Yi-Fu Lai

dblp:273/4679 · DBLP profile ↗
← Back
11ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0002-1346-9372ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 1 first-author · 11 since 2021
YearPublicationVenuePosition
2026 A Little LESS Secure - Side-Channel Attacks Exploiting Randomness Leakage
Dina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas Meers
CRYPTO (7)3
2026 Post-Quantum Blind Signature from Standard Group Action Assumptions and More
Lucjan Hanzlik, Yi-Fu Lai, Eugenio Paracucchi, Edoardo Persichetti
EUROCRYPT (1)2
2026 PIKE: Faster Isogeny-Based Public Key Encryption with Pairing-Assisted Decryption
Shiping Cai, Yi-Fu Lai, Kaizhan Lin
PKC (3)3
2025 Tanuki: New Frameworks for (Concurrently Secure) Blind Signatures from Post-Quantum Group Actions
Lucjan Hanzlik, Yi-Fu Lai, Marzio Mula, Eugenio Paracucchi, Daniel Slamanig
ASIACRYPT (4)2
2024 CSI-Otter: isogeny-based (partially) blind signatures from the class group action with a twist
abstract
Abstract In this paper, we construct the first provably-secure isogeny-based (partially) blind signature scheme. While at a high level the scheme resembles the Schnorr blind signature, our work does not directly follow from that construction, since isogenies do not offer as rich an algebraic structure. Specifically, our protocol does not fit into thelinear identification protocolabstraction introduced by Hauck, Kiltz, and Loss (EUROCYRPT’19), which was used to generically construct Schnorr-like blind signatures based on modules such as classical groups and lattices. Consequently, our scheme is provably secure in the random oracle model (ROM) against poly-logarithmically-many concurrent sessions assuming the subexponential hardness of the group action inverse problem. In more detail, our blind signature exploits thequadratic twistof an elliptic curve in an essential way to endow isogenies with a strictly richer structure than abstract group actions (but still more restrictive than modules). The basic scheme has public key size 128 B and signature size 8 KB under the CSIDH-512 parameter sets—these are the smallest among all provably secure post-quantum secure blind signatures. Relying on a newringvariant of the group action inverse problem ( $$\textsf{rGAIP}$$ rGAIP ), we can halve the signature size to 4 KB while increasing the public key size to 512 B. We provide preliminary cryptanalysis of $${\textsf{rGAIP}} $$ rGAIP and show that for certain parameter settings, it is essentially as secure as the standard $$\textsf{GAIP}$$ GAIP . Finally, we show a novel way to turn our blind signature into a partially blind signature, where we deviate from prior methods since they require hashing into the set of public keys while hiding the corresponding secret key—constructing such a hash function in the isogeny setting remains an open problem.
Shuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow
Des. Codes Cryptogr.2
2023 Efficient Isogeny Proofs Using Generic Techniques
Kelong Cong, Yi-Fu Lai, Shai Levin
ACNS2
2023 CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a Twist
Shuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow
CRYPTO (3)2
2023 Group signatures and more from isogenies and lattices: generic, simple, and efficient
abstract
Abstract We construct an efficient dynamic group signature (or more generally an accountable ring signature) from isogeny and lattice assumptions. Our group signature is based on a simple generic construction that can be instantiated by cryptographically hard group actions such as the CSIDH group action or an MLWE-based group action. The signature is of size $$O(\log N)$$ O ( log N ) , where N is the number of users in the group. Our idea builds on the recent efficient OR-proof by Beullens, Katsumata, and Pintore (Asiacrypt’20), where we efficiently add a proof of valid ciphertext to their OR-proof and further show that the resulting non-interactive zero-knowledge proof system is online extractable . Our group signatures satisfy more ideal security properties compared to previously known constructions, while simultaneously having an attractive signature size. The signature size of our isogeny-based construction is an order of magnitude smaller than all previously known post-quantum group signatures (e.g., 6.6 KB for 64 members). In comparison, our lattice-based construction has a larger signature size (e.g., either 126 KB or 89 KB for 64 members depending on the satisfied security property). However, since the $$O(\cdot )$$ O ( · ) -notation hides a very small constant factor, it remains small even for very large group sizes, say $$2^{20}$$ 2 20 .
Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai, Federico Pintore
Des. Codes Cryptogr.4
2022 Group Signatures and More from Isogenies and Lattices: Generic, Simple, and Efficient
Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai, Federico Pintore
EUROCRYPT (2)4
2022 Attack on SHealS and HealS: The Second Wave of GPST
Steven D. Galbraith, Yi-Fu Lai
PQCrypto2
2021 Compact, Efficient and UC-Secure Isogeny-Based Oblivious Transfer
Yi-Fu Lai, Steven D. Galbraith, Cyprien Delpech de Saint Guilhem
EUROCRYPT (1)1