Keita Emura

dblp:68/1281 · DBLP profile ↗
← Back
67ranked-venue papers
38as first author
20since 2021 · last 2026
0000-0002-8969-3581ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 56 · 31 first-author · 16 since 2021Theory of computation · 9 · 6 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Security analysis on a public-key inverted-index keyword search scheme with designated tester
abstract
• We present two attacks against the Gao et al. scheme (IEEE Internet of Things Journal, 2024) that reveal keyword information from a trapdoor. • We also demonstrate that the computational cost of the attacks is approximately two seconds. • We also discuss the possibility of applying a correction. Gao et al. (IEEE Internet of Things Journal, 2024) proposed a public-key inverted-index keyword search scheme with a designated tester as an extension of public-key encryption with keyword search (PEKS). In their scheme, the server (acting as the tester) holds a secret key and uses it to execute the search algorithm under the designated tester setting. They proved that no information about the keyword is revealed from trapdoors under the decisional Diffie-Hellman (DDH) assumption. However, their construction employs a symmetric pairing, which can effectively serve as a DDH solver. Consequently, the underlying complexity assumption does not hold, and it is expected that keyword information can be extracted from trapdoors. In this paper, we present two keyword guessing attacks against the Gao et al. scheme that reveal keyword information from a trapdoor. The first attack succeeds using only the server’s secret key and the challenge trapdoor, without requiring any additional encryption or trapdoor queries. We note that, in their security model, an adversary is not allowed to obtain the server’s secret key; therefore, our attack lies outside their defined model. Nevertheless, we discuss the role of the server and argue that our attack scenario is reasonable. The second attack does not rely on the server’s secret key but instead exploits the linkability of two trapdoors. In both attacks, the computational complexity is limited to two pairing operations, making them practical in terms of computational cost.
Mizuki Hayashi, Keita Emura
J. Inf. Secur. Appl.2
2026 On the traceability of group signatures: Uncorrupted user must exist
Keita Emura
Theor. Comput. Sci.1
2026 Comments on "Lightweight Multi-User Public-Key Authenticated Encryption With Keyword Search"
abstract
Xu et al. (IEEE Transactions on Information Forensics and Security 2025) proposed a lightweight multi-user public-key authenticated encryption with keyword search (LM-PAEKS) scheme. In this short note, we demonstrate that keyword information can be leaked from ciphertexts in the scheme. We further note that there are shortcomings in the security proof as well.
Keita Emura
IEEE Trans. Inf. Forensics Secur.1
2025 Group Signatures with Message-Dependent Opening Directly Imply Timed-Release Encryption
Yuto Imura, Keita Emura
CANS2
2025 On the Relations Between Matchmaking Public Key Encryption and Public Key Authenticated Encryption with Keyword Search
Takeshi Yoshida 0002, Keita Emura
CANS2
2025 Generic Construction of Dual-Server Public Key Authenticated Encryption With Keyword Search
abstract
In this paper, we propose a generic construction of dual‐server public key authenticated encryption with keyword search (DS‐PAEKS) from PAEKS, public key encryption, and signatures. We also show that previous DS‐PAEKS scheme is vulnerable by providing a concrete attack. That is, the proposed generic construction yields the first DS‐PAEKS schemes. Our attack with a slight modification works against previous dual‐server public key encryption with keyword search (DS‐PEKS) schemes.
Keita Emura
IET Inf. Secur.1
2025 An anonymous yet accountable contract wallet system using account abstraction
Kota Chin, Keita Emura, Kazumasa Omote
J. Inf. Secur. Appl.2
2025 Comments on "Blockchain-Assisted Public-Key Encryption With Keyword Search Against Keyword Guessing Attacks for Cloud Storage"
abstract
As a variant of PEKS (Public key Encryption with Keyword Search), Zhang it al. (IEEE Transactions on Cloud Computing 2021) introduced a secure and efficient PEKS scheme called SEPSE, where servers issue a servers-derived keyword to a sender or a receiver. In this paper, we show that information of keyword is revealed from trapdoor when an adversary is allowed to issue servers-derived keyword queries twice.
Keita Emura
IEEE Trans. Cloud Comput.1
2024 On the Feasibility of Identity-Based Encryption with Equality Test Against Insider Attacks
Keita Emura
ACISP (1)1
2024 Generic Construction of Forward Secure Public Key Authenticated Encryption with Keyword Search
Keita Emura
ACNS (1)1
2023 An End-to-End Encrypted Cache System with Time-Dependent Access Control
Keita Emura, Masato Yoshimi
ICISSP1
2023 Generic Construction of Fully Anonymous Broadcast Authenticated Encryption with Keyword Search with Adaptive Corruptions
abstract
As a multireceiver variant of public key authenticated encryption with keyword search (PAEKS), broadcast authenticated encryption with keyword search (BAEKS) was proposed by Liu et al. (ACISP 2021). BAEKS focuses on receiver anonymity, where no information about the receiver is leaked from ciphertexts, which is reminiscent of the anonymous broadcast encryption. Here, there are rooms for improving their security definitions, e.g., two challenge sets of receivers are selected before the setup phase, and an adversary is not allowed to corrupt any receiver. In this paper, we propose a generic construction of BAEKS derived from PAEKS that provides ciphertext anonymity and consistency in a multireceiver setting. The proposed construction is an extension of the generic construction proposed by Libert et al. (PKC 2012) for the fully anonymous broadcast encryption and provides adaptive corruptions. We also demonstrate that the Qin et al. PAEKS scheme (ProvSec 2021) provides ciphertext anonymity and consistency in a multireceiver setting and can be employed as a building block of the proposed generic construction.
Keita Emura
IET Inf. Secur.1
2022 Keyed-Fully Homomorphic Encryption Without Indistinguishability Obfuscation
Shingo Sato, Keita Emura, Atsushi Takayasu
ACNS2
2022 More Efficient Adaptively Secure Lattice-Based IBE with Equality Test in the Standard Model
Kyoichi Asano, Keita Emura, Atsushi Takayasu
ISC2
2022 A Generic Construction of CCA-Secure Attribute-Based Encryption with Equality Test
Kyoichi Asano, Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
ProvSec2
2022 Identity-based encryption with security against the KGC: A formal model and its instantiations
abstract
The key escrow problem is one of the main barriers to the widespread real-world use of identity-based encryption (IBE). Specifically, a key generation center (KGC), which generates secret keys for a given identity, has the power to decrypt all ciphertexts. At PKC 2009, Chow defined a notion of security against the KGC, that relies on assuming that it cannot discover the underlying identities behind ciphertexts. However, this is not a realistic assumption since, in practice, the KGC manages an identity list, and hence it can easily guess the identities corresponding to given ciphertexts. Chow later amended this issue by introducing a new entity called an identity-certifying authority (ICA) and proposed an anonymous key-issuing protocol. Essentially, this allows the users, KGC, and ICA to interactively generate secret keys without users ever having to reveal their identities to the KGC. Unfortunately, since Chow separately defined the security of IBE and that of the anonymous key-issuing protocol, his IBE definition did not provide any formal treatment when the ICA is used to authenticate the users. Effectively, all of the subsequent works following Chow lack the formal proofs needed to determine whether or not it delivers a secure solution to the key escrow problem. In this paper, based on Chow's work, we formally define an IBE scheme that resolves the key escrow problem and provide formal definitions of security against corrupted users, KGC, and ICA. Along the way, we observe that if we are allowed to assume a fully trusted ICA, as in Chow's work, then we can construct a trivial (and meaningless) IBE scheme that is secure against the KGC. Finally, we present two instantiations in our new security model: a lattice-based construction based on the Gentry–Peikert–Vaikuntanathan IBE scheme (STOC 2008) and Rückert's lattice-based blind signature scheme (ASIACRYPT 2010), and a pairing-based construction based on the Boneh–Franklin IBE scheme (CRYPTO 2001) and Boldyreva's blind signature scheme (PKC 2003).
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001
Theor. Comput. Sci.1
2021 Verifiable Functional Encryption Using Intel SGX
Tatsuya Suzuki 0002, Keita Emura, Toshihiro Ohigashi, Kazumasa Omote
ProvSec2
2021 Adaptively secure revocable hierarchical IBE from k-linear assumption
Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
Des. Codes Cryptogr.1
2021 Efficient identity-based encryption with Hierarchical key-insulation from HIBE
abstract
Abstract Hierarchical key-insulated identity-based encryption (HKIBE) is identity-based encryption (IBE) that allows users to update their secret keys to achieve (hierarchical) key-exposure resilience, which is an important notion in practice. However, existing HKIBE constructions have limitations in efficiency: sizes of ciphertexts and secret keys depend on the hierarchical depth. In this paper, we first triumph over the barrier by proposing simple but effective design methodologies to construct efficient HKIBE schemes. First, we show a generic construction from any hierarchical IBE (HIBE) scheme that satisfies a special requirement, called MSK evaluatability introduced by Emura et al. (Des. Codes Cryptography 89(7):1535–1574, 2021). It provides several new and efficient instantiations since most pairing-based HIBE schemes satisfy the requirement. It is worth noting that it preserves all parameters’ sizes of the underlying HIBE scheme, and hence we obtain several efficient HKIBE schemes under the k-linear assumption in the standard model. Since MSK evaluatability is dedicated to pairing-based HIBE schemes, the first construction restricts pairing-based instantiations. To realize efficient instantiation from various assumptions, we next propose a generic construction of an HKIBE scheme from any plain HIBE scheme. It is based on Hanaoka et al.’s HKIBE scheme (Asiacrypt 2005), and does not need any special properties. Therefore, we obtain new efficient instantiations from various assumptions other than pairing-oriented ones. Though the sizes of secret keys and ciphertexts are larger than those of the first construction, it is more efficient than Hanaoka et al.’s scheme in the sense of the sizes of master public/secret keys.
Keita Emura, Atsushi Takayasu, Yohei Watanabe 0001
Des. Codes Cryptogr.1
2021 Efficient revocable identity-based encryption with short public parameters
abstract
Revocation functionality is vital to real-world cryptographic systems for managing their reliability. In the context of identity-based encryption (IBE), Boldyreva, Goyal, and Kumar (ACM CCS 2008) first showed an efficient revocation method for IBE, and such an IBE scheme with the scalable revocation method is called revocable IBE (RIBE). Seo and Emura (PKC 2013) introduced a new security notion, called decryption key exposure resistance (DKER), which is a desirable security notion for RIBE. However, all existing RIBE schemes that achieve adaptive security with DKER require long public parameters or composite-order bilinear groups. In this paper, we first show an RIBE scheme that (1) satisfies adaptive security; (2) achieves DKER; (3) realizes constant-size public parameters; and (4) is constructed over prime-order bilinear groups. Our core technique relies on Seo and Emura's one (PKC 2013), which transform the Waters IBE (EUROCRYPT 2005) to the corresponding RIBE scheme. Specifically, we construct an IBE scheme that satisfies constant-size public parameters over prime-order groups and some requirements for the Seo-Emura technique, and then transform the IBE scheme to an RIBE scheme. We also discuss how to extend the proposed RIBE scheme to a chosen-ciphertext secure one and server-aided one (ESORICS 2015).
Keita Emura, Jae Hong Seo, Yohei Watanabe 0001
Theor. Comput. Sci.1
2020 Cache-22: A Highly Deployable Encrypted Cache System
Keita Emura, Shiho Moriai, Takuma Nakajima, Masato Yoshimi
ISITA1
2020 Secure-channel free searchable encryption with multiple keywords: A generic construction, an instantiation, and its implementation
Keita Emura, Katsuhiko Ito, Toshihiro Ohigashi
J. Comput. Syst. Sci.1
2020 Group Signatures with Time-Bound Keys Revisited: A New Model, an Efficient Construction, and its Implementation
abstract
Chu et al. (ASIACCS 2012) proposed group signature with time-bound keys (GS-TBK), where each signing key is associated with expiry time τ. In addition, to prove membership of the group, a signer needs to prove that the expiry time has not passed, i.e., t <; τ, where t is the current time. A signer whose expiry time has passed is automatically revoked, and this revocation is called natural revocation. Signers can be revoked simultaneously before their expiry times if the credential is compromised. This revocation is called premature revocation. A nice property in the Chu et al. proposal is that the size of revocation lists can be reduced compared to those of Verifier-Local Revocation (VLR) group signature schemes by assuming that natural revocation accounts for most of the signer revocations in practice, and prematurely revoked signers are only a small fraction. In this paper, we point out that the definition of traceability of Chu et al. did not capture the unforgeability of expiry time for signing keys, which guarantees that no adversary who has a signing key associated with expiry time τ can compute a valid signature after τ has passed. This situation significantly reduces the dependability of the system since legitimate signing keys may be used for providing a forged signature. We introduce a security model that captures unforgeability, and propose a secure GS-TBK scheme in the new model. Our scheme also provides constant signing costs, whereas those of the previous schemes depended on the bit-length of the time representation. Finally, we provide the implementation results. We employ Barreto-Lynn-Scott (BLS) curves with 455-bit prime order and the RELIC library, and demonstrate that our scheme is feasible in practical settings.
Keita Emura, Takuya Hayashi 0001, Ai Ishida
IEEE Trans. Dependable Secur. Comput.1
2019 Proper Usage of the Group Signature Scheme in ISO/IEC 20008-2
abstract
In ISO/IEC 20008-2, several anonymous digital signature schemes are specified. Among these, the scheme denoted as Mechanism 6, is the only plain group signature scheme that does not aim at providing additional functionalities. The Intel Enhanced Privacy Identification (EPID) scheme, which has many applications in connection with Intel Software Guard Extensions (Intel SGX), is in practice derived from Mechanism 6. In this paper, we firstly show that Mechanism 6 does not satisfy anonymity in the standard security model, i.e., the Bellare-Shi-Zhang model [CT-RSA 2005]. We then provide a detailed analysis of the security properties offered by Mechanism 6 and characterize the conditions under which its anonymity is preserved. Consequently, it is seen that Mechanism 6 is secure under the condition that the issuer, who generates user signing keys, does not join the attack. We also derive a simple patch for Mechanism~6 from the analysis.
Ai Ishida, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka
AsiaCCS3
2019 Identity-Based Encryption with Security Against the KGC: A Formal Model and Its Instantiation from Lattices
Keita Emura, Shuichi Katsumata, Yohei Watanabe 0001
ESORICS (2)1
2019 Privacy-Preserving Aggregation of Time-Series Data with Public Verifiability from Simple Assumptions and Its Implementations
abstract
Aggregator oblivious encryption was proposed by Shi et al. (NDSS 2011). In this method, an aggregator can compute an aggregated sum of data and is unable to learn anything else (aggregator obliviousness). Since the aggregator does not learn individual data that may reveal users’ habits and behaviors, several applications including privacy-preserving smart metering have been considered. In this paper, we propose an aggregator oblivious encryption scheme with public verifiability where the aggregator is required to generate a proof of an aggregated sum, and anyone can verify whether the aggregated sum has been correctly computed by the aggregator. Although Leontiadis et al. (CANS 2015) considered verifiability, their scheme requires an interactive complexity assumption to provide the unforgeability of the proof. Our scheme is proven to be unforgeable under a static and simple assumption (a variant of the Computational Diffie–Hellman assumption). Moreover, our scheme inherits the tightness of the reduction of the Benhamouda et al. scheme (ACM TISSEC 2016) for proving aggregator obliviousness. This tight reduction allows us to employ elliptic curves of a smaller order and leads to efficient implementation. Specifically, for 112-bit security, we can employ Barreto–Naehrig (BN) curves with a 383-bit prime order, whereas we need to employ curves with a 1031-bit prime order to implement the Leontiadis et al. scheme. We give implementations of two schemes and evaluate their performances under those curves. We employ a Raspberry-Pi as a power-constrained device such as a smart meter. Consequently, we demonstrate that the running time of the data encryption, data aggregation and verification in our scheme are reduced by approximately 74%, 64% and 89%, respectively, compared to those of the Leontiadis et al. scheme.
Keita Emura, Hayato Kimura 0002, Toshihiro Ohigashi, Tatsuya Suzuki 0002
Comput. J.1
2019 Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions
abstract
This paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes.
Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazuma Ohara, Kazumasa Omote, Yusuke Sakai 0001
Secur. Commun. Networks1
2018 A Generic Construction of Integrated Secure-Channel Free PEKS and PKE
Tatsuya Suzuki 0002, Keita Emura, Toshihiro Ohigashi
ISPEC2
2018 A Revocable Group Signature Scheme with Scalability from Simple Assumptions and Its Implementation
Keita Emura, Takuya Hayashi 0001
ISC1
2018 Chosen ciphertext secure keyed-homomorphic public-key cryptosystems
Keita Emura, Goichiro Hanaoka, Koji Nuida, Go Ohtake, Takahiro Matsuda 0002, Shota Yamada 0001
Des. Codes Cryptogr.1
2017 Privacy-Preserving Aggregation of Time-Series Data with Public Verifiability from Simple Assumptions
Keita Emura
ACISP (2)1
2017 Group Signatures with Time-bound Keys Revisited: A New Model and an Efficient Construction
abstract
Chu et al. (ASIACCS 2012) proposed group signature with time-bound keys (GS-TBK) where each signing key is associated to an expiry time τ. In addition to prove the membership of the group, a signer needs to prove that the expiry time has not passed, i.e., t<τ where t is the current time. A signer whose expiry time has passed is automatically revoked, and this revocation is called natural revocation. Simultaneously, signers can be revoked before their expiry times have passed due to the compromise of the credential. This revocation is called premature revocation. A nice property of the Chu et al. proposal is that the size of revocation lists can be reduced compared to those of Verifier-Local Revocation (VLR) group signature schemes, by assuming that natural revocation accounts for most of signer revocations in practice, and prematurely revoked signers are only a small fraction. In this paper, we point out that the definition of traceability of Chu et al. did not capture unforgeability of expiry time of signing keys which guarantees that no adversary who has a signing key associated to an expiry time τ can compute a valid signature after τ has passed. We introduce a security model that captures unforgeability, and propose a GS-TBK scheme secure in the new model. Our scheme also provides the constant signing costs whereas those of the previous schemes depend on the bit-length of the time representation. Finally, we give implementation results, and show that our scheme is feasible in practical settings.
Keita Emura, Takuya Hayashi 0001, Ai Ishida
AsiaCCS1
2017 Mis-operation Resistant Searchable Homomorphic Encryption
abstract
Let us consider a scenario that a data holder (e.g., a hospital) encrypts a data (e.g., a medical record) which relates a keyword (e.g., a disease name), and sends its ciphertext to a server. We here suppose not only the data but also the keyword should be kept private. A receiver sends a query to the server (e.g., average of body weights of cancer patients). Then, the server performs the homomorphic operation to the ciphertexts of the corresponding medical records, and returns the resultant ciphertext. In this scenario, the server should NOT be allowed to perform the homomorphic operation against ciphertexts associated with different keywords. If such a mis-operation happens, then medical records of different diseases are unexpectedly mixed. However, in the conventional homomorphic encryption, there is no way to prevent such an unexpected homomorphic operation, and this fact may become visible after decrypting a ciphertext, or as the most serious case it might be never detected. To circumvent this problem, in this paper, we propose mis-operation resistant homomorphic encryption, where even if one performs the homomorphic operations against ciphertexts associated with keywords ω' and ω, where ω -ω', the evaluation algorithm detects this fact. Moreover, even if one (intentionally or accidentally) performs the homomorphic operations against such ciphertexts, a ciphertext associated with a random keyword is generated, and the decryption algorithm rejects it. So, the receiver can recognize such a mis-operation happens in the evaluation phase. In addition to mis-operation resistance, we additionally adopt secure search functionality for keywords since it is desirable when one would like to delegate homomorphic operations to a third party. So, we call the proposed primitive mis-operation resistant searchable homomorphic encryption (MR-SHE). We also give our implementation result of inner products of encrypted vectors. In the case when both vectors are encrypted, the running time of the receiver is millisecond order for relatively small-dimensional (e.g., 26) vectors. In the case when one vector is encrypted, the running time of the receiver is approximately 5 msec even for relatively high-dimensional (e.g., 213) vectors.
Keita Emura, Takuya Hayashi 0001, Noboru Kunihiro, Jun Sakuma
AsiaCCS1
2017 New Revocable IBE in Prime-Order Groups: Adaptively Secure, Decryption Key Exposure Resistant, and with Short Public Parameters
Yohei Watanabe 0001, Keita Emura, Jae Hong Seo
CT-RSA2
2017 Generic Constructions for Fully Secure Revocable Attribute-Based Encryption
Kotoko Yamada, Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Keisuke Tanaka
ESORICS (2)3
2017 A Generic Construction of Secure-Channel Free Searchable Encryption with Multiple Keywords
Keita Emura
NSS1
2017 Establishing secure and anonymous communication channel: KEM/DEM-based construction and its implementation
Keita Emura, Akira Kanaoka, Satoshi Ohta, Takeshi Takahashi 0001
J. Inf. Secur. Appl.1
2016 Group Signature with Deniability: How to Disavow a Signature
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka
CANS2
2016 Toward securing tire pressure monitoring systems: A case of PRESENT-based implementation
Keita Emura, Takuya Hayashi 0001, Shiho Moriai
ISITA1
2016 Constructions of dynamic and non-dynamic threshold public-key encryption schemes with decryption consistency
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta
Theor. Comput. Sci.2
2016 Revocable hierarchical identity-based encryption via history-free approach
Jae Hong Seo, Keita Emura
Theor. Comput. Sci.2
2015 Dynamic Threshold Public-Key Encryption with Decryption Consistency from Static Assumptions
Yusuke Sakai 0001, Keita Emura, Jacob C. N. Schuldt, Goichiro Hanaoka, Kazuo Ohta
ACISP2
2015 Accumulable Optimistic Fair Exchange from Verifiably Encrypted Homomorphic Signatures
Jae Hong Seo, Keita Emura, Keita Xagawa, Kazuki Yoneyama
ACNS2
2015 Disavowable Public Key Encryption with Non-interactive Opening
abstract
We propose the notion of disavowable public key encryption with non-interactive opening (disavowable PKENO) where, for a ciphertext and a message, the receiver of the ciphertext can issue a proof that the plaintext of the ciphertext is NOT the message, and give a fairly practical construction.
Ai Ishida, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001, Keisuke Tanaka
AsiaCCS2
2015 Revocable Hierarchical Identity-Based Encryption: History-Free Update, Security Against Insiders, and Short Ciphertexts
Jae Hong Seo, Keita Emura
CT-RSA2
2015 Revocable Group Signature with Constant-Size Revocation List
abstract
It is essential that a multi-user cryptographic primitive be revocable since a legitimate user may quit the organization, or may act on malicious intent, or the relevant key may be leaked. In the group signature context, usually the group manager publishes the revocation list that contains revocation tokens. Since signers/verifiers need to obtain the revocation list in each revocation epoch to generate/verify a group signature, a small-size revocation list is really important in practice. However, all previous revocable group signatures require at least an |$O(r)$|-size revocation list, where |$r$| is the number of revoked users. In this paper, we propose the first revocable group signature scheme with a constant-size revocation list using identity-based revocation (IBR) techniques. We use an IBR scheme proposed by Attrapadung–Libert–Panafieu (PKC 2011) as a building block. As in the Libert–Peters–Yung schemes (EUROCRYPT 2012/CRYPTO 2012), no signing key update is required. In addition, the verification cost does not depend on the number of revoked users |$r$|⁠. Although the maximum number of revoked users needs to be fixed in the setup phase, the maximum number of group members is potentially unbounded as in IBR. This property has not been achieved in the recent scalable revocable group signature schemes and seems to be of independent interest.
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001
Comput. J.2
2015 Generic constructions of secure-channel free searchable encryption with adaptive security
abstract
Abstract For searching keywords against encrypted data, public key encryption scheme with keyword search (PEKS), and its extension secure‐channel free PEKS (SCF‐PEKS), has been proposed. In this paper, we extend the security of SCF‐PEKS, calling it adaptive SCF‐PEKS, wherein an adversary (modeled as a “malicious‐but‐legitimate” receiver) is allowed to issue test queries adaptively. We show that adaptive SCF‐PEKS can be generically constructed by anonymous identity‐based encryption only. That is, SCF‐PEKS can be constructed without any additional cryptographic primitive when compared with the Abdallaet al.PEKS construction (J. Cryptology 2008), even though adaptive SCF‐PEKS requires additional functionalities. We also propose other adaptive SCF‐PEKS construction, which is not fully generic but is efficient compared with the first one. Finally, we instantiate an adaptive SCF‐PEKS scheme (via our second construction) that achieves a similar level of efficiency for the costs of the test procedure and encryption, compared with the (non‐adaptive secure) SCF‐PEKS scheme by Fanget al.(CANS2009). Copyright © 2014 John Wiley & Sons, Ltd.
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman, Kazumasa Omote
Secur. Commun. Networks1
2014 A Revocable Group Signature Scheme from Identity-Based Revocation Techniques: Achieving Constant-Size Revocation List
Nuttapong Attrapadung, Keita Emura, Goichiro Hanaoka, Yusuke Sakai 0001
ACNS2
2014 A Privacy-Enhanced Access Log Management Mechanism in SSO Systems from Nominative Signatures
abstract
In online services, e.g., Online shopping, a service provider (SP) manages access logs containing customers' buying histories. Therefore, user's personal information, e.g., Their hobbies and diversions, is revealed from the exposed logs if each customer can be linked. In fact, such information exposure has occurred due to the popularization of online services. To cope with this problem, SPs may only have to delete access logs, but then no illegitimate users, who accessed the server illegally, will be traced from the logs. In this paper, we propose a log management mechanism where (1) no user information is revealed even if logs are exposed, but (2) illegitimate users can be traced when necessary. Specifically, we consider single sign on (SSO) systems, since plural access logs might be connected by one account, and this could trigger the above privacy infringement problem. We construct our privacy-enhanced access log management mechanism based on the Wang-Wang-Susilo SSO system (TrustCom 2013) which applies nominative signatures as its building block. Specifically, we realize the system by additionally applying the invisibility property of the Schuldt-Hanaoka nominative signature scheme (ACNS 2011). Finally, we estimate the efficiency of the proposed system by using Pairing-Based Cryptography (PBC) library and confirmed that for each algorithm, computation time is at most just over 80 milliseconds on a PC, which seems sufficiently practical.
Sanami Nakagawa, Keita Emura, Goichiro Hanaoka, Akihisa Kodate, Takashi Nishide, Eiji Okamoto, Yusuke Sakai 0001
TrustCom2
2014 A Secure Genetic Algorithm for the Subset Cover Problem and Its Application to Privacy Protection
Dan Bogdanov, Keita Emura, Roman Jagomägis, Akira Kanaoka, Shin'ichiro Matsuo, Jan Willemson
WISTP2
2014 Revocable hierarchical identity-based encryption
Jae Hong Seo, Keita Emura
Theor. Comput. Sci.2
2014 Revocable Identity-Based Cryptosystem Revisited: Security Models and Constructions
abstract
Boneh and Franklin gave a naive revocation method in identity-based encryption (IBE) which imposes a huge overhead into the key generation center. Later, Boldyreva, Goyal, and Kumar proposed an elegant way of achieving an IBE with efficient revocation, called revocable IBE (RIBE). In this paper, we revisit RIBE from the viewpoint of both security models and constructions. First, we introduce a realistic threat, which we call decryption key exposure, and show that all prior RIBE constructions, except the Boneh-Franklin one, are vulnerable to decryption key exposure. Next, we propose the first scalable RIBE scheme with decryption key exposure resistance by combining the (adaptively secure) Waters IBE scheme and the (selectively secure) Boneh-Boyen IBE scheme, and show that our RIBE scheme is more efficient than all previous adaptively secure scalable RIBE schemes. In addition, we extend our interest into identity-based signatures; we introduce a new security definition of revocable identity-based signature (RIBS) with signing key exposure resistance, and propose the first scalable RIBS scheme based on the Paterson-Schuldt IBS. Finally, we provide implementation results of our schemes to adduce the feasibility of our schemes.
Jae Hong Seo, Keita Emura
IEEE Trans. Inf. Forensics Secur.2
2013 A group signature scheme with unbounded message-dependent opening
abstract
Group signature with message-dependent opening (GS-MDO) is a kind of group signature in which only the signers who have created group signatures on problematic messages will be identified. In the previous GS-MDO scheme, however, the number of problematic messages is bounded owing to a limitation of the Groth-Sahai proofs. In this paper, we propose the first GS-MDO scheme with the unbounded-MDO functionality in the random oracle model. Our unbounded GS-MDO scheme is based on the short group signature scheme proposed by Boneh, Boyen, and Shacham and the Boneh-Franklin identity-based encryption scheme. To combine these building blocks and to achieve CCA-anonymity, we also construct a special type of multiple encryption. This technique yields an efficient construction compared with the previous bounded GS-MDO scheme: the signature of our scheme contains about 16 group elements (3630 bits), whereas that of the previous scheme has about 450 group elements (75820 bits).
Kazuma Ohara, Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka
AsiaCCS3
2013 Efficient Delegation of Key Generation and Revocation Functionalities in Identity-Based Encryption
Jae Hong Seo, Keita Emura
CT-RSA2
2012 Group Signatures with Message-Dependent Opening
Yusuke Sakai 0001, Keita Emura, Goichiro Hanaoka, Yutaka Kawai, Takahiro Matsuda 0002, Kazumasa Omote
Pairing2
2012 Constructing Secure-channel Free Searchable Encryption from Anonymous IBE with Partitioned Ciphertext Structure
Keita Emura, Mohammad Shahriar Rahman
SECRYPT1
2012 Flexible Group Key Exchange with On-demand Computation of Subgroup Keys Supporting Subgroup Key Randomization
Keita Emura
SECRYPT1
2011 Toward Dynamic Attribute-Based Signcryption (Poster)
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman
ACISP1
2011 Non-interactive Opening for Ciphertexts Encrypted by Shared Keys
Jiageng Chen, Keita Emura, Atsuko Miyaji
ICICS2
2011 Ideal Secret Sharing Schemes with Share Selectability
Keita Emura, Atsuko Miyaji, Akito Nomura, Mohammad Shahriar Rahman, Masakazu Soshi
ICICS1
2011 Adaptive Secure-Channel Free Public-Key Encryption with Keyword Search Implies Timed Release Encryption
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ISC1
2010 Efficient Privacy-Preserving Data Mining in Malicious Model
Keita Emura, Atsuko Miyaji, Mohammad Shahriar Rahman
ADMA (1)1
2010 An Anonymous Designated Verifier Signature Scheme with Revocation: How to Protect a Company's Reputation
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ProvSec1
2010 A Timed-Release Proxy Re-encryption Scheme and Its Application to Fairly-Opened Multicast Communication
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ProvSec1
2009 A Dynamic Attribute-Based Group Signature Scheme and its Application in an Anonymous Survey for the Collection of Attribute Statistics
abstract
Recently, cryptographic schemes based on the user's attributes have been proposed. An attribute-based group signature (ABGS) scheme is a kind of group signature schemes, where a user with a set of attributes can prove anonymously whether she has these attributes or not. An access tree is applied to express the relationships among some attributes. However, previous schemes do not provide the changing an access tree. In this paper, we propose a dynamic ABGS scheme that enables an access tree to be changed. Our ABGS is efficient in that re-issuing of the attribute certificate previously issued for each user is not necessary. Moreover, calculations depending on the number of attributes are calculated on the domain of a pairing. Therefore, the number of calculations in a pairing does not depend on the number of attributes associated with a signature. Finally, we discuss how our ABGS can be applied to an anonymous survey for collection of attribute statistics.
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ARES1
2009 A Certificate Revocable Anonymous Authentication Scheme with Designated Verifier
abstract
In IEEE ISI 2008, an anonymous attribute authentication scheme has been proposed using a self-blindable certificate scheme. This scheme enables the anonymity and certificate revocation. A Certificate Revocation List (CRL) is used in the revocation check. Even if an attacker can obtain a CRL, the attacker cannot execute the revocation check. This means that this scheme enables the designated revocation. However, this scheme is not secure, namely, a user can make a forged proof using a public value. In this paper, we propose a certificate revocable anonymous authentication scheme with designated verifier. Our scheme enables the anonymity and certificate revocation. Moreover, our scheme enables a designated verification and revocation.
Keita Emura, Atsuko Miyaji, Kazumasa Omote
ARES1
2009 A Ciphertext-Policy Attribute-Based Encryption Scheme with Constant Ciphertext Length
Keita Emura, Atsuko Miyaji, Akito Nomura, Kazumasa Omote, Masakazu Soshi
ISPEC1