María Isabel González Vasco

dblp:23/2309 · DBLP profile ↗
← Back
21ranked-venue papers
14as first author
5since 2021 · last 2025
0000-0002-7452-9121ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 7 first-author · 4 since 2021Theory of computation · 7 · 6 first-authorDatabases, data management, data science and information retrieval · 3 · 3 first-authorComputer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Anonymous Authenticated Key Exchange
abstract
Abstract Authenticated Key Exchange ( $${\textsf {AKE}}$$ AKE ) can be used in client-server applications for mutual authentication and key establishment. In scenarios where client authentication is neither feasible nor desirable, One-Sided AKE ( $${\textsf {OS-AKE}}$$ OS - AKE ) allows both parties to establish a key while only the server authenticates to the client. Thus, $${\textsf {OS-AKE}}$$ OS - AKE provides client anonymity with respect to the server, but does not allow the server to enforce any form of access control—that is, the server simply establishes a key with any client. In this paper, we introduce Anonymous AKE ( $${\textsf {A-AKE}}$$ A - AKE ) to strike a balance between classical client authentication of $${\textsf {AKE}}$$ AKE and client anonymity of $${\textsf {OS-AKE}}$$ OS - AKE . In a nutshell $${\textsf {A-AKE}}$$ A - AKE is an $${\textsf {AKE}}$$ AKE protocol where (i) the server authenticates to the client, (ii) the server can enforce access control by deciding which clients are authorized to run the key-establishment protocol, (iii) a key is established between the server and the client only if the latter is one of the authorized clients as defined by the server, and (iv) the authorized client remains anonymous (within the set of all authorized clients) with respect to the server. We introduce a security model for $${\textsf {A-AKE}}$$ A - AKE that extends popular $${\textsf {AKE}}$$ AKE models and design a general framework for instantiating $${\textsf {A-AKE}}$$ A - AKE protocols based on well-established cryptographic primitives. Finally, we instantiate several $${\textsf {AKE}}$$ AKE protocols aiming at strong security guarantees in the classical and post-quantum settings. We implement a prototype of each instantiation and provide an experimental comparison of their performance.
José Ignacio Escribano Pablos, María Isabel González Vasco, Angel L. Pérez del Pozo, Claudio Soriente
ACNS (1)2
2023 Modular Sumcheck Proofs with Applications to Machine Learning and Image Processing
abstract
Cryptographic proof systems provide integrity, fairness, and privacy in applications that outsource data processing tasks. However, general-purpose proof systems do not scale well to large inputs. At the same time, ad-hoc solutions for concrete applications - e.g., machine learning or image processing - are more efficient but lack modularity, hence they are hard to extend or to compose with other tools of a data-processing pipeline.
David Balbás, Dario Fiore 0001, María Isabel González Vasco, Damien Robissout, Claudio Soriente
CCS3
2023 Secure post-quantum group key exchange: Implementing a solution based on Kyber
abstract
Abstract Quantum computing poses fascinating challenges for current cryptography, threatening the security of many schemes and protocols widely used today. To adapt to this reality, the U.S. National Institute for Standards and Technology (NIST) is currently running a standardization process in search of post‐quantum (classical, yet resistant to quantum attacks ) cryptographic tools, focusing on signature schemes and key encapsulation mechanisms. Many of the competing proposals also include designs for two‐party key exchange, which can be combined in different ways to fit scenarios involving parties, that is, yielding group key exchange protocols. However, very few implementations of such group protocols are available to practitioners, which face a non‐trivial challenge when deciding how to implement a protocol for establishing secure group sessions in this new post‐quantum scenario. With this in mind, the authors report on the implementation of a secure post‐quantum group key exchange protocol in the so‐called Quantum Random Oracle Model . The protocol decided to implement is based on a KEM called Kyber , which is one of the finalists of the NIST competition. Not only this group construction is the only one available in the literature using a NIST finalist, but also, among all post‐quantum designs the authors are aware of, it uses this strongest security model (as, e.g. in other proposals, the adversarial interaction with the hash functions of the system is assumed to be exclusively classical). Furthermore, experimental evidence is provided supporting this choice in terms of performance, even if the number of involved entities is large (up to 2000). All data and code are publicly available.
José Ignacio Escribano Pablos, María Isabel González Vasco
IET Commun.2
2022 Auditable Asymmetric Password Authenticated Public Key Establishment
Antonio Faonio, María Isabel González Vasco, Claudio Soriente, Hien Thi Thu Truong
CANS2
2021 A Key for John Doe: Modeling and Designing Anonymous Password-Authenticated Key Exchange Protocols
abstract
Anonymous Password-Authenticated Key Exchange (\sf APAKEAPAKE) can be seen as the hybrid offspring of standard key exchange and anonymous password authentication protocols. \sf APAKEAPAKE allows a client holding a low-entropy password to establish a session key with a server, provided that the client's password is in the server's set. Moreover, no information about the password input by the client or the set of valid passwords held by the server should leak to the other party-beyond whether the client's password lies or not in the server's password database. To the best of our knowledge, all \sf APAKEAPAKE proposals to date either assume client storage or force the client to remember the index assigned to its password in the server's database. Furthermore, earlier works either provide only informal definitions or fail in some sense to properly model the primitive. In this paper, we provide a formal security model for \sf APAKEAPAKE, capturing security and anonymity provisions for both clients and servers. In addition, we present two \sf APAKEAPAKE protocols that only require clients to remember a password and that attain our sought key secrecy and anonymity guarantees. Our first protocol leverages oblivious pseudo-random functions, while the second one builds upon a special type of identity-based encryption scheme.
María Isabel González Vasco, Angel L. Pérez del Pozo, Claudio Soriente
IEEE Trans. Dependable Secur. Comput.1
2018 Group key exchange protocols withstanding ephemeral-key reveals
abstract
When a group key exchange protocol is executed, the session key is typically extracted from two types of secrets: long‐term keys (for authentication) and freshly generated (often random) values. The leakage of this latter so‐called ephemeral keys has been extensively analysed in the 2‐party case, yet very few works are concerned with it in the group setting. The authors provide a generic group key exchange construction that is strongly secure, meaning that the attacker is allowed to learn both long‐term and ephemeral keys (but not both from the same participant, as this would trivially disclose the session key). Their design can be seen as a compiler, in the sense that it builds on a 2‐party key exchange protocol which is strongly secure and transforms it into a strongly secure group key exchange protocol by adding only one extra round of communication. When applied to an existing 2‐party protocol from Bergsma et al ., the result is a 2‐round group key exchange protocol which is strongly secure in the standard model, thus yielding the first construction with this property.
María Isabel González Vasco, Angel L. Pérez del Pozo, Adriana Suárez Corona
IET Inf. Secur.1
2017 Partitioned Group Password-Based Authenticated Key Exchange
abstract
Group Password-Based Authenticated Key Exchange (GPAKE) allows a group of users to establish a secret key, as long as all of them share the same password. However, in existing GPAKE protocols as soon as one user runs the protocol with a non-matching password, all the others abort and no key is established. In this paper we seek for a more flexible, yet secure, GPAKE and put forward the notion of partitionedGPAKE. Partitioned GPAKE tolerates users that run the protocol on different passwords. Through a protocol run, any subgroup of users that indeed share a password, establish a session key, factoring out the ‘noise’ of inputs by users holding different passwords. At the same time any two keys, each established by a different subgroup of users, are pair-wise independent if the corresponding subgroups hold different passwords. We also introduce the notion of password-privacy for partitioned GPAKE, which is a kind of affiliation hiding property, ensuring that an adversary should not be able to tell whether any given set of users share a password. Finally, we propose an efficient instantiation of partitioned GPAKE building on an unforgeable symmetric encryption scheme and a PAKE by Bellare et al. Our proposal is proven secure in the random oracle/ideal cipher model, and requires only two communication rounds.
Dario Fiore 0001, María Isabel González Vasco, Claudio Soriente
Comput. J.2
2016 Combined schemes for signature and encryption: The public-key and the identity-based setting
María Isabel González Vasco, Florian Hess, Rainer Steinwandt
Inf. Comput.1
2016 Pitfalls in a server-aided authenticated group key establishment
María Isabel González Vasco, Angel L. Pérez del Pozo, Adriana Suárez Corona
Inf. Sci.1
2014 Cryptanalysis of a key exchange scheme based on block matrices
María Isabel González Vasco, Angel L. Pérez del Pozo, Pedro Taborda Duarte, Jorge Luis Villar
Inf. Sci.1
2010 Anonymous Subscription Schemes - A Flexible Construction for On-line Services Access
María Isabel González Vasco, Somayeh Heidarvand, Jorge Luis Villar
SECRYPT1
2010 A note on the security of MST3
María Isabel González Vasco, Angel L. Pérez del Pozo, Pedro Taborda Duarte
Des. Codes Cryptogr.1
2008 Applications of algebra to cryptography
María Isabel González Vasco, Rainer Steinwandt
Discret. Appl. Math.1
2007 (Password) Authenticated Key Establishment: From 2-Party to Group
Michel Abdalla, Jens-Matthias Bohli, María Isabel González Vasco, Rainer Steinwandt
TCC3
2007 Attacking a public key cryptosystem based on tree replacement
María Isabel González Vasco, David Pérez-García
Discret. Appl. Math.1
2005 A New Cramer-Shoup Like Methodology for Group Based Provably Secure Encryption Schemes
María Isabel González Vasco, Consuelo Martínez, Rainer Steinwandt, Jorge Luis Villar
TCC1
2005 Weak Keys in MST1
Jens-Matthias Bohli, Rainer Steinwandt, María Isabel González Vasco, Consuelo Martínez
Des. Codes Cryptogr.3
2004 On the Security of Two Public Key Cryptosystems Using Non-Abelian Groups
María Isabel González Vasco, Dennis Hofheinz, Consuelo Martínez, Rainer Steinwandt
Des. Codes Cryptogr.1
2004 Towards a Uniform Description of Several Group Based Cryptographic Primitives
María Isabel González Vasco, Consuelo Martínez, Rainer Steinwandt
Des. Codes Cryptogr.1
2002 The Hidden Number Problem in Extension Fields and Its Applications
María Isabel González Vasco, Mats Näslund, Igor E. Shparlinski
LATIN1
2001 Clouds over a public key cryptosystem based on Lyndon words
María Isabel González Vasco, Rainer Steinwandt
Inf. Process. Lett.1