Sébastien Canard

dblp:51/2620 · DBLP profile ↗
← Back
49ranked-venue papers
35as first author
9since 2021 · last 2026
0009-0006-9588-7418ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 43 · 31 first-author · 7 since 2021Theory of computation · 3 · 3 first-authorSystems, architecture and hardware · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Simulation secure multi-input quadratic functional encryption: applications to differential privacy
Ferran Alborch Escobar, Sébastien Canard, Fabien Laguillaumie
Des. Codes Cryptogr.2
2025 Systematic Risk Analysis of Multi-Stage Attacks in Zonal Automotive E/E Architecture
abstract
The automotive industry’s shift to zonal Electrical/Electronic (E/E) architectures introduces new lateral movement pathways for multi-stage cyberattacks, posing significant end-user risks. Modeling these “automotive kill chains” is challenging due to the lack of a standardized framework for adversary tactics. This paper presents a methodology that integrates the Automotive Threat Matrix (ATM) with the ISO/SAE 21434 Threat Analysis and Risk Assessment (TARA) process to systematically construct and analyze attack paths. Based on this analysis, we propose the Automotive Kill Chain Correlation (AKCC), a dynamic threat response framework that correlates security alerts along modeled attack paths for high-confidence detection. Applying the methodology to a representative zonal architecture reveals systemic vulnerabilities and enables the design of targeted, stateful countermeasures. The practical utility of this approach is validated through a qualitative survey of industry experts, who confirmed it significantly simplifies and clarifies attack path analysis.
Ramakrishnan Pitchaimani, Sébastien Canard, Badis Hammi, Aurel Sorin Spornic
NCA2
2024 Simulation Secure Multi-input Quadratic Functional Encryption
Ferran Alborch Escobar, Sébastien Canard, Fabien Laguillaumie
SAC (1)2
2024 Computational Differential Privacy for Encrypted Databases Supporting Linear Queries
abstract
Differential privacy is a fundamental concept for protecting individual privacy in databases while enabling data analysis. Conceptually, it is assumed that the adversary has no direct access to the database, and therefore, encryption is not necessary. However, with the emergence of cloud computing and the << on-cloud >> storage of vast databases potentially contributed by multiple parties, it is becoming increasingly necessary to consider the possibility of the adversary having (at least partial) access to sensitive databases. A consequence is that, to protect the on-line database, it is now necessary to employ encryption. At PoPETs'19, it was the first time that the notion of differential privacy was considered for encrypted databases, but only for a limited type of query, namely histograms. Subsequently, a new type of query, summation, was considered at CODASPY'22. These works achieve statistical differential privacy, by still assuming that the adversary has no access to the encrypted database. In this paper, we take an essential step further by assuming that the adversary can eventually access the encrypted data, making it impossible to achieve statistical differential privacy because the security of encryption (beyond the one-time pad) relies on computational assumptions. Therefore, the appropriate privacy notion for encrypted databases that we target is computational differential privacy, which was introduced by Beimel et al. at CRYPTO '08. In our work, we focus on the case of functional encryption, which is an extensively studied primitive permitting some authorized computation over encrypted data. Technically, we show that any randomized functional encryption scheme that satisfies simulation-based security and differential privacy of the output can achieve computational differential privacy for multiple queries to one database. Our work also extends the summation query to a much broader range of queries, specifically linear queries, by utilizing inner-product functional encryption. Hence, we provide an instantiation for inner-product functionalities by proving its simulation soundness and present a concrete randomized inner-product functional encryption with computational differential privacy against multiple queries. In terms of efficiency, our protocol is almost as practical as the underlying inner product functional encryption scheme. As evidence, we provide a full benchmark, based on our concrete implementation for databases with up to 1 000 000 entries. Our work can be considered as a step towards achieving privacy-preserving encrypted databases for a wide range of query types and considering the involvement of multiple database owners.
Ferran Alborch Escobar, Sébastien Canard, Fabien Laguillaumie, Duong Hieu Phan
Proc. Priv. Enhancing Technol.2
2023 Dually Computable Cryptographic Accumulators and Their Application to Attribute Based Encryption
Anaïs Barthoulot, Olivier Blazy, Sébastien Canard
CANS3
2022 (Augmented) Broadcast Encryption from Identity Based Encryption with Wildcard
Anaïs Barthoulot, Olivier Blazy, Sébastien Canard
CANS3
2021 Privacy-preserving Density-based Clustering
abstract
Clustering is an unsupervised machine learning technique that outputs clusters containing similar data items. In this work, we investigate privacy-preserving density-based clustering which is, for example, used in financial analytics and medical diagnosis. When (multiple) data owners collaborate or outsource the computation, privacy concerns arise. To address this problem, we design, implement, and evaluate the first practical and fully private density-based clustering scheme based on secure two-party computation. Our protocol privately executes the DBSCAN algorithm without disclosing any information (including the number and size of clusters). It can be used for private clustering between two parties as well as for private outsourcing of an arbitrary number of data owners to two non-colluding servers. Our implementation of the DBSCAN algorithm privately clusters data sets with 400 elements in 7 minutes on commodity hardware. Thereby, it flexibly determines the number of required clusters and is insensitive to outliers, while being only factor 19x slower than today's fastest private K-means protocol (Mohassel et al., PETS'20) which can only be used for specific data sets. We then show how to transfer our newly designed protocol to related clustering algorithms by introducing a private approximation of the TRACLUS algorithm for trajectory clustering which has interesting real-world applications like financial time series forecasts and the investigation of the spread of a disease like COVID-19.
Beyza Bozdemir, Sébastien Canard, Orhan Ermis, Helen Möllering, Melek Önen, Thomas Schneider 0003
AsiaCCS2
2021 Towards practical intrusion detection system over encrypted traffic
abstract
Abstract Privacy and data confidentiality are today at the heart of many discussions. But such data protection should not be done at the detriment of other security aspects. In the context of network traffic, intrusion detection system becomes totally blind when the traffic is encrypted, making clients again vulnerable to known attacks. To reconcile security and privacy, BlindBox and BlindIDS are proposed to perform Deep Packet Inspection over an encrypted traffic, based on two different cryptographic techniques. But, on one side, even if BlindBox is quite efficient to detect an anomalous encrypted traffic, it necessitates a very high setup time for clients and servers and does not protect the know‐how of Security Editors (SEs) working on detection rules. On the other side, BlindIDS does protect SE's market and does not introduce any latency during setup time, but is definitely not enough efficient for a practical use. Herein, it is shown that the design of a fully efficient and market‐compliant intrusion detection system over an encrypted traffic is possible. The system is based on only symmetric cryptography, and permits to encrypt a packet of 1500 bytes in about 6 μs and to test such packets with 3000 rules in less than 2 μs.
Sébastien Canard, Chaoyun Li
IET Inf. Secur.1
2021 Cooperative Set Homomorphic Proofs for Data Possession Checking in Clouds
abstract
Outsourcing an increasing amount of data to a third party raises a number of security and privacy challenges, namely remote data integrity verification. Indeed, proofs for data possession checking address the verification that some previously outsourced data blocks across multiple storing nodes are correctly stored and fully available. In this paper, we propose a new set homomorphic proof of data possession, referred to as SHoPS, supporting several operations like aggregation of proofs. SHoPS is a deterministic Proof of Data Possession (PDP) scheme, based on an interactive proof protocol. Our approach has several advantages. First, it enables several proofs to be aggregated and a subset of data files' proofs to be verified, while providing an attractive communication overhead. Second, it supports public verifiability where the verification process can be delegated to another entity, thus releasing the data owner from the cumbersome task of periodical verifications. Third, SHoPS is efficient and provably secure, as it is resistant to the fraudulence of the prover and the leakage of verified data. Finally, a theoretical performances' analysis shows that SHoPS performs better in terms of functionality, communication and computation overhead compared to closely related works and experimental results point out the applicability of the proposed scheme in real world scenarios.
Nesrine Kaaniche, Maryline Laurent, Sébastien Canard
IEEE Trans. Cloud Comput.3
2020 Symmetric-Key Authenticated Key Exchange (SAKE) with Perfect Forward Secrecy
Gildas Avoine, Sébastien Canard, Loïc Ferreira
CT-RSA2
2020 Blind Functional Encryption
Sébastien Canard, Adel Hamdi, Fabien Laguillaumie
ICICS1
2020 Constant-Size Lattice-Based Group Signature with Forward Security in the Standard Model
Sébastien Canard, Adela Georgescu, Guillaume Kaim, Adeline Roux-Langlois, Jacques Traoré
ProvSec1
2019 IoT-Friendly AKE: Forward Secrecy and Session Resumption Meet Symmetric-Key Cryptography
Gildas Avoine, Sébastien Canard, Loïc Ferreira
ESORICS (2)2
2018 Privacy-Preserving Plaintext-Equality of Low-Entropy Inputs
Sébastien Canard, David Pointcheval, Quentin Santos, Jacques Traoré
ACNS1
2018 Towards Video Compression in the Encrypted Domain: A Case-Study on the H264 and HEVC Macroblock Processing Pipeline
Donald Nokam Kuate, Sébastien Canard, Renaud Sirdey
CANS2
2018 Practical Strategy-Resistant Privacy-Preserving Elections
Sébastien Canard, David Pointcheval, Quentin Santos, Jacques Traoré
ESORICS (2)1
2018 Certificateless Public Key Cryptography in the Standard Model
abstract
Identity-based cryptography has been introduced by Shamir at Crypto’84 to avoid the use of expensive certificates in certified public key cryptography. In such system, the identity becomes the public key and each user needs to interact with a designated authority to obtain the related private key. It however suffers the key escrow problem since the authority knows the private keys of all users. To deal with this problem, Riyami and Paterson have introduced, at Asiacrypt’03, the notion of certificateless public key cryptography. In this case, there is no need to use the certificate to certify the public key, and neither the user nor the authority can derive the full private key by himself. There have been several efforts to propose a certificateless signature (CLS) scheme in the standard model, but all of them either make use of the Waters’ technique or of the generic conversion technique (proposed by Yum and Lee at ACISP’04) which both lead to inefficient CLS schemes. Besides making use of the Waters’ technique and the generic conversion technique (proposed also by Yum and Lee at ICCSA’04), there exists direct approaches to construct certificateless public key encryption (CLE) scheme in the standard model. In this paper, we introduce a new and direct approach to construct a CLS scheme in the standard model with constant-size of all parameters and having efficient computing time. We also show that the Boneh et al.’s identity-based encryption scheme secured in the standard model at EC’04 can be extended to the certificateless setting. Interestingly, the resulting scheme can be comparable with the existing CLE schemes in term of both efficiency and security.
Sébastien Canard, Viet Cuong Trinh
Fundam. Informaticae1
2018 Attribute-based broadcast encryption scheme for lightweight devices
abstract
Lightweight devices, such as a smartcard associated with a top‐box decoder in pay‐TV or a SIM card coupled with a powerful (but not totally trusted) smartphone, play an important role in modern applications. The essential requirements for a cryptographic scheme to be truly implemented in lightweight devices are that it should have compact secret key size and support fast decryption. Attribute‐based broadcast encryption (ABBE) combines the functionalities of both broadcast encryption and attribute‐based encryption in an efficient way, ABBE is therefore a promising cryptographic scheme to be used in practical applications such as mobile pay‐TV, satellite transmission, or Internet of Things. Designing an ABBE scheme which can be truly implemented in lightweight devices is still an open question. In this study, the authors solve it by proposing an efficient constant‐size private key ciphertext‐policy ABBE scheme for disjunctive normal form supporting fast decryption and achieving standard security levels of an ABBE scheme. They concretely show that the authors’ scheme can be truly implemented in a prototype for a smartphone‐based cloud storage use case. In particular, they show how to alleviate some parts of their scheme so as to obtain a very practical system, and they give some concrete benchmarks.
Sébastien Canard, Duong Hieu Phan, Viet Cuong Trinh
IET Inf. Secur.1
2018 A new technique for compacting ciphertext in multi-channel broadcast encryption and attribute-based encryption
Sébastien Canard, Duong Hieu Phan, David Pointcheval, Viet Cuong Trinh
Theor. Comput. Sci.1
2017 BlindIDS: Market-Compliant and Privacy-Friendly Intrusion Detection System over Encrypted Traffic
abstract
The goal of network intrusion detection is to inspect network traffic in order to identify threats and known attack patterns. One of its key features is Deep Packet Inspection (DPI), that extracts the content of network packets and compares it against a set of detection signatures. While DPI is commonly used to protect networks and information systems, it requires direct access to the traffic content, which makes it blinded against encrypted network protocols such as HTTPS. So far, a difficult choice was to be made between the privacy of network users and security through the inspection of their traffic content to detect attacks or malicious activities.
Sébastien Canard, Aïda Diop, Nizar Kheir, Marie Paindavoine, Mohamed Sabt
AsiaCCS1
2017 Running Compression Algorithms in the Encrypted Domain: A Case-Study on the Homomorphic Execution of RLE
abstract
This paper is devoted to the study of the problem of running compression algorithms in the encrypted domain, using a (somewhat) fully homomorphic encryption (FHE) scheme. We do so with a particular focus on conservative compression algorithms. Despite of the encrypted domain Turingcompleteness which comes with the magic of FHE operators, we show that a number of subtleties crop up when it comes to running compression algorithms and, in particular, that guaranteed conservative compression is not possible to achieve in the FHE setting. To illustrate these points, we analyze the most elementary conservative compression algorithm of all, namely Run-Length Encoding (RLE). We first study the way to regularize this algorithm in order to make it (meaningfully) fit within the constraints of a FHE execution. Secondly, we analyze it from the angle of optimizing the resulting structure towards (as much as possible) FHE execution efficiency. The paper is concluded by concrete experimental results obtained using the Fan-Vercauteren cryptosystem as well as the Armadillo FHE compiler. It is also this paper intent to share the concrete return on experience we gained in attempting to run a simple yet practically significant algorithm over FHE.
Sébastien Canard, Sergiu Carpov, Donald Nokam Kuate, Renaud Sirdey
PST1
2017 Differentially Private Instance-Based Noise Mechanisms in Practice
abstract
Differential privacy is a widely used privacy model today, whose privacy guarantees are obtained to the price of a random perturbation of the result. In some situations, basic differentially private mechanisms may add too much noise to reach a reasonable level of privacy. To answer this shortcoming, several works have provided more technically involved mechanisms, using a new paradigm of differentially private mechanisms called instance-based noise mechanisms. In this paper, we exhibit for the first time theoretical conditions for an instance-based noise mechanism to be (ϵ,δ)-differentially private. We exploit the simplicity of these conditions to design a novel instance-based noise differentially private mechanism. Conducting experimental evaluations, we show that our mechanism compares favorably to existing instance-based noise mechanisms, either regarding time complexity or accuracy of the sanitized result. By contrast with some prior works, our algorithms do not involve the computation of all local sensitivities, a computational task which was proved to be NP hard in some cases, namely for statistic queries on graphs. Our framework is as general as possible and can be used to answer any query, which is in contrast with recent designs of instance-based noise mechanisms where only graph statistics queries are considered.
Sébastien Canard, Baptiste Olivier, Tony Quertier
PST1
2016 Verifiable Message-Locked Encryption
Sébastien Canard, Fabien Laguillaumie, Marie Paindavoine
CANS1
2016 A New Technique for Compacting Secret Key in Attribute-Based Broadcast Encryption
Sébastien Canard, Duong Hieu Phan, Viet Cuong Trinh
CANS1
2016 Edge-calibrated noise for differentially private mechanisms on graphs
abstract
In this paper, we introduce new methods for releasing differentially private graphs. Our techniques are based on a new way to distribute noise among edge weights. More precisely, we rely on the addition of noise whose amplitude is edge-calibrated and optimize the distribution of the privacy budget among subsets of edges. The generic privacy framework that we propose can capture most of the privacy notions introduced so far in the literature to release graphs in a differentially private manner. Furthermore, experimental results on real datasets show that our methods outperform the standard existing techniques, in particular in terms of the preservation of utility. In addition, these experiments show that our mechanisms guarantee ε-differential privacy for a reasonable level of privacy ε, while preserving the spectral information of the input graph.
Solenn Brunet, Sébastien Canard, Sébastien Gambs, Baptiste Olivier
PST2
2016 Highly privacy-protecting data sharing in a tree structure
Sébastien Canard, Julien Devigne
Future Gener. Comput. Syst.1
2016 Divisible e-cash made practical
abstract
Divisible e‐cash systems allow users to withdraw a unique coin of value 2 n units from a bank, but then to spend it in several times to distinct merchants. In such a system, whereas users want anonymity of their transactions, the bank wants to prevent, or at least detect, double‐spending, and trace defrauders. While this primitive was introduced two decades ago, quite a few (really) anonymous constructions have been proposed. In addition, all but one were just proven secure in the random oracle model, but still with either weak security models or quite complex settings and thus costly constructions. The unique proposal, secure in the standard model, appeared recently and is unpractical. As evidence, the authors left the construction of an efficient scheme secure in this model as an open problem. In this study, the authors answer it with the first efficient divisible e‐cash system secure in the standard model. It is based on a new way of building the coins, with a unique and public global tree structure for all the coins. Actually, they propose two constructions which offer a tradeoff between efficiency and security. They both achieve constant time for withdrawing and spending amounts of 2 ℓ units, while allowing the bank to quickly detect double‐spendings by a simple comparison of the serial numbers of deposited coins to the ones of previously spent coins.
Sébastien Canard, David Pointcheval, Olivier Sanders, Jacques Traoré
IET Inf. Secur.1
2015 Scalable Divisible E-cash
Sébastien Canard, David Pointcheval, Olivier Sanders, Jacques Traoré
ACNS1
2014 Delegating a Pairing Can Be Both Secure and Efficient
Sébastien Canard, Julien Devigne, Olivier Sanders
ACNS1
2013 Protecting privacy by sanitizing personal data: a new approach to anonymous credentials
abstract
Anonymous credential systems allow users to obtain certified credentials from organizations and use them later without being traced. For instance, a student will be able to prove, using his student card certified by the University, that he is a student living e.g. in Hangzhou without revealing other information given by the student card, such as his name or studies. Besides, sanitizable signatures enable a designated person, called the sanitizer, to modify some parts of a signed message in a controlled way, such that the message can still be verified w.r.t. the original signer.
Sébastien Canard, Roch Lescuyer
AsiaCCS1
2013 Toward Generic Method for Server-Aided Cryptography
Sébastien Canard, Iwen Coisel, Julien Devigne, Cécilia Gallais, Thomas Peters, Olivier Sanders
ICICS1
2012 Improved (and Practical) Public-Key Authentication for UHF RFID Tags
Sébastien Canard, Loïc Ferreira, Matthew J. B. Robshaw
CARDIS1
2012 Plaintext-Checkable Encryption
Sébastien Canard, Georg Fuchsbauer, Aline Gouget, Fabien Laguillaumie
CT-RSA1
2012 On the Implementation of a Pairing-Based Cryptographic Protocol in a Constrained Device
Sébastien Canard, Nicolas Desmoulins, Julien Devigne, Jacques Traoré
Pairing1
2011 Multi-show Anonymous Credentials with Encrypted Attributes in the Standard Model
Sébastien Canard, Roch Lescuyer, Jacques Traoré
CANS1
2010 One Time Anonymous Certificate: X.509 Supporting Anonymity
Aymen Abed, Sébastien Canard
CANS2
2010 On Extended Sanitizable Signature Schemes
Sébastien Canard, Amandine Jambert
CT-RSA1
2010 Untraceability and Profiling Are Not Mutually Exclusive
Sébastien Canard, Amandine Jambert
TrustBus1
2009 Fair E-Cash: Be Compact, Spend Faster
Sébastien Canard, Cécile Delerablée, Aline Gouget, Emeline Hufschmitt, Fabien Laguillaumie, Hervé Sibert, Jacques Traoré, Damien Vergnaud
ISC1
2008 Anonymity in Transferable E-cash
Sébastien Canard, Aline Gouget
ACNS1
2008 TrapdoorSanitizable Signatures and Their Application to Content Protection
Sébastien Canard, Fabien Laguillaumie, Michel Milhau
ACNS1
2007 Divisible E-Cash Systems Can Be Truly Anonymous
Sébastien Canard, Aline Gouget
EUROCRYPT1
2007 Complex Zero-Knowledge Proofs of Knowledge Are Easy to Use
Sébastien Canard, Iwen Coisel, Jacques Traoré
ProvSec1
2006 A Handy Multi-coupon System
Sébastien Canard, Aline Gouget, Emeline Hufschmitt
ACNS1
2006 Low-Cost Cryptography for Privacy in RFID Systems
Benoît Calmels, Sébastien Canard, Marc Girault, Hervé Sibert
CARDIS2
2006 List signature schemes
Sébastien Canard, Berry Schoenmakers, Martijn Stam, Jacques Traoré
Discret. Appl. Math.1
2004 Anonymous Services using Smart Cards and Cryptography
Sébastien Canard, Jacques Traoré
CARDIS1
2003 On Fair E-cash Systems Based on Group Signature Schemes
Sébastien Canard, Jacques Traoré
ACISP1
2002 Implementing Group Signature Schemes with Smart Cards
Sébastien Canard, Marc Girault
CARDIS1