Nigel P. Smart

dblp:s/NigelPSmart · DBLP profile ↗
← Back
117ranked-venue papers
19as first author
19since 2021 · last 2026
0000-0003-3567-3304ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 106 · 16 first-author · 19 since 2021Theory of computation · 7 · 3 first-authorSystems, architecture and hardware · 3Databases, data management, data science and information retrieval · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Correction to: Actively Secure Setup for SPDZ
Dragos Rotaru, Nigel P. Smart, Titouan Tanguy, Frederik Vercauteren, Tim Wood 0003
J. Cryptol.2
2025 Drifting Towards Better Error Probabilities in Fully Homomorphic Encryption Schemes
Olivier Bernard 0002, Marc Joye, Nigel P. Smart, Michael Walter 0001
EUROCRYPT (8)3
2024 The Key Lattice Framework for Concurrent Group Messaging
Kelong Cong, Karim M. El Defrawy, Nigel P. Smart, Ben Terner
ACNS (2)3
2024 Lightweight Asynchronous Verifiable Secret Sharing with Optimal Resilience
abstract
Abstract We present new protocols for Asynchronous Verifiable Secret Sharing for Shamir (i.e., threshold $$t t < n ) sharing of secrets. Our protocols: Use only “lightweight” cryptographic primitives, such as hash functions; Can share secrets over rings such as $${\mathbb {Z}}/(p^k)$$ Z / ( p k ) as well as finite fields $$\mathbb {F}_q$$ F q ; Provide optimal resilience, in the sense that they tolerate up to $$t < n/3$$ t < n / 3 corruptions, where n is the total number of parties; Are complete, in the sense that they guarantee that if any honest party receives their share then all honest parties receive their shares; Employ batching techniques, whereby a dealer shares many secrets in parallel and achieves an amortized communication complexity that is linear in n, at least on the “happy path”, where no party provably misbehaves.
Victor Shoup, Nigel P. Smart
J. Cryptol.2
2023 MPC with Delayed Parties over Star-Like Networks
Mariana Gama, Emad Heydari Beni, Emmanuela Orsini, Nigel P. Smart, Oliver Zajonc
ASIACRYPT (1)4
2023 ZK-for-Z2K: MPC-in-the-Head Zero-Knowledge Proofs for $\mathbb {Z}_{2^k}$
abstract
In this work, we extend the MPC-in-the-Head framework, used in recent efficient zero-knowledge protocols, to work over the ring $$\mathbb {Z}_{2^k}$$ , which is the primary operating domain for modern CPUs. The proposed schemes are compatible with any threshold linear secret sharing scheme and draw inspiration from MPC protocols adapted for ring operations. Additionally, we explore various batching methodologies, leveraging Shamir’s secret sharing schemes and Galois ring extensions, and show the applicability of our approach in RAM program verification. Finally, we analyse different options for instantiating the resulting ZK scheme over rings and compare their communication costs.
Lennart Braun, Cyprien Delpech de Saint Guilhem, Robin Jadoul, Emmanuela Orsini, Nigel P. Smart, Titouan Tanguy
IMACC5
2023 Practical and Efficient FHE-Based MPC
Nigel P. Smart
IMACC1
2023 Topical Collection on Computing on Encrypted Data
David Pointcheval, Nigel P. Smart
J. Cryptol.2
2022 FINAL: Faster FHE Instantiated with NTRU and LWE
Charlotte Bonte, Ilia Iliashenko, Jeongeun Park 0001, Hilder Vitor Lima Pereira, Nigel P. Smart
ASIACRYPT (2)5
2022 Feta: Efficient Threshold Designated-Verifier Zero-Knowledge Proofs
abstract
Zero-Knowledge protocols have increasingly become both popular and practical in recent years due to their applicability in many areas such as blockchain systems. Unfortunately, public verifiability and small proof sizes of zero-knowledge protocols currently come at the price of strong assumptions, large prover time, or both, when considering statements with millions of gates. In this regime, the most prover-efficient protocols are in the designated verifier setting, where proofs are only valid to a single party that must keep a secret state.
Carsten Baum, Robin Jadoul, Emmanuela Orsini, Peter Scholl, Nigel P. Smart
CCS5
2022 Private Liquidity Matching Using MPC
Shahla Atapoor, Nigel P. Smart, Younes Talibi Alaoui
CT-RSA2
2022 Actively Secure Setup for SPDZ
Dragos Rotaru, Nigel P. Smart, Titouan Tanguy, Frederik Vercauteren, Tim Wood 0003
J. Cryptol.2
2021 Gladius: LWR Based Efficient Hybrid Public Key Encryption with Distributed Decryption
Kelong Cong, Daniele Cozzo, Varun Maram, Nigel P. Smart
ASIACRYPT (4)4
2021 Compilation of Function Representations for Secure Computing Paradigms
Karim Baghery, Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Nigel P. Smart, Titouan Tanguy
CT-RSA4
2021 Secure Fast Evaluation of Iterative Methods: With an Application to Secure PageRank
Daniele Cozzo, Nigel P. Smart, Younes Talibi Alaoui
CT-RSA2
2021 Large Scale, Actively Secure Computation from LPN and Free-XOR Garbled Circuits
Aner Ben-Efraim, Kelong Cong, Eran Omri, Emmanuela Orsini, Nigel P. Smart, Eduardo Soria-Vazquez
EUROCRYPT (3)5
2021 Optimizing Registration Based Encryption
Kelong Cong, Karim M. El Defrawy, Nigel P. Smart
IMACC3
2021 MPC for Q2 Access Structures over Rings and Fields
Robin Jadoul, Nigel P. Smart, Barry Van Leeuwen
SAC2
2021 High-Performance Multi-party Computation for Binary Circuits Based on Oblivious Transfer
abstract
We present a unified view of the two-party and multi-party computation protocols based on oblivious transfer first outlined in Nielsen et al. (CRYPTO 2012) and Larraia et al. (CRYPTO 2014). We present a number of modifications and improvements to these earlier presentations, as well as full proofs of the entire protocol. Improvements include a unified pre-processing and online MAC methodology, mechanisms to pass between different MAC variants and fixing a minor bug in the protocol of Larraia et al. in relation to a selective failure attack. It also fixes a minor bug in Nielsen et al. resulting from using Jensen’s inequality in the wrong direction in an analysis.
Sai Sheshank Burra, Enrique Larraia, Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi, Emmanuela Orsini, Peter Scholl, Nigel P. Smart
J. Cryptol.8
2020 Semi-commutative Masking: A Framework for Isogeny-Based Protocols, with an Application to Fully Secure Two-Round Isogeny-Based OT
Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Christophe Petit 0001, Nigel P. Smart
CANS4
2020 Overdrive2k: Efficient Secure MPC over $\mathbb {Z}_{2^k}$ from Somewhat Homomorphic Encryption
Emmanuela Orsini, Nigel P. Smart, Frederik Vercauteren
CT-RSA2
2020 Sashimi: Cutting up CSI-FiSh Secret Keys to Produce an Actively Secure Distributed Signing Protocol
Daniele Cozzo, Nigel P. Smart
PQCrypto2
2019 Adding Distributed Decryption and Key Generation to a Ring-LWE Based CCA Encryption Scheme
Michael Kraitsberg, Yehuda Lindell, Valery Osheter, Nigel P. Smart, Younes Talibi Alaoui
ACISP4
2019 Benchmarking Privacy Preserving Scientific Operations
Abdelrahaman Aly, Nigel P. Smart
ACNS2
2019 MPC Joins The Dark Side
abstract
We consider the issue of securing dark pools/markets in thefinancial services sector. Currently, these markets are executed via trusted third parties, which opens potential for market operators to conduct fraud. We present a potential solution to this problem by using Multi-Party Computation (MPC) to enable a trusted third party to be emulated in software for three popular market mechanisms: continuous double auction (CDA), periodic auction (PA), and scheduled volume matching (SVM). Our experiments show that whilst the predominate market clearing mechanism of CDA is not currently viable when executed using MPC, SVM (a popular market mechanism for dark pools) is viable. We present experimental validation of this conclusion by presenting the expected throughputs for such markets in two popular MPC paradigms: the two party dishonest majority setting, and the honest majority three party setting.
John Cartlidge, Nigel P. Smart, Younes Talibi Alaoui
AsiaCCS2
2019 EPIC: Efficient Private Image Classification (or: Learning from the Masters)
Eleftheria Makri, Dragos Rotaru, Nigel P. Smart, Frederik Vercauteren
CT-RSA3
2019 Error Detection in Monotone Span Programs with Application to Communication-Efficient Multi-party Computation
Nigel P. Smart, Tim Wood 0003
CT-RSA1
2019 Sharing the LUOV: Threshold Post-quantum Signatures
Daniele Cozzo, Nigel P. Smart
IMACC2
2019 Distributing Any Elliptic Curve Based Protocol
Nigel P. Smart, Younes Talibi Alaoui
IMACC1
2019 Using TopGear in Overdrive: A More Efficient ZKPoK for SPDZ
abstract
The HighGear protocol (Eurocrypt 2018) is the fastest currently known approach to preprocessing for the SPDZ Multi-Party Computation scheme. Its backbone is formed by an Ideal Lattice-based Somewhat Homomorphic Encryption Scheme and accompanying Zero-Knowledge proofs. Unfortunately, due to certain characteristics of HighGear such current implementations limit the security parameters in a number of places. This is mainly due to memory and bandwidth consumption constraints. In this work we present a new approach to the ZKPoKs for the SPDZ Multi-Party Computation scheme. We rigorously formalize the original approach of HighGear and show how to improve upon it using a different proof strategy. This allows us to increase the security of the underlying protocols, whilst simultaneously also increasing the performance in terms of memory and bandwidth consumption as well as overall throughput of the SPDZ offline phase.
Carsten Baum, Daniele Cozzo, Nigel P. Smart
SAC3
2019 BBQ: Using AES in Picnic Signatures
Cyprien Delpech de Saint Guilhem, Lauren De Meyer, Emmanuela Orsini, Nigel P. Smart
SAC4
2019 Efficient Constant-Round Multi-party Computation Combining BMR and SPDZ
Yehuda Lindell, Benny Pinkas, Nigel P. Smart, Avishay Yanai
J. Cryptol.3
2018 CAPA: The Spirit of Beaver Against Physical Attacks
Oscar Reparaz, Lauren De Meyer, Begül Bilgin, Victor Arribas, Svetla Nikova, Ventzislav Nikov, Nigel P. Smart
CRYPTO (1)7
2018 From Keys to Databases - Real-World Applications of Secure Multi-Party Computation
abstract
We discuss the widely increasing range of applications of a cryptographic technique called multi-party computation. For many decades, this was perceived to be of purely theoretical interest, but now it has started to find application in a number of use cases. We highlight in this paper a number of these, ranging from securing small high-value items such as cryptographic keys, through to securing an entire database.
David W. Archer, Dan Bogdanov, Yehuda Lindell, Liina Kamm, Kurt Nielsen, Jakob Illeborg Pagter, Nigel P. Smart, Rebecca N. Wright
Comput. J.7
2017 Tightly Secure Ring-LWE Based Key Encapsulation with Short Ciphertexts
Martin R. Albrecht, Emmanuela Orsini, Kenneth G. Paterson, Guy Peer, Nigel P. Smart
ESORICS (1)5
2017 Multi-rate Threshold FlipThem
David S. Leslie, Chris Sherfield, Nigel P. Smart
ESORICS (2)3
2017 When It's All Just Too Much: Outsourcing MPC-Preprocessing
Peter Scholl, Nigel P. Smart, Tim Wood 0003
IMACC2
2017 Generic Forward-Secure Key Agreement Without Signatures
Cyprien Delpech de Saint Guilhem, Nigel P. Smart, Bogdan Warinschi
ISC2
2016 MPC-Friendly Symmetric Key Primitives
abstract
We discuss the design of symmetric primitives, in particular Pseudo-Random Functions (PRFs) which are suitable for use in a secret-sharing based MPC system. We consider three different PRFs: the Naor-Reingold PRF, a PRF based on the Legendre symbol, and a specialized block cipher design called MiMC. We present protocols for implementing these PRFs within a secret-sharing based MPC system, and discuss possible applications. We then compare the performance of our protocols. Depending on the application, different PRFs may offer different optimizations and advantages over the classic AES benchmark. Thus, we cannot conclude that there is one optimal PRF to be used in all situations.
Lorenzo Grassi 0001, Christian Rechberger, Dragos Rotaru, Peter Scholl, Nigel P. Smart
CCS5
2016 Which Ring Based Somewhat Homomorphic Encryption Scheme is Best?
Anamaria Costache, Nigel P. Smart
CT-RSA2
2016 Fixed-Point Arithmetic in SHE Schemes
Anamaria Costache, Nigel P. Smart, Srinivas Vivek 0001, Adrian Waller
SAC2
2016 Bootstrapping BGV ciphertexts with a wider choice of p and q
abstract
The authors describe a method to bootstrap a packed BGV ciphertext which does not depend (as much) on any special properties of the plaintext and ciphertext moduli. Prior ‘efficient’ methods such as that of Gentry et al . (PKC 2012) required a ciphertext modulus q which was close to a power of the plaintext modulus p . This enables the authors’ method to be applied in a larger number of situations. The authors’ basic bootstrapping technique makes use of a representation based on polynomials of the group over the finite field , followed by polynomial interpolation of the reduction mod p map over the coefficients of the algebraic group. This technique is then extended to the full BGV packed ciphertext space, using a method whose depth depends only logarithmically on the number of packed elements. This method may be of interest as an alternative to the method of Alperin‐Sheriff and Peikert (CRYPTO 2013). To aid efficiency, the authors utilise the ring/field switching technique of Gentry et al . (SCN 2012, JCS 2013).
Emmanuela Orsini, Joop van de Pol, Nigel P. Smart
IET Inf. Secur.3
2015 Efficient Constant Round Multi-party Computation Combining BMR and SPDZ
Yehuda Lindell, Benny Pinkas, Nigel P. Smart, Avishay Yanai
CRYPTO (2)3
2015 Just a Little Bit More
Joop van de Pol, Nigel P. Smart, Yuval Yarom
CT-RSA2
2014 Actively Secure Private Function Evaluation
Payman Mohassel, Seyed Saeed Sadeghian, Nigel P. Smart
ASIACRYPT (2)3
2014 "Ooh Aah... Just a Little Bit" : A Small Amount of Side Channel Can Go a Long Way
Naomi Benger, Joop van de Pol, Nigel P. Smart, Yuval Yarom
CHES3
2014 Dishonest Majority Multi-Party Computation for Binary Circuits
Enrique Larraia, Emmanuela Orsini, Nigel P. Smart
CRYPTO (2)3
2014 Fully homomorphic SIMD operations
Nigel P. Smart, Frederik Vercauteren
Des. Codes Cryptogr.1
2013 Between a Rock and a Hard Place: Interpolating between MPC and FHE
Ashish Choudhury, Jake Loftus, Emmanuela Orsini, Arpita Patra, Nigel P. Smart
ASIACRYPT (2)5
2013 An analysis of the EMV channel establishment protocol
abstract
With over 1.6 billion debit and credit cards in use worldwide, the EMV system (a.k.a. "Chip-and-PIN") has become one of the most important deployed cryptographic protocol suites. Recently, the EMV consortium has decided to upgrade the existing RSA based system with a new system relying on Elliptic Curve Cryptography (ECC). One of the central components of the new system is a protocol that enables a card to establish a secure channel with a card reader. In this paper we provide a security analysis of the proposed protocol, we propose minor changes/clarifications to the "Request for Comments" issued in Nov 2012, and demonstrate that the resulting protocol meets the intended security goals.
Christopher Brzuska, Nigel P. Smart, Bogdan Warinschi, Gaven J. Watson
CCS2
2013 An architecture for practical actively secure MPC with dishonest majority
abstract
We present a runtime environment for executing secure programs via a multi-party computation protocol in the preprocessing model. The runtime environment is general and allows arbitrary reactive computations to be performed. A particularly novel aspect is that it automatically determines the minimum number of rounds needed for a computation, given a specific instruction sequence, and it then uses this to minimize the overall cost of the computation. Various experiments are reported on, on various non-trivial functionalities. We show how, by utilizing the ability of modern processors to execute multiple threads at a time, one can obtain various tradeoffs between latency and throughput
Marcel Keller, Peter Scholl, Nigel P. Smart
CCS3
2013 The Low-Call Diet: Authenticated Encryption for Call Counting HSM Users
Mike Bond, George French, Nigel P. Smart, Gaven J. Watson
CT-RSA3
2013 Practical Covertly Secure MPC for Dishonest Majority - Or: Breaking the SPDZ Limits
abstract
SPDZ (pronounced “Speedz”) is the nickname of the MPC protocol of Damgård et al. from Crypto 2012. In this paper we both resolve a number of open problems with SPDZ; and present several theoretical and practical improvements to the protocol. In detail, we start by designing and implementing a covertly secure key generation protocol for obtaining a BGV public key and a shared associated secret key. We then construct both a covertly and actively secure preprocessing phase, both of which compare favourably with previous work in terms of efficiency and provable security. We also build a new online phase, which solves a major problem of the SPDZ protocol: namely prior to this work preprocessed data could be used for only one function evaluation and then had to be recomputed from scratch for the next evaluation, while our online phase can support reactive functionalities. This improvement comes mainly from the fact that our construction does not require players to reveal the MAC keys to check correctness of MAC’d values. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Ivan Damgård, Marcel Keller, Enrique Larraia, Valerio Pastro, Peter Scholl, Nigel P. Smart
ESORICS6
2013 Estimating Key Sizes for High Dimensional Lattice-Based Systems
Joop van de Pol, Nigel P. Smart
IMACC2
2013 Field switching in BGV-style homomorphic encryption
abstract
The security of contemporary homomorphic encryption schemes over cyclotomic number field relies on fields of very large dimension. This large dimension is needed because of the large modulus-to-noise ratio in the key-switching matrices that are used for the top few levels of the evaluated circuit. However, a smaller modulus-to-noise ratio is used in lower levels of the circuit, so from a security standpoint it is permissible to switch to lower-dimension fields, thus speeding up the homomorphic operations for the lower levels of the circuit. However, implementing such field-switching is nontrivial, since these schemes rely on the field algebraic structure for their homomorphic properties. A basic ring-switching operation was used by Brakerski, Gentry and Vaikuntanathan, over rings of the form Z[X]/(X2n+1), in the context of bootstrapping. In this work we generalize and extend this technique to work over any cyclotomic number field, and show how it can be used not only for bootstrapping but also during the computation itself (in conjunction with the “packed ciphertext” techniques of Gentry, Halevi and Smart).
Craig Gentry, Shai Halevi, Chris Peikert, Nigel P. Smart
J. Comput. Secur.4
2012 Multiparty Computation from Somewhat Homomorphic Encryption
abstract
We propose a general multiparty computation protocol secure against an active adversary corrupting up to $$n-1$$ of the n players. The protocol may be used to compute securely arithmetic circuits over any finite field $$\mathbb {F}_{p^k}$$ . Our protocol consists of a preprocessing phase that is both independent of the function to be computed and of the inputs, and a much more efficient online phase where the actual computation takes place. The online phase is unconditionally secure and has total computational (and communication) complexity linear in n, the number of players, where earlier work was quadratic in n. Moreover, the work done by each player is only a small constant factor larger than what one would need to compute the circuit in the clear. We show this is optimal for computation in large fields. In practice, for 3 players, a secure 64-bit multiplication can be done in 0.05 ms. Our preprocessing is based on a somewhat homomorphic cryptosystem. We extend a scheme by Brakerski et al., so that we can perform distributed decryption and handle many values in parallel in one ciphertext. The computational complexity of our preprocessing phase is dominated by the public-key operations, we need $$O(n^2/s)$$ operations per secure multiplication where s is a parameter that increases with the security parameter of the cryptosystem. Earlier work in this model needed $$\varOmega (n^2)$$ operations. In practice, the preprocessing prepares a secure 64-bit multiplication for 3 players in about 13 ms.
Ivan Damgård, Valerio Pastro, Nigel P. Smart, Sarah Zakarias
CRYPTO3
2012 Homomorphic Evaluation of the AES Circuit
Craig Gentry, Shai Halevi, Nigel P. Smart
CRYPTO3
2012 On the Joint Security of Encryption and Signature in EMV
Jean Paul Degabriele, Anja Lehmann, Kenneth G. Paterson, Nigel P. Smart, Mario Strefler
CT-RSA4
2012 Fully Homomorphic Encryption with Polylog Overhead
Craig Gentry, Shai Halevi, Nigel P. Smart
EUROCRYPT3
2012 Efficient Two-Move Blind Signatures in the Common Reference String Model
Essam Ghadafi, Nigel P. Smart
ISC2
2011 Improved Key Generation for Gentry's Fully Homomorphic Encryption Scheme
Peter Scholl, Nigel P. Smart
IMACC2
2011 Wildcarded Identity-Based Encryption
Michel Abdalla, James Birkett, Dario Catalano, Alexander W. Dent, John Malone-Lee, Gregory Neven, Jacob C. N. Schuldt, Nigel P. Smart
J. Cryptol.8
2010 On the Design and Implementation of an Efficient DAA Scheme
Liqun Chen 0002, Dan Page, Nigel P. Smart
CARDIS3
2010 Errors Matter: Breaking RSA-Based PIN Encryption with Thirty Ciphertext Validity Queries
Nigel P. Smart
CT-RSA1
2010 Constructing Certificateless Encryption and ID-Based Encryption from ID-Based Key Agreement
Dario Fiore 0001, Rosario Gennaro, Nigel P. Smart
Pairing3
2010 The TLS Handshake Protocol: A Modular Analysis
Paul Morrissey, Nigel P. Smart, Bogdan Warinschi
J. Cryptol.2
2009 Security Notions and Generic Constructions for Client Puzzles
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart, Bogdan Warinschi
ASIACRYPT3
2009 Secure Two-Party Computation Is Practical
Benny Pinkas, Thomas Schneider 0003, Nigel P. Smart, Stephen C. Williams
ASIACRYPT3
2009 Distributing the Key Distribution Centre in Sakai-Kasahara Based Systems
Martin Geisler 0001, Nigel P. Smart
IMACC2
2009 Practical Zero-Knowledge Proofs for Circuit Evaluation
Essam Ghadafi, Nigel P. Smart, Bogdan Warinschi
IMACC2
2009 Identity Based Group Signatures from Hierarchical Identity-Based Encryption
Nigel P. Smart, Bogdan Warinschi
Pairing1
2008 A Modular Security Analysis of the TLS Handshake Protocol
Paul Morrissey, Nigel P. Smart, Bogdan Warinschi
ASIACRYPT2
2008 Pairings in Trusted Computing
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart
Pairing3
2008 On Proofs of Security for DAA Schemes
Liqun Chen 0002, Paul Morrissey, Nigel P. Smart
ProvSec3
2008 Pairings for cryptographers
Steven D. Galbraith, Kenneth G. Paterson, Nigel P. Smart
Discret. Appl. Math.3
2008 Randomised representations
abstract
The authors show that a number of existing methods for side-channel defence are essentially the same techniques presented in different contexts. By abstracting this technique, they present necessary conditions which need to be satisfied for it to be successful in preventing side-channel analysis. They also show that concrete application of the technique via randomised field representation produces more efficient implementations than application of the technique via randomised projective coordinates.
Nigel P. Smart, Elisabeth Oswald, Dan Page
IET Inf. Secur.1
2008 Generic Constructions of Identity-Based and Certificateless KEMs
Kamel Bentahar, Pooya Farshim, John Malone-Lee, Nigel P. Smart
J. Cryptol.4
2007 Efficient 15, 360-bit RSA Using Woop-Optimised Montgomery Arithmetic
Kamel Bentahar, Nigel P. Smart
IMACC2
2007 Efficient KEMs with Partial Message Recovery
Tor E. Bjørstad, Alexander W. Dent, Nigel P. Smart
IMACC3
2007 Toward Acceleration of RSA Using 3D Graphics Hardware
Andrew Moss, Dan Page, Nigel P. Smart
IMACC3
2007 On computable isomorphisms in efficient asymmetric pairing-based systems
Nigel P. Smart, Frederik Vercauteren
Discret. Appl. Math.1
2007 Nondeterministic Multithreading
abstract
The physical security of application-specific embedded processors such as those found in smart-cards has become increasingly important since they are used more and more as conduits for sensitive financial and identity information. The advent of side-channel attacks has meant that a combination of algorithm, software, and hardware defense is required. In this paper, we reexamine the issue of nondeterministic processors, simplifying previous designs using a multithreaded architecture. From this simplification, we are able to construct a formally reasoned assessment of the security level offered by such a device.
Peter James Leadbitter, Dan Page, Nigel P. Smart
IEEE Trans. Computers3
2006 The Number Field Sieve in the Medium Prime Case
Antoine Joux, Reynald Lercier, Nigel P. Smart, Frederik Vercauteren
CRYPTO3
2006 Identity-Based Encryption Gone Wild
Michel Abdalla, Dario Catalano, Alexander W. Dent, John Malone-Lee, Gregory Neven, Nigel P. Smart
ICALP (2)6
2006 The Eta Pairing Revisited
abstract
In this paper, we simplify and extend the Eta pairing, originally discovered in the setting of supersingular curves by Barreto , to ordinary curves. Furthermore, we show that by swapping the arguments of the Eta pairing, one obtains a very efficient algorithm resulting in a speed-up of a factor of around six over the usual Tate pairing, in the case of curves that have large security parameters, complex multiplication by an order of Qopf (radic-3), and when the trace of Frobenius is chosen to be suitably small. Other, more minor savings are obtained for more general curves
Florian Hess, Nigel P. Smart, Frederik Vercauteren
IEEE Trans. Inf. Theory2
2005 Further Hidden Markov Model Cryptanalysis
P. J. Green, Richard Noad, Nigel P. Smart
CHES3
2005 Hash Based Digital Signature Schemes
C. Dods, Nigel P. Smart, Martijn Stam
IMACC2
2004 Attacking DSA Under a Repeated Bits Assumption
Peter James Leadbitter, Dan Page, Nigel P. Smart
CHES3
2004 Projective Coordinates Leak
David Naccache, Nigel P. Smart, Jacques Stern
EUROCRYPT2
2004 Security of Signature Schemes in a Multi-User Setting
Alfred Menezes, Nigel P. Smart
Des. Codes Cryptogr.2
2004 Parallel Cryptographic Arithmetic Using a Redundant Montgomery Representation
abstract
We describe how using a redundant Montgomery representation allows for high-performance SIMD-based implementations of RSA and elliptic curve cryptography. This is in addition to the known benefits of immunity from timing attacks afforded by the use of such a representation. We present some preliminary implementation timings using the SSE2 instruction set on a Pentium 4 processor and show that an SIMD parallel implementation of RSA can be around twice as fast as traditional sequential code. This is especially useful given the larger 2,048 bit RSA keys which are now being proposed for standard security levels. Finally, we remark on other application areas that improve the security of our work in the context of side-channel analysis while maintaining high performance.
Dan Page, Nigel P. Smart
IEEE Trans. Computers2
2003 An Analysis of Goubin's Refined Power Analysis Attack
Nigel P. Smart
CHES1
2003 Access Control Using Pairing Based Cryptography
Nigel P. Smart
CT-RSA1
2003 Mental Poker Revisited
Adam Barnett, Nigel P. Smart
IMACC2
2003 Computing the M = U Ut Integer Matrix Decomposition
Katharina Geißler, Nigel P. Smart
IMACC2
2003 Analysis of the Insecurity of ECMQV with Partially Known Nonces
Peter James Leadbitter, Nigel P. Smart
ISC2
2002 Instruction Stream Mutation for Non-Deterministic Processors
abstract
Differential power analysis (DPA) has become a real-world threat to the security of cryptographic hardware devices such as smart-cards. By using cheap and readily available equipment, attacks can easily compromise algorithms running on these devices in a non-invasive manner. Adding non-determinism to the execution of cryptographic algorithms has been proposed as a defence against these attacks. One way of achieving this non-determinism is to introduce random additional operations to the algorithm which produce noise in the power profile of the device. We describe the addition of a specialised processor pipeline stage which increases the level of potential non-determinism and hence guards against the revelation of secret information.
James Irwin, Dan Page, Nigel P. Smart
ASAP3
2002 Hardware Implementation of Finite Fields of Characteristic Three
Dan Page, Nigel P. Smart
CHES2
2002 Flaws in Applying Proof Methodologies to Signature Schemes
Jacques Stern, David Pointcheval, John Malone-Lee, Nigel P. Smart
CRYPTO4
2002 Extending the GHS Weil Descent Attack
Steven D. Galbraith, Florian Hess, Nigel P. Smart
EUROCRYPT3
2002 Certification of Public Keys within an Identity Based System
Liqun Chen 0002, Keith Harrison, Andrew Moss, David Soldera, Nigel P. Smart
ISC5
2002 Public key signatures in the multi-user setting
Steven D. Galbraith, John Malone-Lee, Nigel P. Smart
Inf. Process. Lett.3
2002 Constructive and Destructive Facets of Weil Descent on Elliptic Curves
Pierrick Gaudry, Florian Hess, Nigel P. Smart
J. Cryptol.3
2001 Non-deterministic Processors
David May 0001, Henk L. Muller, Nigel P. Smart
ACISP3
2001 Preventing SPA/DPA in ECC Systems Using the Jacobi Form
Pierre-Yvan Liardet, Nigel P. Smart
CHES2
2001 Random Register Renaming to Foil DPA
David May 0001, Henk L. Muller, Nigel P. Smart
CHES3
2001 The Hessian Form of an Elliptic Curve
Nigel P. Smart
CHES1
2001 How Secure Are Elliptic Curves over Composite Extension Fields?
Nigel P. Smart
EUROCRYPT1
2001 The Exact Security of ECIES in the Generic Group Model
Nigel P. Smart
IMACC1
2001 Lattice Attacks on Digital Signature Schemes
Nick Howgrave-Graham, Nigel P. Smart
Des. Codes Cryptogr.2
2001 A note on the x-coordinate of points on an elliptic curve in characteristic two
Nigel P. Smart
Inf. Process. Lett.1
1999 On the Performance of Hyperelliptic Cryptosystems
Nigel P. Smart
EUROCRYPT1
1999 A Cryptographic Application of Weil Descent
Steven D. Galbraith, Nigel P. Smart
IMACC2
1999 Elliptic Curve Cryptosystems over Small Fields of Odd Characteristic
Nigel P. Smart
J. Cryptol.1
1999 The Discrete Logarithm Problem on Elliptic Curves of Trace One
Nigel P. Smart
J. Cryptol.1
1999 A Fast Diffie-Hellman Protocol in Genus 2
Nigel P. Smart, Samir Siksek
J. Cryptol.1
1996 Solving Discriminant Form Equations Via Unit Equations
Nigel P. Smart
J. Symb. Comput.1