VLDB 2026 Research / reviewers in the wild / expert
Xavier Boyen
dblp:53/4957
· DBLP profile ↗
62ranked-venue papers
38as first author
15since 2021 · last 2026
0009-0003-7554-490XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 53 · 33 first-author · 11 since 2021Artificial intelligence and machine learning · 4 · 4 first-authorTheory of computation · 4 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Identity-Based Matchmaking Encryption with Enhanced Privacy and Chosen-Ciphertext Security
Qinyi Li, Xavier Boyen |
ACISP (2) | 3 |
| 2026 | Two-Factor Authentication Can Harden Servers Against Offline Password Search
Xavier Boyen, Stanislaw Jarecki, Phillip Nazarian, Jiayu Xu 0001, Tianyu Zheng |
EUROCRYPT (2) | 1 |
| 2026 | Proofs of Information Symmetry for Meeting of the Minds in E-Commerce TransactionsabstractDistributed Ledger Technology (DLT) has gained significant attention due to its potential for enabling secure and decentralised systems. However, this premise can only be achieved if information asymmetry is eliminated and there is equal and simultaneous access to consistent and transparent data by all participants in the network. In this article, we explore various DLT information symmetry challenges, including theoretical fundamentals and practical hurdles in relation to the technology stack. We explore the potential of using DLT to facilitate mutual knowledge sharing in E-Commerce scenarios via Proofs of Information Symmetry (PoIS). We found that PoIS have the ability to significantly improve trust between transacting parties, specifically in the context of producer-consumer relationships and associated investor-asset management and contract obligations. In addition, we discovered that the effectiveness of PoIS strongly depends on the presence of a reliable notification system. Our study found that the utilisation of Zero-Knowledge (ZK) proofs can improve confidence among transaction partners, particularly in situations where safeguarding trade secrets or maintaining the privacy of agents is necessary. Our results are demonstrated by deriving from testing PoIS in a commercial context that includes a vehicle under a short-term lease management setup. This evaluation demonstrates the benefit of a contextual ZK proof that maintains the individual privacy of trading partners. Xavier Boyen, Shoufeng Cao, Marcus Foth, Warwick Powell |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2025 | Predicate-Private Asymmetric Searchable Encryption for Conjunctions from Lattices
Qinyi Li, Xavier Boyen |
ESORICS (2) | 2 |
| 2024 | A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected VehiclesabstractWireless broadcast transmission technology enables vehicles to communicate with other nearby vehicles and with nearby fixed equipment. Vehicles and equipment within transmission range establish a self-organizing network called Vehicular Ad-hoc Network (VANET). The communication in VANETs is vulnerable to message manipulation attacks. Thus, mechanisms should be applied to ensure both the authenticity and integrity of the data broadcast. Any cryptographic technique employed for authentication requires the use of a cryptographic key, and mechanisms to restore the system quickly when either long-term and short-term cryptographic keying material are leaked or expired. Such mechanisms must be carefully designed to satisfy both perfect-forward-secrecy and security against known-key attacks. To achieve this, there should be no direct dependencies among keying material. Unfortunately, many existing proposals for authentication are not fully effective in VANETs, since many of them do not take a key-management mechanism into consideration or they fail to satisfy the requirements for secure key-update. In this paper, we first present a case study demonstrating that dependency among keying material is an exploitable vulnerability that violates perfect-forward-secrecy, and results in known-key attacks and message forgery attacks. Secondly, we propose a new cryptographic-key update protocol that consists of two sub-protocols: a long-term-key update protocol (for updating the long-term cryptographic keying material) and a short-term-key update protocol (for session-key establishment). Our scheme is accompanied by both security and efficiency analysis: we provide a formal security proof and demonstrate efficiency by conducting extensive performance analysis. This is compared with the security and efficiency of existing schemes in public literature. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Identity-Based Matchmaking Encryption with Enhanced Privacy - A Generic Construction with Practical Instantiations
Xavier Boyen, Qinyi Li |
ESORICS (2) | 1 |
| 2023 | ALI: Anonymous Lightweight Inter-Vehicle Broadcast Authentication With EncryptionabstractWireless broadcast transmission enables Inter-vehicle or Vehicle-to-Vehicle (V2V) communication among nearby vehicles. This communication supports latency-critical applications for improved safety and maybe optimized traffic. However, V2V communication is vulnerable to cyber attacks involving message manipulation. Mechanisms are required to ensure both authenticity and integrity of broadcast data, while maintaining drivers privacy against surveillance. Considering the limited computational resources of vehicles and the possibility of high traffic density scenarios, authentication processes should have low computational overhead. Prior research has produced multiple authentication protocol proposals based on digital signatures, hash functions, or Message Authentication Codes (MACs). To date, there is no computationally efficient secure broadcast authentication scheme tolerable by the vehicles resource-constrained On-Board Units (OBUs) for latency-critical applications in heavy traffic conditions. This paper provides a new secure, efficient, and privacy-preserving scheme proposing Anonymous Lightweight Inter-vehicle (ALI) broadcast authentication with encryption. ALI provides a high level of anonymity by combining a message authentication scheme with beacon encryption. The cryptographic overhead for V2V communication in the ALI scheme is only 149 bytes, and can handle authentication of approximately 700 broadcast messages every 100 milliseconds. This demonstrates the suitability of the ALI scheme in heavy traffic scenarios. We show the security and efficiency of our proposal by conducting security proof and performance analysis. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Zero-History Confidential Chains with Zero-Knowledge Contracts: A New Normal for Decentralized Ledgers?
Jayamine Alupotha, Xavier Boyen, Matthew McKague |
ESORICS (1) | 2 |
| 2021 | Anonymous Lattice Identity-Based Encryption with Traceable Identities
Xavier Boyen, Ernest Foo, Qinyi Li |
ACISP | 1 |
| 2021 | Epoque: Practical End-to-End Verifiable Post-Quantum-Secure E-VotingabstractThe ultimate goal in modern secure e-voting is to enable everyone to verify whether the final election result correctly reflects the votes chosen by the (human) voters, without exposing how each individual voted. These fundamental security properties are called end-to-end verifiability and voter privacy. Unfortunately, it turns out to be very challenging to pursue these properties simultaneously, especially when the latter must be future-proofed against the rise of quantum computers. In this work, we show, for the first time, a practical approach to do this. We present Epoque, the first end-to-end verifiable, voter-private, post-quantum-secure homomorphic e-voting protocol. It achieves its properties through the combination of practical lattice-based cryptographic primitives only, in a novel way. We formally prove all our security claims under common trust and hardness assumptions. At the core of Epoque lies an efficient identity-based encryption (IBE) scheme with blazingly fast master-key decryption. It is the component that makes the efficient tallying of thousands or millions of ballots a practical possibility. In order to demonstrate its practicality, we fully implemented it and provide detailed benchmarks; we believe this latter contribution is of independent interest beyond the specific e-voting application. Xavier Boyen, Thomas Haines, Johannes Müller 0001 |
EuroS&P | 1 |
| 2021 | Secure Hybrid Encryption in the Standard Model from Hard Learning Problems
Xavier Boyen, Malika Izabachène, Qinyi Li |
PQCrypto | 1 |
| 2021 | From premise to practice of social consensus: How to agree on common knowledge in blockchain-enabled supply chains
Warwick Powell, Shoufeng Cao, Marcus Foth, Xavier Boyen, Barry Earsman, Santiago del Valle, Charles Turner-Morris |
Comput. Networks | 5 |
| 2021 | Efficient public-key encryption with equality test from lattices
Qinyi Li, Xavier Boyen |
Theor. Comput. Sci. | 2 |
| 2021 | CCA-security from adaptive all-but-one lossy trapdoor functions
Qinyi Li, Xavier Boyen, Ernest Foo |
Theor. Comput. Sci. | 2 |
| 2021 | On the Efficiency of Pairing-Based Authentication for Connected Vehicles: Time is Not on Our Side!abstractIn the near future, intelligent vehicles will be connected via wireless communication links, forming Vehicular Ad-hoc Networks (VANETs). This has potential to improve road safety and to optimize traffic. However, if the communications are not secure, VANETs are vulnerable to cyber attacks involving message manipulation. Research on this problem has produced multiple authentication protocols based on bilinear pairings (a variant of elliptic curve cryptography). The efficiency of such authentication schemes must be addressed before they can be used in real-world deployments. Standards bodies have begun standardizing various pairing-based schemes. The IEEE 1609.2 security standard has not yet selected any pairing-based scheme, leaving the settings related to pairing-based cryptography in the vehicular environments unspecified. In this work, we investigate the efficiency of pairing-based cryptographic primitives over the Barreto-Lynn-Scott and Barreto-Naehrig pairing friendly elliptic curves recommended in the IETF and ISO standards, to determine their suitability for practical application. We implement the algorithms and evaluate the effect of cryptographic pairings using theoretical and experimental analysis of four well-known pairing-based short signature schemes, including: Boneh-Lynn-Shacham, Boneh-Boyen, Zhang-Safavi-Susilo, and Boneh-Gentry-Lynn-Shacham. We use metrics including CPU clock cycles per operation, average computation time in milliseconds, and signature/public key size in bits to estimate the cost of implementing cryptographic pairings on modern processors. We demonstrate the effect of pairing-based cryptography on authentication in vehicular networks. We investigate a high-density highway scenario and show that a crash is possible, as a result of the evaluated authentication delay. We share our findings ahead of the IEEE 1609.2 recommendations for the use of cryptographic pairings. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Compact Multi-Party Confidential Transactions
Jayamine Alupotha, Xavier Boyen, Ernest Foo |
CANS | 2 |
| 2020 | A Verifiable and Practical Lattice-Based Decryption Mix Net with External Auditing
Xavier Boyen, Thomas Haines, Johannes Müller 0001 |
ESORICS (2) | 1 |
| 2019 | Direct CCA-Secure KEM and Deterministic PKE from Plain LWE
Xavier Boyen, Qinyi Li |
PQCrypto | 1 |
| 2018 | Forward-Secure Linkable Ring Signatures
Xavier Boyen, Thomas Haines |
ACISP | 1 |
| 2018 | Almost Tight Multi-Instance Multi-Ciphertext Identity-Based Encryption on Lattices
Xavier Boyen, Qinyi Li |
ACNS | 1 |
| 2017 | All-But-Many Lossy Trapdoor Functions from Lattices and Applications
Xavier Boyen, Qinyi Li |
CRYPTO (3) | 1 |
| 2016 | Turing Machines with Shortcuts: Efficient Attribute-Based Encryption for Bounded Functions
Xavier Boyen, Qinyi Li |
ACNS | 1 |
| 2016 | Towards Tightly Secure Lattice Short Signature and Id-Based Encryption
Xavier Boyen, Qinyi Li |
ASIACRYPT (2) | 1 |
| 2016 | Unconditionally Anonymous Ring and Mesh Signatures
Xavier Boyen |
J. Cryptol. | 1 |
| 2015 | Attribute-Based Encryption for Finite Automata from LWE
Xavier Boyen, Qinyi Li |
ProvSec | 1 |
| 2014 | Sealing the Leak on Classical NTRU Signatures
Carlos Aguilar Melchor, Xavier Boyen, Jean-Christophe Deneuville, Philippe Gaborit |
PQCrypto | 2 |
| 2013 | Expressive Cryptography: Lattice Perspectives
Xavier Boyen |
ACISP | 1 |
| 2013 | Attribute-Based Functional Encryption on Lattices
Xavier Boyen |
TCC | 1 |
| 2011 | Expressive Encryption Systems from Lattices - (Abstract from the Invited Lecture)
Xavier Boyen |
CANS | 1 |
| 2011 | Efficient Selective Identity-Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen |
J. Cryptol. | 2 |
| 2010 | Shrinking the Keys of Discrete-Log-Type Lossy Trapdoor Functions
Xavier Boyen, Brent Waters |
ACNS | 1 |
| 2010 | Lattice Basis Delegation in Fixed Dimension and Shorter-Ciphertext Hierarchical IBE
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen |
CRYPTO | 3 |
| 2010 | Kamouflage: Loss-Resistant Password Management
Hristo Bojinov, Elie Bursztein, Xavier Boyen, Dan Boneh |
ESORICS | 3 |
| 2010 | Efficient Lattice (H)IBE in the Standard Model
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen |
EUROCRYPT | 3 |
| 2009 | HPAKE : Password Authentication Secure against Cross-Site User Impersonation
Xavier Boyen |
CANS | 1 |
| 2009 | Hidden credential retrieval from a reusable passwordabstractWe revisit the venerable question of access credentials management, which concerns the techniques that we, humans with limited memory, must employ to safeguard our various access keys and tokens in a connected world. Although many existing solutions can be employed to protect a long secret using a short password, those solutions typically require certain assumptions on the distribution of the secret and/or the password, and are helpful against only a subset of the possible attackers. Xavier Boyen |
AsiaCCS | 1 |
| 2008 | New Paradigms for Password Security
Xavier Boyen |
ACISP | 1 |
| 2008 | The Uber-Assumption Family
Xavier Boyen |
Pairing | 1 |
| 2008 | Short Signatures Without Random Oracles and the SDH Assumption in Bilinear Groups
Dan Boneh, Xavier Boyen |
J. Cryptol. | 2 |
| 2007 | Miniature CCA2 PK Encryption: Tight Security Without Redundancy
Xavier Boyen |
ASIACRYPT | 1 |
| 2007 | Mesh Signatures
Xavier Boyen |
EUROCRYPT | 1 |
| 2007 | General Ad Hoc Encryption from Exponent Inversion IBE
Xavier Boyen |
EUROCRYPT | 1 |
| 2007 | Halting Password Puzzles: Hard-to-break Encryption from Human-memorable Keys
Xavier Boyen |
USENIX Security Symposium | 1 |
| 2006 | Forward-secure signatures with untrusted updateabstractIn most forward-secure signature constructions, a program that updates a user's private signing key must have full access to the private key. Unfortunately, these schemes are incompatible with several security architectures including Gnu Privacy Guard (GPG) and S/MIME, where the private key is encrypted under a user password as a "second factor" of security, in case the private key storage is corrupted, but the password is not.We introduce the concept of forward-secure signatures with untrusted update, where the key update can be performed on an encrypted version of the key. Forward secure signatures with untrusted update allow us to add forward security to signatures, while still keeping passwords as a second factor of security. We provide a construction that has performance characteristics comparable with the best existing forward-secure signatures. In addition, we describe how to modify the Bellare-Miner forward secure signature scheme to achieve untrusted update. Xavier Boyen, Hovav Shacham, Emily Shen, Brent Waters |
CCS | 1 |
| 2006 | On the Impossibility of Efficiently Combining Collision Resistant Hash Functions
Dan Boneh, Xavier Boyen |
CRYPTO | 2 |
| 2006 | Anonymous Hierarchical Identity-Based Encryption (Without Random Oracles)
Xavier Boyen, Brent Waters |
CRYPTO | 1 |
| 2006 | Chosen Ciphertext Secure Public Key Threshold Encryption Without Random Oracles
Dan Boneh, Xavier Boyen, Shai Halevi |
CT-RSA | 2 |
| 2006 | Compact Group Signatures Without Random Oracles
Xavier Boyen, Brent Waters |
EUROCRYPT | 1 |
| 2006 | A Promenade through the New Cryptography of Bilinear PairingsabstractThis paper gives an introductory account of the origin, nature, and uses of bilinear pairings, arguably the newest and hottest toy in a cryptographer's toolbox. A handful of cryptosystems built on pairings are briefly surveyed, including a couple of realizations of the famously elusive identity-based encryption primitive. Xavier Boyen |
ITW | 1 |
| 2005 | Direct chosen ciphertext security from identity-based techniquesabstractWe describe a new encryption technique that is secure in the standard model against chosen ciphertext attacks. We base our method on two very efficient Identity-Based Encryption (IBE) schemes without random oracles due to Boneh and Boyen, and Waters.Unlike previous CCA2-secure cryptosystems that use IBE as a black box, our approach is very simple and compact. It makes direct use of the underlying IBE structure, and requires no cryptographic primitive other than the IBE scheme itself. This conveys several advantages. We achieve shorter ciphertext size than the best known instantiations of the other methods, and our technique is as efficient as the Boneh and Katz method (and more so than that of Canetti, Halevi, and Katz). Further, our method operates nicely on hierarchical IBE, and since it allows the validity of ciphertexts to be checked publicly, it can be used to construct systems with non-interactive threshold decryption.In this paper we describe two main constructions: a full encryption system based on the Waters adaptive-ID secure IBE, and a KEM based on the Boneh-Boyen selective-ID secure IBE. Both systems are shown CCA2-secure in the standard model, the latter with a tight reduction. We discuss several uses and extensions of our approach, and draw comparisons with other schemes that are provably secure in the standard model. Xavier Boyen, Qixiang Mei, Brent Waters |
CCS | 1 |
| 2005 | Hierarchical Identity Based Encryption with Constant Size Ciphertext
Dan Boneh, Xavier Boyen, Eu-Jin Goh |
EUROCRYPT | 2 |
| 2005 | Secure Remote Authentication Using Biometric Data
Xavier Boyen, Yevgeniy Dodis, Jonathan Katz, Rafail Ostrovsky, Adam D. Smith 0001 |
EUROCRYPT | 1 |
| 2004 | Reusable cryptographic fuzzy extractorsabstractWe show that a number of recent definitions and constructions of fuzzy extractors are not adequate for multiple uses of the same fuzzy secret---a major shortcoming in the case of biometric applications. We propose two particularly stringent security models that specifically address the case of fuzzy secret reuse, respectively from an outsider and an insider perspective, in what we call a chosen perturbation attack. We characterize the conditions that fuzzy extractors need to satisfy to be secure, and present generic constructions from ordinary building blocks. As an illustration, we demonstrate how to use a biometric secret in a remote fuzzy authentication protocol that does not require any storage on the client's side. Xavier Boyen |
CCS | 1 |
| 2004 | Secure Identity Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen |
CRYPTO | 2 |
| 2004 | Short Group Signatures
Dan Boneh, Xavier Boyen, Hovav Shacham |
CRYPTO | 2 |
| 2004 | Short Signatures Without Random Oracles
Dan Boneh, Xavier Boyen |
EUROCRYPT | 2 |
| 2004 | Efficient Selective-ID Secure Identity-Based Encryption Without Random Oracles
Dan Boneh, Xavier Boyen |
EUROCRYPT | 2 |
| 2003 | Multipurpose Identity-Based Signcryption (A Swiss Army Knife for Identity-Based Cryptography)
Xavier Boyen |
CRYPTO | 1 |
| 1999 | Discovering the Hidden Structure of Complex Dynamic Systems
Xavier Boyen, Nir Friedman, Daphne Koller |
UAI | 1 |
| 1999 | Automatic induction of fuzzy decision trees and its application to power system security assessment
Xavier Boyen, Louis Wehenkel |
Fuzzy Sets Syst. | 1 |
| 1998 | Approximate Learning of Dynamic Models
Xavier Boyen, Daphne Koller |
NIPS | 1 |
| 1998 | Tractable Inference for Complex Stochastic Processes
Xavier Boyen, Daphne Koller |
UAI | 1 |