EDBT 2026 Demo / reviewers in the wild / expert
Noboru Kunihiro
dblp:59/6407
· DBLP profile ↗
67ranked-venue papers
7as first author
9since 2021 · last 2025
0000-0003-1822-7476ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 58 · 6 first-author · 8 since 2021Theory of computation · 13 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Solving Generalized Approximate Divisor Multiples Problems
Naoki Shimoe, Noboru Kunihiro |
ACISP (2) | 2 |
| 2025 | Key Recovery Attacks on Unpatched MEGA from Four Queries: Solving Approximate Divisor Problem with Help of Approximation of Squared Divisor
Naoki Shimoe, Noboru Kunihiro |
ACNS (1) | 2 |
| 2025 | Converting Fuzzy Signatures into Anonymizable Signatures using Zero-Knowledge ProofabstractManagement of secret keys for digital signatures is one of the most critical issues in decentralized applications. Since there is no administrator, losing a secret key can result in losing all assets or rights. To address this problem, fuzzy extractors and fuzzy signatures, which generate private keys directly from biometric information, have been considered in addition to conventional biometric authentication. However, these methods using biometric secret keys do not support group signatures. Therefore, it is not applicable to use cases that require consensus building by a specific community (group), such as DAO and DeFi.In this paper, we propose a new scheme for converting existing fuzzy signatures to group signatures using zero-knowledge proofs to address this problem. More precisely, we first define an anonymizable signature that is a generalization of a group signature and then convert a fuzzy signature into an anonymizable signature using an ordinary (classical) zero-knowledge proof. In addition, the signature data size is optimized to a constant size using zk-SNARK. Our implementation experiments show that our schemes achieve practical signature generation and verification times and signature sizes even for a group of up to 100,000 people. This paper’s results can be used to prevent the loss of secret keys and enable flexible DApps use cases. Ken Naganuma, Shingo Akata, Masayuki Yoshino, Noboru Kunihiro, Non Kawana, Wataru Nakamura, Kenta Takahashi, Takayuki Suzuki |
ICBC | 4 |
| 2024 | Bias from Uniform Nonce: Revised Fourier Analysis-Based Attack on ECDSA
Shunsuke Osaki, Noboru Kunihiro |
SAC (1) | 2 |
| 2024 | Post-quantum zk-SNARKs from QAPsabstractIn recent years, the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) have drawn significant attention as privacy-enhancing technologies in various domains. A post-quantum designated verifier type zk-SNARK for Boolean circuits was proposed by Gennaro et al. in ACM CCS '18. However, this scheme does not include arithmetic circuits and they claim that a construction of post zk-SNARKs for arithmetic circuits as open problem. In this paper we give answers to this problem. Our first proposal is based on the data structure used in Pinocchio, a previous study, and can be easily implemented using the existing Pinocchio-based systems. In our second proposal, which also employs QAPs, the zero-knowledge proof comprises three learning with errors (LWE) ciphertexts, and the size of the proof is smaller compared with that of the first proposal. Our second proposal is also more efficient than the first one or all other known post-quantum zk-SNARKs. Ken Naganuma, Masayuki Yoshino, Noboru Kunihiro, Atsuo Inoue, Yukinori Matsuoka, Mineaki Okazaki |
Int. J. Inf. Comput. Secur. | 3 |
| 2023 | HS-Based Error Correction Algorithm for Noisy Binary GCD Side-Channel Sequences
Kenta Tani, Noboru Kunihiro |
ACNS (1) | 2 |
| 2023 | Multiplicative and verifiably multiplicative secret sharing for multipartite adversary structures
Reo Eriguchi, Noboru Kunihiro, Koji Nuida |
Des. Codes Cryptogr. | 2 |
| 2023 | Efficient Noise Generation Protocols for Differentially Private Multiparty ComputationabstractTo bound information leakage in outputs of protocols, it is important to construct secure multiparty computation protocols which output differentially private values perturbed by the addition of noise. However, previous noise generation protocols have round and communication complexity growing with differential privacy budgets, or require parties to locally generate non-uniform noise, which makes it difficult to guarantee differential privacy against active adversaries. We propose three kinds of protocols for generating noise drawn from certain distributions providing differential privacy. The two of them generate noise from finite-range variants of the discrete Laplace distribution. For$(\epsilon,\delta )$-differential privacy, they only need constant numbers of rounds independent of$\epsilon,\delta$while the previous protocol needs the number of rounds depending on$\delta$. The two protocols are incomparable as they make a trade-off between round and communication complexity. Our third protocol non-interactively generate shares of noise from the binomial distribution by predistributing keys for a pseudorandom function. It achieves communication complexity independent of$\epsilon$or$\delta$for the computational analogue of$(\epsilon,\delta )$-differential privacy while the previous protocols require communication complexity depending on$\epsilon$. We also prove that our protocols can be extended so that they provide differential privacy in the active setting. Reo Eriguchi, Atsunori Ichikawa, Noboru Kunihiro, Koji Nuida |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Cryptanalysis of the RSA variant based on cubic Pell equation
Mengce Zheng, Noboru Kunihiro, Yuanzhi Yao |
Theor. Comput. Sci. | 2 |
| 2020 | Recovering CRT-RSA Secret Keys from Noisy Square-and-Multiply Sequences in the Sliding Window Method
Kento Oonishi, Noboru Kunihiro |
ACISP | 2 |
| 2020 | A Linear Algebraic Approach to Strongly Secure Ramp Secret Sharing for General Access Structures
Reo Eriguchi, Noboru Kunihiro, Koji Nuida |
ISITA | 2 |
| 2020 | Worst case short lattice vector enumeration on block reduced bases of arbitrary blocksizes
Noboru Kunihiro, Atsushi Takayasu |
Discret. Appl. Math. | 1 |
| 2020 | Strong security of linear ramp secret sharing schemes with general access structures
Reo Eriguchi, Noboru Kunihiro |
Inf. Process. Lett. | 2 |
| 2020 | Extended partial key exposure attacks on RSA: Improvement up to full size decryption exponents
Kaichi Suzuki, Atsushi Takayasu, Noboru Kunihiro |
Theor. Comput. Sci. | 3 |
| 2020 | Generic hardness of inversion on ring and its relation to self-bilinear map
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
Theor. Comput. Sci. | 4 |
| 2019 | Optimal Multiple Assignment Schemes Using Ideal Multipartite Secret Sharing SchemesabstractA multiple assignment scheme (MAS) is a method to construct secret sharing schemes (SSSs) for general access structures. There are MASs using threshold and ramp SSSs. The paper proposes new MASs using ideal SSSs realizing compartmented access structures and those using SSSs realizing multi-level access structures. Since the ideal SSSs realizing compartmented access structures and SSSs realizing multi-level access structures are natural generalizations of threshold and ramp SSSs, respectively, the new MASs cannot be less efficient than those using threshold or ramp SSSs. Reo Eriguchi, Noboru Kunihiro, Mitsugu Iwamoto |
ISIT | 2 |
| 2019 | Strongly Secure Ramp Secret Sharing Schemes from Any Linear Secret Sharing SchemesabstractA secret sharing scheme (SSS) is a cryptographic tool to protect a secret from loss and leakage by dividing it into shares. A ramp SSS can improve the efficiency in terms of the sizes of shares by allowing partial information about the secret to leak out. In order to prevent the partial information from being recovered explicitly, the notion of the strong security has been introduced. However, there have been proposed few methods to construct strongly secure ramp SSSs for general access structures and they are not always sufficient. In this paper, we show that any linear ramp SSS can be transformed into a strongly secure scheme with the same access structure preserving the information ratio. Reo Eriguchi, Noboru Kunihiro |
ITW | 2 |
| 2019 | Partial key exposure attacks on RSA: Achieving the Boneh-Durfee bound
Atsushi Takayasu, Noboru Kunihiro |
Theor. Comput. Sci. | 2 |
| 2018 | A Deterministic Algorithm for Computing Divisors in an Interval
Liqiang Peng, Yao Lu 0002, Noboru Kunihiro, Rui Zhang 0002, Lei Hu 0003 |
ACISP | 3 |
| 2018 | Certifying Variant of RSA with Generalized Moduli
Yao Lu 0002, Noboru Kunihiro, Rui Zhang 0002, Liqiang Peng, Hui Ma 0002 |
ICICS | 2 |
| 2018 | Multi-party Key Exchange Protocols from Supersingular IsogeniesabstractWhen large-scale quantum computers are implemented, several cryptosystems based on the hardness of factoring and discrete logarithm problems will be broken. Hence, it is desirable to construct quantum-resistant cryptographic protocols. Although several candidates are introduced for hard problem, the computational hardness of finding isogenies between two supersingular elliptic curves (supersingular isogenies) is promising among them. It is strongly believed that the computation of supersingular isogenies requires exponential time even in the quantum computers. In this paper, we propose quantum-resistant multi-party key exchange protocols. First, we introduce several assumptions related to supersingular isogenies, which includes a generalization of supersingular isogeny decisional Diffie-Hellman (SSDDH) assumption which is called GSSDDH assumption. We present a construction of the n-party key exchange protocol based on the GSSDDH assumption. It is n - 1-round protocol and can be considered as a natural extension of 2-party 1-round supersingular isogeny Diffie-Hellman (SIDH) protocol, and we call it generalized SIDH (GSIDH) protocol. We then propose an n-party 2-round key exchange protocol by combining SIDH with the idea of Burmester-Desmedt (BD) key exchange, which significantly reduces the number of rounds. This protocol is called SIBD protocol and is based on the SSDDH assumption. Satoshi Furukawa, Noboru Kunihiro, Katsuyuki Takashima |
ISITA | 2 |
| 2018 | Decentralized Netting Protocol over Consortium BlockchainabstractIn recent years, Bitcoin, Ethereum and other cryptocurrencies have attracted a great deal of attention from the whole industry including the financial as a new settlement system. Transaction information of these cryptocurrencies is stored in a distribution ledger called Blockchain on the P2P network through processing such as PoW. Meanwhile, since PoW requires a large amount of computer resources, researches on private / consortium type blockchain that do not need PoW. In this paper, we propose a decentralized netting protocol using a consortium type block chain that has the channel function. On a system that implements the proposed protocol, netting settlement can be performed on P2P hiding information of the sender and receiver name of transaction, amount of money, calculation butt of netting, and without setting up a specific central organization such as a central server. Ken Naganuma, Masayuki Yoshino, Hisayoshi Sato, Nishio Yamada, Takayuki Suzuki, Noboru Kunihiro |
ISITA | 6 |
| 2017 | Solving the DLP with Low Hamming Weight Product Exponents and Improved Attacks on the GPS Identification Scheme
Jason H. M. Ying, Noboru Kunihiro |
ACISP (2) | 2 |
| 2017 | Improved Factoring Attacks on Multi-prime RSA with Small Prime Difference
Mengce Zheng, Noboru Kunihiro, Honggang Hu |
ACISP (1) | 2 |
| 2017 | Bounds in Various Generalized Settings of the Discrete Logarithm Problem
Jason H. M. Ying, Noboru Kunihiro |
ACNS | 2 |
| 2017 | Mis-operation Resistant Searchable Homomorphic EncryptionabstractLet us consider a scenario that a data holder (e.g., a hospital) encrypts a data (e.g., a medical record) which relates a keyword (e.g., a disease name), and sends its ciphertext to a server. We here suppose not only the data but also the keyword should be kept private. A receiver sends a query to the server (e.g., average of body weights of cancer patients). Then, the server performs the homomorphic operation to the ciphertexts of the corresponding medical records, and returns the resultant ciphertext. In this scenario, the server should NOT be allowed to perform the homomorphic operation against ciphertexts associated with different keywords. If such a mis-operation happens, then medical records of different diseases are unexpectedly mixed. However, in the conventional homomorphic encryption, there is no way to prevent such an unexpected homomorphic operation, and this fact may become visible after decrypting a ciphertext, or as the most serious case it might be never detected. To circumvent this problem, in this paper, we propose mis-operation resistant homomorphic encryption, where even if one performs the homomorphic operations against ciphertexts associated with keywords ω' and ω, where ω -ω', the evaluation algorithm detects this fact. Moreover, even if one (intentionally or accidentally) performs the homomorphic operations against such ciphertexts, a ciphertext associated with a random keyword is generated, and the decryption algorithm rejects it. So, the receiver can recognize such a mis-operation happens in the evaluation phase. In addition to mis-operation resistance, we additionally adopt secure search functionality for keywords since it is desirable when one would like to delegate homomorphic operations to a third party. So, we call the proposed primitive mis-operation resistant searchable homomorphic encryption (MR-SHE). We also give our implementation result of inner products of encrypted vectors. In the case when both vectors are encrypted, the running time of the receiver is millisecond order for relatively small-dimensional (e.g., 26) vectors. In the case when one vector is encrypted, the running time of the receiver is approximately 5 msec even for relatively high-dimensional (e.g., 213) vectors. Keita Emura, Takuya Hayashi 0001, Noboru Kunihiro, Jun Sakuma |
AsiaCCS | 3 |
| 2017 | Improved Key Recovery Algorithms from Noisy RSA Secret Keys with Analog Noise
Noboru Kunihiro, Yuki Takahashi |
CT-RSA | 1 |
| 2017 | A Tool Kit for Partial Key Exposure Attacks on RSA
Atsushi Takayasu, Noboru Kunihiro |
CT-RSA | 2 |
| 2017 | Self-Bilinear Map on Unknown Order Groups from Indistinguishability Obfuscation and Its Applications
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
Algorithmica | 4 |
| 2016 | Partial Key Exposure Attacks on RSA with Multiple Exponent Pairs
Atsushi Takayasu, Noboru Kunihiro |
ACISP (2) | 2 |
| 2016 | Generalized Hardness Assumption for Self-bilinear Map with Auxiliary Information
Takashi Yamakawa, Goichiro Hanaoka, Noboru Kunihiro |
ACISP (2) | 3 |
| 2016 | Adversary-Dependent Lossy Trapdoor Function from Hardness of Factoring Semi-smooth RSA Subgroup Moduli
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
CRYPTO (2) | 4 |
| 2016 | Small secret exponent attacks on RSA with unbalanced prime factors
Atsushi Takayasu, Noboru Kunihiro |
ISITA | 2 |
| 2016 | Partial Key Exposure Attacks on CRT-RSA: General Improvement for the Exposed Least Significant Bits
Atsushi Takayasu, Noboru Kunihiro |
ISC | 2 |
| 2016 | A limitation on security evaluation of cryptographic primitives with fixed keysabstractAbstract In this paper, we discuss security of public‐key cryptographic primitives in the case that the public key is fixed. In the standard argument, security of cryptographic primitives are evaluated by estimating the average probability of being successfully attacked where keys are treated as random variables. In contrast to this, in practice, a user is mostly interested in the security under his specific public key, which has been already fixed. However, it is obvious that such security cannot be mathematically guaranteed because for any given public key, there always potentially exists an adversary, which breaks its security. Therefore, the best what we can do is just to use a public key such that its effective adversary is not likely to be constructed in the real life and, thus, it is desired to provide a method for evaluating this possibility. The motivation of this work is to investigate (in)feasibility of predicting whether for a given fixed public key, its successful adversary will actually appear in the real life or not. As our main result, we prove that for any digital signature scheme or public key encryption scheme, it is impossible to reduce any fixed key adversary in any weaker security notion than the de facto ones (i.e., existential unforgery against adaptive chosen message attacks or indistinguishability against adaptive chosen ciphertext attacks) to fixed key adversaries in the de facto security notion in a black‐box manner. This result means that, for example, for any digital signature scheme, impossibility of extracting the secret key from a fixed public key will never imply existential unforgery against chosen message attacks under the same key as long as we consider only black‐box analysis. Copyright © 2016 John Wiley & Sons, Ltd. Yutaka Kawai, Goichiro Hanaoka, Kazuo Ohta, Noboru Kunihiro |
Secur. Commun. Networks | 4 |
| 2016 | Searchable symmetric encryption capable of searching for an arbitrary stringabstractAbstract A booming cloud service has made it possible to consider a third‐party server as private storage. When storage is used as a document archive, it is useful to provide functionality that allows users to find documents containing a specified string as a substring. The current method for providing such functionality while keeping the contents of the documents secret, either has linear complexity in the total size of the documents or needs to extract keywords when the documents are stored. Therefore, no method exists for efficiently searching for an arbitrary string that has not been extracted as a keyword. We propose the first encryption scheme that enables efficient searching for an arbitrary string. Although our scheme leaks some information for the sake of efficiency, all information leaked is derived from the precise leakage profile we have defined. © 2016 The Authors Security and Communication Networks Published by John Wiley & Sons Ltd Yoshinao Uchide, Noboru Kunihiro |
Secur. Commun. Networks | 2 |
| 2015 | Partial Key Exposure Attacks on CRT-RSA: Better Cryptanalysis to Full Size Encryption Exponents
Atsushi Takayasu, Noboru Kunihiro |
ACNS | 2 |
| 2015 | An Improved Attack for Recovering Noisy RSA Secret Keys and Its Countermeasure
Noboru Kunihiro |
ProvSec | 1 |
| 2015 | Private Information Retrieval with Preprocessing Based on the Approximate GCD Problem
Thomas Vannet, Noboru Kunihiro |
SAC | 2 |
| 2014 | Cryptanalysis of RSA with Multiple Small Secret Exponents
Atsushi Takayasu, Noboru Kunihiro |
ACISP | 2 |
| 2014 | RSA Meets DPA: Recovering RSA Secret Keys from Noisy Analog Data
Noboru Kunihiro, Junya Honda |
CHES | 1 |
| 2014 | Self-bilinear Map on Unknown Order Groups from Indistinguishability Obfuscation and Its Applications
Takashi Yamakawa, Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
CRYPTO (2) | 4 |
| 2014 | Constructing Subspace Membership Encryption through Inner Product Encryption
Shuichi Katsumata, Noboru Kunihiro |
ProvSec | 2 |
| 2014 | Partial Key Exposure Attacks on RSA: Achieving the Boneh-Durfee Bound
Atsushi Takayasu, Noboru Kunihiro |
Selected Areas in Cryptography | 2 |
| 2013 | Better Lattice Constructions for Solving Multivariate Linear Equations Modulo Unknown Divisors
Atsushi Takayasu, Noboru Kunihiro |
ACISP | 2 |
| 2013 | Reducing Public Key Sizes in Bounded CCA-Secure KEMs with Optimal Ciphertext Length
Takashi Yamakawa, Shota Yamada 0001, Takahiro Matsuda 0002, Goichiro Hanaoka, Noboru Kunihiro |
ISC | 5 |
| 2012 | Faster Algorithm for Solving Hard Knapsacks for Moderate Message Length
Yuji Nagashima, Noboru Kunihiro |
ACISP | 2 |
| 2012 | Optimal Bounds for Multi-Prime Φ-Hiding Assumption
Kaori Tosu, Noboru Kunihiro |
ACISP | 2 |
| 2012 | Generic Construction of Chosen Ciphertext Secure Proxy Re-Encryption
Goichiro Hanaoka, Yutaka Kawai, Noboru Kunihiro, Takahiro Matsuda 0002, Jian Weng 0001, Rui Zhang 0002, Yunlei Zhao |
CT-RSA | 3 |
| 2012 | Two-Dimensional Representation of Cover Free Families and Its Applications: Short Signatures and More
Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
CT-RSA | 3 |
| 2012 | Improving GGH cryptosystem for large error vector
Masayuki Yoshino, Noboru Kunihiro |
ISITA | 2 |
| 2012 | On Optimal Bounds of Small Inverse Problems and Approximate GCD Problems with Higher Degree
Noboru Kunihiro |
ISC | 1 |
| 2012 | Symmetric Inner-Product Predicate Encryption Based on Three Groups
Masayuki Yoshino, Noboru Kunihiro, Ken Naganuma, Hisayoshi Sato |
ProvSec | 2 |
| 2010 | Solving Generalized Small Inverse Problems
Noboru Kunihiro |
ACISP | 1 |
| 2010 | Toward an Easy-to-Understand Structure for Achieving Chosen Ciphertext Security from the Decisional Diffie-Hellman Assumption
Shota Yamada 0001, Goichiro Hanaoka, Noboru Kunihiro |
ProvSec | 3 |
| 2009 | Yet Another Sanitizable Signature from Bilinear MapsabstractThe sanitizable signature attracts much attention since it allows to modify the original document for hiding partial information with keeping the validity of the signature and the integrity of unmodified parts of the document. The sanitizable signature is quite useful in governmental or military offices where there is a dilemma between is closure laws for public documents and privacy or diplomatic secrets. This paper proposes two new sanitizable signature schemes from bilinear maps with a new structure. Tetsuya Izu, Noboru Kunihiro, Kazuo Ohta, Makoto Sano, Masahiko Takenaka |
ARES | 2 |
| 2008 | A strict evaluation method on the number of conditions for the SHA-1 collision searchabstractThis paper proposes a new algorithm for evaluating the number of chaining variable conditions(CVCs) in the selecting step of a distrubance vector (DV) for the analysis of SHA-1 collision attack. The algorithm is constructed by combining the following four strategies, Strict Bit Compression, DV expansion, Precise Counting Rules in Every Step and Differential Path Confirmation for Rounds 2 to 4, that can evaluate the number of CVCs morestrictly compared with the previous approach. Jun Yajima, Terutoshi Iwasaki, Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Shimoyama, Noboru Kunihiro, Kazuo Ohta |
AsiaCCS | 6 |
| 2008 | Small Secret Key Attack on a Variant of RSA (Due to Takagi)
Kouichi Itoh, Noboru Kunihiro, Kaoru Kurosawa |
CT-RSA | 2 |
| 2008 | Security of MD5 Challenge and Response: Extension of APOP Password Recovery Attack
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro |
CT-RSA | 4 |
| 2008 | New Key-Recovery Attacks on HMAC/NMAC-MD4 and NMAC-MD5
Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro |
EUROCRYPT | 3 |
| 2007 | A New Strategy for Finding a Differential Path of SHA-1
Jun Yajima, Yu Sasaki 0001, Yusuke Naito 0001, Terutoshi Iwasaki, Takeshi Shimoyama, Noboru Kunihiro, Kazuo Ohta |
ACISP | 6 |
| 2007 | New Message Difference for MD4
Yu Sasaki 0001, Lei Wang 0031, Kazuo Ohta, Noboru Kunihiro |
FSE | 4 |
| 2007 | A Sanitizable Signature Scheme with Aggregation
Tetsuya Izu, Noboru Kunihiro, Kazuo Ohta, Masahiko Takenaka, Takashi Yoshioka |
ISPEC | 2 |
| 2006 | Improved Collision Search for SHA-0
Yusuke Naito 0001, Yu Sasaki 0001, Takeshi Shimoyama, Jun Yajima, Noboru Kunihiro, Kazuo Ohta |
ASIACRYPT | 5 |
| 2006 | Problems on the MR micropayment schemesabstractWe discuss the security of the MR schemes and especially point out the vulnerability of the MR3 scheme. The probabilistic deposit mechanism utilized in the MR3 scheme contributes to the reduction of the bank's processing cost. However, as shown in our paper, it also decreases the security of the entire scheme. Masahiro Mambo, Moisés Salinas-Rosales, Kazuo Ohta, Noboru Kunihiro |
AsiaCCS | 4 |
| 1999 | Modulus Search for Elliptic Curve Cryptosystems
Kenji Koyama, Yukio Tsuruoka, Noboru Kunihiro |
ASIACRYPT | 3 |
| 1998 | Equivalence of Counting the Number of Points on Elliptic Curve over the Ring Zn and Factoring n
Noboru Kunihiro, Kenji Koyama |
EUROCRYPT | 1 |