Benoît Libert

dblp:62/1759 · DBLP profile ↗
← Back
85ranked-venue papers
62as first author
15since 2021 · last 2026
0000-0002-6914-1616ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 71 · 49 first-author · 14 since 2021Theory of computation · 15 · 14 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 first-author
YearPublicationVenuePosition
2026 Fully Asymmetric Anamorphic Homomorphic Encryption from LWE
Amit Deo, Benoît Libert
EUROCRYPT (5)2
2025 On Proofs of Plaintext Knowledge for the Joye-Libert Encryption Scheme
Benoît Libert, Thomas Peters
ACNS (2)1
2025 Anamorphic Signatures With Dictator and Recipient Unforgeability for Long Messages
Amit Deo, Benoît Libert
ASIACRYPT (6)2
2025 Fast Homomorphic Evaluation of LWR-based PRFs
abstract
Certain applications of fully homomorphic encryption (such as transciphering, universal thresholdizers, and PIR) require randomness while operating over encrypted data. This randomness has to be obliviously generated in the encrypted domain and remain encrypted throughout the computation. Moreover, it should be guaranteed that independent-looking random coins can be obliviously generated for different computations.
Amit Deo, Marc Joye, Benoît Libert, Benjamin R. Curtis, Mayeul de Bellabre
CCS3
2025 Simplified Adaptively Secure Threshold BLS Signatures
Benoît Libert
CT-RSA1
2025 Leveraging Small Message Spaces for CCA1 Security in Additively Homomorphic and BGN-Type Encryption
Benoît Libert
EUROCRYPT (2)1
2024 Non-malleable Subvector Commitments
Benoît Libert
ASIACRYPT (3)1
2023 Zero-Knowledge Arguments for Lattice-Based Accumulators: Logarithmic-Size Ring Signatures and Group Signatures Without Trapdoors
abstract
Abstract An accumulator is a function that hashes a set of inputs into a short, constant-size string while preserving the ability to efficiently prove the inclusion of a specific input element in the hashed set. It has proved useful in the design of numerous privacy-enhancing protocols, in order to handle revocation or simply prove set membership. In the lattice setting, currently known instantiations of the primitive are based on Merkle trees, which do not interact well with zero-knowledge proofs. In order to efficiently prove the membership of some element in a zero-knowledge manner, the prover has to demonstrate knowledge of a hash chain without revealing it, which is not known to be efficiently possible under well-studied hardness assumptions. In this paper, we provide an efficient method of proving such statements using involved extensions of Stern’s protocol. Under the Small Integer Solution assumption, we provide zero-knowledge arguments showing possession of a hash chain. As an application, we describe new lattice-based group and ring signatures in the random oracle model. In particular, we obtain: (i) the first lattice-based ring signatures with logarithmic size in the cardinality of the ring and (ii) the first lattice-based group signature that does not require any GPV trapdoor and thus allows for a much more efficient choice of parameters.
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang
J. Cryptol.1
2022 PointProofs, Revisited
Benoît Libert, Alain Passelègue, Mahshid Riahinia
ASIACRYPT (4)1
2022 Updatable Public Key Encryption from DCR: Efficient Constructions With Stronger Security
abstract
Forward-secure encryption (FS-PKE) is a key-evolving public-key paradigm that preserves the confidentiality of past encryptions in case of key exposure. Updatable public-key encryption (UPKE) is a natural relaxation of FS-PKE, introduced by Jost et al. (Eurocrypt'19), which is motivated by applications to secure messaging. In UPKE, key updates can be triggered by any sender -- via special update ciphertexts -- willing to enforce the forward secrecy of its encrypted messages. So far, the only truly efficient UPKE candidates (which rely on the random oracle idealization) only provide rather weak security guarantees against passive adversaries as they are malleable. Also, they offer no protection against malicious senders willing to hinder the decryption capability of honest users. A recent work of Dodis et al. (TCC'21) described UPKE systems in the standard model that also hedge against maliciously generated update messages in the chosen-ciphertext setting (where adversaries are equipped with a decryption oracle). While important feasibility results, their constructions lag behind random-oracle candidates in terms of efficiency. In this paper, we first provide a drastically more efficient UPKE realization in the standard model using Paillier's Composite Residuosity (DCR) assumption. In the random oracle model, we then extend our initial scheme so as to achieve chosen-ciphertext security, even in a model that accounts for maliciously generated update ciphertexts. Under the DCR and Strong RSA assumptions, we thus obtain the first practical UPKE systems that satisfy the strongest security notions put forth by Dodis et al.
Calvin Abou Haidar, Benoît Libert, Alain Passelègue
CCS2
2022 One-Shot Fiat-Shamir-Based NIZK Arguments of Composite Residuosity and Logarithmic-Size Ring Signatures in the Standard Model
Benoît Libert, Khoa Nguyen 0002, Thomas Peters, Moti Yung
EUROCRYPT (2)1
2021 Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing Scheme
Benoît Libert, Khoa Nguyen 0002, Thomas Peters, Moti Yung
EUROCRYPT (3)1
2021 SO-CCA secure PKE from pairing based all-but-many lossy trapdoor functions
Dingding Jia, Benoît Libert
Des. Codes Cryptogr.2
2021 Adaptively Secure Distributed PRFs from sf LWE
Benoît Libert, Damien Stehlé, Radu Titiu
J. Cryptol.1
2021 Adaptive oblivious transfer with access control from lattice assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang
Theor. Comput. Sci.1
2020 Lattice-Based E-Cash, Revisited
Amit Deo, Benoît Libert, Khoa Nguyen 0002, Olivier Sanders
ASIACRYPT (2)2
2020 Simulation-Sound Arguments for LWE and Applications to KDM-CCA2 Security
Benoît Libert, Khoa Nguyen 0002, Alain Passelègue, Radu Titiu
ASIACRYPT (1)1
2020 New Constructions of Statistical NIZKs: Dual-Mode DV-NIZKs and More
Benoît Libert, Alain Passelègue, Hoeteck Wee, David J. Wu 0001
EUROCRYPT (3)1
2020 Adaptively Secure Non-interactive CCA-Secure Threshold Cryptosystems: Generic Framework and Constructions
Benoît Libert, Moti Yung
J. Cryptol.1
2019 Multi-Client Functional Encryption for Linear Functions in the Standard Model from LWE
Benoît Libert, Radu Titiu
ASIACRYPT (3)1
2019 Zero-knowledge arguments for matrix-vector relations and lattice-based group encryption
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang
Theor. Comput. Sci.1
2018 Lattice-Based Zero-Knowledge Arguments for Integer Relations
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang
CRYPTO (2)1
2018 Logarithmic-Size Ring Signatures with Tight Security from the DDH Assumption
Benoît Libert, Thomas Peters, Chen Qian 0002
ESORICS (2)1
2018 Adaptively Secure Distributed PRFs from \mathsf LWE
Benoît Libert, Damien Stehlé, Radu Titiu
TCC (2)1
2017 Adaptive Oblivious Transfer with Access Control from Lattice Assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang
ASIACRYPT (1)1
2017 Zero-Knowledge Arguments for Lattice-Based PRFs and Applications to E-Cash
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang
ASIACRYPT (3)1
2017 All-But-Many Lossy Trapdoor Functions and Selective Opening Chosen-Ciphertext Security from LWE
Benoît Libert, Amin Sakzad, Damien Stehlé, Ron Steinfeld
CRYPTO (3)1
2017 Encoding-Free ElGamal-Type Encryption Schemes on Elliptic Curves
Marc Joye, Benoît Libert
CT-RSA2
2017 Efficient Cryptosystems From 2k-th Power Residue Symbols
Fabrice Benhamouda, Javier Herranz, Marc Joye, Benoît Libert
J. Cryptol.4
2016 A Lattice-Based Group Signature Scheme with Message-Dependent Opening
Benoît Libert, Fabrice Mouhartem, Khoa Nguyen 0002
ACNS1
2016 Zero-Knowledge Arguments for Matrix-Vector Relations and Lattice-Based Group Encryption
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang
ASIACRYPT (2)1
2016 Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang
ASIACRYPT (2)1
2016 Practical "Signatures with Efficient Protocols" from Simple Assumptions
abstract
Digital signatures are perhaps the most important base for authentication and trust relationships in large scale systems. More specifically, various applications of signatures provide privacy and anonymity preserving mechanisms and protocols, and these, in turn, are becoming critical (due to the recently recognized need to protect individuals according to national rules and regulations). A specific type of signatures called "signatures with efficient protocols", as introduced by Camenisch and Lysyanskaya (CL), efficiently accommodates various basic protocols and extensions like zero-knowledge proofs, signing committed messages, or re-randomizability. These are, in fact, typical operations associated with signatures used in typical anonymity and privacy-preserving scenarios.
Benoît Libert, Fabrice Mouhartem, Thomas Peters, Moti Yung
AsiaCCS1
2016 Fully Secure Functional Encryption for Inner Products, from Standard Assumptions
Shweta Agrawal 0001, Benoît Libert, Damien Stehlé
CRYPTO (3)2
2016 Zero-Knowledge Arguments for Lattice-Based Accumulators: Logarithmic-Size Ring Signatures and Group Signatures Without Trapdoors
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang
EUROCRYPT (2)1
2016 Functional Commitment Schemes: From Polynomial Commitments to Pairing-Based Accumulators from Simple Assumptions
abstract
We formalize a cryptographic primitive called functional commitment (FC) which can be viewed as a generalization of vector commitments (VCs), polynomial commitments and many other special kinds of commitment schemes. A non-interactive functional commitment allows committing to a message in such a way that the committer has the flexibility of only revealing a function of the committed message during the opening phase. We provide constructions for the functionality of linear functions, where messages consist of vectors over some domain and commitments can later be opened to a specific linear function of the vector coordinates. An opening for a function thus generates a witness for the fact that the function indeed evaluates to a given value for the committed message. One security requirement is called function binding and requires that no adversary be able to open a commitment to two different evaluations for the same function. We propose a construction of functional commitment for linear functions based on constantsize assumptions in composite order groups endowed with a bilinear map. The construction has commitments and openings of constant size (i.e., independent of n or function description) and is perfectly hiding - the underlying message is information theoretically hidden. Our security proofs build on the Déjà Q framework of Chase and Meiklejohn (Eurocrypt 2014) and its extension by Wee (TCC 2016) to encryption primitives, thus relying on constant-size subgroup decisional assumptions. We show that FC for linear functions are sufficiently powerful to solve four open problems. They, first, imply polynomial commitments, and, then, give cryptographic accumulators (i.e., an algebraic hash function which makes it possible to efficiently prove that some input belongs to a hashed set). In particular, specializing our FC construction leads to the first pairing-based polynomial commitments and accumulators for large universes known to achieve security under simple assumptions. We also substantially extend our pairing-based accumulator to handle subset queries which requires a non-trivial extension of the Déjà Q framework.
Benoît Libert, Somindu C. Ramanna, Moti Yung
ICALP1
2016 Born and raised distributively: Fully distributed non-interactive adaptively-secure threshold signatures with short shares
Benoît Libert, Marc Joye, Moti Yung
Theor. Comput. Sci.1
2016 A New Framework for Privacy-Preserving Aggregation of Time-Series Data
abstract
Aggregator-oblivious encryption is a useful notion put forward by Shi et al. in 2011 that allows an untrusted aggregator to periodically compute an aggregate value over encrypted data contributed by a set of users. Such encryption schemes find numerous applications, particularly in the context of privacy-preserving smart metering. This article presents a general framework for constructing privacy-preserving aggregator-oblivious encryption schemes using a variant of Cramer-Shoup’s paradigm of smooth projective hashing. This abstraction leads to new schemes based on a variety of complexity assumptions. It also improves upon existing constructions, providing schemes with shorter ciphertexts and better encryption times.
Fabrice Benhamouda, Marc Joye, Benoît Libert
ACM Trans. Inf. Syst. Secur.3
2015 Compactly Hiding Linear Spans - Tightly Secure Constant-Size Simulation-Sound QA-NIZK Proofs and Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
ASIACRYPT (1)1
2015 Short Group Signatures via Structure-Preserving Signatures: Standard Model Security from Simple Assumptions
Benoît Libert, Thomas Peters, Moti Yung
CRYPTO (2)1
2015 Linearly homomorphic structure-preserving signatures and their applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
Des. Codes Cryptogr.1
2014 Concise Multi-challenge CCA-Secure Encryption and Signatures with Almost Tight Security
Benoît Libert, Marc Joye, Moti Yung, Thomas Peters
ASIACRYPT (2)1
2014 Group Signatures with Message-Dependent Opening in the Standard Model
Benoît Libert, Marc Joye
CT-RSA1
2014 Non-malleability from Malleability: Simulation-Sound Quasi-Adaptive NIZK Proofs and CCA2-Secure Encryption from Homomorphic Signatures
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
EUROCRYPT1
2014 Born and raised distributively: fully distributed non-interactive adaptively-secure threshold signatures with short shares
abstract
Threshold cryptography is a fundamental distributed computational paradigm for enhancing the availability and the security of cryptographic public-key schemes. It does it by dividing private keys into n shares handed out to distinct servers. In threshold signature schemes, a set of at least t+1 ≤ n servers is needed to produce a valid digital signature. Availability is assured by the fact that any subset of t+1 servers can produce a signature when authorized. At the same time, the scheme should remain robust (in the fault tolerance sense) and unforgeable (cryptographically) against up to t corrupted servers; i.e., it adds quorum control to traditional cryptographic services and introduces redundancy. Originally, most practical threshold signatures have a number of demerits: They have been analyzed in a static corruption model (where the set of corrupted servers is fixed at the very beginning of the attack), they require interaction, they assume a trusted dealer in the key generation phase (so that the system is not fully distributed), or they suffer from certain overheads in terms of storage (large share sizes). In this paper, we construct practical fully distributed (the private key is born distributed), non-interactive schemes --- where the servers can compute their partial signatures without communication with other servers--- with adaptive security (i.e., the adversary corrupts servers dynamically based on its full view of the history of the system). Our schemes are very efficient in terms of computation, communication, and scalable storage (with private key shares of size O(1), where certain solutions incur O(n) storage costs at each server). Unlike other adaptively secure schemes, our schemes are erasure-free (reliable erasure is a hard to assure and hard to administer property in actual systems).
Benoît Libert, Marc Joye, Moti Yung
PODC1
2013 Lattice-Based Group Signatures with Logarithmic Signature Size
Fabien Laguillaumie, Adeline Roux-Langlois, Benoît Libert, Damien Stehlé
ASIACRYPT (2)3
2013 Linearly Homomorphic Structure-Preserving Signatures and Their Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
CRYPTO (2)1
2013 Efficient Cryptosystems from 2 k -th Power Residue Symbols
Marc Joye, Benoît Libert
EUROCRYPT2
2013 Adaptively secure non-interactive threshold cryptosystems
Benoît Libert, Moti Yung
Theor. Comput. Sci.1
2012 Computing on Authenticated Data: New Privacy Definitions and Constructions
Nuttapong Attrapadung, Benoît Libert, Thomas Peters
ASIACRYPT2
2012 Group Signatures with Almost-for-Free Revocation
Benoît Libert, Thomas Peters, Moti Yung
CRYPTO1
2012 Short Attribute-Based Signatures for Threshold Predicates
Javier Herranz, Fabien Laguillaumie, Benoît Libert, Carla Ràfols
CT-RSA3
2012 Scalable Group Signatures with Revocation
Benoît Libert, Thomas Peters, Moti Yung
EUROCRYPT1
2012 Divisible E-Cash in the Standard Model
Malika Izabachène, Benoît Libert
Pairing2
2012 Non-interactive CCA-Secure Threshold Cryptosystems with Adaptive Security: New Framework and Constructions
Benoît Libert, Moti Yung
TCC1
2012 Attribute-based encryption schemes with constant-size ciphertexts
Nuttapong Attrapadung, Javier Herranz, Fabien Laguillaumie, Benoît Libert, Elie de Panafieu, Carla Ràfols
Theor. Comput. Sci.4
2011 Non-interactive and Re-usable Universally Composable String Commitments with Adaptive Security
Marc Fischlin, Benoît Libert, Mark Manulis
ASIACRYPT2
2011 Lossy Encryption: Constructions from General Assumptions and Efficient Selective Opening Chosen Ciphertext Security
Brett Hemenway, Benoît Libert, Rafail Ostrovsky, Damien Vergnaud
ASIACRYPT2
2011 Adaptively Secure Forward-Secure Non-interactive Threshold Cryptosystems
Benoît Libert, Moti Yung
Inscrypt1
2011 Adaptively Secure Non-interactive Threshold Cryptosystems
Benoît Libert, Moti Yung
ICALP (2)1
2011 Block-Wise P-Signatures and Non-interactive Anonymous Credentials with Efficient Attributes
Malika Izabachène, Benoît Libert, Damien Vergnaud
IMACC2
2011 Efficient traceable signatures in the standard model
Benoît Libert, Moti Yung
Theor. Comput. Sci.1
2011 Unidirectional Chosen-Ciphertext Secure Proxy Re-Encryption
abstract
In 1998, Blaze, Bleumer and Strauss introduced a cryptographic primitive called proxy re-encryption in which a proxy can transform-without seeing the plaintext-a ciphertext encrypted under one key into an encryption of the same plaintext under another key. The concept has recently drawn renewed interest. Notably, Canetti and Hohenberger showed how to properly define (and realize) chosen-ciphertext security for the primitive. Their system is bidirectional as the translation key allows converting ciphertexts in both directions. This paper presents the first unidirectional proxy re-encryption schemes with chosen-ciphertext security in the standard model (i.e., without the random oracle idealization). The first system provably fits a unidirectional extension of the Canetti-Hohenberger security model. As a second contribution, the paper considers a more realistic adversarial model where attackers may choose dishonest users' keys on their own. It is shown how to modify the first scheme to achieve security in the latter scenario. At a moderate expense, the resulting system provides additional useful properties such as non-interactive temporary delegations. Both constructions are efficient and rely on mild complexity assumptions in bilinear groups. Like the Canetti-Hohenberger scheme, they meet a relaxed flavor of chosen-ciphertext security introduced by Canetti, Krawczyk and Nielsen.
Benoît Libert, Damien Vergnaud
IEEE Trans. Inf. Theory1
2011 Towards Practical Black-Box Accountable Authority IBE: Weak Black-Box Traceability With Short Ciphertexts and Private Keys
abstract
At Crypto'07, Goyal introduced the concept of Accountable Authority Identity-Based Encryption (A-IBE) as a convenient tool to reduce the amount of trust in authorities in Identity-Based Encryption. In this model, if the Private Key Generator (PKG) maliciously re-distributes users' decryption keys, it runs the risk of being caught and prosecuted. Goyal proposed two constructions: the first one is efficient but can only trace well-formed decryption keys to their source; the second one allows tracing obfuscated decryption boxes in a model (called weak black-box model) where cheating authorities have no decryption oracle. The latter scheme is unfortunately far less efficient in terms of decryption cost and ciphertext size. The contribution of this paper is to describe a new construction that combines the efficiency of Goyal's first proposal with a simple weak black-box tracing mechanism. The proposed scheme is the first A-IBE that meets all security properties (although traceability is only guaranteed in the weak black-box model) in the adaptive-ID sense.
Benoît Libert, Damien Vergnaud
IEEE Trans. Inf. Theory1
2010 Dynamic fully forward-secure group signatures
abstract
Enhancing user privacy while allowing the use of digital credentials in network-wide applications is a very active area. Group signatures are primary privacy-preserving credentials that enable both, non-repudiation and abuser-tracing.When embedding cryptographic tools in actual computing systems, it is important to ensure physical layer protection to cryptographic keys. A simple risk analysis shows that taking advantage of system (i.e., hardware, software, network) vulnerabilities is usually much easier than cryptanalyzing the cryptographic primitives themselves. Forward-secure cryptosystems, in turn, are one of the suggested protective measures, where private keys periodically evolve in such a way that, if a break-in occurs, past uses of those keys in earlier periods are protected.At CCS 2001, Song argued why key exposures may cause even more important concerns in the context of group signatures (namely, under the mask of anonymity within a group of other key holders). She then gave two examples of forward-secure group signatures, and argued their ad hoc properties based on the state of understanding of group security properties at that time (proper security models had not been formalized yet). These implementations are fruitful initial efforts, but still suffer from certain imperfections. In the first scheme for instance, forward security is only guaranteed to signers as long as the group manager's private key is safe. Another scheme recently described by Nakanishi et al. for static groups also fails to maintain security when the group manager is compromised.In this paper, we reconsider the subject and first formalize the notion of fully forward-secure group signature (FS-GS) in dynamic groups. We carefully define the correctness and security properties that such a scheme ought to have. We then give a realization of the primitive with quite attractive features: constant-size signatures, constant cost of signing/verifying, and at most polylog complexity of other metrics. The scheme is further proven secure in the standard model (no random oracle idealization is used).
Benoît Libert, Moti Yung
AsiaCCS1
2010 Efficient Completely Non-malleable Public Key Encryption
Benoît Libert, Moti Yung
ICALP (1)1
2010 Concise Mercurial Vector Commitments and Independent Zero-Knowledge Sets with Short Proofs
Benoît Libert, Moti Yung
TCC1
2010 Key Evolution Systems in Untrusted Update Environments
abstract
Forward-Secure Signatures (FSS) prevent forgeries for past time periods when an attacker obtains full access to the signer’s storage by evolving the private key in a one-way fashion. To simplify the integration of these primitives into standard security architectures, Boyen et al. [2006] recently introduced the concept of forward-secure signatures with untrusted updates where private keys are additionally protected by a second factor (derived from a password). Key updates can be made on encrypted version of signing keys so that passwords only come into play for signing messages and not at update time (since update is not user-driven). The scheme put forth by Boyen et al. relies on bilinear maps and does not require the random oracle. They also suggest the integration of untrusted updates in the Bellare-Miner forward-secure signature. Their work left open the problem of endowing other existing FSS systems with the same second factor protection, and a natural second question is whether the method can apply to other key-evolving paradigms. This article solves the first problem by showing an efficient generic construction that does not require to set a bound on the number of time periods at key generation. The article then extends the unprotected update model to other key-evolving primitives such as forward-secure public key encryption and key-insulated cryptosystems.
Benoît Libert, Jean-Jacques Quisquater, Moti Yung
ACM Trans. Inf. Syst. Secur.1
2009 Group Encryption: Non-interactive Realization in the Standard Model
Julien Cathalo, Benoît Libert, Moti Yung
ASIACRYPT2
2009 Group Signatures with Verifier-Local Revocation and Backward Unlinkability in the Standard Model
Benoît Libert, Damien Vergnaud
CANS1
2009 Adaptive-ID Secure Revocable Identity-Based Encryption
Benoît Libert, Damien Vergnaud
CT-RSA1
2009 Efficient Traceable Signatures in the Standard Model
Benoît Libert, Moti Yung
Pairing1
2008 Multi-use unidirectional proxy re-signatures
abstract
In 1998, Blaze, Bleumer, and Strauss suggested a cryptographic primitive termed proxy re-signature in which a proxy transforms a signature computed under Alice's secret key into one from Bob on the same message. The proxy is only semi-trusted in that it cannot learn any signing key or sign arbitrary messages on behalf of Alice or Bob. At CCS 2005, Ateniese and Hohenberger revisited this primitive by providing appropriate security definitions and efficient constructions in the random oracle model. Nonetheless, they left open the problem of constructing a multi-use unidirectional scheme where the proxy is only able to translate in one direction and signatures can be re-translated several times. This paper provides the first steps towards efficiently solving this problem, suggested for the first time 10 years ago, and presents the first multi-hop unidirectional proxy re-signature schemes. Although our proposals feature a linear signature size in the number of translations, they are the first multi-use realizations of the primitive that satisfy the requirements of the Ateniese-Hohenberger security model. The first scheme is secure in the random oracle model. Using the same underlying idea, it readily extends into a secure construction in the standard model (i.e. the security proof of which avoids resorting to the random oracle idealization). Both schemes are computationally efficient but require newly defined Diffie-Hellman-like assumptions in bilinear groups.
Benoît Libert, Damien Vergnaud
CCS1
2008 Key Evolution Systems in Untrusted Update Environments
Benoît Libert, Jean-Jacques Quisquater, Moti Yung
Inscrypt1
2008 Tracing Malicious Proxies in Proxy Re-encryption
Benoît Libert, Damien Vergnaud
Pairing1
2007 Forward-secure signatures in untrusted update environments: efficient and generic constructions
abstract
Forward-secure signatures (FSS) prevent forgeries for past time periods when an attacker obtains full access to the signer’s storage. To simplify the integration of these primitives into standard security architectures, Boyen, Shacham, Shen and Waters recently introduced the concept of forwardsecure signatures with untrusted updates where private keys are additionally protected by a second factor (derived from a password). Key updates can be made on encrypted version of signing keys so that passwords only come into play for signing messages. The scheme put forth by Boyen et al. relies on bilinear maps and does not require the random oracle. The latter work also suggested the integration of untrusted updates in the Bellare-Miner forward-secure signature and left open the problem of endowing other existing FSS systems with the same second factor protection. This paper solves this problem by showing how to adapt the very efficient generic construction of Malkin, Micciancio and Miner (MMM) to untrusted update environments. More precisely, our modified construction- which does not use random oracles either- obtains a forward-secure signature with untrusted updates from any 2-party multi-signature in the plain public key model. In combination with Bellare and Neven’s multi-signatures, our generic method yields implementations based on standard assumptions such as RSA, factoring or the hardness of computing discrete logarithms. Like the original MMM scheme, it does not require to set a bound on the number of time periods at key generation.
Benoît Libert, Jean-Jacques Quisquater, Moti Yung
CCS1
2007 Practical Time Capsule Signatures in the Standard Model from Bilinear Maps
Benoît Libert, Jean-Jacques Quisquater
Pairing1
2006 Efficient Intrusion-Resilient Signatures Without Random Oracles
Benoît Libert, Jean-Jacques Quisquater, Moti Yung
Inscrypt1
2005 Identity Based Encryption Without Redundancy
Benoît Libert, Jean-Jacques Quisquater
ACNS1
2005 Efficient and Provably-Secure Identity-Based Signatures and Signcryption from Bilinear Maps
Paulo S. L. M. Barreto, Benoît Libert, Noel McCullagh, Jean-Jacques Quisquater
ASIACRYPT2
2005 Efficient and Non-interactive Timed-Release Encryption
Julien Cathalo, Benoît Libert, Jean-Jacques Quisquater
ICICS2
2004 Identity Based Undeniable Signatures
Benoît Libert, Jean-Jacques Quisquater
CT-RSA1
2004 Cryptanalysis of a Verifiably Committed Signature Scheme Based on GPS and RSA
Julien Cathalo, Benoît Libert, Jean-Jacques Quisquater
ISC2
2003 A new identity based signcryption scheme from pairings
abstract
We present a new identity based scheme using pairings over elliptic curves. It combines the functionalities of signature and encryption and is provably secure in the random oracle model. We compare it with J. Malone-Lee's scheme from the points of view of security and efficiency. We give a proof of semantic security under the decisional bilinear Diffie-Hellman assumption for this new scheme.
Benoît Libert, Jean-Jacques Quisquater
ITW1
2003 Efficient revocation and threshold pairing based cryptosystems
abstract
Boneh, Ding, Tsudik and Wong recently proposed a way for obtaining fast revocation of RSA keys. Their method consists in using security mediators that keep a piece of each user's private key in such a way that every decrytion or signature operation requires the help of the mediator for the user. Revocation is achieved by instructing the mediator to stop helping the user to sign or decrypt messages. This security architecture, called SEM, gave rise to an identity based mediated RSA scheme (IB-mRSA) that combines the advantages of fast revocation and identity based public keys. We show that, in opposition to what was stated in [9], this revocation method can be applied to several existing public key encryption and signature schemes (all those for which a secure practical threshold adaptation exists) including the Boneh-Franklin identity based encryption scheme and a pairing based digital signature schemes. We first describe a threshold adaptation of the Boneh-Franklin identity based encryption scheme and, then, we compare the mediated versions of these schemes with IB-mRSA from security and efficiency points of view.
Benoît Libert, Jean-Jacques Quisquater
PODC1