VLDB 2026 Research / reviewers in the wild / expert
Benoît Libert
dblp:62/1759
· DBLP profile ↗
85ranked-venue papers
62as first author
15since 2021 · last 2026
0000-0002-6914-1616ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 49 first-author · 14 since 2021Theory of computation · 15 · 14 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fully Asymmetric Anamorphic Homomorphic Encryption from LWE
Amit Deo, Benoît Libert |
EUROCRYPT (5) | 2 |
| 2025 | On Proofs of Plaintext Knowledge for the Joye-Libert Encryption Scheme
Benoît Libert, Thomas Peters |
ACNS (2) | 1 |
| 2025 | Anamorphic Signatures With Dictator and Recipient Unforgeability for Long Messages
Amit Deo, Benoît Libert |
ASIACRYPT (6) | 2 |
| 2025 | Fast Homomorphic Evaluation of LWR-based PRFsabstractCertain applications of fully homomorphic encryption (such as transciphering, universal thresholdizers, and PIR) require randomness while operating over encrypted data. This randomness has to be obliviously generated in the encrypted domain and remain encrypted throughout the computation. Moreover, it should be guaranteed that independent-looking random coins can be obliviously generated for different computations. Amit Deo, Marc Joye, Benoît Libert, Benjamin R. Curtis, Mayeul de Bellabre |
CCS | 3 |
| 2025 | Simplified Adaptively Secure Threshold BLS Signatures
Benoît Libert |
CT-RSA | 1 |
| 2025 | Leveraging Small Message Spaces for CCA1 Security in Additively Homomorphic and BGN-Type Encryption
Benoît Libert |
EUROCRYPT (2) | 1 |
| 2024 | Non-malleable Subvector Commitments
Benoît Libert |
ASIACRYPT (3) | 1 |
| 2023 | Zero-Knowledge Arguments for Lattice-Based Accumulators: Logarithmic-Size Ring Signatures and Group Signatures Without TrapdoorsabstractAbstract An accumulator is a function that hashes a set of inputs into a short, constant-size string while preserving the ability to efficiently prove the inclusion of a specific input element in the hashed set. It has proved useful in the design of numerous privacy-enhancing protocols, in order to handle revocation or simply prove set membership. In the lattice setting, currently known instantiations of the primitive are based on Merkle trees, which do not interact well with zero-knowledge proofs. In order to efficiently prove the membership of some element in a zero-knowledge manner, the prover has to demonstrate knowledge of a hash chain without revealing it, which is not known to be efficiently possible under well-studied hardness assumptions. In this paper, we provide an efficient method of proving such statements using involved extensions of Stern’s protocol. Under the Small Integer Solution assumption, we provide zero-knowledge arguments showing possession of a hash chain. As an application, we describe new lattice-based group and ring signatures in the random oracle model. In particular, we obtain: (i) the first lattice-based ring signatures with logarithmic size in the cardinality of the ring and (ii) the first lattice-based group signature that does not require any GPV trapdoor and thus allows for a much more efficient choice of parameters. Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang |
J. Cryptol. | 1 |
| 2022 | PointProofs, Revisited
Benoît Libert, Alain Passelègue, Mahshid Riahinia |
ASIACRYPT (4) | 1 |
| 2022 | Updatable Public Key Encryption from DCR: Efficient Constructions With Stronger SecurityabstractForward-secure encryption (FS-PKE) is a key-evolving public-key paradigm that preserves the confidentiality of past encryptions in case of key exposure. Updatable public-key encryption (UPKE) is a natural relaxation of FS-PKE, introduced by Jost et al. (Eurocrypt'19), which is motivated by applications to secure messaging. In UPKE, key updates can be triggered by any sender -- via special update ciphertexts -- willing to enforce the forward secrecy of its encrypted messages. So far, the only truly efficient UPKE candidates (which rely on the random oracle idealization) only provide rather weak security guarantees against passive adversaries as they are malleable. Also, they offer no protection against malicious senders willing to hinder the decryption capability of honest users. A recent work of Dodis et al. (TCC'21) described UPKE systems in the standard model that also hedge against maliciously generated update messages in the chosen-ciphertext setting (where adversaries are equipped with a decryption oracle). While important feasibility results, their constructions lag behind random-oracle candidates in terms of efficiency. In this paper, we first provide a drastically more efficient UPKE realization in the standard model using Paillier's Composite Residuosity (DCR) assumption. In the random oracle model, we then extend our initial scheme so as to achieve chosen-ciphertext security, even in a model that accounts for maliciously generated update ciphertexts. Under the DCR and Strong RSA assumptions, we thus obtain the first practical UPKE systems that satisfy the strongest security notions put forth by Dodis et al. Calvin Abou Haidar, Benoît Libert, Alain Passelègue |
CCS | 2 |
| 2022 | One-Shot Fiat-Shamir-Based NIZK Arguments of Composite Residuosity and Logarithmic-Size Ring Signatures in the Standard Model
Benoît Libert, Khoa Nguyen 0002, Thomas Peters, Moti Yung |
EUROCRYPT (2) | 1 |
| 2021 | Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing Scheme
Benoît Libert, Khoa Nguyen 0002, Thomas Peters, Moti Yung |
EUROCRYPT (3) | 1 |
| 2021 | SO-CCA secure PKE from pairing based all-but-many lossy trapdoor functions
Dingding Jia, Benoît Libert |
Des. Codes Cryptogr. | 2 |
| 2021 | Adaptively Secure Distributed PRFs from sf LWE
Benoît Libert, Damien Stehlé, Radu Titiu |
J. Cryptol. | 1 |
| 2021 | Adaptive oblivious transfer with access control from lattice assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang |
Theor. Comput. Sci. | 1 |
| 2020 | Lattice-Based E-Cash, Revisited
Amit Deo, Benoît Libert, Khoa Nguyen 0002, Olivier Sanders |
ASIACRYPT (2) | 2 |
| 2020 | Simulation-Sound Arguments for LWE and Applications to KDM-CCA2 Security
Benoît Libert, Khoa Nguyen 0002, Alain Passelègue, Radu Titiu |
ASIACRYPT (1) | 1 |
| 2020 | New Constructions of Statistical NIZKs: Dual-Mode DV-NIZKs and More
Benoît Libert, Alain Passelègue, Hoeteck Wee, David J. Wu 0001 |
EUROCRYPT (3) | 1 |
| 2020 | Adaptively Secure Non-interactive CCA-Secure Threshold Cryptosystems: Generic Framework and Constructions
Benoît Libert, Moti Yung |
J. Cryptol. | 1 |
| 2019 | Multi-Client Functional Encryption for Linear Functions in the Standard Model from LWE
Benoît Libert, Radu Titiu |
ASIACRYPT (3) | 1 |
| 2019 | Zero-knowledge arguments for matrix-vector relations and lattice-based group encryption
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang |
Theor. Comput. Sci. | 1 |
| 2018 | Lattice-Based Zero-Knowledge Arguments for Integer Relations
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang |
CRYPTO (2) | 1 |
| 2018 | Logarithmic-Size Ring Signatures with Tight Security from the DDH Assumption
Benoît Libert, Thomas Peters, Chen Qian 0002 |
ESORICS (2) | 1 |
| 2018 | Adaptively Secure Distributed PRFs from \mathsf LWE
Benoît Libert, Damien Stehlé, Radu Titiu |
TCC (2) | 1 |
| 2017 | Adaptive Oblivious Transfer with Access Control from Lattice Assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang |
ASIACRYPT (1) | 1 |
| 2017 | Zero-Knowledge Arguments for Lattice-Based PRFs and Applications to E-Cash
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang |
ASIACRYPT (3) | 1 |
| 2017 | All-But-Many Lossy Trapdoor Functions and Selective Opening Chosen-Ciphertext Security from LWE
Benoît Libert, Amin Sakzad, Damien Stehlé, Ron Steinfeld |
CRYPTO (3) | 1 |
| 2017 | Encoding-Free ElGamal-Type Encryption Schemes on Elliptic Curves
Marc Joye, Benoît Libert |
CT-RSA | 2 |
| 2017 | Efficient Cryptosystems From 2k-th Power Residue Symbols
Fabrice Benhamouda, Javier Herranz, Marc Joye, Benoît Libert |
J. Cryptol. | 4 |
| 2016 | A Lattice-Based Group Signature Scheme with Message-Dependent Opening
Benoît Libert, Fabrice Mouhartem, Khoa Nguyen 0002 |
ACNS | 1 |
| 2016 | Zero-Knowledge Arguments for Matrix-Vector Relations and Lattice-Based Group Encryption
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang |
ASIACRYPT (2) | 1 |
| 2016 | Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions
Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen 0002, Huaxiong Wang |
ASIACRYPT (2) | 1 |
| 2016 | Practical "Signatures with Efficient Protocols" from Simple AssumptionsabstractDigital signatures are perhaps the most important base for authentication and trust relationships in large scale systems. More specifically, various applications of signatures provide privacy and anonymity preserving mechanisms and protocols, and these, in turn, are becoming critical (due to the recently recognized need to protect individuals according to national rules and regulations). A specific type of signatures called "signatures with efficient protocols", as introduced by Camenisch and Lysyanskaya (CL), efficiently accommodates various basic protocols and extensions like zero-knowledge proofs, signing committed messages, or re-randomizability. These are, in fact, typical operations associated with signatures used in typical anonymity and privacy-preserving scenarios. Benoît Libert, Fabrice Mouhartem, Thomas Peters, Moti Yung |
AsiaCCS | 1 |
| 2016 | Fully Secure Functional Encryption for Inner Products, from Standard Assumptions
Shweta Agrawal 0001, Benoît Libert, Damien Stehlé |
CRYPTO (3) | 2 |
| 2016 | Zero-Knowledge Arguments for Lattice-Based Accumulators: Logarithmic-Size Ring Signatures and Group Signatures Without Trapdoors
Benoît Libert, San Ling, Khoa Nguyen 0002, Huaxiong Wang |
EUROCRYPT (2) | 1 |
| 2016 | Functional Commitment Schemes: From Polynomial Commitments to Pairing-Based Accumulators from Simple AssumptionsabstractWe formalize a cryptographic primitive called functional commitment (FC) which can be viewed as a generalization of vector commitments (VCs), polynomial commitments and many other special kinds of commitment schemes. A non-interactive functional commitment allows committing to a message in such a way that the committer has the flexibility of only revealing a function of the committed message during the opening phase. We provide constructions for the functionality of linear functions, where messages consist of vectors over some domain and commitments can later be opened to a specific linear function of the vector coordinates. An opening for a function thus generates a witness for the fact that the function indeed evaluates to a given value for the committed message. One security requirement is called function binding and requires that no adversary be able to open a commitment to two different evaluations for the same function. We propose a construction of functional commitment for linear functions based on constantsize assumptions in composite order groups endowed with a bilinear map. The construction has commitments and openings of constant size (i.e., independent of n or function description) and is perfectly hiding - the underlying message is information theoretically hidden. Our security proofs build on the Déjà Q framework of Chase and Meiklejohn (Eurocrypt 2014) and its extension by Wee (TCC 2016) to encryption primitives, thus relying on constant-size subgroup decisional assumptions. We show that FC for linear functions are sufficiently powerful to solve four open problems. They, first, imply polynomial commitments, and, then, give cryptographic accumulators (i.e., an algebraic hash function which makes it possible to efficiently prove that some input belongs to a hashed set). In particular, specializing our FC construction leads to the first pairing-based polynomial commitments and accumulators for large universes known to achieve security under simple assumptions. We also substantially extend our pairing-based accumulator to handle subset queries which requires a non-trivial extension of the Déjà Q framework. Benoît Libert, Somindu C. Ramanna, Moti Yung |
ICALP | 1 |
| 2016 | Born and raised distributively: Fully distributed non-interactive adaptively-secure threshold signatures with short shares
Benoît Libert, Marc Joye, Moti Yung |
Theor. Comput. Sci. | 1 |
| 2016 | A New Framework for Privacy-Preserving Aggregation of Time-Series DataabstractAggregator-oblivious encryption is a useful notion put forward by Shi et al. in 2011 that allows an untrusted aggregator to periodically compute an aggregate value over encrypted data contributed by a set of users. Such encryption schemes find numerous applications, particularly in the context of privacy-preserving smart metering. This article presents a general framework for constructing privacy-preserving aggregator-oblivious encryption schemes using a variant of Cramer-Shoup’s paradigm of smooth projective hashing. This abstraction leads to new schemes based on a variety of complexity assumptions. It also improves upon existing constructions, providing schemes with shorter ciphertexts and better encryption times. Fabrice Benhamouda, Marc Joye, Benoît Libert |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2015 | Compactly Hiding Linear Spans - Tightly Secure Constant-Size Simulation-Sound QA-NIZK Proofs and Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung |
ASIACRYPT (1) | 1 |
| 2015 | Short Group Signatures via Structure-Preserving Signatures: Standard Model Security from Simple Assumptions
Benoît Libert, Thomas Peters, Moti Yung |
CRYPTO (2) | 1 |
| 2015 | Linearly homomorphic structure-preserving signatures and their applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung |
Des. Codes Cryptogr. | 1 |
| 2014 | Concise Multi-challenge CCA-Secure Encryption and Signatures with Almost Tight Security
Benoît Libert, Marc Joye, Moti Yung, Thomas Peters |
ASIACRYPT (2) | 1 |
| 2014 | Group Signatures with Message-Dependent Opening in the Standard Model
Benoît Libert, Marc Joye |
CT-RSA | 1 |
| 2014 | Non-malleability from Malleability: Simulation-Sound Quasi-Adaptive NIZK Proofs and CCA2-Secure Encryption from Homomorphic Signatures
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung |
EUROCRYPT | 1 |
| 2014 | Born and raised distributively: fully distributed non-interactive adaptively-secure threshold signatures with short sharesabstractThreshold cryptography is a fundamental distributed computational paradigm for enhancing the availability and the security of cryptographic public-key schemes. It does it by dividing private keys into n shares handed out to distinct servers. In threshold signature schemes, a set of at least t+1 ≤ n servers is needed to produce a valid digital signature. Availability is assured by the fact that any subset of t+1 servers can produce a signature when authorized. At the same time, the scheme should remain robust (in the fault tolerance sense) and unforgeable (cryptographically) against up to t corrupted servers; i.e., it adds quorum control to traditional cryptographic services and introduces redundancy. Originally, most practical threshold signatures have a number of demerits: They have been analyzed in a static corruption model (where the set of corrupted servers is fixed at the very beginning of the attack), they require interaction, they assume a trusted dealer in the key generation phase (so that the system is not fully distributed), or they suffer from certain overheads in terms of storage (large share sizes). In this paper, we construct practical fully distributed (the private key is born distributed), non-interactive schemes --- where the servers can compute their partial signatures without communication with other servers--- with adaptive security (i.e., the adversary corrupts servers dynamically based on its full view of the history of the system). Our schemes are very efficient in terms of computation, communication, and scalable storage (with private key shares of size O(1), where certain solutions incur O(n) storage costs at each server). Unlike other adaptively secure schemes, our schemes are erasure-free (reliable erasure is a hard to assure and hard to administer property in actual systems). Benoît Libert, Marc Joye, Moti Yung |
PODC | 1 |
| 2013 | Lattice-Based Group Signatures with Logarithmic Signature Size
Fabien Laguillaumie, Adeline Roux-Langlois, Benoît Libert, Damien Stehlé |
ASIACRYPT (2) | 3 |
| 2013 | Linearly Homomorphic Structure-Preserving Signatures and Their Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung |
CRYPTO (2) | 1 |
| 2013 | Efficient Cryptosystems from 2 k -th Power Residue Symbols
Marc Joye, Benoît Libert |
EUROCRYPT | 2 |
| 2013 | Adaptively secure non-interactive threshold cryptosystems
Benoît Libert, Moti Yung |
Theor. Comput. Sci. | 1 |
| 2012 | Computing on Authenticated Data: New Privacy Definitions and Constructions
Nuttapong Attrapadung, Benoît Libert, Thomas Peters |
ASIACRYPT | 2 |
| 2012 | Group Signatures with Almost-for-Free Revocation
Benoît Libert, Thomas Peters, Moti Yung |
CRYPTO | 1 |
| 2012 | Short Attribute-Based Signatures for Threshold Predicates
Javier Herranz, Fabien Laguillaumie, Benoît Libert, Carla Ràfols |
CT-RSA | 3 |
| 2012 | Scalable Group Signatures with Revocation
Benoît Libert, Thomas Peters, Moti Yung |
EUROCRYPT | 1 |
| 2012 | Divisible E-Cash in the Standard Model
Malika Izabachène, Benoît Libert |
Pairing | 2 |
| 2012 | Non-interactive CCA-Secure Threshold Cryptosystems with Adaptive Security: New Framework and Constructions
Benoît Libert, Moti Yung |
TCC | 1 |
| 2012 | Attribute-based encryption schemes with constant-size ciphertexts
Nuttapong Attrapadung, Javier Herranz, Fabien Laguillaumie, Benoît Libert, Elie de Panafieu, Carla Ràfols |
Theor. Comput. Sci. | 4 |
| 2011 | Non-interactive and Re-usable Universally Composable String Commitments with Adaptive Security
Marc Fischlin, Benoît Libert, Mark Manulis |
ASIACRYPT | 2 |
| 2011 | Lossy Encryption: Constructions from General Assumptions and Efficient Selective Opening Chosen Ciphertext Security
Brett Hemenway, Benoît Libert, Rafail Ostrovsky, Damien Vergnaud |
ASIACRYPT | 2 |
| 2011 | Adaptively Secure Forward-Secure Non-interactive Threshold Cryptosystems
Benoît Libert, Moti Yung |
Inscrypt | 1 |
| 2011 | Adaptively Secure Non-interactive Threshold Cryptosystems
Benoît Libert, Moti Yung |
ICALP (2) | 1 |
| 2011 | Block-Wise P-Signatures and Non-interactive Anonymous Credentials with Efficient Attributes
Malika Izabachène, Benoît Libert, Damien Vergnaud |
IMACC | 2 |
| 2011 | Efficient traceable signatures in the standard model
Benoît Libert, Moti Yung |
Theor. Comput. Sci. | 1 |
| 2011 | Unidirectional Chosen-Ciphertext Secure Proxy Re-EncryptionabstractIn 1998, Blaze, Bleumer and Strauss introduced a cryptographic primitive called proxy re-encryption in which a proxy can transform-without seeing the plaintext-a ciphertext encrypted under one key into an encryption of the same plaintext under another key. The concept has recently drawn renewed interest. Notably, Canetti and Hohenberger showed how to properly define (and realize) chosen-ciphertext security for the primitive. Their system is bidirectional as the translation key allows converting ciphertexts in both directions. This paper presents the first unidirectional proxy re-encryption schemes with chosen-ciphertext security in the standard model (i.e., without the random oracle idealization). The first system provably fits a unidirectional extension of the Canetti-Hohenberger security model. As a second contribution, the paper considers a more realistic adversarial model where attackers may choose dishonest users' keys on their own. It is shown how to modify the first scheme to achieve security in the latter scenario. At a moderate expense, the resulting system provides additional useful properties such as non-interactive temporary delegations. Both constructions are efficient and rely on mild complexity assumptions in bilinear groups. Like the Canetti-Hohenberger scheme, they meet a relaxed flavor of chosen-ciphertext security introduced by Canetti, Krawczyk and Nielsen. Benoît Libert, Damien Vergnaud |
IEEE Trans. Inf. Theory | 1 |
| 2011 | Towards Practical Black-Box Accountable Authority IBE: Weak Black-Box Traceability With Short Ciphertexts and Private KeysabstractAt Crypto'07, Goyal introduced the concept of Accountable Authority Identity-Based Encryption (A-IBE) as a convenient tool to reduce the amount of trust in authorities in Identity-Based Encryption. In this model, if the Private Key Generator (PKG) maliciously re-distributes users' decryption keys, it runs the risk of being caught and prosecuted. Goyal proposed two constructions: the first one is efficient but can only trace well-formed decryption keys to their source; the second one allows tracing obfuscated decryption boxes in a model (called weak black-box model) where cheating authorities have no decryption oracle. The latter scheme is unfortunately far less efficient in terms of decryption cost and ciphertext size. The contribution of this paper is to describe a new construction that combines the efficiency of Goyal's first proposal with a simple weak black-box tracing mechanism. The proposed scheme is the first A-IBE that meets all security properties (although traceability is only guaranteed in the weak black-box model) in the adaptive-ID sense. Benoît Libert, Damien Vergnaud |
IEEE Trans. Inf. Theory | 1 |
| 2010 | Dynamic fully forward-secure group signaturesabstractEnhancing user privacy while allowing the use of digital credentials in network-wide applications is a very active area. Group signatures are primary privacy-preserving credentials that enable both, non-repudiation and abuser-tracing.When embedding cryptographic tools in actual computing systems, it is important to ensure physical layer protection to cryptographic keys. A simple risk analysis shows that taking advantage of system (i.e., hardware, software, network) vulnerabilities is usually much easier than cryptanalyzing the cryptographic primitives themselves. Forward-secure cryptosystems, in turn, are one of the suggested protective measures, where private keys periodically evolve in such a way that, if a break-in occurs, past uses of those keys in earlier periods are protected.At CCS 2001, Song argued why key exposures may cause even more important concerns in the context of group signatures (namely, under the mask of anonymity within a group of other key holders). She then gave two examples of forward-secure group signatures, and argued their ad hoc properties based on the state of understanding of group security properties at that time (proper security models had not been formalized yet). These implementations are fruitful initial efforts, but still suffer from certain imperfections. In the first scheme for instance, forward security is only guaranteed to signers as long as the group manager's private key is safe. Another scheme recently described by Nakanishi et al. for static groups also fails to maintain security when the group manager is compromised.In this paper, we reconsider the subject and first formalize the notion of fully forward-secure group signature (FS-GS) in dynamic groups. We carefully define the correctness and security properties that such a scheme ought to have. We then give a realization of the primitive with quite attractive features: constant-size signatures, constant cost of signing/verifying, and at most polylog complexity of other metrics. The scheme is further proven secure in the standard model (no random oracle idealization is used). Benoît Libert, Moti Yung |
AsiaCCS | 1 |
| 2010 | Efficient Completely Non-malleable Public Key Encryption
Benoît Libert, Moti Yung |
ICALP (1) | 1 |
| 2010 | Concise Mercurial Vector Commitments and Independent Zero-Knowledge Sets with Short Proofs
Benoît Libert, Moti Yung |
TCC | 1 |
| 2010 | Key Evolution Systems in Untrusted Update EnvironmentsabstractForward-Secure Signatures (FSS) prevent forgeries for past time periods when an attacker obtains full access to the signer’s storage by evolving the private key in a one-way fashion. To simplify the integration of these primitives into standard security architectures, Boyen et al. [2006] recently introduced the concept of forward-secure signatures with untrusted updates where private keys are additionally protected by a second factor (derived from a password). Key updates can be made on encrypted version of signing keys so that passwords only come into play for signing messages and not at update time (since update is not user-driven). The scheme put forth by Boyen et al. relies on bilinear maps and does not require the random oracle. They also suggest the integration of untrusted updates in the Bellare-Miner forward-secure signature. Their work left open the problem of endowing other existing FSS systems with the same second factor protection, and a natural second question is whether the method can apply to other key-evolving paradigms. This article solves the first problem by showing an efficient generic construction that does not require to set a bound on the number of time periods at key generation. The article then extends the unprotected update model to other key-evolving primitives such as forward-secure public key encryption and key-insulated cryptosystems. Benoît Libert, Jean-Jacques Quisquater, Moti Yung |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2009 | Group Encryption: Non-interactive Realization in the Standard Model
Julien Cathalo, Benoît Libert, Moti Yung |
ASIACRYPT | 2 |
| 2009 | Group Signatures with Verifier-Local Revocation and Backward Unlinkability in the Standard Model
Benoît Libert, Damien Vergnaud |
CANS | 1 |
| 2009 | Adaptive-ID Secure Revocable Identity-Based Encryption
Benoît Libert, Damien Vergnaud |
CT-RSA | 1 |
| 2009 | Efficient Traceable Signatures in the Standard Model
Benoît Libert, Moti Yung |
Pairing | 1 |
| 2008 | Multi-use unidirectional proxy re-signaturesabstractIn 1998, Blaze, Bleumer, and Strauss suggested a cryptographic primitive termed proxy re-signature in which a proxy transforms a signature computed under Alice's secret key into one from Bob on the same message. The proxy is only semi-trusted in that it cannot learn any signing key or sign arbitrary messages on behalf of Alice or Bob. At CCS 2005, Ateniese and Hohenberger revisited this primitive by providing appropriate security definitions and efficient constructions in the random oracle model. Nonetheless, they left open the problem of constructing a multi-use unidirectional scheme where the proxy is only able to translate in one direction and signatures can be re-translated several times. This paper provides the first steps towards efficiently solving this problem, suggested for the first time 10 years ago, and presents the first multi-hop unidirectional proxy re-signature schemes. Although our proposals feature a linear signature size in the number of translations, they are the first multi-use realizations of the primitive that satisfy the requirements of the Ateniese-Hohenberger security model. The first scheme is secure in the random oracle model. Using the same underlying idea, it readily extends into a secure construction in the standard model (i.e. the security proof of which avoids resorting to the random oracle idealization). Both schemes are computationally efficient but require newly defined Diffie-Hellman-like assumptions in bilinear groups. Benoît Libert, Damien Vergnaud |
CCS | 1 |
| 2008 | Key Evolution Systems in Untrusted Update Environments
Benoît Libert, Jean-Jacques Quisquater, Moti Yung |
Inscrypt | 1 |
| 2008 | Tracing Malicious Proxies in Proxy Re-encryption
Benoît Libert, Damien Vergnaud |
Pairing | 1 |
| 2007 | Forward-secure signatures in untrusted update environments: efficient and generic constructionsabstractForward-secure signatures (FSS) prevent forgeries for past time periods when an attacker obtains full access to the signer’s storage. To simplify the integration of these primitives into standard security architectures, Boyen, Shacham, Shen and Waters recently introduced the concept of forwardsecure signatures with untrusted updates where private keys are additionally protected by a second factor (derived from a password). Key updates can be made on encrypted version of signing keys so that passwords only come into play for signing messages. The scheme put forth by Boyen et al. relies on bilinear maps and does not require the random oracle. The latter work also suggested the integration of untrusted updates in the Bellare-Miner forward-secure signature and left open the problem of endowing other existing FSS systems with the same second factor protection. This paper solves this problem by showing how to adapt the very efficient generic construction of Malkin, Micciancio and Miner (MMM) to untrusted update environments. More precisely, our modified construction- which does not use random oracles either- obtains a forward-secure signature with untrusted updates from any 2-party multi-signature in the plain public key model. In combination with Bellare and Neven’s multi-signatures, our generic method yields implementations based on standard assumptions such as RSA, factoring or the hardness of computing discrete logarithms. Like the original MMM scheme, it does not require to set a bound on the number of time periods at key generation. Benoît Libert, Jean-Jacques Quisquater, Moti Yung |
CCS | 1 |
| 2007 | Practical Time Capsule Signatures in the Standard Model from Bilinear Maps
Benoît Libert, Jean-Jacques Quisquater |
Pairing | 1 |
| 2006 | Efficient Intrusion-Resilient Signatures Without Random Oracles
Benoît Libert, Jean-Jacques Quisquater, Moti Yung |
Inscrypt | 1 |
| 2005 | Identity Based Encryption Without Redundancy
Benoît Libert, Jean-Jacques Quisquater |
ACNS | 1 |
| 2005 | Efficient and Provably-Secure Identity-Based Signatures and Signcryption from Bilinear Maps
Paulo S. L. M. Barreto, Benoît Libert, Noel McCullagh, Jean-Jacques Quisquater |
ASIACRYPT | 2 |
| 2005 | Efficient and Non-interactive Timed-Release Encryption
Julien Cathalo, Benoît Libert, Jean-Jacques Quisquater |
ICICS | 2 |
| 2004 | Identity Based Undeniable Signatures
Benoît Libert, Jean-Jacques Quisquater |
CT-RSA | 1 |
| 2004 | Cryptanalysis of a Verifiably Committed Signature Scheme Based on GPS and RSA
Julien Cathalo, Benoît Libert, Jean-Jacques Quisquater |
ISC | 2 |
| 2003 | A new identity based signcryption scheme from pairingsabstractWe present a new identity based scheme using pairings over elliptic curves. It combines the functionalities of signature and encryption and is provably secure in the random oracle model. We compare it with J. Malone-Lee's scheme from the points of view of security and efficiency. We give a proof of semantic security under the decisional bilinear Diffie-Hellman assumption for this new scheme. Benoît Libert, Jean-Jacques Quisquater |
ITW | 1 |
| 2003 | Efficient revocation and threshold pairing based cryptosystemsabstractBoneh, Ding, Tsudik and Wong recently proposed a way for obtaining fast revocation of RSA keys. Their method consists in using security mediators that keep a piece of each user's private key in such a way that every decrytion or signature operation requires the help of the mediator for the user. Revocation is achieved by instructing the mediator to stop helping the user to sign or decrypt messages. This security architecture, called SEM, gave rise to an identity based mediated RSA scheme (IB-mRSA) that combines the advantages of fast revocation and identity based public keys. We show that, in opposition to what was stated in [9], this revocation method can be applied to several existing public key encryption and signature schemes (all those for which a secure practical threshold adaptation exists) including the Boneh-Franklin identity based encryption scheme and a pairing based digital signature schemes. We first describe a threshold adaptation of the Boneh-Franklin identity based encryption scheme and, then, we compare the mediated versions of these schemes with IB-mRSA from security and efficiency points of view. Benoît Libert, Jean-Jacques Quisquater |
PODC | 1 |