Goichiro Hanaoka

dblp:88/1238 · DBLP profile ↗
← Back
121ranked-venue papers
17as first author
8since 2021 · last 2024
0000-0001-6617-2962ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 106 · 15 first-author · 8 since 2021Theory of computation · 23 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Privacy-Preserving Verifiable CNNs
abstract
Convolutional neural networks (CNNs) have emerged as one of the most successful deep learning approaches to image recognition and classification. A recent line of research, which includes zkCNN (ACM CCS ’21), vCNN (Cryptology ePrint Archive), and ZEN (Cryptology ePrint Archive), aims at protecting the privacy of CNN models by developing publicly verifiable proofs of correct classification which do not leak any information about the underlying CNN models themselves. A shared feature of these schemes is that they require the entity constructing the proof to have access to both the model and the input in the clear. In other words, a client holding a potentially sensitive input is required to reveal this input to the entity holding the CNN model, thereby sacrificing his privacy, to be able to obtain a verifiable proof of correct classification. This is in contrast to the security guarantees provided by secure classification considered in privacy-preserving machine learning, which does not require the client to reveal his input to obtain a (non-verifiable) classification. In this paper, we propose a privacy-preserving verifiable CNN scheme that overcomes this limitation of the previous schemes by allowing the client to obtain a classification proof without having to reveal his input. The obtained proof allows the client to selectively reveal properties of the obtained classification and his input, which will be verifiable to any third-party verifier. Our scheme is based on the recent notion of collaborative zk-SNARKs by Ozdemir and Boneh (USENIX ’22). Specifically, we construct a new collaborative zk-SNARK based on Bulletproofs achieving an efficient maliciously secure proof generation protocol. Based on this, we then present an optimized approach to CNN evaluation. Finally, we demonstrate the feasibility of our approach by measuring the performance of our scheme on a CNN for classifying the MNIST dataset.
Nuttapong Attrapadung, Goichiro Hanaoka, Ryo Hiromasa, Yoshihiro Koseki, Takahiro Matsuda 0002, Yutaro Nishida, Yusuke Sakai 0001, Jacob C. N. Schuldt, Satoshi Yasuda
ACNS (2)2
2024 Multi-query Verifiable PIR and Its Application
Ryuya Hayashi, Junichiro Hayata, Keisuke Hara, Kenta Nomura, Masaki Kamizono, Goichiro Hanaoka
CANS (2)6
2024 Tighter Adaptive IBEs and VRFs: Revisiting Waters' Artificial Abort
Goichiro Hanaoka, Shuichi Katsumata, Kei Kimura, Kaoru Takemure, Shota Yamada 0001
TCC (3)1
2023 Signature for Objects: Formalizing How to Authenticate Physical Data and More
Ryuya Hayashi, Taiki Asano, Junichiro Hayata, Takahiro Matsuda 0002, Shota Yamada 0001, Shuichi Katsumata, Yusuke Sakai 0001, Tadanori Teruya, Jacob C. N. Schuldt, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Tsutomu Matsumoto
FC (1)11
2023 Two-Dimensional Dynamic Fusion for Continuous Authentication
abstract
Continuous authentication has been widely studied to provide high security and usability for mobile devices by continuously monitoring and authenticating users. Recent studies adopt multibiometric fusion for continuous authentication to provide high accuracy even when some of captured biometric data are of a low quality. However, existing continuous fusion approaches are resource-heavy as they rely on all classifiers being activated all the time and may not be suitable for mobile devices.In this paper, we propose a new approach to multibiometric continuous authentication: two-dimensional dynamic fusion. Our key insight is that multibiometric continuous authentication calculates two-dimensional matching scores over classifiers and over time. Based on this, we dynamically select a set of classifiers based on the context in which authentication is taking place, and fuse matching scores by multi-classifier fusion and multi-sample fusion. Through experimental evaluation, we show that our approach provides a better balance between resource usage and accuracy than the existing fusion methods. In particular, we show that our approach provides higher accuracy than the existing methods with the same number of score calculations by adopting multi-sample fusion.
Nuttapong Attrapadung, Goichiro Hanaoka, Haochen M. Kotoi-Xie, Takahiro Matsuda 0002, Takumi Moriyama, Takao Murakami, Hidenori Nakamura, Jacob C. N. Schuldt, Masaaki Tokuyama
IJCB2
2023 Maliciously circuit-private multi-key FHE and MPC based on LWE
abstract
Abstract In this paper, we construct multi-key homomorphic and fully homomorphic encryption (resp. MKHE and MKFHE) schemes with malicious circuit privacy. Our schemes are based on learning with errors (LWE) besides appropriate circular security assumptions. In contrast, the previous maliciously circuit-private MKFHE scheme by Chongchitmate and Ostrovsky (PKC, 2017) is based on the non-standard decisional small polynomial ratio (DSPR) assumption with a super-polynomial modulus, besides ring learning with errors and circular security assumptions. We note that it was shown by Albrecht et al. (CRYPTO, 2016) that there exists a sub-exponential time attack against this type of DSPR assumption. The main building block of our maliciously circuit-private MKFHE scheme is a (plain) MKFHE scheme by Brakerski et al. (TCC, 2017), and the security of our schemes is proven under the hardness of LWE with sub-exponential modulus-to-noise ratio and circular security assumptions related to the Brakerski et al. scheme. Furthermore, based on our MKFHE schemes, we construct four-round multi-party computation (MPC) protocols with circuit privacy against a semi-honest server and malicious clients in the plain model. The protocols are obtained by combining our schemes with a maliciously sender-private oblivious transfer protocol and a circuit garbling scheme, all of which can be instantiated only assuming LWE.
Nuttapong Attrapadung, Goichiro Hanaoka, Ryo Hiromasa, Takahiro Matsuda 0002, Jacob C. N. Schuldt
Des. Codes Cryptogr.2
2022 Generic transformation from broadcast encryption to round-optimal deniable ring authentication
Keisuke Hara, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
Des. Codes Cryptogr.3
2021 Oblivious Linear Group Actions and Applications
abstract
In this paper we propose efficient two-party protocols for obliviously applying a (possibly random) linear group action to a data set. Our protocols capture various applications such as oblivious shuffles, circular shifts, matrix multiplications, to name just a few. A notable feature enjoyed by our protocols, is that they admit a round-optimal (more precisely, one-round) online computation phase, once an input-independent off-line computation phase has been completed. Our oblivious shuffle is the first to achieve a round-optimal online phase. The most efficient instantiations of our protocols are obtained in the so-called client-aided client-server setting, where the offline phase is run by a semi-honest input party (client) who will then distribute the generated correlated randomness to the computing parties (servers). When comparing the total running time to the previous best two-party oblivious shuffle protocol by Chase et al. (Asiacrypt 2020), our shuffle protocol in this client-aided setting is up to 105 times and 152 times faster, in the LAN and WAN setting, respectively. We additionally show how the Chase et al. protocol (which is a standard two-party protocol) can be modified to leverage the advantages of the client-aided setting, but show that, even doing so, our scheme is still two times faster in the online phase and 1.34 times faster in total on average.
Nuttapong Attrapadung, Goichiro Hanaoka, Takahiro Matsuda 0002, Hiraku Morita, Kazuma Ohara, Jacob C. N. Schuldt, Tadanori Teruya, Kazunari Tozawa
CCS2
2020 Semantic Definition of Anonymity in Identity-Based Encryption and Its Relation to Indistinguishability-Based Definition
Goichiro Hanaoka, Misaki Komatsu, Kazuma Ohara, Yusuke Sakai 0001, Shota Yamada 0001
ESORICS (2)1
2020 On Private Information Retrieval Supporting Range Queries
Junichiro Hayata, Jacob C. N. Schuldt, Goichiro Hanaoka, Kanta Matsuura
ESORICS (2)3
2020 Achieving Pairing-Free Aggregate Signatures using Pre-Communication between Signers
Kaoru Takemure, Yusuke Sakai 0001, Bagus Santoso, Goichiro Hanaoka, Kazuo Ohta
ProvSec4
2020 Exposing Private User Behaviors of Collaborative Filtering via Model Inversion Techniques
abstract
Abstract Privacy risks of collaborative filtering (CF) have been widely studied. The current state-of-theart inference attack on user behaviors (e.g., ratings/purchases on sensitive items) for CF is by Calandrino et al. (S&P, 2011). They showed that if an adversary obtained a moderate amount of user’s public behavior before some timeT, she can infer user’s private behavioraftertimeT. However, the existence of an attack that infers user’s private behaviorbefore Tremains open. In this paper, we propose the first inference attack that reveals past private user behaviors. Our attack departs from previous techniques and is based onmodel inversion(MI). In particular, we propose the first MI attack on factorization-based CF systems by leveraging data poisoning by Li et al. (NIPS, 2016) in a novel way. We inject malicious users into the CF system so that adversarialy chosen “decoy” items are linked with user’s private behaviors. We also show how to weaken the assumption made by Li et al. on the information available to the adversary from the whole rating matrix to only the item profile and how to create malicious ratings effectively. We validate the effectiveness of our inference algorithm using two real-world datasets.
Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka
Proc. Priv. Enhancing Technol.5
2020 Generic hardness of inversion on ring and its relation to self-bilinear map
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
Theor. Comput. Sci.3
2019 Proper Usage of the Group Signature Scheme in ISO/IEC 20008-2
abstract
In ISO/IEC 20008-2, several anonymous digital signature schemes are specified. Among these, the scheme denoted as Mechanism 6, is the only plain group signature scheme that does not aim at providing additional functionalities. The Intel Enhanced Privacy Identification (EPID) scheme, which has many applications in connection with Intel Software Guard Extensions (Intel SGX), is in practice derived from Mechanism 6. In this paper, we firstly show that Mechanism 6 does not satisfy anonymity in the standard security model, i.e., the Bellare-Shi-Zhang model [CT-RSA 2005]. We then provide a detailed analysis of the security properties offered by Mechanism 6 and characterize the conditions under which its anonymity is preserved. Consequently, it is seen that Mechanism 6 is secure under the condition that the issuer, who generates user signing keys, does not join the attack. We also derive a simple patch for Mechanism~6 from the analysis.
Ai Ishida, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka
AsiaCCS4
2019 Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions
abstract
This paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes.
Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazuma Ohara, Kazumasa Omote, Yusuke Sakai 0001
Secur. Commun. Networks2
2019 Simulation-based receiver selective opening CCA secure PKE from standard computational assumptions
Keisuke Hara, Fuyuki Kitagawa, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
Theor. Comput. Sci.4
2018 Attribute-Based Signatures for Unbounded Languages from Standard Assumptions
Yusuke Sakai 0001, Shuichi Katsumata, Nuttapong Attrapadung, Goichiro Hanaoka
ASIACRYPT (2)4
2018 Efficient Two-level Homomorphic Encryption in Prime-order Bilinear Groups and A Fast Implementation in WebAssembly
abstract
We construct an efficient two-level homomorphic public-key encryption in prime-order bilinear groups. Such a scheme supports polynomially many homomorphic additions and one multiplication over encrypted data, similar to the cryptosystem of Boneh, Goh, and Nissim (BGN, presented at TCC 2005), which was constructed in composite-order bilinear groups. Prior to our work, the state-of-the-art for two-level homomorphic public-key encryption is the Freeman scheme (presented at Eurocrypt 2010), which is indeed the prime-order realization of the BGN scheme. Our proposed scheme significantly improves efficiency for almost all the aspects of the Freeman scheme, while retains the same ciphertext sizes. Our scheme is surprisingly simple as it is indeed (a concatenation of two copies of) the ElGamal encryption "in the exponent'' resided in an asymmetric bilinear groups.
Nuttapong Attrapadung, Goichiro Hanaoka, Shigeo Mitsunari, Yusuke Sakai 0001, Kana Shimizu, Tadanori Teruya
AsiaCCS2
2018 Constant-Round Client-Aided Secure Comparison Protocol
Hiraku Morita, Nuttapong Attrapadung, Tadanori Teruya, Satsuya Ohata, Koji Nuida, Goichiro Hanaoka
ESORICS (2)6
2018 Memory Lower Bounds of Reductions Revisited
Yuyu Wang 0001, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
EUROCRYPT (1)3
2018 A Remark on an Identity-Based Encryption Scheme with Non-interactive Opening
abstract
Identity-based encryption with non-interactive opening is an extension of identity-based encryption which allows a receiver to prove a given ciphertext will be decrypted to a public message without revealing his decryption key. Fan et al. (J. Shanghai Jiaotong Univ. (Sci.)) proposed a construction of this primitive. We analyze the security of their scheme and show that the scheme is in fact not secure.
Yusuke Sakai 0001, Goichiro Hanaoka
ISITA2
2018 Generic Construction of Adaptively Secure Anonymous Key-Policy Attribute-Based Encryption from Public-Key Searchable Encryption
abstract
Public-key encryption with keyword search (PEKS) is a cryptographic primitive that allows us to search encrypted data for those of including particular keywords without decrypting them. PEKS is expected to be used for enhancing security of cloud storages. It is known that PEKS can be constructed from anonymous identity-based encryption (IBE), anonymous attribute-based encryption (ABE) and so on. It is believed that it is difficult to construct PEKS schemes that can specify a flexible search condition such as logical disjunctions and logical conjunctions from weaker cryptographic tools than ABE. However, this intuition has not been rigorously justified. In this paper, we formally prove it by constructing key-policy ABE from PEKS for monotone boolean formulas.
Junichiro Hayata, Masahito Ishizaka, Yusuke Sakai 0001, Goichiro Hanaoka, Kanta Matsuura
ISITA4
2018 A Consideration on the Transformation from Deniable Group Signature to Disavowable PKENO
abstract
Emura et al. [Int. J. Inf. Sec. 2014] showed that a public key encryption scheme with non-interactive opening (PKENO scheme) can be constructed from a group signature scheme secure in the dynamic setting. By following this construction, it seems that we can obtain a disavowable PKENO scheme [Ishida et al., ASIACCS 2015] from a deniable group signature scheme [Ishida et al., CANS 2016] since these primitives have the similar functionalities. In this work, we claim that this intuition is incorrect. Concretely, we show that the obtained scheme does not satisfy the functionality of disavowable PKENO by providing an attack for the indistinguishability against chosen ciphertext and prove attack security.
Ai Ishida, Yusuke Sakai 0001, Goichiro Hanaoka
ISITA3
2018 Embedding Lemmas for Functional Encryption
abstract
Functional encryption is an extension of the ordinary public key encryption where decryption results vary depending on the functions (or key attributes) associated to secret keys. In this paper, we show an embedding lemma for functional encryption, which provides a sufficient criterion for implication from one FE to FE with another function class. The lemma is an extension of the embedding lemma for attribute-based encryption that was introduced in the previous work by Boneh and Hamburg (Asiacrypt 2008). As an application of our lemma, we show that FE for cubic forms can be constructed from FE for inner product or FE for quadratic forms.
Ryo Kato, Naohisa Nishida, Ryo Hirano, Tatsumi Oba, Yuji Unagami, Shota Yamada 0001, Tadanori Teruya, Nuttapong Attrapadung, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA10
2018 Tree-based Secure Comparison of Secret Shared Data
abstract
A secure integer comparison protocol is one of the most fundamental building blocks to construct protocols of rich functionality in multi-party computation. It allows parties to compute the less-than functionality on shared values in privacy preserving manner. In this paper, we present a tree-based secure two-party comparison protocol in the client-aided client-server model, which outperforms existing approaches in terms of round complexity when it is used for 64-bit data. Our proposed protocol requires only 9 communication rounds to compare 64-bit data, which is at least 3 times fewer rounds than existing protocols. This suggests that our protocol is adequate to be used in low-latency networks such as WAN.
Hiraku Morita, Nuttapong Attrapadung, Satsuya Ohata, Shota Yamada 0001, Koji Nuida, Goichiro Hanaoka
ISITA6
2018 Secure Division Protocol and Applications to Privacy-preserving Chi-squared Tests
abstract
We present a new secure integer division protocol with private divisor. Our protocol is based loosely on the Bogdanov et al. (Int. J. Inf. Secur.'12) protocol, which securely computes the classical Goldschmidt's division algorithm. While the Bogdanov et al. scheme was designed specifically to work only on a 3-out-of-3 secret sharing scheme, our scheme works on a 2-out-of-2 secret sharing scheme. This has an advantage since the latter setting is more widely used in the literature of secure computation, and our protocol can thus be used as an efficient building block in this setting. We implement our protocol in Python and provide its benchmark. As a main application of our division protocol, we implement a secure protocol for privacy-preserving chi-squared tests on genomic data. This demonstrates that the proposed protocol is suitable for the statistical analysis on sensitive data.
Hiraku Morita, Nuttapong Attrapadung, Satsuya Ohata, Koji Nuida, Shota Yamada 0001, Kana Shimizu, Goichiro Hanaoka, Kiyoshi Asai
ISITA7
2018 Accuracy/Efficiency Trade-Off for Privacy-Preserving Division Protocol
abstract
Secure multi-party computation (MPC) allows a set of parties to jointly compute a function, while keeping their inputs private. We can consider many applications of MPC and various operations/protocols for MPC have been proposed. We focus on (privacy-preserving) division protocols in this paper. Although division is included in four arithmetic operations, we need extremely high computation/communication costs in privacy-preserving settings compared with other operations. Especially, we need many communication rounds for error correction to get accurate quotients. Since we iterate error correction procedure for several times in the division protocol, we can expect to reduce communication rounds by removing error correcting iterations. In this strategy, however, we cannot obtain accurate quotients. In this paper, we show experimental results about a relation between accuracy of quotients obtained by the round-reduced division protocol and the number of communication rounds we need. From our results, we find the error of quotients becomes less than 0.1% even if we reduce the number of communication rounds for error correction to 33%. This property will be useful when we make concrete applications efficient in some cases.
Satsuya Ohata, Hiraku Morita, Goichiro Hanaoka
ISITA3
2018 Token-Based Multi-input Functional Encryption
Nuttapong Attrapadung, Goichiro Hanaoka, Takato Hirano, Yutaka Kawai, Yoshihiro Koseki, Jacob C. N. Schuldt
ProvSec2
2018 Formal Treatment of Verifiable Privacy-Preserving Data-Aggregation Protocols
Satoshi Yasuda, Yoshihiro Koseki, Yusuke Sakai 0001, Fuyuki Kitagawa, Yutaka Kawai, Goichiro Hanaoka
ProvSec6
2018 Chosen ciphertext secure keyed-homomorphic public-key cryptosystems
Keita Emura, Goichiro Hanaoka, Koji Nuida, Go Ohtake, Takahiro Matsuda 0002, Shota Yamada 0001
Des. Codes Cryptogr.2
2018 Practical attribute-based signature schemes for circuits from bilinear map
abstract
Attribute‐based signatures allow us to sign anonymously, in such a way that the signature proves that the signer's attributes satisfy some predicate, but it hides any other information on the signer's attributes beyond that fact. As well as any cryptographic primitive, one of the important goals of the research on this primitive is to construct a scheme that is expressive (supports a wide class of predicates), is practically efficient , and is based on well‐studied cryptographic assumptions . The authors construct attribute‐based signature schemes that support any Boolean circuit of unbounded depth and number of gates, are practically efficient, from the symmetric bilinear Diffie–Hellman assumption. Toward this end, they combine the Groth–Sahai proof system, which serve as an efficient proof system for algebraic equations, and the Groth–Ostrovsky–Sahai proof system, which are still inefficient, but can prove any NP language via a Karp reduction to circuit satisfiability.
Yusuke Sakai 0001, Nuttapong Attrapadung, Goichiro Hanaoka
IET Inf. Secur.3
2017 Generic Constructions for Fully Secure Revocable Attribute-Based Encryption
Kotoko Yamada, Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka
ESORICS (2)4
2017 A Taxonomy of Secure Two-Party Comparison Protocols and Efficient Constructions
abstract
Secure two-party comparison plays a crucial role in many privacy-preserving applications, such as privacy-preserving data mining and machine learning. In particular, the available comparison protocols with the appropriate input/output configuration have a significant impact on the performance of these applications. In this paper, we firstly describe a taxonomy of secure two-party comparison protocols which allows us to describe the different configurations used for these protocols in a systematic manner. This taxonomy leads to a total of 216 types of comparison protocols.We then describe conversions among these types. While these conversions are based on known techniques and have explicitly or implicitly been considered previously, we show that a combination of these conversion techniques can be used to convert a perhaps less-known two-party comparison protocol by Nergiz et al. (IEEE SocialCom 2010) into a very efficient protocol in a configuration where the two parties hold shares of the values being compared, and obtain a share of the comparison result. This setting is often used in multi-party computation protocols, and hence in many privacy-preserving applications as well. We furthermore implement the protocol and measure its performance. Our measurement suggests that the protocol outperforms the previously proposed protocols for this input/output configuration, when off-line pre-computation is not permitted.
Nuttapong Attrapadung, Goichiro Hanaoka, Shinsaku Kiyomoto, Tomoaki Mimoto, Jacob C. N. Schuldt
PST2
2017 Model Inversion Attacks for Prediction Systems: Without Knowledge of Non-Sensitive Attributes
abstract
While online services based on machine learning (ML) have been attracting considerable attention in both academic and business, privacy issues are becoming a threat that cannot be ignored. Recently, Fredrikson et al. [USENIX 2014] proposed a new paradigm of model inversion attacks, which allows an adversary to expose the sensitive information of users by using an ML system for an unintended purpose. In particular, the attack reveals the sensitive attribute values of the target user by using their non-sensitive attributes and the output of the ML model. Here, for the attack to succeed, the adversary needs to possess the non-sensitive attribute values of the target user prior to the attack. However, in reality, even if this information (i.e., non-sensitive attributes) is not necessarily information the user regards as sensitive, it may be difficult for the adversary to actually acquire it. In this paper, we propose a general model inversion (GMI) framework to capture the above scenario where knowledge of the non-sensitive attributes is not necessarily provided. Here, our framework also captures the scenario of Fredrikson et al. Notably, we generalize the paradigm of Fredrikson et al. by additionally modeling the amount of auxiliary information the adversary possesses at the time of the attack. Our proposed GMI framework enables a new type of model inversion attack for prediction systems, which can be carried out without knowledge of the non-sensitive attributes. At a high level, we use the paradigm of data poisoning in a novel way and inject malicious data into the set of training data to modify the ML model into a target ML model, which we can attack without having to have knowledge of the non-sensitive attributes. Our new attack enables the inference of sensitive attributes in the user input from only the output of the ML model, even when the non-sensitive attributes of the user are not available to the adversary. Finally, we provide a concrete algorithm of our model inversion attack on prediction systems based on linear regression models, and give a detailed description of how the data poisoning algorithm is constructed.We evaluate the performance of our new model inversion attack without the knowledge of non-sensitive attributes through experiments with actual data sets.
Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka
PST5
2017 A Public-Key Encryption Scheme Based on Non-linear Indeterminate Equations
Koichiro Akiyama, Yasuhiro Goto, Shinya Okumura, Tsuyoshi Takagi, Koji Nuida, Goichiro Hanaoka
SAC6
2017 Self-Bilinear Map on Unknown Order Groups from Indistinguishability Obfuscation and Its Applications
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
Algorithmica3
2017 Compact public key encryption without full random oracles
Kazuki Yoneyama, Goichiro Hanaoka
Pervasive Mob. Comput.2
2016 Generalized Hardness Assumption for Self-bilinear Map with Auxiliary Information
Takashi Yamakawa, Goichiro Hanaoka, Noboru Kunihiro
ACISP (2)2
2016 Fuzzy Signatures: Relaxing Requirements and a New Construction
Takahiro Matsuda 0002, Kenta Takahashi, Takao Murakami, Goichiro Hanaoka
ACNS4
2016 Attribute Based Encryption with Direct Efficiency Tradeoff
Nuttapong Attrapadung, Goichiro Hanaoka, Tsutomu Matsumoto, Tadanori Teruya, Shota Yamada 0001
ACNS2
2016 Size-Hiding Computation for Multiple Parties
Kazumasa Shinagawa, Koji Nuida, Takashi Nishide, Goichiro Hanaoka, Eiji Okamoto
ASIACRYPT (2)4
2016 How to Obtain Fully Structure-Preserving (Automorphic) Signatures from Structure-Preserving Ones
Yuyu Wang 0001, Zongyang Zhang, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
ASIACRYPT (2)4
2016 Group Signature with Deniability: How to Disavow a Signature
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka
CANS3
2016 Adversary-Dependent Lossy Trapdoor Function from Hardness of Factoring Semi-smooth RSA Subgroup Moduli
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
CRYPTO (2)3
2016 Signatures from trapdoor commitments with strong openings
Goichiro Hanaoka, Jacob C. N. Schuldt
ISITA1
2016 On signatures with tight security in the multi-user setting
Goichiro Hanaoka, Jacob C. N. Schuldt
ISITA1
2016 Tag-KEM/DEM framework for public-key encryption with non-interactive opening
Yusuke Sakai 0001, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA3
2016 Committed AND protocol using three cards with more handy shuffle
Kazumasa Shinagawa, Koji Nuida, Takashi Nishide, Goichiro Hanaoka, Eiji Okamoto
ISITA4
2016 Private similarity searchable encryption for Euclidean distance
Yuji Unagami, Natsume Matsuzaki, Shota Yamada 0001, Nuttapong Attrapadung, Takahiro Matsuda 0002, Goichiro Hanaoka
ISITA6
2016 Efficient key encapsulation mechanisms with tight security reductions to standard assumptions in the two security models
abstract
Abstract In this paper, we propose two new practical constructions of chosen ciphertext attack secure (CCA secure) key encapsulation mechanisms (KEM, which is the main building block for public key encryption in hybrid encryption), with remarkable security features: Our KEMs can be proved not only to satisfy CCA security (or constrained CCA security introduced by Hofheinz and Kiltz at CRYPTO'07) in the standard model with a tight security reduction to a basic indistinguishability‐type assumption but also to be CCA secure in the random oracle model with a tight security reduction to a basic computational‐type assumption. Our first construction is based on the Diffie–Hellman‐type assumptions, and compared with the KEM by Shoup at EUROCRYPT'00 that has security reductions in two security models (but its security proof in the random model is a loose reduction), our proposed KEM has a smaller ciphertext size with the same computational costs, and more importantly, ours has a tight security reduction also in the random oracle model. Our second construction is based on assumptions related to integer factoring, and compared with the KEM by Hofheinz and Kiltz at CRYPTO'99 that also has tight security reductions in two security models to factoring‐related assumptions, our proposed KEM has similar efficiency (both ciphertext size and computational costs) and bases the security on incomparable assumptions. Copyright © 2016 John Wiley & Sons, Ltd.
Yoshikazu Hanatani, Goichiro Hanaoka, Takahiro Matsuda 0002, Takashi Yamakawa
Secur. Commun. Networks2
2016 A limitation on security evaluation of cryptographic primitives with fixed keys
abstract
Abstract In this paper, we discuss security of public‐key cryptographic primitives in the case that the public key is fixed. In the standard argument, security of cryptographic primitives are evaluated by estimating the average probability of being successfully attacked where keys are treated as random variables. In contrast to this, in practice, a user is mostly interested in the security under his specific public key, which has been already fixed. However, it is obvious that such security cannot be mathematically guaranteed because for any given public key, there always potentially exists an adversary, which breaks its security. Therefore, the best what we can do is just to use a public key such that its effective adversary is not likely to be constructed in the real life and, thus, it is desired to provide a method for evaluating this possibility. The motivation of this work is to investigate (in)feasibility of predicting whether for a given fixed public key, its successful adversary will actually appear in the real life or not. As our main result, we prove that for any digital signature scheme or public key encryption scheme, it is impossible to reduce any fixed key adversary in any weaker security notion than the de facto ones (i.e., existential unforgery against adaptive chosen message attacks or indistinguishability against adaptive chosen ciphertext attacks) to fixed key adversaries in the de facto security notion in a black‐box manner. This result means that, for example, for any digital signature scheme, impossibility of extracting the secret key from a fixed public key will never imply existential unforgery against chosen message attacks under the same key as long as we consider only black‐box analysis. Copyright © 2016 John Wiley & Sons, Ltd.
Yutaka Kawai, Goichiro Hanaoka, Kazuo Ohta, Noboru Kunihiro
Secur. Commun. Networks2
2016 Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta
Theor. Comput. Sci.4
2015 Dynamic Threshold Public-Key Encryption with Decryption Consistency from Static Assumptions
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta
ACISP4
2015 A Signature Scheme with a Fuzzy Private Key
Kenta Takahashi, Takahiro Matsuda 0002, Takao Murakami, Goichiro Hanaoka, Masakatsu Nishigaki
ACNS4
2015 An Asymptotically Optimal Method for Converting Bit Encryption to Multi-Bit Encryption
Takahiro Matsuda 0002, Goichiro Hanaoka
ASIACRYPT (1)2
2015 A Framework for Identity-Based Encryption with Almost Tight Security
Nuttapong Attrapadung, Goichiro Hanaoka, Shota Yamada 0001
ASIACRYPT (1)2
2015 Conversions Among Several Classes of Predicate Encryption and Applications to ABE with Various Compactness Tradeoffs
Nuttapong Attrapadung, Goichiro Hanaoka, Shota Yamada 0001
ASIACRYPT (1)2
2015 Disavowable Public Key Encryption with Non-interactive Opening
abstract
We propose the notion of disavowable public key encryption with non-interactive opening (disavowable PKENO) where, for a ciphertext and a message, the receiver of the ciphertext can issue a proof that the plaintext of the ciphertext is NOT the message, and give a fairly practical construction.
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka
AsiaCCS3
2015 Completeness of Single-Bit Projection-KDM Security for Public Key Encryption
Fuyuki Kitagawa, Takahiro Matsuda 0002, Goichiro Hanaoka, Keisuke Tanaka
CT-RSA3
2015 Re-Encryption Verifiability: How to Detect Malicious Activities of a Proxy in Proxy Re-Encryption
Satsuya Ohata, Yutaka Kawai, Takahiro Matsuda 0002, Goichiro Hanaoka, Kanta Matsuura
CT-RSA4
2015 Multi-party Computation with Small Shuffle Complexity Using Regular Polygon Cards
Kazumasa Shinagawa, Takaaki Mizuki, Jacob C. N. Schuldt, Koji Nuida, Naoki Kanayama, Takashi Nishide, Goichiro Hanaoka, Eiji Okamoto
ProvSec7
2015 Black-Box Separations of Hash-and-Sign Signatures in the Non-Programmable Random Oracle Model
Zongyang Zhang, Yu Chen 0003, Sherman S. M. Chow, Goichiro Hanaoka, Zhenfu Cao, Yunlei Zhao
ProvSec4
2015 Gateway Threshold Password-based Authenticated Key Exchange Secure against Undetectable On-line Dictionary Attack
abstract
Password-based Authenticated Key Exchange (PAKE) allows a server to authenticate a user and to establish a session key shared between the server and the user just by having memorable passwords. In PAKE, conventionally the server is assumed to have the authentication functionality and also provide on-line services simultaneously. However, in the real-life applications, this may not be the case, and the authentication server may be separate from on-line service providers. In such a case, there is a problem that a malicious service provider with no authentication functionality may be able to guess the passwords by interacting with other participants repeatedly. Abdalla et al. put forward a notion of the server password protection security to deal with this problem. However, their proposed schemes turned out to be vulnerable to Undetectable On-line Dictionary Attack (UDonDA). To cope with this situation, we propose the Gateway Threshold PAKE provably secure against this password guessing attack by also taking the corruption of authentication servers into consideration.
Yukou Kobayashi, Naoto Yanai, Kazuki Yoneyama, Takashi Nishide, Goichiro Hanaoka, Kwangjo Kim, Eiji Okamoto
SECRYPT5
2015 Constructing and Understanding Chosen Ciphertext Security via Puncturable Key Encapsulation Mechanisms
Takahiro Matsuda 0002, Goichiro Hanaoka
TCC (1)2
2015 Privacy-preserving search for chemical compound databases
abstract
BACKGROUND: Searching for similar compounds in a database is the most important process for in-silico drug screening. Since a query compound is an important starting point for the new drug, a query holder, who is afraid of the query being monitored by the database server, usually downloads all the records in the database and uses them in a closed network. However, a serious dilemma arises when the database holder also wants to output no information except for the search results, and such a dilemma prevents the use of many important data resources. RESULTS: In order to overcome this dilemma, we developed a novel cryptographic protocol that enables database searching while keeping both the query holder's privacy and database holder's privacy. Generally, the application of cryptographic techniques to practical problems is difficult because versatile techniques are computationally expensive while computationally inexpensive techniques can perform only trivial computation tasks. In this study, our protocol is successfully built only from an additive-homomorphic cryptosystem, which allows only addition performed on encrypted values but is computationally efficient compared with versatile techniques such as general purpose multi-party computation. In an experiment searching ChEMBL, which consists of more than 1,200,000 compounds, the proposed method was 36,900 times faster in CPU time and 12,000 times as efficient in communication size compared with general purpose multi-party computation. CONCLUSION: We proposed a novel privacy-preserving protocol for searching chemical compound databases. The proposed method, easily scaling for large-scale databases, may help to accelerate drug discovery research by making full use of unused but valuable data that includes sensitive information.
Kana Shimizu, Koji Nuida, Hiromi Arai, Shigeo Mitsunari, Nuttapong Attrapadung, Michiaki Hamada, Koji Tsuda, Takatsugu Hirokawa, Jun Sakuma, Goichiro Hanaoka, Kiyoshi Asai
BMC Bioinform.10
2015 Revocable Group Signature with Constant-Size Revocation List
abstract
It is essential that a multi-user cryptographic primitive be revocable since a legitimate user may quit the organization, or may act on malicious intent, or the relevant key may be leaked. In the group signature context, usually the group manager publishes the revocation list that contains revocation tokens. Since signers/verifiers need to obtain the revocation list in each revocation epoch to generate/verify a group signature, a small-size revocation list is really important in practice. However, all previous revocable group signatures require at least an |$O(r)$|-size revocation list, where |$r$| is the number of revoked users. In this paper, we propose the first revocable group signature scheme with a constant-size revocation list using identity-based revocation (IBR) techniques. We use an IBR scheme proposed by Attrapadung–Libert–Panafieu (PKC 2011) as a building block. As in the Libert–Peters–Yung schemes (EUROCRYPT 2012/CRYPTO 2012), no signing key update is required. In addition, the verification cost does not depend on the number of revoked users |$r$|⁠. Although the maximum number of revoked users needs to be fixed in the setup phase, the maximum number of group members is potentially unbounded as in IBR. This property has not been achieved in the recent scalable revocable group signature schemes and seems to be of independent interest.
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001
Comput. J.3
2015 Public-Key Encryption Schemes with Bounded CCA Security and Optimal Ciphertext Length Based on the CDH and HDH Assumptions
abstract
In Cramer et al. (2007, Bounded CCA2-Secure Encryption. In Kurosawa, K. (ed.), Advances in Cryptology – ASIACRYPT 2007, Kuching, Malaysia, December 2–6, Lecture Notes in Computer Science, Vol. 4833, pp. 502–518. Springer, Berlin, Germany) proposed a public-key encryption scheme secure against adversaries with a bounded number of decryption queries based on the decisional Diffie–Hellman problem. In this paper, we show that the same result can be obtained based on weaker computational assumptions, namely: the computational Diffie–Hellman and the hashed Diffie–Hellman assumptions.
Mayana Pereira, Rafael Dowsley, Anderson C. A. Nascimento, Goichiro Hanaoka
Comput. J.4
2014 A Revocable Group Signature Scheme from Identity-Based Revocation Techniques: Achieving Constant-Size Revocation List
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001
ACNS3
2014 All-but-One Dual Projective Hashing and Its Applications
Zongyang Zhang, Yu Chen 0003, Sherman S. M. Chow, Goichiro Hanaoka, Zhenfu Cao, Yunlei Zhao
ACNS4
2014 Self-bilinear Map on Unknown Order Groups from Indistinguishability Obfuscation and Its Applications
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
CRYPTO (2)3
2014 New Security Proof for the Boneh-Boyen IBE: Tight Reduction in Unbounded Multi-challenge Security
Nuttapong Attrapadung, Goichiro Hanaoka, Shota Yamada 0001
ICICS2
2014 A Short Fail-Stop Signature Scheme from Factoring
Takashi Yamakawa, Nobuaki Kitajima, Takashi Nishide, Goichiro Hanaoka, Eiji Okamoto
ProvSec4
2014 Compact Public Key Encryption with Minimum Ideal Property of Hash Functions
Kazuki Yoneyama, Goichiro Hanaoka
ProvSec2
2014 Chosen Ciphertext Security via Point Obfuscation
Takahiro Matsuda 0002, Goichiro Hanaoka
TCC2
2014 A Privacy-Enhanced Access Log Management Mechanism in SSO Systems from Nominative Signatures
abstract
In online services, e.g., Online shopping, a service provider (SP) manages access logs containing customers' buying histories. Therefore, user's personal information, e.g., Their hobbies and diversions, is revealed from the exposed logs if each customer can be linked. In fact, such information exposure has occurred due to the popularization of online services. To cope with this problem, SPs may only have to delete access logs, but then no illegitimate users, who accessed the server illegally, will be traced from the logs. In this paper, we propose a log management mechanism where (1) no user information is revealed even if logs are exposed, but (2) illegitimate users can be traced when necessary. Specifically, we consider single sign on (SSO) systems, since plural access logs might be connected by one account, and this could trigger the above privacy infringement problem. We construct our privacy-enhanced access log management mechanism based on the Wang-Wang-Susilo SSO system (TrustCom 2013) which applies nominative signatures as its building block. Specifically, we realize the system by additionally applying the invisibility property of the Schuldt-Hanaoka nominative signature scheme (ACNS 2011). Finally, we estimate the efficiency of the proposed system by using Pairing-Based Cryptography (PBC) library and confirmed that for each algorithm, computation time is at most just over 80 milliseconds on a PC, which seems sufficiently practical.
Sanami Nakagawa, Keita Emura, Goichiro Hanaoka, Akihisa Kodate, Takashi Nishide, Eiji Okamoto, Yusuke Sakai 0001
TrustCom3
2013 A group signature scheme with unbounded message-dependent opening
abstract
Group signature with message-dependent opening (GS-MDO) is a kind of group signature in which only the signers who have created group signatures on problematic messages will be identified. In the previous GS-MDO scheme, however, the number of problematic messages is bounded owing to a limitation of the Groth-Sahai proofs. In this paper, we propose the first GS-MDO scheme with the unbounded-MDO functionality in the random oracle model. Our unbounded GS-MDO scheme is based on the short group signature scheme proposed by Boneh, Boyen, and Shacham and the Boneh-Franklin identity-based encryption scheme. To combine these building blocks and to achieve CCA-anonymity, we also construct a special type of multiple encryption. This technique yields an efficient construction compared with the previous bounded GS-MDO scheme: the signature of our scheme contains about 16 group elements (3630 bits), whereas that of the previous scheme has about 450 group elements (75820 bits).
Kazuma Ohara, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka
AsiaCCS4
2013 Reducing Public Key Sizes in Bounded CCA-Secure KEMs with Optimal Ciphertext Length
Takashi Yamakawa, Shota Yamada 0001, Takahiro Matsuda 0002, Goichiro Hanaoka, Noboru Kunihiro
ISC4
2013 Partially Wildcarded Attribute-based Encryption and Its Efficient Construction
Go Ohtake, Yuki Hironaka, Kenjiro Kai, Yosuke Endo, Goichiro Hanaoka, Hajime Watanabe, Shota Yamada 0001, Kohei Kasamatsu, Takashi Yamakawa, Hideki Imai
SECRYPT5
2013 On the Security of Pseudorandomized Information-Theoretically Secure Schemes
abstract
In this paper, we discuss a naive method of randomness reduction for cryptographic schemes, which replaces the required perfect randomness with output distribution of a computationally secure pseudorandom generator (PRG). We propose novel ideas and techniques for evaluating the indistinguishability between the random and pseudorandom cases, even against an adversary with computationally unbounded attack algorithm. Hence, the PRG-based randomness reduction can be effective even for information-theoretically secure cryptographic schemes, especially when the amount of information received by the adversary is small. In comparison to a preceding result of Dubrov and Ishai (STOC 2006), our result removes the requirement of generalized notion of “nb-PRGs” and is effective for more general kinds of protocols. We give some numerical examples to show the effectiveness of our result in practical situations, and we also propose a further idea for improving the effect of the PRG-based randomness reduction.
Koji Nuida, Goichiro Hanaoka
IEEE Trans. Inf. Theory2
2012 On the Impossibility of Constructing Efficient Key Encapsulation and Programmable Hash Functions in Prime Order Groups
Goichiro Hanaoka, Takahiro Matsuda 0002, Jacob C. N. Schuldt
CRYPTO1
2012 Generic Construction of Chosen Ciphertext Secure Proxy Re-Encryption
Goichiro Hanaoka, Yutaka Kawai, Noboru Kunihiro, Takahiro Matsuda 0002, Jian Weng 0001, Rui Zhang 0002, Yunlei Zhao
CT-RSA1
2012 Two-Dimensional Representation of Cover Free Families and Its Applications: Short Signatures and More
Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
CT-RSA2
2012 Group Signatures with Message-Dependent Opening
Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazumasa Omote
Pairing3
2011 Non-transferable User Certification Secure against Authority Information Leaks and Impersonation Attacks
Jacob C. N. Schuldt, Goichiro Hanaoka
ACNS2
2010 Improving Efficiency of an ‘On the Fly' Identification Scheme by Perfecting Zero-Knowledgeness
Bagus Santoso, Kazuo Ohta, Kazuo Sakiyama, Goichiro Hanaoka
CT-RSA4
2010 Public Key Encryption Schemes with Bounded CCA Security and Optimal Ciphertext Length Based on the CDH Assumption
Mayana Pereira, Rafael Dowsley, Goichiro Hanaoka, Anderson C. A. Nascimento
ISC3
2010 Efficient Broadcast Encryption with Personalized Messages
Go Ohtake, Goichiro Hanaoka, Kazuto Ogawa
ProvSec2
2010 Toward an Easy-to-Understand Structure for Achieving Chosen Ciphertext Security from the Decisional Diffie-Hellman Assumption
Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro
ProvSec2
2009 A generic construction of useful client puzzles
abstract
Denial of Service (DoS) attacks are serious threats for network societies. For dealing with DoS attacks, Jakobsson and Juels first proposed the notion of useful client puzzles (UCPs) which simultaneously decrease servers' burden and increase clients'. In ACM CCS'04, Diament, Lee, Keromytis, and Yung introduced the decryption-based UCPs. In this paper, we give a general framework for constructing such UCPs which is based on identity-based cryptography along with well-analyzed symmetric key authenticated encryption techniques (without random oracles). By using this framework, we can flexibly construct various UCPs according to different types of system requirements. We also give some instantiations: the first is a UCP based on the Boneh-Boyen Identity based encryption scheme, with provable security in the standard model. Another one is a UCP based on the Boneh-Gentry-Hamburg identity-based encryption scheme, which doesn't require pairings.
Rui Zhang 0002, Goichiro Hanaoka, Hideki Imai
AsiaCCS2
2009 An Efficient Encapsulation Scheme from Near Collision Resistant Pseudorandom Generators and Its Application to IBE-to-PKE Transformations
Takahiro Matsuda 0002, Goichiro Hanaoka, Kanta Matsuura, Hideki Imai
CT-RSA2
2008 Efficient Chosen Ciphertext Secure Public Key Encryption under the Computational Diffie-Hellman Assumption
Goichiro Hanaoka, Kaoru Kurosawa
ASIACRYPT1
2008 Introduction to the Special Issue on Information Theoretic Security
abstract
The 26 papers and six items of correspondence in this special issue focus on information theoretic security. The papers and items of correspondence are summarized here.
Hideki Imai, Goichiro Hanaoka, Ueli Maurer, Yuliang Zheng 0001
IEEE Trans. Inf. Theory2
2007 Bounded CCA2-Secure Encryption
Ronald Cramer, Goichiro Hanaoka, Dennis Hofheinz, Hideki Imai, Eike Kiltz, Rafael Pass, Abhi Shelat, Vinod Vaikuntanathan
ASIACRYPT2
2007 Orthogonality between Key Privacy and Data Privacy, Revisited
Rui Zhang 0002, Goichiro Hanaoka, Hideki Imai
Inscrypt2
2007 Formal Security Treatments for Signatures from Identity-Based Encryption
Yang Cui 0001, Eiichiro Fujisaki, Goichiro Hanaoka, Hideki Imai, Rui Zhang 0002
ProvSec3
2007 A CDH-Based Strongly Unforgeable Signature Without Collision Resistant Hash Function
Takahiro Matsuda 0002, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Hideki Imai
ProvSec3
2006 Generic Transforms to Acquire CCA-Security for Identity Based Encryption: The Cases of FOpkc and REACT
Takashi Kitagawa, Peng Yang 0002, Goichiro Hanaoka, Rui Zhang 0002, Hajime Watanabe, Kanta Matsuura, Hideki Imai
ACISP3
2006 Adaptively Secure Traitor Tracing Against Key Exposure and Its Application to Anywhere TV Service
Kazuto Ogawa, Goichiro Hanaoka, Hideki Imai
ACISP2
2006 Efficient Identity-Based Encryption with Tight Security Reduction
Nuttapong Attrapadung, Jun Furukawa 0001, Takeshi Gomi, Goichiro Hanaoka, Hideki Imai, Rui Zhang 0002
CANS4
2006 Digitally signed document sanitizing scheme based on bilinear maps
abstract
A digital signature does not allow any alteration of the document to which it is attached. Appropriate alteration of some signed documents, however, should be allowed because there are security requirements other than the integrity of the document. In the disclosure of official information, for example, sensitive information such as personal information or national secrets is masked when an official document is sanitized so that its nonsensitive information can be disclosed when it is requested by a citizen. If this disclosure is done digitally by using the current digital signature schemes, the citizen cannot verify the disclosed information because it has been altered to prevent the leakage of sensitive information. The confidentiality of official information is thus incompatible with the integrity of that information, and this is called the digital document sanitizing problem. Conventional solutions such as content extraction signatures and digitally signed document sanitizing schemes with disclosure condition control can either let the sanitizer assign disclosure conditions or hide the number of sanitized portions. The digitally signed document sanitizing scheme we propose here is based on the aggregate signature derived from bilinear maps and can do both.
Kunihiko Miyazaki, Goichiro Hanaoka, Hideki Imai
AsiaCCS2
2006 Relations Among Notions of Security for Identity Based Encryption Schemes
Nuttapong Attrapadung, Yang Cui 0001, David Galindo, Goichiro Hanaoka, Ichiro Hasuo, Hideki Imai, Kanta Matsuura, Peng Yang 0002, Rui Zhang 0002
LATIN4
2006 Unconditionally Secure Anonymous Encryption and Group Authentication
abstract
Anonymous channels or similar techniques that achieve sender's anonymity play important roles in many applications, e.g. electronic voting. However, they will be meaningless if cryptographic primitives containing sender's identity are carelessly used during the transmission. In computationally secure settings, this problem may be easily overcome by using public key encryption and group signatures. However, in an unconditionally secure setting, in which no computational difficulty is assumed, this is not an easy case as such. As the increasing computational power approaches the point where security policy can no longer assume the difficulty of solving factoring or discrete logarithm problems, it must shift its focus to assuring the solvency of unconditionally secure schemes that provide long-term security. The main contribution of this paper is to study the security primitives for the above problem. In this paper, we first define the unconditionally secure asymmetric encryption scheme, which is an encryption scheme with unconditional security and where it is impossible for a receiver to deduce the identity of a sender from the encrypted message. We also investigate tight lower bounds on required memory sizes from an information theoretic viewpoint and show an optimal construction based on polynomials. It is remarkable to see that these bounds are considerably different from those in Shannon's model of the conventional unconditionally secure symmetric encryption. Other than the polynomial-based scheme, we also show a construction based on combinatorial theory, a non-malleable scheme and a multi-receiver scheme. Then, we define and formalize the group authentication code (GA-code), which is an unconditionally secure authentication code with anonymity like group signatures. In this scheme, any authenticated user will be able to generate and send an authenticated message while the receiver can verify the legitimacy of the message—that it has been sent from a legitimate user but at the same time retains his anonymity. However, by cooperating with the group authority, such as in the case of disputes, the receiver is able to obtain information of the user's identity. For GA-code, we show two concrete constructions.
Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai
Comput. J.1
2005 Identity-Based Hierarchical Strongly Key-Insulated Encryption and Its Application
Yumiko Hanaoka, Goichiro Hanaoka, Junji Shikata, Hideki Imai
ASIACRYPT2
2005 A secure traitor tracing scheme against key exposure
abstract
Copyright protection is a major issue in distributing digital content. On the other hand, improvements to usability are sought by content users. In this paper, we propose a secure traitor tracing scheme against key exposure (TTaKE) which contains the properties of both a traitor tracing scheme and a forward secure public key cryptosystem. Its structure fits current digital broadcasting systems and it may be useful in preventing traitors from making illegal decoders and in minimizing the damage from accidental key exposure. It can improve usability through these properties
Kazuto Ogawa, Goichiro Hanaoka, Hideki Imai
ISIT2
2004 Information Theoretically Secure Oblivious Polynomial Evaluation: Model, Bounds, and Constructions
Goichiro Hanaoka, Hideki Imai, Jörn Müller-Quade, Anderson C. A. Nascimento, Akira Otsuka, Andreas J. Winter 0002
ACISP1
2004 Unconditionally Non-interactive Verifiable Secret Sharing Secure against Faulty Majorities in the Commodity Based Model
Anderson C. A. Nascimento, Jörn Müller-Quade, Akira Otsuka, Goichiro Hanaoka, Hideki Imai
ACNS4
2004 On the Security of Cryptosystems with All-or-Nothing Transform
Rui Zhang 0002, Goichiro Hanaoka, Hideki Imai
ACNS2
2003 Separating Encryption and Key Issuance in Digital Rights Management Systems
Goichiro Hanaoka, Kazuto Ogawa, Itsuro Murota, Go Ohtake, Keigo Majima, Kimiyuki Oyamada, Seiichi Gohshi, Seiichi Namba, Hideki Imai
ACISP1
2003 The Role of Arbiters in Asymmetric Authentication Schemes
Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai
ISC1
2003 Unconditionally Secure Homomorphic Pre-distributed Bit Commitment and Secure Two-Party Computations
Anderson C. A. Nascimento, Jörn Müller-Quade, Akira Otsuka, Goichiro Hanaoka, Hideki Imai
ISC4
2002 Unconditionally Secure Anonymous Encryption and Group Authentication
Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai
ASIACRYPT1
2002 Security Notions for Unconditionally Secure Signature Schemes
Junji Shikata, Goichiro Hanaoka, Yuliang Zheng 0001, Hideki Imai
EUROCRYPT2
2002 Unconditionally Secure Key Insulated Cryptosystems: Models, Bounds and Constructions
Yumiko Hanaoka, Goichiro Hanaoka, Junji Shikata, Hideki Imai
ICICS2
2002 Traceability Schemes for Signed Documents
Shoko Yonezawa, Goichiro Hanaoka, Junji Shikata, Hideki Imai
ISC2
2002 Cryptography with information theoretic security
abstract
Summary form only given. We discuss information-theoretic methods to prove the security of cryptosystems. We study what is called, unconditionally secure (or information-theoretically secure) cryptographic schemes in search for a system that can provide long-term security and that does not impose limits on the adversary's computational power.
Hideki Imai, Goichiro Hanaoka, Junji Shikata, Akira Otsuka, Anderson C. A. Nascimento
ITW2
2002 A Hierarchical Non-interactive Key-Sharing Scheme with Low Memory Size and High Resistance against Collusion Attacks
abstract
Efficient ID-based key sharing schemes are desired worldwide for secure communications on Internet and other networks. The Key Predistribution Systems (KPSs) are a large class of such key sharing schemes. The remarkable property of KPSs is that in order to share the key, a participant should only input its partner's identifier to its secret KPS algorithm. Although it has many advantages in terms of efficiency, on the other hand it is vulnerable to certain collusion attacks. While conventional KPSs establish communication links between any pair of entities in a communication system, in many practical communication systems, such as broadcasting, not all links are required. In this paper, we propose a new version of KPS which is called the Hierarchical KPS. In the Hierarchical KPS, simply by removing unnecessary communication links, we can significantly increase the collusion threshold. As an example, for a typical security parameter setting, the collusion threshold of the Hierarchical KPS is 16 times higher than that of the conventional KPS while using the same amount of memory at the KPS center. The memory required by the user is even reduced by a factor $1/16$ in comparison with the conventional linear scheme. Hence, Hierarchical KPS provides a more efficient method for secure communication.
Goichiro Hanaoka, Tsuyoshi Nishioka, Yuliang Zheng 0001, Hideki Imai
Comput. J.1
2001 Efficient Asymmetric Public-Key Traitor Tracing without Trusted Agents
Yuji Watanabe, Goichiro Hanaoka, Hideki Imai
CT-RSA2
2000 Unconditionally Secure Digital Signature Schemes Admitting Transferability
Goichiro Hanaoka, Junji Shikata, Yuliang Zheng 0001, Hideki Imai
ASIACRYPT1
1999 An Efficient Hierarchical Identity-Based Key-Sharing Method Resistant against Collusion-Attacks
Goichiro Hanaoka, Tsuyoshi Nishioka, Yuliang Zheng 0001, Hideki Imai
ASIACRYPT1
1999 Optimal Construction of Unconditionally Secure ID-Based Key Sharing Scheme for Large-Scale Networks
Goichiro Hanaoka, Tsuyoshi Nishioka, Yuliang Zheng 0001, Hideki Imai
ICICS1
1998 LITESET: A Light-Weight Secure Electronic Transaction Protocol
Goichiro Hanaoka, Yuliang Zheng 0001, Hideki Imai
ACISP1