VLDB 2026 Research / reviewers in the wild / expert
Keita Emura
dblp:68/1281
· DBLP profile ↗
67ranked-venue papers
38as first author
20since 2021 · last 2026
0000-0002-8969-3581ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 56 · 31 first-author · 16 since 2021Theory of computation · 9 · 6 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security analysis on a public-key inverted-index keyword search scheme with designated testerabstract• We present two attacks against the Gao et al. scheme (IEEE Internet of Things Journal, 2024) that reveal keyword information from a trapdoor. • We also demonstrate that the computational cost of the attacks is approximately two seconds. • We also discuss the possibility of applying a correction. Gao et al. (IEEE Internet of Things Journal, 2024) proposed a public-key inverted-index keyword search scheme with a designated tester as an extension of public-key encryption with keyword search (PEKS). In their scheme, the server (acting as the tester) holds a secret key and uses it to execute the search algorithm under the designated tester setting. They proved that no information about the keyword is revealed from trapdoors under the decisional Diffie-Hellman (DDH) assumption. However, their construction employs a symmetric pairing, which can effectively serve as a DDH solver. Consequently, the underlying complexity assumption does not hold, and it is expected that keyword information can be extracted from trapdoors. In this paper, we present two keyword guessing attacks against the Gao et al. scheme that reveal keyword information from a trapdoor. The first attack succeeds using only the server’s secret key and the challenge trapdoor, without requiring any additional encryption or trapdoor queries. We note that, in their security model, an adversary is not allowed to obtain the server’s secret key; therefore, our attack lies outside their defined model. Nevertheless, we discuss the role of the server and argue that our attack scenario is reasonable. The second attack does not rely on the server’s secret key but instead exploits the linkability of two trapdoors. In both attacks, the computational complexity is limited to two pairing operations, making them practical in terms of computational cost. Mizuki Hayashi, Keita Emura |
J. Inf. Secur. Appl. | 2 |
| 2026 | On the traceability of group signatures: Uncorrupted user must exist
Keita Emura |
Theor. Comput. Sci. | 1 |
| 2026 | Comments on "Lightweight Multi-User Public-Key Authenticated Encryption With Keyword Search"abstractXu et al. (IEEE Transactions on Information Forensics and Security 2025) proposed a lightweight multi-user public-key authenticated encryption with keyword search (LM-PAEKS) scheme. In this short note, we demonstrate that keyword information can be leaked from ciphertexts in the scheme. We further note that there are shortcomings in the security proof as well. Keita Emura |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Group Signatures with Message-Dependent Opening Directly Imply Timed-Release Encryption
Yuto Imura, Keita Emura |
CANS | 2 |
| 2025 | On the Relations Between Matchmaking Public Key Encryption and Public Key Authenticated Encryption with Keyword Search
Takeshi Yoshida 0002, Keita Emura |
CANS | 2 |
| 2025 | Generic Construction of Dual-Server Public Key Authenticated Encryption With Keyword SearchabstractIn this paper, we propose a generic construction of dual‐server public key authenticated encryption with keyword search (DS‐PAEKS) from PAEKS, public key encryption, and signatures. We also show that previous DS‐PAEKS scheme is vulnerable by providing a concrete attack. That is, the proposed generic construction yields the first DS‐PAEKS schemes. Our attack with a slight modification works against previous dual‐server public key encryption with keyword search (DS‐PEKS) schemes. Keita Emura |
IET Inf. Secur. | 1 |
| 2025 | An anonymous yet accountable contract wallet system using account abstraction
Kota Chin, Keita Emura, Kazumasa Omote |
J. Inf. Secur. Appl. | 2 |
| 2025 | Comments on "Blockchain-Assisted Public-Key Encryption With Keyword Search Against Keyword Guessing Attacks for Cloud Storage"abstractAs a variant of PEKS (Public key Encryption with Keyword Search), Zhang it al. (IEEE Transactions on Cloud Computing 2021) introduced a secure and efficient PEKS scheme called SEPSE, where servers issue a servers-derived keyword to a sender or a receiver. In this paper, we show that information of keyword is revealed from trapdoor when an adversary is allowed to issue servers-derived keyword queries twice. Keita Emura |
IEEE Trans. Cloud Comput. | 1 |
| 2024 | On the Feasibility of Identity-Based Encryption with Equality Test Against Insider Attacks
Keita Emura |
ACISP (1) | 1 |
| 2024 | Generic Construction of Forward Secure Public Key Authenticated Encryption with Keyword Search
Keita Emura |
ACNS (1) | 1 |
| 2023 | An End-to-End Encrypted Cache System with Time-Dependent Access Control
Keita Emura, Masato Yoshimi |
ICISSP | 1 |
| 2023 | Generic Construction of Fully Anonymous Broadcast Authenticated Encryption with Keyword Search with Adaptive CorruptionsabstractAs a multireceiver variant of public key authenticated encryption with keyword search (PAEKS), broadcast authenticated encryption with keyword search (BAEKS) was proposed by Liu et al. (ACISP 2021). BAEKS focuses on receiver anonymity, where no information about the receiver is leaked from ciphertexts, which is reminiscent of the anonymous broadcast encryption. Here, there are rooms for improving their security definitions, e.g., two challenge sets of receivers are selected before the setup phase, and an adversary is not allowed to corrupt any receiver. In this paper, we propose a generic construction of BAEKS derived from PAEKS that provides ciphertext anonymity and consistency in a multireceiver setting. The proposed construction is an extension of the generic construction proposed by Libert et al. (PKC 2012) for the fully anonymous broadcast encryption and provides adaptive corruptions. We also demonstrate that the Qin et al. PAEKS scheme (ProvSec 2021) provides ciphertext anonymity and consistency in a multireceiver setting and can be employed as a building block of the proposed generic construction. Keita Emura |
IET Inf. Secur. | 1 |
| 2022 | Keyed-Fully Homomorphic Encryption Without Indistinguishability Obfuscation
Shingo Sato, Keita Emura, Atsushi Takayasu |
ACNS | 2 |
| 2022 | More Efficient Adaptively Secure Lattice-Based IBE with Equality Test in the Standard Model
Kyoichi Asano, Keita Emura, Atsushi Takayasu |
ISC | 2 |
| 2022 | A Generic Construction of CCA-Secure Attribute-Based Encryption with Equality Test
Kyoichi Asano, Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001 |
ProvSec | 2 |
| 2022 | Identity-based encryption with security against the KGC: A formal model and its instantiationsabstractThe key escrow problem is one of the main barriers to the widespread real-world use of identity-based encryption (IBE). Specifically, a key generation center (KGC), which generates secret keys for a given identity, has the power to decrypt all ciphertexts. At PKC 2009, Chow defined a notion of security against the KGC, that relies on assuming that it cannot discover the underlying identities behind ciphertexts. However, this is not a realistic assumption since, in practice, the KGC manages an identity list, and hence it can easily guess the identities corresponding to given ciphertexts. Chow later amended this issue by introducing a new entity called an identity-certifying authority (ICA) and proposed an anonymous key-issuing protocol. Essentially, this allows the users, KGC, and ICA to interactively generate secret keys without users ever having to reveal their identities to the KGC. Unfortunately, since Chow separately defined the security of IBE and that of the anonymous key-issuing protocol, his IBE definition did not provide any formal treatment when the ICA is used to authenticate the users. Effectively, all of the subsequent works following Chow lack the formal proofs needed to determine whether or not it delivers a secure solution to the key escrow problem. In this paper, based on Chow's work, we formally define an IBE scheme that resolves the key escrow problem and provide formal definitions of security against corrupted users, KGC, and ICA. Along the way, we observe that if we are allowed to assume a fully trusted ICA, as in Chow's work, then we can construct a trivial (and meaningless) IBE scheme that is secure against the KGC. Finally, we present two instantiations in our new security model: a lattice-based construction based on the Gentry–Peikert–Vaikuntanathan IBE scheme (STOC 2008) and Rückert's lattice-based blind signature scheme (ASIACRYPT 2010), and a pairing-based construction based on the Boneh–Franklin IBE scheme (CRYPTO 2001) and Boldyreva's blind signature scheme (PKC 2003). Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001 |
Theor. Comput. Sci. | 1 |
| 2021 | Verifiable Functional Encryption Using Intel SGX
Tatsuya Suzuki 0002, Keita Emura, Toshihiro Ohigashi, Kazumasa Omote |
ProvSec | 2 |
| 2021 | Adaptively secure revocable hierarchical IBE from k-linear assumption
Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001 |
Des. Codes Cryptogr. | 1 |
| 2021 | Efficient identity-based encryption with Hierarchical key-insulation from HIBEabstractAbstract Hierarchical key-insulated identity-based encryption (HKIBE) is identity-based encryption (IBE) that allows users to update their secret keys to achieve (hierarchical) key-exposure resilience, which is an important notion in practice. However, existing HKIBE constructions have limitations in efficiency: sizes of ciphertexts and secret keys depend on the hierarchical depth. In this paper, we first triumph over the barrier by proposing simple but effective design methodologies to construct efficient HKIBE schemes. First, we show a generic construction from any hierarchical IBE (HIBE) scheme that satisfies a special requirement, called MSK evaluatability introduced by Emura et al. (Des. Codes Cryptography 89(7):1535–1574, 2021). It provides several new and efficient instantiations since most pairing-based HIBE schemes satisfy the requirement. It is worth noting that it preserves all parameters’ sizes of the underlying HIBE scheme, and hence we obtain several efficient HKIBE schemes under the k-linear assumption in the standard model. Since MSK evaluatability is dedicated to pairing-based HIBE schemes, the first construction restricts pairing-based instantiations. To realize efficient instantiation from various assumptions, we next propose a generic construction of an HKIBE scheme from any plain HIBE scheme. It is based on Hanaoka et al.’s HKIBE scheme (Asiacrypt 2005), and does not need any special properties. Therefore, we obtain new efficient instantiations from various assumptions other than pairing-oriented ones. Though the sizes of secret keys and ciphertexts are larger than those of the first construction, it is more efficient than Hanaoka et al.’s scheme in the sense of the sizes of master public/secret keys. Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001 |
Des. Codes Cryptogr. | 1 |
| 2021 | Efficient revocable identity-based encryption with short public parametersabstractRevocation functionality is vital to real-world cryptographic systems for managing their reliability. In the context of identity-based encryption (IBE), Boldyreva, Goyal, and Kumar (ACM CCS 2008) first showed an efficient revocation method for IBE, and such an IBE scheme with the scalable revocation method is called revocable IBE (RIBE). Seo and Emura (PKC 2013) introduced a new security notion, called decryption key exposure resistance (DKER), which is a desirable security notion for RIBE. However, all existing RIBE schemes that achieve adaptive security with DKER require long public parameters or composite-order bilinear groups. In this paper, we first show an RIBE scheme that (1) satisfies adaptive security; (2) achieves DKER; (3) realizes constant-size public parameters; and (4) is constructed over prime-order bilinear groups. Our core technique relies on Seo and Emura's one (PKC 2013), which transform the Waters IBE (EUROCRYPT 2005) to the corresponding RIBE scheme. Specifically, we construct an IBE scheme that satisfies constant-size public parameters over prime-order groups and some requirements for the Seo-Emura technique, and then transform the IBE scheme to an RIBE scheme. We also discuss how to extend the proposed RIBE scheme to a chosen-ciphertext secure one and server-aided one (ESORICS 2015). Keita Emura, Jae Hong Seo, Yohei Watanabe 0001 |
Theor. Comput. Sci. | 1 |
| 2020 | Cache-22: A Highly Deployable Encrypted Cache System
Keita Emura, Shiho Moriai, Takuma Nakajima, Masato Yoshimi |
ISITA | 1 |
| 2020 | Secure-channel free searchable encryption with multiple keywords: A generic construction, an instantiation, and its implementation
Keita Emura, Katsuhiko Ito, Toshihiro Ohigashi |
J. Comput. Syst. Sci. | 1 |
| 2020 | Group Signatures with Time-Bound Keys Revisited: A New Model, an Efficient Construction, and its ImplementationabstractChu et al. (ASIACCS 2012) proposed group signature with time-bound keys (GS-TBK), where each signing key is associated with expiry time τ. In addition, to prove membership of the group, a signer needs to prove that the expiry time has not passed, i.e., t <; τ, where t is the current time. A signer whose expiry time has passed is automatically revoked, and this revocation is called natural revocation. Signers can be revoked simultaneously before their expiry times if the credential is compromised. This revocation is called premature revocation. A nice property in the Chu et al. proposal is that the size of revocation lists can be reduced compared to those of Verifier-Local Revocation (VLR) group signature schemes by assuming that natural revocation accounts for most of the signer revocations in practice, and prematurely revoked signers are only a small fraction. In this paper, we point out that the definition of traceability of Chu et al. did not capture the unforgeability of expiry time for signing keys, which guarantees that no adversary who has a signing key associated with expiry time τ can compute a valid signature after τ has passed. This situation significantly reduces the dependability of the system since legitimate signing keys may be used for providing a forged signature. We introduce a security model that captures unforgeability, and propose a secure GS-TBK scheme in the new model. Our scheme also provides constant signing costs, whereas those of the previous schemes depended on the bit-length of the time representation. Finally, we provide the implementation results. We employ Barreto-Lynn-Scott (BLS) curves with 455-bit prime order and the RELIC library, and demonstrate that our scheme is feasible in practical settings. Keita Emura, Takuya Hayashi 0001, Ai Ishida |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | Proper Usage of the Group Signature Scheme in ISO/IEC 20008-2abstractIn ISO/IEC 20008-2, several anonymous digital signature schemes are specified. Among these, the scheme denoted as Mechanism 6, is the only plain group signature scheme that does not aim at providing additional functionalities. The Intel Enhanced Privacy Identification (EPID) scheme, which has many applications in connection with Intel Software Guard Extensions (Intel SGX), is in practice derived from Mechanism 6. In this paper, we firstly show that Mechanism 6 does not satisfy anonymity in the standard security model, i.e., the Bellare-Shi-Zhang model [CT-RSA 2005]. We then provide a detailed analysis of the security properties offered by Mechanism 6 and characterize the conditions under which its anonymity is preserved. Consequently, it is seen that Mechanism 6 is secure under the condition that the issuer, who generates user signing keys, does not join the attack. We also derive a simple patch for Mechanism~6 from the analysis. Ai Ishida, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka |
AsiaCCS | 3 |
| 2019 | Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001 |
ESORICS (2) | 1 |
| 2019 | Privacy-Preserving Aggregation of Time-Series Data with Public Verifiability from Simple Assumptions and Its ImplementationsabstractAggregator oblivious encryption was proposed by Shi et al. (NDSS 2011). In this method, an aggregator can compute an aggregated sum of data and is unable to learn anything else (aggregator obliviousness). Since the aggregator does not learn individual data that may reveal users’ habits and behaviors, several applications including privacy-preserving smart metering have been considered. In this paper, we propose an aggregator oblivious encryption scheme with public verifiability where the aggregator is required to generate a proof of an aggregated sum, and anyone can verify whether the aggregated sum has been correctly computed by the aggregator. Although Leontiadis et al. (CANS 2015) considered verifiability, their scheme requires an interactive complexity assumption to provide the unforgeability of the proof. Our scheme is proven to be unforgeable under a static and simple assumption (a variant of the Computational Diffie–Hellman assumption). Moreover, our scheme inherits the tightness of the reduction of the Benhamouda et al. scheme (ACM TISSEC 2016) for proving aggregator obliviousness. This tight reduction allows us to employ elliptic curves of a smaller order and leads to efficient implementation. Specifically, for 112-bit security, we can employ Barreto–Naehrig (BN) curves with a 383-bit prime order, whereas we need to employ curves with a 1031-bit prime order to implement the Leontiadis et al. scheme. We give implementations of two schemes and evaluate their performances under those curves. We employ a Raspberry-Pi as a power-constrained device such as a smart meter. Consequently, we demonstrate that the running time of the data encryption, data aggregation and verification in our scheme are reduced by approximately 74%, 64% and 89%, respectively, compared to those of the Leontiadis et al. scheme. Keita Emura, Hayato Kimura 0002, Toshihiro Ohigashi, Tatsuya Suzuki 0002 |
Comput. J. | 1 |
| 2019 | Group Signatures with Message-Dependent Opening: Formal Definitions and ConstructionsabstractThis paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes. Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazuma Ohara, Kazumasa Omote, Yusuke Sakai 0001 |
Secur. Commun. Networks | 1 |
| 2018 | A Generic Construction of Integrated Secure-Channel Free PEKS and PKE
Tatsuya Suzuki 0002, Keita Emura, Toshihiro Ohigashi |
ISPEC | 2 |
| 2018 | A Revocable Group Signature Scheme with Scalability from Simple Assumptions and Its Implementation
Keita Emura, Takuya Hayashi 0001 |
ISC | 1 |
| 2018 | Chosen ciphertext secure keyed-homomorphic public-key cryptosystems
Keita Emura, Goichiro Hanaoka, Koji Nuida, Go Ohtake, Takahiro Matsuda 0002, Shota Yamada 0001 |
Des. Codes Cryptogr. | 1 |
| 2017 | Privacy-Preserving Aggregation of Time-Series Data with Public Verifiability from Simple Assumptions
Keita Emura |
ACISP (2) | 1 |
| 2017 | Group Signatures with Time-bound Keys Revisited: A New Model and an Efficient ConstructionabstractChu et al. (ASIACCS 2012) proposed group signature with time-bound keys (GS-TBK) where each signing key is associated to an expiry time τ. In addition to prove the membership of the group, a signer needs to prove that the expiry time has not passed, i.e., t<τ where t is the current time. A signer whose expiry time has passed is automatically revoked, and this revocation is called natural revocation. Simultaneously, signers can be revoked before their expiry times have passed due to the compromise of the credential. This revocation is called premature revocation. A nice property of the Chu et al. proposal is that the size of revocation lists can be reduced compared to those of Verifier-Local Revocation (VLR) group signature schemes, by assuming that natural revocation accounts for most of signer revocations in practice, and prematurely revoked signers are only a small fraction. In this paper, we point out that the definition of traceability of Chu et al. did not capture unforgeability of expiry time of signing keys which guarantees that no adversary who has a signing key associated to an expiry time τ can compute a valid signature after τ has passed. We introduce a security model that captures unforgeability, and propose a GS-TBK scheme secure in the new model. Our scheme also provides the constant signing costs whereas those of the previous schemes depend on the bit-length of the time representation. Finally, we give implementation results, and show that our scheme is feasible in practical settings. Keita Emura, Takuya Hayashi 0001, Ai Ishida |
AsiaCCS | 1 |
| 2017 | Mis-operation Resistant Searchable Homomorphic EncryptionabstractLet us consider a scenario that a data holder (e.g., a hospital) encrypts a data (e.g., a medical record) which relates a keyword (e.g., a disease name), and sends its ciphertext to a server. We here suppose not only the data but also the keyword should be kept private. A receiver sends a query to the server (e.g., average of body weights of cancer patients). Then, the server performs the homomorphic operation to the ciphertexts of the corresponding medical records, and returns the resultant ciphertext. In this scenario, the server should NOT be allowed to perform the homomorphic operation against ciphertexts associated with different keywords. If such a mis-operation happens, then medical records of different diseases are unexpectedly mixed. However, in the conventional homomorphic encryption, there is no way to prevent such an unexpected homomorphic operation, and this fact may become visible after decrypting a ciphertext, or as the most serious case it might be never detected. To circumvent this problem, in this paper, we propose mis-operation resistant homomorphic encryption, where even if one performs the homomorphic operations against ciphertexts associated with keywords ω' and ω, where ω -ω', the evaluation algorithm detects this fact. Moreover, even if one (intentionally or accidentally) performs the homomorphic operations against such ciphertexts, a ciphertext associated with a random keyword is generated, and the decryption algorithm rejects it. So, the receiver can recognize such a mis-operation happens in the evaluation phase. In addition to mis-operation resistance, we additionally adopt secure search functionality for keywords since it is desirable when one would like to delegate homomorphic operations to a third party. So, we call the proposed primitive mis-operation resistant searchable homomorphic encryption (MR-SHE). We also give our implementation result of inner products of encrypted vectors. In the case when both vectors are encrypted, the running time of the receiver is millisecond order for relatively small-dimensional (e.g., 26) vectors. In the case when one vector is encrypted, the running time of the receiver is approximately 5 msec even for relatively high-dimensional (e.g., 213) vectors. Keita Emura, Takuya Hayashi 0001, Noboru Kunihiro, Jun Sakuma |
AsiaCCS | 1 |
| 2017 | New Revocable IBE in Prime-Order Groups: Adaptively Secure, Decryption Key Exposure Resistant, and with Short Public Parameters
Yohei Watanabe 0001, Keita Emura, Jae Hong Seo |
CT-RSA | 2 |
| 2017 | Generic Constructions for Fully Secure Revocable Attribute-Based Encryption
Kotoko Yamada, Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka |
ESORICS (2) | 3 |
| 2017 | A Generic Construction of Secure-Channel Free Searchable Encryption with Multiple Keywords
Keita Emura |
NSS | 1 |
| 2017 | Establishing secure and anonymous communication channel: KEM/DEM-based construction and its implementation
Keita Emura, Akira Kanaoka, Satoshi Ohta, Takeshi Takahashi 0001 |
J. Inf. Secur. Appl. | 1 |
| 2016 | Group Signature with Deniability: How to Disavow a Signature
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka |
CANS | 2 |
| 2016 | Toward securing tire pressure monitoring systems: A case of PRESENT-based implementation
Keita Emura, Takuya Hayashi 0001, Shiho Moriai |
ISITA | 1 |
| 2016 | Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta |
Theor. Comput. Sci. | 2 |
| 2016 | Revocable hierarchical identity-based encryption via history-free approach
Jae Hong Seo, Keita Emura |
Theor. Comput. Sci. | 2 |
| 2015 | Dynamic Threshold Public-Key Encryption with Decryption Consistency from Static Assumptions
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta |
ACISP | 2 |
| 2015 | Accumulable Optimistic Fair Exchange from Verifiably Encrypted Homomorphic Signatures
Jae Hong Seo, Keita Emura, Keita Xagawa, Kazuki Yoneyama |
ACNS | 2 |
| 2015 | Disavowable Public Key Encryption with Non-interactive OpeningabstractWe propose the notion of disavowable public key encryption with non-interactive opening (disavowable PKENO) where, for a ciphertext and a message, the receiver of the ciphertext can issue a proof that the plaintext of the ciphertext is NOT the message, and give a fairly practical construction. Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka |
AsiaCCS | 2 |
| 2015 | Revocable Hierarchical Identity-Based Encryption: History-Free Update, Security Against Insiders, and Short Ciphertexts
Jae Hong Seo, Keita Emura |
CT-RSA | 2 |
| 2015 | Revocable Group Signature with Constant-Size Revocation ListabstractIt is essential that a multi-user cryptographic primitive be revocable since a legitimate user may quit the organization, or may act on malicious intent, or the relevant key may be leaked. In the group signature context, usually the group manager publishes the revocation list that contains revocation tokens. Since signers/verifiers need to obtain the revocation list in each revocation epoch to generate/verify a group signature, a small-size revocation list is really important in practice. However, all previous revocable group signatures require at least an |$O(r)$|-size revocation list, where |$r$| is the number of revoked users. In this paper, we propose the first revocable group signature scheme with a constant-size revocation list using identity-based revocation (IBR) techniques. We use an IBR scheme proposed by Attrapadung–Libert–Panafieu (PKC 2011) as a building block. As in the Libert–Peters–Yung schemes (EUROCRYPT 2012/CRYPTO 2012), no signing key update is required. In addition, the verification cost does not depend on the number of revoked users |$r$|. Although the maximum number of revoked users needs to be fixed in the setup phase, the maximum number of group members is potentially unbounded as in IBR. This property has not been achieved in the recent scalable revocable group signature schemes and seems to be of independent interest. Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001 |
Comput. J. | 2 |
| 2015 | Generic constructions of secure-channel free searchable encryption with adaptive securityabstractAbstract For searching keywords against encrypted data, public key encryption scheme with keyword search (PEKS), and its extension secure‐channel free PEKS (SCF‐PEKS), has been proposed. In this paper, we extend the security of SCF‐PEKS, calling it adaptive SCF‐PEKS, wherein an adversary (modeled as a “malicious‐but‐legitimate” receiver) is allowed to issue test queries adaptively. We show that adaptive SCF‐PEKS can be generically constructed by anonymous identity‐based encryption only. That is, SCF‐PEKS can be constructed without any additional cryptographic primitive when compared with the Abdallaet al.PEKS construction (J. Cryptology 2008), even though adaptive SCF‐PEKS requires additional functionalities. We also propose other adaptive SCF‐PEKS construction, which is not fully generic but is efficient compared with the first one. Finally, we instantiate an adaptive SCF‐PEKS scheme (via our second construction) that achieves a similar level of efficiency for the costs of the test procedure and encryption, compared with the (non‐adaptive secure) SCF‐PEKS scheme by Fanget al.(CANS2009). Copyright © 2014 John Wiley & Sons, Ltd. Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman, Kazumasa Omote |
Secur. Commun. Networks | 1 |
| 2014 | A Revocable Group Signature Scheme from Identity-Based Revocation Techniques: Achieving Constant-Size Revocation List
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001 |
ACNS | 2 |
| 2014 | A Privacy-Enhanced Access Log Management Mechanism in SSO Systems from Nominative SignaturesabstractIn online services, e.g., Online shopping, a service provider (SP) manages access logs containing customers' buying histories. Therefore, user's personal information, e.g., Their hobbies and diversions, is revealed from the exposed logs if each customer can be linked. In fact, such information exposure has occurred due to the popularization of online services. To cope with this problem, SPs may only have to delete access logs, but then no illegitimate users, who accessed the server illegally, will be traced from the logs. In this paper, we propose a log management mechanism where (1) no user information is revealed even if logs are exposed, but (2) illegitimate users can be traced when necessary. Specifically, we consider single sign on (SSO) systems, since plural access logs might be connected by one account, and this could trigger the above privacy infringement problem. We construct our privacy-enhanced access log management mechanism based on the Wang-Wang-Susilo SSO system (TrustCom 2013) which applies nominative signatures as its building block. Specifically, we realize the system by additionally applying the invisibility property of the Schuldt-Hanaoka nominative signature scheme (ACNS 2011). Finally, we estimate the efficiency of the proposed system by using Pairing-Based Cryptography (PBC) library and confirmed that for each algorithm, computation time is at most just over 80 milliseconds on a PC, which seems sufficiently practical. Sanami Nakagawa, Keita Emura, Goichiro Hanaoka, Akihisa Kodate, Takashi Nishide, Eiji Okamoto, Yusuke Sakai 0001 |
TrustCom | 2 |
| 2014 | A Secure Genetic Algorithm for the Subset Cover Problem and Its Application to Privacy Protection
Dan Bogdanov, Keita Emura, Roman Jagomägis, Akira Kanaoka, Shin'ichiro Matsuo, Jan Willemson |
WISTP | 2 |
| 2014 | Revocable hierarchical identity-based encryption
Jae Hong Seo, Keita Emura |
Theor. Comput. Sci. | 2 |
| 2014 | Revocable Identity-Based Cryptosystem Revisited: Security Models and ConstructionsabstractBoneh and Franklin gave a naive revocation method in identity-based encryption (IBE) which imposes a huge overhead into the key generation center. Later, Boldyreva, Goyal, and Kumar proposed an elegant way of achieving an IBE with efficient revocation, called revocable IBE (RIBE). In this paper, we revisit RIBE from the viewpoint of both security models and constructions. First, we introduce a realistic threat, which we call decryption key exposure, and show that all prior RIBE constructions, except the Boneh-Franklin one, are vulnerable to decryption key exposure. Next, we propose the first scalable RIBE scheme with decryption key exposure resistance by combining the (adaptively secure) Waters IBE scheme and the (selectively secure) Boneh-Boyen IBE scheme, and show that our RIBE scheme is more efficient than all previous adaptively secure scalable RIBE schemes. In addition, we extend our interest into identity-based signatures; we introduce a new security definition of revocable identity-based signature (RIBS) with signing key exposure resistance, and propose the first scalable RIBS scheme based on the Paterson-Schuldt IBS. Finally, we provide implementation results of our schemes to adduce the feasibility of our schemes. Jae Hong Seo, Keita Emura |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | A group signature scheme with unbounded message-dependent openingabstractGroup signature with message-dependent opening (GS-MDO) is a kind of group signature in which only the signers who have created group signatures on problematic messages will be identified. In the previous GS-MDO scheme, however, the number of problematic messages is bounded owing to a limitation of the Groth-Sahai proofs. In this paper, we propose the first GS-MDO scheme with the unbounded-MDO functionality in the random oracle model. Our unbounded GS-MDO scheme is based on the short group signature scheme proposed by Boneh, Boyen, and Shacham and the Boneh-Franklin identity-based encryption scheme. To combine these building blocks and to achieve CCA-anonymity, we also construct a special type of multiple encryption. This technique yields an efficient construction compared with the previous bounded GS-MDO scheme: the signature of our scheme contains about 16 group elements (3630 bits), whereas that of the previous scheme has about 450 group elements (75820 bits). Kazuma Ohara, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka |
AsiaCCS | 3 |
| 2013 | Efficient Delegation of Key Generation and Revocation Functionalities in Identity-Based Encryption
Jae Hong Seo, Keita Emura |
CT-RSA | 2 |
| 2012 | Group Signatures with Message-Dependent Opening
Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazumasa Omote |
Pairing | 2 |
| 2012 | Constructing Secure-channel Free Searchable Encryption from Anonymous IBE with Partitioned Ciphertext Structure
Keita Emura, Mohammad Shahriar Rahman |
SECRYPT | 1 |
| 2012 | Flexible Group Key Exchange with On-demand Computation of Subgroup Keys Supporting Subgroup Key Randomization
Keita Emura |
SECRYPT | 1 |
| 2011 | Toward Dynamic Attribute-Based Signcryption (Poster)
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman |
ACISP | 1 |
| 2011 | Non-interactive Opening for Ciphertexts Encrypted by Shared Keys
Jiageng Chen, Keita Emura, Atsuko Miyaji |
ICICS | 2 |
| 2011 | Ideal Secret Sharing Schemes with Share Selectability
Keita Emura, Atsuko Miyaji, Akito Nomura, Mohammad Shahriar Rahman, Masakazu Soshi |
ICICS | 1 |
| 2011 | Adaptive Secure-Channel Free Public-Key Encryption with Keyword Search Implies Timed Release Encryption
Keita Emura, Atsuko Miyaji, Kazumasa Omote |
ISC | 1 |
| 2010 | Efficient Privacy-Preserving Data Mining in Malicious Model
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman |
ADMA (1) | 1 |
| 2010 | An Anonymous Designated Verifier Signature Scheme with Revocation: How to Protect a Company's Reputation
Keita Emura, Atsuko Miyaji, Kazumasa Omote |
ProvSec | 1 |
| 2010 | A Timed-Release Proxy Re-encryption Scheme and Its Application to Fairly-Opened Multicast Communication
Keita Emura, Atsuko Miyaji, Kazumasa Omote |
ProvSec | 1 |
| 2009 | A Dynamic Attribute-Based Group Signature Scheme and its Application in an Anonymous Survey for the Collection of Attribute StatisticsabstractRecently, cryptographic schemes based on the user's attributes have been proposed. An attribute-based group signature (ABGS) scheme is a kind of group signature schemes, where a user with a set of attributes can prove anonymously whether she has these attributes or not. An access tree is applied to express the relationships among some attributes. However, previous schemes do not provide the changing an access tree. In this paper, we propose a dynamic ABGS scheme that enables an access tree to be changed. Our ABGS is efficient in that re-issuing of the attribute certificate previously issued for each user is not necessary. Moreover, calculations depending on the number of attributes are calculated on the domain of a pairing. Therefore, the number of calculations in a pairing does not depend on the number of attributes associated with a signature. Finally, we discuss how our ABGS can be applied to an anonymous survey for collection of attribute statistics. Keita Emura, Atsuko Miyaji, Kazumasa Omote |
ARES | 1 |
| 2009 | A Certificate Revocable Anonymous Authentication Scheme with Designated VerifierabstractIn IEEE ISI 2008, an anonymous attribute authentication scheme has been proposed using a self-blindable certificate scheme. This scheme enables the anonymity and certificate revocation. A Certificate Revocation List (CRL) is used in the revocation check. Even if an attacker can obtain a CRL, the attacker cannot execute the revocation check. This means that this scheme enables the designated revocation. However, this scheme is not secure, namely, a user can make a forged proof using a public value. In this paper, we propose a certificate revocable anonymous authentication scheme with designated verifier. Our scheme enables the anonymity and certificate revocation. Moreover, our scheme enables a designated verification and revocation. Keita Emura, Atsuko Miyaji, Kazumasa Omote |
ARES | 1 |
| 2009 | A Ciphertext-Policy Attribute-Based Encryption Scheme with Constant Ciphertext Length
Keita Emura, Atsuko Miyaji, Akito Nomura, Kazumasa Omote, Masakazu Soshi |
ISPEC | 1 |