Michel Abdalla

dblp:67/2285 · DBLP profile ↗
← Back
60ranked-venue papers
56as first author
5since 2021 · last 2023
0000-0002-2447-4329ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 55 · 53 first-author · 5 since 2021Theory of computation · 4 · 4 first-authorComputer networks · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2023 Practical dynamic group signatures without knowledge extractors
Hyoseung Kim 0002, Olivier Sanders, Michel Abdalla, Jong Hwan Park
Des. Codes Cryptogr.3
2022 Password-Authenticated Key Exchange from Group Actions
Michel Abdalla, Thorsten Eisenhofer, Eike Kiltz, Sabrina Kunzweiler, Doreen Riepel
CRYPTO (2)1
2021 Algebraic Adversaries in the Universal Composability Framework
Michel Abdalla, Manuel Barbosa, Jonathan Katz, Julian Loss, Jiayu Xu 0001
ASIACRYPT (3)1
2021 Security Analysis of CPace
Michel Abdalla, Björn Haase, Julia Hesse
ASIACRYPT (4)1
2021 Practical dynamic group signature with efficient concurrent joins and batch verifications
Hyoseung Kim 0002, Youngkyung Lee, Michel Abdalla, Jong Hwan Park
J. Inf. Secur. Appl.3
2020 Inner-Product Functional Encryption with Fine-Grained Access Control
Michel Abdalla, Dario Catalano, Romain Gay, Bogdan Ursu
ASIACRYPT (3)1
2020 Universally Composable Relaxed Password Authenticated Key Exchange
Michel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki, Jonathan Katz, Jiayu Xu 0001
CRYPTO (1)1
2020 Functional Encryption for Attribute-Weighted Sums from k-Lin
Michel Abdalla, Junqing Gong 0001, Hoeteck Wee
CRYPTO (1)1
2020 Corrigendum: Public-key encryption indistinguishable under plaintext-checkable attacks
abstract
This note is a corrigendum for the paper ‘Public‐key encryption indistinguishable under plaintext‐checkable attacks’, IET Information Security (2016), 10(6): 288, http://doi.org/10.1049/iet‐ifs.2015.0500 .
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
IET Inf. Secur.1
2019 From Single-Input to Multi-client Inner-Product Functional Encryption
Michel Abdalla, Fabrice Benhamouda, Romain Gay
ASIACRYPT (3)1
2019 Algebraic XOR-RKA-Secure Pseudorandom Functions from Post-Zeroizing Multilinear Maps
Michel Abdalla, Fabrice Benhamouda, Alain Passelègue
ASIACRYPT (2)1
2019 New technique for chosen-ciphertext security based on non-interactive zero-knowledge
Minhye Seo, Michel Abdalla, Dong Hoon Lee 0001, Jong Hwan Park
Inf. Sci.2
2019 On the Tightness of Forward-Secure Signature Reductions
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
J. Cryptol.1
2018 Multi-Input Functional Encryption for Inner Products: Function-Hiding Realizations and Constructions Without Pairings
Michel Abdalla, Dario Catalano, Dario Fiore 0001, Romain Gay, Bogdan Ursu
CRYPTO (1)1
2018 Robust Encryption
Michel Abdalla, Mihir Bellare, Gregory Neven
J. Cryptol.1
2018 Related-Key Security for Pseudorandom Functions Beyond the Linear Barrier
Michel Abdalla, Fabrice Benhamouda, Alain Passelègue, Kenneth G. Paterson
J. Cryptol.1
2017 Multi-input Inner-Product Functional Encryption from Pairings
Michel Abdalla, Romain Gay, Mariana Raykova 0001, Hoeteck Wee
EUROCRYPT (1)1
2016 Robust Password-Protected Secret Sharing
Michel Abdalla, Mario Cornejo, Anca Nitulescu, David Pointcheval
ESORICS (2)1
2016 Public-key encryption indistinguishable under plaintext-checkable attacks
abstract
Indistinguishability under chosen‐ciphertext attack (IND‐CCA) is now considered the de facto security notion for public‐key encryption. However, this sometimes offers a stronger security guarantee than what is needed. In this study, the authors consider a weaker security notion, termed as indistinguishability under plaintext‐checking attacks (IND‐PCA), in which the adversary has only access to an oracle indicating whether or not a given ciphertext encrypts a given message. After formalising this notion, the authors design a new public‐key encryption scheme satisfying it. The new scheme is a variant of the Cramer–Shoup encryption scheme with shorter ciphertexts. Its security is also based on the plain decisional Diffie–Hellman (DDH) assumption. Additionally, the algebraic properties of the new scheme allow proving plaintext knowledge using Groth–Sahai non‐interactive zero‐knowledge proofs or smooth projective hash functions. Finally, as a concrete application, the authors show that, for many password‐based authenticated key exchange (PAKE) schemes in the Bellare–Pointcheval–Rogaway security model, they can safely replace the underlying IND‐CCA encryption schemes with their new IND‐PCA one. By doing so, they reduce the overall communication complexity of these protocols and obtain the most efficient PAKE schemes to date based on plain DDH.
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
IET Inf. Secur.1
2016 Tightly Secure Signatures From Lossy Identification Schemes
Michel Abdalla, Pierre-Alain Fouque, Vadim Lyubashevsky, Mehdi Tibouchi
J. Cryptol.1
2015 Robust Pseudo-Random Number Generators with Input Secure Against Side-Channel Attacks
Michel Abdalla, Sonia Belaïd, David Pointcheval, Sylvain Ruhault, Damien Vergnaud
ACNS1
2015 Multilinear and Aggregate Pseudorandom Functions: New Constructions and Improved Security
Michel Abdalla, Fabrice Benhamouda, Alain Passelègue
ASIACRYPT (1)1
2015 An Algebraic Framework for Pseudorandom Functions and Applications to Related-Key Security
Michel Abdalla, Fabrice Benhamouda, Alain Passelègue
CRYPTO (1)1
2015 Disjunctions for Hash Proof Systems: New Constructions and Applications
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
EUROCRYPT (2)1
2015 Security of the J-PAKE Password-Authenticated Key Exchange Protocol
abstract
J-PAKE is an efficient password-authenticated key exchange protocol that is included in the Open SSL library and is currently being used in practice. We present the first proof of security for this protocol in a well-known and accepted model for authenticated key-exchange, that incorporates online and offline password guessing, concurrent sessions, forward secrecy, server compromise, and loss of session keys. This proof relies on the Decision Square Diffie-Hellman assumption, as well as a strong security assumption for the non-interactive zero-knowledge (NIZK) proofs in the protocol (specifically, simulation-sound extractability). We show that the Schnorr proof-of-knowledge protocol, which was recommended for the J-PAKE protocol, satisfies this strong security assumption in a model with algebraic adversaries and random oracles, and extend the full J-PAKE proof of security to this model. Finally, we show that by modifying the recommended labels in the Schnorr protocol used in J-PAKE, we can achieve a security proof for J-PAKE with a tighter security reduction.
Michel Abdalla, Fabrice Benhamouda, Philip MacKenzie
IEEE Symposium on Security and Privacy1
2014 Related-Key Security for Pseudorandom Functions Beyond the Linear Barrier
Michel Abdalla, Fabrice Benhamouda, Alain Passelègue, Kenneth G. Paterson
CRYPTO (1)1
2014 Improving Thomlinson-Walker's Software Patching Scheme Using Standard Cryptographic and Statistical Tools
Michel Abdalla, Hervé Chabanne, Houda Ferradi, Julien Jainski, David Naccache
ISPEC1
2014 Password-Based Authenticated Key Exchange: An Overview
Michel Abdalla
ProvSec1
2014 Verifiable Random Functions: Relations to Identity-Based Key Encapsulation and New Constructions
Michel Abdalla, Dario Catalano, Dario Fiore 0001
J. Cryptol.1
2013 SPHF-Friendly Non-interactive Commitments
Michel Abdalla, Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval
ASIACRYPT (1)1
2013 Leakage-Resilient Symmetric Encryption via Re-keying
Michel Abdalla, Sonia Belaïd, Pierre-Alain Fouque
CHES1
2012 Tightly-Secure Signatures from Lossy Identification Schemes
Michel Abdalla, Pierre-Alain Fouque, Vadim Lyubashevsky, Mehdi Tibouchi
EUROCRYPT1
2012 Generalized Key Delegation for Wildcarded Identity-Based and Inner-Product Encryption
abstract
Inspired by the fact that many e-mail addresses correspond to groups of users, Abdalla introduced the notion of identity-based encryption with wildcards (WIBE), which allows a sender to simultaneously encrypt messages to a group of users matching a certain pattern, defined as a sequence of identity strings and wildcards. This notion was later generalized by Abdalla, Kiltz, and Neven, who considered more general delegation patterns during the key derivation process. Despite its many applications, current constructions have two significant limitations: 1) they are only known to be fully secure when the maximum hierarchy depth is a constant; and 2) they do not hide the pattern associated with the ciphertext. To overcome these, this paper offers two new constructions. First, we show how to convert a WIBE scheme of Abdalla into a (nonanonymous) WIBE scheme with generalized key delegation (WW-IBE) that is fully secure even for polynomially many levels. Then, to achieve anonymity, we initially consider hierarchical predicate encryption (HPE) schemes with more generalized forms of key delegation and use them to construct an anonymous WW-IBE scheme. Finally, to instantiate the former, we modify the HPE scheme of Lewko to allow for more general key delegation patterns. Our proofs are in the standard model and use existing complexity assumptions.
Michel Abdalla, Angelo De Caro, Duong Hieu Phan
IEEE Trans. Inf. Forensics Secur.1
2011 Contributory Password-Authenticated Group Key Exchange with Join Capability
Michel Abdalla, Céline Chevalier, Louis Granboulan, David Pointcheval
CT-RSA1
2011 Wildcarded Identity-Based Encryption
Michel Abdalla, James Birkett, Dario Catalano, Alexander W. Dent, John Malone-Lee, Gregory Neven, Jacob C. N. Schuldt, Nigel P. Smart
J. Cryptol.1
2010 Robust Encryption
Michel Abdalla, Mihir Bellare, Gregory Neven
TCC1
2009 Smooth Projective Hashing for Conditionally Extractable Commitments
Michel Abdalla, Céline Chevalier, David Pointcheval
CRYPTO1
2009 Verifiable Random Functions from Identity-Based Key Encapsulation
Michel Abdalla, Dario Catalano, Dario Fiore 0001
EUROCRYPT1
2008 Anonymous and Transparent Gateway-Based Password-Authenticated Key Exchange
Michel Abdalla, Malika Izabachène, David Pointcheval
CANS1
2008 Efficient Two-Party Password-Based Key Exchange Protocols in the UC Framework
Michel Abdalla, Dario Catalano, Céline Chevalier, David Pointcheval
CT-RSA1
2008 Generalised key delegation for hierarchical identity-based encryption
abstract
The authors introduce a new primitive called identity-based encryption with wildcard key derivation (WKD-IBE or ‘wicked IBE’) that enhances the concept of hierarchical identity-based encryption by allowing more general key delegation patterns. A secret key is derived for a vector of identity strings, where entries can be left blank using a wildcard. This key can then be used to derive keys for any pattern that replaces wildcards with concrete identity strings. For example, one may want to allow the university's head system administrator to derive secret keys (and hence the ability to decrypt) for all departmental sysadmin email addresses sysadmin@*.univ.edu, where * is a wildcard that can be replaced with any string. The authors provide appropriate security notions and provably secure instantiations with different tradeoffs in terms of ciphertext size and efficiency. The authors also present a generic construction of identity-based broadcast encryption (IBBE) from any WKD-IBE scheme. One of their instantiations yields an IBBE scheme with constant ciphertext size.
Michel Abdalla, Eike Kiltz, Gregory Neven
IET Inf. Secur.1
2008 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
J. Cryptol.1
2008 From Identification to Signatures Via the Fiat-Shamir Transform: Necessary and Sufficient Conditions for Security and Forward-Security
abstract
The Fiat-Shamir paradigm for transforming identification schemes into signature schemes has been popular since its introduction because it yields efficient signature schemes, and has been receiving renewed interest of late as the main tool in deriving forward-secure signature schemes. In this paper, minimal (meaning necessary and sufficient) conditions on the identification scheme to ensure security of the signature scheme in the random oracle model are determined, both in the usual and in the forward-secure cases. Specifically, it is shown that the signature scheme is secure (respectively, forward-secure) against chosen-message attacks in the random oracle modelifandonlyifthe underlying identification scheme is secure (respectively, forward-secure) against impersonation underpassive(i.e., eavesdropping only) attacks, and has its commitments drawn at random from a large space. An extension is proven incorporating a random seed into the Fiat-Shamir transform so that the commitment space assumption may be removed.
Michel Abdalla, Jee Hea An, Mihir Bellare, Chanathip Namprempre
IEEE Trans. Inf. Theory1
2007 Generalized Key Delegation for Hierarchical Identity-Based Encryption
Michel Abdalla, Eike Kiltz, Gregory Neven
ESORICS1
2007 (Password) Authenticated Key Establishment: From 2-Party to Group
Michel Abdalla, Jens-Matthias Bohli, María Isabel González Vasco, Rainer Steinwandt
TCC1
2006 A Scalable Password-Based Group Key Exchange Protocol in the Standard Model
Michel Abdalla, David Pointcheval
ASIACRYPT1
2006 Provably secure password-based authentication in TLS
abstract
In this paper, we show how to design an efficient, provably secure password-based authenticated key exchange mechanism specifically for the TLS (Transport Layer Security) protocol. The goal is to provide a technique that allows users to employ (short) passwords to securely identify themselves to servers. As our main contribution, we describe a new password-based technique for user authentication in TLS, called Simple Open Key Exchange (SOKE). Loosely speaking, the SOKE ciphersuites are unauthenticated Diffie-Hellman ciphersuites in which the client's Diffie-Hellman ephemeral public value is encrypted using a simple mask generation function. The mask is simply a constant value raised to the power of (a hash of) the password.The SOKE ciphersuites, in advantage over previous password-based authentication ciphersuites for TLS, combine the following features. First, SOKE has formal security arguments; the proof of security based on the computational Diffie-Hellman assumption is in the random oracle model, and holds for concurrent executions and for arbitrarily large password dictionaries. Second, SOKE is computationally efficient; in particular, it only needs operations in a sufficiently large prime-order subgroup for its Diffie-Hellman computations (no safe primes). Third, SOKE provides good protocol flexibility because the user identity and password are only required once a SOKE ciphersuite has actually been negotiated, and after the server has sent a server identity.
Michel Abdalla, Emmanuel Bresson, Olivier Chevassut, Bodo Möller, David Pointcheval
AsiaCCS1
2006 Resisting against aggregator compromises in sensor networks
abstract
In order to reduce the amount of radio communications, wireless sensor networks may perform data aggregation, where relaying nodes perform in-network processing. Guaranteeing security in aggregation schemes is particularly challenging because node compromises in such a scenario are doubly problematic, both in terms data confidentiality (eavesdropping) and availability (denial of service). Indeed, by compromising an aggregator node the attacker would endanger all of the readings that are part of the aggregate the node is in charge of.
Thomas Claveirole, Marcelo Dias de Amorim, Michel Abdalla, Yannis Viniotis
CoNEXT3
2006 On the (Im)possibility of Blind Message Authentication Codes
Michel Abdalla, Chanathip Namprempre, Gregory Neven
CT-RSA1
2006 Identity-Based Encryption Gone Wild
Michel Abdalla, Dario Catalano, Alexander W. Dent, John Malone-Lee, Gregory Neven, Nigel P. Smart
ICALP (2)1
2005 A Simple Threshold Authenticated Key Exchange from Short Secrets
Michel Abdalla, Olivier Chevassut, Pierre-Alain Fouque, David Pointcheval
ASIACRYPT1
2005 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
CRYPTO1
2005 Simple Password-Based Encrypted Key Exchange Protocols
Michel Abdalla, David Pointcheval
CT-RSA1
2004 On the Minimal Assumptions of Group Signature Schemes
Michel Abdalla, Bogdan Warinschi
ICICS1
2002 From Identification to Signatures via the Fiat-Shamir Transform: Minimizing Assumptions for Security and Forward-Security
Michel Abdalla, Jee Hea An, Mihir Bellare, Chanathip Namprempre
EUROCRYPT1
2001 The Oracle Diffie-Hellman Assumptions and an Analysis of DHIES
Michel Abdalla, Mihir Bellare, Phillip Rogaway
CT-RSA1
2001 Forward-Secure Threshold Signature Schemes
Michel Abdalla, Sara Miner More, Chanathip Namprempre
CT-RSA1
2000 Increasing the Lifetime of a Key: A Comparative Analysis of the Security of Re-keying Techniques
Michel Abdalla, Mihir Bellare
ASIACRYPT1
2000 A New Forward-Secure Digital Signature Scheme
Michel Abdalla, Leonid Reyzin
ASIACRYPT1
2000 Key management for restricted multicast using broadcast encryption
abstract
The problem we address is how to communicate securely with a set of users (the target set) over an insecure broadcast channel. This problem occurs in two application domains: satellite/cable pay TV and the Internet MBone. In these systems, the parameters of major concern are the number of key transmissions and the number of keys held by each receiver. In the Internet domain, previous schemes suggest building a separate key tree for each multicast program, thus incurring a setup cost of at least k log k per program for target sets of size k. In the pay TV domain, a single key structure is used for all programs, but known theoretical bounds show that either very long transmissions are required, or that each receiver needs to keep prohibitively many keys. Our approach is targeted at both domains. Our schemes maintain a single key structure that requires each receiver to keep only a logarithmic number of establishment keys for its entire lifetime. At the same time our schemes admit low numbers of transmissions. In order to achieve these goals, and to break away from the theoretical bounds, we allow a controlled number of users outside the target set to occasionally receive the multicast. This relaxation is appropriate for many scenarios in which the encryption is used to force consumers to pay for a service, rather than to withhold sensitive information. For this purpose, we introduce f-redundant establishment key allocations, which guarantee that the total number of recipients is no more than f times the number of intended recipients. We measure the performance of such schemes by the number of key transmissions they require, by their redundancy f, and by the probability that a user outside the target set (a free-rider) will be able to decrypt the multicast. We prove a new lower bound, present several new establishment key allocations, and evaluate our schemes' performance by extensive simulation.
Michel Abdalla, Yuval Shavitt, Avishai Wool
IEEE/ACM Trans. Netw.1