VLDB 2026 Research / reviewers in the wild / expert
Ron Steinfeld
dblp:71/625
· DBLP profile ↗
100ranked-venue papers
11as first author
36since 2021 · last 2026
0000-0003-1745-4183ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 88 · 9 first-author · 32 since 2021Theory of computation · 6 · 1 first-authorSystems, architecture and hardware · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lattice-Based Ring Verifiable Random Functions
Jie Xu 0065, Muhammed F. Esgin, Ron Steinfeld |
ACISP (3) | 3 |
| 2026 | LeOPaRd: Towards Practical Post-quantum Oblivious PRFs via 2HashDH Paradigm
Muhammed F. Esgin, Ron Steinfeld, Erkan Tairi, Jie Xu 0065 |
CRYPTO (3) | 2 |
| 2026 | PQCIP: A Post-Quantum Cryptography Educational Program for Cybersecurity ProfessionalsabstractIn 2023, the National Institute of Standards and Technology (NIST) announced its post-quantum cryptography (PQC) standards; CRYSTALS-Dilithium, Falcon and SPHINCS+ as digital signatures and CRYSTALS-Kyber as the key-encapsulation mechanism (KEM) (or put simply, encryption). These PQC standards are to replace today’s quantum-vulnerable cryptography algorithms, currently securing digital systems, to protect against emerging quantum computing threats. One of the main challenges in transitioning into such standards is to educate the current and future IT/Cybersecurity workforce about PQC, particularly around the practical aspects. In particular, the original proposers of the selected algorithms only provided the reference (and optimized) software implementations of them. The final NIST standard specifications will only be equipped with mathematical explanations and test vectors. Hence, there are not many custom-designed educational content, assessment, and practical tools for PQC. In this experience paper, we introduce and discuss our PQC educational program, PQCIP, targeted at industry and governmental IT/Cybersecurity professionals. PQCIP has significantly contributed to its participants’ learning and engagement by providing tailored high-quality content, hands-on assessments, and strategic planning, making them ready to develop evaluated transition plans for their organizations and/or governments. We have also created custom software interfaces for CRYSTALS-Kyber, the NIST PQC standard for KEM. Using the developed interface along with Open Quantum Safe (OQS) software library for OpenSSL, we bridge a gap in available educational tools for PQC training. This tool has been shown to enhance the participants’ understanding of PQC’s practical applications and improve their engagement with highly technical cryptographic contents. Ron Steinfeld, Muhammed F. Esgin, Nikai Jagganath, Amin Sakzad, Carsten Rudolph, James Boorman |
SIGCSE (1) | 1 |
| 2025 | Plum: SNARK-Friendly Post-Quantum Signature Based on Power Residue PRFs
Xinyu Zhang 0017, Qishuang Fu, Ron Steinfeld, Joseph K. Liu, Tsz Hon Yuen, Man Ho Au |
ProvSec | 3 |
| 2025 | Constant Latency and Finality for Dynamically Available DAGabstractDirected Acyclic Graph (DAG) based protocols have shown great promise to improve the performance of blockchains. The CAP theorem shows that it is impossible to have a single system that achieves both liveness (known as dynamic availability) and safety under network partition. This paper explores two types of DAG-based protocols prioritizing liveness or safety, named structured dissemination and Graded Common Prefix (GCP), respectively. For the former, we introduce the first DAG-based protocol with constant expected latency, providing high throughput dynamic availability under the sleepy model. Its expected latency is 3Δ and its throughput linearly scales with participation. We validate these expected performance improvements over existing constant latency sleepy model BFT by running prototypes of each protocol across multiple machines. The latter, GCP, is a primitive that provides safety under network partition, while being weaker than standard consensus. As a result, we are able to obtain a construction that runs in only 2 communication steps, as opposed to the 4 steps of existing low latency partially synchronous BFT. In addition, GCP can easily avoid relying on single leaders' proposals, becoming more resilient to crashes. We also validate these theoretical benefits of GCP experimentally. We leverage our findings to extend the Ebb-and-Flow framework, where two BFT sub-protocols allow different types of clients in the same system to prioritize either liveness or safety. Our extension integrates our two types of DAG-based protocols. This provides a hybrid DAG-based protocol with high throughput, dynamical availability, and finality under network partitions, without running a standard consensus protocol twice as required in existing work. Hans Schmiedel, Runchao Han, Qiang Tang 0005, Ron Steinfeld, Jiangshan Yu |
SP | 4 |
| 2025 | Formal Treatment of Watchtowers and FPPW: A Fair and Privacy-Preserving Bitcoin WatchtowerabstractThis article formalises watchtower and its different properties includingagility,privacyagainst both watchtower and third parties,fairnesswith respect to both watchtower and its client andcoverage. We also evaluate the existing schemes regarding these properties and show they cannot achieve all properties altogether. Furthermore, we prove that there is a trade-off between the level of fairness that a watchtower provides to its clients and the coverage it can achieve. We also introduce FPPW, the first Fair and Privacy-Preserving Watchtower for Bitcoin. This new scheme provides fairness with respect to all channel participants including both channel parties and the watchtower. It means the funds of any honest channel participants are safe even assuming that the other two participants are corrupted and/or collude with each other. Furthermore, the watchtower in FPPW learns no information about the off-chain transactions and hence FPPW provides privacy against the watchtower. We also show that FPPW coverage, i.e., the total capacity of channels that an FPPW watchtower can cover, is higher than that of PISA and Cerberus and FPPW can be implemented without any update in the Bitcoin script. Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | DualRing-PRF: Post-quantum (Linkable) Ring Signatures from Legendre and Power Residue PRFs
Xinyu Zhang 0017, Ron Steinfeld, Joseph K. Liu, Muhammed F. Esgin, Dongxi Liu, Sushmita Ruj |
ACISP (2) | 2 |
| 2024 | LUNA: Quasi-Optimally Succinct Designated-Verifier Zero-Knowledge Arguments from LatticesabstractWe introduce the first candidate Lattice-based designated verifier (DV) zero knowledge sUccinct Non-interactive Argument (ZK-SNARG) protocol, named LUNA, with quasi-optimal proof length (quasi-linear in the security/privacy parameter). By simply relying on mildly stronger security assumptions, LUNA is also a candidate ZK-SNARK (i.e. argument of knowledge). LUNA achieves significant improvements in concrete proof sizes, reaching below 6 KB (compared to >32 KB in prior work) for 128-bit security/privacy level. To achieve our quasi-optimal succinct LUNA, we give a new regularity result for 'private' re-randomization of Module LWE (MLWE) samples using discrete Gaussian randomization vectors, also known as a lattice-based leftover hash lemma with leakage, which applies with a discrete Gaussian re-randomization parameter that is polynomial in the statistical privacy parameter (avoiding exponential smudging), and hides the coset of the re-randomization vector support set. Along the way, we derive bounds on the smoothing parameter of the intersection of short integer solution (SIS), gadget, and Gaussian perp module lattices over the power of 2 cyclotomic rings. We then introduce a new candidate linear-only homomorphic encryption scheme called Module Half-GSW (HGSW), and apply our regularity theorem to provide smudging-free circuit-private homomorphic linear operations for Module HGSW. Our implementation and experimental performance evaluation show that, for typical instance sizes, Module HGSW provides favourable performance for ZK-SNARG applications involving lightweight verifiers. It enables significantly (around 5x) shorter proof lengths while speeding up CRS generation and encryption time by 4-16x and speeding up decryption time by 4.3x, while incurring just 1.2-2x time overhead in linear homomorphic proof generation operations, compared to a Regev encryption used in prior work in the ZK-SNARG context. We believe our techniques are of independent interest and will find application in other privacy-preserving lattice-based protocols. Ron Steinfeld, Amin Sakzad, Muhammed F. Esgin, Veronika Kuchta, Mert Yassi, Raymond K. Zhao |
CCS | 1 |
| 2024 | Loquat: A SNARK-Friendly Post-quantum Signature Based on the Legendre PRF with Applications in Ring and Aggregate Signatures
Xinyu Zhang 0017, Ron Steinfeld, Muhammed F. Esgin, Joseph K. Liu, Dongxi Liu, Sushmita Ruj |
CRYPTO (1) | 2 |
| 2024 | Modeling Mobile Crash in Byzantine ConsensusabstractTargeted Denial-of-Service (DoS) attacks have been a practical concern for permissionless blockchains. Potential solutions, such as random sampling, are adopted by blockchains. However, the associated security guarantees have only been informally discussed in prior work. This is due to the fact that existing adversary models are either not fully capturing this attack or giving up certain design choices (as in the sleepy model or asynchronous network model), or too strong to be practical (as in the mobile Byzantine adversary model). This paper provides theoretical foundations and desired properties for consensus protocols that resist against targeted DoS attacks. In particular, we define the Mobile Crash Adaptive Byzantine (MCAB) model to capture such an attack. In addition, we identify and formalize two properties for consensus protocols under the MCAB model, and analyze their trade-offs. As case studies, we prove that Ouroboros Praos and Algorand are secure in our MCAB model, giving the first formal proofs supporting their security guarantee against targeted DoS attacks, which were previously only informally discussed. We also illustrate an application of our properties to secure a streamlined BFT protocol, chained Hotstuff, against targeted DoS attacks. Hans Schmiedel, Runchao Han, Qiang Tang 0005, Ron Steinfeld, Jiangshan Yu |
CSF | 4 |
| 2024 | Plover: Masking-Friendly Hash-and-Sign Lattice Signatures
Muhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest, Amin Sakzad, Ron Steinfeld |
EUROCRYPT (6) | 6 |
| 2024 | Fast and private multi-dimensional range search over encrypted dataabstractFor businesses looking to outsource their data to remote servers, cloud-based data storage is a popular choice. It is popular due to its flexibility, cost-effectiveness, and widespread availability. However, ensuring the confidentiality of data is a critical challenge that must be addressed. As a response to this issue, searchable encryption techniques have been developed. These techniques enable search queries to be performed on encrypted data while still keeping the plaintext confidential. While most existing symmetric searchable encryption schemes are designed for one-dimensional data records or document-keyword inverted indices, this paper introduces MDRSSE, a novel symmetric searchable encryption scheme specifically tailored for multi-dimensional range search. MDRSSE stands out as one of the pioneering SSE schemes to support multi-dimensional range search efficiently, without incurring undetermined additional communication or computation costs. By employing a single round of communication between the client and server, MDRSSE enables an honest-but-curious server to respond to multi-dimensional range queries without gaining knowledge of the data records or revealing the search query. Notably, MDRSSE boasts the lowest overall search complexity compared to existing state-of-the-art symmetric searchable encryption schemes designed for multi-dimensional range search. Extensive experimental tests were conducted to validate the robustness and practicality of our proposed scheme. The results demonstrate that, for a dataset consisting of 100K records with 12 dimensions (with each leaf node holding 500 records), it takes only 2.2 seconds to generate the encrypted dataset, and the overall setup phase completes within 2.5 seconds. Furthermore, for a range query encompassing 50 nodes, the search time is less than 2 ms and 3 ms for the client and server, respectively. MDRSSE achieves semantic security under the IND-CPA assumption, all without requiring additional storage size at the server. Shabnam Kasra Kermanshahi, Ron Steinfeld, Xun Yi, Joseph K. Liu, Surya Nepal, Junwei Lou |
Inf. Sci. | 2 |
| 2024 | Quantum-Safe HIBE: Does It Cost a Latte?abstractThe United Kingdom (UK) government is considering advanced primitives such as identity-based encryption (IBE) for adoption as they transition their public-safety communications network from TETRA to an LTE-based service. However, the current LTE standard relies on elliptic-curve-based IBE, which will be vulnerable to quantum computing attacks, expected within the next 20–30 years. Lattices can provide quantum-safe alternatives for IBE. These schemes have shown promising results in terms of practicality. To date, several IBE schemes over lattices have been proposed, but there has been little in the way of practical evaluation. This paper provides the first complete optimised practical implementation and benchmarking of Latte, a promising Hierarchical IBE (HIBE) scheme proposed by the UK National Cyber Security Centre (NCSC) in 2017 and endorsed by European Telecommunications Standards Institute (ETSI). We propose optimisations for the KeyGen, Delegate, Extract and Gaussian sampling components of Latte, to increase attack costs, reduce decryption key lengths by 2x–3x, ciphertext sizes by up to 33%, and improve speed. In addition, we conduct a precision analysis, bounding the Rényi divergence of the distribution of the real Gaussian sampling procedures from the ideal distribution in corroboration of our claimed security levels. Our resulting implementation of the Delegate function takes 0.4 seconds at 80-bit security level on a desktop machine at 4.2GHz, significantly faster than the order of minutes estimated in the ETSI technical report. Furthermore, our optimised Latte Encrypt/Decrypt implementation reaches speeds up to 9.7x faster than the ETSI implementation. Raymond K. Zhao, Sarah McCarthy, Ron Steinfeld, Amin Sakzad, Máire O'Neill |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | High Throughput Lattice-Based Signatures on GPUs: Comparing Falcon and MitakaabstractThe US National Institute of Standards and Technology initiated a standardization process for post-quantum cryptography in 2017, with the aim of selecting key encapsulation mechanisms and signature schemes that can withstand the threat from emerging quantum computers. In 2022, Falcon was selected as one of the standard signature schemes, eventually attracting effort to optimize the implementation of Falcon on various hardware architectures for practical applications. Recently, Mitaka was proposed as an alternative to Falcon, allowing parallel execution of most of its operations. These recent advancements motivate us to develop high throughput implementations of Falcon and Mitaka signature schemes on Graphics Processing Units (GPUs), a massively parallel architecture widely available on cloud service platforms. In this paper, we propose the first parallel implementation of Falcon on various GPUs. An iterative version of the sampling process in Falcon, which is also the most time-consuming Falcon operation, was developed. This allows us to implement Falcon signature generation without relying on expensive recursive function calls on GPUs. In addition, we propose a parallel random samples generation approach to accelerate the performance of Mitaka on GPUs. We evaluate our implementation techniques on state-of-the-art GPU architectures (RTX 3080, A100, T4 and V100). Experimental results show that our Falcon-512 implementation achieves 58,595 signatures/second and 2,721,562 verifications/second on an A100 GPU, which is$20.03\times$and$29.51\times$faster than the highly optimized AVX2 implementation on CPU. Our Mitaka implementation achieves 161,985 signatures/second and 1,421,046 verifications/second on the same GPU. Due to the adoption of a parallelizable sampling process, Mitaka signature generation enjoys$\approx 2$–$20 \times$higher throughput than Falcon on various GPUs. The high throughput signature generation and verification achieved by this work can be very useful in various emerging applications, including the Internet of Things. Wai-Kong Lee, Raymond K. Zhao, Ron Steinfeld, Amin Sakzad, Seong Oun Hwang |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2023 | A New Look at Blockchain Leader Election: Simple, Efficient, Sustainable and Post-QuantumabstractIn this work, we study the blockchain leader election problem. The purpose of such protocols is to elect a leader who decides on the next block to be appended to the blockchain, for each block proposal round. Solutions to this problem are vital for the security of blockchain systems. We introduce an efficient blockchain leader election method with security based solely on standard assumptions for cryptographic hash functions (rather than public-key cryptographic assumptions) and that does not involve a racing condition as in Proof-of-Work based approaches. Thanks to the former feature, our solution provides the highest confidence in security, even in the post-quantum era. A particularly scalable application of our solution is in the Proof-of-Stake setting, and we investigate our solution in the Algorand blockchain system. We believe our leader election approach can be easily adapted to a range of other blockchain settings. Muhammed F. Esgin, Oguzhan Ersoy, Veronika Kuchta, Julian Loss, Amin Sakzad, Ron Steinfeld, Xiangwen Yang, Raymond K. Zhao |
AsiaCCS | 6 |
| 2023 | Energy Consumption Evaluation of Post-Quantum TLS 1.3 for Resource-Constrained Embedded DevicesabstractPost-Quantum cryptography (PQC), in the past few years, constitutes the main driving force of the quantum resistance transition for security primitives, protocols and tools. TLS is one of the widely used security protocols that needs to be made quantum safe. However, PQC algorithms integration into TLS introduce various implementation overheads compared to traditional TLS that in battery powered embedded devices with constrained resources, cannot be overlooked. While there exist several works, evaluating the PQ TLS execution time overhead in embedded systems there are only a few that explore the PQ TLS energy consumption cost. In this paper, a thorough power/energy consumption evaluation and analysis of PQ TLS 1.3 on embedded systems has been made. A WolfSSL PQ TLS 1.3 custom implementation is used that integrates all the NIST PQC algorithms selected for standardisation as well as 2 out of 3 of those evaluated in NIST Round 4. Also 1 out of 2 of the BSI recommendations have been included. The PQ TLS 1.3 with the various PQC algorithms is deployed in a STM Nucleo evaluation board under a mutual and a unilateral client-server authentication scenario. The power and energy consumption collected results are analyzed in detail. The performed comparisons and overall analysis provide very interesting results indicating that the choice of the PQC algorithms in TLS 1.3 to be deployed on an embedded system may be very different depending on the device use as an authenticated or not authenticated, client or server. Also, the results indicate that in some cases, PQ TLS 1.3 implementations can be equally or more energy consumption efficient compared to traditional TLS 1.3. George Tasopoulos, Charis Dimopoulos, Apostolos P. Fournaris, Raymond K. Zhao, Amin Sakzad, Ron Steinfeld |
CF | 6 |
| 2023 | Efficient Hybrid Exact/Relaxed Lattice Proofs and Applications to Rounding and VRFs
Muhammed F. Esgin, Ron Steinfeld, Dongxi Liu, Sushmita Ruj |
CRYPTO (5) | 2 |
| 2023 | Guest editorial: Special issue on Mathematics of Zero-Knowledge
Steven D. Galbraith, Rosario Gennaro, Carla Ràfols, Ron Steinfeld |
Des. Codes Cryptogr. | 4 |
| 2023 | Incremental symmetric puncturable encryption with support for unbounded number of punctures
Shifeng Sun 0001, Ron Steinfeld, Amin Sakzad |
Des. Codes Cryptogr. | 2 |
| 2022 | An Injectivity Analysis of Crystals-Kyber and Implications on Quantum Security
Muhammed F. Esgin, Amin Sakzad, Ron Steinfeld |
ACISP | 4 |
| 2022 | Garrison: A Novel Watchtower Scheme for Bitcoin
Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
ACISP | 4 |
| 2022 | Post-quantum ID-Based Ring Signatures from Symmetric-Key Primitives
Maxime Buser, Joseph K. Liu, Ron Steinfeld, Amin Sakzad |
ACNS | 3 |
| 2022 | Performance Evaluation of Post-Quantum TLS 1.3 on Resource-Constrained Embedded Systems
George Tasopoulos, Apostolos P. Fournaris, Raymond K. Zhao, Amin Sakzad, Ron Steinfeld |
ISPEC | 6 |
| 2022 | Daric: A Storage Efficient Payment Channel with Punishment Mechanism
Arash Mirzaei, Amin Sakzad, Jiangshan Yu, Ron Steinfeld |
ISC | 4 |
| 2022 | MatRiCT+: More Efficient Post-Quantum Private Blockchain PaymentsabstractWe introduce MatRiCT+, a practical private blockchain payment protocol based on “post-quantum” lattice assumptions. MatRiCT+builds on MatRiCT due to Esgin et al. (ACM CCS’19) and, in general, follows the Ring Confidential Transactions (RingCT) approach used in Monero, the largest privacy-preserving cryptocurrency. In terms of the practical aspects, MatRiCT+has 2-18× shorter proofs (depending on the number of input accounts, M) and runs 3-11× faster (for a typical transaction) in comparison to MatRiCT. A significant advantage of MatRiCT+is that the proof length’s dependence on M is very minimal (only O(logM)), while MatRiCT has a proof length linear in M. To support its efficiency, we devise several novel techniques in our design of MatRiCT+to achieve compact lattice-based zeroknowledge proof systems, exploiting the algebraic properties of power-of-2 cyclotomic rings commonly used in practical latticebased cryptography. Along the way, we design a family of “optimal” challenge spaces, using a technique we call partition-and-sample, with minimal $\ell_{1}$-norm and invertible challenge differences (with overwhelming probability), while supporting highly-splitting power-of-2 cyclotomic rings. We believe all these results to be widely applicable and of independent interest. Muhammed F. Esgin, Ron Steinfeld, Raymond K. Zhao |
SP | 2 |
| 2022 | Vandermonde meets Regev: public key encryption schemes based on partial Vandermonde problems
Katharina Boudgoust, Amin Sakzad, Ron Steinfeld |
Des. Codes Cryptogr. | 3 |
| 2022 | Range search on encrypted spatial data with dynamic updatesabstractDriven by the cloud-first initiative taken by various governments and companies, it has become a common practice to outsource spatial data to cloud servers for a wide range of applications such as location-based services and geographic information systems. Searchable encryption is a common practice for outsourcing spatial data which enables search over encrypted data by sacrificing the full security via leaking some information about the queries to the server. However, these inherent leakages could equip the server to learn beyond what is considered in the scheme, in the worst-case allowing it to reconstruct of the database. Recently, a novel form of database reconstruction attack against such kind of outsourced spatial data was introduced (Markatou and Tamassia, IACR ePrint 2020/284), which is performed using common leakages of searchable encryption schemes, i.e., access and search pattern leakages. An access pattern leakage is utilized to achieve an order reconstruction attack, whereas both access and search pattern leakages are exploited for the full database reconstruction attack. In this paper, we propose two novel schemes for outsourcing encrypted spatial data supporting dynamic range search. Our proposed schemes leverage R+tree to partition the dataset and binary secret sharing to support secure range search. They further provide backward and content privacy and do not leak the access pattern, therefore being resilient against the above mentioned database reconstruction attacks. The evaluations and results on the real-world dataset demonstrate the practicality of our schemes, due to (a) the minimal round-trip between the client and server, and (b) the low computation and storage overhead on the client side. Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi, Shangqi Lai |
J. Comput. Secur. | 3 |
| 2022 | Geometric Range Search on Encrypted Data With Forward/Backward SecurityabstractThis article presents two dynamic symmetric searchable encryption schemes for geometric range search. Our constructions are the first to provide forward/backward security in the context of SSE-based schemes supporting geometric range search. Besides, we define a security notion called content privacy. This security notion captures the leakages that are critical in the context of geometric range search but not considered by forward/backward security. Content privacy eliminates the leakage on the updated points of the database during both search and update. Due to the inherent leakages associated with range queries, none of the existing related works can support content privacy, whereas the design of our constructions avoids such leakages. When compared to the state-of-the-art schemes, our constructions provide a higher level of security and practical efficiency supported by our experimental results. Shabnam Kasra Kermanshahi, Shifeng Sun 0001, Joseph K. Liu, Ron Steinfeld, Surya Nepal, Wang Fat Lau, Man Ho Au |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Practical Encrypted Network Traffic Pattern Matching for Secure MiddleboxesabstractNetwork Function Virtualisation (NFV) advances the adoption of composable software middleboxes. Accordingly, cloud data centres become major NFV vendors for enterprise traffic processing. Due to the privacy concern of traffic redirection to the cloud, secure middlebox systems (e.g., BlindBox) draw much attention; they can process encrypted packets against encrypted rules directly. However, most of the existing systems supporting pattern matching based network functions require the enterprise gateway to tokenise packet payloads via sliding windows. Such tokenisation induces a considerable communication overhead, which can be over 100× to the packet size. To overcome this bottleneck, in this article, we propose the first bandwidth-efficient encrypted pattern matching protocol for secure middleboxes. We resort to a primitive called symmetric hidden vector encryption (SHVE), and propose a variant of it, aka SHVE+, to achieve constant and moderate communication cost. To speed up, we devise encrypted filters to reduce the number of accesses to SHVE+ during matching highly. We formalise the security of our proposed protocol and conduct comprehensive evaluations over real-world rulesets and traffic dumps. The results show that our design can inspect a packet over 20 k rules within 100$\mu$s. Compared to prior work, it brings a saving of 94 percent in bandwidth consumption. Shangqi Lai, Xingliang Yuan, Shifeng Sun 0001, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, Dongxi Liu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Non-Interactive Multi-Client Searchable Encryption: Realization and ImplementationabstractIn this article, we introduce a new mechanism for constructing multi-client searchable encryption (SE). By tactfully leveraging the RSA-function, we propose the first multi-client SE protocol that successfully avoids per-query interaction between data owner and client. Therefore, our approach significantly reduces the communication cost by eliminating the need for data owner to authorize client queries at all times. To be compatible with the RSA-based approach, we also present a deterministic and memory-efficient ‘keyword to prime’ hash function, which may be of independent interest. Further, to improve efficiency, we put forward a more generic construction from set-constrained PRFs. The construction not only inherits the merits of our first protocol, but also achieves an enhanced security (against untrusted clients), where colluding attack among clients is also taken into account. Both protocols are instantiated via the recent representative SE protocol by Cashet al.with the support of boolean queries. At last, we implement our proposed protocols and comprehensively evaluate their performance to demonstrate their practicability and scalability. Shifeng Sun 0001, Cong Zuo 0001, Joseph K. Liu, Amin Sakzad, Ron Steinfeld, Tsz Hon Yuen, Xingliang Yuan, Dawu Gu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Transparency or Anonymity Leak: Monero Mining Pools Data Publication
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu |
ACISP | 3 |
| 2021 | Geo-DRS: Geometric Dynamic Range Search on Spatial Data with Backward and Content Privacy
Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi |
ESORICS (2) | 3 |
| 2021 | A Non-interactive Multi-user Protocol for Private Authorised Query Processing on Genomic Data
Sara Jafarbeiki, Amin Sakzad, Shabnam Kasra Kermanshahi, Ron Steinfeld, Raj Gaire 0001, Shangqi Lai |
ISC | 4 |
| 2021 | Practical Non-Interactive Searchable Encryption with Forward and Backward Privacy
Shifeng Sun 0001, Ron Steinfeld, Shangqi Lai, Xingliang Yuan, Amin Sakzad, Joseph K. Liu, Surya Nepal, Dawu Gu |
NDSS | 2 |
| 2021 | Lattice-based zero-knowledge arguments for additive and multiplicative relations
Veronika Kuchta, Amin Sakzad, Ron Steinfeld, Joseph K. Liu |
Des. Codes Cryptogr. | 3 |
| 2021 | Multi-Client Cloud-Based Symmetric Searchable EncryptionabstractWe propose a multi-client Symmetric Searchable Encryption (SSE) scheme based on the single-user protocol [3] . The scheme allows any user to generate a search query by interacting with any θ is a threshold parameter) `helping' users. It preserves the privacy of a database content against the server assuming a leakage of up to θ-1 users' keys to the server while hiding the query from the θ-1 `helping users'. To achieve the query privacy, we design a new distributed key-homomorphic pseudorandom function (PRF) that hides the PRF input (search keyword) from the `helping' users. We present a concrete construction of our randomizable distributed PRF. By distributing the utilized keys among the users, the need for a constant online presence of the data owner to provide services to the users is eliminated, while providing resilience against a user key exposure. We extended our scheme to support user revocation in two different scenarios. In addition, we give a solution for fast update of the encryption key with the overhead significantly smaller than the re-encryption and re-uploading the database. Moreover, our scheme is secure against passive and active collusion between the server and a subset of users. Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld, Surya Nepal, Shangqi Lai, Randolph Loh, Cong Zuo 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Measure-Rewind-Measure: Tighter Quantum Random Oracle Model Proofs for One-Way to Hiding and CCA Security
Veronika Kuchta, Amin Sakzad, Damien Stehlé, Ron Steinfeld, Shifeng Sun 0001 |
EUROCRYPT (3) | 4 |
| 2020 | COSAC: COmpact and Scalable Arbitrary-Centered Discrete Gaussian Sampling over Integers
Raymond K. Zhao, Ron Steinfeld, Amin Sakzad |
PQCrypto | 2 |
| 2020 | Efficient Lattice-Based Polynomial Evaluation and Batch ZK Arguments
Veronika Kuchta, Amin Sakzad, Ron Steinfeld, Joseph K. Liu |
SAC | 3 |
| 2020 | FACCT: FAst, Compact, and Constant-Time Discrete Gaussian Sampler over IntegersabstractThe discrete Gaussian sampler is one of the fundamental tools in implementing lattice-based cryptosystems. However, a naive discrete Gaussian sampling implementation suffers from side-channel vulnerabilities, and the existing countermeasures usually introduce significant overhead in either the running speed or the memory consumption. In this paper, we propose a fast, compact, and constant-time implementation of the binary sampling algorithm, originally introduced in the BLISS signature scheme. Our implementation adapts the Rényi divergence and the transcendental function polynomial approximation techniques. The efficiency of our scheme is independent of the standard deviation, and we show evidence that our implementations are either faster or more compact than several existing constant-time samplers. In addition, we show the performance of our implementation techniques applied to and integrated with two existing signature schemes: qTesla and Falcon. On the other hand, the convolution theorems are typically adapted to sample from larger standard deviations, by combining samples with much smaller standard deviations. As an additional contribution, we show better parameters for the convolution theorems. Raymond K. Zhao, Ron Steinfeld, Amin Sakzad |
IEEE Trans. Computers | 2 |
| 2019 | Lattice RingCT V2.0 with Multiple Input and Multiple Output Wallets
Wilson Abel Alberto Torres, Veronika Kuchta, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Jacob Cheng |
ACISP | 3 |
| 2019 | Risk of Asynchronous Protocol Update: Attacks to Monero Protocols
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu |
ACISP | 3 |
| 2019 | Short Lattice-Based One-out-of-Many Proofs and Applications to Ring Signatures
Muhammed F. Esgin, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Dongxi Liu |
ACNS | 2 |
| 2019 | Designing Smart Contract for Electronic Document Taxation
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Fengkie Junis, Dony Ariadi Suwarsono |
CANS | 3 |
| 2019 | Senarai: A Sustainable Public Blockchain-Based Permanent Storage Protocol
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Limerlina |
CANS | 3 |
| 2019 | MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions ProtocolabstractWe introduce MatRiCT, an efficient RingCT protocol for blockchain confidential transactions, whose security is based on "post-quantum'' (module) lattice assumptions. The proof length of the protocol is around two orders of magnitude shorter than the existing post-quantum proposal, and scales efficiently to large anonymity sets, unlike the existing proposal. Further, we provide the first full implementation of a post-quantum RingCT, demonstrating the practicality of our scheme. In particular, a typical transaction can be generated in a fraction of a second and verified in about 23 ms on a standard PC. Moreover, we show how our scheme can be extended to provide auditability, where a user can select a particular authority from a set of authorities to reveal her identity. The user also has the ability to select no auditing and all these auditing options may co-exist in the same environment. The key ingredients, introduced in this work, of MatRiCT are 1) the shortest to date scalable ring signature from standard lattice assumptions with no Gaussian sampling required, 2) a novel balance zero-knowledge proof and 3) a novel extractable commitment scheme from (module) lattices. We believe these ingredients to be of independent interest for other privacy-preserving applications such as secure e-voting. Despite allowing 64-bit precision for transaction amounts, our new balance proof, and thus our protocol, does not require a range proof on a wide range (such as 32- or 64-bit ranges), which has been a major obstacle against efficient lattice-based solutions. Further, we provide new formal definitions for RingCT-like protocols, where the real-world blockchain setting is captured more closely. The definitions are applicable in a generic setting, and thus are believed to contribute to the development of future confidential transaction protocols in general (not only in the lattice setting). Muhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu, Dongxi Liu |
CCS | 3 |
| 2019 | On The Unforkability of MoneroabstractMonero, ranked as one of the top privacy-preserving cryptocurrencies by market cap, introduced semi-annual hard fork in 2018. Although hard fork is not an uncommon event in the cryptocurrency industry, the two hard forks in 2018 caused an anonymity risk to Monero where transactions became traceable due to the problem of key reuse. Thisproblem was triggered by the existence of multiple copies of the same coin on different Monero blockchain branches such that the users spent the coins multiple times without preemptive action. We investigate the Monero hard fork events by analysing the transaction data on three different branches of the Monero blockchain. Although we have discovered an insignificant portion of traceable inputs compared to the total available inputs in our dataset, our analyses show that the scalability of the event depends on external factors such as market price and market availability. We propose a cheap, easy to implement strategy to prevent the problem of key reuse, should in the future stronger Monero forks emerge in the market. Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Jiangshan Yu |
AsiaCCS | 3 |
| 2019 | Multi-Writer Searchable Encryption: An LWE-based Realization and ImplementationabstractMulti-Writer Searchable Encryption, also known as public-key encryption with keyword search(PEKS), serves a wide spectrum of data sharing applications. It allows users to search over encrypted data encrypted via different keys. However, most of the existing PEKS schemes are built on classic security assumptions, which are proven to be untenable to overcome the threats of quantum computers. To address the above problem, in this paper, we propose a lattice-based searchable encryption scheme from the learning with errors (LWE) hardness assumption. Specifically, we observe that the keys of each user in a basic scheme are composed of large-sized matrices and basis of the lattice. To reduce the complexity of key management, our scheme is designed to enable users to directly use their identity for data encryption. We present several optimization techniques for implementation to make our design nearly practical. For completeness, we conduct rigorous security, complexity, and parameter analysis on our scheme, and perform comprehensive evaluations at a commodity machine. With a scenario of 100 users, the cost of key generation for each user is 125s, and the cost of searching a document with 1000 keywords is 13.4ms. Lei Xu 0019, Xingliang Yuan, Ron Steinfeld, Cong Wang 0001, Chungen Xu |
AsiaCCS | 3 |
| 2019 | Revocable and Linkable Ring Signature
Xinyu Zhang 0017, Joseph K. Liu, Ron Steinfeld, Veronika Kuchta, Jiangshan Yu |
Inscrypt | 3 |
| 2019 | Lattice-Based Zero-Knowledge Proofs: New Techniques for Shorter and Faster Constructions and Applications
Muhammed F. Esgin, Ron Steinfeld, Joseph K. Liu, Dongxi Liu |
CRYPTO (1) | 2 |
| 2019 | DGM: A Dynamic and Revocable Group Merkle Signature
Maxime Buser, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, Shifeng Sun 0001 |
ESORICS (1) | 3 |
| 2019 | Generic Multi-keyword Ranked Search on Encrypted Cloud Data
Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld, Surya Nepal |
ESORICS (2) | 3 |
| 2019 | Practical $$\mathsf {MP} \text{- }\mathsf {LWE} $$ -based encryption balancing security-risk versus efficiency
Ron Steinfeld, Amin Sakzad, Raymond K. Zhao |
Des. Codes Cryptogr. | 1 |
| 2018 | Post-Quantum One-Time Linkable Ring Signature and Application to Ring Confidential Transactions in Blockchain (Lattice RingCT v1.0)
Wilson Abel Alberto Torres, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Veronika Kuchta, Nandita Bhattacharjee, Man Ho Au, Jacob Cheng |
ACISP | 2 |
| 2018 | Result Pattern Hiding Searchable Encryption for Conjunctive QueriesabstractThe recently proposed Oblivious Cross-Tags (OXT) protocol (CRYPTO 2013) has broken new ground in designing efficient searchable symmetric encryption (SSE) protocol with support for conjunctive keyword search in a single-writer single-reader framework. While the OXT protocol offers high performance by adopting a number of specialised data-structures, it also trades-off security by leaking 'partial' database information to the server. Recent attacks have exploited similar partial information leakage to breach database confidentiality. Consequently, it is an open problem to design SSE protocols that plug such leakages while retaining similar efficiency. In this paper, we propose a new SSE protocol, called Hidden Cross-Tags (HXT), that removes 'Keyword Pair Result Pattern' (KPRP) leakage for conjunctive keyword search. We avoid this leakage by adopting two additional cryptographic primitives - Hidden Vector Encryption (HVE) and probabilistic (Bloom filter) indexing into the HXT protocol. We propose a 'lightweight' HVE scheme that only uses efficient symmetric-key building blocks, and entirely avoids elliptic curve-based operations. At the same time, it affords selective simulation-security against an unbounded number of secret-key queries. Adopting this efficient HVE scheme, the overall practical storage and computational overheads of HXT over OXT are relatively small (no more than 10% for two keywords query, and 21% for six keywords query), while providing a higher level of security. Shangqi Lai, Sikhar Patranabis, Amin Sakzad, Joseph K. Liu, Debdeep Mukhopadhyay, Ron Steinfeld, Shifeng Sun 0001, Dongxi Liu, Cong Zuo 0001 |
CCS | 6 |
| 2018 | Practical Backward-Secure Searchable Encryption from Symmetric Puncturable EncryptionabstractSymmetric Searchable Encryption (SSE) has received wide attention due to its practical application in searching on encrypted data. Beyond search, data addition and deletion are also supported in dynamic SSE schemes. Unfortunately, these update operations leak some information of updated data. To address this issue, forward-secure SSE is actively explored to protect the relations of newly updated data and previously searched keywords. On the contrary, little work has been done in backward security, which enforces that search should not reveal information of deleted data. In this paper, we propose the first practical and non-interactive backward-secure SSE scheme. In particular, we introduce a new form of symmetric encryption, named symmetric puncturable encryption (SPE), and construct a generic primitive from simple cryptographic tools. Based on this primitive, we then present a backward-secure SSE scheme that can revoke a server's searching ability on deleted data. We instantiate our scheme with a practical puncturable pseudorandom function and implement it on a large dataset. The experimental results demonstrate its efficiency and scalability. Compared to the state-of-the-art, our scheme achieves a speedup of almost 50x in search latency, and a saving of 62% in server storage consumption. Shifeng Sun 0001, Xingliang Yuan, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, Viet Vo, Surya Nepal |
CCS | 4 |
| 2018 | Anonymity Reduction Attacks to Monero
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Tsz Hon Yuen |
Inscrypt | 3 |
| 2018 | Platform-Independent Secure Blockchain-Based Voting System
Bin Yu 0009, Joseph K. Liu, Amin Sakzad, Surya Nepal, Ron Steinfeld, Paul Rimba, Man Ho Au |
ISC | 5 |
| 2018 | Improved Security Proofs in Lattice-Based Cryptography: Using the Rényi Divergence Rather than the Statistical Distance
Shi Bai 0001, Tancrède Lepoint, Adeline Roux-Langlois, Amin Sakzad, Damien Stehlé, Ron Steinfeld |
J. Cryptol. | 6 |
| 2017 | An implementation of access-control protocol for IoT home scenarioabstractThe internet of things comes into our daily life. It connected lots of resource-constrained devices, denoted as smart device, in an Internet-like structure. Considering the computing burden, the CoAP protocol is developed for serving the resource-constrained device and maps to HTTP for integration with existing web. In this paper, an access-control protocol will be introduced. The protocol is designed for IoT(Internet of Things) home scenario. Like the most IoT we can see, the IoT home scenario contains lots smart devices which collect some private information from us. To protect those data, an access-control protocol is needed. The protocol is deployed into Contiki OS and evaluated using the powertrace and some other tools. The results shows the protocol we designed takes a little more memory usage than an OAuth based authorisation protocol but smaller power consumption and more suitable for small scale IoT environment. Xiaoyang Wu 0006, Ron Steinfeld, Joseph K. Liu, Carsten Rudolph |
ICIS | 2 |
| 2017 | Multi-user Cloud-Based Secure Keyword Search
Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld |
ACISP (1) | 3 |
| 2017 | All-But-Many Lossy Trapdoor Functions and Selective Opening Chosen-Ciphertext Security from LWE
Benoît Libert, Amin Sakzad, Damien Stehlé, Ron Steinfeld |
CRYPTO (3) | 4 |
| 2017 | Middle-Product Learning with Errors
Miruna Rosca, Amin Sakzad, Damien Stehlé, Ron Steinfeld |
CRYPTO (3) | 4 |
| 2017 | A Lattice-Based Approach to Privacy-Preserving Biometric Authentication Without Relying on Trusted Third Parties
Trung Dinh, Ron Steinfeld, Nandita Bhattacharjee |
ISPEC | 2 |
| 2017 | Hardness of k-LWE and Applications in Traitor Tracing
San Ling, Duong Hieu Phan, Damien Stehlé, Ron Steinfeld |
Algorithmica | 4 |
| 2016 | An Efficient Non-interactive Multi-client Searchable Encryption with Support for Boolean Queries
Shifeng Sun 0001, Joseph K. Liu, Amin Sakzad, Ron Steinfeld, Tsz Hon Yuen |
ESORICS (1) | 4 |
| 2016 | Anonymizing Bitcoin Transaction
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Shifeng Sun 0001, Xinyi Huang 0001 |
ISPEC | 3 |
| 2015 | Improved Security Proofs in Lattice-Based Cryptography: Using the Rényi Divergence Rather Than the Statistical Distance
Shi Bai 0001, Adeline Roux-Langlois, Tancrède Lepoint, Damien Stehlé, Ron Steinfeld |
ASIACRYPT (1) | 5 |
| 2015 | Rotational Cryptanalysis of ARX Revisited
Dmitry Khovratovich, Ivica Nikolic, Josef Pieprzyk, Przemyslaw Sokolowski, Ron Steinfeld |
FSE | 5 |
| 2015 | On the Linearization of Human Identification Protocols: Attacks Based on Linear Algebra, Coding Theory, and LatticesabstractHuman identification protocols are challenge-response protocols that rely on human computational ability to reply to random challenges from the server based on a public function of a shared secret and the challenge to authenticate the human user. One security criterion for a human identification protocol is the number of challenge-response pairs the adversary needs to observe before it can deduce the secret. In order to increase this number, protocol designers have tried to construct protocols that cannot be represented as a system of linear equations or congruences. In this paper, we take a closer look at different ways from algebra, lattices, and coding theory to obtain the secret from a system of linear congruences. We then show two examples of human identification protocols from literature that can be transformed into a system of linear congruences. The resulting attack limits the number of authentication sessions these protocols can be used before secret renewal. Prior to this paper, these protocols had no known upper bound on the number of allowable sessions per secret. Hassan Jameel Asghar, Ron Steinfeld, Shujun Li 0001, Mohamed Ali Kâafar, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Hardness of k-LWE and Applications in Traitor Tracing
San Ling, Duong Hieu Phan, Damien Stehlé, Ron Steinfeld |
CRYPTO (1) | 4 |
| 2014 | GGHLite: More Efficient Multilinear Maps from Ideal Lattices
Adeline Roux-Langlois, Damien Stehlé, Ron Steinfeld |
EUROCRYPT | 3 |
| 2014 | Lattice-based completely non-malleable public-key encryption in the standard model
Reza Sepahi, Ron Steinfeld, Josef Pieprzyk |
Des. Codes Cryptogr. | 2 |
| 2014 | Practical attack on NLM-MAC scheme
Mohammad Ali Orumiehchiha, Josef Pieprzyk, Ron Steinfeld |
Inf. Process. Lett. | 3 |
| 2013 | Truncated Differential Analysis of Reduced-Round LBlock
Sareh Emami, Cameron McDonald, Josef Pieprzyk, Ron Steinfeld |
CANS | 4 |
| 2013 | Security Evaluation of Rakaposhi Stream Cipher
Mohammad Ali Orumiehchiha, Josef Pieprzyk, Elham Shakour, Ron Steinfeld |
ISPEC | 4 |
| 2013 | Does Counting Still Count? Revisiting the Security of Counting based User Authentication Protocols against Statistical Attacks
Hassan Jameel Asghar, Shujun Li 0001, Ron Steinfeld, Josef Pieprzyk |
NDSS | 3 |
| 2013 | Cryptanalysis of RC4(n, m) stream cipherabstractRC4(n, m) is a stream cipher based on RC4 and is designed by G. Gong et al. It can be seen as a generalization of the famous RC4 stream cipher designed by Ron Rivest. The authors of RC4(n, m) claim that the cipher resists all the attacks that are successful against the original RC4. Mohammad Ali Orumiehchiha, Josef Pieprzyk, Elham Shakour, Ron Steinfeld |
SIN | 4 |
| 2012 | Multi-party computation with conversion of secret sharing
Hossein Ghodosi, Josef Pieprzyk, Ron Steinfeld |
Des. Codes Cryptogr. | 3 |
| 2012 | Graph Coloring Applied to Secure Computation in Non-Abelian Groups
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Xiaoming Sun 0001, Christophe Tartary, Huaxiong Wang, Andrew Chi-Chih Yao |
J. Cryptol. | 3 |
| 2012 | On the modular inversion hidden number problem
San Ling, Igor E. Shparlinski, Ron Steinfeld, Huaxiong Wang |
J. Symb. Comput. | 3 |
| 2011 | Lattice-Based Completely Non-malleable PKE in the Standard Model (Poster)
Reza Sepahi, Ron Steinfeld, Josef Pieprzyk |
ACISP | 2 |
| 2011 | Making NTRU as Secure as Worst-Case Problems over Ideal Lattices
Damien Stehlé, Ron Steinfeld |
EUROCRYPT | 2 |
| 2010 | Faster Fully Homomorphic Encryption
Damien Stehlé, Ron Steinfeld |
ASIACRYPT | 2 |
| 2009 | Efficient Public Key Encryption Based on Ideal Lattices
Damien Stehlé, Ron Steinfeld, Keisuke Tanaka, Keita Xagawa |
ASIACRYPT | 2 |
| 2008 | Cryptanalysis of Short Exponent RSA with Primes Sharing Least Significant Bits
Mu-En Wu, Ron Steinfeld, Jian Guo 0001, Huaxiong Wang |
CANS | 3 |
| 2008 | Cryptanalysis of LASH
Ron Steinfeld, Scott Contini, Krystian Matusiewicz, Josef Pieprzyk, Jian Guo 0001, San Ling, Huaxiong Wang |
FSE | 1 |
| 2007 | On Secure Multi-party Computation in Black-Box Groups
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Huaxiong Wang |
CRYPTO | 3 |
| 2007 | How to Strengthen Any Weakly Unforgeable Signature into a Strongly Unforgeable Signature
Ron Steinfeld, Josef Pieprzyk, Huaxiong Wang |
CT-RSA | 1 |
| 2007 | Formal Proofs for the Security of Signcryption
Joonsang Baek, Ron Steinfeld, Yuliang Zheng 0001 |
J. Cryptol. | 2 |
| 2007 | Chinese Remaindering with Multiplicative Noise
Igor E. Shparlinski, Ron Steinfeld |
Theory Comput. Syst. | 2 |
| 2007 | Lattice-Based Threshold Changeability for Standard Shamir Secret-Sharing SchemesabstractWe consider the problem of increasing the threshold parameter of a secret-sharing scheme after the setup (share distribution) phase, without further communication between the dealer and the shareholders. Previous solutions to this problem require one to start off with a nonstandard scheme designed specifically for this purpose, or to have communication between shareholders. In contrast, we show how to increase the threshold parameter of thestandardShamir secret-sharing scheme without communication between the shareholders. Our technique can thus be applied to existing Shamir schemes even if they were set up without consideration to future threshold increases. Ron Steinfeld, Josef Pieprzyk, Huaxiong Wang |
IEEE Trans. Inf. Theory | 1 |
| 2006 | On the Provable Security of an Efficient RSA-Based Pseudorandom Generator
Ron Steinfeld, Josef Pieprzyk, Huaxiong Wang |
ASIACRYPT | 1 |
| 2006 | VSH, an Efficient and Provable Collision-Resistant Hash Function
Scott Contini, Arjen K. Lenstra, Ron Steinfeld |
EUROCRYPT | 3 |
| 2006 | A Non-malleable Group Key Exchange Protocol Robust Against Active Insiders
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Huaxiong Wang |
ISC | 3 |
| 2004 | Lattice-Based Threshold-Changeability for Standard Shamir Secret-Sharing Schemes
Ron Steinfeld, Huaxiong Wang, Josef Pieprzyk |
ASIACRYPT | 1 |
| 2004 | Noisy Chinese remaindering in the Lee norm
Igor E. Shparlinski, Ron Steinfeld |
J. Complex. | 2 |
| 2003 | Universal Designated-Verifier Signatures
Ron Steinfeld, Laurence Bull, Huaxiong Wang, Josef Pieprzyk |
ASIACRYPT | 1 |
| 2002 | On the Necessity of Strong Assumptions for the Security of a Class of Asymmetric Encryption Schemes
Ron Steinfeld, Joonsang Baek, Yuliang Zheng 0001 |
ACISP | 1 |
| 2001 | An Advantage of Low-Exponent RSA with Modulus Primes Sharing Least Significant Bits
Ron Steinfeld, Yuliang Zheng 0001 |
CT-RSA | 1 |