EDBT 2026 Demo / reviewers in the wild / expert
Shuichi Katsumata
dblp:151/6926
· DBLP profile ↗
52ranked-venue papers
24as first author
33since 2021 · last 2026
0000-0002-8496-0476ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 49 · 22 first-author · 32 since 2021Theory of computation · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMs
Keitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom Wiggers |
SP | 2 |
| 2025 | Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort Protocol
Rafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle, Kaoru Takemure |
CRYPTO (6) | 2 |
| 2025 | Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal Protocol
Yevgeniy Dodis, Daniel Jost 0001, Shuichi Katsumata, Thomas Prest, Rolfe Schmidt |
EUROCRYPT (8) | 3 |
| 2025 | How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol
Benedikt Auerbach, Yevgeniy Dodis, Daniel Jost 0001, Shuichi Katsumata, Rolfe Schmidt |
USENIX Security Symposium | 4 |
| 2025 | Exploring How to Authenticate Application Messages in MLS: More Efficient, Post-Quantum, and Anonymous Blocklistable
Keitaro Hashimoto, Shuichi Katsumata, Guillermo Pascual-Perez |
USENIX Security Symposium | 2 |
| 2025 | Bundled Authenticated Key Exchange: A Concrete Treatment of Signal's Handshake Protocol and Post-Quantum Security
Keitaro Hashimoto, Shuichi Katsumata, Thom Wiggers |
USENIX Security Symposium | 2 |
| 2025 | Comprehensive Deniability Analysis of Signal Handshake Protocols: X3DH, PQXDH to Fully Post-Quantum with Deniable Ring Signatures
Shuichi Katsumata, Guilhem Niot, Ida Tucker, Thom Wiggers |
USENIX Security Symposium | 1 |
| 2025 | Two-Round Threshold Signature from Algebraic One-More Learning with Errors
Thomas Espitau, Shuichi Katsumata, Kaoru Takemure |
J. Cryptol. | 2 |
| 2024 | Two-Round Threshold Signature from Algebraic One-More Learning with Errors
Thomas Espitau, Shuichi Katsumata, Kaoru Takemure |
CRYPTO (7) | 2 |
| 2024 | Adaptively Secure 5 Round Threshold Signatures from MLWE/MSIS and DL with Rewinding
Shuichi Katsumata, Michael Reichle, Kaoru Takemure |
CRYPTO (7) | 1 |
| 2024 | Raccoon: A Masking-Friendly Signature Proven in the Probing Model
Rafaël Del Pino, Shuichi Katsumata, Thomas Prest, Melissa Rossi |
CRYPTO (1) | 2 |
| 2024 | Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions
Rafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem, Thomas Prest, Markku-Juhani O. Saarinen |
EUROCRYPT (2) | 2 |
| 2024 | Anonymous Reputation Systems with Revocation, Revisited
Ryuya Hayashi, Shuichi Katsumata, Yusuke Sakai 0001 |
FC (2) | 2 |
| 2024 | Tighter Adaptive IBEs and VRFs: Revisiting Waters' Artificial Abort
Goichiro Hanaoka, Shuichi Katsumata, Kei Kimura, Kaoru Takemure, Shota Yamada 0001 |
TCC (3) | 2 |
| 2024 | CSI-Otter: isogeny-based (partially) blind signatures from the class group action with a twistabstractAbstract In this paper, we construct the first provably-secure isogeny-based (partially) blind signature scheme. While at a high level the scheme resembles the Schnorr blind signature, our work does not directly follow from that construction, since isogenies do not offer as rich an algebraic structure. Specifically, our protocol does not fit into thelinear identification protocolabstraction introduced by Hauck, Kiltz, and Loss (EUROCYRPT’19), which was used to generically construct Schnorr-like blind signatures based on modules such as classical groups and lattices. Consequently, our scheme is provably secure in the random oracle model (ROM) against poly-logarithmically-many concurrent sessions assuming the subexponential hardness of the group action inverse problem. In more detail, our blind signature exploits thequadratic twistof an elliptic curve in an essential way to endow isogenies with a strictly richer structure than abstract group actions (but still more restrictive than modules). The basic scheme has public key size 128 B and signature size 8 KB under the CSIDH-512 parameter sets—these are the smallest among all provably secure post-quantum secure blind signatures. Relying on a newringvariant of the group action inverse problem ( $$\textsf{rGAIP}$$ rGAIP ), we can halve the signature size to 4 KB while increasing the public key size to 512 B. We provide preliminary cryptanalysis of $${\textsf{rGAIP}} $$ rGAIP and show that for certain parameter settings, it is essentially as secure as the standard $$\textsf{GAIP}$$ GAIP . Finally, we show a novel way to turn our blind signature into a partially blind signature, where we deviate from prior methods since they require hashing into the set of public keys while hiding the corresponding secret key—constructing such a hash function in the isogeny setting remains an open problem. Shuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow |
Des. Codes Cryptogr. | 1 |
| 2024 | Compact NIZKs from Standard Assumptions on Bilinear Maps
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
J. Cryptol. | 1 |
| 2023 | Practical Round-Optimal Blind Signatures in the ROM from Standard Assumptions
Shuichi Katsumata, Michael Reichle, Yusuke Sakai 0001 |
ASIACRYPT (2) | 1 |
| 2023 | CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a Twist
Shuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow |
CRYPTO (3) | 1 |
| 2023 | Signature for Objects: Formalizing How to Authenticate Physical Data and More
Ryuya Hayashi, Taiki Asano, Junichiro Hayata, Takahiro Matsuda 0002, Shota Yamada 0001, Shuichi Katsumata, Yusuke Sakai 0001, Tadanori Teruya, Jacob C. N. Schuldt, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Tsutomu Matsumoto |
FC (1) | 6 |
| 2023 | Group signatures and more from isogenies and lattices: generic, simple, and efficientabstractAbstract We construct an efficient dynamic group signature (or more generally an accountable ring signature) from isogeny and lattice assumptions. Our group signature is based on a simple generic construction that can be instantiated by cryptographically hard group actions such as the CSIDH group action or an MLWE-based group action. The signature is of size $$O(\log N)$$ O ( log N ) , where N is the number of users in the group. Our idea builds on the recent efficient OR-proof by Beullens, Katsumata, and Pintore (Asiacrypt’20), where we efficiently add a proof of valid ciphertext to their OR-proof and further show that the resulting non-interactive zero-knowledge proof system is online extractable . Our group signatures satisfy more ideal security properties compared to previously known constructions, while simultaneously having an attractive signature size. The signature size of our isogeny-based construction is an order of magnitude smaller than all previously known post-quantum group signatures (e.g., 6.6 KB for 64 members). In comparison, our lattice-based construction has a larger signature size (e.g., either 126 KB or 89 KB for 64 members depending on the satisfied security property). However, since the $$O(\cdot )$$ O ( · ) -notation hides a very small constant factor, it remains small even for very large group sizes, say $$2^{20}$$ 2 20 . Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai, Federico Pintore |
Des. Codes Cryptogr. | 3 |
| 2023 | Direct computation of branching programs and its applications to more efficient lattice-based cryptography
Shuichi Katsumata, Toi Tomita, Shota Yamada 0001 |
Des. Codes Cryptogr. | 1 |
| 2022 | How to Hide MetaData in MLS-Like Secure Group Messaging: Simple, Modular, and Post-QuantumabstractSecure group messaging (SGM) protocols allow large groups of users to communicate in a secure and asynchronous manner. In recent years, continuous group key agreements (CGKAs) have provided a powerful abstraction to reason on the security properties we expect from SGM protocols. While robust techniques have been developed to protect the contents of conversations in this context, it is in general more challenging to protect metadata (e.g. the identity and social relationships of group members), since their knowledge is often needed by the server in order to ensure the proper function of the SGM protocol. Keitaro Hashimoto, Shuichi Katsumata, Thomas Prest |
CCS | 2 |
| 2022 | A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor Sampling
Rafaël Del Pino, Shuichi Katsumata |
CRYPTO (2) | 2 |
| 2022 | Group Signatures and More from Isogenies and Lattices: Generic, Simple, and Efficient
Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai, Federico Pintore |
EUROCRYPT (2) | 3 |
| 2022 | An Efficient and Generic Construction for Signal's Handshake (X3DH): Post-quantum, State Leakage Secure, and Deniable
Keitaro Hashimoto, Shuichi Katsumata, Kris Kwiatkowski, Thomas Prest |
J. Cryptol. | 2 |
| 2022 | Identity-based encryption with security against the KGC: A formal model and its instantiationsabstractThe key escrow problem is one of the main barriers to the widespread real-world use of identity-based encryption (IBE). Specifically, a key generation center (KGC), which generates secret keys for a given identity, has the power to decrypt all ciphertexts. At PKC 2009, Chow defined a notion of security against the KGC, that relies on assuming that it cannot discover the underlying identities behind ciphertexts. However, this is not a realistic assumption since, in practice, the KGC manages an identity list, and hence it can easily guess the identities corresponding to given ciphertexts. Chow later amended this issue by introducing a new entity called an identity-certifying authority (ICA) and proposed an anonymous key-issuing protocol. Essentially, this allows the users, KGC, and ICA to interactively generate secret keys without users ever having to reveal their identities to the KGC. Unfortunately, since Chow separately defined the security of IBE and that of the anonymous key-issuing protocol, his IBE definition did not provide any formal treatment when the ICA is used to authenticate the users. Effectively, all of the subsequent works following Chow lack the formal proofs needed to determine whether or not it delivers a secure solution to the key escrow problem. In this paper, based on Chow's work, we formally define an IBE scheme that resolves the key escrow problem and provide formal definitions of security against corrupted users, KGC, and ICA. Along the way, we observe that if we are allowed to assume a fully trusted ICA, as in Chow's work, then we can construct a trivial (and meaningless) IBE scheme that is secure against the KGC. Finally, we present two instantiations in our new security model: a lattice-based construction based on the Gentry–Peikert–Vaikuntanathan IBE scheme (STOC 2008) and Rückert's lattice-based blind signature scheme (ASIACRYPT 2010), and a pairing-based construction based on the Boneh–Franklin IBE scheme (CRYPTO 2001) and Boldyreva's blind signature scheme (PKC 2003). Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001 |
Theor. Comput. Sci. | 2 |
| 2021 | A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsabstractContinuous group key agreements (CGKAs) are a class of protocols that can provide strong security guarantees to secure group messaging protocols such as Signal and MLS. Protection against device compromise is provided by commit messages: at a regular rate, each group member may refresh their key material by uploading a commit message, which is then downloaded and processed by all the other members. In practice, propagating commit messages dominates the bandwidth consumption of existing CGKAs. Keitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest, Bas Westerbaan |
CCS | 2 |
| 2021 | Revisiting Fuzzy Signatures: Towards a More Risk-Free Cryptographic Authentication System based on BiometricsabstractBiometric authentication is one of the promising alternatives to standard password-based authentication offering better usability and security. In this work, we revisit the biometric authentication based on fuzzy signatures introduced by Takahashi et al. (ACNS'15, IJIS'19). These are special types of digital signatures where the secret signing key can be a ''fuzzy'' data such as user's biometrics. Compared to other cryptographically secure biometric authentications as those relying on fuzzy extractors, the fuzzy signature-based scheme provides a more attractive security guarantee. However, despite their potential values, fuzzy signatures have not attracted much attention owing to their theory-oriented presentations in all prior works. For instance, the discussion on the practical feasibility of the assumptions (such as the entropy of user biometrics), which the security of fuzzy signatures hinges on, is completely missing. Shuichi Katsumata, Takahiro Matsuda 0002, Wataru Nakamura, Kazuma Ohara, Kenta Takahashi |
CCS | 1 |
| 2021 | A New Simple Technique to Bootstrap Various Lattice Zero-Knowledge Proofs to QROM Secure NIZKs
Shuichi Katsumata |
CRYPTO (2) | 1 |
| 2021 | Round-Optimal Blind Signatures in the Plain Model from Classical and Quantum Standard Assumptions
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
EUROCRYPT (1) | 1 |
| 2021 | Statistical ZAPs from Group-Based Assumptions
Geoffroy Couteau, Shuichi Katsumata, Elahe Sadeghi, Bogdan Ursu |
TCC (1) | 2 |
| 2021 | Compact Designated Verifier NIZKs from the CDH Assumption Without Pairings
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
J. Cryptol. | 1 |
| 2021 | Tighter Security Proofs for GPV-IBE in the Quantum Random Oracle Model
Shuichi Katsumata, Shota Yamada 0001, Takashi Yamakawa |
J. Cryptol. | 1 |
| 2020 | Calamari and Falafl: Logarithmic (Linkable) Ring Signatures from Isogenies and Lattices
Ward Beullens, Shuichi Katsumata, Federico Pintore |
ASIACRYPT (2) | 2 |
| 2020 | Scalable Ciphertext Compression Techniques for Post-quantum KEMs and Their Applications
Shuichi Katsumata, Kris Kwiatkowski, Federico Pintore, Thomas Prest |
ASIACRYPT (1) | 1 |
| 2020 | Adaptively Secure Inner Product Encryption from LWE
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
ASIACRYPT (3) | 1 |
| 2020 | Adaptively Secure Constrained Pseudorandom Functions in the Standard Model
Alex Davidson, Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
CRYPTO (1) | 2 |
| 2020 | Non-interactive Zero-Knowledge in Pairing-Free Groups from Weaker Assumptions
Geoffroy Couteau, Shuichi Katsumata, Bogdan Ursu |
EUROCRYPT (3) | 2 |
| 2020 | Compact NIZKs from Standard Assumptions on Bilinear Maps
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
EUROCRYPT (3) | 1 |
| 2020 | Exposing Private User Behaviors of Collaborative Filtering via Model Inversion TechniquesabstractAbstract Privacy risks of collaborative filtering (CF) have been widely studied. The current state-of-theart inference attack on user behaviors (e.g., ratings/purchases on sensitive items) for CF is by Calandrino et al. (S&P, 2011). They showed that if an adversary obtained a moderate amount of user’s public behavior before some timeT, she can infer user’s private behavioraftertimeT. However, the existence of an attack that infers user’s private behaviorbefore Tremains open. In this paper, we propose the first inference attack that reveals past private user behaviors. Our attack departs from previous techniques and is based onmodel inversion(MI). In particular, we propose the first MI attack on factorization-based CF systems by leveraging data poisoning by Li et al. (NIPS, 2016) in a novel way. We inject malicious users into the CF system so that adversarialy chosen “decoy” items are linked with user’s private behaviors. We also show how to weaken the assumption made by Li et al. on the information available to the adversary from the whole rating matrix to only the item profile and how to create malicious ratings effectively. We validate the effectiveness of our inference algorithm using two real-world datasets. Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka |
Proc. Priv. Enhancing Technol. | 3 |
| 2020 | Lattice-based revocable (hierarchical) IBE with decryption key exposure resistance
Shuichi Katsumata, Takahiro Matsuda 0002, Atsushi Takayasu |
Theor. Comput. Sci. | 1 |
| 2019 | Exploring Constructions of Compact NIZKs from Various Assumptions
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
CRYPTO (3) | 1 |
| 2019 | Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001 |
ESORICS (2) | 2 |
| 2019 | Group Signatures Without NIZK: From Lattices in the Standard Model
Shuichi Katsumata, Shota Yamada 0001 |
EUROCRYPT (3) | 1 |
| 2019 | Designated Verifier/Prover and Preprocessing NIZKs from Diffie-Hellman Assumptions
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
EUROCRYPT (2) | 1 |
| 2018 | Attribute-Based Signatures for Unbounded Languages from Standard Assumptions
Yusuke Sakai 0001, Shuichi Katsumata, Nuttapong Attrapadung, Goichiro Hanaoka |
ASIACRYPT (2) | 2 |
| 2018 | Tighter Security Proofs for GPV-IBE in the Quantum Random Oracle Model
Shuichi Katsumata, Shota Yamada 0001, Takashi Yamakawa |
ASIACRYPT (2) | 1 |
| 2017 | On the Untapped Potential of Encoding Predicates by Arithmetic Circuits and Their Applications
Shuichi Katsumata |
ASIACRYPT (3) | 1 |
| 2017 | Model Inversion Attacks for Prediction Systems: Without Knowledge of Non-Sensitive AttributesabstractWhile online services based on machine learning (ML) have been attracting considerable attention in both academic and business, privacy issues are becoming a threat that cannot be ignored. Recently, Fredrikson et al. [USENIX 2014] proposed a new paradigm of model inversion attacks, which allows an adversary to expose the sensitive information of users by using an ML system for an unintended purpose. In particular, the attack reveals the sensitive attribute values of the target user by using their non-sensitive attributes and the output of the ML model. Here, for the attack to succeed, the adversary needs to possess the non-sensitive attribute values of the target user prior to the attack. However, in reality, even if this information (i.e., non-sensitive attributes) is not necessarily information the user regards as sensitive, it may be difficult for the adversary to actually acquire it. In this paper, we propose a general model inversion (GMI) framework to capture the above scenario where knowledge of the non-sensitive attributes is not necessarily provided. Here, our framework also captures the scenario of Fredrikson et al. Notably, we generalize the paradigm of Fredrikson et al. by additionally modeling the amount of auxiliary information the adversary possesses at the time of the attack. Our proposed GMI framework enables a new type of model inversion attack for prediction systems, which can be carried out without knowledge of the non-sensitive attributes. At a high level, we use the paradigm of data poisoning in a novel way and inject malicious data into the set of training data to modify the ML model into a target ML model, which we can attack without having to have knowledge of the non-sensitive attributes. Our new attack enables the inference of sensitive attributes in the user input from only the output of the ML model, even when the non-sensitive attributes of the user are not available to the adversary. Finally, we provide a concrete algorithm of our model inversion attack on prediction systems based on linear regression models, and give a detailed description of how the data poisoning algorithm is constructed.We evaluate the performance of our new model inversion attack without the knowledge of non-sensitive attributes through experiments with actual data sets. Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka |
PST | 3 |
| 2016 | Partitioning via Non-linear Polynomial Functions: More Compact IBEs from Ideal Lattices and Bilinear Maps
Shuichi Katsumata, Shota Yamada 0001 |
ASIACRYPT (2) | 1 |
| 2015 | Robust Cost Sensitive Support Vector MachineabstractIn this paper we consider robust classifications and show equivalence between the regularized classifications. In general, robust classifications are used to create a classifier robust to data by taking into account the uncertainty of the data. Our result shows that regularized classifications inherit robustness and provide reason on why some regularized classifications tend to be robust against data. Although most robust classification problems assume that every uncertain data lie within an identical bounded set, this paper considers a generalized model where the sizes of the bounded sets are different for each data. These models can be transformed into regularized classification models where the penalties for each data are assigned according to their losses. We see that considering such models opens up for new applications. For an example, we show that this robust classification technique can be used for Imbalanced Data Learning. We conducted experimentation with actual data and compared it with other IDL algorithms such as Cost Sensitive SVMs. This is a novel usage for the robust classification scheme and encourages it to be a suitable candidate for imbalanced data learning. Shuichi Katsumata, Akiko Takeda |
AISTATS | 1 |
| 2014 | Constructing Subspace Membership Encryption through Inner Product Encryption
Shuichi Katsumata, Noboru Kunihiro |
ProvSec | 1 |