EDBT 2026 Demo / reviewers in the wild / expert
Céline Chevalier
dblp:61/1937
· DBLP profile ↗
38ranked-venue papers
10as first author
17since 2021 · last 2026
0009-0006-4231-4958ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 32 · 7 first-author · 14 since 2021Theory of computation · 6 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DAKE: Bandwidth-Efficient (U)AKE from Double-KEM
Hugo Beguinet, Céline Chevalier, Guirec Lebrun, Thomas Legavre, Thomas Ricosset, Maxime Roméas, Éric Sageloli |
PKC (4) | 2 |
| 2025 | Spilling-Cascade: An Optimal PKE Combiner for KEM Hybridization
Céline Chevalier, Guirec Lebrun, Ange Martinelli |
ACNS (1) | 1 |
| 2025 | Cryptographic Commitments on Anonymizable DataabstractLocal Differential Privacy (LDP) mechanisms consist of (locally) adding controlled noise to data in order to protect the privacy of their owner. In this paper, we introduce a new cryptographic primitive called LDP commitment. Usually, a commitment ensures that the committed value cannot be modified before it is revealed. In the case of an LDP commitment, however, the value is revealed after being perturbed by an LDP mechanism. Opening an LDP commitment therefore requires a proof that the mechanism has been correctly applied to the value, to ensure that the value is still usable for statistical purposes. We also present a security model for this primitive, in which we define the hiding and binding properties. Finally, we present a concrete scheme for an LDP staircase mechanism (generalizing the randomized response technique), based on classical cryptographic tools and standard assumptions. We provide an implementation in Rust that demonstrates its practical efficiency (the generation of a commitment requires just a few milliseconds).On the application side, we show how our primitive can be used to ensure simultaneously privacy, usability and traceability of medical data when it is used for statistical studies in an open science context. We consider a scenario where a hospital provides sensitive patients data signed by doctors to a research center after it has been anonymized, so that the research center can verify both the provenance of the data (i.e. verify the doctors’ signatures even though the data has been noised) and that the data has been correctly anonymized (i.e. is usable even though it has been anonymized). Xavier Bultel, Céline Chevalier, Charlène Jojon, Diandian Liu, Benjamin Nguyen |
EuroS&P | 2 |
| 2025 | The Art of Bonsai: How Well-Shaped Trees Improve the Communication Cost of MLSabstractMessaging Layer Security (MLS) is a Secure Group Messaging protocol that uses for its handshake a binary tree – called a Ratchet Tree – in order to reach a logarithmic communication cost in the number of group members. This Ratchet Tree represents users as its leaves; therefore any change in the group membership results in adding or removing a leaf in the tree. MLS consequently implements what we call a tree evolution mechanism, consisting of a user add algorithm – determining where to insert a new leaf – and a tree expansion process – stating how to increase the size of the tree when no space is available for a new user. The tree evolution mechanism currently used by MLS is designed so that it naturally left-balances the Ratchet Tree. However, such a tree structure is often quite inefficient in terms of communication cost. Furthermore, one may wonder whether the binary Ratchet Tree has a degree optimized for the features of MLS.Therefore, we study in this paper how to improve the communication cost of the handshake in MLS – realized through an operation called a commit – by considering both the tree evolution mechanism and the tree degree used for the Ratchet Tree. To do so, we determine the tree structure that optimizes its communication cost and we propose algorithms for both the user add and the tree expansion processes, that allow to remain close to that optimal structure and thus to have a communication cost as close as possible to the optimum. We also find out the Ratchet Tree degree that is best suited to a given set of parameters induced by the encryption scheme used by MLS. This study shows that when using classical (i.e. pre-quantum) ciphersuites, a binary tree is indeed the most appropriate Ratchet Tree; nevertheless, with post-quantum algorithms, it generally becomes more interesting to use instead a ternary tree.Our improvements do not change the TreeKEM protocol and are easy to implement. With parameter sets corresponding to practical ciphersuites, they reduce TreeKEM’s communication cost by 5 to 10%. In particular, the gain of 10% appears in the post-quantum setting – when both an optimized tree evolution mechanism and a ternary tree are necessary –, which is precisely the context where any optimization of the protocol’s communication cost is welcome, due to the large bandwidth of PQ encrypted communication. Céline Chevalier, Guirec Lebrun, Ange Martinelli, Jérôme Plût |
EuroS&P | 1 |
| 2025 | On security notions for encryption in a quantum world
Céline Chevalier, Ehsan Ebrahimi 0001, Quoc-Huy Vu |
Des. Codes Cryptogr. | 1 |
| 2024 | Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersabstractThe recently standardized secure group messaging protocol Messaging Layer Security (MLS) is designed to ensure asynchronous communications within large groups, with an almost-optimal communication cost and the same security level as point-to-point secure messaging protocols such as Signal. In particular, the core sub-protocol of MLS, a Continuous Group Key Agreement (CGKA) called TreeKEM, must generate a common group key that respects the fundamental security properties of post-compromise security and forward secrecy which mitigate the effects of user corruption over time Céline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman Taleb |
CCS | 1 |
| 2023 | Efficient Implementation of a Post-Quantum Anonymous Credential ProtocolabstractAuthentication on the Internet usually has the drawback of leaking the identity of the users, or at least allowing to trace them from a server to another. Anonymous credentials overcome this issue, by allowing users to reveal the attributes necessary for the authentication, without revealing any other information (in particular not their identity). In this article, we provide a generic framework to construct anonymous credential schemes and use it to give a concrete construction of post-quantum (lattice-based) anonymous credential protocol. Our protocol thus allows for long-term security even when one considers the emergence of quantum computers able to break widely used traditional computational assumptions, such as RSA, the discrete logarithm or Diffie-Hellman. We also give a concrete implementation of our protocol, which is only one order of magnitude slower and bandwidth consuming than previous anonymous credentials that are not post-quantum. Olivier Blazy, Céline Chevalier, Guillaume Renaut, Thomas Ricosset, Éric Sageloli, Hugo Senet |
ARES | 2 |
| 2023 | GeT a CAKE: Generic Transformations from Key Encaspulation Mechanisms to Password Authenticated Key Exchanges
Hugo Beguinet, Céline Chevalier, David Pointcheval, Thomas Ricosset, Melissa Rossi |
ACNS | 2 |
| 2023 | Shorter and Faster Identity-Based Signatures with Tight Security in the (Q)ROM from Lattices
Éric Sageloli, Pierre Pébereau, Pierrick Méaux, Céline Chevalier |
ACNS (1) | 4 |
| 2023 | Practical Construction for Secure Trick-Taking Games Even with Cards Set Aside
Rohann Bella, Xavier Bultel, Céline Chevalier, Pascal Lafourcade 0001, Charles Olivier-Anclin |
FC (1) | 3 |
| 2023 | Semi-quantum Copy-Protection and More
Céline Chevalier, Paul Hermouet, Quoc-Huy Vu |
TCC (4) | 1 |
| 2023 | Formal Verification of a Post-quantum Signal Protocol with Tamarin
Hugo Beguinet, Céline Chevalier, Thomas Ricosset, Hugo Senet |
VECoS | 2 |
| 2022 | Embedding the UC Model into the IITM Model
Daniel Rausch 0001, Ralf Küsters, Céline Chevalier |
EUROCRYPT (2) | 3 |
| 2022 | Dispelling myths on superposition attacks: formal security model and attack analyses
Luka Music, Céline Chevalier, Elham Kashefi |
Des. Codes Cryptogr. | 2 |
| 2022 | Correction to: Dispelling myths on superposition attacks: formal security model and attack analyses
Luka Music, Céline Chevalier, Elham Kashefi |
Des. Codes Cryptogr. | 2 |
| 2021 | Privately Outsourcing Exponentiation to a Single Server: Cryptanalysis and Optimal Constructions
Céline Chevalier, Fabien Laguillaumie, Damien Vergnaud |
Algorithmica | 1 |
| 2021 | Hardware security without secure hardware: How to decrypt with a password and a server
Olivier Blazy, Laura Brouilhet, Céline Chevalier, Patrick Towa, Ida Tucker, Damien Vergnaud |
Theor. Comput. Sci. | 3 |
| 2020 | Dispelling Myths on Superposition Attacks: Formal Security Model and Attack Analyses
Luka Music, Céline Chevalier, Elham Kashefi |
ProvSec | 2 |
| 2020 | Converting networks to predictive logic models from perturbation signalling data with CellNOptabstractSUMMARY: The molecular changes induced by perturbations such as drugs and ligands are highly informative of the intracellular wiring. Our capacity to generate large datasets is increasing steadily. A useful way to extract mechanistic insight from the data is by integrating them with a prior knowledge network of signalling to obtain dynamic models. CellNOpt is a collection of Bioconductor R packages for building logic models from perturbation data and prior knowledge of signalling networks. We have recently developed new components and refined the existing ones to keep up with the computational demand of increasingly large datasets, including (i) an efficient integer linear programming, (ii) a probabilistic logic implementation for semi-quantitative datasets, (iii) the integration of a stochastic Boolean simulator, (iv) a tool to identify missing links, (v) systematic post-hoc analyses and (vi) an R-Shiny tool to run CellNOpt interactively. AVAILABILITY AND IMPLEMENTATION: R-package(s): https://github.com/saezlab/cellnopt. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Enio Gjerga, Panuwat Trairatphisan, Attila Gábor, Hermann Koch, Céline Chevalier, Franceco Ceccarelli, Aurélien Dugourd, Alexander Mitsos, Julio Saez-Rodriguez, Jonathan D. Wren |
Bioinform. | 5 |
| 2019 | Post-Quantum UC-Secure Oblivious Transfer in the Standard Model with Adaptive CorruptionsabstractSince the seminal result of Kilian, Oblivious Transfer (OT) has proven to be a fundamental primitive in cryptography. In such a scheme, a user is able to gain access to an element owned by a server, without learning more than this single element, and without the server learning which element the user has accessed. The NIST call for post-quantum encryption and signature schemes has revived the interest for cryptographic protocols based on post-quantum assumptions and the need for secure post-quantum OT schemes. In this paper, we show how to construct an OT scheme based on lattices, from a collision-resistant chameleon hash scheme (CH) and a CCA encryption scheme accepting a smooth projective hash function (SPHF). Note that our scheme does not rely on random oracles and provides UC security against adaptive corruptions assuming reliable erasures. Olivier Blazy, Céline Chevalier, Quoc-Huy Vu |
ARES | 2 |
| 2018 | Non-Interactive Key Exchange from Identity-Based EncryptionabstractSince the seminal work of Diffie and Hellman [19], Non-Interactive Key Exchange (NIKE) has become one of the fundamental problems of modern cryptography, but additional security requirements have led to elaborated ad-hoc constructions, which often lack simplicity in their design. In particular, Identity-Based NIKE is still a major problem with few available constructions, and those ad-hoc constructions do not give a lot of insight on what is required to be able to achieve such a NIKE scheme only based on the identity (and not relying on the public-key setting). Olivier Blazy, Céline Chevalier |
ARES | 2 |
| 2018 | Spreading Alerts Quietly: New Insights from Theory and PracticeabstractWith the emergence of the Internet of things and of electronic home health-care, more and more sensitive signals are transiting over easily accessible wireless networks. It has become an important task to manage to spread alerts on a wireless network at the same time as to hide the nature of these signals, in a secure and efficient way. No one (an adversarial observer or even the node transmitting the signal) should be able to learn whether a signal corresponds to an alert or a normal echo. Blind Coupon Mechanism is a primitive proposed at Asiacrypt 2005 that allows to spread such alerts quietly and quickly. In this paper, we propose to strengthen their security model and we give a concrete solution which is both more secure and more efficient than the protocol originally proposed. Olivier Blazy, Céline Chevalier |
ARES | 2 |
| 2017 | Almost Optimal Oblivious Transfer from QA-NIZK
Olivier Blazy, Céline Chevalier, Paul Germouty |
ACNS | 2 |
| 2016 | Structure-Preserving Smooth Projective Hashing
Olivier Blazy, Céline Chevalier |
ASIACRYPT (2) | 2 |
| 2016 | Adaptive Oblivious Transfer and Generalization
Olivier Blazy, Céline Chevalier, Paul Germouty |
ASIACRYPT (2) | 2 |
| 2016 | Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions
Olivier Blazy, Céline Chevalier, Damien Vergnaud |
CT-RSA | 2 |
| 2016 | Privately Outsourcing Exponentiation to a Single Server: Cryptanalysis and Optimal Constructions
Céline Chevalier, Fabien Laguillaumie, Damien Vergnaud |
ESORICS (1) | 1 |
| 2015 | Generic Construction of UC-Secure Oblivious Transfer
Olivier Blazy, Céline Chevalier |
ACNS | 2 |
| 2015 | Non-Interactive Zero-Knowledge Proofs of Non-Membership
Olivier Blazy, Céline Chevalier, Damien Vergnaud |
CT-RSA | 2 |
| 2013 | Analysis and Improvement of Lindell's UC-Secure Commitment Schemes
Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud |
ACNS | 2 |
| 2013 | SPHF-Friendly Non-interactive Commitments
Michel Abdalla, Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval |
ASIACRYPT (1) | 4 |
| 2013 | New Techniques for SPHFs and Efficient One-Round PAKE Protocols
Fabrice Benhamouda, Olivier Blazy, Céline Chevalier, David Pointcheval, Damien Vergnaud |
CRYPTO (1) | 3 |
| 2013 | Composition of password-based protocols
Céline Chevalier, Stéphanie Delaune, Steve Kremer, Mark Ryan 0001 |
Formal Methods Syst. Des. | 1 |
| 2011 | Contributory Password-Authenticated Group Key Exchange with Join Capability
Michel Abdalla, Céline Chevalier, Louis Granboulan, David Pointcheval |
CT-RSA | 2 |
| 2011 | Transforming Password Protocols to ComposeabstractFormal, symbolic techniques are extremely useful for modelling and analysing security protocols. They improved our understanding of security protocols, allowed to discover flaws, and also provide support for protocol design. However, such analyses usually consider that the protocol is executed in isolation or assume a bounded number of protocol sessions. Hence, no security guarantee is provided when the protocol is executed in a more complex environment. In this paper, we study whether password protocols can be safely composed, even when a same password is reused. More precisely, we present a transformation which maps a password protocol that is secure for a single protocol session (a decidable problem) to a protocol that is secure for an unbounded number of sessions. Our result provides an effective strategy to design secure password protocols: (i) design a protocol intended to be secure for one protocol session; (ii) apply our transformation and obtain a protocol which is secure for an unbounded number of sessions. Our technique also applies to compose different password protocols allowing us to obtain both inter-protocol and inter-session composition. Céline Chevalier, Stéphanie Delaune, Steve Kremer |
FSTTCS | 1 |
| 2009 | Smooth Projective Hashing for Conditionally Extractable Commitments
Michel Abdalla, Céline Chevalier, David Pointcheval |
CRYPTO | 2 |
| 2009 | Optimal Randomness Extraction from a Diffie-Hellman Element
Céline Chevalier, Pierre-Alain Fouque, David Pointcheval, Sébastien Zimmer |
EUROCRYPT | 1 |
| 2008 | Efficient Two-Party Password-Based Key Exchange Protocols in the UC Framework
Michel Abdalla, Dario Catalano, Céline Chevalier, David Pointcheval |
CT-RSA | 3 |