VLDB 2026 Research / reviewers in the wild / expert
Seongan Lim
dblp:84/2757
· DBLP profile ↗
18ranked-venue papers
4as first author
2since 2021 · last 2022
0000-0002-1192-6672ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-authorTheory of computation · 6 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | On Insecure Uses of BGN for Privacy Preserving Data Aggregation ProtocolsabstractThe notion of aggregator oblivious (AO) security for privacy preserving data aggregation was formalized with a specific construction of AO-secure blinding technique over a cyclic group by Shi et al. Some of proposals of data aggregation protocols use the blinding technique of Shi et al. for BGN cryptosystem, an additive homomorphic encryption. Previously, there have been some security analysis on some of BGN based data aggregation protocols in the context of integrity or authenticity of data. Even with such security analysis, the BGN cryptosystem has been a popular building block of privacy preserving data aggregation protocol. In this paper, we study the privacy issues in the blinding technique of Shi et al. used for BGN cryptosystem. We show that the blinding techniques for the BGN cryptosystem used in several protocols are not privacy preserving against the recipient, the decryptor. Our analysis is based on the fact that the BGN cryptosystem uses a pairing e : G × G → G T and the existence of the pairing makes the DDH problem on G easy to solve. We also suggest how to prevent such privacy leakage in the blinding technique of Shi et al. used for BGN cryptosystem. Hyang-Sook Lee, Seongan Lim, Ikkwon Yie, Aaram Yun |
Fundam. Informaticae | 2 |
| 2021 | Analysis on Yu et al.'s dynamic algorithm for canonic DBC
Soo-Kyung Eom, Hyang-Sook Lee, Seongan Lim, Kyunghwan Song |
Discret. Appl. Math. | 3 |
| 2020 | New orthogonality criterion for shortest vector of lattices and its applications
Hyang-Sook Lee, Seongan Lim, Kyunghwan Song, Ikkwon Yie |
Discret. Appl. Math. | 2 |
| 2020 | Algorithms for the Generalized NTRU Equations and their Storage AnalysisabstractIn LATTE, a lattice based hierarchical identity-based encryption (HIBE) scheme, each hierarchical level user delegates a trapdoor basis to the next level by solving a generalized NTRU equation of level ℓ ≥ 3. For ℓ = 2, Howgrave-Graham, Pipher, Silverman, and Whyte presented an algorithm using resultant and Pornin and Prest presented an algorithm using a field norm with complexity analysis. Even though their ideas of solving NTRU equations can be conceptually extended for ℓ ≥ 3, no explicit algorithmic extensions with the storage analysis are known so far. In this paper, we interpret the generalized NTRU equation as the determinant of a matrix. By using the mathematical properties of the determinant, we show that how to construct algorithms for solving the generalized NTRU equation either using resultant or a field norm for any ℓ ≥ 3. We also obtain an upper bound of the size of solutions by using the properties of the determinant. From our analysis, the storage requirement of the algorithm using resultant is O(ℓ 2 n 2 log B) and that of the algorithm using a field norm is O(ℓ 2 n log B), where B is an upper bound of the coefficients of the input polynomials of the generalized NTRU equations. We present examples of our algorithms for ℓ = 3 and the average storage requirements for ℓ = 3; 4. Gook Hwa Cho, Seongan Lim, Hyang-Sook Lee |
Fundam. Informaticae | 2 |
| 2018 | On the Non-repudiation of Isogeny Based Signature Scheme
Soo-Kyung Eom, Hyang-Sook Lee, Seongan Lim |
WISTP | 3 |
| 2018 | Key Substitution Attacks on Lattice Signature Schemes Based on SIS ProblemabstractThe notion of key substitution security on digital signatures in the multiuser setting has been proposed by Menezes and Smart in 2004. Along with the unforgeability of signature, the key substitution security is very important since it is a critical requirement for the nonrepudiation and the authentication of the signature. Lattice-based signature is a promising candidate for post-quantum cryptography, and the unforgeability of each scheme has been relatively well studied. In this paper, we present key substitution attacks on BLISS, Lyubashevsky’s signature scheme, and GPV and thus show that these signature schemes do not provide nonrepudiation. We also suggest how to avoid key substitution attack on these schemes. Youngjoo An, Hyang-Sook Lee, Juhee Lee, Seongan Lim |
Secur. Commun. Networks | 4 |
| 2017 | A Lattice Attack on Homomorphic NTRU with Non-invertible Public Keys
Soyoung Ahn, Hyang-Sook Lee, Seongan Lim, Ikkwon Yie |
ICICS | 3 |
| 2017 | Security Analysis of a Certificateless Signature from LatticesabstractTian and Huang proposed a lattice-based CLS scheme based on the hardness of the SIS problem and proved, in the random oracle model, that the scheme is existentially unforgeable against strong adversaries. Their security proof uses the general forking lemma under the assumption that the underlying hash function H is a random oracle. We show that the hash function in the scheme is neither one-way nor collision-resistant in the view of a strong Type 1 adversary. We point out flaws in the security arguments and present attack algorithms that are successful in the strong Type 1 adversarial model using the weak properties of the hash function. Seunghwan Chang, Hyang-Sook Lee, Juhee Lee, Seongan Lim |
Secur. Commun. Networks | 4 |
| 2016 | An efficient lattice reduction using reuse technique blockwisely on NTRU
Kyungmi Chung, Hyang-Sook Lee, Seongan Lim |
Discret. Appl. Math. | 3 |
| 2014 | An Efficient Decoding of Goppa Codes for the McEliece CryptosystemabstractThe McEliece cryptosystem is defined using a Goppa code, and decoding the Goppa code is a crucial step of its decryption. Patterson's decoding algorithm is the best known algorithm for decoding Goppa codes. Currently, the most efficient implementation of Patterson's algorithm uses a precomputation. In this paper, we modify Patterson's decoding algorithm so that one can remove the precomputation part while sustaining the best efficiency. Precomputations yield additional storage requirement to store the precomputed value which increases as the security level increases in McEliece cryptosystem. In the original decoding algorithm of Patterson, computing square root in a quotient field of polynomial ring over a finite field is necessary. In our modification, the computations are involved only in the arithmetics of polynomial ring over a finite field, not in the quotient field. This achieves better efficiency because one can remove polynomial reductions in the computations of quotient field. Seongan Lim, Hyang-Sook Lee, Mijin Choi |
Fundam. Informaticae | 1 |
| 2014 | Equivalent public keys and a key substitution attack on the schemes from vector decompositionabstractABSTRACT The vector decomposition problem has been considered as a hard problem, which is applicable to cryptography. Okamoto and Takashima proposed various types of public key cryptographic schemes based on the VDP. In this paper, we study the cryptographic implications of Okamoto‐Takashima schemes with respect to the properties of public keys. In the public key cryptography, one public key is associated to a unique private key, and an action using the public key implicitly assumes that the corresponding private action can be done only with the corresponding private key. We formalize this security issue by introducing the notion of equivalent public keys. We show that equivalent public keys exist in the Okamoto‐Takashima basic signature scheme and the homomorphic encryption scheme. We present a strong key substitution attack to their basic signature. We suggest how to prevent equivalent public keys and strong key substitution attack in their signature scheme. We point out that there are cases with no efficient methods to prevent equivalent public keys in their encryption scheme. Copyright © 2013 John Wiley & Sons, Ltd. Seongan Lim, Eunjeong Lee, Cheol-Min Park |
Secur. Commun. Networks | 1 |
| 2013 | Key exposure free chameleon hash schemes based on discrete logarithm problemabstractABSTRACT A chameleon hash scheme is a trapdoor collision‐resistant hash scheme, and it provides many interesting features in signature schemes with hash‐and‐sign construction. In this paper, we introduce the notion of key exposure threshold τ for a chameleon hash scheme for which a key exposure free chameleon hash scheme can be understood as the case with τ = ∞. We propose chameleon hash schemes CHτ with the key exposure threshold τ based on discrete logarithm problem (DLP). For τ < ∞, the proposed scheme is noninteractive and key exposure free as long as k ephemeral trapdoors are disclosed for k < τ. The proposed scheme CH∞ is a key exposure free chameleon hash scheme based on DLP, and it requires a label directory that can be managed by a third party. This improves the only known efficient key exposure free chameleon hash scheme based on DLP, which requires one interaction with the trapdoor holder. Copyright © 2012 John Wiley & Sons, Ltd. Seongan Lim, Juhee Lee, Youngjoo An |
Secur. Commun. Networks | 1 |
| 2012 | A short redactable signature scheme using pairingabstractABSTRACT Redactable signature schemes permit deletion of arbitrary substrings of a signed document while preserving the authenticity of the remaining document. Most of known redactable signatures based on pairing have large‐sized signatures and the sizes depend on the product of security parameter and the number of blocks of the redacted document. In this paper, we present a short redactable signature scheme based on pairing. We modify Waters signature scheme to obtain an underlying standard signature defined on composite‐order bilinear group. The modified scheme satisfies the unforgeability under the known message attack based on the Computational Diffie–Hellman assumption. Based on the modified Waters signature, we propose a short redactable signature that is existentially unforgeable under random message attack and weakly private. The size of the proposed scheme is 20% of known redactable signatures using aggregated pairing‐based signatures when half of the message blocks are deleted. Copyright © 2011 John Wiley & Sons, Ltd. Seongan Lim, Eunjeong Lee, Cheol-Min Park |
Secur. Commun. Networks | 1 |
| 2011 | An efficient incomparable public key encryption scheme
Hyang-Sook Lee, Seongan Lim |
Inf. Sci. | 2 |
| 2006 | Cryptanalysis of Two Signature Schemes Based on Bilinear Pairings in CISC '05
Haeryong Park, Zhengjun Cao, Lihua Liu 0001, Seongan Lim, Ikkwon Yie, Kilsoo Chun |
Inscrypt | 4 |
| 2004 | A Study on Smart Card Security Evaluation Criteria for Side Channel Attacks
Hoonjae Lee 0001, ManKi Ahn, Seongan Lim, Sang-Jae Moon |
ICCSA (1) | 3 |
| 2003 | RSA Speedup with Chinese Remainder Theorem Immune against Hardware Fault CryptanalysisabstractThis article considers the problem of how to prevent RSA signature and decryption computation with a residue number system (CRT-based approach) speedup from a hardware fault cryptanalysis in a highly reliable and efficient approach. CRT-based speedup for an RSA signature has been widely adopted as an implementation standard ranging from large servers to very tiny smart IC cards. However, given a single erroneous computation result, hardware fault cryptanalysis can totally break the RSA system by factoring the public modulus. Countermeasures using a simple verification function (e.g., raising a signature to the power of a public key) or fault detection (e.g., an expanded modulus approach) have been reported in the literature; however, it is pointed out that very few of these existing solutions are both sound and efficient. Unreasonably, in these methods, they assume that a comparison instruction will always be fault-free when developing countermeasures against hardware fault cryptanalysis. Research shows that the expanded modulus approach proposed by Shamir (1997, 1999) is superior to the approach using a simple verification function when another physical cryptanalysis (e.g., timing cryptanalysis) is considered. So, we intend to improve Shamir's method. In this paper, the new concepts of fault infective CRT computation and fault infective CRT recombination are proposed. Based on the new concepts, two novel protocols are developed with a rigorous proof of security. Two possible parameter settings are provided for the protocols. One setting selects a small public key and the proposed protocols can have comparable performance to Shamir's scheme. The other setting has better performance than Shamir's scheme (i.e., having comparable performance to conventional CRT speedup), but with a large public key. Most importantly, we wish to emphasize the importance of developing and proving the security of physically secure protocols without relying on unreliable or unreasonable assumptions, e.g., always fault-free instructions. In this paper, related protocols are also considered and carefully examined to point out possible weaknesses. Sung-Ming Yen, Seungjoo Kim, Seongan Lim, Sang-Jae Moon |
IEEE Trans. Computers | 3 |
| 2001 | Strong Adaptive Chosen-Ciphertext Attacks with Memory Dump (or: The Importance of the Order of Decryption and Validation)
Seungjoo Kim, Jung Hee Cheon, Marc Joye, Seongan Lim, Masahiro Mambo, Dongho Won, Yuliang Zheng 0001 |
IMACC | 4 |