Marc Joye

dblp:j/MarcJoye · DBLP profile ↗
← Back
88ranked-venue papers
44as first author
7since 2021 · last 2026
0000-0003-4433-2333ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 77 · 39 first-author · 6 since 2021Systems, architecture and hardware · 4 · 1 first-authorTheory of computation · 4 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Boolean Arithmetic over $\mathbb {F}_{2}$ from Group Commutators
Marc Joye
WAIFI1
2025 Bootstrapping (T)FHE Ciphertexts via Automorphisms: Closing the Gap Between Binary and Gaussian Keys
Olivier Bernard 0002, Marc Joye
ASIACRYPT (7)2
2025 Fast Homomorphic Evaluation of LWR-based PRFs
abstract
Certain applications of fully homomorphic encryption (such as transciphering, universal thresholdizers, and PIR) require randomness while operating over encrypted data. This randomness has to be obliviously generated in the encrypted domain and remain encrypted throughout the computation. Moreover, it should be guaranteed that independent-looking random coins can be obliviously generated for different computations.
Amit Deo, Marc Joye, Benoît Libert, Benjamin R. Curtis, Mayeul de Bellabre
CCS2
2025 Drifting Towards Better Error Probabilities in Fully Homomorphic Encryption Schemes
Olivier Bernard 0002, Marc Joye, Nigel P. Smart, Michael Walter 0001
EUROCRYPT (8)2
2024 TFHE Public-Key Encryption Revisited
Marc Joye
CT-RSA1
2023 On-Line/Off-Line DCR-Based Homomorphic Encryption and Applications
Marc Joye
CT-RSA1
2021 Balanced Non-adjacent Forms
Marc Joye
ASIACRYPT (3)1
2019 Private Data Aggregation over Selected Subsets of Users
Amit Datta, Marc Joye, Nadia Fawaz
CANS2
2018 Privacy-Preserving Ridge Regression with only Linearly-Homomorphic Encryption
Irene Giacomelli, Somesh Jha, Marc Joye, David Page, Kyonghwan Yoon
ACNS3
2018 Differential Attacks on Deterministic Signatures
Christopher Ambrose, Joppe W. Bos, Björn Fay, Marc Joye, Manfred Lochter, Bruce Murray
CT-RSA4
2018 Private yet Efficient Decision Tree Evaluation
Marc Joye, Fariborz Salehi
DBSec1
2018 Decentralized Policy-Hiding ABE with Receiver Privacy
Yan Michalevsky, Marc Joye
ESORICS (2)2
2017 Encoding-Free ElGamal-Type Encryption Schemes on Elliptic Curves
Marc Joye, Benoît Libert
CT-RSA1
2017 Efficient Cryptosystems From 2k-th Power Residue Symbols
Fabrice Benhamouda, Javier Herranz, Marc Joye, Benoît Libert
J. Cryptol.3
2017 Cryptanalysis of a Privacy-Preserving Aggregation Protocol
abstract
Privacy-preserving aggregation protocols allow an untrusted aggregator to evaluate certain statistics over a population of individuals without learning each individual’s privately owned data. In this note, we show that a recent protocol for computing an aggregate sum due to Jung, Li, and Wan (IEEE Transactions on Dependable and Secure Computing, 2015) is universally breakable, that is, anyone is able to recover each individual’s private data from the corresponding ciphertext. We also describe an alternate collusion attack against their companion product protocol.
Marc Joye
IEEE Trans. Dependable Secur. Comput.1
2016 Born and raised distributively: Fully distributed non-interactive adaptively-secure threshold signatures with short shares
Benoît Libert, Marc Joye, Moti Yung
Theor. Comput. Sci.2
2016 A New Framework for Privacy-Preserving Aggregation of Time-Series Data
abstract
Aggregator-oblivious encryption is a useful notion put forward by Shi et al. in 2011 that allows an untrusted aggregator to periodically compute an aggregate value over encrypted data contributed by a set of users. Such encryption schemes find numerous applications, particularly in the context of privacy-preserving smart metering. This article presents a general framework for constructing privacy-preserving aggregator-oblivious encryption schemes using a variant of Cramer-Shoup’s paradigm of smooth projective hashing. This abstraction leads to new schemes based on a variety of complexity assumptions. It also improves upon existing constructions, providing schemes with shorter ciphertexts and better encryption times.
Fabrice Benhamouda, Marc Joye, Benoît Libert
ACM Trans. Inf. Syst. Secur.2
2015 Compactly Hiding Linear Spans - Tightly Secure Constant-Size Simulation-Sound QA-NIZK Proofs and Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
ASIACRYPT (1)3
2015 A Key-private Cryptosystem from the Quadratic Residuosity
abstract
Abstract: This paper presents a key-private public-key cryptosystem. More specifically, in addition to confidentiality, it provides privacy. Informally, ciphertexts yield no information whatsoever about its recipient (beyond what is publicly known). The presented cryptosystem also features a very fast key generation: the key generation boils down to a mere squaring modulo an RSA modulus. Further, it comes with strong security guarantees: it is proved to be semantically secure and key-private under the standard quadratic residuosity assumption. 1
Marc Joye
SECRYPT1
2015 Linearly homomorphic structure-preserving signatures and their applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
Des. Codes Cryptogr.3
2014 Concise Multi-challenge CCA-Secure Encryption and Signatures with Almost Tight Security
Benoît Libert, Marc Joye, Moti Yung, Thomas Peters
ASIACRYPT (2)2
2014 Group Signatures with Message-Dependent Opening in the Standard Model
Benoît Libert, Marc Joye
CT-RSA2
2014 Non-malleability from Malleability: Simulation-Sound Quasi-Adaptive NIZK Proofs and CCA2-Secure Encryption from Homomorphic Signatures
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
EUROCRYPT3
2014 Born and raised distributively: fully distributed non-interactive adaptively-secure threshold signatures with short shares
abstract
Threshold cryptography is a fundamental distributed computational paradigm for enhancing the availability and the security of cryptographic public-key schemes. It does it by dividing private keys into n shares handed out to distinct servers. In threshold signature schemes, a set of at least t+1 ≤ n servers is needed to produce a valid digital signature. Availability is assured by the fact that any subset of t+1 servers can produce a signature when authorized. At the same time, the scheme should remain robust (in the fault tolerance sense) and unforgeable (cryptographically) against up to t corrupted servers; i.e., it adds quorum control to traditional cryptographic services and introduces redundancy. Originally, most practical threshold signatures have a number of demerits: They have been analyzed in a static corruption model (where the set of corrupted servers is fixed at the very beginning of the attack), they require interaction, they assume a trusted dealer in the key generation phase (so that the system is not fully distributed), or they suffer from certain overheads in terms of storage (large share sizes). In this paper, we construct practical fully distributed (the private key is born distributed), non-interactive schemes --- where the servers can compute their partial signatures without communication with other servers--- with adaptive security (i.e., the adversary corrupts servers dynamically based on its full view of the history of the system). Our schemes are very efficient in terms of computation, communication, and scalable storage (with private key shares of size O(1), where certain solutions incur O(n) storage costs at each server). Unlike other adaptively secure schemes, our schemes are erasure-free (reliable erasure is a hard to assure and hard to administer property in actual systems).
Benoît Libert, Marc Joye, Moti Yung
PODC2
2013 Toward Practical Group Encryption
Laila El Aimani, Marc Joye
ACNS2
2013 Privacy-preserving matrix factorization
abstract
Recommender systems typically require users to reveal their ratings to a recommender service, which subsequently uses them to provide relevant recommendations. Revealing ratings has been shown to make users susceptible to a broad set of inference attacks, allowing the recommender to learn private user attributes, such as gender, age, etc. In this work, we show that a recommender can profile items without ever learning the ratings users provide, or even which items they have rated. We show this by designing a system that performs matrix factorization, a popular method used in a variety of modern recommendation systems, through a cryptographic technique known as garbled circuits. Our design uses oblivious sorting networks in a novel way to leverage sparsity in the data. This yields an efficient implementation, whose running time is O(Mlog^2M) in the number of ratings M. Crucially, our design is also highly parallelizable, giving a linear speedup with the number of available processors. We further fully implement our system, and demonstrate that even on commodity hardware with 16 cores, our privacy-preserving implementation can factorize a matrix with 10K ratings within a few hours.
Valeria Nikolaenko, Stratis Ioannidis, Udi Weinsberg, Marc Joye, Nina Taft, Dan Boneh
CCS4
2013 Linearly Homomorphic Structure-Preserving Signatures and Their Applications
Benoît Libert, Thomas Peters, Marc Joye, Moti Yung
CRYPTO (2)3
2013 Efficient Cryptosystems from 2 k -th Power Residue Symbols
Marc Joye, Benoît Libert
EUROCRYPT1
2013 Elliptic Curve Cryptosystems in the Presence of Faults
abstract
Elliptic curve cryptography was introduced in the mid 1980s as a promising alternative for cryptographic protocols based on the discrete logarithm problem in the multiplicative group of a finite field (e.g., Diffie-Hellman key exchange or ElGamal encryption/signature). The security of elliptic curve cryptosystems relies on the hardness of solving the elliptic curve discrete logarithm problem (ECDLP). However, there is no need to make use of strong cryptographic techniques if they are poorly implemented. This talk surveys various fault attacks against elliptic curve cryptosystems. It also presents a number of countermeasures developed so far as well as new ones by exploiting the rich underlying mathematical structure. Finally, several research problems are listed.
Marc Joye
FDTC1
2013 Privacy-Preserving Ridge Regression on Hundreds of Millions of Records
abstract
Ridge regression is an algorithm that takes as input a large number of data points and finds the best-fit linear curve through these points. The algorithm is a building block for many machine-learning operations. We present a system for privacy-preserving ridge regression. The system outputs the best-fit curve in the clear, but exposes no other information about the input data. Our approach combines both homomorphic encryption and Yao garbled circuits, where each is used in a different part of the algorithm to obtain the best performance. We implement the complete system and experiment with it on real data-sets, and show that it significantly outperforms pure implementations based only on homomorphic encryption or Yao circuits.
Valeria Nikolaenko, Udi Weinsberg, Stratis Ioannidis, Marc Joye, Dan Boneh, Nina Taft
IEEE Symposium on Security and Privacy4
2012 Partial Key Exposure on RSA with Private Exponents Larger Than N
Marc Joye, Tancrède Lepoint
ISPEC1
2011 Memory-Efficient Fault Countermeasures
Marc Joye, Mohamed Karroumi
CARDIS1
2011 Binary Huff Curves
Julien Devigne, Marc Joye
CT-RSA2
2011 Traitor tracing schemes for protected software implementations
abstract
This paper considers the problem of converting an encryption scheme into a scheme in which there is one encryption process but several decryption processes. Each decryption process is made available as a protected software implementation (decoder). So, when some digital content is encrypted, a legitimate user can recover the content in clear using its own private software implementation. Moreover, it is possible to trace a decoder in a black-box fashion in case it is suspected to be an illegal copy. Our conversions assume software tamper-resistance.
Marc Joye, Tancrède Lepoint
Digital Rights Management Workshop1
2011 How (Not) to design strong-RSA signatures
Marc Joye
Des. Codes Cryptogr.1
2011 Notions and relations for RKA-secure permutation and function families
Jongsung Kim, Jaechul Sung, Ermaliza Razali, Raphael C.-W. Phan, Marc Joye
Des. Codes Cryptogr.5
2010 The Polynomial Composition Problem in (Z/nZ)[X]
Marc Joye, David Naccache, Stéphanie Porte
CARDIS1
2010 Co-Z Addition Formulæ and Binary Ladders on Elliptic Curves - (Extended Abstract)
Raveen R. Goundar, Marc Joye, Atsuko Miyaji
CHES2
2010 Coordinate Blinding over Large Prime Fields
Michael Tunstall, Marc Joye
CHES2
2009 On Cryptographic Schemes Based on Discrete Logarithms and Factoring
Marc Joye
CANS1
2009 A simple construction for public-key encryption with revocable anonymity: the honest-sender case
abstract
This paper presents a generic and simple transformation that adds traceability to an anonymous encryption scheme. We focus on the case of honest senders, which finds applications in many real-life scenarios. Advantageously, our transformation can be applied to already deployed public-key infrastructures. Two concrete implementations are provided.
Davide Alessio, Marc Joye
Digital Rights Management Workshop2
2009 Protecting RSA against Fault Attacks: The Embedding Method
abstract
Fault attacks constitute a major threat toward cryptographic products supporting RSA-based technologies. Most often, the public exponent is unknown, turning resistance to fault attacks into an intricate problem. Over the past few years, several techniques for secure implementations have been published, but none of them is fully satisfactory. We propose a completely different approach by embedding the public exponent into [the description of] the private key. As a result, we obtain a very efficient countermeasure with a 100% fault detection.
Marc Joye
FDTC1
2009 Chosen-Ciphertext Secure RSA-Type Cryptosystems
Benoît Chevallier-Mames, Marc Joye
ProvSec2
2008 Laundering and Repackaging of Multimedia Content in Content Distribution Systems
abstract
Content distribution systems enable the secure distribution of multimedia content. At the same time, and sometimes more importantly, they should also disable the illegal [re-]distribution of multimedia content. This paper identifies different types of attacks on current systems: laundering attacks and repackaging attacks. The attacks are described generically so that they may apply to most systems used for distributing protected content to set of users. First hints to prevent such attacks are also discussed.
Alain Durand, Marc Joye, Mohamed Karroumi
APSCC2
2008 An Efficient On-Line/Off-Line Signature Scheme without Random Oracles
Marc Joye
CANS1
2008 On the Security of a Unified Countermeasure
abstract
Implementation attacks are a major threat for cryptographic applications. Recently, Baek and Vasyltsov (ISPEC 2007) proposed a unified countermeasure for protecting elliptic curve implementations against a variety of implementation attacks, including differential power attacks and fault attacks. This paper studies the security of this countermeasure. In particular, it shows that the fault coverage is less than what was anticipated. Further security weaknesses are also pointed out.
Marc Joye
FDTC1
2008 RSA Moduli with a Predetermined Portion: Techniques and Applications
Marc Joye
ISPEC1
2008 Fast Point Multiplication on Elliptic Curves without Precomputation
Marc Joye
WAIFI1
2007 Highly Regular Right-to-Left Algorithms for Scalar Multiplication
Marc Joye
CHES1
2007 A Practical and Tightly Secure Signature Scheme Without Hash Function
Benoît Chevallier-Mames, Marc Joye
CT-RSA2
2007 Cryptanalysis of a Video Scrambling Based on Space Filling Curves
abstract
In this paper, we study the security of an image scrambling algorithm based on space-filling curves (SFC). A random SFC is a pixel permutation that changes the scanning order without changing pixels values. Few attacks were reported in the literature. A ciphertext-only attack when a different scan is generated for each frame in the video was proposed. The success of this attack heavily depends on the statistics of the plain frame. In addition, scanning each frame with a different SFC is not adapted to compression as many compression algorithms exploit temporal redundancy. We revisit the security properties of this scrambling technique and propose an efficient and low-cost chosen-plaintext attack when the same SFC is used for each frame in the video.
Ayoub Massoudi, Frédéric Lefèbvre, Marc Joye
ICME3
2007 On the Notions of PRP - RKA , KR and KR - RKA for Block Ciphers
Ermaliza Razali, Raphael C.-W. Phan, Marc Joye
ProvSec3
2007 Securing OpenSSL against Micro-Architectural Attacks
Marc Joye, Michael Tunstall
SECRYPT1
2007 Strengthening hardware AES implementations against fault attacks
abstract
Differential fault attacks become a threat of increasing importance against cryptographic devices. One of the most efficient hardware countermeasures for block ciphers to prevent such attacks relies on duplication. Novel techniques to implement a duplication scheme for the AES are proposed. Remarkably, the proposed techniques do not impact on the throughput/area ratio and better withstand a large variety of known fault attacks.
Marc Joye, Pascal Manet, Jean-Baptiste Rigaud
IET Inf. Secur.1
2006 Fast Generation of Prime Numbers on Portable Devices: An Update
Marc Joye, Pascal Paillier
CHES1
2006 On the TYS Signature Scheme
Marc Joye, Hung-Mei Lin
ICCSA (3)1
2006 Trading Inversions for Multiplications in Elliptic Curve Cryptography
Mathieu Ciet, Marc Joye, Kristin E. Lauter, Peter L. Montgomery
Des. Codes Cryptogr.2
2005 On Second-Order Differential Power Analysis
Marc Joye, Pascal Paillier, Berry Schoenmakers
CHES1
2005 Elliptic Curve Cryptosystems in the Presence of Permanent and Transient Faults
Mathieu Ciet, Marc Joye
Des. Codes Cryptogr.2
2004 Smart-Card Implementation of Elliptic Curve Cryptography and DPA-type Attacks
Marc Joye
CARDIS1
2004 Low-Cost Solutions for Preventing Simple Side-Channel Analysis: Side-Channel Atomicity
abstract
We introduce simple methods to convert a cryptographic algorithm into an algorithm protected against simple side-channel attacks. Contrary to previously known solutions, the proposed techniques are not at the expense of the execution time. Moreover, they are generic and apply to virtually any algorithm. In particular, we present several novel exponentiation algorithms, namely, a protected square-and-multiply algorithm, its right-to-left counterpart, and several protected sliding-window algorithms. We also illustrate our methodology applied to point multiplication on elliptic curves. All these algorithms share the common feature that the complexity is globally unchanged compared to the corresponding unprotected implementations.
Benoît Chevallier-Mames, Mathieu Ciet, Marc Joye
IEEE Trans. Computers3
2003 Faster Double-Size Modular Multiplication from Euclidean Multipliers
Benoît Chevallier-Mames, Marc Joye, Pascal Paillier
CHES2
2003 GCD-Free Algorithms for Computing Modular Inverses
Marc Joye, Pascal Paillier
CHES1
2003 (Virtually) Free Randomization Techniques for Elliptic Curve Cryptography
Mathieu Ciet, Marc Joye
ICICS2
2003 Cryptanalysis of a pay-as-you-watch system
Marc Joye
Inf. Process. Lett.1
2002 A Protected Division Algorithm
Marc Joye, Karine Villegas
CARDIS1
2002 The Montgomery Powering Ladder
Marc Joye, Sung-Ming Yen
CHES1
2002 Universal Padding Schemes for RSA
Jean-Sébastien Coron, Marc Joye, David Naccache, Pascal Paillier
CRYPTO2
2002 GEM: A Generic Chosen-Ciphertext Secure Encryption Method
Jean-Sébastien Coron, Helena Handschuh, Marc Joye, Pascal Paillier, David Pointcheval, Christophe Tymen
CT-RSA3
2002 Observability Analysis - Detecting When Improved Cryptosystems Fail
Marc Joye, Jean-Jacques Quisquater, Sung-Ming Yen, Moti Yung
CT-RSA1
2001 Universal Exponentiation Algorithm
Christophe Clavier, Marc Joye
CHES2
2001 Hessian Elliptic Curves and Side-Channel Attacks
Marc Joye, Jean-Jacques Quisquater
CHES1
2001 Protections against Differential Analysis for Elliptic Curve Cryptography
Marc Joye, Christophe Tymen
CHES1
2001 On the Power of Misbehaving Adversaries and Security Analysis of the Original EPOC
Marc Joye, Jean-Jacques Quisquater, Moti Yung
CT-RSA1
2001 On Rabin-Type Signatures
Marc Joye, Jean-Jacques Quisquater
IMACC1
2001 Strong Adaptive Chosen-Ciphertext Attacks with Memory Dump (or: The Importance of the Order of Decryption and Validation)
Seungjoo Kim, Jung Hee Cheon, Marc Joye, Seongan Lim, Masahiro Mambo, Dongho Won, Yuliang Zheng 0001
IMACC3
2001 How to Choose Secret Parameters for RSA-Type Cryptosystems over Elliptic Curves
Marc Joye, Jean-Jacques Quisquater, Tsuyoshi Takagi
Des. Codes Cryptogr.1
2000 Efficient Generation of Prime Numbers
Marc Joye, Pascal Paillier, Serge Vaudenay
CHES1
2000 A Practical and Provably Secure Coalition-Resistant Group Signature Scheme
Giuseppe Ateniese, Jan Camenisch, Marc Joye, Gene Tsudik
CRYPTO3
2000 New Attacks on PKCS#1 v1.5 Encryption
Jean-Sébastien Coron, Marc Joye, David Naccache, Pascal Paillier
EUROCRYPT2
2000 Optimal Left-to-Right Binary Signed-Digit Recoding
abstract
This paper describes new methods for producing optimal binary signed-digit representations. This can be useful in the fast computation of exponentiations. Contrary to existing algorithms, the digits are scanned from left to right (i.e., from the most significant position to the least significant position). This may lead to better performances in both hardware and software.
Marc Joye, Sung-Ming Yen
IEEE Trans. Computers1
2000 Checking Before Output May Not Be Enough Against Fault-Based Cryptanalysis
abstract
In order to avoid fault-based attacks on cryptographic security modules (e.g., smart-cards), some authors suggest that the computation results should be checked for faults before being transmitted. In this paper, we describe a potential fault-based attack where key bits leak only through the information whether the device produces a correct answer after a temporary fault or not. This information is available to the adversary even if a check is performed before output.
Sung-Ming Yen, Marc Joye
IEEE Trans. Computers2
1999 Chinese Remaindering Based Cryptosystems in the Presence of Faults
Marc Joye, Arjen K. Lenstra, Jean-Jacques Quisquater
J. Cryptol.1
1998 Reducing the Elliptic Curve Cryptosystem of Meyer-Müuller to the Cryptosystem of Rabin-Williams
Marc Joye, Jean-Jacques Quisquater
Des. Codes Cryptogr.1
1997 On the Importance of Securing Your Bins: The Garbage-man-in-the-middle Attack
abstract
Article On the importance of securing your bins: the garbage-man-in-the-middle attack Share on Authors: Marc Joye UCL Crypto Group, Dép. de Math., Université de Louvain, Belgium UCL Crypto Group, Dép. de Math., Université de Louvain, BelgiumView Profile , Jean-Jacques Quisquater UCL Crypto Group, Dép. d'Électricité, Université de Louvain, Belgium UCL Crypto Group, Dép. d'Électricité, Université de Louvain, BelgiumView Profile Authors Info & Claims CCS '97: Proceedings of the 4th ACM conference on Computer and communications securityApril 1997 Pages 135–141https://doi.org/10.1145/266420.266449Online:01 April 1997Publication History 7citation635DownloadsMetricsTotal Citations7Total Downloads635Last 12 Months11Last 6 weeks2 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Marc Joye, Jean-Jacques Quisquater
CCS1
1997 A new and optimal chosen-message attack on RSA-type cryptosystems
Daniel Bleichenbacher, Marc Joye, Jean-Jacques Quisquater
ICICS2
1997 RSA-type Signatures in the Presence of Transient Faults
Marc Joye, Jean-Jacques Quisquater, Feng Bao 0001, Robert H. Deng
IMACC1
1997 Authentication of Sequences with the SL2 Hash Function: Application to Video Sequences
abstract
This paper presents an interesting application of the Tillich–Zémor function TZ . In particular, we emphasize the concatenation property of this one-way hash function. i.e., TZ ( S | T ) = TZ ( S ) TZ ( T ) where S and T are two binary strings. This
Jean-Jacques Quisquater, Marc Joye
J. Comput. Secur.2