Céline Chevalier

dblp:61/1937 · DBLP profile ↗
← Back
38ranked-venue papers
10as first author
17since 2021 · last 2026
0009-0006-4231-4958ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 32 · 7 first-author · 14 since 2021Theory of computation · 6 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 DAKE: Bandwidth-Efficient (U)AKE from Double-KEM
Hugo Beguinet, Céline Chevalier, Guirec Lebrun, Thomas Legavre, Thomas Ricosset, Maxime Roméas, Éric Sageloli
PKC (4)2
2025 Spilling-Cascade: An Optimal PKE Combiner for KEM Hybridization
Céline Chevalier, Guirec Lebrun, Ange Martinelli
ACNS (1)1
2025 Cryptographic Commitments on Anonymizable Data
abstract
Local Differential Privacy (LDP) mechanisms consist of (locally) adding controlled noise to data in order to protect the privacy of their owner. In this paper, we introduce a new cryptographic primitive called LDP commitment. Usually, a commitment ensures that the committed value cannot be modified before it is revealed. In the case of an LDP commitment, however, the value is revealed after being perturbed by an LDP mechanism. Opening an LDP commitment therefore requires a proof that the mechanism has been correctly applied to the value, to ensure that the value is still usable for statistical purposes. We also present a security model for this primitive, in which we define the hiding and binding properties. Finally, we present a concrete scheme for an LDP staircase mechanism (generalizing the randomized response technique), based on classical cryptographic tools and standard assumptions. We provide an implementation in Rust that demonstrates its practical efficiency (the generation of a commitment requires just a few milliseconds).On the application side, we show how our primitive can be used to ensure simultaneously privacy, usability and traceability of medical data when it is used for statistical studies in an open science context. We consider a scenario where a hospital provides sensitive patients data signed by doctors to a research center after it has been anonymized, so that the research center can verify both the provenance of the data (i.e. verify the doctors’ signatures even though the data has been noised) and that the data has been correctly anonymized (i.e. is usable even though it has been anonymized).
Xavier Bultel, Céline Chevalier, Charlène Jojon, Diandian Liu, Benjamin Nguyen
EuroS&P2
2025 The Art of Bonsai: How Well-Shaped Trees Improve the Communication Cost of MLS
abstract
Messaging Layer Security (MLS) is a Secure Group Messaging protocol that uses for its handshake a binary tree – called a Ratchet Tree – in order to reach a logarithmic communication cost in the number of group members. This Ratchet Tree represents users as its leaves; therefore any change in the group membership results in adding or removing a leaf in the tree. MLS consequently implements what we call a tree evolution mechanism, consisting of a user add algorithm – determining where to insert a new leaf – and a tree expansion process – stating how to increase the size of the tree when no space is available for a new user. The tree evolution mechanism currently used by MLS is designed so that it naturally left-balances the Ratchet Tree. However, such a tree structure is often quite inefficient in terms of communication cost. Furthermore, one may wonder whether the binary Ratchet Tree has a degree optimized for the features of MLS.Therefore, we study in this paper how to improve the communication cost of the handshake in MLS – realized through an operation called a commit – by considering both the tree evolution mechanism and the tree degree used for the Ratchet Tree. To do so, we determine the tree structure that optimizes its communication cost and we propose algorithms for both the user add and the tree expansion processes, that allow to remain close to that optimal structure and thus to have a communication cost as close as possible to the optimum. We also find out the Ratchet Tree degree that is best suited to a given set of parameters induced by the encryption scheme used by MLS. This study shows that when using classical (i.e. pre-quantum) ciphersuites, a binary tree is indeed the most appropriate Ratchet Tree; nevertheless, with post-quantum algorithms, it generally becomes more interesting to use instead a ternary tree.Our improvements do not change the TreeKEM protocol and are easy to implement. With parameter sets corresponding to practical ciphersuites, they reduce TreeKEM’s communication cost by 5 to 10%. In particular, the gain of 10% appears in the post-quantum setting – when both an optimized tree evolution mechanism and a ternary tree are necessary –, which is precisely the context where any optimization of the protocol’s communication cost is welcome, due to the large bandwidth of PQ encrypted communication.
Céline Chevalier, Guirec Lebrun, Ange Martinelli, Jérôme Plût
EuroS&P1
2025 On security notions for encryption in a quantum world
Céline Chevalier, Ehsan Ebrahimi 0001, Quoc-Huy Vu
Des. Codes Cryptogr.1
2024 Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive Users
abstract
The recently standardized secure group messaging protocol Messaging Layer Security (MLS) is designed to ensure asynchronous communications within large groups, with an almost-optimal communication cost and the same security level as point-to-point secure messaging protocols such as Signal. In particular, the core sub-protocol of MLS, a Continuous Group Key Agreement (CGKA) called TreeKEM, must generate a common group key that respects the fundamental security properties of post-compromise security and forward secrecy which mitigate the effects of user corruption over time
Céline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman Taleb
CCS1
2023 Efficient Implementation of a Post-Quantum Anonymous Credential Protocol
abstract
Authentication on the Internet usually has the drawback of leaking the identity of the users, or at least allowing to trace them from a server to another. Anonymous credentials overcome this issue, by allowing users to reveal the attributes necessary for the authentication, without revealing any other information (in particular not their identity). In this article, we provide a generic framework to construct anonymous credential schemes and use it to give a concrete construction of post-quantum (lattice-based) anonymous credential protocol. Our protocol thus allows for long-term security even when one considers the emergence of quantum computers able to break widely used traditional computational assumptions, such as RSA, the discrete logarithm or Diffie-Hellman. We also give a concrete implementation of our protocol, which is only one order of magnitude slower and bandwidth consuming than previous anonymous credentials that are not post-quantum.
Olivier Blazy, Céline Chevalier, Guillaume Renaut, Thomas Ricosset, Éric Sageloli, Hugo Senet
ARES2
2023 GeT a CAKE: Generic Transformations from Key Encaspulation Mechanisms to Password Authenticated Key Exchanges
Hugo Beguinet, Céline Chevalier, David Pointcheval, Thomas Ricosset, Melissa Rossi
ACNS2
2023 Shorter and Faster Identity-Based Signatures with Tight Security in the (Q)ROM from Lattices
Éric Sageloli, Pierre Pébereau, Pierrick Méaux, Céline Chevalier
ACNS (1)4
2023 Practical Construction for Secure Trick-Taking Games Even with Cards Set Aside
Rohann Bella, Xavier Bultel, Céline Chevalier, Pascal Lafourcade 0001, Charles Olivier-Anclin
FC (1)3
2023 Semi-quantum Copy-Protection and More
Céline Chevalier, Paul Hermouet, Quoc-Huy Vu
TCC (4)1
2023 Formal Verification of a Post-quantum Signal Protocol with Tamarin
Hugo Beguinet, Céline Chevalier, Thomas Ricosset, Hugo Senet
VECoS2
2022 Embedding the UC Model into the IITM Model
Daniel Rausch 0001, Ralf Küsters, Céline Chevalier
EUROCRYPT (2)3
2022 Dispelling myths on superposition attacks: formal security model and attack analyses
Luka Music, Céline Chevalier, Elham Kashefi
Des. Codes Cryptogr.2
2022 Correction to: Dispelling myths on superposition attacks: formal security model and attack analyses
Luka Music, Céline Chevalier, Elham Kashefi
Des. Codes Cryptogr.2
2021 Privately Outsourcing Exponentiation to a Single Server: Cryptanalysis and Optimal Constructions
Céline Chevalier, Fabien Laguillaumie, Damien Vergnaud
Algorithmica1
2021 Hardware security without secure hardware: How to decrypt with a password and a server
Olivier Blazy, Laura Brouilhet, Céline Chevalier, Patrick Towa, Ida Tucker, Damien Vergnaud
Theor. Comput. Sci.3
2020 Dispelling Myths on Superposition Attacks: Formal Security Model and Attack Analyses
Luka Music, Céline Chevalier, Elham Kashefi
ProvSec2
2020 Converting networks to predictive logic models from perturbation signalling data with CellNOpt
abstract
SUMMARY: The molecular changes induced by perturbations such as drugs and ligands are highly informative of the intracellular wiring. Our capacity to generate large datasets is increasing steadily. A useful way to extract mechanistic insight from the data is by integrating them with a prior knowledge network of signalling to obtain dynamic models. CellNOpt is a collection of Bioconductor R packages for building logic models from perturbation data and prior knowledge of signalling networks. We have recently developed new components and refined the existing ones to keep up with the computational demand of increasingly large datasets, including (i) an efficient integer linear programming, (ii) a probabilistic logic implementation for semi-quantitative datasets, (iii) the integration of a stochastic Boolean simulator, (iv) a tool to identify missing links, (v) systematic post-hoc analyses and (vi) an R-Shiny tool to run CellNOpt interactively. AVAILABILITY AND IMPLEMENTATION: R-package(s): https://github.com/saezlab/cellnopt. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online.
Enio Gjerga, Panuwat Trairatphisan, Attila Gábor, Hermann Koch, Céline Chevalier, Franceco Ceccarelli, Aurélien Dugourd, Alexander Mitsos, Julio Saez-Rodriguez, Jonathan D. Wren
Bioinform.5
2019 Post-Quantum UC-Secure Oblivious Transfer in the Standard Model with Adaptive Corruptions
abstract
Since the seminal result of Kilian, Oblivious Transfer (OT) has proven to be a fundamental primitive in cryptography. In such a scheme, a user is able to gain access to an element owned by a server, without learning more than this single element, and without the server learning which element the user has accessed. The NIST call for post-quantum encryption and signature schemes has revived the interest for cryptographic protocols based on post-quantum assumptions and the need for secure post-quantum OT schemes. In this paper, we show how to construct an OT scheme based on lattices, from a collision-resistant chameleon hash scheme (CH) and a CCA encryption scheme accepting a smooth projective hash function (SPHF). Note that our scheme does not rely on random oracles and provides UC security against adaptive corruptions assuming reliable erasures.
Olivier Blazy, Céline Chevalier, Quoc-Huy Vu
ARES2
2018 Non-Interactive Key Exchange from Identity-Based Encryption
abstract
Since the seminal work of Diffie and Hellman [19], Non-Interactive Key Exchange (NIKE) has become one of the fundamental problems of modern cryptography, but additional security requirements have led to elaborated ad-hoc constructions, which often lack simplicity in their design. In particular, Identity-Based NIKE is still a major problem with few available constructions, and those ad-hoc constructions do not give a lot of insight on what is required to be able to achieve such a NIKE scheme only based on the identity (and not relying on the public-key setting).
Olivier Blazy, Céline Chevalier
ARES2
2018 Spreading Alerts Quietly: New Insights from Theory and Practice
abstract
With the emergence of the Internet of things and of electronic home health-care, more and more sensitive signals are transiting over easily accessible wireless networks. It has become an important task to manage to spread alerts on a wireless network at the same time as to hide the nature of these signals, in a secure and efficient way. No one (an adversarial observer or even the node transmitting the signal) should be able to learn whether a signal corresponds to an alert or a normal echo. Blind Coupon Mechanism is a primitive proposed at Asiacrypt 2005 that allows to spread such alerts quietly and quickly. In this paper, we propose to strengthen their security model and we give a concrete solution which is both more secure and more efficient than the protocol originally proposed.
Olivier Blazy, Céline Chevalier
ARES2
2017 Almost Optimal Oblivious Transfer from QA-NIZK
Olivier Blazy, Céline Chevalier, Paul Germouty
ACNS2
2016 Structure-Preserving Smooth Projective Hashing
Olivier Blazy, Céline Chevalier
ASIACRYPT (2)2
2016 Adaptive Oblivious Transfer and Generalization
Olivier Blazy, Céline Chevalier, Paul Germouty
ASIACRYPT (2)2
2016 Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions
Olivier Blazy, Céline Chevalier, Damien Vergnaud
CT-RSA2
2016 Privately Outsourcing Exponentiation to a Single Server: Cryptanalysis and Optimal Constructions
Céline Chevalier, Fabien Laguillaumie, Damien Vergnaud
ESORICS (1)1
2015 Generic Construction of UC-Secure Oblivious Transfer
Olivier Blazy, Céline Chevalier
ACNS2
2015 Non-Interactive Zero-Knowledge Proofs of Non-Membership
Olivier Blazy, Céline Chevalier, Damien Vergnaud
CT-RSA2
2013 Analysis and Improvement of Lindell's UC-Secure Commitment Schemes
Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
ACNS2
2013 SPHF-Friendly Non-interactive Commitments
Michel Abdalla, Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval
ASIACRYPT (1)4
2013 New Techniques for SPHFs and Efficient One-Round PAKE Protocols
Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud
CRYPTO (1)3
2013 Composition of password-based protocols
Céline Chevalier, Stéphanie Delaune, Steve Kremer, Mark Ryan 0001
Formal Methods Syst. Des.1
2011 Contributory Password-Authenticated Group Key Exchange with Join Capability
Michel Abdalla, Céline Chevalier, Louis Granboulan, David Pointcheval
CT-RSA2
2011 Transforming Password Protocols to Compose
abstract
Formal, symbolic techniques are extremely useful for modelling and analysing security protocols. They improved our understanding of security protocols, allowed to discover flaws, and also provide support for protocol design. However, such analyses usually consider that the protocol is executed in isolation or assume a bounded number of protocol sessions. Hence, no security guarantee is provided when the protocol is executed in a more complex environment. In this paper, we study whether password protocols can be safely composed, even when a same password is reused. More precisely, we present a transformation which maps a password protocol that is secure for a single protocol session (a decidable problem) to a protocol that is secure for an unbounded number of sessions. Our result provides an effective strategy to design secure password protocols: (i) design a protocol intended to be secure for one protocol session; (ii) apply our transformation and obtain a protocol which is secure for an unbounded number of sessions. Our technique also applies to compose different password protocols allowing us to obtain both inter-protocol and inter-session composition.
Céline Chevalier, Stéphanie Delaune, Steve Kremer
FSTTCS1
2009 Smooth Projective Hashing for Conditionally Extractable Commitments
Michel Abdalla, Céline Chevalier, David Pointcheval
CRYPTO2
2009 Optimal Randomness Extraction from a Diffie-Hellman Element
Céline Chevalier, Pierre-Alain Fouque, David Pointcheval, Sébastien Zimmer
EUROCRYPT1
2008 Efficient Two-Party Password-Based Key Exchange Protocols in the UC Framework
Michel Abdalla, Dario Catalano, Céline Chevalier, David Pointcheval
CT-RSA3