David Pointcheval

dblp:p/DPointcheval · DBLP profile ↗
← Back
118ranked-venue papers
14as first author
15since 2021 · last 2025
0000-0002-6668-683XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 110 · 14 first-author · 14 since 2021Theory of computation · 7 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Computer networks · 1
YearPublicationVenuePosition
2025 Security Analysis of Covercrypt: A Quantum-Safe Hybrid Key Encapsulation Mechanism for Hidden Access Policies
Théophile Brézot, Chloé Hébant, Paola de Perthuis, David Pointcheval
ESORICS (2)4
2025 Multi-client Functional Encryption with Public Inputs and Strong Security
Ky Nguyen, Duong Hieu Phan, David Pointcheval
PKC (3)3
2025 Dynamic Decentralized Functional Encryption: Generic Constructions with Strong Security
Ky Nguyen, David Pointcheval, Robert Schädlich
PKC (4)2
2024 Attribute-Based Signatures with Advanced Delegation, and Tracing
Cécile Delerablée, Lénaïck Gouriou, David Pointcheval
CT-RSA3
2024 Multi-client Attribute-Based and Predicate Encryption from Standard Assumptions
David Pointcheval, Robert Schädlich
TCC (3)1
2023 GeT a CAKE: Generic Transformations from Key Encaspulation Mechanisms to Password Authenticated Key Exchanges
Hugo Beguinet, Céline Chevalier, David Pointcheval, Thomas Ricosset, Melissa Rossi
ACNS3
2023 Optimal Security Notion for Decentralized Multi-Client Functional Encryption
Ky Nguyen, Duong Hieu Phan, David Pointcheval
ACNS3
2023 Verifiable Decentralized Multi-client Functional Encryption for Inner Product
Dinh Duy Nguyen, Duong Hieu Phan, David Pointcheval
ASIACRYPT (5)3
2023 Covercrypt: An Efficient Early-Abort KEM for Hidden Access Policies with Traceability from the DDH and LWE
Théophile Brézot, Paola de Perthuis, David Pointcheval
ESORICS (1)3
2023 Traceable constant-size multi-authority credentials
Chloé Hébant, David Pointcheval
Inf. Comput.2
2023 Topical Collection on Computing on Encrypted Data
David Pointcheval, Nigel P. Smart
J. Cryptol.1
2022 Multi-Client Functional Encryption with Fine-Grained Access Control
Ky Nguyen, Duong Hieu Phan, David Pointcheval
ASIACRYPT (1)3
2022 Two-Client Inner-Product Functional Encryption with an Application to Money-Laundering Detection
abstract
In this paper, we extend Inner-Product Functional Encryption (IPFE), where there is just a vector in the key and a vector in the single sender's ciphertext, to two-client ciphertexts. More precisely, in our two-client functional encryption scheme, there are two Data Providers who can independently encrypt vectors x and y for a data consumer who can, from a functional decryption key associated to a vector α, compute ∑αi xiyi = x ⋅ Diag(α) ⋅ yT. Ciphertexts are linear in the dimension of the vectors, whereas the functional decryption keys are of constant size. We study two interesting particular cases:
Paola de Perthuis, David Pointcheval
CCS2
2022 AriaNN: Low-Interaction Privacy-Preserving Deep Learning via Function Secret Sharing
abstract
Abstract We propose AriaNN, a low-interaction privacy-preserving framework for private neural network training and inference on sensitive data. Our semi-honest 2-party computation protocol (with a trusted dealer) leverages function secret sharing, a recent lightweight cryptographic protocol that allows us to achieve an efficient online phase. We design optimized primitives for the building blocks of neural networks such as ReLU, MaxPool and BatchNorm. For instance, we perform private comparison for ReLU operations with a single message of the size of the input during the online phase, and with preprocessing keys close to 4× smaller than previous work. Last, we propose an extension to support n-party private federated learning. We implement our framework as an extensible system on top of PyTorch that leverages CPU and GPU hardware acceleration for cryptographic and machine learning operations. We evaluate our end-to-end system for private inference between distant servers on standard neural networks such as AlexNet, VGG16 or ResNet18, and for private training on smaller networks like LeNet. We show that computation rather than communication is the main bottleneck and that using GPUs together with reduced key size is a promising solution to overcome this barrier.
Théo Ryffel, Pierre Tholoniat, David Pointcheval, Francis R. Bach
Proc. Priv. Enhancing Technol.3
2021 Secure Decision Forest Evaluation
abstract
Decision forests are classical models to efficiently make decision on complex inputs with multiple features. While the global structure of the trees or forests is public, sensitive information have to be protected during the evaluation of some client inputs with respect to some server model. Indeed, the comparison thresholds on the server side may have economical value while the client inputs might be critical personal data. In addition, soundness is also important for the receiver. In our case, we will consider the server to be interested in the outcome of the model evaluation so that the client should not be able to bias it. In this paper, we propose a new offline/online protocol between a client and a server with a constant number of rounds in the online phase, with both privacy and soundness against malicious clients.
Slim Bettaieb, Loïc Bidoux, Olivier Blazy, Baptiste Cottier, David Pointcheval
ARES5
2020 Dynamic Decentralized Functional Encryption
Jérémy Chotard, Edouard Dufour Sans, Romain Gay, Duong Hieu Phan, David Pointcheval
CRYPTO (1)5
2020 Traceable Inner Product Functional Encryption
Xuan Thanh Do, Duong Hieu Phan, David Pointcheval
CT-RSA3
2020 Corrigendum: Public-key encryption indistinguishable under plaintext-checkable attacks
abstract
This note is a corrigendum for the paper ‘Public‐key encryption indistinguishable under plaintext‐checkable attacks’, IET Information Security (2016), 10(6): 288, http://doi.org/10.1049/iet‐ifs.2015.0500 .
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
IET Inf. Secur.3
2019 Unbounded Inner-Product Functional Encryption with Succinct Keys
Edouard Dufour Sans, David Pointcheval
ACNS2
2019 Divisible E-Cash from Constrained Pseudo-Random Functions
Florian Bourse, David Pointcheval, Olivier Sanders
ASIACRYPT (1)2
2019 Decentralized Evaluation of Quadratic Polynomials on Encrypted Data
Chloé Hébant, Duong Hieu Phan, David Pointcheval
ISC3
2019 Partially Encrypted Deep Learning using Functional Encryption
abstract
Machine learning on encrypted data has received a lot of attention thanks to recent breakthroughs in homomorphic encryption and secure multi-party computation. It allows outsourcing computation to untrusted servers without sacrificing privacy of sensitive data. We propose a practical framework to perform partially encrypted and privacy-preserving predictions which combines adversarial training and functional encryption. We first present a new functional encryption scheme to efficiently compute quadratic functions so that the data owner controls what can be computed but is not involved in the calculation: it provides a decryption key which allows one to learn a specific function evaluation of some encrypted data. We then show how to use it in machine learning to partially encrypt neural networks with quadratic activation functions at evaluation time and we provide a thorough analysis of the information leaks based on indistinguishability of data items of the same label. Last, since several encryption schemes cannot deal with the last thresholding operation used for classification, we propose a training method to prevent selected sensitive features from leaking which adversarially optimizes the network against an adversary trying to identify these features. This is of great interest for several existing works using partially encrypted machine learning as it comes with almost no cost on the model's accuracy and significantly improves data privacy.
Théo Ryffel, David Pointcheval, Francis R. Bach, Edouard Dufour Sans, Romain Gay
NeurIPS2
2019 On the Tightness of Forward-Secure Signature Reductions
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
J. Cryptol.3
2018 Privacy-Preserving Plaintext-Equality of Low-Entropy Inputs
Sébastien Canard, David Pointcheval, Quentin Santos, Jacques Traoré
ACNS2
2018 Decentralized Multi-Client Functional Encryption for Inner Product
Jérémy Chotard, Edouard Dufour Sans, Romain Gay, Duong Hieu Phan, David Pointcheval
ASIACRYPT (2)5
2018 Reassessing Security of Randomizable Signatures
David Pointcheval, Olivier Sanders
CT-RSA1
2018 Practical Strategy-Resistant Privacy-Preserving Elections
Sébastien Canard, David Pointcheval, Quentin Santos, Jacques Traoré
ESORICS (2)2
2018 Fuzzy Password-Authenticated Key Exchange
Pierre-Alain Dupont, Julia Hesse, David Pointcheval, Leonid Reyzin, Sophia Yakoubov
EUROCRYPT (3)3
2018 On the Leakage of Corrupted Garbled Circuits
Aurélien Dupin, David Pointcheval, Christophe Bidan
ProvSec2
2018 A new technique for compacting ciphertext in multi-channel broadcast encryption and attribute-based encryption
Sébastien Canard, Duong Hieu Phan, David Pointcheval, Viet Cuong Trinh
Theor. Comput. Sci.3
2017 Functional Encryption with Oblivious Helper
abstract
Functional encryption is a nice tool that bridges the gap between usability and privacy when providing access to huge databases: while being encrypted, aggregated information is available with a fine-tuned control by the owner of the database who can specify the functions he allows users to compute on the data. Unfortunately, giving access to several functions might leak too much information on the database, since once the decryption capability is given for a specific function, this is for an unlimited number of ciphertexts. In the particular case of the inner-product, if rows or records of the database contain l fields on which one got l independent inner-product capabilities, one can extract all the individual fields. On the other hand, the major applications that make use of inner-products, such as machine-learning, need to compute many of them.
Pierre-Alain Dupont, David Pointcheval
AsiaCCS2
2017 VTBPEKE: Verifier-based Two-Basis Password Exponential Key Exchange
abstract
PAKE protocols, for Password-Authenticated Key Exchange, enable two parties to establish a shared cryptographically strong key over an insecure network using a short common secret as authentication means. After the seminal work by Bellovin and Merritt, with the famous EKE, for Encrypted Key Exchange, various settings and security notions have been defined, and many protocols have been proposed.
David Pointcheval, Guilin Wang
AsiaCCS1
2017 Human Computing for Handling Strong Corruptions in Authenticated Key Exchange
abstract
We propose the first user authentication and key exchange protocols that can tolerate strong corruptions on the client-side. If a user happens to log in to a server from a terminal that has been fully compromised, then the other past and future user's sessions initiated from honest terminals stay secure. We define the security model for Human Authenticated Key Exchange HAKE) protocols and first propose two generic protocols based on human-compatible (HC) function family, password-authenticated key exchange (PAKE), commitment, and authenticated encryption. We prove our HAKE protocols secure under reasonable assumptions and discuss efficient instantiations. We thereafter propose a variant where the human gets help from a small device such as RSA SecurID. This permits to implement an HC function family with stronger security and thus allows to weaken required assumptions on the PAKE. This leads to the very efficient HAKE which is still secure in case of strong corruptions. We believe that our work will promote further developments in the area of human-oriented cryptography.
Alexandra Boldyreva, Pierre-Alain Dupont, David Pointcheval
CSF4
2017 Removing the Strong RSA Assumption from Arguments over the Integers
Geoffroy Couteau, Thomas Peters, David Pointcheval
EUROCRYPT (2)3
2017 Homomorphic-Policy Attribute-Based Key Encapsulation Mechanisms
Jérémy Chotard, Duong Hieu Phan, David Pointcheval
ISC3
2016 Legally Fair Contract Signing Without Keystones
Houda Ferradi, Rémi Géraud, Diana Maimut, David Naccache, David Pointcheval
ACNS5
2016 Encryption Switching Protocols
Geoffroy Couteau, Thomas Peters, David Pointcheval
CRYPTO (1)3
2016 Short Randomizable Signatures
David Pointcheval, Olivier Sanders
CT-RSA1
2016 Robust Password-Protected Secret Sharing
Michel Abdalla, Mario Cornejo, Anca Nitulescu, David Pointcheval
ESORICS (2)4
2016 Public-key encryption indistinguishable under plaintext-checkable attacks
abstract
Indistinguishability under chosen‐ciphertext attack (IND‐CCA) is now considered the de facto security notion for public‐key encryption. However, this sometimes offers a stronger security guarantee than what is needed. In this study, the authors consider a weaker security notion, termed as indistinguishability under plaintext‐checking attacks (IND‐PCA), in which the adversary has only access to an oracle indicating whether or not a given ciphertext encrypts a given message. After formalising this notion, the authors design a new public‐key encryption scheme satisfying it. The new scheme is a variant of the Cramer–Shoup encryption scheme with shorter ciphertexts. Its security is also based on the plain decisional Diffie–Hellman (DDH) assumption. Additionally, the algebraic properties of the new scheme allow proving plaintext knowledge using Groth–Sahai non‐interactive zero‐knowledge proofs or smooth projective hash functions. Finally, as a concrete application, the authors show that, for many password‐based authenticated key exchange (PAKE) schemes in the Bellare–Pointcheval–Rogaway security model, they can safely replace the underlying IND‐CCA encryption schemes with their new IND‐PCA one. By doing so, they reduce the overall communication complexity of these protocols and obtain the most efficient PAKE schemes to date based on plain DDH.
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
IET Inf. Secur.3
2016 Divisible e-cash made practical
abstract
Divisible e‐cash systems allow users to withdraw a unique coin of value 2 n units from a bank, but then to spend it in several times to distinct merchants. In such a system, whereas users want anonymity of their transactions, the bank wants to prevent, or at least detect, double‐spending, and trace defrauders. While this primitive was introduced two decades ago, quite a few (really) anonymous constructions have been proposed. In addition, all but one were just proven secure in the random oracle model, but still with either weak security models or quite complex settings and thus costly constructions. The unique proposal, secure in the standard model, appeared recently and is unpractical. As evidence, the authors left the construction of an efficient scheme secure in this model as an open problem. In this study, the authors answer it with the first efficient divisible e‐cash system secure in the standard model. It is based on a new way of building the coins, with a unique and public global tree structure for all the coins. Actually, they propose two constructions which offer a tradeoff between efficiency and security. They both achieve constant time for withdrawing and spending amounts of 2 ℓ units, while allowing the bank to quickly detect double‐spendings by a simple comparison of the serial numbers of deposited coins to the ones of previously spent coins.
Sébastien Canard, David Pointcheval, Olivier Sanders, Jacques Traoré
IET Inf. Secur.2
2015 Robust Pseudo-Random Number Generators with Input Secure Against Side-Channel Attacks
Michel Abdalla, Sonia Belaïd, David Pointcheval, Sylvain Ruhault, Damien Vergnaud
ACNS3
2015 Scalable Divisible E-cash
Sébastien Canard, David Pointcheval, Olivier Sanders, Jacques Traoré
ACNS2
2015 Implicit Zero-Knowledge Arguments and Applications to the Malicious Setting
Fabrice Benhamouda, Geoffroy Couteau, David Pointcheval, Hoeteck Wee
CRYPTO (2)3
2015 Disjunctions for Hash Proof Systems: New Constructions and Applications
Michel Abdalla, Fabrice Benhamouda, David Pointcheval
EUROCRYPT (2)3
2013 Analysis and Improvement of Lindell's UC-Secure Commitment Schemes
Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
ACNS3
2013 SPHF-Friendly Non-interactive Commitments
Michel Abdalla, Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval
ASIACRYPT (1)5
2013 Security analysis of pseudo-random number generators with input: /dev/random is not robust
abstract
A pseudo-random number generator (PRNG) is a deterministic algorithm that produces numbers whose distribution is indistinguishable from uniform. A formal security model for PRNGs with input was proposed in 2005 by Barak and Halevi (BH). This model involves an internal state that is refreshed with a (potentially biased) external random source, and a cryptographic function that outputs random numbers from the continually internal state. In this work we extend the BH model to also include a new security property capturing how it should accumulate the entropy of the input data into the internal state after state compromise. This property states that a good PRNG should be able to eventually recover from compromise even if the entropy is injected into the system at a very slow pace, and expresses the real-life expected behavior of existing PRNG designs. Unfortunately, we show that neither the model nor the specific PRNG construction proposed by BH meet this new property, despite meeting a weaker robustness notion introduced by BH. From a practical side, we give a precise assessment of the Linux PRNGs, /dev/random and /dev/urandom. In particular, we show attacks proving that these PRNGs are not robust according to our definition, due to vulnerabilities in their entropy estimator and their internal mixing function. Finally, we propose a simple PRNG construction that is provably robust in our new and stronger adversarial model and we show that it is more efficient than the Linux PRNGs. We therefore recommend to use this construction whenever a PRNG with input is used for cryptography.
Yevgeniy Dodis, David Pointcheval, Sylvain Ruhault, Damien Vergnaud, Daniel Wichs
CCS2
2013 Multi-channel broadcast encryption
abstract
Broadcast encryption aims at sending a content to a large arbitrary group of users at once. Currently, the most efficient schemes provide constant-size headers, that encapsulate ephemeral session keys under which the payload is encrypted. However, in practice, and namely for pay-TV, providers have to send various contents to different groups of users. Headers are thus specific to each group, one for each channel: as a consequence, the global overhead is linear in the number of channels. Furthermore, when one wants to zap to and watch another channel, one has to get the new header and decrypt it to learn the new session key: either the headers are sent quite frequently or one has to store all the headers, even if one watches one channel only. Otherwise, the zapping time becomes unacceptably long.
Duong Hieu Phan, David Pointcheval, Viet Cuong Trinh
AsiaCCS2
2013 New Techniques for SPHFs and Efficient One-Round PAKE Protocols
Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
CRYPTO (1)4
2013 Black-Box Trace&Revoke Codes
Hung Q. Ngo 0001, Duong Hieu Phan, David Pointcheval
Algorithmica3
2013 Short blind signatures
abstract
Blind signatures allow users to obtain signatures on messages hidden from the signer; moreover, the signer cannot link the resulting message/signature pair to the signing session. This paper presents blind signature schemes, in which the number of interactions between the user and the signer is min imal and whose blind signatures are short. Our schemes are defined over bilinear groups and are proved secure in the common-reference-string model without random oracles and under standard assumptions: CDH and the decision-linear assumption. (We also give variants over asymmetric groups based on similar assumptions.) The blind signatures are Waters signatures, which consist of 2 group elements. Moreover, we instantiate partially blind signatures, where the message consists of a part hidden from the signer and a commonly known public part, and schemes achieving perfect blindness. We propose new variants of blind signatures, such as signer-friendly partially blind signatures, where the public part can be chosen by the signer without prior agreement, 3-party blind signatures, as well as blind signatures on multiple aggregated messages provided by independent sources. We also extend Waters signatures to non-binary alphabets by proving a new result on the underlying hash function.
Olivier Blazy, Georg Fuchsbauer, David Pointcheval, Damien Vergnaud
J. Comput. Secur.3
2012 Adaptive CCA Broadcast Encryption with Constant-Size Secret Keys and Ciphertexts
Duong Hieu Phan, David Pointcheval, Siamak F. Shahandashti, Mario Strefler
ACISP2
2012 Verified security of redundancy-free encryption from Rabin and RSA
abstract
Verified security provides a firm foundation for cryptographic proofs by means of rigorous programming language techniques and verification methods. EasyCrypt is a framework that realizes the verified security paradigm and supports the machine-checked construction and verification of cryptographic proofs using state-of-the-art SMT solvers, automated theorem provers and interactive proof assistants. Previous experiments have shown that EasyCrypt is effective for a posteriori validation of cryptographic systems. In this paper, we report on the first application of verified security to a novel cryptographic construction, with strong security properties and interesting practical features. Specifically, we use EasyCrypt to prove in the Random Oracle Model the IND-CCA security of a redundancy-free public-key encryption scheme based on trapdoor one-way permutations. Somewhat surprisingly, we show that even with a zero-length redundancy, Boneh's SAEP scheme (an OAEP-like construction with a single-round Feistel network rather than two) converts a trapdoor one-way permutation into an IND-CCA-secure scheme, provided the permutation satisfies two additional properties. We then prove that the Rabin function and RSA with short exponent enjoy these properties, and thus can be used to instantiate the construction we propose to obtain efficient encryption schemes. The reduction that justifies the security of our construction is tight enough to achieve practical security with reasonable key sizes.
Gilles Barthe, David Pointcheval, Santiago Zanella-Béguelin
CCS2
2012 Round-Optimal Privacy-Preserving Protocols with Smooth Projective Hash Functions
Olivier Blazy, David Pointcheval, Damien Vergnaud
TCC2
2011 Security Notions for Broadcast Encryption
Duong Hieu Phan, David Pointcheval, Mario Strefler
ACNS2
2011 Contributory Password-Authenticated Group Key Exchange with Join Capability
Michel Abdalla, Céline Chevalier, Louis Granboulan, David Pointcheval
CT-RSA4
2009 Transferable Constant-Size Fair E-Cash
Georg Fuchsbauer, David Pointcheval, Damien Vergnaud
CANS2
2009 Smooth Projective Hashing for Conditionally Extractable Commitments
Michel Abdalla, Céline Chevalier, David Pointcheval
CRYPTO3
2009 Optimal Randomness Extraction from a Diffie-Hellman Element
Céline Chevalier, Pierre-Alain Fouque, David Pointcheval, Sébastien Zimmer
EUROCRYPT3
2009 Proofs on Encrypted Values in Bilinear Groups and an Application to Anonymity of Signatures
Georg Fuchsbauer, David Pointcheval
Pairing2
2008 Multi-factor Authenticated Key Exchange
David Pointcheval, Sébastien Zimmer
ACNS1
2008 Anonymous and Transparent Gateway-Based Password-Authenticated Key Exchange
Michel Abdalla, Malika Izabachène, David Pointcheval
CANS3
2008 HMAC is a randomness extractor and applications to TLS
abstract
In this paper, we study the security of a practical randomness extractor and its application in the TLS standard. Randomness extraction is the first stage of key derivation functions since the secret shared between the entities does not always come from a uniformly distributed source. More precisely, we wonder if the Hmac function, used in many standards, can be considered as a randomness extractor? We show that when the shared secret is put in the key space of the Hmac function, there are two cases to consider depending on whether the key is larger than the block-length of the hash function or not. In both cases, we provide a formal proof that the output is pseudo-random, but under different assumptions. Nevertheless, all the assumptions are related to the fact that the compression function of the underlying hash function behaves like a pseudo-random function. This analysis allows us to prove the TLS randomness extractor for Diffie-Hellman and RSA key exchange. Of independent interest, we study a computational analog to the leftover hash lemma for computational almost universal hash function families: any pseudo-random function family matches the latter definition.
Pierre-Alain Fouque, David Pointcheval, Sébastien Zimmer
AsiaCCS2
2008 Dynamic Threshold Public-Key Encryption
Cécile Delerablée, David Pointcheval
CRYPTO2
2008 Efficient Two-Party Password-Based Key Exchange Protocols in the UC Framework
Michel Abdalla, Dario Catalano, Céline Chevalier, David Pointcheval
CT-RSA4
2008 A Formal Study of the Privacy Concerns in Biometric-Based Remote Authentication Schemes
Qiang Tang 0001, Julien Bringer, Hervé Chabanne, David Pointcheval
ISPEC4
2007 An Application of the Goldwasser-Micali Cryptosystem to Biometric Authentication
Julien Bringer, Hervé Chabanne, Malika Izabachène, David Pointcheval, Qiang Tang 0001, Sébastien Zimmer
ACISP4
2007 Extended Private Information Retrieval and Its Application in Biometrics Authentications
Julien Bringer, Hervé Chabanne, David Pointcheval, Qiang Tang 0001
CANS3
2007 Fully Collusion Secure Dynamic Broadcast Encryption with Constant-Size Ciphertexts or Decryption Keys
Cécile Delerablée, Pascal Paillier, David Pointcheval
Pairing3
2007 Trapdoor Hard-to-Invert Group Isomorphisms and Their Application to Password-Based Authentication
Dario Catalano, David Pointcheval, Thomas Pornin
J. Cryptol.2
2007 Provably secure authenticated group Diffie-Hellman key exchange
abstract
Authenticated key-exchange protocols allow two participants A and B , communicating over a public network and each holding an authentication means to exchange a shared secret value. Methods designed to deal with this cryptographic problem ensure A (resp. B ) that no other participants aside from B (resp. A ) can learn any information about the agreed value and often also ensure A and B that their respective partner has actually computed this value. A natural extension to this cryptographic method is to consider a pool of participants exchanging a shared secret value and to provide a formal treatment for it. Starting from the famous two-party Diffie--Hellman (DH) key-exchange protocol and from its authenticated variants, security experts have extended it to the multiparty setting for over a decade and, in the past few years, completed a formal analysis in the framework of modern cryptography. The present paper synthesizes this body of work on the provably-secure authenticated group DH key exchange.
Emmanuel Bresson, Olivier Chevassut, David Pointcheval
ACM Trans. Inf. Syst. Secur.3
2006 A Scalable Password-Based Group Key Exchange Protocol in the Standard Model
Michel Abdalla, David Pointcheval
ASIACRYPT2
2006 Provably secure password-based authentication in TLS
abstract
In this paper, we show how to design an efficient, provably secure password-based authenticated key exchange mechanism specifically for the TLS (Transport Layer Security) protocol. The goal is to provide a technique that allows users to employ (short) passwords to securely identify themselves to servers. As our main contribution, we describe a new password-based technique for user authentication in TLS, called Simple Open Key Exchange (SOKE). Loosely speaking, the SOKE ciphersuites are unauthenticated Diffie-Hellman ciphersuites in which the client's Diffie-Hellman ephemeral public value is encrypted using a simple mask generation function. The mask is simply a constant value raised to the power of (a hash of) the password.The SOKE ciphersuites, in advantage over previous password-based authentication ciphersuites for TLS, combine the following features. First, SOKE has formal security arguments; the proof of security based on the computational Diffie-Hellman assumption is in the random oracle model, and holds for concurrent executions and for arbitrarily large password dictionaries. Second, SOKE is computationally efficient; in particular, it only needs operations in a sufficiently large prime-order subgroup for its Diffie-Hellman computations (no safe primes). Third, SOKE provides good protocol flexibility because the user identity and password are only required once a SOKE ciphersuite has actually been negotiated, and after the server has sent a server identity.
Michel Abdalla, Emmanuel Bresson, Olivier Chevassut, Bodo Möller, David Pointcheval
AsiaCCS5
2006 Automated Security Proofs with Sequences of Games
Bruno Blanchet, David Pointcheval
CRYPTO2
2006 Hardness of Distinguishing the MSB or LSB of Secret Keys in Diffie-Hellman Schemes
Pierre-Alain Fouque, David Pointcheval, Jacques Stern, Sébastien Zimmer
ICALP (2)2
2005 Optimal Asymmetric Encryption and Signature Paddings
Benoît Chevallier-Mames, Duong Hieu Phan, David Pointcheval
ACNS3
2005 A Simple Threshold Authenticated Key Exchange from Short Secrets
Michel Abdalla, Olivier Chevassut, Pierre-Alain Fouque, David Pointcheval
ASIACRYPT4
2005 Simple Password-Based Encrypted Key Exchange Protocols
Michel Abdalla, David Pointcheval
CT-RSA2
2005 Public Traceability in Traitor Tracing Schemes
Hervé Chabanne, Duong Hieu Phan, David Pointcheval
EUROCRYPT3
2004 OAEP 3-Round: A Generic and Secure Asymmetric Encryption Padding
Duong Hieu Phan, David Pointcheval
ASIACRYPT2
2004 How to Disembed a Program?
Benoît Chevallier-Mames, David Naccache, Pascal Paillier, David Pointcheval
CHES4
2004 IPAKE: Isomorphisms for Password-Based Authenticated Key Exchange
Dario Catalano, David Pointcheval, Thomas Pornin
CRYPTO2
2004 Mutual authentication and group key agreement for low-power mobile devices
Emmanuel Bresson, Olivier Chevassut, Abdelilah Essiari, David Pointcheval
Comput. Commun.4
2004 RSA-OAEP Is Secure under the RSA Assumption
Eiichiro Fujisaki, Tatsuaki Okamoto, David Pointcheval, Jacques Stern
J. Cryptol.3
2003 Josef Pieprzyk, David Pointcheval
Josef Pieprzyk, David Pointcheval
ACISP2
2003 A Simple Public-Key Cryptosystem with a Double Trapdoor Decryption Mechanism and Its Applications
Emmanuel Bresson, Dario Catalano, David Pointcheval
ASIACRYPT3
2003 Chosen-Ciphertext Security without Redundancy
Duong Hieu Phan, David Pointcheval
ASIACRYPT2
2003 Security proofs for an efficient password-based key exchange
abstract
Password-based key exchange schemes are designed to provide entities communicating over a public network, and sharing a (short) password only, with a session key (e.g, the key is used for data integrity and/or confidentiality). The focus of the present paper is on the analysis of very efficient schemes that have been proposed to the IEEE P1363 Standard working group on password-based authenticated key-exchange methods, but which actual security was an open problem. We analyze the AuthA key exchange scheme and give a complete proof of its security. Our analysis shows that the AuthA protocol and its multiple modes of operations are provably secure under the computational Diffie-Hellman intractability assumption, in both the random-oracle and the ideal-ciphers models.
Emmanuel Bresson, Olivier Chevassut, David Pointcheval
CCS3
2003 The Impact of Decryption Failures on the Security of NTRU Encryption
Nick Howgrave-Graham, Phong Q. Nguyen, David Pointcheval, John Proos, Joseph H. Silverman, Ari Singer, William Whyte
CRYPTO3
2003 A New NP-Complete Problem and Public-Key Identification
David Pointcheval, Guillaume Poupard
Des. Codes Cryptogr.1
2003 The One-More-RSA-Inversion Problems and the Security of Chaum's Blind Signature Scheme
Mihir Bellare, Chanathip Namprempre, David Pointcheval, Michael Semanko
J. Cryptol.3
2002 Group Diffie-Hellman Key Exchange Secure against Dictionary Attacks
Emmanuel Bresson, Olivier Chevassut, David Pointcheval
ASIACRYPT3
2002 Analysis and Improvements of NTRU Encryption Paddings
Phong Q. Nguyen, David Pointcheval
CRYPTO2
2002 Flaws in Applying Proof Methodologies to Signature Schemes
Jacques Stern, David Pointcheval, John Malone-Lee, Nigel P. Smart
CRYPTO2
2002 GEM: A Generic Chosen-Ciphertext Secure Encryption Method
Jean-Sébastien Coron, Helena Handschuh, Marc Joye, Pascal Paillier, David Pointcheval, Christophe Tymen
CT-RSA5
2002 Dynamic Group Diffie-Hellman Key Exchange under Standard Assumptions
Emmanuel Bresson, Olivier Chevassut, David Pointcheval
EUROCRYPT3
2001 Key-Privacy in Public-Key Encryption
Mihir Bellare, Alexandra Boldyreva, Anand Desai, David Pointcheval
ASIACRYPT4
2001 Provably Authenticated Group Diffie-Hellman Key Exchange - The Dynamic Case
Emmanuel Bresson, Olivier Chevassut, David Pointcheval
ASIACRYPT3
2001 Threshold Cryptosystems Secure against Chosen-Ciphertext Attacks
Pierre-Alain Fouque, David Pointcheval
ASIACRYPT2
2001 Provably authenticated group Diffie-Hellman key exchange
abstract
Group Diffie-Hellman protocols for Authenticated Key Exchange (AKE) are designed to provide a pool of players with a shared secret key which may later be used, for example, to achieve multicast message integrity. Over the years, several schemes have been offered. However, no formal treatment for this cryptographic problem has ever been suggested. In this paper, we present a security model for this problem and use it to precisely define AKE (with "implicit" authentication) as the fundamental goal, and the entity-authentication goal as well. We then define in this model the execution of an authenticated group Diffie-Hellman scheme and prove its security.
Emmanuel Bresson, Olivier Chevassut, David Pointcheval, Jean-Jacques Quisquater
CCS3
2001 Twin signatures: an alternative to the hash-and-sign paradigm
abstract
This paper introduces a simple alternative to the hash-and-sign paradigm, from the security point of view but for signing short messages, called twinning. A twin signature is obtained by signing twice a short message by a signature scheme. Analysis of the concept in different settings yields the following results:
David Naccache, David Pointcheval, Jacques Stern
CCS2
2001 RSA-OAEP Is Secure under the RSA Assumption
Eiichiro Fujisaki, Tatsuaki Okamoto, David Pointcheval, Jacques Stern
CRYPTO3
2001 Secure Mobile Gambling
Markus Jakobsson, David Pointcheval, Adam L. Young
CT-RSA2
2001 REACT: Rapid Enhanced-Security Asymmetric Cryptosystem Transform
Tatsuaki Okamoto, David Pointcheval
CT-RSA2
2001 Practical multi-candidate election system
abstract
The aim of electronic voting schemes is to provide a set of protocols that allow voters to cast ballots while a group of authorities collect the votes and output the final tally. In this paper we describe a practical multi-candidate election scheme that guarantees privacy of voters, public verifiability, and robustness against a coalition of malicious authorities. Furthermore, we address the problem of receipt-freeness and incoercibility of voters. Our new scheme is based on the Paillier cryptosystem and on some related zero-knowledge proof techniques. The voting schemes are very practical and can be efficiently implemented in a real system.
Olivier Baudron, Pierre-Alain Fouque, David Pointcheval, Jacques Stern, Guillaume Poupard
PODC3
2000 Authenticated Key Exchange Secure against Dictionary Attacks
Mihir Bellare, David Pointcheval, Phillip Rogaway
EUROCRYPT2
2000 Extended Notions of Security for Multicast Public Key Cryptosystems
Olivier Baudron, David Pointcheval, Jacques Stern
ICALP2
2000 Security Arguments for Digital Signatures and Blind Signatures
David Pointcheval, Jacques Stern
J. Cryptol.1
1999 Efficient Public-Key Cryptosystems Provably Secure Against Active Adversaries
Pascal Paillier, David Pointcheval
ASIACRYPT2
1999 New Public Key Cryptosystems Based on the Dependent-RSA Problems
David Pointcheval
EUROCRYPT1
1998 Relations Among Notions of Security for Public-Key Encryption Schemes
Mihir Bellare, Anand Desai, David Pointcheval, Phillip Rogaway
CRYPTO3
1998 Strengthened Security for Blind Signatures
David Pointcheval
EUROCRYPT1
1998 Computational Alternatives to Random Number Generators
David M'Raïhi, David Naccache, David Pointcheval, Serge Vaudenay
Selected Areas in Cryptography3
1997 New Blind Signatures Equivalent to Factorization (extended abstract)
abstract
In this paper, we present new blind signature schemes based on the factorization problem.They are the first blind signat,ure schemes proved secure relatively to factorization.By security, we mean that no "one-more forgery" is possible even under a parallel attack.In other terms, a user that receives k electronic coins cannot manufacture K + 1.Those security definitions have been introduced by Pointcheval and Stern [lS] for use in electronic cash.In fact, blind signatures were defined with this aim and it is still their most important application, together with anonymous voting.In the following, we will present an efficient reduction of an attack to a factorization algorithm in the random oracle model [l].
David Pointcheval, Jacques Stern
CCS1
1996 Provably Secure Blind Signature Schemes
David Pointcheval, Jacques Stern
ASIACRYPT1
1996 Security Proofs for Signature Schemes
David Pointcheval, Jacques Stern
EUROCRYPT1
1995 A New Identification Scheme Based on the Perceptrons Problem
David Pointcheval
EUROCRYPT1