Raylin Tso

dblp:73/5733 · DBLP profile ↗
← Back
52ranked-venue papers
17as first author
17since 2021 · last 2026
0000-0003-1485-0164ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 9 first-author · 11 since 2021Systems, architecture and hardware · 8 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Theory of computation · 3 · 2 since 2021Artificial intelligence and machine learning · 2Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 Hierarchical identity-based encryption with receiver selective opening security in the multi-challenge setting
abstract
Receiver selective opening (RSO) security considers the security of encryption schemes under the scenario of a single sender and multiple receivers, where an adversary is allowed to adaptively corrupt some receivers’ secret keys. RSO security has been proven to be more secure than indistinguishability-based security notions. A lot of research has focused on RSO security in terms of public-key encryption and identity-based encryption (IBE); however, hierarchical IBE (HIBE), which is a generalization of IBE, is still lacking in the study, and how to obtain such a construction remains an open problem. To address this gap, we initiate a study of RSO security on HIBE in this work. Precisely, we first formalize the definition of simulation-based RSO against identity-chosen-plaintext/ciphertext attacks in the k-challenge setting (SIM-ID-RSO $$_k$$ -CPA/CCA) for HIBE. We then present generic SIM-ID-RSO $$_k$$ -CCA secure HIBE constructions by introducing the double secret key paradigm. Specifically, we show that a SIM-ID-RSO $$_k$$ -CCA secure HIBE scheme can be obtained from an IND-ID-CPA secure HIBE scheme as well as a one-time signature scheme that satisfies strong unforgeability. Through our general construction, we can derive various concrete schemes based on different hard assumptions (e.g., lattice-based and pairing-based SIM-ID-RSO $$_k$$ -CCA secure HIBE schemes) according to usage requirements.
Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng
Des. Codes Cryptogr.3
2026 Public-key encryption with filtered equality test against adaptive chosen-ciphertext attacks
Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng
Theor. Comput. Sci.3
2026 A Generic Construction of Efficient Oblivious Signature Protocols
abstract
In an oblivious signature, a receiver can obtain a signature from the signer for a message in the specified message set. It satisfies unforgeability and blind property similar to blind signature, and in-addition satisfies constrained-message property, i.e. the signer can only obtain valid signatures from the specified message set. Most existing oblivious signature protocols have communication complexity that's linearly proportional to the message set size, which makes the applications less scalable. Another common issue is they usually do not satisfy unlinkable, i.e. the signer cannot map a signature back to a specific run/receiver. In this work, we propose a generic construction of oblivious signature protocol from a set-membership NIZK and a blind signature protocol. Our construction has communication complexity that does not grow linearly with respect to the message set, and preserves unlinkability from the underlying blind signature protocol.
Jen-Chieh Hsu, Chao-Hong Chen, Raylin Tso
IEEE Trans. Reliab.3
2024 Predicate encryption with selective-opening security for receivers: formal definition, generic construction, and concrete instantiations for several primitives
Yi-Fan Tseng, Zi-Yuan Liu, Raylin Tso
Des. Codes Cryptogr.3
2024 Privacy-Enhanced Data Sharing Systems from Hierarchical ID-Based Puncturable Functional Encryption with Inner Product Predicates
abstract
The emergence of cloud computing enables users to upload data to remote clouds and compute them. This drastically reduces computing and storage costs for users. Considering secure computing for multilevel users in enterprises, the notion of hierarchical identity‐based inner product functional encryption (HIB‐IPFE) is proposed. In this cryptosystem, a sender can encrypt a vector into a ciphertext with a hierarchical identity, while a receiver who possesses a secret key corresponding to the same hierarchical identity and a vector can decrypt the ciphertext and obtain the inner product . However, HIB‐IPFE is not sufficient to capture flexible data sharing and forward security. In this study, we present a notion of hierarchical identity‐based puncturable HIBP‐IPFE. Furthermore, we present a formal definition and security model of HIBP‐IPFE to guarantee data confidentiality and receiver anonymity. Compared with HIB‐IPFE, our proposed scheme enables users to puncture keys on specific tags ensuring that the punctured keys cannot be used to decrypt the ciphertexts associated with those tags. The proposed scheme is provably secure under d ‐DBDHE assumption in the standard model. The experimental results indicate that our scheme is more practical in cloud computing, with superior functionality.
Cheng-Yi Lee 0001, Zi-Yuan Liu, Masahiro Mambo, Raylin Tso
IET Inf. Secur.4
2023 Cryptanalysis of a round optimal lattice-based multisignature scheme
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso
Inf. Process. Lett.3
2022 Public-key Authenticated Encryption with Keyword Search: Cryptanalysis, Enhanced Security, and Quantum-resistant Instantiation
abstract
With the rapid development of cloud computing, an increasing number of companies are adopting cloud storage technology to reduce overhead. However, to ensure the privacy of sensitive data, the uploaded data need to be encrypted before being outsourced to the cloud. The concept of public-key encryption with keyword search (PEKS) was introduced by Boneh et al. to provide flexible usage of the encrypted data. Unfortunately, most of the PEKS schemes are not secure against inside keyword guessing attacks (IKGA), so the keyword information of the trapdoor may be leaked to the adversary. To solve this issue, Huang and Li presented public key authenticated encryption with keyword search (PAEKS) in which the trapdoor generated by the receiver is only valid for authenticated ciphertexts. With their seminal work, many PAEKS schemes have been introduced for the enhanced security of PAEKS. Some of them further consider the upcoming quantum attacks. However, our cryptanalysis indicated that in fact, these schemes could not withstand IKGA. To fight against the attacks from quantum adversaries and support the privacy-preserving search functionality, we first introduce a novel generic PAEKS construction in this work. Then, we further present the first quantum-resistant PAEKS instantiation based on lattices. The security proofs show that our instantiation not only satisfies the basic requirements but also achieves enhanced security models, namely the multi-ciphertext indistinguishability and multi-trapdoor privacy. Furthermore, the comparative results indicate that with only some additional expenditure, the proposed instantiation provides more secure properties, making it suitable for more diverse application environments.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
AsiaCCS3
2022 Blockchain-Based Self-Sovereign Identity System with Attribute-Based Issuance
Yi-Hsiu Lee, Zi-Yuan Liu, Raylin Tso, Yi-Fan Tseng
ISPEC3
2022 Blockchain-Based Confidential Payment System with Controllable Regulation
Yu-Chen Liao, Raylin Tso, Zi-Yuan Liu, Yi-Fan Tseng
ISPEC2
2022 Public-Key Authenticated Encryption with Keyword Search: A Generic Construction and Its Quantum-Resistant Instantiation
abstract
Abstract The industrial Internet of Things (IIoT) integrates sensors, instruments, equipment and industrial applications, enabling traditional industries to automate and intelligently process data. To reduce the cost and demand of required service equipment, IIoT relies on cloud computing to further process and store data. Public-key encryption with keyword search (PEKS) plays an important role, due to its search functionality, to ensure the privacy and confidentiality of the outsourced data and the maintenance of flexibility in the use of the data. Recently, Huang and Li proposed the ‘public-key authenticated encryption with keyword search’ (PAEKS) to avoid the insider keyword guessing attacks (IKGAs) in the previous PEKS schemes. However, all current PAEKS schemes are based on the discrete logarithm assumption and are therefore vulnerable to quantum attacks. In this study, we first introduce a generic PAEKS construction, with the assistance of a trusted authority, that enjoys the security against IKGA in the standard model, if all building blocks are secure under standard model. Based on the framework, we further propose a novel instantiation of quantum-resistant PAEKS that is based on NTRU assumption under random oracle. Compared with its state-of-the-art counterparts, the experiment result indicates that our instantiation is more efficient and secure.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
Comput. J.3
2022 Quantum-resistant anonymous identity-based encryption with trable identities
abstract
Abstract Identity‐based encryption (IBE), introduced by Shamir, eliminates the need for public‐key infrastructure. The sender can simply encrypt a message by using the recipient's identity (such as email or IP address) without needing to look up the public key. In particular, when ciphertexts of an IBE do not reveal recipient's identity, this scheme is known as an anonymous IBE scheme. Recently, Blazy et al. (ARES '19) analysed the trade‐off between public safety and unconditional privacy in anonymous IBE and introduced a new notion that incorporates traceability into anonymous IBE, called anonymous IBE with traceable identities (AIBET). However, their construction is based on the discrete logarithm assumption, which is insecure in the quantum era. In this paper, we first formalize the consistency of tracing key of the AIBET scheme to ensure that a ciphertext cannot be traced with the use of wrong tracing keys. Subsequently, we present a generic formulation concept that can be used to transform structure‐specific lattice‐based anonymous IBE schemes into an AIBET. Finally, we apply this concept to Katsumata and Yamada's compact anonymous IBE scheme (Asiacrypt '16) to obtain the first quantum‐resistant AIBET scheme that is adaptively secure under the ring learning with errors assumption without random oracle.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
IET Inf. Secur.3
2022 Extension of elliptic curve Qu-Vanstone certificates and their applications
abstract
In public key infrastructure, a certificate, issued by a certificate authority (CA), is used to guarantee the connection between a user and her/his public key. In order to improve the efficiency, the concept of implicit certificate protocol is introduced by Girault and Gönther. In the existing implicit certificate protocol, a user must issue a certificate request to the CA for each key pair. However, in certain applications (e.g., IoT, sensor networks, and cryptocurrency), a user (or a device) will have multiple public/private key pairs that are related to the same identity. Therefore, the communication cost will be linearly related to the number of key pairs the user has. Furthermore, the storage cost of a large number of certificates is not an ideal property in practice. In this paper, to address the above issues, we proposed two schemes from the most widely used elliptic curve Qu–Vanstone implicit certificate scheme (ECQV). In our first scheme, called M-ECQV I, an ECQV certificate holder, who obtains an ECQV certificate issued by the certificate authority, can further issue multiple credentials with the same identity as ECQV certificate holder and the corresponding key pairs from the ECQV certificate. In our second scheme, called M-ECQV II, it not only supports the comparable functionality of M-ECQV I, but the verifier can ensure that the credentials are only used by the ECQV certificate holder (i.e., these credential are “self-use”) to be suitable to different scenarios. In addition, the security models are well-defined and the rigorous security proofs are also given. Experimental results show that our schemes not only greatly improve the performance, but also reduce the storage cost.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Peter Shaojui Wang, Qin-Wen Su
J. Inf. Secur. Appl.3
2022 Privacy-preserving bidirectional keyword search over encrypted data for cloud-assisted IIoT
Cheng-Yi Lee 0001, Zi-Yuan Liu, Raylin Tso, Yi-Fan Tseng
J. Syst. Archit.3
2021 Public key encryption with filtered equality test revisited
Yu-Chi Chen 0001, Xin Xie 0005, Hung-Yu Tsao, Raylin Tso
Des. Codes Cryptogr.4
2021 Designated-ciphertext searchable encryption
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo
J. Inf. Secur. Appl.3
2021 Private Predicate Encryption for Inner Product from Key-Homomorphic Pseudorandom Function
abstract
Predicate encryption (PE), formalized by Katz et al., is a new paradigm of public-key encryption that conceptually captures the public-key encryption that supports fine-grained access control policy. Because of the nature of PE, it is used for cloud storage so that users can retrieve encrypted data without revealing any information about the data to cloud servers and other users. Although lots of PE schemes have been studied, the predicate-hiding security is seldom considered; that is, the user’s secret key may leak sensitive information of the predicate. Additionally, the security of the current predicate-hiding PE schemes relies on the discrete logarithm assumption which cannot resist the quantum attacks in the future. In this paper, we propose a generic PE for inner product under symmetric-key setting, called private IPE, from specific key-homomorphic pseudorandom function (PRF). The rigorous proofs are provided to show that the construction is payload-hiding, attribute-hiding, and predicate-hiding secure. With the advantage of the generic construction, if the underlying PRF can resist quantum attacks, then, through our proposed generic construction, a quantum-resistant private IPE can be obtained.
Yi-Fan Tseng, Zi-Yuan Liu, Jen-Chieh Hsu, Raylin Tso
Secur. Commun. Networks4
2021 Provably secure authentication key exchange scheme using fog nodes in vehicular ad hoc networks
Tsu-Yang Wu, Zhiyuan Lee, Lei Yang 0055, Jia-Ning Luo, Raylin Tso
J. Supercomput.5
2019 Malware Image Classification Using One-Shot Learning with Siamese Networks
abstract
Machine learning has largely applied to malware detection and classification, due to the ineffectiveness of signature-based method toward rapid malware proliferation. Although state-of-the-art machine learning models tend to achieve high performances, they require a large number of training samples. It is infeasible to train machine learning models with sufficient malware samples while facing newly appeared malware variants. Therefore, it is important for security protectors to train a model given a small set of data, which can identify malware variants based on the similarity function. In addition, security protectors should keep re-training the models on newly-found samples, while the typical machine learning models based on massive data are not efficient for the instant update. Inspired by recent success using Siamese neural networks for one-shot image recognition, we aim to apply the networks to malware image classification task. The implementation includes three main stages: pre-processing, training, and testing. In the pre-processing stage, the system transforms malware samples to the resized gray-scale images and classifies them by average hash in the same family. In the training and testing stages, Siamese networks are trained to rank similarity between samples and the accuracy is calculated through N-way one-shot tasks. The experiment results showed that our networks outperformed the baseline methods. Besides, this paper indicated that our networks were more suitable for malware image one-shot learning than typical deep learning models.
Shou-Ching Hsiao, Da-Yu Kao, Zi-Yuan Liu, Raylin Tso
KES4
2019 Witness-based searchable encryption with optimal overhead for cloud-edge computing
Yu-Chi Chen 0001, Xin Xie 0005, Peter Shaojui Wang, Raylin Tso
Future Gener. Comput. Syst.4
2019 Two-in-one oblivious signatures
Raylin Tso
Future Gener. Comput. Syst.1
2019 Quantum secret sharing by using Fourier transform on orbital angular momentum
abstract
A quantum secret sharing scheme based on orbital angular momentum (OAM) is proposed. The dealer generates single particles in OAM basis or angular position (ANG) basis randomly. The participants encode their private keys into the particles through performing quantum Fourier transforms. Then the dealer can use the single‐particle measurements to get the shared secret. In the authors’ scheme, the secret is protected by the distinguishability of OAM basis and ANG basis. Compared to the traditional two‐dimensional schemes, the authors’ scheme can use the higher dimension of OAM to increase the detecting rate of eavesdropping, and enhance the security in practice. Besides, only the single particles are needed in their scheme. Compared to the schemes based on entangled particles, the authors’ scheme will be more practical with the present technology.
Huawang Qin, Raylin Tso, Yuewei Dai
IET Inf. Secur.2
2018 A shareable keyword search over encrypted data in cloud computing
Li Xu 0002, Chi-Yao Weng, Lun-Pin Yuan, Mu-En Wu, Raylin Tso
J. Supercomput.5
2017 Somewhat semantic secure public key encryption with filtered-equality-test in the standard model and its extension to searchable encryption
Kaibin Huang, Raylin Tso, Yu-Chi Chen 0001
J. Comput. Syst. Sci.2
2016 Security analysis of a NTRU-based mutual authentication scheme
abstract
NFC-based mobile transaction has come into limelight in recent years thanks to the rapid development of NFC and mobile technologies. In these applications, the NFC-chip is in the card emulation mode to simulate a credit card. Because many sensitive information is exchanged during the communication of the mobile transaction, mutual authentication is required in order to verify the legality of each communicating party. Recently, Part and Lee introduced an anonymous authentication scheme based on NTRU. It is aimed to protect user information in NFC mobile payment systems without directly using private financial information of users. However, we found a security flaw in their new scheme. In this paper, we show that their scheme is insecure against an eavesdropping attack. An attacker, without any secret information, can impersonate the user against a service provider and pass the authentication procedure. This may result in a serious problem in which an attacker can enjoy a service such as an on-line shopping on behalf of the real user without the permission of the real user. An improved scheme will be left as our future work.
Raylin Tso, Yi-Shio Jheng
APNOMS1
2016 Two-in-One Oblivious Signatures Secure in the Random Oracle Model
Raylin Tso
NSS1
2015 Semantic Secure Public Key Encryption with Filtered Equality Test - PKE-FET
abstract
Cloud storage allows users to outsource their data to a storage server. For general security and privacy concerns, users prefer storing encrypted data to pure ones so that servers do not learn anything about privacy. However, there is a natural issue that servers have worked some analyses (i.e. statistics) or routines for encrypted data without losing privacy. In this paper, we address the basic functionality, equality test, over encrypted data, which at least can be applied to specific analyses like private information retrieval. We introduce a new system, called filtered equality test, which is an additional functionality for existing public key encryption schemes. It satisfies the following scenario: a ciphertext-receiver selects several messages as a set and produces its related warrant; then, on receiving this warrant, an user is able to perform equality test on the receiver's ciphertext without decryption when the hidden message belongs to that message set. Similar to the attribute based encryption, ABE. In ABE schemes, those ones who match the settled conditions could get the privilege of decryption. In FET schemes, those ‘messages inside selected set’ can be equality tested. Combining PKE schemes and filtered equality test, we propose a framework of public key encryption scheme with filtered equality test, abbreviated as PKE-FET. Then, taking ElGamal for example, we propose a concrete PKE-FET scheme based on secret sharing and bilinear map. Finally, we prove our proposition with semantic security in the standard model.
Kaibin Huang, Yu-Chi Chen 0001, Raylin Tso
SECRYPT3
2015 PKE-AET: Public Key Encryption with Authorized Equality Test
abstract
In this paper, we propose a new notion of public key encryption scheme with authorized equality test (PKE-AET), which allows authorized users those who have warrants to test the equivalence between two messages, where the messages are encrypted using different public keys. Comparing with the existing researches, our PKE-AET provides two kinds of warrants that are referred to as receiver's warrants and cipher-warrants. The proposed PKE-AET is able to deal with the following complicated scenario: Assume that a receiver authorizes a receiver's warrant to a tester, which makes the tester be able to perform equality test on all of receivers’ ciphertext; on the other hand, if receiver authorizes a cipher-warrant corresponding to a specific ciphertext to the tester, then the tester only acquires the equality test on that particular ciphertext. The equality between two ciphertexts can be verified by the tester without decryption after he or she receives two warrants and varies their validations. Moreover, for security analysis, we define two types of adversaries and security notions for PKE-AET in the multi-user setting. Furthermore, we prove that our PKE-AET is one-way CCA secure against type-I adversaries and IND-CCA secure against type-II adversaries. Finally, the proposed scheme leads better efficiency than most of previous equality test schemes.
Kaibin Huang, Raylin Tso, Yu-Chi Chen 0001, Sk. Md. Mizanur Rahman, Ahmad S. Al-Mogren, Atif Alamri
Comput. J.2
2015 Certificateless aggregate signature with efficient verification
abstract
Certificateless public key cryptography CL-PKC is a cryptosystem solving the key escrow problem of identity-based cryptography. One of the applications of CL-PKC is certificateless aggregate signature CLAS that in practice can be used to efficiently verify concealed data aggregation in wireless sensor networks. CLAS is referred to as an extension of certificateless signature, which in particular performs verification for many signatures efficiently. Therefore, not only plenty of CLAS schemes have been proposed but also the security models of CLAS were introduced in the literature. Recently, some CLAS schemes are extended from specific certificateless signature CLS schemes. However, we found that two certificateless signature CLS and their corresponding CLAS schemes are not secure. In this paper, we simplify the relation of security definitions of CLS and CLAS. Then, a new CLAS scheme is proposed, which leads to the advantages of both certificateless cryptography and aggregate signature. Moreover, our scheme only depends on constant pairing operations to verify a large number of signatures per time, because pairing is a complicated operation with high cost in computations. Copyright © 2014 John Wiley & Sons, Ltd.
Yu-Chi Chen 0001, Raylin Tso, Masahiro Mambo, Kaibin Huang, Gwoboa Horng
Secur. Commun. Networks2
2014 An Improved Visual Cryptography with Cheating Prevention
Yu-Chi Chen 0001, Kunhan Lu, Raylin Tso, Mu-En Wu
IWDW3
2014 Security Analysis and Improvement of Femtocell Access Control
Chien-Ming Chen 0001, Tsu-Yang Wu, Raylin Tso, Mu-En Wu
NSS3
2014 A New Public Key Encryption with Equality Test
Kaibin Huang, Raylin Tso, Yu-Chi Chen 0001, Wangyu Li
NSS2
2014 On the improvement of Fermat factorization using a continued fraction technique
Mu-En Wu, Raylin Tso
Future Gener. Comput. Syst.2
2013 Security analysis and improvements of a communication-efficient three-party password authenticated key exchange protocol
Raylin Tso
J. Supercomput.1
2012 Cryptanalysis of Exhaustive Search on Attacking RSA
Mu-En Wu, Raylin Tso
NSS2
2012 On the Improvement of Fermat Factorization
Mu-En Wu, Raylin Tso
NSS2
2012 Identity-based Password-Authenticated Key Exchange for Client/Server Model
Xun Yi, Raylin Tso, Eiji Okamoto
SECRYPT2
2012 Strongly secure certificateless short signatures
Raylin Tso, Xinyi Huang 0001, Willy Susilo
J. Syst. Softw.1
2012 Convertible ring signatures with gradual revelation of non-signers
abstract
ABSTRACT A ring signature enables a member of a group to sign any message on behalf of the group while hiding the identity of the real signer. On the other hand, a convertible ring signature is a kind of ring signature in which the real signer can convert it into an ordinary signature. In this way, the real signer can prove the ownership of a ring signature if necessary. In this paper, we introduce a new convertible ring signature with an additional property. That is, before converting a ring signature into an ordinary signature, we allow the real signer to reveal the identity of non‐signers gradually. In other words, if there are n possible signers in a ring, then, by revealing one non‐signer, it will become a ring signature with n − 1 possible signers. By revealing n − 1 non‐signers, then, the ring signature comes to an ordinary signature, and anyone can verify who is the real signer. This property is useful when some non‐signers of a ring signature are not trusted by a verifier (i.e., the signature will not be accepted if someone is a possible signer). Rivest, Shamir, and Tauman first mentioned this problem and gave a solution as their modified ring signature scheme. However, their modified scheme can only guarantee computational anonymity. Our new scheme provides the same property on one hand and still guarantees unconditional anonymity on the other hand. The security is rigorously proved in the random oracle model according to the formal definition. Copyright © 2011 John Wiley & Sons, Ltd.
Raylin Tso
Secur. Commun. Networks1
2011 Three-party Password-authenticated Key Exchange without Random Oracles
Xun Yi, Raylin Tso, Eiji Okamoto
SECRYPT2
2011 Efficient and short certificateless signatures secure against realistic adversaries
Raylin Tso, Xun Yi
J. Supercomput.1
2010 Design and Analysis of "Flexible" k-out-of-n Signatures
Raylin Tso, Xun Yi, Tadahiko Ito, Takeshi Okamoto, Eiji Okamoto
ATC1
2010 Certificateless Proxy Signature and Its Extension to Blind Signature
abstract
In this paper, a certificateless proxy signature scheme is introduced. The advantage of our scheme is that it can be extended into a certificateless proxy blind signature scheme very easily.
Raylin Tso, Xun Yi
NSS1
2008 A Restricted Undeniable Designated Verifier Signature
abstract
A restricted universal designated verifier signature scheme proposed by Huang et al., which is a variant of digital signatures, allows a signature holder to convince at most t designated verifiers.The signature will become publicly verifiable when the signature holder uses the signature for t+1 times.The applications of this type of signatures are expected to, for example, trial services or electronic votings on the internet. However, confirming process and universal opening are required in some situations. But both Huang et al.'s scheme as well as Laugullaumie et al.'s scheme do not support universal opening. In this paper, we propose a new restricted undeniable designated verifier signature scheme. Our scheme surpasses both Huang et al.'s scheme and Laugullaumie et al.'s scheme in the sense of universal opening.
Atsushi Koide, Raylin Tso, Takeshi Okamoto, Eiji Okamoto
APSCC2
2008 Signcryption Scheme with Standardized Verification Algorithm
abstract
Confidentiality and authenticity are two of the most important goals in setting a cryptographic system. A signcryption scheme, invented in 1996, is a new cryptographic primitive which can simultaneously achieve these two goals in one logical step. On the other hand, the standardization is always one of the crucial factors for practical uses for cryptosystems. Yum and Lee first introduced the need for public verifiability using standard signature algorithm. Following Yum and Lee's work, in 2003, Shin et al. proposed a signcryption scheme in which the verification phase can adopt the standard DSA. However, this scheme is not forward secure. A forward secure signcryption scheme means that the private key of the sender does not help any attack to break the confidentiality of any signcrypted ciphertext generated by the sender. In this paper, modified from Shin et al. 's scheme, we propose a new signcrypion scheme. Our scheme is forward secure and the verification phase can be done using the standardized signature algorithm, ECDSA. The efficiency and features of our scheme are compared with other schemes and the security of our scheme is proved in the random oracle model.
Raylin Tso
APSCC1
2008 Efficient and Short Certificateless Signature
Raylin Tso, Xun Yi, Xinyi Huang 0001
CANS1
2008 Efficient convertible Limited Verifier Signatures
abstract
The notion of limited verifier signature (LVS) was first introduced by Araki et al. in 1999. It is a useful cryptographic primitive to limit the publicly verifiable property of ordinary digital signatures. In a LVS, the signature can be verified by a limited verifier. When necessary, the signer or the limited verifier can provide a proof to convince a designated verifier (eg., a judge) that the signer has indeed generated the signature. However, the judge cannot transfer this proof to convince any other party. Also, the LVS should be converted into an ordinary one for public verification if required. In this paper, we propose an efficient LVS scheme which is more efficient than previous proposed schemes. Based on the intractability of the Computational Diffie-Hellman (CDH) problem, we give the security proofs of the scheme in the random oracle model.
Raylin Tso, Xun Yi, Takeshi Okamoto, Eiji Okamoto
ISIT1
2008 1-out-of-
Raylin Tso, Takeshi Okamoto, Eiji Okamoto
ISPEC1
2007 ID-Based Key Agreement for Dynamic Peer Groups in Mobile Computing Environments
abstract
In order to secure communications for dynamic peer groups in mobile computing environments, key agreement protocols are required. In this paper, we propose a new key agreement protocol based on identities of mobile users, composed of a basic protocol and a dynamic protocol, for dynamic peer groups. With the basic protocol, an initial secret group key can be achieved in a peer group. By the dynamic protocol, a new secret group key can be reached whenever member or mass join, group mergence, group division, member or mass quit occurs. Our protocol has security features, such as implicit group key authentication, key confirmation, forward secrecy, key independence, and etc. Because our protocol runs in parallel, it is more efficient than those running in series.
Raylin Tso, Xun Yi, Eiji Okamoto
APSCC1
2007 Efficient ID-Based Digital Signatures with Message Recovery
Raylin Tso, Takeshi Okamoto, Eiji Okamoto
CANS1
2007 ECDSA-Verifiable Signcryption Scheme with Signature Verification on the Signcrypted Message
Raylin Tso, Takeshi Okamoto, Eiji Okamoto
Inscrypt1
2007 Verifier-Key-Flexible Universal Designated-Verifier Signatures
Raylin Tso, Juan Manuel González Nieto, Takeshi Okamoto, Colin Boyd, Eiji Okamoto
IMACC1
2005 One-Way and Two-Party Authenticated ID-Based Key Agreement Protocols Using Pairing
Takeshi Okamoto, Raylin Tso, Eiji Okamoto
MDAI2