EDBT 2026 Demo / reviewers in the wild / expert
Keita Xagawa
dblp:17/5868
· DBLP profile ↗
35ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0002-6832-9940ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 7 first-author · 10 since 2021Theory of computation · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Strong existential unforgeability and BUFF securities of MPC-in-the-head signatures
Mukul Kulkarni, Keita Xagawa |
Des. Codes Cryptogr. | 2 |
| 2025 | The Security of ML-DSA Against Fault-Injection Attacks
Haruhisa Kosuge, Keita Xagawa |
ASIACRYPT (2) | 2 |
| 2025 | The Security of Hash-and-Sign with Retry Against Superposition Attacks
Haruhisa Kosuge, Keita Xagawa |
PKC (1) | 2 |
| 2025 | Post-Quantum Cryptographic Analysis of SSHabstractThe Secure Shell (SSH) protocol is one of the first security protocols on the Internet to upgrade itself to resist attacks against future quantum computers, with the default adoption of the “quantum (otherwise, classically)” secure hybrid key exchange in OpenSSH from April 2022. However, there is a lack of a comprehensive security analysis of this quantum-resistant version of SSH in the literature: related works either focus on the hybrid key exchange in isolation and do not consider security of the overall protocol, or analyze the protocol in security models which are not appropriate for SSH, especially in the “post-quantum” setting. In this paper, we remedy the state of affairs by providing a thorough post-quantum cryptographic analysis of SSH. We follow a “top-down” approach wherein we first prove security of SSH in a more appropriate model, namely, our post-quantum extension of the so-called authenticated and confidential channel establishment (ACCE) protocol security model; our extension which captures “harvest now, decrypt later” attacks could be of independent interest. Then we establish the cryptographic properties of SSH's underlying primitives, as concretely instantiated in practice, based on our protocol-level ACCE security analysis: for example, we prove relevant cryptographic properties of “Streamlined NTRU Prime”, a key encapsulation mechanism (KEM) which is used in recent versions of OpenSSH and TinySSH, in the quantum random oracle model, and address open problems related to its analysis in the literature. Notably, our ACCE security analysis of post-quantum SSH relies on the weaker notion of IND-CPA security of the ephemeral KEMs used in the hybrid key exchange. This is in contrast to prior works which rely on the stronger assumption of IND-CCA secure ephemeral KEMs. Hence we conclude the paper with a discussion on potentially replacing IND-CCA secure KEMs in current post-quantum implementations of SSH with simpler and faster IND-CPA secure counterparts, and also provide the corresponding benchmarks. Benjamin Bencina, Benjamin Dowling, Varun Maram, Keita Xagawa |
SP | 4 |
| 2024 | Signatures with Memory-Tight Security in the Quantum Random Oracle Model
Keita Xagawa |
EUROCRYPT (6) | 1 |
| 2024 | Chameleon Hashing Security Enhancement to Hierarchical Identity-Based IdentificationabstractThis paper examines a security enhancement technique from a passively secure hierarchical identity-based identification (HIBI) protocol to a concurrently secure one. Two types of security enhancement techniques for the identification protocols have been proposed: one based on the OR-proof technique and the other using a chameleon hash function. The former has been examined in detail, while the latter has not been formulated in the HIBI protocol, and its close evaluation of applicability, especially in identity-selecting settings, and reduction efficiency has not been made public. We describe a transformation using a chameleon hash function and compare it with the others based on the OR-proof technique in applicability and reduction efficiency. Atsushi Fujioka, Keisuke Saito, Taiichi Saito, Keita Xagawa |
ISITA | 4 |
| 2022 | Anonymity of NIST PQC Round 3 KEMs
Keita Xagawa |
EUROCRYPT (3) | 1 |
| 2022 | Cryptanalysis of Boyen's attribute-based encryption scheme in TCC 2013
Shweta Agrawal 0001, Rajarshi Biswas, Ryo Nishimaki, Keita Xagawa, Shota Yamada 0001 |
Des. Codes Cryptogr. | 4 |
| 2021 | Fault-Injection Attacks Against NIST's Post-Quantum Cryptography Round 3 KEM Candidates
Keita Xagawa, Akira Ito 0002, Rei Ueno, Junko Takahashi, Naofumi Homma |
ASIACRYPT (2) | 1 |
| 2021 | The Boneh-Katz Transformation, Revisited: Pseudorandom/Obliviously-Samplable PKE from Lattices and Codes and Its Application
Keita Xagawa |
SAC | 1 |
| 2020 | Non-committing Encryption with Constant Ciphertext Expansion from Standard Assumptions
Yusuke Yoshida, Fuyuki Kitagawa, Keita Xagawa, Keisuke Tanaka |
ASIACRYPT (2) | 3 |
| 2020 | ModFalcon: Compact Signatures Based On Module-NTRU LatticesabstractLattices lead to promising practical post-quantum digital signatures, combining asymptotic efficiency with strong theoretical security guarantees. However, tuning their parameters into practical instantiations is a delicate task. On the one hand, NIST round~2 candidates based on Lyubashevsky's design (such as dilithium and qtesla) allow several tradeoffs between security and efficiency, but at the expense of a large bandwidth consumption. On the other hand, the hash-and-sign falcon signature is much more compact and is still very efficient, but it allows only two security levels, with large compactness and security gaps between them. We introduce a new family of signature schemes based on the falcon design, which relies on module lattices. Our concrete instantiation enjoys the compactness and efficiency of falcon, and allows an intermediate security level. It leads to the most compact lattice-based signature achieving a quantum security above 128 bits. Chitchanok Chuengsatiansup, Thomas Prest, Damien Stehlé, Alexandre Wallet, Keita Xagawa |
AsiaCCS | 5 |
| 2020 | Post-quantum Provably-Secure Authentication and MAC from Mersenne Primes
Houda Ferradi, Keita Xagawa |
CT-RSA | 2 |
| 2020 | Cryptanalysis of a rank-based signature with short public keys
Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Terry Shue Chien Lau, Chik How Tan, Keita Xagawa |
Des. Codes Cryptogr. | 7 |
| 2020 | Quantum algorithm for the multicollision problem
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa |
Theor. Comput. Sci. | 4 |
| 2019 | Quantum Random Oracle Model with Auxiliary Input
Minki Hhan, Keita Xagawa, Takashi Yamakawa |
ASIACRYPT (1) | 2 |
| 2019 | Improved Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Seiichiro Tani, Keita Xagawa |
PQCrypto | 4 |
| 2019 | (Tightly) QCCA-Secure Key-Encapsulation Mechanism in the Quantum Random Oracle Model
Keita Xagawa, Takashi Yamakawa |
PQCrypto | 1 |
| 2018 | Cryptanalysis of Compact-LWE
Jonathan Bootle, Mehdi Tibouchi, Keita Xagawa |
CT-RSA | 3 |
| 2018 | Tightly-Secure Key-Encapsulation Mechanism in the Quantum Random Oracle Model
Tsunekazu Saito, Keita Xagawa, Takashi Yamakawa |
EUROCRYPT (3) | 2 |
| 2018 | Practical Cryptanalysis of a Public-Key Encryption Scheme Based on Non-linear Indeterminate Equations at SAC 2017
Keita Xagawa |
PQCrypto | 1 |
| 2017 | Quantum Multicollision-Finding Algorithm
Akinori Hosoyamada, Yu Sasaki 0001, Keita Xagawa |
ASIACRYPT (2) | 3 |
| 2017 | Cryptanalysis of Comparable Encryption in SIGMOD'16abstractComparable Encryption proposed by Furukawa (ESORICS 2013, CANS 2014) is a variant of order-preserving encryption (OPE) and order-revealing encryption (ORE); we cannot compare a ciphertext of v and another ciphertext of v', but we can compare a ciphertext of v and a token of b and compare a token of $b$ and another token of b'. Comparable encryption allows us to implement range and point queries while keeping the order of v's as secret as possible. Caleb Horst, Ryo Kikuchi, Keita Xagawa |
SIGMOD Conference | 3 |
| 2016 | Public-Key Cryptosystems Resilient to Continuous Tampering and Leakage of Arbitrary Functions
Eiichiro Fujisaki, Keita Xagawa |
ASIACRYPT (1) | 2 |
| 2015 | Accumulable Optimistic Fair Exchange from Verifiably Encrypted Homomorphic Signatures
Jae Hong Seo, Keita Emura, Keita Xagawa, Kazuki Yoneyama |
ACNS | 3 |
| 2015 | Strongly secure authenticated key exchange from factoring, codes, and lattices
Atsushi Fujioka, Koutarou Suzuki, Keita Xagawa, Kazuki Yoneyama |
Des. Codes Cryptogr. | 3 |
| 2015 | Verifiably encrypted signatures with short keys based on the decisional linear problem and obfuscation for encrypted VES
Ryo Nishimaki, Keita Xagawa |
Des. Codes Cryptogr. | 2 |
| 2013 | Practical and post-quantum authenticated key exchange from one-way secure key encapsulation mechanismabstractThis paper discusses how to realize practical post-quantum authenticated key exchange (AKE) with strong security, i.e., CK+ security (Krawczyk, CRYPTO 2005). It is known that strongly secure post-quantum AKE protocols exist on a generic construction from IND-CCA secure key encapsulation mechanisms (KEMs) in the standard model. Atsushi Fujioka, Koutarou Suzuki, Keita Xagawa, Kazuki Yoneyama |
AsiaCCS | 3 |
| 2012 | Security Enhancements by OR-Proof in Identity-Based Identification
Atsushi Fujioka, Taiichi Saito, Keita Xagawa |
ACNS | 3 |
| 2012 | Applicability of OR-Proof Techniques to Hierarchical Identity-Based Identification
Atsushi Fujioka, Taiichi Saito, Keita Xagawa |
CANS | 3 |
| 2012 | Security Enhancement of Identity-Based Identification with Reversibility
Atsushi Fujioka, Taiichi Saito, Keita Xagawa |
ICICS | 3 |
| 2012 | Secure Hierarchical Identity-Based Identification without Random Oracles
Atsushi Fujioka, Taiichi Saito, Keita Xagawa |
ISC | 3 |
| 2009 | Efficient Public Key Encryption Based on Ideal Lattices
Damien Stehlé, Ron Steinfeld, Keisuke Tanaka, Keita Xagawa |
ASIACRYPT | 4 |
| 2009 | Zero-Knowledge Protocols for NTRU: Application to Identification and Proof of Plaintext Knowledge
Keita Xagawa, Keisuke Tanaka |
ProvSec | 1 |
| 2008 | Concurrently Secure Identification Schemes Based on the Worst-Case Hardness of Lattice Problems
Akinori Kawachi, Keisuke Tanaka, Keita Xagawa |
ASIACRYPT | 3 |