2021 Epoque: Practical End-to-End Verifiable Post-Quantum-Secure E-Voting
abstract
The ultimate goal in modern secure e-voting is to enable everyone to verify whether the final election result correctly reflects the votes chosen by the (human) voters, without exposing how each individual voted. These fundamental security properties are called end-to-end verifiability and voter privacy. Unfortunately, it turns out to be very challenging to pursue these properties simultaneously, especially when the latter must be future-proofed against the rise of quantum computers. In this work, we show, for the first time, a practical approach to do this. We present Epoque, the first end-to-end verifiable, voter-private, post-quantum-secure homomorphic e-voting protocol. It achieves its properties through the combination of practical lattice-based cryptographic primitives only, in a novel way. We formally prove all our security claims under common trust and hardness assumptions. At the core of Epoque lies an efficient identity-based encryption (IBE) scheme with blazingly fast master-key decryption. It is the component that makes the efficient tallying of thousands or millions of ballots a practical possibility. In order to demonstrate its practicality, we fully implemented it and provide detailed benchmarks; we believe this latter contribution is of independent interest beyond the specific e-voting application.
Xavier Boyen, Thomas Haines, Johannes Müller 0001
EuroS&P1
2021 Secure Hybrid Encryption in the Standard Model from Hard Learning Problems
Xavier Boyen, Malika Izabachène, Qinyi Li
PQCrypto1
2021 From premise to practice of social consensus: How to agree on common knowledge in blockchain-enabled supply chains
Warwick Powell, Shoufeng Cao, Marcus Foth, Xavier Boyen, Barry Earsman, Santiago del Valle, Charles Turner-Morris
Comput. Networks5
2021 Efficient public-key encryption with equality test from lattices
Qinyi Li, Xavier Boyen
Theor. Comput. Sci.2
2021 CCA-security from adaptive all-but-one lossy trapdoor functions
Qinyi Li, Xavier Boyen, Ernest Foo
Theor. Comput. Sci.2
2021 On the Efficiency of Pairing-Based Authentication for Connected Vehicles: Time is Not on Our Side!
abstract
In the near future, intelligent vehicles will be connected via wireless communication links, forming Vehicular Ad-hoc Networks (VANETs). This has potential to improve road safety and to optimize traffic. However, if the communications are not secure, VANETs are vulnerable to cyber attacks involving message manipulation. Research on this problem has produced multiple authentication protocols based on bilinear pairings (a variant of elliptic curve cryptography). The efficiency of such authentication schemes must be addressed before they can be used in real-world deployments. Standards bodies have begun standardizing various pairing-based schemes. The IEEE 1609.2 security standard has not yet selected any pairing-based scheme, leaving the settings related to pairing-based cryptography in the vehicular environments unspecified. In this work, we investigate the efficiency of pairing-based cryptographic primitives over the Barreto-Lynn-Scott and Barreto-Naehrig pairing friendly elliptic curves recommended in the IETF and ISO standards, to determine their suitability for practical application. We implement the algorithms and evaluate the effect of cryptographic pairings using theoretical and experimental analysis of four well-known pairing-based short signature schemes, including: Boneh-Lynn-Shacham, Boneh-Boyen, Zhang-Safavi-Susilo, and Boneh-Gentry-Lynn-Shacham. We use metrics including CPU clock cycles per operation, average computation time in milliseconds, and signature/public key size in bits to estimate the cost of implementing cryptographic pairings on modern processors. We demonstrate the effect of pairing-based cryptography on authentication in vehicular networks. We investigate a high-density highway scenario and show that a crash is possible, as a result of the evaluated authentication delay. We share our findings ahead of the IEEE 1609.2 recommendations for the use of cryptographic pairings.
Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk
IEEE Trans. Inf. Forensics Secur.3
2020 Compact Multi-Party Confidential Transactions
Jayamine Alupotha, Xavier Boyen, Ernest Foo
CANS2
2020 A Verifiable and Practical Lattice-Based Decryption Mix Net with External Auditing
Xavier Boyen, Thomas Haines, Johannes Müller 0001
ESORICS (2)1
2019 Direct CCA-Secure KEM and Deterministic PKE from Plain LWE
Xavier Boyen, Qinyi Li
PQCrypto1
2018 Forward-Secure Linkable Ring Signatures
Xavier Boyen, Thomas Haines
ACISP1
2018 Almost Tight Multi-Instance Multi-Ciphertext Identity-Based Encryption on Lattices
Xavier Boyen, Qinyi Li
ACNS1
2017 All-But-Many Lossy Trapdoor Functions from Lattices and Applications
Xavier Boyen, Qinyi Li
CRYPTO (3)1
2016 Turing Machines with Shortcuts: Efficient Attribute-Based Encryption for Bounded Functions
Xavier Boyen, Qinyi Li
ACNS1
2016 Towards Tightly Secure Lattice Short Signature and Id-Based Encryption
Xavier Boyen, Qinyi Li
ASIACRYPT (2)1
2016 Unconditionally Anonymous Ring and Mesh Signatures
Xavier Boyen
J. Cryptol.1
2015 Attribute-Based Encryption for Finite Automata from LWE
Xavier Boyen, Qinyi Li
ProvSec1
2014 Sealing the Leak on Classical NTRU Signatures
Carlos Aguilar Melchor, Xavier Boyen, Jean-Christophe Deneuville, Philippe Gaborit
PQCrypto2
2013 Expressive Cryptography: Lattice Perspectives
Xavier Boyen
ACISP1
2013 Attribute-Based Functional Encryption on Lattices
Xavier Boyen
TCC1
2011 Expressive Encryption Systems from Lattices - (Abstract from the Invited Lecture)
Xavier Boyen
CANS1
2011 Efficient Selective Identity-Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen
J. Cryptol.2
2010 Shrinking the Keys of Discrete-Log-Type Lossy Trapdoor Functions
Xavier Boyen, Brent Waters
ACNS1
2010 Lattice Basis Delegation in Fixed Dimension and Shorter-Ciphertext Hierarchical IBE
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen
CRYPTO3
2010 Kamouflage: Loss-Resistant Password Management
Hristo Bojinov, Elie Bursztein, Xavier Boyen, Dan Boneh
ESORICS3
2010 Efficient Lattice (H)IBE in the Standard Model
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen
EUROCRYPT3
2009 HPAKE : Password Authentication Secure against Cross-Site User Impersonation
Xavier Boyen
CANS1
2009 Hidden credential retrieval from a reusable password
abstract
We revisit the venerable question of access credentials management, which concerns the techniques that we, humans with limited memory, must employ to safeguard our various access keys and tokens in a connected world. Although many existing solutions can be employed to protect a long secret using a short password, those solutions typically require certain assumptions on the distribution of the secret and/or the password, and are helpful against only a subset of the possible attackers.
Xavier Boyen
AsiaCCS1
2008 New Paradigms for Password Security
Xavier Boyen
ACISP1
2008 The Uber-Assumption Family
Xavier Boyen
Pairing1
2008 Short Signatures Without Random Oracles and the SDH Assumption in Bilinear Groups
Dan Boneh, Xavier Boyen
J. Cryptol.2
2007 Miniature CCA2 PK Encryption: Tight Security Without Redundancy
Xavier Boyen
ASIACRYPT1
2007 Mesh Signatures
Xavier Boyen
EUROCRYPT1
2007 General Ad Hoc Encryption from Exponent Inversion IBE
Xavier Boyen
EUROCRYPT1
2007 Halting Password Puzzles: Hard-to-break Encryption from Human-memorable Keys
Xavier Boyen
USENIX Security Symposium1
2006 Forward-secure signatures with untrusted update
abstract
In most forward-secure signature constructions, a program that updates a user's private signing key must have full access to the private key. Unfortunately, these schemes are incompatible with several security architectures including Gnu Privacy Guard (GPG) and S/MIME, where the private key is encrypted under a user password as a "second factor" of security, in case the private key storage is corrupted, but the password is not.We introduce the concept of forward-secure signatures with untrusted update, where the key update can be performed on an encrypted version of the key. Forward secure signatures with untrusted update allow us to add forward security to signatures, while still keeping passwords as a second factor of security. We provide a construction that has performance characteristics comparable with the best existing forward-secure signatures. In addition, we describe how to modify the Bellare-Miner forward secure signature scheme to achieve untrusted update.
Xavier Boyen, Hovav Shacham, Emily Shen, Brent Waters
CCS1
2006 On the Impossibility of Efficiently Combining Collision Resistant Hash Functions
Dan Boneh, Xavier Boyen
CRYPTO2
2006 Anonymous Hierarchical Identity-Based Encryption (Without Random Oracles)
Xavier Boyen, Brent Waters
CRYPTO1
2006 Chosen Ciphertext Secure Public Key Threshold Encryption Without Random Oracles
Dan Boneh, Xavier Boyen, Shai Halevi
CT-RSA2
2006 Compact Group Signatures Without Random Oracles
Xavier Boyen, Brent Waters
EUROCRYPT1
2006 A Promenade through the New Cryptography of Bilinear Pairings
abstract
This paper gives an introductory account of the origin, nature, and uses of bilinear pairings, arguably the newest and hottest toy in a cryptographer's toolbox. A handful of cryptosystems built on pairings are briefly surveyed, including a couple of realizations of the famously elusive identity-based encryption primitive.
Xavier Boyen
ITW1
2005 Direct chosen ciphertext security from identity-based techniques
abstract
We describe a new encryption technique that is secure in the standard model against chosen ciphertext attacks. We base our method on two very efficient Identity-Based Encryption (IBE) schemes without random oracles due to Boneh and Boyen, and Waters.Unlike previous CCA2-secure cryptosystems that use IBE as a black box, our approach is very simple and compact. It makes direct use of the underlying IBE structure, and requires no cryptographic primitive other than the IBE scheme itself. This conveys several advantages. We achieve shorter ciphertext size than the best known instantiations of the other methods, and our technique is as efficient as the Boneh and Katz method (and more so than that of Canetti, Halevi, and Katz). Further, our method operates nicely on hierarchical IBE, and since it allows the validity of ciphertexts to be checked publicly, it can be used to construct systems with non-interactive threshold decryption.In this paper we describe two main constructions: a full encryption system based on the Waters adaptive-ID secure IBE, and a KEM based on the Boneh-Boyen selective-ID secure IBE. Both systems are shown CCA2-secure in the standard model, the latter with a tight reduction. We discuss several uses and extensions of our approach, and draw comparisons with other schemes that are provably secure in the standard model.
Xavier Boyen, Qixiang Mei, Brent Waters
CCS1
2005 Hierarchical Identity Based Encryption with Constant Size Ciphertext
Dan Boneh, Xavier Boyen, Eu-Jin Goh
EUROCRYPT2
2005 Secure Remote Authentication Using Biometric Data
Xavier Boyen, Yevgeniy Dodis, Jonathan Katz, Rafail Ostrovsky, Adam D. Smith 0001
EUROCRYPT1
2004 Reusable cryptographic fuzzy extractors
abstract
We show that a number of recent definitions and constructions of fuzzy extractors are not adequate for multiple uses of the same fuzzy secret---a major shortcoming in the case of biometric applications. We propose two particularly stringent security models that specifically address the case of fuzzy secret reuse, respectively from an outsider and an insider perspective, in what we call a chosen perturbation attack. We characterize the conditions that fuzzy extractors need to satisfy to be secure, and present generic constructions from ordinary building blocks. As an illustration, we demonstrate how to use a biometric secret in a remote fuzzy authentication protocol that does not require any storage on the client's side.
Xavier Boyen
CCS1
2004 Secure Identity Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen
CRYPTO2
2004 Short Group Signatures
Dan Boneh, Xavier Boyen, Hovav Shacham
CRYPTO2
2004 Short Signatures Without Random Oracles
Dan Boneh, Xavier Boyen
EUROCRYPT2
2004 Efficient Selective-ID Secure Identity-Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen
EUROCRYPT2
2003 Multipurpose Identity-Based Signcryption (A Swiss Army Knife for Identity-Based Cryptography)
Xavier Boyen
CRYPTO1
1999 Discovering the Hidden Structure of Complex Dynamic Systems
Xavier Boyen, Nir Friedman, Daphne Koller
UAI1
1999 Automatic induction of fuzzy decision trees and its application to power system security assessment
Xavier Boyen, Louis Wehenkel
Fuzzy Sets Syst.1
1998 Approximate Learning of Dynamic Models
Xavier Boyen, Daphne Koller
NIPS1
1998 Tractable Inference for Complex Stochastic Processes
Xavier Boyen, Daphne Koller
UAI1