VLDB 2026 Research / reviewers in the wild / expert
Masahiro Mambo
dblp:69/6508
· DBLP profile ↗
31ranked-venue papers
5as first author
9since 2021 · last 2026
0009-0006-3462-0699ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 5 first-author · 6 since 2021Theory of computation · 4 · 1 since 2021Computer networks · 2 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hierarchical identity-based encryption with receiver selective opening security in the multi-challenge settingabstractReceiver selective opening (RSO) security considers the security of encryption schemes under the scenario of a single sender and multiple receivers, where an adversary is allowed to adaptively corrupt some receivers’ secret keys. RSO security has been proven to be more secure than indistinguishability-based security notions. A lot of research has focused on RSO security in terms of public-key encryption and identity-based encryption (IBE); however, hierarchical IBE (HIBE), which is a generalization of IBE, is still lacking in the study, and how to obtain such a construction remains an open problem. To address this gap, we initiate a study of RSO security on HIBE in this work. Precisely, we first formalize the definition of simulation-based RSO against identity-chosen-plaintext/ciphertext attacks in the k-challenge setting (SIM-ID-RSO $$_k$$ -CPA/CCA) for HIBE. We then present generic SIM-ID-RSO $$_k$$ -CCA secure HIBE constructions by introducing the double secret key paradigm. Specifically, we show that a SIM-ID-RSO $$_k$$ -CCA secure HIBE scheme can be obtained from an IND-ID-CPA secure HIBE scheme as well as a one-time signature scheme that satisfies strong unforgeability. Through our general construction, we can derive various concrete schemes based on different hard assumptions (e.g., lattice-based and pairing-based SIM-ID-RSO $$_k$$ -CCA secure HIBE schemes) according to usage requirements. Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng |
Des. Codes Cryptogr. | 2 |
| 2026 | Public-key encryption with filtered equality test against adaptive chosen-ciphertext attacks
Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng |
Theor. Comput. Sci. | 2 |
| 2025 | Towards a Lattice-Based Non-interactive Aggregate Signature Scheme Following the Fiat-Shamir with Aborts Paradigm
Mingmei Zheng, Masahiro Mambo, Junzuo Lai, Xinyi Huang 0001 |
ISPEC | 2 |
| 2024 | Privacy-Enhanced Data Sharing Systems from Hierarchical ID-Based Puncturable Functional Encryption with Inner Product PredicatesabstractThe emergence of cloud computing enables users to upload data to remote clouds and compute them. This drastically reduces computing and storage costs for users. Considering secure computing for multilevel users in enterprises, the notion of hierarchical identity‐based inner product functional encryption (HIB‐IPFE) is proposed. In this cryptosystem, a sender can encrypt a vector into a ciphertext with a hierarchical identity, while a receiver who possesses a secret key corresponding to the same hierarchical identity and a vector can decrypt the ciphertext and obtain the inner product . However, HIB‐IPFE is not sufficient to capture flexible data sharing and forward security. In this study, we present a notion of hierarchical identity‐based puncturable HIBP‐IPFE. Furthermore, we present a formal definition and security model of HIBP‐IPFE to guarantee data confidentiality and receiver anonymity. Compared with HIB‐IPFE, our proposed scheme enables users to puncture keys on specific tags ensuring that the punctured keys cannot be used to decrypt the ciphertexts associated with those tags. The proposed scheme is provably secure under d ‐DBDHE assumption in the standard model. The experimental results indicate that our scheme is more practical in cloud computing, with superior functionality. Cheng-Yi Lee 0001, Zi-Yuan Liu, Masahiro Mambo, Raylin Tso |
IET Inf. Secur. | 3 |
| 2022 | Public-key Authenticated Encryption with Keyword Search: Cryptanalysis, Enhanced Security, and Quantum-resistant InstantiationabstractWith the rapid development of cloud computing, an increasing number of companies are adopting cloud storage technology to reduce overhead. However, to ensure the privacy of sensitive data, the uploaded data need to be encrypted before being outsourced to the cloud. The concept of public-key encryption with keyword search (PEKS) was introduced by Boneh et al. to provide flexible usage of the encrypted data. Unfortunately, most of the PEKS schemes are not secure against inside keyword guessing attacks (IKGA), so the keyword information of the trapdoor may be leaked to the adversary. To solve this issue, Huang and Li presented public key authenticated encryption with keyword search (PAEKS) in which the trapdoor generated by the receiver is only valid for authenticated ciphertexts. With their seminal work, many PAEKS schemes have been introduced for the enhanced security of PAEKS. Some of them further consider the upcoming quantum attacks. However, our cryptanalysis indicated that in fact, these schemes could not withstand IKGA. To fight against the attacks from quantum adversaries and support the privacy-preserving search functionality, we first introduce a novel generic PAEKS construction in this work. Then, we further present the first quantum-resistant PAEKS instantiation based on lattices. The security proofs show that our instantiation not only satisfies the basic requirements but also achieves enhanced security models, namely the multi-ciphertext indistinguishability and multi-trapdoor privacy. Furthermore, the comparative results indicate that with only some additional expenditure, the proposed instantiation provides more secure properties, making it suitable for more diverse application environments. Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001 |
AsiaCCS | 4 |
| 2022 | Public-Key Authenticated Encryption with Keyword Search: A Generic Construction and Its Quantum-Resistant InstantiationabstractAbstract The industrial Internet of Things (IIoT) integrates sensors, instruments, equipment and industrial applications, enabling traditional industries to automate and intelligently process data. To reduce the cost and demand of required service equipment, IIoT relies on cloud computing to further process and store data. Public-key encryption with keyword search (PEKS) plays an important role, due to its search functionality, to ensure the privacy and confidentiality of the outsourced data and the maintenance of flexibility in the use of the data. Recently, Huang and Li proposed the ‘public-key authenticated encryption with keyword search’ (PAEKS) to avoid the insider keyword guessing attacks (IKGAs) in the previous PEKS schemes. However, all current PAEKS schemes are based on the discrete logarithm assumption and are therefore vulnerable to quantum attacks. In this study, we first introduce a generic PAEKS construction, with the assistance of a trusted authority, that enjoys the security against IKGA in the standard model, if all building blocks are secure under standard model. Based on the framework, we further propose a novel instantiation of quantum-resistant PAEKS that is based on NTRU assumption under random oracle. Compared with its state-of-the-art counterparts, the experiment result indicates that our instantiation is more efficient and secure. Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001 |
Comput. J. | 4 |
| 2022 | Quantum-resistant anonymous identity-based encryption with trable identitiesabstractAbstract Identity‐based encryption (IBE), introduced by Shamir, eliminates the need for public‐key infrastructure. The sender can simply encrypt a message by using the recipient's identity (such as email or IP address) without needing to look up the public key. In particular, when ciphertexts of an IBE do not reveal recipient's identity, this scheme is known as an anonymous IBE scheme. Recently, Blazy et al. (ARES '19) analysed the trade‐off between public safety and unconditional privacy in anonymous IBE and introduced a new notion that incorporates traceability into anonymous IBE, called anonymous IBE with traceable identities (AIBET). However, their construction is based on the discrete logarithm assumption, which is insecure in the quantum era. In this paper, we first formalize the consistency of tracing key of the AIBET scheme to ensure that a ciphertext cannot be traced with the use of wrong tracing keys. Subsequently, we present a generic formulation concept that can be used to transform structure‐specific lattice‐based anonymous IBE schemes into an AIBET. Finally, we apply this concept to Katsumata and Yamada's compact anonymous IBE scheme (Asiacrypt '16) to obtain the first quantum‐resistant AIBET scheme that is adaptively secure under the ring learning with errors assumption without random oracle. Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001 |
IET Inf. Secur. | 4 |
| 2021 | Performance Comparison of Hybrid Encryption-based Access Control Schemes in NDNabstractThe newly emerging technologies and applications primarily focus on content distribution over the Internet, and a current host-centric TCP/IP Internet architecture becomes infeasible to fulfill this demand. Named Data Networking (NDN) is one of the most promising Future Internet architecture that facilitates a content-centric communication model over TCP/IP architecture. NDN supports in-network caching as the main characteristic that provides efficient scalability and minimum latency of content retrieval. Each NDN router possesses a content store table to cache the contents and directly serve the same requests in the future. Content can be cached anywhere in the NDN network, and content security and confidentiality become vital to prevent content access by unauthorized consumers. A hybrid encryption-based access control scheme has been proposed to address content confidentiality concerns by applying symmetric and identity-based proxy re-encryption schemes in NDN. However, it still requires further implementation and evaluation analyses with related schemes to prove that it offers a lower computational overhead and faster content retrieval time while protecting content confidentiality in NDN architecture. This paper conducts an additional experimental study on the scheme and shows some evidence about the reduction of the computational and communication time. Htet Htet Hlaing, Yuki Funamoto, Masahiro Mambo |
MSN | 3 |
| 2021 | Designated-ciphertext searchable encryption
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo |
J. Inf. Secur. Appl. | 4 |
| 2020 | Trapdoor Assignment of PEKS-based NDN Strategy in Two-Tier NetworksabstractNamed Data Networking (NDN), where addressable content name is used, is a candidate of next-generation Internet architectures. NDN routers use In-Network cache to replicate and store passing packets to make faster content delivery. NDN uses human-readable names, and therefore, it is easy for an attacker to guess which content is requested. To solve this issue, we have proposed the application of Public Key Encryption with Keyword Search (PEKS) to NDN and a PEKS-based NDN strategy has been developed for forwarding packets. Applying the PEKS scheme produces latency during transmission because of cryptographic operations. To reduce the number of such operations, we consider a network environment based on Two- Tier network design and examine different trapdoor assignments of PEKS-based NDN. We show some evidences that setting trapdoor storage only at core routers in Two-Tier network gives the reduction of the cryptographic operations. Kyi Thar Ko, Masahiro Mambo |
MSN | 2 |
| 2018 | Parallelizable Message Preprocessing for Merkle-Damgård Hash FunctionsabstractSince well-known hash functions sequentially process a message, the time for computing a digest strongly depends on the performance of a single processor. Even if multi-core processors are available, it is difficult to reduce the time. This paper focuses on designing a message preprocessing that can fully utilize multi-core processors. Since our message preprocessing can be efficiently computed by massively parallel processing, it contributes to reduce the time for computing a digest. The experiments using graphics processing units show that our message preprocessing improves the throughput for computing a digest. Hidenori Kuwakado, Shoichi Hirose, Masahiro Mambo |
ISITA | 3 |
| 2018 | Mobile edge computing, Fog et al.: A survey and analysis of security threats and challenges
Rodrigo Roman, Javier López 0001, Masahiro Mambo |
Future Gener. Comput. Syst. | 3 |
| 2015 | Certificateless aggregate signature with efficient verificationabstractCertificateless public key cryptography CL-PKC is a cryptosystem solving the key escrow problem of identity-based cryptography. One of the applications of CL-PKC is certificateless aggregate signature CLAS that in practice can be used to efficiently verify concealed data aggregation in wireless sensor networks. CLAS is referred to as an extension of certificateless signature, which in particular performs verification for many signatures efficiently. Therefore, not only plenty of CLAS schemes have been proposed but also the security models of CLAS were introduced in the literature. Recently, some CLAS schemes are extended from specific certificateless signature CLS schemes. However, we found that two certificateless signature CLS and their corresponding CLAS schemes are not secure. In this paper, we simplify the relation of security definitions of CLS and CLAS. Then, a new CLAS scheme is proposed, which leads to the advantages of both certificateless cryptography and aggregate signature. Moreover, our scheme only depends on constant pairing operations to verify a large number of signatures per time, because pairing is a complicated operation with high cost in computations. Copyright © 2014 John Wiley & Sons, Ltd. Yu-Chi Chen 0001, Raylin Tso, Masahiro Mambo, Kaibin Huang, Gwoboa Horng |
Secur. Commun. Networks | 3 |
| 2014 | A CDH-based ordered multisignature scheme in the standard model with better efficiency
Naoto Yanai, Masahiro Mambo, Eiji Okamoto |
ISITA | 2 |
| 2013 | An Ordered Multisignature Scheme Under the CDH Assumption Without Random Oracles
Naoto Yanai, Masahiro Mambo, Eiji Okamoto |
ISC | 2 |
| 2013 | Certificate-based proxy decryption systems with revocability in the standard model
Lihua Wang 0001, Jun Shao 0001, Zhenfu Cao, Masahiro Mambo, Akihiro Yamamura, Licheng Wang 0004 |
Inf. Sci. | 4 |
| 2010 | Identity-Based Proxy Cryptosystems with Revocability and Hierarchical Confidentialities
Lihua Wang 0001, Licheng Wang 0004, Masahiro Mambo, Eiji Okamoto |
ICICS | 3 |
| 2010 | A structured aggregate signature schemeabstractIn multisignature scheme, verifiying the signing order is sometimes very important. A multisignature scheme in which generated signatures reflect the structure of signers, e.g. signing order, is called structured multisignature scheme and many such schemes have been proposed so far. Structured multisignature schemes are dedicated to represent not only serial/parallel signer structures but also mixture of serial and parallel signer structures. In most structured schemes, the signature size depends on the number of signers. There are some structured schemes which can generate fixed-size signatures, but these schemes do not have order-flexibility, i.e. public keys arranged for one signer structure cannot be used for other signer structure. On the other hand, a sequential multisignature scheme is one type of structured multisignature schemes, which is dedicated to represent the serial signer structure. Some sequential multisig-nature scheme like sequential aggregate signature schemes can generate fixed-size signatures and have order-flexibility but no structured aggregate signature scheme has been proposed so far. In this paper, we construct a structured aggregate scheme which provides order-flexiblity, the fixed-size signature and applicability to mixed signer structures by extending the sequential aggregate signature scheme by Boldyreva et al. Naoto Yanai, Eikoh Chida, Masahiro Mambo |
ISITA | 3 |
| 2010 | New Identity-Based Proxy Re-encryption Schemes to Prevent Collusion Attacks
Lihua Wang 0001, Licheng Wang 0004, Masahiro Mambo, Eiji Okamoto |
Pairing | 3 |
| 2008 | Anonymous authentication and secure communication protocol for wireless mobile ad hoc networksabstractAbstract The main characteristic of a mobile ad hoc network (MANET) is its infrastructure‐less, highly dynamic topology, which is subject to malicious traffic analysis. Malicious intermediate nodes in MANETs are a threat concerning security as well as anonymity of exchanged information. In this paper, we propose an anonymous on‐demand routing protocol, called RINOMO, to protect anonymity and achieve security of nodes in MANETs. After successful authentication of the legitimate nodes in the network they can use their pseudo IDs for secure communication. Pseudo IDs of the nodes are generated considering pairing‐based cryptography. Nodes can generate their pseudo IDs independently and dynamically without consulting with system administrator. As a result, RINOMO reduces pseudo IDs maintenance costs. Only trust‐worthy nodes are allowed to take part in routing to discover a route. To ensure trustiness each node has to make authentication to its neighbors through the designed anonymous authentication process. Thus, RINOMO safely communicates between nodes without disclosing node identities. It also provides different desirable anonymous properties such as identity privacy, location privacy, route anonymity, and robustness against several attacks. Mathematical analysis of privacy loss is also evaluated and it shows there is no loss of privacy with respect to time. Thus, RINOMO is an anonymous robust protocol in MANETs. Copyright © 2008 John Wiley & Sons, Ltd. Sk. Md. Mizanur Rahman, Nidal Nasser, Atsuo Inomata, Takeshi Okamoto, Masahiro Mambo, Eiji Okamoto |
Secur. Commun. Networks | 5 |
| 2006 | Problems on the MR micropayment schemesabstractWe discuss the security of the MR schemes and especially point out the vulnerability of the MR3 scheme. The probabilistic deposit mechanism utilized in the MR3 scheme contributes to the reduction of the bank's processing cost. However, as shown in our paper, it also decreases the security of the entire scheme. Masahiro Mambo, Moisés Salinas-Rosales, Kazuo Ohta, Noboru Kunihiro |
AsiaCCS | 1 |
| 2003 | Rethinking Chosen-Ciphertext Security under Kerckhoffs' Assumption
Seungjoo Kim, Masahiro Mambo, Yuliang Zheng 0001 |
CT-RSA | 2 |
| 2001 | Evaluation of Tamper-Resistant Software Deviating from Structured Programming Rules
Hideaki Goto, Masahiro Mambo, Hiroki Shizuya, Yasuyoshi Watanabe |
ACISP | 2 |
| 2001 | Strong Adaptive Chosen-Ciphertext Attacks with Memory Dump (or: The Importance of the Order of Decryption and Validation)
Seungjoo Kim, Jung Hee Cheon, Marc Joye, Seongan Lim, Masahiro Mambo, Dongho Won, Yuliang Zheng 0001 |
IMACC | 5 |
| 2000 | On the Security of the RSA-Based Multisignature Scheme for Various Group Structures
Hiroshi Doi, Masahiro Mambo, Eiji Okamoto |
ACISP | 2 |
| 1998 | A User Identification System Using Signature Written with Mouse
Agus Fanar Syukri, Eiji Okamoto, Masahiro Mambo |
ACISP | 3 |
| 1997 | Protection of Data and Delegated Keys in Digital Distribution
Masahiro Mambo, Eiji Okamoto, Kouichi Sakurai |
ACISP | 1 |
| 1997 | Proposal of user identification scheme using mouse
Kenichi Hayashi, Eiji Okamoto, Masahiro Mambo |
ICICS | 3 |
| 1997 | A tentative approach to constructing tamper-resistant softwareabstractSo far tamper-resistance has been considered as a property such as information stored in (I device is hard to read or modify by tampering.Such tamper-resistance is quite important in many situations: superdistribution, electronic commerce systems using IC card, pay television systems with decoders containing secret values for descrambling image and so on.Tamper-resistance ensures proper operation of a program and prevents extraction of secret data and abuse of the program.Moreover, tamper-resistance enables a vendor to enforce his own conditions upon users.A new notion of tamper-resistance is stated as follows.Tamper-resistance means a property such as information stored in a device or software is hard to read or modify by tampering.A tamper-resistant device is usually expensive and not easy to handle compared with its realization in software.It is better to achieve tamperresistance without relying on any physical device.Meanwhile, intellectual property rights for a software program can be easily violated once an attacker analyzes the algorithm of a target program.The attacker can create a distinct program which looks quite different but functions just as the target program does.It is very important for software programs to be protected from any reverse engineering and manipulation.From these observations we study methods to generate a tamper-resistant code and explain an elementary tool, aO/fl/f2/f3.It replaces and shuffles operational codes or inserts reproductive dummy codes in a program so that t,he output becomes hard to read.After Masahiro Mambo, Takanori Murayama, Eiji Okamoto |
NSPW | 1 |
| 1996 | How to Utilize the Transformability of Digital Signatures for Solving the Oracle Problem
Masahiro Mambo, Kouichi Sakurai, Eiji Okamoto |
ASIACRYPT | 1 |
| 1996 | Proxy Signatures for Delegating Signing OperationabstractIn this paper a new type of digital proxy signature is proposed.The proxy signature allows a designated person, called a proxy signer, to sign on behalf of an original signer.Classification of the proxy signatures is shown from the point of view of the degree of delegation, and conditions of a proposed proxy signature for partial delegation are clarified.The proposed proxy signature scheme is based on the discrete logarithm problem.Compared to the consecutive execution of the ordinary digital signature schemes, it has a direct form, and a verifier does not need a public key of a user other than the original signer in the verification stage.Moreover, it requires less amount of computational work than the consecutive execution of the signature schemes.Due to this efficiency together with the delegation property, an organization, e.g. a software company, can very efficiently create many signatures of its own by delegating its signing operations to multiple employees.Another attractive feature of the proposed schemes is their highapplicability to other ordinary signature schemes based on the discrete logarithm problem.For instance, designated confirmer proxy signatures can be constructed.Furthermore, using a proposed on-line proxy updating protocol, the original signer can revoke proxies of dishonest proxy signers. Masahiro Mambo, Keisuke Usuda, Eiji Okamoto |
CCS | 1 |