Olivier Pereira

dblp:78/1061 · DBLP profile ↗
← Back
44ranked-venue papers
6as first author
6since 2021 · last 2026
0000-0002-1901-3587ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 36 · 6 first-author · 6 since 2021Theory of computation · 3Computer networks · 2Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 CAnonize: A Compact Anonymous Survey Protocol
abstract
Online surveys are frequently used to collect feedback on sensitive topics, yet most deployed platforms rely on authenticated accounts, cookies, or operator-enforced policies to protect anonymity and limit participation. These approaches offer limited protection against retrospective deanonymization in the event of database compromise. The anonymous survey primitive addresses this problem by enabling authenticated yet anonymous submissions with at-most-once participation per survey, without requiring a trusted setup. Current solutions may however be computationally demanding when aiming for large scale deployment. We revisit this primitive and present CAnonize, a new anonymous survey protocol that considerably improves the efficiency compared to the state of the art, while also relying on weaker computational assumptions and preserving a strong corruption model: our protocol relies solely on the SXDH assumption in asymmetric bilinear groups (q-type assumptions were used before), and offers unlinkability under adaptive corruption of the registration authority, survey authorities, and users, even under full transcript exposure and post-compromise database leakage. We confirm the efficiency benefits and practicality of CAnonize through a prototype implementation in Rust: using the BLS12-381 curves, the running times for submitting and processing a survey response are below 100ms for the user and for the survey authority.
Marie Lonfils, Olivier Pereira, Thomas Peters, Moti Yung
Proc. Priv. Enhancing Technol.2
2024 Encryption Mechanisms for Receipt-Free and Perfectly Private Verifiable Elections
Thi Van Thao Doan, Olivier Pereira, Thomas Peters
ACNS (1)2
2024 Can we cast a ballot as intended and be receipt free?
abstract
This paper explores the interaction between receipt- freeness and cast-as-intended verifiability, a property that has been overlooked until now or assumed to be granted through procedural means in the context of receipt-free voting protocols.We first demonstrate that it is impossible to obtain a receipt-free voting protocol with cast-as-intended verifiability if the voting process is non-interactive, unless a trusted authority is available. We also demonstrate that, if a trusted voter registration authority is available, then cast-as-intended verifiability and receipt-freeness can be obtained.Furthermore, after extending standard receipt-freeness security definitions to an interactive voting (and corruption) setting, we demonstrate that the same security properties can be obtained using an interactive voting process.Finally, we discuss the performance of our protocols based on a prototype implementation.
Henri Devillez, Olivier Pereira, Thomas Peters, Quentin Yang
SP2
2024 ElectionGuard: a Cryptographic Toolkit to Enable Verifiable Elections
Josh Benaloh, Michael Naehrig, Olivier Pereira, Dan S. Wallach
USENIX Security Symposium3
2022 Traceable Receipt-Free Encryption
Henri Devillez, Olivier Pereira, Thomas Peters
ASIACRYPT (3)2
2022 How to Verifiably Encrypt Many Bits for an Election?
Henri Devillez, Olivier Pereira, Thomas Peters
ESORICS (2)2
2020 CLAPS: Client-Location-Aware Path Selection in Tor
abstract
Much research has investigated improving the security and performance of Tor by having Tor clients choose paths through the network in a way that depends on the client's location. However, this approach has been demonstrated to lead to serious deanonymization attacks. Moreover, we show how in some scenarios it can lead to significant performance degradation. For example, we demonstrate that using the recently-proposed Counter-RAPTOR system when guard bandwidth isn't abundant could increase median download times by 28.7%. We propose the CLAPS system for performing client-location-aware path selection, which fixes the known security and performance issues of existing designs. We experimentally compare the security and performance of CLAPS to Counter-RAPTOR and DeNASA. CLAPS puts a strict bound on the leakage of information about the client's location, where the other systems could completely reveal it after just a few connections. It also guarantees a limit on the advantage that an adversary can obtain by strategic relay placement, which we demonstrate to be overwhelming against the other systems. Finally, due to a powerful formalization of path selection as an optimization problem, CLAPS is approaching or even exceeding the original goals of algorithms to which it is applied, while solving their known deficiencies.
Florentin Rochet, Ryan Wails, Aaron Johnson 0001, Prateek Mittal, Olivier Pereira
CCS5
2020 Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance Jungle
Davide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso, Chun Guo 0002, Charles Momin, Olivier Pereira, Thomas Peters, François-Xavier Standaert
CRYPTO (1)7
2020 When Is a Test Not a Proof?
Eleanor McMurtry, Olivier Pereira, Vanessa Teague
ESORICS (2)2
2020 How not to prove your election outcome
abstract
The Scytl/SwissPost e-voting solution was intended to provide complete verifiability for Swiss government elections. We show failures in both individual verifiability and universal verifiability (as defined in Swiss Federal Ordinance 161.116), based on mistaken implementations of cryptographic components. These failures allow for the construction of "proofs" of an accurate election outcome that pass verification though the votes have been manipulated. Using sophisticated cryptographic protocols without a proper consideration of what properties they offer, and under which conditions, can introduce opportunities for undetectable fraud even though the system appears to allow verification of the outcome.Our findings are immediately relevant to systems in use in Switzerland and Australia, and probably also elsewhere.
Thomas Haines, Sarah Jamie Lewis, Olivier Pereira, Vanessa Teague
SP3
2020 Scaling Up Anonymous Communication with Efficient Nanopayment Channels
abstract
Abstract Tor, the most widely used and well-studied traffic anonymization network in the world, suffers from limitations in its network diversity and performance. We propose to mitigate both problems simultaneously through the introduction of a premium bandwidth market between clients and relays. To this end, we present moneTor: incentivizing nodes to join and support Tor by giving them anonymous payments from Tor users. Our approach uses efficient cryptographic nanopayments delivered alongside regular Tor traffic. Our approach also gives a degree of centralized control, allowing Tor’s managers to shape the economy created by these payments. In this paper, we present a novel payment algorithm as well as a data-driven simulation and evaluation of its costs and benefits. The results show that moneTor is both feasible and flexible, offering upwards of 100% improvements in differentiated bandwidth for paying users with near-optimal throughput and latency overheads.
Thien-Nam Dinh, Florentin Rochet, Olivier Pereira, Dan S. Wallach
Proc. Priv. Enhancing Technol.3
2019 Strong Authenticity with Leakage Under Weak and Falsifiable Physical Assumptions
Francesco Berti, Chun Guo 0002, Olivier Pereira, Thomas Peters, François-Xavier Standaert
Inscrypt3
2019 Pluginizing QUIC
abstract
Application requirements evolve over time and the underlying protocols need to adapt. Most transport protocols evolve by negotiating protocol extensions during the handshake. Experience with TCP shows that this leads to delays of several years or more to widely deploy standardized extensions. In this paper, we revisit the extensibility paradigm of transport protocols.
Quentin De Coninck, François Michel, Maxime Piraux, Florentin Rochet, Thomas Given-Wilson, Axel Legay, Olivier Pereira, Olivier Bonaventure
SIGCOMM7
2019 SWAT: Seamless Web Authentication Technology
abstract
We present a seamless challenge-response authentication protocol which leverages on the variations of html5 canvas rendering made by the software and hardware stacks. After a training phase that leads to feature extraction with deep learning techniques, a server becomes able to authenticate a user based on fresh canvasses, hence avoiding replay attacks. The whole authentication process is natively supported by any mainstream browser, stateless on client side and can be transparent to the user. We argue that those features facilitate deployment and composition with other authentication mechanisms without lowering the user experience. We present the threat model against which our protocol is expected to live and discuss its security. We also present a prototype implementation of our protocol and report on a real-word experimentation that we ran in order to analyze its efficiency and effectiveness.
Florentin Rochet, Kyriakos Efthymiadis, François Koeune, Olivier Pereira
WWW4
2018 Ciphertext Integrity with Misuse and Leakage: Definition and Efficient Constructions with Symmetric Primitives
abstract
Leakage resilience (LR) and misuse resistance (MR) are two important properties for the deployment of authenticated encryption (AE) schemes. They aim at mitigating the impact of implementation flaws due to side-channel leakages and misused randomness. In this paper, we discuss the interactions and incompatibilities between these two properties.
Francesco Berti, François Koeune, Olivier Pereira, Thomas Peters, François-Xavier Standaert
AsiaCCS3
2018 Task-structured probabilistic I/O automata
Ran Canetti, Ling Cheung, Dilsun Kirli Kaynar, Moses D. Liskov, Nancy A. Lynch, Olivier Pereira, Roberto Segala
J. Comput. Syst. Sci.6
2018 Dropping on the Edge: Flexibility and Traffic Confirmation in Onion Routing Protocols
abstract
Abstract The design of Tor includes a feature that is common to most distributed systems: the protocol is flexible. In particular, the Tor protocol requires nodes to ignore messages that are not understood, in order to guarantee the compatibility with future protocol versions. This paper shows how to exploit this flexibility by proposing two new active attacks: one against onion services and the other against Tor clients. Our attack against onion services is a new low-cost side-channel guard discovery attack that makes it possible to retrieve the entry node used by an onion service in one day, without injecting any relay in the network. This attack uses the possibility to send dummy cells that are silently dropped by onion services, in accordance with the flexible protocol design, and the possibility to observe those cells by inspecting public bandwidth measurements, which act as a side channel. Our attack against Tor clients, called the dropmark attack, is an efficient 1-bit conveying active attack that correlates flows. Simulations performed in Shadow show that the attack succeeds with an overwhelming probability and with no noticeable impact on user performance. Finally, we open the discussion regarding a trade-off between flexibility and security in anonymous communication systems, based on what we learned within the scope of our attacks.
Florentin Rochet, Olivier Pereira
Proc. Priv. Enhancing Technol.2
2017 Securing multipath TCP: Design & implementation
abstract
MultiFath TCP (MPTCP) is a recent TCP extension that enables hosts to send data over multiple paths for a single connection. It is already deployed for various use cases, notably on smartphones. In parallel with this, there is a growing deployment of encryption and authentication techniques to counter various forms of security attacks. Tcpcrypt and TLS are some of these security solutions. In this paper, we propose MPTCPsec, a MultiPath TCP extension that closely integrates authentication and encryption inside the protocol itself. Our design relies on an adaptation for the multipath environment of the ENO option that is being discussed within the IETF tcpinc working group. We then detail how MultiPath TCP needs to be modified to authenticate and encrypt all data and authenticate the different TCP options that it uses. Finally, we implement our proposed extension in the reference implementation of MultiPath TCP in the Linux kernel and we evaluate its performance.
Mathieu Jadin, Gautier Tihon, Olivier Pereira, Olivier Bonaventure
INFOCOM3
2017 Waterfilling: Balancing the Tor network with maximum diversity
abstract
Abstract We present the Waterfilling circuit selection method, which we designed in order to mitigate the risks of a successful end-to-end traffic correlation attack. Waterfilling proceeds by balancing the Tor network load as evenly as possible on endpoints of user paths. We simulate the use of Waterfilling thanks to the TorPS and Shadow tools. Applying several security metrics, we show that the adoption of Waterfilling considerably increases the number of nodes that an adversary needs to control in order to be able to mount a successful attack, while somewhat decreasing the minimum amount of bandwidth required to do so. Moreover, we evaluate Waterfilling in Shadow and show that it does not impact significantly the performance of the network. Furthermore, Waterfilling reduces the benefits that an attacker could obtain by hacking into a top bandwidth Tor relay, hence limiting the risks raised by such relays. Waterfilling does not require any major change in Tor, and can co-exist with the current circuit selection algorithm.
Florentin Rochet, Olivier Pereira
Proc. Priv. Enhancing Technol.2
2016 Verifiable Multi-party Computation with Perfectly Private Audit Trail
Edouard Cuvelier, Olivier Pereira
ACNS2
2015 Leakage-Resilient Authentication and Encryption from Symmetric Cryptographic Primitives
abstract
Leakage-resilient cryptosystems aim to maintain security in situations where their implementation leaks physical information about their internal secrets. Because of their efficiency and usability on a wide range of platforms, solutions based on symmetric primitives (such as block ciphers) are particularly attractive in this context. So far, the literature has mostly focused on the design of leakage-resilient pseudorandom objects (e.g. PRGs, PRFs, PRPs). In this paper, we consider the complementary and practically important problem of designing secure authentication and encryption schemes. For this purpose, we follow a pragmatic approach based on the advantages and limitations of existing leakage-resilient pseudorandom objects, and rely on the (arguably necessary, yet minimal) use of a leak-free component. The latter can typically be instantiated with a block cipher implementation protected by traditional countermeasures, and we investigate how to combine it with the more intensive use of a much more efficient (less protected) block cipher implementation. Based on these premises, we propose and analyse new constructions of leakage-resilient MAC and encryption schemes, which allow fixing security and efficiency drawbacks of previous proposals in this direction. For encryption, we additionally provide a detailed discussion of why previously proposed (indistinguishability based) security definitions cannot capture actual side-channel attacks, and suggest a relaxed and more realistic way to quantify leakage-resilience in this case, by reducing the security of many iterations of the primitive to the security of a single iteration, independent of the security notion guaranteed by this single iteration (that remains hard to define).
Olivier Pereira, François-Xavier Standaert, Srinivas Vivek 0001
CCS1
2015 SoK: A Comprehensive Analysis of Game-Based Ballot Privacy Definitions
abstract
We critically survey game-based security definitions for the privacy of voting schemes. In addition to known limitations, we unveil several previously unnoticed shortcomings. Surprisingly, the conclusion of our study is that none of the existing definitions is satisfactory: they either provide only weak guarantees, or can be applied only to a limited class of schemes, or both. Based on our findings, we propose a new game-based definition of privacy which we call BPRIV. We also identify a new property which we call strong consistency, needed to express that tallying does not leak sensitive information. We validate our security notions by showing that BPRIV, strong consistency (and an additional simple property called strong correctness) for a voting scheme imply its security in a simulation-based sense. This result also yields a proof technique for proving entropy-based notions of privacy which offer the strongest security guarantees but are hard to prove directly: first prove your scheme BPRIV, strongly consistent (and correct), then study the entropy-based privacy of the result function of the election, which is a much easier task.
David Bernhard, Véronique Cortier, David Galindo, Olivier Pereira, Bogdan Warinschi
IEEE Symposium on Security and Privacy4
2013 Leakage-Resilient Symmetric Cryptography under Empirically Verifiable Assumptions
François-Xavier Standaert, Olivier Pereira, Yu Yu 0001
CRYPTO (1)2
2013 Election Verifiability or Ballot Privacy: Do We Need to Choose?
Edouard Cuvelier, Olivier Pereira, Thomas Peters
ESORICS2
2012 How Not to Prove Yourself: Pitfalls of the Fiat-Shamir Heuristic and Applications to Helios
David Bernhard, Olivier Pereira, Bogdan Warinschi
ASIACRYPT2
2012 Measuring vote privacy, revisited
abstract
We propose a new measure for privacy of votes. Our measure relies on computational conditional entropy, an extension of the traditional notion of entropy that incorporates both information-theoretic and computational aspects. As a result, we capture in a unified manner privacy breaches due to two orthogonal sources of insecurity: combinatorial aspects that have to do with the number of participants, the distribution of their votes and published election outcome as well as insecurity of the cryptography used in an implementation.
David Bernhard, Véronique Cortier, Olivier Pereira, Bogdan Warinschi
CCS3
2011 Leftover Hash Lemma, Revisited
Boaz Barak, Yevgeniy Dodis, Hugo Krawczyk, Olivier Pereira, Krzysztof Pietrzak, François-Xavier Standaert, Yu Yu 0001
CRYPTO4
2011 Adapting Helios for Provable Ballot Privacy
David Bernhard, Véronique Cortier, Olivier Pereira, Ben Smyth, Bogdan Warinschi
ESORICS3
2011 Secure Two-Party Computation over a Z-Channel
Paolo Palmieri 0001, Olivier Pereira
ProvSec2
2010 Practical leakage-resilient pseudorandom generators
abstract
Cryptographic systems and protocols are the core of many Internet security procedures (such as SSL, SSH, IPSEC, DNSSEC, secure mail, etc.). At the heart of all cryptographic functions is a good source of randomness, and for efficiency, the primitive of pseudorandom generator (PRG). PRG can also be used in the design of stream ciphers, for secure communications. The Internet is nowadays composed of many types of devices with very different hardware and software characteristics. Hence, one of the concerns in such open environments is the information "leakage" and its exploitation via the so-called "side channel attacks".
Yu Yu 0001, François-Xavier Standaert, Olivier Pereira, Moti Yung
CCS3
2010 Building Oblivious Transfer on Channel Delays
Paolo Palmieri 0001, Olivier Pereira
Inscrypt2
2009 Simulation based security in the applied pi calculus
abstract
We present a symbolic framework for refinement and composition of security protocols. The framework uses the notion of ideal functionalities. These are abstract systems which are secure by construction and which can be combined into larger systems. They can be separately refined in order to obtain concrete protocols implementing them. Our work builds on ideas from the ``trusted party paradigm'' used in computational cryptography models. The underlying language we use is the applied pi calculus which is a general language for specifying security protocols. In our framework we can express the different standard flavours of simulation-based security which happen to all coincide. We illustrate our framework on an authentication functionality which can be realized using the Needham-Schroeder-Lowe protocol. For this we need to define an ideal functionality for asymmetric encryption and its realization. We show a joint state result for this functionality which allows composition (even though the same key material is reused) using a tagging mechanism.
Stéphanie Delaune, Steve Kremer, Olivier Pereira
FSTTCS3
2008 Automatic Verification of Simulatability in Security Protocols
abstract
This paper investigates the problem of the automatic verification of the computational indistinguishability of systems in the simulation-based security setting, which allows proving the composable security of cryptographic protocols whose security relies on computational hardness assumptions. We use task-structured probabilistic I/O automata (task-PIOA) as our modeling framework. In this context, proofs of indistinguishability between real and ideal systems are typically divided into steps involving either proofs of perfect indistinguishability or proofs of computational indistinguishability. Our method automates the proof of perfect indistinguishability for a class of simple protocols, which is, by far, the most error-prone and time-consuming part of those security proofs. We proceed by transforming the targeted real and ideal probabilistic systems into nondeterministic ones, and check the bisimulation between the obtained systems by a partition refinement algorithm. We prove the correctness of our transformation. Our method has also been implemented in a symbolic way and we showed its usefulness by applying it to a practical protocol for oblivious transfer.
Tadashi Araragi, Olivier Pereira
IAS2
2008 A block cipher based pseudo random number generator secure against side-channel key recovery
abstract
We study the security of a block cipher-based pseudorandom number generator (PRNG), both in the black box world and in the physical world, separately. We first show that the construction is a secure PRNG in the ideal cipher model. Then, we demonstrate its security against a Bayesian side-channel key recovery adversary. As a main result, we show that our construction guarantees that the success rate of the adversary does not increase with the number of physical observations, but in a limited and controlled way. Besides, we observe that, under common assumptions on side-channel attack strategies, increasing the security parameter (typically the block cipher key size) by a polynomial factor involves an increase of a side-channel attack complexity by an exponential factor, making the probability of a successful attack negligible. We believe this work provides a first interesting example of the way the algorithmic design of a cryptographic scheme influences its side-channel resistance.
Christophe Petit 0001, François-Xavier Standaert, Olivier Pereira, Tal Malkin, Moti Yung
AsiaCCS3
2008 Modeling Computational Security in Long-Lived Systems
Ran Canetti, Ling Cheung, Dilsun Kirli Kaynar, Nancy A. Lynch, Olivier Pereira
CONCUR5
2008 Universally Composable Security Analysis of TLS
Sebastian Gajek, Mark Manulis, Olivier Pereira, Ahmad-Reza Sadeghi, Jörg Schwenk
ProvSec3
2008 On the Energy Cost of Communication and Cryptography in Wireless Sensor Networks
abstract
Energy is a central concern in the deployment of wireless sensor networks. In this paper, we investigate the energy cost of cryptographic protocols, both from a communication and a computation point of view, based on practical measurements on the MICAz and TelosB sensors. We focus on the cost of two key agreement protocols: Kerberos and the elliptic curve Diffie-Hellman key exchange with authentication provided by the elliptic curve digital signature algorithm (ECDH-ECDSA). We find that, in our context, Kerberos is around one order of magnitude less costly than the ECDH-ECDSA key exchange and confirm that it should be preferred in situations where a trusted third party is available. We also observe that the power dedicated to communications can become a central concern when the nodes need to stay in listen mode, e.g. between the protocol rounds, even when reduced using a low power listening (LPL) protocol. Therefore, listening should be considered when assessing the cost of cryptographic protocols on sensor nodes.
Giacomo de Meulenaer, François Gosset, François-Xavier Standaert, Olivier Pereira
WiMob4
2007 Compositional Security for Task-PIOAs
abstract
Task-PIOA is a modeling framework for distributed systems with both probabilistic and nondeterministic behaviors. It is suitable for cryptographic applications because its task-based scheduling mechanism is less powerful than the traditional perfect-information scheduler. Moreover, one can speak of two types of complexity restrictions: time bounds on description of task-PIOAs and time bounds on length of schedules. This distinction, along with the flexibility of nondeterministic specifications, are interesting departures from existing formal frameworks for computational security. The current paper presents a new approximate implementation relation for task-PIOAs. This relation is transitive and is preserved under hiding of external actions. Also, it is shown to be preserved under concurrent composition, with any polynomial number of substitutions. Building upon this foundation, we present the notion of structures, which classifies communications into two categories: those with a distinguisher environment and those with an adversary. We then formulate secure emulation in the spirit of traditional simulation-based security, and a composition theorem follows as a corollary of the composition theorem for the new approximate implementation relation.
Ran Canetti, Ling Cheung, Dilsun Kirli Kaynar, Nancy A. Lynch, Olivier Pereira
CSF5
2006 Time-Bounded Task-PIOAs: A Framework for Analyzing Security Protocols
Ran Canetti, Ling Cheung, Dilsun Kirli Kaynar, Moses D. Liskov, Nancy A. Lynch, Olivier Pereira, Roberto Segala
DISC6
2006 On the impossibility of building secure Cliques-type authenticated group key agreement protocols
abstract
The A-GDH.2 and SA-GDH.2 authenticated group key agreement protocols showed to be flawed in 2001. Even though the corresponding attacks (or some variants of them) have been rediscovered in several different frameworks, no fixed version of these protocols has been proposed until now. In this paper, we prove that it is in fact impossible to design a scalable authenticated group key agreement protocol based on the same design assumptions as the A-GDH ones. We proceed by providing a systematic way to derive an attack against any A-GDH-type protocol with at least four participants and exhibit protocols with two and three participants which we cannot break using our technique. As far as we know, this is the first generic insecurity result reported in the literature concerning authentication protocols.
Olivier Pereira, Jean-Jacques Quisquater
J. Comput. Secur.1
2004 Generic Insecurity of Cliques-Type Authenticated Group Key Agreement Protocols
Olivier Pereira, Jean-Jacques Quisquater
CSFW1
2003 Some Attacks Upon Authenticated Group Key Agreement Protocols
abstract
During the last few years, a number of authenticated group key agreement protocols have been proposed in the literature. We observed that the efforts in this domain were mostly dedicated to the improvement of their performance in term of bandwidth or
Olivier Pereira, Jean-Jacques Quisquater
J. Comput. Secur.1
2001 A Security Analysis of the Cliques Protocols Suites
abstract
Secure group protocols are not easy to design: this paper will show new attacks found against a protocol suite for sharing key. The method we propose to analyse these protocols is very systematic, and can be applied to numerous protocols of this type. The A-GDH.2 protocols suite analysed throughout this paper is part of the Cliques suites that propose extensions of the Diffie-Hellman key exchange protocol to a group setting. The A-GDH.2 main protocol is intended to allow a group to share an authenticated key while the other protocols of the suite allow to perform dynamic changes in the group constitution (adding and deleting members, fusion of groups,...). We are proposing an original method to analyse these protocols and are presenting a number of unpublished flaws with respect to each of the main security properties claimed in protocol definition (key authentication, perfect forward secrecy, resistance to known-keys attacks). Most of these flaws arise from the fact that using a group setting does not allow to reason about security properties in the same way as when only two (or three) parties are concerned. Our method has been easily applied on other Cliques protocols and allowed us to pinpoint similar flaws. 1.
Olivier Pereira, Jean-Jacques Quisquater
CSFW1
2001 Security Analysis of the Cliques Protocols Suites: First Results
Olivier Pereira, Jean-Jacques Quisquater
SEC1