Olivier Blazy

dblp:24/8243 · DBLP profile ↗
← Back
43ranked-venue papers
27as first author
13since 2021 · last 2026
0000-0001-6205-8249ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 36 · 25 first-author · 10 since 2021Theory of computation · 5 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Computer networks · 1
YearPublicationVenuePosition
2026 Sanitizable Signatures with Different Admissibility Policies for Multiple Sanitizers
abstract
Sanitizable signatures authorize semi-trusted sanitizers to modify admissible blocks of a signed message. Most works consider only one sanitizer while those considering multiple sanitizers are limited by their capacity to manage admissible blocks which must be the same for all of them. We study the case where different sanitizers with different roles can be trusted to modify different blocks of the message. We define a model for multi-sanitizer sanitizable signatures which allow managing authorization for each sanitizer independently. We also provide formal definitions of its security properties. We propose two secure generic constructions FSV-k-SAN and IUT-k-SAN with different security properties. We implement both constructions and evaluate their performance on a server and a smartphone.
Osama Allabwani, Olivier Blazy, Pascal Lafourcade 0001, Charles Olivier-Anclin, Olivier Raynaud
AsiaCCS2
2024 A Public Key Identity-Based Revocation Scheme: - Fully Attribute-Hiding and Function Private
Olivier Blazy, Sayantan Mukherjee
CT-RSA1
2023 Efficient Implementation of a Post-Quantum Anonymous Credential Protocol
abstract
Authentication on the Internet usually has the drawback of leaking the identity of the users, or at least allowing to trace them from a server to another. Anonymous credentials overcome this issue, by allowing users to reveal the attributes necessary for the authentication, without revealing any other information (in particular not their identity). In this article, we provide a generic framework to construct anonymous credential schemes and use it to give a concrete construction of post-quantum (lattice-based) anonymous credential protocol. Our protocol thus allows for long-term security even when one considers the emergence of quantum computers able to break widely used traditional computational assumptions, such as RSA, the discrete logarithm or Diffie-Hellman. We also give a concrete implementation of our protocol, which is only one order of magnitude slower and bandwidth consuming than previous anonymous credentials that are not post-quantum.
Olivier Blazy, Céline Chevalier, Guillaume Renaut, Thomas Ricosset, Éric Sageloli, Hugo Senet
ARES1
2023 Dually Computable Cryptographic Accumulators and Their Application to Attribute Based Encryption
Anaïs Barthoulot, Olivier Blazy, Sébastien Canard
CANS2
2023 How fast do you heal? A taxonomy for post-compromise security in secure-channel establishment
Olivier Blazy, Ioana Boureanu, Pascal Lafourcade 0001, Cristina Onete, Léo Robert
USENIX Security Symposium1
2022 (Augmented) Broadcast Encryption from Identity Based Encryption with Wildcard
Anaïs Barthoulot, Olivier Blazy, Sébastien Canard
CANS2
2022 A gapless code-based hash proof system based on RQC and its applications
Slim Bettaieb, Loïc Bidoux, Olivier Blazy, Yann Connan 0001, Philippe Gaborit
Des. Codes Cryptogr.3
2022 Ouroboros: An Efficient and Provably Secure KEM Family
abstract
In this paper we introduce Ouroboros, a new family of Key Exchange protocols based on coding theory. The protocols propose a middle ground between the cryptosystems based on$\mathsf {QC}$-$\mathsf {MDPC}$codes, which feature small parameter sizes, but have a security reduction to two problems: the syndrome decoding problem and the indistinguishability of the code, and the HQC protocol, which features bigger parameters but has a security reduction to the syndrome decoding problem only. Ouroboros features a reduction to the syndrome decoding problem with only a small overhead compared to the$\mathsf {QC}$-$\mathsf {MDPC}$based cryptosystems. The approach is based on an ideal structure and also works for the rank metric. This yields a simple, secure and efficient approach for key exchange, the Ouroboros family of protocols. For the Hamming metric we obtain the same type of parameters (and almost the same simple decoding) as for$\mathsf {MDPC}$based cryptosystems, but with a security reduction to decoding random quasi-cyclic codes in the Random Oracle Model. This represents a reduction of up to 38% on the public key size compared to HQC, for the most secure parameters. For the rank metric, we obtain better parameters than for RQC, saving up to 31% on the public key for the most secure set of parameters, using non homogeneous errors in Ouroboros. In this full version, the protocol and decoding algorithm have been slightly improved, additional details are given in the security proof, and the protocol is fully described for the rank metric.
Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Gilles Zémor
IEEE Trans. Inf. Theory2
2021 Secure Decision Forest Evaluation
abstract
Decision forests are classical models to efficiently make decision on complex inputs with multiple features. While the global structure of the trees or forests is public, sensitive information have to be protected during the evaluation of some client inputs with respect to some server model. Indeed, the comparison thresholds on the server side may have economical value while the client inputs might be critical personal data. In addition, soundness is also important for the receiver. In our case, we will consider the server to be interested in the outcome of the model evaluation so that the client should not be able to bias it. In this paper, we propose a new offline/online protocol between a client and a server with a constant number of rounds in the online phase, with both privacy and soundness against malicious clients.
Slim Bettaieb, Loïc Bidoux, Olivier Blazy, Baptiste Cottier, David Pointcheval
ARES3
2021 An Anonymous Trace-and-Revoke Broadcast Encryption Scheme
Olivier Blazy, Sayantan Mukherjee, Duong Hieu Phan, Damien Stehlé
ACISP1
2021 How to (Legally) Keep Secrets from Mobile Operators
Ghada Arfaoui, Olivier Blazy, Xavier Bultel, Pierre-Alain Fouque, Thibaut Jacques, Adina Nedelcu, Cristina Onete
ESORICS (1)2
2021 Zero-Knowledge Reparation of the Véron and AGS Code-based Identification Schemes
abstract
Designing code-based signatures is both an important and challenging problem. A standard way to tackle it consists to use the Fiat-Shamir heuristic along with an identification scheme that is required to be zero-knowledge. The authors of [1] have highlighted an issue within the zero-knowledge proof of the Veron identification scheme [2]. It turns out that the zero-knowledge proof of the AGS protocol [3] is impacted in a similar way. In this paper, we present a masking technique that solves the aforementioned issue without inducing any performance penalty. We introduce the Masked Veron and Masked AGS protocols that both leverage this masking technique and provide their zero-knowledge proofs. In addition, we present a new technique improving the performances of signatures built from code-based identification schemes subject to the attack described in [4]. The Masked Veron and Masked AGS protocols feature all the existing performance improvements from the literature.
Slim Bettaieb, Loïc Bidoux, Olivier Blazy, Philippe Gaborit
ISIT3
2021 Hardware security without secure hardware: How to decrypt with a password and a server
Olivier Blazy, Laura Brouilhet, Céline Chevalier, Patrick Towa, Ida Tucker, Damien Vergnaud
Theor. Comput. Sci.1
2020 Public-Key Generation with Verifiable Randomness
Olivier Blazy, Patrick Towa, Damien Vergnaud
ASIACRYPT (1)1
2020 Cryptanalysis of a rank-based signature with short public keys
Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Terry Shue Chien Lau, Chik How Tan, Keita Xagawa
Des. Codes Cryptogr.2
2020 New efficient M2C and M2M mutual authentication protocols for IoT-based healthcare applications
Fatma Merabet, Amina Cherif, Malika Belkadi, Olivier Blazy, Emmanuel Conchon, Damien Sauveron
Peer-to-Peer Netw. Appl.4
2019 Anonymous Identity Based Encryption with Traceable Identities
abstract
We introduce Anonymous Identity Based Encryption with Traceable Identities, in which we provide a new feature to anonymous identity-based encryption schemes: lifting the anonymity of some specific recipients in necessary situations (such as when they are suspected as criminals). Our primitive allows a tracer, given a tracing key associated to an identity, to filter all the ciphertexts that are sent to this specific identity (and only those). As it is primordial to preserve the privacy of the law-abiding users, the security takes into account the collusion of tracers and corrupted users.
Olivier Blazy, Laura Brouilhet, Duong Hieu Phan
ARES1
2019 Post-Quantum UC-Secure Oblivious Transfer in the Standard Model with Adaptive Corruptions
abstract
Since the seminal result of Kilian, Oblivious Transfer (OT) has proven to be a fundamental primitive in cryptography. In such a scheme, a user is able to gain access to an element owned by a server, without learning more than this single element, and without the server learning which element the user has accessed. The NIST call for post-quantum encryption and signature schemes has revived the interest for cryptographic protocols based on post-quantum assumptions and the need for secure post-quantum OT schemes. In this paper, we show how to construct an OT scheme based on lattices, from a collision-resistant chameleon hash scheme (CH) and a CCA encryption scheme accepting a smooth projective hash function (SPHF). Note that our scheme does not rely on random oracles and provides UC security against adaptive corruptions assuming reliable erasures.
Olivier Blazy, Céline Chevalier, Quoc-Huy Vu
ARES1
2019 Downgradable Identity-Based Encryption and Applications
Olivier Blazy, Paul Germouty, Duong Hieu Phan
CT-RSA1
2019 Durandal: A Rank Metric Based Signature Scheme
Nicolas Aragon, Olivier Blazy, Philippe Gaborit, Adrien Hauteville, Gilles Zémor
EUROCRYPT (3)2
2019 SAID: Reshaping Signal into an Identity-Based Asynchronous Messaging Protocol with Authenticated Ratcheting
abstract
As messaging applications are becoming increasingly popular, it is of utmost importance to analyze their security and mitigate existing weaknesses. This paper focuses on one of the most acclaimed messaging applications: Signal. Signal is a protocol that provides end-to-end channel security, forward secrecy, and post-compromise security. These features are achieved thanks to a key-ratcheting mechanism that updates the key material at every message. Due to its high security impact, Signal's key-ratcheting has recently been formalized, along with an analysis of its security. In this paper, we revisit Signal, describing some attacks against the original design and proposing SAID: Signal Authenticated and IDentity-based. As the name indicates, our protocol relies on an identity-based setup, which allows us to dispense with Signal's centralized server. We use the identity-based long-term secrets to obtain persistent and explicit authentication, such that SAID achieves higher security guarantees than Signal. We prove the security of SAID not only in the Authenticated Key Exchange (AKE) model (as done by previous work), but also in the Authenticated and Confidential Channel Establishment (ACCE) model, which we adapted and redefined for SAID and asynchronous messaging protocols in general into a model we call identity-based Multistage Asynchronous Messaging (iMAM). We believe our model to be more faithful in particular to the true security of Signal, whose use of the message keys prevents them from achieving the composable guarantee claimed by previous analysis.
Olivier Blazy, Angèle Bossuat, Xavier Bultel, Pierre-Alain Fouque, Cristina Onete, Elena Pagnin
EuroS&P1
2018 Non-Interactive Key Exchange from Identity-Based Encryption
abstract
Since the seminal work of Diffie and Hellman [19], Non-Interactive Key Exchange (NIKE) has become one of the fundamental problems of modern cryptography, but additional security requirements have led to elaborated ad-hoc constructions, which often lack simplicity in their design. In particular, Identity-Based NIKE is still a major problem with few available constructions, and those ad-hoc constructions do not give a lot of insight on what is required to be able to achieve such a NIKE scheme only based on the identity (and not relying on the public-key setting).
Olivier Blazy, Céline Chevalier
ARES1
2018 Spreading Alerts Quietly: New Insights from Theory and Practice
abstract
With the emergence of the Internet of things and of electronic home health-care, more and more sensitive signals are transiting over easily accessible wireless networks. It has become an important task to manage to spread alerts on a wireless network at the same time as to hide the nature of these signals, in a secure and efficient way. No one (an adversarial observer or even the node transmitting the signal) should be able to learn whether a signal corresponds to an alert or a normal echo. Blind Coupon Mechanism is a primitive proposed at Asiacrypt 2005 that allows to spread such alerts quietly and quickly. In this paper, we propose to strengthen their security model and we give a concrete solution which is both more secure and more efficient than the protocol originally proposed.
Olivier Blazy, Céline Chevalier
ARES1
2018 Efficient Encryption From Random Quasi-Cyclic Codes
abstract
We propose a framework for constructing efficient code-based encryption schemes that do not hide any structure in their public matrix. The framework is in the spirit of the schemes first proposed by Alekhnovich in 2003 and based on the difficulty of decoding random linear codes from random errors of low weight. We depart somewhat from Alekhnovich's approach and propose an encryption scheme based on the difficulty of decoding random quasi-cyclic codes. We propose two new cryptosystems instantiated within our framework: the hamming quasi-cyclic cryptosystem (HQC), based on the hamming metric, and the rank quasi-cyclic cryptosystem (RQC), based on the rank metric. We give a security proof, which reduces the indistinguishability under chosen plaintext attack security of our systems to a decision version of the well-known problem of decoding random families of quasi-cyclic codes for the hamming and rank metrics (the respective QCSD and RQCSD problems). We also provide an analysis of the decryption failure probability of our scheme in the Hamming metric case: for the rank metric there is no decryption failure. Our schemes benefit from a very fast decryption algorithm together with small key sizes of only a few thousand bits. The cryptosystems are very efficient for low encryption rates and are very well suited to key exchange and authentication. Asymptotically, for λ the security parameter, the public key sizes are respectively in O(λ2) for HQC and in O(λ 4/3) for RQC. Practical parameter compares well to the systems based on ring-learning parity with noise or the recent moderate density parity check codes system.
Carlos Aguilar Melchor, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Gilles Zémor
IEEE Trans. Inf. Theory2
2017 Efficient ID-based Designated Verifier Signature
abstract
The concept of undeniable signatures has been introduced at Crypto'89 by Chaum and van Antwerpen. It has been revisited several times since, in particular by Jakobsson, Sako and Impagliazzo at Eurocrypt'96 who introduced designated verifier signatures and by Steinfeld, Bull, Wang and Pieprzyk at Asiacrypt'03 who designed universal designated verifier signatures. Behind all those notions lies the idea to produce some kind of signature that can be verified only by a targeted verifier. However the verifier should not be able to convince anyone that the signature is valid. In this paper, we present an efficient way to solve those three problems, under classical assumptions, namely DLin and CDH in the standard model. Once we propose such construction, we generalize our approach to a framework showing how to build efficient ID-based Designated Verifier Signature, in the standard model under classical assumptions.
Olivier Blazy, Emmanuel Conchon, Paul Germouty, Amandine Jambert
ARES1
2017 Almost Optimal Oblivious Transfer from QA-NIZK
Olivier Blazy, Céline Chevalier, Paul Germouty
ACNS1
2017 A code-based blind signature
abstract
In this paper we give the first blind signature protocol for code-based cryptography. Our approach is different from the classical original RSA based blind signature scheme, it is done in the spirit of the Fischlin approach [9] which is based on proofs of knowledge. To achieve our goal we consider a new tool for zero-knowledge (ZK) proofs, the Concatenated Stern ZK protocol, which permits to obtain an authentication protocol for concatenated matrices. A signature is then obtained from the usual Fiat-Shamir heuristic. We describe our blind signature protocol for cryptography based on Hamming metric and show how it can be extended to rank based cryptography. The security of our blind protocol is based on the security of a trapdoor function for the syndrome decoding problem: the CFS signature scheme for Hamming distance and on the more recent RankSign protocol for rank metric. We give proofs in the random oracle model (ROM) for our blind signature scheme, which rely on the Syndrome Decoding problem. The parameters we obtain for our protocol are practical for rank metric (200kBytes) for the signature length and 15kBytes for public key size) and a little less practical for Hamming distance.
Olivier Blazy, Philippe Gaborit, Julien Schrek, Nicolas Sendrier
ISIT1
2017 A code-based group signature scheme
Quentin Alamélou, Olivier Blazy, Stéphane Cauchie, Philippe Gaborit
Des. Codes Cryptogr.2
2016 Structure-Preserving Smooth Projective Hashing
Olivier Blazy, Céline Chevalier
ASIACRYPT (2)1
2016 Adaptive Oblivious Transfer and Generalization
Olivier Blazy, Céline Chevalier, Paul Germouty
ASIACRYPT (2)1
2016 Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions
Olivier Blazy, Céline Chevalier, Damien Vergnaud
CT-RSA1
2016 Non-Interactive Plaintext (In-)Equality Proofs and Group Signatures with Verifiable Controllable Linkability
Olivier Blazy, David Derler, Daniel Slamanig, Raphael Spreitzer
CT-RSA1
2016 Two Secure Anonymous Proxy-based Data Storages
abstract
International audience
Olivier Blazy, Xavier Bultel, Pascal Lafourcade 0001
SECRYPT1
2016 A Practical Group Signature Scheme Based on Rank Metric
Quentin Alamélou, Olivier Blazy, Stéphane Cauchie, Philippe Gaborit
WAIFI2
2015 Generic Construction of UC-Secure Oblivious Transfer
Olivier Blazy, Céline Chevalier
ACNS1
2015 Non-Interactive Zero-Knowledge Proofs of Non-Membership
Olivier Blazy, Céline Chevalier, Damien Vergnaud
CT-RSA1
2014 (Hierarchical) Identity-Based Encryption from Affine Message Authentication
Olivier Blazy, Eike Kiltz, Jiaxin Pan 0001
CRYPTO (1)1
2013 Analysis and Improvement of Lindell's UC-Secure Commitment Schemes
Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
ACNS1
2013 SPHF-Friendly Non-interactive Commitments
Michel Abdalla, Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval
ASIACRYPT (1)3
2013 New Techniques for SPHFs and Efficient One-Round PAKE Protocols
Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
CRYPTO (1)2
2013 Short blind signatures
abstract
Blind signatures allow users to obtain signatures on messages hidden from the signer; moreover, the signer cannot link the resulting message/signature pair to the signing session. This paper presents blind signature schemes, in which the number of interactions between the user and the signer is min imal and whose blind signatures are short. Our schemes are defined over bilinear groups and are proved secure in the common-reference-string model without random oracles and under standard assumptions: CDH and the decision-linear assumption. (We also give variants over asymmetric groups based on similar assumptions.) The blind signatures are Waters signatures, which consist of 2 group elements. Moreover, we instantiate partially blind signatures, where the message consists of a part hidden from the signer and a commonly known public part, and schemes achieving perfect blindness. We propose new variants of blind signatures, such as signer-friendly partially blind signatures, where the public part can be chosen by the signer without prior agreement, 3-party blind signatures, as well as blind signatures on multiple aggregated messages provided by independent sources. We also extend Waters signatures to non-binary alphabets by proving a new result on the underlying hash function.
Olivier Blazy, Georg Fuchsbauer, David Pointcheval, Damien Vergnaud
J. Comput. Secur.1
2012 Round-Optimal Privacy-Preserving Protocols with Smooth Projective Hash Functions
Olivier Blazy, David Pointcheval, Damien Vergnaud
TCC1
2010 Batch Groth-Sahai
Olivier Blazy, Georg Fuchsbauer, Malika Izabachène, Amandine Jambert, Hervé Sibert, Damien Vergnaud
ACNS1