Tsuyoshi Takagi

dblp:t/TsuyoshiTakagi · DBLP profile ↗
← Back
138ranked-venue papers
4as first author
25since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 110 · 3 first-author · 19 since 2021Theory of computation · 12 · 1 first-author · 6 since 2021Systems, architecture and hardware · 10Artificial intelligence and machine learning · 4Applied, interdisciplinary, general and emerging computing · 4Databases, data management, data science and information retrieval · 2Computer networks · 1
YearPublicationVenuePosition
2026 Threshold FHE with Short Decryption Shares Without a Semi-trusted Server
Hiroki Okada 0001, Tsuyoshi Takagi
ACISP (2)2
2026 Revisiting ISD Algorithms and New Decoding Records for Large Weight Syndrome Decoding over F q
Takeshi Wakao, Yusuke Aikawa, Shintaro Narisada, Tsuyoshi Takagi
ICISSP (2)4
2026 On the Feasibility of 256-Bit Prime Field Arithmetic via PMNS on 8-Bit Architectures
Daichi Aoki, Tsuyoshi Takagi
WAIFI2
2026 Explicit Bounds on the Existence Probability of Random Multivariate Quadratic Systems over Finite Fields
Michiya Iwata, Ryomei Sugai, Kosuke Sakata, Tsuyoshi Takagi
WAIFI4
2025 Low Communication Threshold FHE from Standard (Module-)LWE
Hiroki Okada 0001, Tsuyoshi Takagi
ASIACRYPT (7)2
2025 Lower Bounds of Costs of 3-Isogenies Formulas in the Framework of Generalized Montgomery Coordinates
Tomoki Moriya, Hiroshi Onuki, Yusuke Aikawa, Tsuyoshi Takagi
CASC4
2025 Gram Root Decomposition over the Polynomial Ring: Application to Sphericalization of Discrete Gaussian
Hiroki Okada 0001, Tsuyoshi Takagi
ICISSP (2)2
2025 Exfiltration-Resistant Proxy Re-Encryption for IoT Data Sharing in Unreliable Clouds
abstract
The sharing of Internet of Things (IoT) data plays an extensive role in our everyday lives. Exploring secure and efficient methods for data sharing is a prominent area of research. Proxy re-encryption (PRE) in the cloud provides a solution. However, traditional PRE schemes are vulnerable to algorithm substitution attacks (ASA). Moreover, in most PRE schemes, the proxy can know the relevant identity information of the data owner or the data recipient through the re-encryption key, and some current PRE schemes cannot guarantee strong resistance to collision. To address the limitations of traditional PRE schemes and offer a robust solution for secure and efficient data sharing in IoT application, we propose a reverse firewall for proxy re-encryption (PRE-RF) scheme, which is implemented by JPBC library. Security analysis shows that our PRE-RF scheme provides effective resistance to ASA, along with strong collision security, chosen plaintext attack security, and key-private security. Compared with similar state-of-the-art PRE schemes, our scheme reduces the length of the re-encryption keys and ciphertext, thereby reducing the storage cost of the system. Meanwhile, our scheme’s computational cost is lower, thereby improving the operational efficiency of the system. Furthermore, the amount of time devoted to the reverse firewall in our scheme decreases as security level increases. As a result, these advantages make it a secure and efficient choice for sharing IoT data in unreliable cloud environments.
Liang Zhao 0020, Fagen Li, Tsuyoshi Takagi
IEEE Trans. Dependable Secur. Comput.4
2024 Revisiting the Security of Fiat-Shamir Signature Schemes Under Superposition Attacks
Tsuyoshi Takagi
ACISP (2)3
2024 Review the Cuckoo Hash-Based Unbalanced Private Set Union: Leakage, Fix, and Optimization
Keyang Liu, Xingxin Li, Tsuyoshi Takagi
ESORICS (2)3
2024 A Faster Variant of CGL Hash Function via Efficient Backtracking Checks
Shota Inoue, Yusuke Aikawa, Tsuyoshi Takagi
ISC (2)3
2024 Consecutive Adaptor Signature Scheme: From Two-Party to N-Party Settings
Kaisei Kajita, Go Ohtake, Tsuyoshi Takagi
ProvSec (1)3
2024 Tightly Secure Identity-Based Signature from Cryptographic Group Actions
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Hyungrok Jo, Tsuyoshi Takagi
ProvSec (1)6
2023 Memory-Efficient Quantum Information Set Decoding Algorithm
Naoto Kimura, Atsushi Takayasu, Tsuyoshi Takagi
ACISP3
2023 Spherical Gaussian Leftover Hash Lemma via the Rényi Divergence
Hiroki Okada 0001, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi
ACNS (1)4
2023 Robust Property-Preserving Hash Meets Homomorphism
Keyang Liu, Xingxin Li, Tsuyoshi Takagi
ISC3
2023 Fast Enumeration Algorithm for Multivariate Polynomials over General Finite Fields
Hiroki Furue, Tsuyoshi Takagi
PQCrypto2
2023 L1-norm ball for CSIDH: Optimal strategy for choosing the secret key space
Kohei Nakagawa, Hiroshi Onuki, Atsushi Takayasu, Tsuyoshi Takagi
Discret. Appl. Math.4
2023 Recent progress in the security evaluation of multivariate public-key cryptography
abstract
Abstract Multivariate public‐key cryptography (MPKC) is considered a leading candidate for post‐quantum cryptography (PQC). It is based on the hardness of the multivariate quadratic polynomial (MQ) problem, which is a problem of finding a solution to a system of quadratic equations over a finite field. In this paper, we survey some recent progress in the security analysis of MPKC. Among various existing multivariate schemes, the most important one is the Rainbow signature scheme proposed by Ding et al. in 2005, which was later selected as a finalist in the third round of the PQC standardization project by the National Institute of Standards and Technology. Under the circumstances, some recent research studies in MPKC have focussed on the security analysis of the Rainbow scheme. In this paper, the authors first explain efficient algorithms for solving the MQ problem and the research methodology for estimating their complexity in MPKC. Then, the authors survey some recent results related to the security analysis of the Rainbow scheme. In particular, the authors provide a detailed description of the complexity analysis for solving the bi‐graded polynomial systems studied independently by Nakamura et al. and Smith‐Tone et al., and then expound the rectangular MinRank attack against Rainbow proposed by Beullens.
Yasuhiko Ikematsu, Shuhei Nakamura, Tsuyoshi Takagi
IET Inf. Secur.3
2022 Efficient Word Size Modular Multiplication over Signed Integers
abstract
As an efficient multiplication method for polynomial rings, Number Theoretic Transform (NTT) is a fundamental algorithm that is both practically useful and theoretically established. Chung et al. proposed a method to perform NTT-based polynomial multiplication for NTT-unfriendly rings that do not have suitable primitive roots. They applied their proposal to lattice-based cryptography using NTT-unfriendly rings and speeded up several schemes. At ARITH 2021, Plantard proposed a modular multiplication algorithm that improves the speed of NTT if moduli are not large (a few dozen of bits), which is the case for typical lattice-based cryptography. It is natural to expect that Plantard's method improves Chung et al.‘s NTT when applied to them, however, this is not possible as Chung et al. requires the use of signed integers while Plantard's method assumes unsigned integers. A simple fix would cause a slowdown and a non-constant-time operation. To overcome this problem, we propose an efficient method for calculating the modular multiplication for signed integers based on Plantard's method. Our proposal generally incurs no overhead from the original and works in a constant-time fashion. To show the effectiveness of our proposal, we provide experimental implementation results on a lattice-based cryptographic scheme Saber. Currently, NIST is selecting candidates for standardization of post-quantum cryp-tography in preparation for the compromise of current public key cryptography by quantum computers, and has completed the selection of the final candidates. Saber is one of the finalists for the NIST standardization project,
Daichi Aoki, Kazuhiko Minematsu, Toshihiko Okamura, Tsuyoshi Takagi
ARITH4
2022 A New Fault Attack on UOV Multivariate Signature Scheme
Hiroki Furue, Yutaro Kiyomura, Tatsuya Nagasawa, Tsuyoshi Takagi
PQCrypto4
2021 A New Variant of Unbalanced Oil and Vinegar Using Quotient Ring: QR-UOV
Hiroki Furue, Yasuhiko Ikematsu, Yutaro Kiyomura, Tsuyoshi Takagi
ASIACRYPT (4)4
2021 Improving Thomae-Wolf Algorithm for Solving Underdetermined Multivariate Quadratic Polynomial Problem
Hiroki Furue, Shuhei Nakamura, Tsuyoshi Takagi
PQCrypto3
2021 Memory-constrained implementation of lattice-based encryption scheme on standard Java Card platform
abstract
Abstract The lattice‐based encryption scheme has high efficiency and reliability, and it can be run on small devices with limited memory capacity and computational resources such as sensor nodes or smart cards. The first implementation is presented of the original ring–learning‐with‐errors‐based encryption scheme on a standard Java Card platform by combining the number theoretic transform with improved Montgomery modular multiplication. Without any cryptographic coprocessor support, the decryption running time is around 7 s, corresponding to the AES‐128 security level. Two efficient discrete Gaussian sampling approaches, known at the discrete Ziggurat sampling algorithm and Knuth–Yao algorithm, were implemented on the Java Card and resulted in a reduction in running times. More important, polynomial modular multiplication is shown to perform efficiently on a standard Java Card platform even when the big integers and floating‐point number operations are not supported. The results show the feasibility of implementing more lattice‐based cryptosystems on existing memory‐constrained Java Cards. A preliminary version of this paper appeared with the title ‘Memory‐constrained implementation of lattice‐based encryption scheme on standard Java Card’ in Proceedings of the 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) .
Ye Yuan 0005, Kazuhide Fukushima, Junting Xiao, Shinsaku Kiyomoto, Tsuyoshi Takagi
IET Inf. Secur.5
2021 New complexity estimation on the Rainbow-Band-Separation attack
Shuhei Nakamura, Yasuhiko Ikematsu, Yacheng Wang, Jintai Ding, Tsuyoshi Takagi
Theor. Comput. Sci.5
2020 Improving Key Mismatch Attack on NewHope with Fewer Queries
Satoshi Okada, Yuntao Wang 0002, Tsuyoshi Takagi
ACISP3
2020 SiGamal: A Supersingular Isogeny-Based PKE and Its Application to a PRF
Tomoki Moriya, Hiroshi Onuki, Tsuyoshi Takagi
ASIACRYPT (2)3
2020 How to Construct CSIDH on Edwards Curves
Tomoki Moriya, Hiroshi Onuki, Tsuyoshi Takagi
CT-RSA3
2020 A Compact Digital Signature Scheme Based on the Module-LWR Problem
Hiroki Okada 0001, Atsushi Takayasu, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi
ICICS5
2020 The Existence of Cycles in the Supersingular Isogeny Graphs Used in SIKE
Hiroshi Onuki, Yusuke Aikawa, Tsuyoshi Takagi
ISITA3
2020 A Structural Attack on Block-Anti-Circulant UOV at SAC 2019
Hiroki Furue, Koha Kinjo, Yasuhiko Ikematsu, Yacheng Wang, Tsuyoshi Takagi
PQCrypto5
2020 Multivariate Encryption Schemes Based on Polynomial Equations over Real Numbers
Takanori Yasuda, Yacheng Wang, Tsuyoshi Takagi
PQCrypto3
2020 Short Lattice Signatures in the Standard Model with Efficient Tag Generation
Kaisei Kajita, Kazuto Ogawa, Koji Nuida, Tsuyoshi Takagi
ProvSec4
2019 One Sample Ring-LWE with Rounding and Its Application to Key Exchange
Jintai Ding, Xinwei Gao, Tsuyoshi Takagi, Yuntao Wang 0002
ACNS3
2019 Group Key Exchange from CSIDH and Its Application to Trusted Setup in Supersingular Isogeny Cryptosystems
Tomoki Moriya, Katsuyuki Takashima, Tsuyoshi Takagi
Inscrypt3
2019 Tight Reductions for Diffie-Hellman Variants in the Algebraic Group Model
Taiga Mizuide, Atsushi Takayasu, Tsuyoshi Takagi
CT-RSA3
2019 Security Analysis and Efficient Implementation of Code-based Signature Schemes
Partha Sarathi Roy 0001, Kirill Morozov, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi
ICISSP5
2018 Efficient Decryption Algorithms for Extension Field Cancellation Type Encryption Schemes
Yacheng Wang, Yasuhiko Ikematsu, Dung Hoang Duong, Tsuyoshi Takagi
ACISP4
2018 Improving the BKZ Reduction Algorithm by Quick Reordering Technique
Yuntao Wang 0002, Tsuyoshi Takagi
ACISP2
2018 An Improvement on the Linear Algebraic Attack for the Indeterminate Equation Encryption Scheme
abstract
At SAC2017, Akiyama et al. proposed the indeterminate equation encryption scheme whose security is based on a solution problem of indeterminate equation. It is an extension of algebraic surface encryption scheme. A public key X for this scheme is a polynomial in two variables over a finite ring. Akiyama et al. also proposed two attacks, the linear algebraic attack (LAA) and the key recovery attack (KRA), by using the lattice structure associated with this scheme. In this paper, we give an improvement on LAA. Also we explain the relation between our improvement and the improvement on LAA proposed by Xagawa and examine parameters that those attacks fail by experiments. As a result, we conclude that if the total degree of the public key X is one, then KRA is more efficient than LAA and if that of X is two, then LAA is more efficient than KRA.
Yasuhiko Ikematsu, Koichiro Akiyama, Tsuyoshi Takagi
ISITA3
2018 HFERP - A New Multivariate Encryption Scheme
Yasuhiko Ikematsu, Ray A. Perlner, Daniel Smith-Tone, Tsuyoshi Takagi, Jeremy Vates
PQCrypto4
2018 Portable Implementation of Postquantum Encryption Schemes and Key Exchange Protocols on JavaScript-Enabled Platforms
abstract
Quantum computers have the potential to solve some difficult mathematical problems efficiently and thus will inevitably exert a more significant impact on the traditional asymmetric cryptography. The National Institute of Standards and Technology (NIST) has opened a formal call for the submission of proposals of quantum-resistant public-key cryptographic algorithms to set the next-generation cryptography standards. Compared to powerful machines with ample amount of hardware resources such as racks of servers and IoT devices, including the massive number of microcontrollers, smart terminals, and sensor nodes with limited computing capacity, should also have some postquantum cryptography features for security and privacy. To ensure the correct execution of encryption algorithms on any platforms, the portability of implementation becomes more important. As distinguished from C/C++, JavaScript is a popular cross-platform language that can be used for the web applications and some hardware platforms directly, and it could be one of the solutions of portability. Therefore, we investigate and implement several recent lattice-based encryption schemes and public-key exchange protocols including Lizard, ring-Lizard, Kyber, Frodo, and NewHope in JavaScript, which are the active candidates of postquantum cryptography due to their applicabilities and efficiencies. We show and compare the performance of our JavaScript implementation on web browsers, embedded device Tessel2, Android phone, and several JavaScript-enabled platforms on PC and Mac. Our work shows that implementing lattice-based cryptography on JavaScript-enabled platforms is achievable and results in desirable portability.
Ye Yuan 0005, Junting Xiao, Kazuhide Fukushima, Shinsaku Kiyomoto, Tsuyoshi Takagi
Secur. Commun. Networks5
2017 Secure and Efficient Pairing at 256-Bit Security Level
Yutaro Kiyomura, Akiko Inoue, Yuto Kawahara, Masaya Yasuda, Tsuyoshi Takagi, Tetsutaro Kobayashi
ACNS5
2017 An Experimental Study of the BDD Approach for the Search LWE Problem
Rui Xu 0006, Sze Ling Yeo, Kazuhide Fukushima, Tsuyoshi Takagi, Hwajung Seo, Shinsaku Kiyomoto, Matt Henricksen
ACNS4
2017 An Experimental Study of Kannan's Embedding Technique for the Search LWE Problem
Yuntao Wang 0002, Yoshinori Aono, Tsuyoshi Takagi
ICICS3
2017 Choosing Parameters for the Subfield Lattice Attack Against Overstretched NTRU
Dung Hoang Duong, Masaya Yasuda, Tsuyoshi Takagi
ISC3
2017 A Public-Key Encryption Scheme Based on Non-linear Indeterminate Equations
Koichiro Akiyama, Yasuhiro Goto, Shinya Okumura, Tsuyoshi Takagi, Koji Nuida, Goichiro Hanaoka
SAC4
2017 Efficient outsourcing of secure k-nearest neighbour query over encrypted database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi
Comput. Secur.5
2016 Reducing the Key Size of the SRP Encryption Scheme
Dung Hoang Duong, Albrecht Petzoldt, Tsuyoshi Takagi
ACISP (2)3
2016 Privacy-Preserving k-Nearest Neighbour Query on Outsourced Database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi
ACISP (1)5
2016 Improved Progressive BKZ Algorithms and Their Precise Cost Estimation by Sharp Simulator
Yoshinori Aono, Yuntao Wang 0002, Takuya Hayashi 0001, Tsuyoshi Takagi
EUROCRYPT (1)4
2016 Secure and controllable k-NN query over encrypted cloud data with key confidentiality
Youwen Zhu, Tsuyoshi Takagi
J. Parallel Distributed Comput.3
2016 Special issue on provable security
abstract
Provable security is an important research area in modern cryptography. Cryptographic primitives or protocols without rigorous proofs cannot be regarded as secure even in practice. In fact, many schemes were originally thought as secure but were broken subsequently. This clearly indicates the necessity of formal security analysis. For real-world applications, provable security provides us with a strong confidence in using cryptographic solutions. For a theoretical study, provable security sometimes provides a clear answer to the (in)feasibility issue of a certain security mechanism. This special issue offers a platform for security researchers and practitioners to exchange their new ideas for studying information systems in provably secure manners. We have included eighteen high-quality papers. Among them, six papers were selected from accepted papers at the 6th International Conference on Provable Security (ProvSec 2012), and the remaining 12 papers were selected from new invited submissions. All of them have gone through stringent reviews in two rounds. Further, any selected paper that has a preliminary version at ProvSec 2012 or somewhere else must have been extensively expanded to include new contributions. The included articles highlight recent advances in provable security by presenting many novel techniques in this area. We now give a short summary of them, through six categories. The first category is public-key encryption (PKE). It considers the formal models, constructions, and analysis of PKE under various security concerns. In the leakage-resiliency model, one considers the security of PKE when a partial secret key has been leaked (e.g., through a side-channel attack). Paper “continual key-leakage tolerant encryption from extensible-set delegation functionality” by Bo Yang and Mingwu Zhang proposes a leakage-resilient functional encryption and shows that its provable security under a continual leakage of the secret key. Motivated by the threat from malware such as RAM scrapers, the paper “stronger public key encryption system withstanding RAM scraper like attacks” by S. Sree Vivek, S. Sharmila Deva Selvi, Akshayaram Srinivasan and C. Pandu Rangan proposes a public-key security notion that is stronger than adaptive chosen-ciphertext (CCA2) security. They show that the traditionally CCA2 secure schemes are no longer secure in the new model. They also propose a new scheme that is provably secure in the new model without a random oracle. The paper “a limitation on security evaluation of cryptographic primitives with fixed keys” by Yutaka Kawai, Goichiro Hanaoka, Kazuo Ohta, and Noboru Kunihiro studies the security of public-key system when the public key is fixed. They have obtained some impossibility results for this setting. A key encapsulation mechanism is an efficient tool to construct a public-key encryption through a paradigm of a hybrid encryption. The paper “efficient key encapsulation mechanisms with tight security reductions to standard assumptions in the two security models” by Yoshikazu Hanatani, Goichiro Hanaoka, Takahiro Matsuda, and Takashi Yamakawa presents two constructions of efficient key encapsulation mechanisms. Their schemes can be proven CCA secure under a strong hardness assumption without random oracle or under a weaker assumption in the random oracle model. A hash proof system is a general cryptographic structure proposed by Cramer-Shoup in Eurotypt 2002 to construct public-key systems. The paper “generalized (identity-based) hash proof system and its applications” by Yu Chen, Zongyang Zhang, Dongdai Lin, and Zhenfu Cao generalizes this concept to admit an anonymity property. They use this generalized structure to propose public-key encryptions with leakage resilience and anonymity. They further study it in the identity-based setting. The second category is searchable encryption. It considers the public key or the symmetric key cryptosystems that allow keywords search over encrypted data. Usually, the search encryption requires a complete match on the keyword during the search. The paper “character-based symmetric searchable encryption and its implementation on mobile devices” by Takanori Suga, Takashi Nishide, and Kouichi Sakurai proposes a scheme that admits a partial keyword match for the search, and their scheme uses a symmetric encryption. They also have implemented the solution over a mobile device. The paper “searchable symmetric encryption capable of searching for an arbitrary string” by Yoshinao Uchide and Noboru Kunihiro further studies the partial keyword match problem and proposes a searchable encryption that admits a search query of an arbitrary string. Their main technique is an oblivious cross tag protocol by Cash et al. at CRYPTO 2013. The third category is a re-encryption. This considers to re-encrypt a ciphertext without using a decryption key. This is to reuse the ciphertext for a certain security or privacy purpose. The paper “strongly average-case secure obfuscation: achieving input privacy and circuit obscurity” by Mingwu Zhang, Yi Mu, Yixin Su, and Xinyi Huang studies the obfuscation for a re-encryption program with strong security such that an attacker, when executing an obfuscated re-encryption program, cannot obtain any information about the private key and the plaintext. Here, an obfuscation is an algorithm that converts a program into another with the same functionality while difficult to understand. An attribute-based encryption is a public-key cryptosystem that classifies a user using attributes such that a user can decrypt a ciphertext if and only if his attribute collection satisfies the desired requirement in the ciphertext. This achieves the access control functionality for the encryption. Attribute-based proxy re-encryption (PRE) is a useful technique for a delegation of access rights to encrypted data, which is useful in a public cloud storage. The paper “verifiable attribute-based proxy re-encryption for secure public cloud data sharing” by Suqing Lin, Rui Zhang, and Mingsheng Wang proposes a generic construction for attribute-based PRE and presents three realizations for it. The paper “on the application of generic CCA-secure transformations to proxy re-encryption” by David Nuñez, Isaac Agudo, and Javier Lopez studies the generic transformation for PRE from weak security to CCA security. For a regular public-key encryption, it is well known that a Fujisaki–Okamoto technique can transform a chosen-plaintext secure scheme into a CCA2 secure scheme. But the authors found out that this does not work for PRE. Instead, they achieve a weak form of CCA security for PRE using a generalized Fujisaki–Okamoto. The paper “proxy re-encryption via indistinguishability obfuscation” by Satsuya Ohata and Kanta Matsuura presents a technique for achieving PRE from obfuscation. Their idea is to carefully modify the public-key encryption scheme of Sahai and Waters at STOC 2014. The fourth category is a digital signature. This studies the models, constructions, and their analysis under various security concerns. A nominative signature is a signature that is generated by a signer A and a user B jointly. When the signature is to be verified by a user C, C will run a disavowal/confirmation protocol with B. The paper “one-move convertible nominative signature in the standard model” by Dennis Y. W. Liu and Duncan S. Wong proposes an efficient nominative signature that is provably secure in the standard model with a constant size of key for any party in the system. A ring signature is a signature, where a signer remains fully anonymous among a group of members (called a ring). The paper “non-interactive deniable ring signature without random oracles” by Shengke Zeng and Qinyi Li considers a variant of a ring signature, where the signer anonymity is conditional in the sense that a signer can confirm the authorship of the signature while a non-signer can disprove the authorship of a signature. They propose a new scheme for this model using the Boneh and Boyen signature and shows its security in the standard model. A blind signature is a special signature that allows one to obtain a signature on a message from a signature without leaking the message to the latter. This primitive has many applications in systems such as e-cash and e-voting schemes. The paper “a lattice based partially blind signature” by Haibo Tian, Fangguo Zhang, and Baodian Wei proposes the first latticed-based blind signature with partial blindness using the technique of Lyubashevsky from EUROCRYPT 2012 and the technique of Abe and Okamoto from CRYPTO 2000. The paper “generic transformations for existentially unforgeable signature schemes in the bounded leakage model” by Yuyu Wang and Keisuke Tanaka studies how to obtain strongly secure digital signatures. They propose two transformations that convert a regular weakly secure signature into a strongly secure signature in the bounded leakage model. The fifth category is a key exchange. A key exchange is a procedure that allows two or more parties to share a secret key securely. The paper “authenticated key exchange with entities from different settings and varied groups” by Yanfei Guo and Zhenfeng Zhang proposes several key exchange protocols with an initiator being identity based and the responder being certificate based. They consider the constructions with an identity-based system from a bilinear group and a prime residue group both. The last category is the symmetric key cryptography. It studies the cryptographic structure that does not use any public-key tool. A lightweight cryptographic primitive is such an example. It only incurs a very small computation cost. A lightweight primitive with provable security has a very important impact in the real world. The paper “two new message authentication codes based on APN functions and stream ciphers” by Teng Wu and Guang Gong proposes two lightweight message authentication codes and quantifies the insecurity upper bounds against a substitution attack. The paper “two-level security for message streams” by Mohsen Alimomeni and Reihaneh Safavi-Naini studies the information theoretic security of a private key encryption. They formalize a new model to quantify the security of many ciphertexts, where they require the message in the most recent ciphertext to be perfectly secure while messages in older ciphertexts have a lower level of security. They propose a non-trivial construction with provable security under their model. We would like to thank editor-in-chiefs Prof. Hsiao-Hwa Chen and Prof. Hamid R. Sharif for agreeing to this special issue and supporting us throughout the process. We also would like to thank all authors who submitted their papers to this special issue and reviewers who spent their precious time on the submissions and provided us with their insights that help us in an essential way to make the decisions.
Shaoquan Jiang, Tsuyoshi Takagi, Guilin Wang
Secur. Commun. Networks2
2016 Revocable and strongly unforgeable identity-based signature scheme in the standard model
abstract
Abstract Revocation functionality is crucial for the practicality of the public key cryptosystems, especially for that of identity‐based cryptosystems. When some users lose their private keys, the cryptosystems must support an efficient revocation method to revoke such users. On the other hand, strong unforgeability provides stronger security than existential unforgeability and ensures the adversary cannot even produce a new signature for a previously signed message. However, existing revocable identity‐based signature schemes can support neither efficient key revocation nor strong unforgeability. In this paper, we propose a strongly unforgeable identity‐based signature scheme with efficient revocation. In the proposed scheme, the master key is randomly divided into two parts: one is used to construct the initial secret key, the other is used to generate the key update. Furthermore, they are used to periodically and re‐randomly produce signing keys for non‐revoked users. Thus, the proposed scheme can efficiently revoke users and resist key exposure attacks. In the standard model, our scheme is proven to be strongly unforgeable under the CDH hardness assumption. Copyright © 2016 John Wiley & Sons, Ltd.
Zhenhua Liu 0001, Xiangsong Zhang, Yupu Hu, Tsuyoshi Takagi
Secur. Commun. Networks4
2016 Security Analysis and Improvements on Two Homomorphic Authentication Schemes for Network Coding
abstract
Recently, based on the homomorphic signatures, the authentication schemes, such as homomorphic subspace signature (HSS) and key predistribution-based tag encoding (KEPTE), have been proposed to resist against pollution attacks in network coding. In this paper, we show that there exists an efficient multi-generation pollution attack on HSS and KEPTE. In particular, we show that using packets and their signatures of different generations, the adversary can create invalid packets and their corresponding signatures that pass the verification of HSS and KEPTE at intermediate the nodes as well as at the destination nodes. After giving a more generic attack, we analyze the cause of the proposed attack. We then propose the improved key distribution schemes for HSS and KEPTE, respectively. Next, we show that the proposed key distribution schemes can combat against the proposed multi-generation pollution attacks. Finally, we analyze the computation and communication costs of the proposed key distribution schemes for HSS and KEPTE, and by implementing experiments, we demonstrate that the proposed schemes add acceptable burden on the system.
Chi Cheng 0003, Jemin Lee 0002, Tao Jiang 0002, Tsuyoshi Takagi
IEEE Trans. Inf. Forensics Secur.4
2016 Efficient Deniably Authenticated Encryption and Its Application to E-Mail
abstract
Confidentiality and authentication are two main security goals in secure electronic mail (e-mail). Pretty good privacy (PGP) and secure/multipurpose internet mail extensions (S/MIME) are two famous secure e-mail solutions. Both PGP and S/MIME use digital envelope to provide message confidentiality and digital signature to provide message authentication. However, these methods have the following two weaknesses: 1) digital signature provides non-repudiation evidence of sender that is not desired in some e-mail applications and 2) efficiency is low, since these methods use two kinds of public key cryptographic primitives: public key encryption and digital signature. To overcome the above two weaknesses, we introduce a new concept called deniably authenticated encryption that can achieve confidentiality, integrity, and deniable authentication in a logical single step. We first propose a deniably authenticated encryption scheme and prove its security in the random oracle model. Then, we design a secure e-mail protocol using the proposed deniably authenticated encryption scheme. The deniable authentication property protects senders' privacy.
Fagen Li, Di Zhong, Tsuyoshi Takagi
IEEE Trans. Inf. Forensics Secur.3
2015 Functional Encryption Resilient to Hard-to-Invert Leakage
abstract
Functional encryption (FE) systems provide a flexible and expressive encryption mechanism that private keys and ciphertexts are associated with attributes and predicate formulae Γ and decryption are possible whenever keys and ciphertexts are related, i.e. ⁠. In this work, we put forward a leakage-resilient FE scheme against the amount of leakage output over a hard-to-invert function family. In our scheme, the encryption policy is specified as an arbitrary monotonic formula, and the adversary can learn the arbitrary length output of the master key and the private key from any computationally irreversible function with the input (master) keys. To improve the efficiency, we employ the set of minimal sets to describe the predicate formula or access structure, and initiate the formal model of leakage-resilient FE, which is a generic extension of identity-based encryption and attribute-based encryption in the presence of key leakage with auxiliary inputs. We provide the concrete construction in bilinear groups of composite order, and prove the adaptively leakage-resilient security in the standard model based on static assumptions. Our hard-to-invert leakage resilience employs the Goldreich–Levin theorem and its extension as a hard-core value over large fields. We also give an extensional construction in the case of obtaining the hard-to-invert randomness leakage of the encryption, which uses a strong extractor to prevent leakage of randomness and a hard-to-invert encryption to prevent the leakage of the key. Finally, we analyze and discuss the stepped-up security on master leakage and continual leakage, and the lower bound of the irreversible leakage function.
Mingwu Zhang, Tsuyoshi Takagi, Yi Mu 0001
Comput. J.3
2015 On the Security of A Privacy-Preserving Product Calculation Scheme
abstract
Recently, Jung and Li [1] propose a highly efficient privacy-preserving product calculation scheme without requiring secure communication channels. Then, they present secure approaches to solve several application problems using the product calculation protocol. In this work, we observe several security flawsin their privacy-preserving product calculation scheme and some application protocols. We show the security vulnerabilities will result in the disclosure of private data. In two application protocols, almost all the private numbers will be revealed. We further suggest solutions to fix the security problems.
Youwen Zhu, Liusheng Huang, Tsuyoshi Takagi
IEEE Trans. Dependable Secur. Comput.4
2014 A Polynomial-Time Algorithm for Solving a Class of Underdetermined Multivariate Quadratic Equations over Fields of Odd Characteristics
Chen-Mou Cheng, Yasufumi Hashimoto, Hiroyuki Miura, Tsuyoshi Takagi
PQCrypto4
2014 Anonymous encryption with partial-order subset delegation and its application in privacy email systems
abstract
In privacy‐carrying email systems, the authors should guarantee that the email content is confidential and sometimes the sender/receiver identities are hidden. Also, they require that the key generation is flexible and manageable. In this study, first, they propose an anonymous encryption scheme that supports a partial‐order subset delegatable ability. The proposed scheme achieves the security properties of confidentiality against adaptive chosen‐plaintext attacks, anonymity against adaptive chosen‐subset attacks and computational delegation indistinguishability. Secondly, they provide a deployment application of their anonymous encryption in an interdisciplinary group email management system with flexible and fine‐grained key delegation. The deployment can achieve the privacy of message confidentiality, receiver anonymity and delegation obliviousness, which has fine‐grained security in secure email systems. Finally, they provide an extension for the chosen‐ciphertext secure scheme, and discuss the efficiency for decryption and the security level.
Mingwu Zhang, Takashi Nishide, Bo Yang 0003, Tsuyoshi Takagi
IET Inf. Secur.4
2014 Anonymous spatial encryption under affine space delegation functionality with full security
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Inf. Sci.3
2014 Collaborative agglomerative document clustering with limited information disclosure
abstract
ABSTRACT Document clustering is a practical and powerful data mining technique to analyze large amount of documents and large sets of text or hypertext documents. However, it also brings the problem of sensitive information leaking in disregard of privacy, especially when it is executed in distributed environment. In this paper, we propose a cryptography‐based framework to realize privacy‐preserving document clustering among the users under the distributed environment; there are two parties, each having his private document database, want to collaboratively execute agglomerative document clustering without disclosing their private contents. We provide two implementations of such a framework, one is with more precision and stronger security but requires more computational resources. The other is a simplified version with less computational complexity and achieves higher processing speed. Additionally, we provide the security proofs and experimental analysis of precision and scalability of our proposal. Copyright © 2013 John Wiley & Sons, Ltd.
Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai
Secur. Commun. Networks4
2014 Unbounded anonymous hierarchical IBE with continual-key-leakage tolerance
abstract
ABSTRACT Modern cryptographic schemes are constructed under the fundamental assumption that secret keys are perfectly hidden from all possible attackers. In practice, however, keys and internal states may partially be leaked. Recently, cryptographic construction with key‐leakage resilience has been a crucial research topic. In this work, we proposed an anonymous hierarchical identity‐based encryption that can tolerate partial leakage of secret keys. Our results were as follows. First, we provided a tolerance for continual key leakage that can capture both memory leakage and continual leakage. We extended a dual‐system encryption mechanism in orthogonal subgroups to achieve key‐leakage resilience and implicitly employed an update algorithm to guard against continual leakage. Second, the delegation depth is unbounded, which means that no predetermined depth was imposed in the setup algorithm, thus making the scheme very flexible in practice. We employed a secret‐sharing approach to split the master key into multiple shares in key components corresponding to the elements. Third, we analyzed and discussed the performance of allowable leakage‐tolerance bounds and the leakage rate of the proposed scheme and gave an evaluation that attains about 40–70% leakage rate under the Advanced Encryption Standard 112 security level. Copyright © 2013 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Secur. Commun. Networks4
2013 Attacks on Multi-Prime RSA with Small Prime Difference
Hui Zhang 0051, Tsuyoshi Takagi
ACISP2
2013 Proof of plaintext knowledge for code-based public-key encryption revisited
abstract
In a recent paper at Asiacrypt'2012, Jain et al point out that Veron code-based identification scheme is not perfect zero-knowledge. In particular, this creates a gap in security arguments of proof of plaintext knowledge (PPK) and verifiable encryption for the McEliece public key encryption (PKE) proposed by Morozov and Takagi at ACISP'2012. We fix the latter result by showing that PPK for the code-based Niederreiter and McEliece PKE's can be constructed using Stern zero-knowledge identification scheme, which is unaffected by the above mentioned problem. Since code-based verifiable encryption uses PPK as a main ingredient, our proposal presents a fix for the McEliece verifiable encryption as well. In addition, we present the Niederreiter verifiable encryption.
Kirill Morozov, Tsuyoshi Takagi
AsiaCCS3
2013 Extended Algorithm for Solving Underdefined Multivariate Quadratic Equations
Hiroyuki Miura, Yasufumi Hashimoto, Tsuyoshi Takagi
PQCrypto3
2013 Multivariate Signature Scheme Using Quadratic Forms
Takanori Yasuda, Tsuyoshi Takagi, Kouichi Sakurai
PQCrypto2
2013 Bounded Leakage-Resilient Functional Encryption with Hidden Vector Predicate
abstract
Recent research shows that many public-key or identity-based encryption schemes are vulnerable to side-channel attacks on the keys by the interaction of an adversary with a physical device. To tolerate the possible key leakage, leakage-resilient cryptography models a class of leakage output by allowing the adversary to be able to specify a computable leakage function and obtaining the partial keys or other possibly internal states from the output of function. In this article, we propose a leakage-resilient hidden-vector encryption (HVE) scheme that supports the predicate operators such as conjunction, disjunction, comparison, range query and subset query, etc. The proposed scheme is leakage-resilient attribute-hiding secure in the sense that the adversary cannot only obtain the tokens of non-match vectors but also learn amount of key information of the vector that matches the challenge vector. To the best of our knowledge, this is the first HVE that supports token-leakage resilience. We prove the security with a series of computationally indistinguishable games that uses the dual system encryption mechanism. We also analyze and discuss the performance of leakage bound parameters and leakage fraction in the practical security level. Finally, we also give an extensive scheme to achieve the security of both attribute-hiding and payload-hiding, and analyze the performance in larger alphabets.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Comput. J.3
2013 Lattice-based signcryption
abstract
SUMMARY Signcryption is a cryptographic primitive that performs simultaneously both the functions of digital signature and public‐key encryption, at a cost significantly lower than that required by the traditional signature‐ then‐encryption approach. In this paper, we provide a positive answer to the question of if it is possible to construct signcryption based on lattice problems. More precisely, we design an efficient signcryption scheme that can send a message of length l one time. We prove that the proposed scheme has the indistinguishability against adaptive chosen ciphertext attacks under the learning with errors assumption and strong unforgeability against adaptive chosen messages attacks under the inhomogeneous small integer solution assumption in the random oracle model. Copyright © 2012 John Wiley & Sons, Ltd.
Fagen Li, Fahad Bin Muhaya, Muhammad Khurram Khan, Tsuyoshi Takagi
Concurr. Comput. Pract. Exp.4
2013 Efficient and adaptively secure broadcast encryption systems
abstract
ABSTRACT Broadcast encryption is an effective way to broadcast a message securely such that more than one privileged receiver can decrypt it. The well‐known constructions of identity‐based broadcast encryption only support bounded broadcast users that had to deploy the maximum user number in advance. This is somewhat inefficient and impractical if the broadcast user number is predetermined. In this paper, we propose an adaptively secure identity‐based broadcast encryption in the standard model that supports arbitrary number of users in broadcast set, which eliminates the size of public parameters with a constant number of group elements and obtain short ciphertexts, secret keys, and public parameters. We use the techniques of semi‐functional ciphertexts and semi‐functional keys in orthogonal subgroups to implement the boundless broadcast set and adaptive security by means of dual‐system encryption mechanism in a composite‐order group, and we prove the scheme to be fully secure without the random oracles in the static assumptions. The proposed scheme captures the properties of confidentiality, adaptive security, constant key, and short ciphertext. We also evaluate the computational costs and communication overheads and give the deployment in secure set‐top box broadcast systems. Copyright © 2012 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Zhenhua Chen 0001, Tsuyoshi Takagi
Secur. Commun. Networks4
2012 Zero-Knowledge Protocols for the McEliece Encryption
Kirill Morozov, Tsuyoshi Takagi
ACISP2
2012 Breaking Pairing-Based Cryptosystems Using η T Pairing over GF(397)
Takuya Hayashi 0001, Takeshi Shimoyama, Naoyuki Shinohara, Tsuyoshi Takagi
ASIACRYPT4
2012 Reducing the Key Size of Rainbow Using Non-commutative Rings
Takanori Yasuda, Kouichi Sakurai, Tsuyoshi Takagi
CT-RSA3
2012 Key Length Estimation of Pairing-Based Cryptosystems Using η T Pairing
Naoyuki Shinohara, Takeshi Shimoyama, Takuya Hayashi 0001, Tsuyoshi Takagi
ISPEC4
2012 Efficient signcryption in the standard model
abstract
SUMMARY Signcryption is a cryptographic primitive that fulfills both the functions of digital signature and public key encryption simultaneously, at a cost significantly lower than that required by the traditional signature‐then‐encryption approach. The performance advantage of signcryption over the signature‐then‐encryption method makes signcryption useful in many applications, such as electronic commerce, mobile communications, and smart cards. In this paper, we propose an efficient signcryption scheme in the standard model. We prove that our scheme satisfies the confidentiality and strong unforgeability. Compared with the Tan's scheme, our scheme has | G | + | p | (320) bits shorter ciphertext, 2 | p | − | G | (160) bits shorter private key, and | GT | + | G | (1184) bits shorter public key. In addition, in the Tan's scheme, a user must hold two public key/private key pairs at one time if it were both sender and receiver. Our scheme only needs a public key/private key pair, which is more practical for application. Copyright © 2011 John Wiley & Sons, Ltd.
Fagen Li, Mingwu Zhang, Tsuyoshi Takagi
Concurr. Comput. Pract. Exp.3
2012 Identity-based online/offline signcryption for low power devices
Fagen Li, Muhammad Khurram Khan, Khaled Alghathbar, Tsuyoshi Takagi
J. Netw. Comput. Appl.4
2012 Reconciling and improving of multi-receiver signcryption protocols with threshold decryption
abstract
ABSTRACT Signcryption is a cryptographic primitive that offers both confidentiality and authentication simultaneously, which combines the functionalities of signature and encryption in a provably secure manner. Indistinguishability against adaptive chosen‐ciphertext attacks (ind‐cca2) and unforgeability against adaptive chosen‐message attacks (euf‐cma2) are two important security requirements of a signcryption protocol. In a multi‐receiver signcryption with a threshold decryption scheme, the ciphertext can be decrypted and verified when arbitrary t or more receivers among the n candidate decrypters work together. Recently, Qin et al. [Security and Communication Networks, 2011] proposed an identity‐based multi‐receiver signcryption scheme with threshold decryption, and they declared that the scheme achieves ind‐cca2 and euf‐cma2 security. In this paper, we first indicate that Qin et al.'s scheme is not secure, that is, Qin et al.'s scheme is neither semantically secure against ind‐cca2 nor unforgeable against euf‐cma2. After that, we present an improved scheme to capture the security requirements. Furthermore, we construct an anonymous version that can preserve the identity privacy of the sender and receiver, and we give the performance evaluation to indicate that our scheme has lower communication overhead although it provides the identity privacy preservation. Copyright © 2012 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Secur. Commun. Networks3
2011 GeoEnc: Geometric Area Based Keys and Policies in Functional Encryption Systems
Mingwu Zhang, Tsuyoshi Takagi
ACISP2
2011 General Fault Attacks on Multivariate Public Key Cryptosystems
Yasufumi Hashimoto, Tsuyoshi Takagi, Kouichi Sakurai
PQCrypto2
2011 Efficient Identity-Based Signcryption in the Standard Model
Fagen Li, Fahad Bin Muhaya, Mingwu Zhang, Tsuyoshi Takagi
ProvSec4
2011 Anonymous Encryption with Partial-Order Subset Delegation Functionality
Mingwu Zhang, Takashi Nishide, Bo Yang 0003, Tsuyoshi Takagi
ProvSec4
2011 Group-oriented setting's multisigncryption scheme with threshold designcryption
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Inf. Sci.3
2010 Cryptanalysis of efficient proxy signature schemes for mobile communication
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
Sci. China Inf. Sci.3
2009 Identity-Based Hybrid Signcryption
abstract
Signcryption is a cryptographic primitive that fulfills both the functions of digital signature and public key encryption simultaneously, at a cost significantly lower than that required by the traditional signature-then-encryption approach. In this paper, we address a question whether it is possible to construct a hybrid signcryption scheme in identity-based setting. This question seems to have never been addressed in the literature. We answer the question positively in this paper. In particular, we extend the concept of signcryption key encapsulation mechanism to the identity-based setting. We show that an identity-based signcryption scheme can be constructed by combining an identity-based signcryption key encapsulation mechanism with a data encapsulation mechanism. We also give an example of identity-based signcryption key encapsulation mechanism.
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
ARES3
2009 Certificateless Hybrid Signcryption
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
ISPEC3
2009 One-wayness equivalent to general factoring
abstract
This paper shows the first practical semantically secure public-key encryption scheme such that its one-wayness is equivalent togeneralfactoring in thestandardmodel [in the sense of indistinguishability against chosen-plaintext attack (IND-CPA)]. Next our proof technique is applied to the Rabin-Paillier encryption scheme and a variant of the RSA-Paillier encryption scheme to prove their one-wayness under the factoring assumption via tight security reductions.
Kaoru Kurosawa, Tsuyoshi Takagi
IEEE Trans. Inf. Theory2
2008 A Secure RFID Protocol based on Insubvertible Encryption Using Guardian Proxy
abstract
Radio frequency identification (RFID) has been widely deployed for manufacturing, supply chain management, etc. Unfortunately, RFID may cause privacy and security problems. To solve these problems, researchers have studied extensively on RFID security systems. Ateniese et al. proposed an RFID protocol using insubvertible encryption based on the universal re-encryption. Although this protocol achieves the integrity of ciphertexts randomized by authorized users, it still leaves security problems. In this paper, we propose a secure RFID protocol based on insubvertible encryption involving guardian proxy. The guardian proxy is a personal RFID-privacy device which may be integrated into cellular phones or PDAs. By introducing the guardian proxy and other basic cryptographic primitives into RFID systems, our protocol is secure against the tag spoofing and swapping attacks. Moreover, our protocol enables ownership transfer.
Kyosuke Osaka, Shuang Chang, Tsuyoshi Takagi, Kenichi Yamazaki, Osamu Takahashi
ARES3
2008 A New Scheme for Distributed Density Estimation based Privacy-Preserving Clustering
abstract
The sensitive information leakage and security risk is a problem from which both individual and enterprise suffer in massive data collection and the information retrieval by the distrusted parties. In this paper, we focus on the privacy issue of data clustering and point out some security risks in the existing data mining algorithms. Associated with cryptographic techniques, we initiate an application of random data perturbation (RDP) which has been widely used for preserving the privacy of individual records in statistical database for the distributed data clustering scheme. Our scheme applies linear transformation of Gaussian distribution perturbed data and general additional data perturbation (GADP) schemes to preserve the privacy for distributed kernel density estimation with the help of any trusted third party. We also show that our scheme is more secure against the random matrix-based filtering attack which is based on analysis of the distribution of the eigenvalues by using two RDP methods.
Chunhua Su, Feng Bao 0001, Jianying Zhou 0001, Tsuyoshi Takagi, Kouichi Sakurai
ARES4
2008 On the Security of Online/Offline Signatures and Multisignatures from ACISP'06
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
CANS3
2008 Efficient Signcryption Key Encapsulation without Random Oracles
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
Inscrypt3
2008 Efficient Multi-PKG ID-Based Signcryption for Ad Hoc Networks
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
Inscrypt3
2008 Efficient Arithmetic on Subfield Elliptic Curves over Small Finite Fields of Odd Characteristic
Keisuke Hakuta, Hisayoshi Sato, Tsuyoshi Takagi
ISPEC3
2008 An Efficient Countermeasure against Side Channel Attacks for Pairing Computation
Masaaki Shirase, Tsuyoshi Takagi, Eiji Okamoto
ISPEC2
2008 Network Forensics on Mobile Ad-Hoc Networks
Akira Otaka, Tsuyoshi Takagi, Osamu Takahashi
KES (3)2
2008 Key Management Using Certificateless Public Key Cryptography in Ad Hoc Networks
Fagen Li, Masaaki Shirase, Tsuyoshi Takagi
NPC3
2008 Faster Implementation of eta-T Pairing over GF(3m) Using Minimum Number of Logical Instructions for GF(3)-Addition
Yuto Kawahara, Kazumaro Aoki, Tsuyoshi Takagi
Pairing3
2008 Digital Signatures Out of Second-Preimage Resistant Hash Functions
Erik Dahmen, Katsuyuki Okeya, Tsuyoshi Takagi, Camille Vuillaume
PQCrypto3
2008 Algorithms and Arithmetic Operators for Computing the etaT Pairing in Characteristic Three
abstract
Since their introduction in constructive cryptographic applications, pairings over (hyper)elliptic curves are at the heart of an ever increasing number of protocols. Software implementations being rather slow, the study of hardware architectures became an active research area. In this paper, we discuss several algorithms to compute the ηT pairing in characteristic three and suggest further improvements. These algorithms involve addition, multiplication, cubing, inversion, and sometimes cube root extraction over GF(3m). We propose a hardware accelerator based on a unified arithmetic operator able to perform the operations required by a given algorithm. We describe the implementation of a compact coprocessor for the field GF(397) given by GF(3)[x]/(x97+x12+2), which compares favorably with other solutions described in the open literature.
Jean-Luc Beuchat, Nicolas Brisebarre, Jérémie Detrey, Eiji Okamoto, Masaaki Shirase, Tsuyoshi Takagi
IEEE Trans. Computers6
2008 Short-Memory Scalar Multiplication for Koblitz Curves
abstract
This paper presents a scalar multiplication method for Koblitz curves. Koblitz curves are elliptic curves where the scalar multiplication can be computed in a much faster way than with other curves, allowing designs and implementations without arithmetic coprocessor. The new method is as fast as the fastest known techniques on Koblitz curves but requires much less memory; therefore, it is of particular interest for environments with low resources. Our technique is well suited for both hardware and software implementations. In hardware, we show that a normal basis implementation reduces memory consumption by 85 percent compared to conventional methods, but this still has exactly the same computational cost. In software, thanks to a mixed normal-polynomial bases approach, our technique allows memory savings up to 70 percent and, depending on the instruction set of the CPU, can be as fast as the fastest known scalar multiplication methods or can even beat them by a large margin. Therefore, in software and in hardware, our scalar multiplication technique offers high performance without sacrifice in view of memory.
Camille Vuillaume, Katsuyuki Okeya, Tsuyoshi Takagi
IEEE Trans. Computers3
2007 Compressed XTR
Masaaki Shirase, Dong-Guk Han, Yasushi Hibino, Howon Kim 0001, Tsuyoshi Takagi
ACNS5
2007 An Algorithm for the nt Pairing Calculation in Characteristic Three and its Hardware Implementation
abstract
In this paper, we propose a modified etaTpairing algorithm in characteristic three which does not need any cube root extraction. We also discuss its implementation on a low cost platform which hosts an Altera Cyclone II FPGA device. Our pairing accelerator is ten times faster than previous known FPGA implementations in characteristic three.
Jean-Luc Beuchat, Masaaki Shirase, Tsuyoshi Takagi, Eiji Okamoto
IEEE Symposium on Computer Arithmetic3
2007 Some Efficient Algorithms for the Final Exponentiation of eta T Pairing
Masaaki Shirase, Tsuyoshi Takagi, Eiji Okamoto
ISPEC2
2007 Two-Party Privacy-Preserving Agglomerative Document Clustering
Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai
ISPEC4
2007 A Coprocessor for the Final Exponentiation of the eta T Pairing in Characteristic Three
Jean-Luc Beuchat, Nicolas Brisebarre, Masaaki Shirase, Tsuyoshi Takagi, Eiji Okamoto
WAIFI4
2006 New Approach for Selectively Convertible Undeniable Signature Schemes
Kaoru Kurosawa, Tsuyoshi Takagi
ASIACRYPT2
2006 Side Channel Attacks and Countermeasures on Pairing Based Cryptosystems over Binary Fields
Tae Hyun Kim 0003, Tsuyoshi Takagi, Dong-Guk Han, Howon Kim 0001, Jongin Lim 0001
CANS2
2006 Power Analysis to ECC Using Differential Power Between Multiplication and Squaring
Toru Akishita, Tsuyoshi Takagi
CARDIS2
2006 New Security Problem in RFID Systems "Tag Killing"
Dong-Guk Han, Tsuyoshi Takagi, Howon Kim 0001, Kyoil Chung
ICCSA (3)2
2006 Further Security Analysis of XTR
Dong-Guk Han, Tsuyoshi Takagi, Jongin Lim 0001
ISPEC2
2006 Analysis of Fractional Window Recoding Methods and Their Application to Elliptic Curve Cryptosystems
abstract
Elliptic curve cryptosystems (ECC) are suitable for memory-constraint devices like smart cards due to their small key-size. A standard way of computing elliptic curve scalar multiplication, the most frequent operation in ECC, is window methods, which enhance the efficiency of the binary method at the expense of some precomputation. The most established window methods are sliding window on NAF (NAF+SW), wNAF, and wMOF, where NAF and MOF are acronyms for nonadjacent form and mutually opposite form, respectively. A common drawback of these schemes is that only a small portion of the numbers is possible sizes for precomputation tables. Therefore, in practice, it is often necessary to waste memory because there is no table fitting exactly the available storage. In the case of wNAF, there exists a variant that allows arbitrary table sizes, the so-called fractional wNAF (Frac-wNAF). In this paper, we give a comprehensive proof using Markov theory for the estimation of the average nonzero density of the Frac-wNAF representation. Then, we propose the fractional wMOF (Frac-wMOF), which is a left-to-right analogue of Frac-wNAF. We prove that Frac-wMOF inherits the outstanding properties of Frac-wAF. However, because of its left-to-right nature, Frac-wMOF is preferable as it reduces the memory consumption of the scalar multiplication. Finally, we show that the properties of all discussed previous schemes can be achieved as special instances of the Frac-wMOF method. To demonstrate the practicability of Frac-wMOF, we develop an on-the-fly algorithm for computing elliptic curve scalar multiplication with a flexibly chosen amount of memory.
Katja Schmidt-Samoa, Olivier Semay, Tsuyoshi Takagi
IEEE Trans. Computers3
2005 A Complete Divisor Class Halving Algorithm for Hyperelliptic Curve Cryptosystems of Genus Two
Izuru Kitamura, Masanobu Katagi, Tsuyoshi Takagi
ACISP3
2005 Efficient Representations on Koblitz Curves with Resistance to Side Channel Attacks
Katsuyuki Okeya, Tsuyoshi Takagi, Camille Vuillaume
ACISP2
2005 Short Memory Scalar Multiplication on Koblitz Curves
Katsuyuki Okeya, Tsuyoshi Takagi, Camille Vuillaume
CHES2
2004 On the Exact Flexibility of the Flexible Countermeasure Against Side Channel Attacks
Katsuyuki Okeya, Tsuyoshi Takagi, Camille Vuillaume
ACISP2
2004 Security Analysis of CRT-Based Cryptosystems
Katsuyuki Okeya, Tsuyoshi Takagi
ACNS2
2004 Signed Binary Representations Revisited
Katsuyuki Okeya, Katja Schmidt-Samoa, Christian Spahn, Tsuyoshi Takagi
CRYPTO4
2004 Behavior Description and Control using Behavior Module for Personal Robot
abstract
This paper describes a module-based behavior selection architecture for a personal robot intended for a real world environment. We adopt the Emotional GrOunded architecture for a basis, and define and describe a behavior module and an associated tree structure for controlling many behavior modules. Also we discuss the requirements and approach for controlling the behavior module tree. Through experimentation and implementation on QRIO SDR4X-II, we confirm the feasibility and design of the behavior selection system.
Yukiko Hoshino, Tsuyoshi Takagi, Ugo Di Profio
ICRA2
2004 Behavior selection and motion modulation in emotionally grounded architecture for QRIO SDR-4XII
abstract
This paper focuses OD the design and evaluation of behavior module selection and motion modulation based on emotion in the emotionally grounded (EGO) architecture that is applied in autonomous robot QRIO SDR-4 X II. In the EGO architecture, a behavior module is selected based on homeostasis in order for the robot to regulate its internal state within a certain range. Each behavior module has a value called activation level (AL) that is composed of motivation value (Mot) and releasing value (Rel). Mot determines the degree that the instinct drives the behavior module. It is derived from internal state. Rel is the degree that reflects how much external stimuli would satisfy an internal state as a result of the behavior. It is derived from the internal state and external stimuli. Each behavior module competes in AL to select a behavior module. Emotion is a key for motion modulation. It is derived from the internal state, its change, and the expected change of internal state associated with external stimuli in long-term memory. Through the implementation and experiments on QRIO SDR-4X II, we confirm the behavior selection and motion modulation processes in the EGO architecture.
Tsutomu Sawada, Tsuyoshi Takagi
IROS2
2004 Radix-r Non-Adjacent Form
Tsuyoshi Takagi, Sung-Ming Yen, Bo-Ching Wu
ISC1
2004 Efficient Undeniable Signature Schemes Based on Ideal Arithmetic in Quadratic Orders
Ingrid Biehl, Sachar Paulus, Tsuyoshi Takagi
Des. Codes Cryptogr.3
2003 A Complete and Explicit Security Reduction Algorithm for RSA-Based Cryptosystems
Kaoru Kurosawa, Katja Schmidt-Samoa, Tsuyoshi Takagi
ASIACRYPT3
2003 Some RSA-Based Encryption Schemes with Tight Security Reduction
Kaoru Kurosawa, Tsuyoshi Takagi
ASIACRYPT2
2003 Generalized Powering Functions and Their Application to Digital Signatures
Hisayoshi Sato, Tsuyoshi Takagi, Satoru Tezuka, Kazuo Takaragi
ASIACRYPT2
2003 A More Flexible Countermeasure against Side Channel Attacks Using Window Method
Katsuyuki Okeya, Tsuyoshi Takagi
CHES2
2003 The Width-w NAF Method Provides Small Memory and Fast Elliptic Scalar Multiplications Secure against Side Channel Attacks
Katsuyuki Okeya, Tsuyoshi Takagi
CT-RSA2
2003 Zero-Value Point Attacks on Elliptic Curve Cryptosystem
Toru Akishita, Tsuyoshi Takagi
ISC2
2002 A New Distributed Primality Test for Shared RSA Keys Using Quadratic Fields
Ingrid Biehl, Tsuyoshi Takagi
ACISP2
2002 On the Security of a Modified Paillier Public-Key Primitive
Kouichi Sakurai, Tsuyoshi Takagi
ACISP2
2002 Fast Elliptic Curve Multiplications with SIMD Operations
Tetsuya Izu, Tsuyoshi Takagi
ICICS2
2001 Ethological Modeling and Architecture for an Entertainment Robot
abstract
Presents a method for creating high-fidelity models of animal behavior for use in robotic systems based on a behavioral systems approach, and describes in particular how an ethological model of a domestic dog can be implemented with AIBO, the Sony entertainment robot.
Ronald C. Arkin, Tsuyoshi Takagi, Rika Hasegawa
ICRA3
2001 How to Choose Secret Parameters for RSA-Type Cryptosystems over Elliptic Curves
Marc Joye, Jean-Jacques Quisquater, Tsuyoshi Takagi
Des. Codes Cryptogr.3
2000 A New Public-Key Cryptosystem over a Quadratic Order with Quadratic Decryption Time
Sachar Paulus, Tsuyoshi Takagi
J. Cryptol.2
1999 Reducing Logarithms in Totally Non-maximal Imaginary Quadratic Orders to Logarithms in Finite Fields
Detlef Hühnlein, Tsuyoshi Takagi
ASIACRYPT2
1999 NICE - New Ideal Coset Encryption
Michael Hartmann, Sachar Paulus, Tsuyoshi Takagi
CHES3
1998 Fast RSA-Type Cryptosystem Modulo pkq
Tsuyoshi Takagi
CRYPTO1
1998 A Cryptosystem Based on Non-maximal Imaginary Quadratic Orders with Fast Decryption
Detlef Hühnlein, Michael J. Jacobson Jr., Sachar Paulus, Tsuyoshi Takagi
EUROCRYPT4
1997 Fast RSA-Type Cryptosystems Using N-Adic Expansion
Tsuyoshi Takagi
CRYPTO1
1996 The Multi-variable Modular Polynomial and Its Applications to Cryptography
Tsuyoshi Takagi, Shozo Naito
ISAAC1