VLDB 2026 Research / reviewers in the wild / expert
Yvo Desmedt
dblp:d/YvoDesmedt
· DBLP profile ↗
102ranked-venue papers
55as first author
6since 2021 · last 2026
0000-0002-6679-7484ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 79 · 45 first-author · 5 since 2021Theory of computation · 16 · 7 first-author · 1 since 2021Computer networks · 3 · 2 first-authorDatabases, data management, data science and information retrieval · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Oblivis: A Framework for Delegated and Efficient Oblivious TransferabstractAs database deployments shift toward cloud platforms and edge devices, thin clients need to securely retrieve sensitive records without leaking their query intent or metadata to the proxies that mediate access. Oblivious Transfer (OT) is a core tool for private retrieval, yet existing OTs assume direct client–database interaction and lack support for delegated querying or lightweight clients. We present Oblivis, a modular framework of new OT protocols that enable delegated, privacy-preserving query execution. Oblivis allows clients to retrieve database records without direct access, protects against leakage to both databases and proxies, and is designed with practical efficiency in mind. Its components include: (1) Delegated-Query OT, which permits secure outsourcing of query generation; (2) Multi-Receiver OT for merged, cloud-hosted databases; (3) a compiler producing constant-size responses suitable for thin clients; and (4) Supersonic OT, a proxy-based, information-theoretic, and highly efficient 1-out-of-2 OT. The protocols are formally defined and proven secure in the simulation-based paradigm, under non-colluding assumption. We implement and empirically evaluate Supersonic OT. It achieves at least a 92× speedup over a highly efficient 1-out-of-2 OT, and a 2.6×–106× speedup over a standard OT extension across 200–100,000 invocations. Our implementation further shows that Supersonic OT remains efficient even on constrained hardware, e.g., it completes an end-to-end transfer in 1.36 ms on a Raspberry Pi 4. Aydin Abadi, Yvo Desmedt |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Poster: Byzantine Discrepancy Attacks against Calendar, Set-intersection and NationsabstractNowadays Communication Security usually refers to digital communication and in particular via the Internet. We explain why the topic should be broadened to include any communication, in particular when done in person, e.g., with co-authors, colleagues, reporters, etc. Yvo Desmedt, Alireza Kavousi, Aydin Abadi |
CCS | 1 |
| 2023 | Using Untrusted and Unreliable Cloud Providers to Obtain Private Email
Nicolas Chiapputo, Yvo Desmedt, Kirill Morozov |
SECRYPT | 2 |
| 2022 | Are Clouds making Our Research Irrelevant and Who Is at Fault? (Position Paper)
Yvo Desmedt |
SECRYPT | 1 |
| 2021 | Extremal set theory and LWE based access structure hiding verifiable secret sharing with malicious-majority and free verification
Vipin Singh Sehrawat, Foo Yee Yeo, Yvo Desmedt |
Theor. Comput. Sci. | 3 |
| 2021 | Framing in Secret SharingabstractSecret sharing, a well-known cryptographic technique, introduced 40 years ago as a private and reliable variant of classical storage, has now become a major cryptographic primitive with numerous real-world applications. In this paper we consider the digital forensics aspects of secret sharing. We investigate the problem of framing which occurs when a coalition is able to calculate the share of a participant who does not belong to it. In the extreme case one authorized coalition can calculate shares of another authorized coalition and use the secret in some way blaming another authorized coalition for their action. In this context seniority plays an important role. We define seniority, which comes natural in the context of hierarchical access structures. Roughly speaking, our work shows that in an ideal secret sharing scheme an authorized coalition cannot frame participants who are less senior than all members of the coalition and is able to frame a participant who is more senior than at least one pivotal member of the coalition. We show that for any monotone access structure there exists a (non-ideal) frameproof secret sharing scheme. Yvo Desmedt, Songbao Mo, Arkadii M. Slinko |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Access Structure Hiding Secret Sharing from Novel Set Systems and Vector Families
Vipin Singh Sehrawat, Yvo Desmedt |
COCOON | 2 |
| 2019 | Evolving Perfect Hash Families: A Combinatorial Viewpoint of Evolving Secret Sharing
Yvo Desmedt, Sabyasachi Dutta, Kirill Morozov |
CANS | 1 |
| 2019 | Bi-homomorphic Lattice-Based PRFs and Unidirectional Updatable Encryption
Vipin Singh Sehrawat, Yvo Desmedt |
CANS | 2 |
| 2019 | Perfect AnonymityabstractFor 35 years, the cryptographic community has created the impression that anonymous communication is always possible. Chaum's dining cryptographer's solution is regarded as achieving unconditional security. Chaum's MIX approach, namely, applying a uniformly random permutation on the plaintexts to be sent, is often given as a definition for anonymity. However, people working in law enforcement know that attempts by whistle-blowers and criminals to remain at large, often fail. The content of the message may reveal the name of the sender or may leak for whom the message is really intended. To understand this issue, we give a definition of perfect anonymity. We contrast our definition with Chaum's approach and discuss the impact on Chaum's dining cryptographer's solution. Yvo Desmedt, Fred Piper |
IEEE Trans. Inf. Theory | 1 |
| 2017 | Candidate MDS Array Codes for Tolerating Three Disk Failures in RAID-7 Architectures
Mayur Punekar, Qutaibah M. Malluhi, Yongge Wang 0001, Yvo Desmedt |
BDCAT | 4 |
| 2017 | Computational Aspects of Ideal (t, n)-Threshold Scheme of Chen, Laing, and Martin
Mayur Punekar, Qutaibah M. Malluhi, Yvo Desmedt, Yongge Wang 0001 |
CANS | 3 |
| 2015 | Parity Check based redistribution of secret sharesabstractIn 2002, Wong-Wang-Wing presented a verifiable redistributing secret shares protocol, where the new parties must have been honest. They used Feldman's Verifiable Secret Sharing scheme, which assumed that the discrete logarithm is hard. In 2013, Nojoumian and Stinson presented information-theoretically (unconditionally) secure schemes under assumption that at most t out of 4t+1 parties are actively corrupt, where only the threshold (but not the number of parties) can be changed. We present an unconditionally secure solution assuming that at most t out of 3t+1 parties are actively corrupt. Our protocol uses properties of the parity-check matrix of a Generalized Reed-Solomon code. Moreover, we introduce a new open problem in the area of Reed-Solomon decoding. Yvo Desmedt, Kirill Morozov |
ISIT | 1 |
| 2014 | Efficient secret sharing schemes achieving optimal information rateabstractOne of the important problems in secret sharing schemes is to establish bounds on the size of the shares to be given to participants in secret sharing schemes. The other important problem in secret sharing schemes is to reduce the computational complexity in both secret distribution phase and secret reconstruction phase. In this paper, we design efficient threshold (n, k) secret sharing schemes to achieve both of the above goals. In particular, we show that if the secret size |s| is larger than max{1 + log2n, n(n - k)/(n - 1)}, then ideal secret sharing schemes exist. In the efficient ideal secret sharing schemes that we will construct, only XOR-operations on binary strings are required (which is the best we could achieve). These schemes will have many applications both in practice and in theory. For example, they could be used to design very efficient verifiable secret sharing schemes which will have broad applications in secure multi-party computation and could be used to design efficient privacy preserving data storage in cloud systems. Yongge Wang 0001, Yvo Desmedt |
ITW | 2 |
| 2012 | Applying Divertibility to Blind Ballot Copying in the Helios Internet Voting System
Yvo Desmedt, Pyrros Chaidos |
ESORICS | 1 |
| 2012 | Online Social Networks, a Criminals Multipurpose Toolbox (Poster Abstract)
Shah Mahmood, Yvo Desmedt |
RAID | 2 |
| 2012 | Graph Coloring Applied to Secure Computation in Non-Abelian Groups
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Xiaoming Sun 0001, Christophe Tartary, Huaxiong Wang, Andrew Chi-Chih Yao |
J. Cryptol. | 1 |
| 2011 | Secure Communication in Multicast Graphs
Qiushi Yang, Yvo Desmedt |
ASIACRYPT | 2 |
| 2011 | Poster: preliminary analysis of Google+'s privacy
Shah Mahmood, Yvo Desmedt |
CCS | 2 |
| 2011 | Edge-colored graphs with applications to homogeneous faults
Yongge Wang 0001, Yvo Desmedt |
Inf. Process. Lett. | 2 |
| 2010 | General Perfectly Secure Message Transmission Using Linear Codes
Qiushi Yang, Yvo Desmedt |
ASIACRYPT | 2 |
| 2010 | Redesigning Group Key Exchange Protocol Based on Bilinear Pairing Suitable for Various Environments
Yvo Desmedt, Atsuko Miyaji |
Inscrypt | 1 |
| 2010 | Pseudo-Cryptanalysis of Luffa
Keting Jia, Yvo Desmedt, Lidong Han, Xiaoyun Wang 0001 |
Inscrypt | 2 |
| 2010 | Improved Distinguishing Attack on Rabbit
Yi Lu 0002, Yvo Desmedt |
ISC | 2 |
| 2010 | Equilibria of plurality voting with abstentionsabstractIn the traditional voting manipulation literature, it is assumed that a group of manipulators jointly misrepresent their preferences to get a certain candidate elected, while the remaining voters are truthful. In this paper, we depart from this assumption, and consider the setting where all voters are strategic. In this case, the election can be viewed as a game, and the election outcomes correspond to Nash equilibria of this game. We use this framework to analyze two variants of Plurality voting, namely, simultaneous voting, where all voters submit their ballots at the same time, and sequential voting, where the voters express their preferences one by one. For simultaneous voting, we characterize the preference profiles that admit a pure Nash equilibrium, but show that it is computationally hard to check if a given profile fits our criterion. For sequential voting, we provide a complete analysis of the setting with two candidates, and show that for three or more candidates the equilibria of sequential voting may behave in a counterintuitive manner. Yvo Desmedt, Edith Elkind |
EC | 1 |
| 2010 | A New and Improved Paradigm for Hybrid Encryption Secure Against Chosen-Ciphertext Attack
Yvo Desmedt, Rosario Gennaro, Kaoru Kurosawa, Victor Shoup |
J. Cryptol. | 1 |
| 2008 | Hybrid Damgård Is CCA1-Secure under the DDH Assumption
Yvo Desmedt, Helger Lipmaa, Duong Hieu Phan |
CANS | 1 |
| 2008 | A CCA Secure Hybrid Damgård's ElGamal Encryption
Yvo Desmedt, Duong Hieu Phan |
ProvSec | 1 |
| 2008 | Perfectly Secure Message Transmission RevisitedabstractSecure communications guaranteeing reliability and privacy (without unproven assumptions) in networks with active adversaries has been an important research issue. It has been studied for point to point networks by Dolev-Dwork-Waarts-Yung (J. ACM1993), Desmedt–Wang (Eurocrypt 2002), and Srinathan–Narayanan–Rangan (Crypto 2004). Dolev–Dwork–Waarts–Yung gave necessary and sufficient conditions for secure communication in networks with the condition that 1) all the channels are two-way; or 2) all the channels are one-way from the sender to the receiver. In this paper, we study the general case with a network modeled by a directed graph. In this general case, there are communication channels from the sender to the receiver and there are feedback channels from the receiver to the sender. We give necessary and sufficient bounds on the number of channels that are required from sender to receiver given a number of “feedback” channels from receiver to sender. We give these bounds for the case reliability is perfect, as well as for the case it is not perfect. Yongge Wang 0001, Yvo Desmedt |
IEEE Trans. Inf. Theory | 2 |
| 2007 | Secure Protocols with Asymmetric Trust
Ivan Damgård, Yvo Desmedt, Matthias Fitzi, Jesper Buus Nielsen |
ASIACRYPT | 2 |
| 2007 | Unconditionally secure ring authenticationabstractWe propose ring authentication in unconditionally secure setting. In a ring authentication system a sender can choose a set of users and construct an authenticated message for a receiver such that the receiver can verify authenticity of the message with respect to the user group chosen by the real sender. The sender will be unconditionally secure even if the receiver has corrupted up to c users and has access to up to ℓ past messages in the system. This functionality is similar to the one provided by ring signature systems with the difference that protection is against an adversary with unlimited power. (This also implies that the verification is not public and is by group members.) In ring signatures an adversary with unlimited computational power can always forge signed messages attributing them to groups of his choice. In our proposed systems the success chance of the adversary can be reduced to the required security of the system. We define model, propose a generic construction whose security is reduced to the security of its building blocks, and give concrete examples of this construction. The construction can also be used in computational setting resulting in ring authentication systems without public key cryptography. Reihaneh Safavi-Naini, Yvo Desmedt |
AsiaCCS | 3 |
| 2007 | On Secure Multi-party Computation in Black-Box Groups
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Huaxiong Wang |
CRYPTO | 1 |
| 2007 | Non-degrading Erasure-Tolerant Information Authentication with an Application to Multicast Stream Authentication over Lossy Channels
Yvo Desmedt, Goce Jakimoski |
CT-RSA | 1 |
| 2007 | A Generalization and a Variant of Two Threshold Cryptosystems Based on Factoring
Yvo Desmedt, Kaoru Kurosawa |
ISC | 1 |
| 2006 | Revisiting Colored Networks and Privacy Preserving Censorship
Yvo Desmedt, Yongge Wang 0001, Mike Burmester |
CRITIS | 1 |
| 2006 | A Non-malleable Group Key Exchange Protocol Robust Against Active Insiders
Yvo Desmedt, Josef Pieprzyk, Ron Steinfeld, Huaxiong Wang |
ISC | 1 |
| 2006 | Index Calculation Attacks on RSA Signature and Encryption
Jean-Sébastien Coron, David Naccache, Yvo Desmedt, Andrew M. Odlyzko, Julien P. Stern |
Des. Codes Cryptogr. | 3 |
| 2005 | Potential Impacts of a Growing Gap Between Theory and Practice in Information Security
Yvo Desmedt |
ACISP | 1 |
| 2005 | Radio Networks with Reliable Communication
Yvo Desmedt, Yongge Wang 0001, Reihaneh Safavi-Naini, Huaxiong Wang |
COCOON | 1 |
| 2005 | A Complete Characterization of Tolerable Adversary Structures for Secure Point-to-Point Transmissions Without Feedback
Yvo Desmedt, Yongge Wang 0001, Mike Burmester |
ISAAC | 1 |
| 2005 | Electronic Voting: Starting Over?
Yvo Desmedt, Kaoru Kurosawa |
ISC | 1 |
| 2005 | A secure and scalable Group Key Exchange system
Mike Burmester, Yvo Desmedt |
Inf. Process. Lett. | 2 |
| 2004 | A New Paradigm of Hybrid Encryption Scheme
Kaoru Kurosawa, Yvo Desmedt |
CRYPTO | 2 |
| 2004 | Identity-based Key Infrastructures (IKI)abstractKohnfelder realized in 1978 that public key schemes require a Public Key Infrastructure (PKI) . X500/X509 were set up to standardize these ideas. PGP, proposed by Zimmermann is an alternative to the original PKI idea. Variants of the PGP based PKI were discussed independently by Reiter-Stubblebine and Burmester-Desmedt-Kabatianskii. The goal of Shamir’s 1984 idea of “identity-based” cryptography was to avoid a Public Key Infrastructure. Instead of having the users have their own public key, the identity of the user is the “public key,” and a trusted center provides each party with a secret key. Several identitybased cryptosystems have been proposed, in particular recently. We analyze Shamir’s identity-based concept critically. We argue the need for at least a registration infrastructure, which we call a”basic Identity-based Key Infrastructure.” Moreover, if secret keys of users can be stolen or lost, the infrastructure required to deal with this is as complex as the one of PKI. We make further comparisons between public key systems and identity-based ones. Yvo Desmedt, Mike Burmester |
SEC | 1 |
| 2003 | Error Correcting and Complexity Aspects of Linear Secret Sharing Schemes
Yvo Desmedt, Kaoru Kurosawa, Tri Van Le |
ISC | 1 |
| 2002 | Maximum Flows and Critical Vertices in AND/OR Graphs
Yvo Desmedt, Yongge Wang 0001 |
COCOON | 1 |
| 2002 | Perfectly Secure Message Transmission Revisited
Yvo Desmedt, Yongge Wang 0001 |
EUROCRYPT | 1 |
| 2002 | Is there a Need for Survivable Computation in Critical Infrastructures?
Yvo Desmedt |
Inf. Secur. Tech. Rep. | 1 |
| 2001 | Broadcast anti-jamming systems
Yvo Desmedt, Reihaneh Safavi-Naini, Huaxiong Wang, Lynn Margaret Batten, Chris Charnes, Josef Pieprzyk |
Comput. Networks | 1 |
| 2001 | Secure Communication in Multicast Channels: The Answer to Franklin and Wright's Question
Yongge Wang 0001, Yvo Desmedt |
J. Cryptol. | 2 |
| 2000 | Enabling Secure On-Line DNS Dynamic UpdateabstractDomain Name System (DNS) is the system for the mapping between easily memorizable host names and their IP addresses. Due to its criticality, security extensions to DNS have been proposed in an Internet Engineering Task Force (IETF) working group to provide authentication. We point out two difficulties in the current DNSSEC (DNS Security Extension) standards in the handling of DNS dynamic updates: the online storage of a zone security key, creating a single point of attack for both inside and outside attackers; and the violation of the role separation principle, which in the context of DNSSEC separates the roles of zone security managers from DNS server administrators. To address these issues, we propose a secure DNS architecture that is based on threshold cryptography. We show that the architecture adheres to the role separation principle without presenting any single point of attack. Our experimental results reveal that, in terms of signature computation times, our architecture incurs negligible performance penalty when using RSA/MD5 signatures but significant overhead when using DSA signatures. It is our belief that the high level of security that can be achieved by the proposed architecture far outweighs its potential overhead, especially in critical DNS zones, such as the .com zone. Xunhua Wang, Yih Huang, Yvo Desmedt, David C. Rine |
ACSAC | 3 |
| 2000 | Which PKI (public key infrastructure) is the right one? (panel session)abstractSeveral organizations are setting up Public Key Infrastructures, examples are:the Corporation for Research and Educational Networking (CREN),• the Federal Government plans to fund 7 Public Key Infrastructure Models pilot programs at different federal agencies.However, experts have quite different viewpoints on how to set up such Public Key Infrastructure (PKI).Indeed, X500 and X509 are hierarchically organized (i.e.vertical), but PGP (see also Rivest-Lampson) is horizontally organized.Variants of PGP (see Reiter-Stubblebine (CCCS, ACM) and Burmester-Desmedt-Kabatianski (DIMACS)) require a minimum connectivity, i.e., a minimum number of disjoint paths in order to deal with hackers breaking into certifying entities (authorities).Moreover, Ellison-Schneier have questioned the need for a Public Key Infrastructure (PKI).Before one builds such an expensive infrastructure, experts should debate what method to use and whether a PKI is needed.While a hierarchical PKI may become the next target of computer hackers, a multiple-connected one seems much more expensive to build. Carlisle M. Adams, Mike Burmester, Yvo Desmedt, Michael K. Reiter, Philip R. Zimmermann |
CCS | 3 |
| 2000 | Moiré cryptographyabstractAs already pointed out by other researchers, one of the central problems with applicability of visual cryptography is the random nature of its secret shares.It makes secret shares not suited for carrying or for transmission over an open channel.In this paper, we apply concepts of steganography t o create secret sharing schemes whose shares are realistically looking images.Our new technique is based on an idea of employing Moir e patterns for producing images.The advantage of this scheme over others is that it does not require a complicated algorithm, thus a computer, to decrypt the ciphertext.The cleartext can be read simply by putting the ciphertexts one onto the other.We therefore give a solution to the above mentioned problem with a novel type of visual secret sharing schemes, whose secrecy and anonymity are both satis ed. Yvo Desmedt, Tri Van Le |
CCS | 1 |
| 2000 | How to Break a Practical MIX and Design a New One
Yvo Desmedt, Kaoru Kurosawa |
EUROCRYPT | 1 |
| 2000 | Secure linking of customers, merchants and banks in electronic commerce
Nikos Alexandris, Mike Burmester, Vassilios Chrissikopoulos, Yvo Desmedt |
Future Gener. Comput. Syst. | 4 |
| 2000 | Models For Dependable Computation with Multiple Inputs and Some Hardness ResultsabstractWe consider the problem of dependable computation with multiple inputs. The goal is to study when redundancy can help to achieve survivability and when it cannot. We use AND/OR graphs to model fault tolerant computations with multiple inputs. While there is a polynomial time algorithm for finding vertex disjoint paths in networks, we will show that the equivalent problem in computation systems with multiple inputs is NP-hard. Our main results are as follows. (1) We present a general model for fault tolerant computation systems with multiple inputs: AND/OR graphs. (2) We show that it is NP-hard to find two vertex disjoint solution graphs in an AND/OR graph. It follows that in the general case redundancy cannot help to achieve survivability, assuming P≠NP. Yongge Wang 0001, Yvo Desmedt, Mike Burmester |
Fundam. Informaticae | 2 |
| 2000 | Computing Functions of a Shared SecretabstractIn this work we introduce and study threshold (t-out-of-n) secret sharing schemes for families of functions ${\cal F}$. Such schemes allow any set of at least t parties to compute privately the value f(s) of a (previously distributed) secret s, for any $f\in {\cal F}$. Smaller sets of players get no more information about the secret than what follows from the value f(s). The goal is to make the shares as short as possible. Results are obtained for two different settings: we study the case when the evaluation is done on a broadcast channel without interaction, and we examine what can be gained by allowing evaluations to be done interactively via private channels. Amos Beimel, Mike Burmester, Yvo Desmedt, Eyal Kushilevitz |
SIAM J. Discret. Math. | 3 |
| 1999 | Secure Communication in an Unknown Network Using Certificates
Mike Burmester, Yvo Desmedt |
ASIACRYPT | 2 |
| 1999 | Approximation Hardness and Secure Communication in Broadcast Channels
Yvo Desmedt, Yongge Wang 0001 |
ASIACRYPT | 1 |
| 1999 | Secure Communication in Broadcast Channels: The Answer to Franklin and Wright's Question
Yongge Wang 0001, Yvo Desmedt |
EUROCRYPT | 2 |
| 1999 | Divertible and Subliminal-Free Zero-Knowledge Proofs for Languages
Mike Burmester, Yvo Desmedt, Toshiya Itoh, Kouichi Sakurai, Hiroki Shizuya |
J. Cryptol. | 2 |
| 1998 | A Comment on the Efficiency of Secret Sharing Scheme over Any Finite Abelian Group
Yvo Desmedt, Brian King, Wataru Kishimoto, Kaoru Kurosawa |
ACISP | 1 |
| 1998 | Equitable Key Escrow with Limited Time Span (or, How to Enforce Time Expiration Cryptographically)
Mike Burmester, Yvo Desmedt, Jennifer Seberry |
ASIACRYPT | 2 |
| 1998 | Audio and Optical Cryptography
Yvo Desmedt, Shuang Hou, Jean-Jacques Quisquater |
ASIACRYPT | 1 |
| 1998 | Some Bounds and a Construction for Secure Broadcast Encryption
Kaoru Kurosawa, Takuya Yoshida, Yvo Desmedt, Mike Burmester |
ASIACRYPT | 3 |
| 1998 | Optimum Traitor Tracing and Asymmetric Schemes
Kaoru Kurosawa, Yvo Desmedt |
EUROCRYPT | 2 |
| 1997 | A General Zero-Knowledge Scheme
Mike Burmester, Yvo Desmedt, Fred Piper, Michael Walker 0001 |
Des. Codes Cryptogr. | 2 |
| 1996 | Simmons' protocol is not free of subliminal channelsabstractAt the VIth Computer Security Foundations Workshop Simmons presented a protocol to make the Digital Signature Standard free of any subliminal channels. As Simmons has pointed out at several occasions the design of protocols is very difficult and one has claimed protocols to have certain properties, they turned out not to have. In this paper we demonstrate that Simmons' protocol is not free of any subliminal channels, by presenting a subliminal channel with a small capacity. We also discuss generalizations which imply that several already presented protocols claimed to be "subliminal-free" are not. Yvo Desmedt |
CSFW | 1 |
| 1996 | Efficient Multiplicative Sharing Schemes
Simon R. Blackburn, Mike Burmester, Yvo Desmedt, Peter R. Wild |
EUROCRYPT | 3 |
| 1995 | Securing Traceability of Ciphertexts - Towards a Secure Software Key Escrow System (Extended Abstract)
Yvo Desmedt |
EUROCRYPT | 1 |
| 1994 | Multiplicative Non-abelian Sharing Schemes and their Application to Threshold Cryptography
Yvo Desmedt, Giovanni Di Crescenzo, Mike Burmester |
ASIACRYPT | 1 |
| 1994 | How to share a function securelyabstractArticle Free Access Share on How to share a function securely Authors: Alfredo De Santis Dip. di Informatica ed Applicazioni Università di Salerno, Baronissi (SA), Italy Dip. di Informatica ed Applicazioni Università di Salerno, Baronissi (SA), ItalyView Profile , Yvo Desmedt Dept. of EE&CS, Univ. of Wisconsin Milwaukee, WI Dept. of EE&CS, Univ. of Wisconsin Milwaukee, WIView Profile , Yair Frankel GTE Laboratories Incorporated, Waltham, MA GTE Laboratories Incorporated, Waltham, MAView Profile , Moti Yung IBM T. J. Watson Research Center, Yorktown Heights, NY IBM T. J. Watson Research Center, Yorktown Heights, NYView Profile Authors Info & Claims STOC '94: Proceedings of the twenty-sixth annual ACM symposium on Theory of ComputingMay 1994 Pages 522–533https://doi.org/10.1145/195058.195405Published:23 May 1994Publication History 193citation1,775DownloadsMetricsTotal Citations193Total Downloads1,775Last 12 Months169Last 6 weeks18 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF Alfredo De Santis, Yvo Desmedt, Yair Frankel, Moti Yung |
STOC | 2 |
| 1994 | Perfect Homomorphic Zero-Knowledge Threshold Schemes over any Finite Abelian GroupabstractA threshold scheme is an algorithm in which a distributor creates l shares of a secret such that a fixed minimum number $( t )$ of shares are needed to regenerate the secret. A perfect threshold scheme does not reveal anything new from an information theoretical viewpoint to $t - 1$ shareholders about the secret. When the entropy of the secret is zero all sharing schemes are perfect, so perfect sharing loses its intuitive meaning. The concept of zero-knowledge sharing scheme is introduced to prove that the distributor does not reveal anything, even from a computational viewpoint. New homomorphic perfect secret threshold schemes over any finite Abelian group for which the group operation and inverses are computable in polynomial time are developed. One of the new threshold schemes also satisfies the zero-knowledge property. A generalization toward a homomorphic zero-knowledge general sharing scheme over any finite Abelian group is discussed and it is proven that ideal homomorphic threshold schemes do not always exist. Yvo Desmedt, Yair Frankel |
SIAM J. Discret. Math. | 1 |
| 1993 | Towards Practical "Proven Secure" Authenticated Key DistributionabstractSecure key distribution is a critical component in secure communications. Finding 'proven secure' practical key distribution systems is one of the major goals in cryptography. The Diffie-Hellman variants, a family of key distribution systems, achieve some of the objectives of this goal. In particular, the 'non-paradoxical' system (by Matsumoto-Takashima-Imai and Yacobi) is claimed to be secure against a known-key attack. In this paper we show that the argument used to prove this is flawed, and we explain how it can be fixed. Yvo Desmedt, Mike Burmester |
CCS | 1 |
| 1993 | Computer security by redefining what a computer isabstractThe security of modern networked computers is very low and must be dramatically improved.Integrity of data and programs is an essential aspect of computers.We propose approaches towards computer security in which the main trust is a cryptographically authenticated "keyboard".The achievability follows from the current trend towards personal computers, workstations and notebooks.We discuss how this could increase computer security and which problems remain to be solved in such an environment. Yvo Desmedt |
NSPW | 1 |
| 1992 | Non-Existence of Homomorphic General Sharing Schemes for Some Key Spaces (Extended Abstract)
Yair Frankel, Yvo Desmedt, Mike Burmester |
CRYPTO | 2 |
| 1992 | Breaking the Traditional Computer Security Barriers
Yvo Desmedt |
ESORICS | 1 |
| 1992 | Multi-Receiver/Multi-Sender Network Security: Efficient Authenticated Multicast/FeedbackabstractThe authors extend the use of traditional point-to-point message authentication to multireceiver and/or multisender scenarios. They provide efficient cryptographic authentication methods for point-to-multipoint communication, where a single sender can broadcast (multicast) only one unconditionally secure authenticator for a message and which all receivers can verify. They further develop multipoint-to-point communication (incast) in which any subset (of a specified size) of a group of individuals can transmit a single authenticator (or a signature) for a message using the group's key. This method has been called threshold authentication. It is an application layer that is transparent to the receiver which only deals with the group as one entity. The bandwidth, computations, and storage overheads are reduced substantially when compared with the traditional approach. Threshold authentication hides some aspects of the internal structure of the group, which may be important in interenterprise communication.> Yvo Desmedt, Yair Frankel, Moti Yung |
INFOCOM | 1 |
| 1992 | Efficient Zero-Knowledge Identification Schemes for Smart CardsabstractSecure identification is an important security issue to avoid computer fraud due to masquerading. This can be achieved with zero-knowledge based smart cards. We present very efficient new zero-knowledge schemes in a general algebraic setting. Particular cases of our scheme improve the performance of the Guillou–Quisquater and the Chaum–Evertse–van de Graaf schemes. Our scheme is formally proven and, overall, is more efficient than currently available schemes including the Fiat–Shamir scheme. As an application we discuss how our scheme can be used for identification, in particular as an electronic passport scheme. Mike Burmester, Yvo Desmedt, Thomas Beth |
Comput. J. | 2 |
| 1992 | Passports and visas versus IDs
George I. Davida, Yvo Desmedt |
Comput. Secur. | 2 |
| 1991 | An Efficient Zero-Knowledge Scheme for the Discrete Logarithm Based on Smooth Numbers
Yvo Desmedt, Mike Burmester |
ASIACRYPT | 1 |
| 1991 | Shared Generation of Authenticators and Signatures (Extended Abstract)
Yvo Desmedt, Yair Frankel |
CRYPTO | 1 |
| 1991 | Secure Implementations of Identification Systems
Samy Bengio, Gilles Brassard, Yvo Desmedt, Claude Goutier, Jean-Jacques Quisquater |
J. Cryptol. | 3 |
| 1990 | Identification Tokens - or: Solving the Chess Grandmaster Problem
Thomas Beth, Yvo Desmedt |
CRYPTO | 2 |
| 1990 | Abritrated Unconditionally Secure Authentication Can Be Unconditionally Protected Against Arbiter's Attacks (Extended Abstract)
Yvo Desmedt, Moti Yung |
CRYPTO | 1 |
| 1989 | Making Conditionally Secure Cryptosystems Unconditionally Abuse-Free in a General Context
Yvo Desmedt |
CRYPTO | 1 |
| 1989 | Threshold Cryptosystems
Yvo Desmedt, Yair Frankel |
CRYPTO | 1 |
| 1989 | Defending Systems against Viruses through Cryptographic AuthenticationabstractThe author describes the use of cryptographic authentication for controlling computer viruses. The objective is to protect against viruses infecting software distributions, updates, and programs stored or executed on a system. The authentication determines the source and integrity of an executable, relying on the source to produce virus-free software. The scheme relies on a trusted (and verifiable, where possible) device, the authenticator, used to authenticate and update programs and convert programs between the various formats. In addition, each user's machine uses a similar device to perform run-time checking.> George I. Davida, Yvo Desmedt, Brian J. Matt |
S&P | 2 |
| 1988 | Abuses in Cryptography and How to Fight Them
Yvo Desmedt |
CRYPTO | 1 |
| 1987 | Society and Group Oriented Cryptography: A New Concept
Yvo Desmedt |
CRYPTO | 1 |
| 1987 | Special Uses and Abuses of the Fiat-Shamir Passport Protocol
Yvo Desmedt, Claude Goutier, Samy Bengio |
CRYPTO | 1 |
| 1986 | Is There an ultimate Use of Cryptography?
Yvo Desmedt |
CRYPTO | 1 |
| 1986 | Public-Key Systems Based on the Difficulty of Tampering (Is There a Difference Between DES and RSA?)
Yvo Desmedt, Jean-Jacques Quisquater |
CRYPTO | 1 |
| 1985 | Unconditionally Secure Authentication Schemes and Practical and Theoretical Consequences
Yvo Desmedt |
CRYPTO | 1 |
| 1985 | A Chosen Text Attack on the RSA Cryptosystem and Some Discrete Logarithm Schemes
Yvo Desmedt, Andrew M. Odlyzko |
CRYPTO | 1 |
| 1985 | The Importance of "Good" Key Scheduling Schemes (How to Make a Secure DES Scheme with <= 48 Bit Keys)
Jean-Jacques Quisquater, Yvo Desmedt, Marc Davio |
CRYPTO | 2 |
| 1984 | Efficient Hardware and Software Implementations for the DES
Marc Davio, Yvo Desmedt, Jo Goubert, Frank Hoornaert, Jean-Jacques Quisquater |
CRYPTO | 2 |
| 1984 | Dependence of Output on Input in DES: Small Avalanche Characteristics
Yvo Desmedt, Jean-Jacques Quisquater, Marc Davio |
CRYPTO | 1 |
| 1984 | Efficient Hardware Implementation of the DES
Frank Hoornaert, Jo Goubert, Yvo Desmedt |
CRYPTO | 3 |
| 1984 | Cryptography: How to Attack, What to Protect?
René Govaerts, Yvo Desmedt, Joos Vandewalle |
ICC (1) | 2 |
| 1984 | A critical analysis of the security of knapsack public-key algorithmsabstractThe authors claim that the security of the Merkle-Hellman algorithm is greatly exaggerated. First, any enciphering key that is obtained from a superincreasing sequence has infinitely many superincreasing deciphering keys that can decipher all messages. This follows from the fact that the conditions on the transformation^{\ast} w \bmod mrequirew/mto lie in a restricted set of intervals. Second, it is claimed that iterative transformations^{\ast} w \bmod mmay not increase the security. In the example that Merkle and Hellman used for "proving" the benefits of the iterative transformation, the security is completely ruined. Third, techniques are presented to crack one bit of the plaintext. These techniques apply to sets of enciphering keys introduced in this text, which contain all the Merkle-Hellman enciphering keys. Such bit-by-bit techniques also allow the construction of new enciphering keys. Fourth, some knapsacks that allow a one-to-one deciphering cannot be obtained from easy deciphering keys, e.g., superincreasing keys, even with infinitely many transformations^{\ast} w \bmod m!If the worst cases of nondeterministic polynomial complete knapsack problems are always of this kind, the foundation of the security of the Merkle-Hellman algorithm is nonexistent. The cryptanalysis can be reduced to a problem of simultaneous diophantine approximations. A link is made with other recent results. Yvo Desmedt, Joos Vandewalle, René Govaerts |
IEEE Trans. Inf. Theory | 1 |
| 1983 | Analytical Characteristics of the DES
Marc Davio, Yvo Desmedt, Marc Fosseprez, René Govaerts, Jan Hulsbosch, Patrik Neutjens, Philippe Piret, Jean-Jacques Quisquater, Joos Vandewalle, Pascal Wouters |
CRYPTO | 2 |