EDBT 2026 Demo / reviewers in the wild / expert
Yusuke Sakai 0001
dblp:44/7691
· DBLP profile ↗
30ranked-venue papers
8as first author
7since 2021 · last 2026
0000-0002-5115-8292ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 7 first-author · 7 since 2021Theory of computation · 5 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Attribute-Based Signatures for Circuits with Optimal Parameter Size from Standard Assumptions
Ryuya Hayashi, Yusuke Sakai 0001, Shota Yamada 0001 |
PKC (3) | 2 |
| 2025 | Aggregate Signatures Tightly Secure Under Adaptive Corruptions
Yusuke Sakai 0001 |
ASIACRYPT (6) | 1 |
| 2025 | Abuse-Resistant Evaluation of AI-as-a-Service via Function-Hiding Homomorphic Signatures
Nuttapong Attrapadung, Goichiro Hanaoaka, Ryo Hiromasa, Yoshihiro Koseki, Takahiro Matsuda 0002, Yutaro Nishida, Yusuke Sakai 0001, Jacob C. N. Schuldt, Satoshi Yasuda |
ESORICS (1) | 7 |
| 2024 | Privacy-Preserving Verifiable CNNsabstractConvolutional neural networks (CNNs) have emerged as one of the most successful deep learning approaches to image recognition and classification. A recent line of research, which includes zkCNN (ACM CCS ’21), vCNN (Cryptology ePrint Archive), and ZEN (Cryptology ePrint Archive), aims at protecting the privacy of CNN models by developing publicly verifiable proofs of correct classification which do not leak any information about the underlying CNN models themselves. A shared feature of these schemes is that they require the entity constructing the proof to have access to both the model and the input in the clear. In other words, a client holding a potentially sensitive input is required to reveal this input to the entity holding the CNN model, thereby sacrificing his privacy, to be able to obtain a verifiable proof of correct classification. This is in contrast to the security guarantees provided by secure classification considered in privacy-preserving machine learning, which does not require the client to reveal his input to obtain a (non-verifiable) classification. In this paper, we propose a privacy-preserving verifiable CNN scheme that overcomes this limitation of the previous schemes by allowing the client to obtain a classification proof without having to reveal his input. The obtained proof allows the client to selectively reveal properties of the obtained classification and his input, which will be verifiable to any third-party verifier. Our scheme is based on the recent notion of collaborative zk-SNARKs by Ozdemir and Boneh (USENIX ’22). Specifically, we construct a new collaborative zk-SNARK based on Bulletproofs achieving an efficient maliciously secure proof generation protocol. Based on this, we then present an optimized approach to CNN evaluation. Finally, we demonstrate the feasibility of our approach by measuring the performance of our scheme on a CNN for classifying the MNIST dataset. Nuttapong Attrapadung, Goichiro Hanaoka, Ryo Hiromasa, Yoshihiro Koseki, Takahiro Matsuda 0002, Yutaro Nishida, Yusuke Sakai 0001, Jacob C. N. Schuldt, Satoshi Yasuda |
ACNS (2) | 7 |
| 2024 | Anonymous Reputation Systems with Revocation, Revisited
Ryuya Hayashi, Shuichi Katsumata, Yusuke Sakai 0001 |
FC (2) | 3 |
| 2023 | Practical Round-Optimal Blind Signatures in the ROM from Standard Assumptions
Shuichi Katsumata, Michael Reichle, Yusuke Sakai 0001 |
ASIACRYPT (2) | 3 |
| 2023 | Signature for Objects: Formalizing How to Authenticate Physical Data and More
Ryuya Hayashi, Taiki Asano, Junichiro Hayata, Takahiro Matsuda 0002, Shota Yamada 0001, Shuichi Katsumata, Yusuke Sakai 0001, Tadanori Teruya, Jacob C. N. Schuldt, Nuttapong Attrapadung, Goichiro Hanaoka, Kanta Matsuura, Tsutomu Matsumoto |
FC (1) | 7 |
| 2020 | Semantic Definition of Anonymity in Identity-Based Encryption and Its Relation to Indistinguishability-Based Definition
Goichiro Hanaoka, Misaki Komatsu, Kazuma Ohara, Yusuke Sakai 0001, Shota Yamada 0001 |
ESORICS (2) | 4 |
| 2020 | Achieving Pairing-Free Aggregate Signatures using Pre-Communication between Signers
Kaoru Takemure, Yusuke Sakai 0001, Bagus Santoso, Goichiro Hanaoka, Kazuo Ohta |
ProvSec | 2 |
| 2019 | Field Extension in Secret-Shared Form and Its Applications to Efficient Secure Computation
Ryo Kikuchi, Nuttapong Attrapadung, Koki Hamada, Dai Ikarashi, Ai Ishida, Takahiro Matsuda 0002, Yusuke Sakai 0001, Jacob C. N. Schuldt |
ACISP | 7 |
| 2019 | Proper Usage of the Group Signature Scheme in ISO/IEC 20008-2abstractIn ISO/IEC 20008-2, several anonymous digital signature schemes are specified. Among these, the scheme denoted as Mechanism 6, is the only plain group signature scheme that does not aim at providing additional functionalities. The Intel Enhanced Privacy Identification (EPID) scheme, which has many applications in connection with Intel Software Guard Extensions (Intel SGX), is in practice derived from Mechanism 6. In this paper, we firstly show that Mechanism 6 does not satisfy anonymity in the standard security model, i.e., the Bellare-Shi-Zhang model [CT-RSA 2005]. We then provide a detailed analysis of the security properties offered by Mechanism 6 and characterize the conditions under which its anonymity is preserved. Consequently, it is seen that Mechanism 6 is secure under the condition that the issuer, who generates user signing keys, does not join the attack. We also derive a simple patch for Mechanism~6 from the analysis. Ai Ishida, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka |
AsiaCCS | 2 |
| 2019 | Group Signatures with Message-Dependent Opening: Formal Definitions and ConstructionsabstractThis paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes. Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazuma Ohara, Kazumasa Omote, Yusuke Sakai 0001 |
Secur. Commun. Networks | 7 |
| 2018 | Attribute-Based Signatures for Unbounded Languages from Standard Assumptions
Yusuke Sakai 0001, Shuichi Katsumata, Nuttapong Attrapadung, Goichiro Hanaoka |
ASIACRYPT (2) | 1 |
| 2018 | Efficient Two-level Homomorphic Encryption in Prime-order Bilinear Groups and A Fast Implementation in WebAssemblyabstractWe construct an efficient two-level homomorphic public-key encryption in prime-order bilinear groups. Such a scheme supports polynomially many homomorphic additions and one multiplication over encrypted data, similar to the cryptosystem of Boneh, Goh, and Nissim (BGN, presented at TCC 2005), which was constructed in composite-order bilinear groups. Prior to our work, the state-of-the-art for two-level homomorphic public-key encryption is the Freeman scheme (presented at Eurocrypt 2010), which is indeed the prime-order realization of the BGN scheme. Our proposed scheme significantly improves efficiency for almost all the aspects of the Freeman scheme, while retains the same ciphertext sizes. Our scheme is surprisingly simple as it is indeed (a concatenation of two copies of) the ElGamal encryption "in the exponent'' resided in an asymmetric bilinear groups. Nuttapong Attrapadung, Goichiro Hanaoka, Shigeo Mitsunari, Yusuke Sakai 0001, Kana Shimizu, Tadanori Teruya |
AsiaCCS | 4 |
| 2018 | A Remark on an Identity-Based Encryption Scheme with Non-interactive OpeningabstractIdentity-based encryption with non-interactive opening is an extension of identity-based encryption which allows a receiver to prove a given ciphertext will be decrypted to a public message without revealing his decryption key. Fan et al. (J. Shanghai Jiaotong Univ. (Sci.)) proposed a construction of this primitive. We analyze the security of their scheme and show that the scheme is in fact not secure. Yusuke Sakai 0001, Goichiro Hanaoka |
ISITA | 1 |
| 2018 | Generic Construction of Adaptively Secure Anonymous Key-Policy Attribute-Based Encryption from Public-Key Searchable EncryptionabstractPublic-key encryption with keyword search (PEKS) is a cryptographic primitive that allows us to search encrypted data for those of including particular keywords without decrypting them. PEKS is expected to be used for enhancing security of cloud storages. It is known that PEKS can be constructed from anonymous identity-based encryption (IBE), anonymous attribute-based encryption (ABE) and so on. It is believed that it is difficult to construct PEKS schemes that can specify a flexible search condition such as logical disjunctions and logical conjunctions from weaker cryptographic tools than ABE. However, this intuition has not been rigorously justified. In this paper, we formally prove it by constructing key-policy ABE from PEKS for monotone boolean formulas. Junichiro Hayata, Masahito Ishizaka, Yusuke Sakai 0001, Goichiro Hanaoka, Kanta Matsuura |
ISITA | 3 |
| 2018 | A Consideration on the Transformation from Deniable Group Signature to Disavowable PKENOabstractEmura et al. [Int. J. Inf. Sec. 2014] showed that a public key encryption scheme with non-interactive opening (PKENO scheme) can be constructed from a group signature scheme secure in the dynamic setting. By following this construction, it seems that we can obtain a disavowable PKENO scheme [Ishida et al., ASIACCS 2015] from a deniable group signature scheme [Ishida et al., CANS 2016] since these primitives have the similar functionalities. In this work, we claim that this intuition is incorrect. Concretely, we show that the obtained scheme does not satisfy the functionality of disavowable PKENO by providing an attack for the indistinguishability against chosen ciphertext and prove attack security. Ai Ishida, Yusuke Sakai 0001, Goichiro Hanaoka |
ISITA | 2 |
| 2018 | Formal Treatment of Verifiable Privacy-Preserving Data-Aggregation Protocols
Satoshi Yasuda, Yoshihiro Koseki, Yusuke Sakai 0001, Fuyuki Kitagawa, Yutaka Kawai, Goichiro Hanaoka |
ProvSec | 3 |
| 2018 | Practical attribute-based signature schemes for circuits from bilinear mapabstractAttribute‐based signatures allow us to sign anonymously, in such a way that the signature proves that the signer's attributes satisfy some predicate, but it hides any other information on the signer's attributes beyond that fact. As well as any cryptographic primitive, one of the important goals of the research on this primitive is to construct a scheme that is expressive (supports a wide class of predicates), is practically efficient , and is based on well‐studied cryptographic assumptions . The authors construct attribute‐based signature schemes that support any Boolean circuit of unbounded depth and number of gates, are practically efficient, from the symmetric bilinear Diffie–Hellman assumption. Toward this end, they combine the Groth–Sahai proof system, which serve as an efficient proof system for algebraic equations, and the Groth–Ostrovsky–Sahai proof system, which are still inefficient, but can prove any NP language via a Karp reduction to circuit satisfiability. Yusuke Sakai 0001, Nuttapong Attrapadung, Goichiro Hanaoka |
IET Inf. Secur. | 1 |
| 2016 | Group Signature with Deniability: How to Disavow a Signature
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka |
CANS | 4 |
| 2016 | Tag-KEM/DEM framework for public-key encryption with non-interactive opening
Yusuke Sakai 0001, Takahiro Matsuda 0002, Goichiro Hanaoka |
ISITA | 1 |
| 2016 | Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta |
Theor. Comput. Sci. | 1 |
| 2015 | Dynamic Threshold Public-Key Encryption with Decryption Consistency from Static Assumptions
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta |
ACISP | 1 |
| 2015 | Disavowable Public Key Encryption with Non-interactive OpeningabstractWe propose the notion of disavowable public key encryption with non-interactive opening (disavowable PKENO) where, for a ciphertext and a message, the receiver of the ciphertext can issue a proof that the plaintext of the ciphertext is NOT the message, and give a fairly practical construction. Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka |
AsiaCCS | 4 |
| 2015 | Revocable Group Signature with Constant-Size Revocation ListabstractIt is essential that a multi-user cryptographic primitive be revocable since a legitimate user may quit the organization, or may act on malicious intent, or the relevant key may be leaked. In the group signature context, usually the group manager publishes the revocation list that contains revocation tokens. Since signers/verifiers need to obtain the revocation list in each revocation epoch to generate/verify a group signature, a small-size revocation list is really important in practice. However, all previous revocable group signatures require at least an |$O(r)$|-size revocation list, where |$r$| is the number of revoked users. In this paper, we propose the first revocable group signature scheme with a constant-size revocation list using identity-based revocation (IBR) techniques. We use an IBR scheme proposed by Attrapadung–Libert–Panafieu (PKC 2011) as a building block. As in the Libert–Peters–Yung schemes (EUROCRYPT 2012/CRYPTO 2012), no signing key update is required. In addition, the verification cost does not depend on the number of revoked users |$r$|. Although the maximum number of revoked users needs to be fixed in the setup phase, the maximum number of group members is potentially unbounded as in IBR. This property has not been achieved in the recent scalable revocable group signature schemes and seems to be of independent interest. Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001 |
Comput. J. | 4 |
| 2014 | A Revocable Group Signature Scheme from Identity-Based Revocation Techniques: Achieving Constant-Size Revocation List
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001 |
ACNS | 4 |
| 2014 | A Privacy-Enhanced Access Log Management Mechanism in SSO Systems from Nominative SignaturesabstractIn online services, e.g., Online shopping, a service provider (SP) manages access logs containing customers' buying histories. Therefore, user's personal information, e.g., Their hobbies and diversions, is revealed from the exposed logs if each customer can be linked. In fact, such information exposure has occurred due to the popularization of online services. To cope with this problem, SPs may only have to delete access logs, but then no illegitimate users, who accessed the server illegally, will be traced from the logs. In this paper, we propose a log management mechanism where (1) no user information is revealed even if logs are exposed, but (2) illegitimate users can be traced when necessary. Specifically, we consider single sign on (SSO) systems, since plural access logs might be connected by one account, and this could trigger the above privacy infringement problem. We construct our privacy-enhanced access log management mechanism based on the Wang-Wang-Susilo SSO system (TrustCom 2013) which applies nominative signatures as its building block. Specifically, we realize the system by additionally applying the invisibility property of the Schuldt-Hanaoka nominative signature scheme (ACNS 2011). Finally, we estimate the efficiency of the proposed system by using Pairing-Based Cryptography (PBC) library and confirmed that for each algorithm, computation time is at most just over 80 milliseconds on a PC, which seems sufficiently practical. Sanami Nakagawa, Keita Emura, Goichiro Hanaoka, Akihisa Kodate, Takashi Nishide, Eiji Okamoto, Yusuke Sakai 0001 |
TrustCom | 7 |
| 2013 | A group signature scheme with unbounded message-dependent openingabstractGroup signature with message-dependent opening (GS-MDO) is a kind of group signature in which only the signers who have created group signatures on problematic messages will be identified. In the previous GS-MDO scheme, however, the number of problematic messages is bounded owing to a limitation of the Groth-Sahai proofs. In this paper, we propose the first GS-MDO scheme with the unbounded-MDO functionality in the random oracle model. Our unbounded GS-MDO scheme is based on the short group signature scheme proposed by Boneh, Boyen, and Shacham and the Boneh-Franklin identity-based encryption scheme. To combine these building blocks and to achieve CCA-anonymity, we also construct a special type of multiple encryption. This technique yields an efficient construction compared with the previous bounded GS-MDO scheme: the signature of our scheme contains about 16 group elements (3630 bits), whereas that of the previous scheme has about 450 group elements (75820 bits). Kazuma Ohara, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka |
AsiaCCS | 2 |
| 2012 | Group Signatures with Message-Dependent Opening
Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazumasa Omote |
Pairing | 1 |
| 2011 | Ciphertext-Policy Delegatable Hidden Vector Encryption and Its Application to Searchable Encryption in Multi-user Setting
Mitsuhiro Hattori, Takato Hirano, Takashi Ito, Nori Matsuda, Takumi Mori, Yusuke Sakai 0001, Kazuo Ohta |
IMACC | 6 |