EDBT 2026 Demo / reviewers in the wild / expert
Junji Shikata
dblp:65/4968
· DBLP profile ↗
61ranked-venue papers
7as first author
19since 2021 · last 2025
0000-0003-2861-359XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 4 first-author · 14 since 2021Theory of computation · 7 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-authorComputer networks · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Bounded CCA2-Secure Proxy Re-encryption from Lattices
Shingo Sato, Junji Shikata |
SAC | 2 |
| 2025 | Lightweight Yet Nonce-Misuse Secure Authenticated Encryption for Very Short InputsabstractWe study authenticated encryption (AE) modes dedicated to very short messages, which are crucial for Internet of Things applications. One of the most popular class of AE is built on block ciphers, namely a mode of operation. The computational cost of a mode is typically measured by its rate, indicating the number of input blocks processed per block cipher call in asymptotic terms. While certain modes demonstrate efficiency in terms of rate, such as$\mathsf { OCB}$, this metric does not always accurately portray the total computational burden as it ignores overhead. Consequently, modes efficient in terms of rate may not always perform optimally with short messages. This observation motivates us to study modes that are efficient on short inputs rather than focusing on rate. Since the existing general-purpose AE modes need at least three block cipher calls for nonempty messages, we explore the design space for AE modes that use at most two calls. We propose a family of AE modes, dubbed$ \mathsf {Manx}$, which work when the total input length is less than$2n$bits, using an n-bit block cipher. Notably, the second construction of$ \mathsf {Manx}$can encrypt almost n-bit plaintexts and saves one or two block cipher calls compared to standard modes, such as$\mathsf { GCM}$or$\mathsf { OCB}$, while preserving comparable provable security. In addition to the conventional security against nonce-respecting adversary, we prove that$ \mathsf {Manx}$have security against nonce-misusing adversary with a different security level for each family member. We also present benchmarks on popular 8/32-bit microprocessors, namely 8-bit AVR, 32-bit ARM Cortex-M0, and ARM Cortex-M4, using AES and lightweight block ciphers. Our results show the clear advantage of$ \mathsf {Manx}$over the previous modes for such short messages. In particular,$ \mathsf {Manx2}$has significant performance gain from the existing representative schemes thanks to the simple structure and parallelizability. For example, using AES-128,$ \mathsf {Manx2}$is faster than$\mathsf { OCB}$by a factor of 1.5 to 1.7 to process a 64-bit nonce and a 120-bit plaintext. Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata |
IEEE Internet Things J. | 3 |
| 2024 | How to Apply Fujisaki-Okamoto Transformation to Registration-Based Encryption
Sohto Chiku, Keisuke Hara, Keitaro Hashimoto, Toi Tomita, Junji Shikata |
CANS (2) | 5 |
| 2024 | Compact Post-quantum Bounded-Collusion Identity-Based Encryption
Shingo Sato, Junji Shikata |
CANS (1) | 2 |
| 2024 | How to Accomplish Key and Communication Compression Over Authentication Channels - Proxy Re-authentication and Its Instantiations
Yoshiro Matsuoka, Sohto Chiku, Keisuke Hara, Junji Shikata |
NSS | 4 |
| 2024 | Efficient Identity-Based Encryption with Tight Adaptive Anonymity from RLWE
Toi Tomita, Junji Shikata |
PQCrypto (1) | 2 |
| 2024 | Interactive aggregate message authentication equipped with detecting functionality from adaptive group testing
Kazuhiko Minematsu, Shingo Sato, Junji Shikata |
Des. Codes Cryptogr. | 3 |
| 2023 | Anonymous Broadcast Authentication with Logarithmic-Order Ciphertexts from LWE
Yoshinori Aono, Junji Shikata |
CANS | 2 |
| 2023 | Authenticated Encryption for Very Short Inputs
Alexandre Adomnicai, Kazuhiko Minematsu, Junji Shikata |
CT-RSA | 3 |
| 2023 | Chosen Ciphertext Security for Blind Identity-Based Encryption with Certified Identities
Sohto Chiku, Keisuke Hara, Junji Shikata |
ISPEC | 3 |
| 2023 | IoT-REX: A Secure Remote-Control System for IoT Devices from Centralized Multi-designated Verifier Signatures
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata |
ISPEC | 3 |
| 2023 | Group-Testing Aggregate Entity AuthenticationabstractChallenge-response entity authentication can be implemented with a MAC function. In such an entity authentication scheme, if a server has to authenticate a large number of entities simultaneously, for example, in an IoT network, aggregate MAC is applicable. Aggregate MAC allows multiple tags (responses to the challenge) of entities to be aggregated into a single short tag so that the server can authenticate the entities only with it. If the pair of a challenge and the corresponding aggregate tag is valid, then all the involved entities are valid. However, a drawback of this method is that the server cannot identify invalid entities if they exist. We propose group-testing aggregate entity authentication by adapting group testing for entity authentication using aggregate MAC to solve this problem. We formalize its security requirements and reduces the security of our generic construction to that of aggregate MAC and group testing. We also extend our generic construction to produce a secure scheme from a weaker but efficient and plausible aggregate MAC scheme. Shoichi Hirose, Junji Shikata |
ITW | 2 |
| 2023 | A Tightly Secure Identity-Based Signature Scheme from Isogenies
Hyungrok Jo, Shingo Sato, Junji Shikata |
PQCrypto | 4 |
| 2023 | Identity-Based Matchmaking Encryption Secure Against Key Generation Center
Sohto Chiku, Keisuke Hara, Junji Shikata |
ProvSec | 3 |
| 2023 | Tight lower bounds and optimal constructions of anonymous broadcast encryption and authenticationabstractAbstract Broadcast Encryption (BE) is public-key encryption allowing a sender to encrypt a message by specifing recipients, and only the specified recipients can decrypt the message. In several BE applications, since the privacy of recipients allowed to access the message is often as important as the confidentiality of the message, anonymity is introduced as an additional but important security requirement for BE. Kiayias and Samari (IH 2013) presented an asymptotic lower bound on the ciphertext sizes in BE schemes satisfying anonymity (ANO-BE for short). More precisely, their lower bound is derived under the assumption that ANO-BE schemes have a special property. However, it is insufficient to show their lower bound is asymptotically tight since it is unclear whether existing ANO-BE schemes meet the special property. In this work, we derive asymptotically tight lower bounds on the ciphertext size in ANO-BE by assuming only properties that most existing ANO-BE schemes satisfy. With a similar technique, we first derive asymptoticallyPlease provide MSC codes. For more details, please visit http://www.ams.org/msc/. tight lower bounds on the authenticator sizes in Anonymous Broadcast Authentication (ABA). Furthermore, we extend the above result and present (non-asymptotically) tight lower and upper bounds on thePlease check and confirm the Running title. ciphertext sizes in ANO-BE. We show that a variant of ANO-BE scheme proposed by Li and Gong (ACNS 2018) is optimal. We also provide tight bounds on the authenticator sizes in ABA via the same approach as ANO-BE, and propose an optimal construction for ABA. Hirokazu Kobayashi, Yohei Watanabe 0001, Kazuhiko Minematsu, Junji Shikata |
Des. Codes Cryptogr. | 4 |
| 2023 | Exact Markov Chain of Random Propagation of Malware With Network-Level MitigationabstractIn the age of Internet of Things (IoT), exploitation of security vulnerabilities is increasing, including self-propagating IoT malware. As an answer, specific research on IoT malware is being developed. Many studies use Markov chain models of malware propagation to predict the behavior of epidemics qualitatively and quantitatively. However, most studies approximate random propagation as a simple multiplicative term and no exact derivation of the Markov chain for random propagation was done so far. Moreover, systems of malware mitigation operating at the network level are rare and the majority of proposals focus on local networks like wireless sensor networks. In this article, we present a simple derivation of the exact Markov chain for random propagation of malware. Our model assumes a binomial form, compatible with binomial distributions in stochastic studies. To validate this derivation we implemented a stochastic simulation for the simplest compartmental epidemic model, susceptible–infected–susceptible (SIS). Predictions of the proposed Markov chain match simulation results with less than 0.2% error, well within stochastic variability and much smaller than the error of literature models. To complement our model of propagation, we developed and derived the Markov chain of a new system of malware mitigation, based on grouping random devices with identified infections during malware cleaning. Our mitigation system works at the network level and counteracts the vulnerability of mass deployment of IoT devices with aggressive but calculated mass disconnection. The system is able to artificially reduce$R_{0}$(the basic reproduction number) below 1 and prevent malware taking over the network—all without changing the rate of detection. Rodrigo Matos Carnier, Yasutaka Fujimoto, Junji Shikata |
IEEE Internet Things J. | 4 |
| 2022 | Quantum-Secure Aggregate One-time Signatures with Detecting Functionality
Shingo Sato, Junji Shikata |
AINA (2) | 2 |
| 2021 | Anonymous Broadcast Authentication for Securely Remote-Controlling IoT Devices
Yohei Watanabe 0001, Naoto Yanai, Junji Shikata |
AINA (2) | 3 |
| 2021 | Asymptotically Tight Lower Bounds in Anonymous Broadcast Encryption and Authentication
Hirokazu Kobayashi, Yohei Watanabe 0001, Junji Shikata |
IMACC | 3 |
| 2020 | Aggregate Message Authentication Codes with Detecting Functionality from Biorthogonal CodesabstractMessage authentication code (MAC) is one of the most fundamental cryptographic primitives, and aggregate message authentication code (AMAC) is an authentication technique that can compress multiple MAC tags into a short tag for messages from multiple senders. Although AMAC cannot specify an invalid message, AMAC with detecting functionality (AMAD) enables us to compress multiple MAC tags and to identify an invalid message. In this paper, we propose construction of AMAD from biorthogonal codes, and show that our AMAD achieves a better compression rate than other constructions of AMAD. Yoshinori Ogawa, Shingo Sato, Junji Shikata, Hideki Imai |
ISIT | 3 |
| 2020 | On the Power of Interaction in Signcryption
Junichi Ida, Junji Shikata, Yohei Watanabe 0001 |
ISITA | 2 |
| 2020 | A Physical-Layer Security Based on Wireless Steganography Through OFDM and DFT-Precoded OFDM SignalsabstractWe propose a physical-layer security approach based on the concept of steganography for IoT networks. Similar to the covert communications, the transmitter (Alice) attempts to send her secret signal to the legitimate receiver (Bob) avoiding being detected by the warden (Willie). Instead of sending the weak signal that is barely detectable by Willie, we hide secret signal in the cover signal that is transmitted over the same channel such that its existence may not be easily detected without any knowledge of prior information. Considering the practical applications to IoT networks, the DFT-precoded OFDM is adopted for the cover signal and conventional OFDM for the secret signal. Through theoretical analysis and corresponding simulations, the detection error probability of Willie is evaluated over an AWGN channel, revealing that judicious selection of cover signal power may increase the detection error probability of Willie and thus improve the covertness. Ryohei Yamaguchi, Hideki Ochiai, Junji Shikata |
VTC Spring | 3 |
| 2019 | Interactive Aggregate Message Authentication Scheme with Detecting Functionality
Shingo Sato, Junji Shikata |
AINA | 2 |
| 2019 | Quantum-Secure (Non-)Sequential Aggregate Message Authentication Codes
Shingo Sato, Junji Shikata |
IMACC | 2 |
| 2019 | SO-CCA Secure PKE in the Quantum Random Oracle Model or the Quantum Ideal Cipher Model
Shingo Sato, Junji Shikata |
IMACC | 2 |
| 2019 | Sequential Aggregate MACs with Detecting Functionality Revisited
Shingo Sato, Shoichi Hirose, Junji Shikata |
NSS | 3 |
| 2019 | History-Free Sequential Aggregate MAC Revisited
Shoichi Hirose, Junji Shikata |
ProvSec | 2 |
| 2019 | Identity-based encryption with hierarchical key-insulation in the standard model
Junji Shikata, Yohei Watanabe 0001 |
Des. Codes Cryptogr. | 1 |
| 2018 | Lower Bounds on Lattice Enumeration with Extreme Pruning
Yoshinori Aono, Phong Q. Nguyen, Takenobu Seito, Junji Shikata |
CRYPTO (2) | 4 |
| 2018 | Non-adaptive Group-Testing Aggregate MAC Scheme
Shoichi Hirose, Junji Shikata |
ISPEC | 2 |
| 2018 | Lattice-Based Signcryption Without Random Oracles
Shingo Sato, Junji Shikata |
PQCrypto | 2 |
| 2018 | Generic Construction of Sequential Aggregate MACs from Any MACs
Shingo Sato, Shoichi Hirose, Junji Shikata |
ProvSec | 3 |
| 2018 | Signcryption with Quantum Random Oracles
Shingo Sato, Junji Shikata |
ProvSec | 2 |
| 2018 | Timed-release computational secret sharing and threshold encryption
Yohei Watanabe 0001, Junji Shikata |
Des. Codes Cryptogr. | 2 |
| 2018 | Security Formalizations and Their Relationships for Encryption and Key Agreement in Information-Theoretic CryptographyabstractThis paper analyzes the formalizations of information-theoretic security for the fundamental primitives in cryptography: symmetric-key encryption and key agreement. Revisiting the previous results, we can formalize information-theoretic security using different methods, by extending Shannon's perfect secrecy, by information-theoretic analogues of indistinguishability and semantic security, and by the frameworks for composability of protocols. We show the relationships among the security formalizations and obtain the following results. First, in the case of encryption, there are significant gaps among the formalizations, and a certain type of relaxed perfect secrecy or a variant of information-theoretic indistinguishability is the strongest notion. Second, in the case of key agreement, there are significant gaps among the formalizations, and a certain type of relaxed perfect secrecy is the strongest notion. In particular, in both encryption and key agreement, the formalization of composable security is not stronger than any other formalizations. Furthermore, as an application of the relationships in encryption and key agreement, we simultaneously derive a family of lower bounds on the size of secret keys and security quantities required under the above formalizations, which also implies the importance and usefulness of the relationships. Mitsugu Iwamoto, Kazuo Ohta, Junji Shikata |
IEEE Trans. Inf. Theory | 3 |
| 2017 | Tighter bounds on entropy of secret keys in authentication codesabstractThe traditional theory of information-theoretically secure authentication codes (A-codes) developed by Simmons and others usually assumes that a uniformly random source for truly random keys is available. However, if we consider the scenario without the assumption, previously known bounds on key-entropy are not tight. In this paper, tighter lower bounds of A-codes with non-uniformly random secret keys are investigated and derived in terms of the Rényi entropy. Junji Shikata |
ITW | 1 |
| 2015 | Constructions of CCA-Secure Revocable Identity-Based Encryption
Yuu Ishida, Yohei Watanabe 0001, Junji Shikata |
ACISP | 3 |
| 2015 | A Compiler of Two-Party Protocols for Composable and Game-Theoretic Security, and Its Application to Oblivious Transfer
Shota Goto, Junji Shikata |
IMACC | 2 |
| 2015 | Constructions of symmetric-key encryption with guessing secrecyabstractConstructions of symmetric-key encryption with guessing secrecy are discussed. In the previous works, only a construction of symmetric-key encryption with average guessing secrecy is proposed for one-bit plaintexts. In this paper, we analyze a symmetric-key encryption with average guessing secrecy through OTP (one-time pad) constructions for a wide class of probability distributions of plaintexts and keys. As a result, we show a necessary and sufficient condition that such class of distributions satisfies average guessing secrecy in OTP constructions. On the other hand, we prove that optimal guessing secrecy is essentially equivalent to perfect secrecy under several natural restrictions. Therefore, only average guessing secrecy is meaningful for considering guessing secrecy other than perfect secrecy. Mitsugu Iwamoto, Junji Shikata |
ISIT | 2 |
| 2015 | Constructions of Unconditionally Secure Broadcast Encryption from Key Predistribution Systems with Trade-Offs Between Communication and Storage
Yohei Watanabe 0001, Junji Shikata |
ProvSec | 2 |
| 2014 | Secret sharing schemes based on min-entropiesabstractFundamental results on secret sharing schemes (SSSs) are discussed in the setting where security and share size are measured by (conditional) min-entropies. We first formalize a unified framework of SSSs based on (conditional) Rέnyi entropies, which includes SSSs based on Shannon and min entropies etc. as special cases. By deriving the lower bound of share sizes in terms of Rέnyi entropies based on the technique introduced by Iwamoto-Shikata, we obtain the lower bounds of share sizes measured by min entropies as well as by Shannon entropies in a unified manner. As the main contributions of this paper, we show two existential results of non-perfect SSSs based on min-entropies under several important settings. We first show that there exists a nonperfect SSS for arbitrary binary secret information and arbitrary monotone access structure. In addition, for every integers k and n (k ≤ n), we prove that the ideal non-perfect (k, n)-threshold scheme exists even if the distribution of the secret is not uniformly distributed. Mitsugu Iwamoto, Junji Shikata |
ISIT | 2 |
| 2014 | Timed-Release Computational Secret Sharing Scheme and Its Applications
Yohei Watanabe 0001, Junji Shikata |
ProvSec | 2 |
| 2013 | Constructions of Signcryption in the Multi-user Setting from Identity-Based Encryption
Rintaro Nakano, Junji Shikata |
IMACC | 2 |
| 2013 | Formalization of information-theoretic security for key agreement, revisitedabstractIn this paper, we investigate relationships between the following formalizations of information-theoretic security for key agreement protocols which may have agreement-errors: formalizations extended (or relaxed) from Shannon's perfect secrecy by using mutual information and statistical distance; and the ones of composable security by Maurer et al. and Canetti. Then, we explicitly show that those are essentially equivalent. We also derive lower bounds on the adversary's (or distinguisher's) advantage and the size of a correlated randomness resource required under all of the above formalizations at once through our relationships. In addition, we observe impossibility results which easily follow from the lower bounds. Junji Shikata |
ISIT | 1 |
| 2011 | Constructing Secure Hybrid Encryption from Key Encapsulation Mechanism with Authenticity
Yuki Shibuya, Junji Shikata |
IMACC | 2 |
| 2011 | Bit Commitment in the Bounded Storage Model: Tight Bound and Simple Optimal Construction
Junji Shikata, Daisuke Yamanaka |
IMACC | 1 |
| 2011 | Information-theoretically secure key-insulated key-agreementabstractIn this paper, we study key-agreement which realizes the protection against key-exposure problems in the information-theoretic security setting. And we newly define a model and security notions for information-theoretically secure key-insulated key-agreement (KI-KA for short). In addition, we show tight lower bounds of sizes of entities' secret-keys required for KI-KA. We also propose constructions of KI-KA which are provably secure and optimal. Furthermore, we provide some applications of KI-KA. Takenobu Seito, Junji Shikata |
ITW | 2 |
| 2008 | Unconditionally Secure Steganography Against Active AttacksabstractIn this paper, we study unconditionally secure stegosystems against active attacks over an insecure channel in which an adversary can read and write a message. More specifically, we propose an information-theoretic model for steganography in the presence of active adversaries by extending both Simmons' and Cachin's works; and we show a generic construction of stegosystems secure against active attacks by using authenticated encryption in unconditional setting. Although the idea behind this construction is already used in different models (i.e., computational models and/or information-theoretic models with passive adversaries) of steganography, our contribution lies in showing the construction methodology provides provable and unconditional security against active adversaries. Junji Shikata, Tsutomu Matsumoto |
IEEE Trans. Inf. Theory | 1 |
| 2007 | Construction of Threshold (Hybrid) Encryption in the Random Oracle Model: How to Construct Secure Threshold Tag-KEM from Weakly Secure Threshold KEM
Takeru Ishihara, Hiroshi Aono, Sadayuki Hongo, Junji Shikata |
ACISP | 4 |
| 2006 | Unconditionally Secure Anonymous Encryption and Group AuthenticationabstractAnonymous channels or similar techniques that achieve sender's anonymity play important roles in many applications, e.g. electronic voting. However, they will be meaningless if cryptographic primitives containing sender's identity are carelessly used during the transmission. In computationally secure settings, this problem may be easily overcome by using public key encryption and group signatures. However, in an unconditionally secure setting, in which no computational difficulty is assumed, this is not an easy case as such. As the increasing computational power approaches the point where security policy can no longer assume the difficulty of solving factoring or discrete logarithm problems, it must shift its focus to assuring the solvency of unconditionally secure schemes that provide long-term security. The main contribution of this paper is to study the security primitives for the above problem. In this paper, we first define the unconditionally secure asymmetric encryption scheme, which is an encryption scheme with unconditional security and where it is impossible for a receiver to deduce the identity of a sender from the encrypted message. We also investigate tight lower bounds on required memory sizes from an information theoretic viewpoint and show an optimal construction based on polynomials. It is remarkable to see that these bounds are considerably different from those in Shannon's model of the conventional unconditionally secure symmetric encryption. Other than the polynomial-based scheme, we also show a construction based on combinatorial theory, a non-malleable scheme and a multi-receiver scheme. Then, we define and formalize the group authentication code (GA-code), which is an unconditionally secure authentication code with anonymity like group signatures. In this scheme, any authenticated user will be able to generate and send an authenticated message while the receiver can verify the legitimacy of the message—that it has been sent from a legitimate user but at the same time retains his anonymity. However, by cooperating with the group authority, such as in the case of disputes, the receiver is able to obtain information of the user's identity. For GA-code, we show two concrete constructions. Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai |
Comput. J. | 2 |
| 2005 | Identity-Based Hierarchical Strongly Key-Insulated Encryption and Its Application
Yumiko Hanaoka, Goichiro Hanaoka, Junji Shikata, Hideki Imai |
ASIACRYPT | 3 |
| 2003 | The Role of Arbiters in Asymmetric Authentication Schemes
Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai |
ISC | 2 |
| 2003 | Systematic Treatment of Collusion Secure Codes: Security Definitions and Their Relations
Katsunari Yoshioka, Junji Shikata, Tsutomu Matsumoto |
ISC | 2 |
| 2002 | Unconditionally Secure Anonymous Encryption and Group Authentication
Goichiro Hanaoka, Junji Shikata, Yumiko Hanaoka, Hideki Imai |
ASIACRYPT | 2 |
| 2002 | Security Notions for Unconditionally Secure Signature Schemes
Junji Shikata, Goichiro Hanaoka, Yuliang Zheng 0001, Hideki Imai |
EUROCRYPT | 1 |
| 2002 | Unconditionally Secure Key Insulated Cryptosystems: Models, Bounds and Constructions
Yumiko Hanaoka, Goichiro Hanaoka, Junji Shikata, Hideki Imai |
ICICS | 3 |
| 2002 | Traceability Schemes for Signed Documents
Shoko Yonezawa, Goichiro Hanaoka, Junji Shikata, Hideki Imai |
ISC | 3 |
| 2002 | Cryptography with information theoretic securityabstractSummary form only given. We discuss information-theoretic methods to prove the security of cryptosystems. We study what is called, unconditionally secure (or information-theoretically secure) cryptographic schemes in search for a system that can provide long-term security and that does not impose limits on the adversary's computational power. Hideki Imai, Goichiro Hanaoka, Junji Shikata, Akira Otsuka, Anderson C. A. Nascimento |
ITW | 3 |
| 2000 | Unconditionally Secure Digital Signature Schemes Admitting Transferability
Goichiro Hanaoka, Junji Shikata, Yuliang Zheng 0001, Hideki Imai |
ASIACRYPT | 2 |
| 1999 | Optimizing the Menezes-Okamoto-Vanstone (MOV) Algorithm for Non-supersingular Elliptic Curves
Junji Shikata, Yuliang Zheng 0001, Joe Suzuki, Hideki Imai |
ASIACRYPT | 1 |
| 1999 | Comparing the MOV and FR Reductions in Elliptic Curve Cryptography
Ryuichi Harasawa, Junji Shikata, Joe Suzuki, Hideki Imai |
EUROCRYPT | 2 |