VLDB 2026 Research / reviewers in the wild / expert
Lucjan Hanzlik
dblp:119/3581
· DBLP profile ↗
44ranked-venue papers
17as first author
22since 2021 · last 2026
0009-0006-1941-693XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 42 · 15 first-author · 22 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Post-Quantum Blind Signature from Standard Group Action Assumptions and More
Lucjan Hanzlik, Yi-Fu Lai, Eugenio Paracucchi, Edoardo Persichetti |
EUROCRYPT (1) | 1 |
| 2026 | When Threshold Meets Anamorphic Signatures: What is Possible and What is Not!abstractAnamorphic signatures allow covert communication through signatures in environments where encryption is restricted. They enable trusted recipients with a double-key to extract hidden messages while the signature remains indistinguishable from a regular one. However, the traditional notion of anamorphic signatures suffers from vulnerabilities, particularly when a single recipient or sender is compromised, exposing all hidden messages and providing undeniable proof that citizens are part of the anamorphic exchange. To address these limitations, we explore a threshold-based approach to distribute trust among multiple recipients, preventing adversaries from decrypting anamorphic messages even if some recipients are compromised. Our first contribution is the formalization of the notion of threshold-recipient anamorphic signatures, where decryption is possible only through collaboration among a subset of recipients. We then explore a stronger model in which the dictator controls the key-generation process through which it learns all secret keys, as well as how citizens store cryptographic keys. A particular example of this model in the real world is a dictator providing citizens with electronic identity documents (eIDs) and blocking all other usage of cryptography. We demonstrate that anamorphic communication is still possible even in such a scenario. Our construction is secure against quantum adversaries and does not rely on any computational assumptions beyond the random-oracle model. Finally, we present an impossibility result for encoding anamorphic messages with a threshold-sender model when using many existing threshold signature schemes, even when the adversary is part of the signing group. Our work outlines both the possibilities and limitations of extending anamorphic signatures with threshold cryptography, offering new insights into improving the security and privacy of individuals under authoritarian regimes. Hien Chu, Khue Do, Lucjan Hanzlik, Sri Aravinda Krishnan Thyagarajan |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Tanuki: New Frameworks for (Concurrently Secure) Blind Signatures from Post-Quantum Group Actions
Lucjan Hanzlik, Yi-Fu Lai, Marzio Mula, Eugenio Paracucchi, Daniel Slamanig |
ASIACRYPT (4) | 1 |
| 2025 | VRaaS: Verifiable Randomness as a Service on BlockchainsabstractWeb3 applications, such as on-chain games, NFT minting, and leader elections necessitate access to unbiased, unpredictable, and publicly verifiable randomness. Despite its broad use cases and huge demand, there is a notable absence of comprehensive treatments of on-chain verifiable randomness services. To bridge this, we offer an extensive formal analysis of on-chain verifiable randomness services. We present the first formalization of on-chain verifiable randomness in the blockchain setting by introducing the notion of Verifiable Randomness as a Service (VRaaS). We formally define VRaaS using an ideal functionality$\mathcal{F}\text{VRaaS}$in the Universal Composability model. Our definition not only captures the core features of randomness services, such as unbiasability, unpredictability, and public verifiability, but also accounts for many other crucial nuances pertaining to different entities involved, such as smart contracts. Within our framework we study a generic design of Verifiable Random Function (VRF)-based randomness service - where the randomness requester provides an input on which the randomness is evaluated as VRF output. We show that it does satisfy our formal VRaaS definition. Furthermore, we show that the generic protocol captures many real-world randomness services like Chainlink VRF and Supra dVRF. Moreover, we investigate the minimalism of the frame-work. Towards that, first we show that, the two transactions in-built in our framework are actually necessary for any randomness service to support the essential qualities. We also discover practical vulnerabilities in other designs such as Algorand beacon, Pyth VRF and Band VRF, captured within our framework. Jacob Gorman, Lucjan Hanzlik, Aniket Kate, Easwar Vivek Mangipudi, Pratyay Mukherjee, Pratik Sarkar, Sri Aravinda Krishnan Thyagarajan |
CSF | 2 |
| 2025 | Non-interactive Blind Signatures from RSA Assumption and More
Lucjan Hanzlik, Eugenio Paracucchi, Riccardo Zanotto |
EUROCRYPT (2) | 1 |
| 2025 | Vitārit: Paying for Threshold Services on Bitcoin and FriendsabstractBlockchain service offerings have seen a rapid rise in recent times. Many of these services realize a decentralized architecture with a threshold adversary to avoid a single point of failure and to mitigate key escrow issues. Although payments to such services are straightforward in systems that support smart contracts, achieving fairness poses challenges in systems like Bitcoin, which use the UTXO model with limited scripting capabilities. This is especially challenging without smart contracts, as we wish to pay only the required threshold of$t$+ 1 out of the$n$servers offering the service, without any server claiming payment twice. In this paper, we introduce Vitārit11.A Sanskrit word for ‘distributed’, a novel payment solution tailored for threshold cryptographic services in UTXO systems like Bitcoin. Our approach guarantees robust, provable security while facilitating practical deployment. We focus on the t-out-of-n distributed threshold verifiable random function (VRF) service with certain properties, such as threshold BLS signatures, a recently highlighted area of interest. Our protocol enables clients to request verifiable random function (VRF) values from the threshold service, triggering payments to up to$t$+ 1 servers of the distributed threshold VRF. Our efficient design relies on simple transactions using signature verification scripts, making it immediately applicable in Bitcoin-like systems. We also introduce new tools and techniques at both the cryptographic and transaction layers, including a novel signature-VRF exchange protocol for standard constructions, which may be of independent interest. Additionally, our transaction flow design prevents malicious servers from claiming payments twice, offering broader implications for decentralized payment systems. Our prototype implementation shows that in the two-party interaction, the client takes 126.4 msec, and the server takes 204 msec, demonstrating practicality and deployability of the system. Sri Aravinda Krishnan Thyagarajan, Easwar Vivek Mangipudi, Lucjan Hanzlik, Aniket Kate, Pratyay Mukherjee |
SP | 3 |
| 2024 | Delegating FIDO Credentials Using Single-use ECDSA SignaturesabstractSingle-use delegatable signatures allow a delegatee to give the signing right in a restrictive way to a third party. This cryptographic primitive finds applications in the design of blank checks and can even delegate access rights in web authentication. Unfortunately, known constructions work only with non-standard signature schemes and require non-existing secure hardware, making them impractical. Wei-Zhu Yeoh, Lucjan Hanzlik, Oliver Valta |
AsiaCCS | 2 |
| 2024 | M&M'S: Mix and Match Attacks on Schnorr-Type Blind Signatures with Repetition
Khue Do, Lucjan Hanzlik, Eugenio Paracucchi |
EUROCRYPT (6) | 2 |
| 2024 | SoK: Signatures with Randomizable Keys
Sofía Celi, Scott Griffy, Lucjan Hanzlik, Octavio Perez-Kempner, Daniel Slamanig |
FC (2) | 3 |
| 2024 | Sweep-UC: Swapping Coins PrivatelyabstractFair exchange (also referred to as atomic swap) is a fundamental operation in any cryptocurrency that allows users to atomically exchange coins. While a large body of work has been devoted to this problem, most solutions lack on-chain privacy. Thus, coins retain a public transaction history which is known to degrade the fungibility of a currency. This has led to a flourishing line of related research on fair exchange with privacy guarantees. Existing protocols either rely on heavy scripting (which also degrades fungibility and leads to high transaction fees), do not support atomic swaps across a wide range of currencies, or come with incomplete security proofs.To overcome these limitations, we introduce Sweep-UC1, the first fair exchange protocol that simultaneously is efficient, minimizes scripting, and is compatible with a wide range of currencies (more than the state of the art). We build SweepUC from modular sub-protocols and give a rigorous security analysis in the UC framework. Many of our tools and security definitions can be used in standalone fashion and may serve as useful components for future constructions of fair exchange. Lucjan Hanzlik, Julian Loss, Sri Aravinda Krishnan Thyagarajan, Benedikt Wagner |
SP | 1 |
| 2023 | On the Security of Rate-limited Privacy PassabstractThe privacy pass protocol allows users to redeem anonymously issued cryptographic tokens instead of solving annoying CAPTCHAs. The issuing authority verifies the credibility of the user, who can later use the pass while browsing the web using an anonymous or virtual private network. Hendrickson et al. proposed an IETF draft (privacypass-rate-limit-tokens-00) for a rate-limiting version of the privacy pass protocol, also called rate-limited Privacy Pass(RlP). Introducing a new actor called a mediator makes both versions inherently different. The mediator applies access policies to rate-limit users' access to the service while, at the same time, should be oblivious to the website/origin the user is trying to access. In this paper, we formally define the rate-limited Privacy Pass protocol and propose a game-based security model to capture the informal security notions introduced by Hendrickson et al.. We show a construction from simple building blocks that fulfills our security definitions and even allows for a post-quantum secure instantiation. Interestingly, the instantiation proposed in the IETF draft is a specific case of our construction. Thus, we can reuse the security arguments for the generic construction and show that the version used in practice is secure. Hien Chu, Khue Do, Lucjan Hanzlik |
CCS | 3 |
| 2023 | Post Quantum Fuzzy Stealth Signatures and ApplicationsabstractPrivate payments in blockchain-based cryptocurrencies have been a topic of research, both academic and industrial, ever since the advent of Bitcoin. Stealth address payments were proposed as a solution to improve payment privacy for users and are, in fact, deployed in several major cryptocurrencies today. The mechanism lets users receive payments so that none of these payments are linkable to each other or the recipient. Currently known stealth address mechanisms either (1) are insecure in certain reasonable adversarial models, (2) are inefficient in practice or (3) are incompatible with many existing currencies. Sihang Pu, Sri Aravinda Krishnan Thyagarajan, Nico Döttling, Lucjan Hanzlik |
CCS | 4 |
| 2023 | Non-interactive Blind Signatures for Random Messages
Lucjan Hanzlik |
EUROCRYPT (5) | 1 |
| 2023 | Rai-Choo! Evolving Blind Signatures to the Next Level
Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
EUROCRYPT (5) | 1 |
| 2023 | McFly: Verifiable Encryption to the Future Made Practical
Nico Döttling, Lucjan Hanzlik, Bernardo Magri, Stella Wohnig |
FC (1) | 2 |
| 2023 | Token meets Wallet: Formalizing Privacy and Revocation for FIDO2abstractThe FIDO2 standard is a widely-used class of challenge-response type protocols that allows to authenticate to an online service using a hardware token. Barbosa et al. (CRYPTO ‘21) provided the first formal security model and analysis for the FIDO2 standard. However, their model has two shortcomings: (1) It does not include privacy, one of the key features claimed by FIDO2. (2) It only covers tokens that store all secret keys locally. In contrast, due to limited memory, most existing FIDO2 tokens either derive all secret keys from a common seed or store keys on the server (the latter approach is also known as key wrapping).In this paper, we revisit the security of the WebAuthn component of FIDO2 as implemented in practice. Our contributions are as follows. (1) We adapt the model of Barbosa et al. so as to capture authentication tokens using key derivation or key wrapping. (2) We provide the first formal definition of privacy for the WebAuthn component of FIDO2. We then prove the privacy of this component in common FIDO2 token implementations if the underlying building blocks are chosen appropriately. (3) We address the unsolved problem of global key revocation in FIDO2. To this end, we introduce and analyze a simple revocation procedure that builds on the popular BIP32 standard used in cryptocurrency wallets and can efficiently be implemented with existing FIDO2 servers. Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
SP | 1 |
| 2023 | Fast IDentity Online with Anonymous Credentials (FIDO-AC)
Wei-Zhu Yeoh, Michal Kepkowski, Gunnar Heide, Mohamed Ali Kâafar, Lucjan Hanzlik |
USENIX Security Symposium | 5 |
| 2022 | FeIDo: Recoverable FIDO2 Tokens Using Electronic IDsabstractTwo-factor authentication (2FA) mitigates the security risks of passwords as sole authentication factor. FIDO2---the de facto standard for interoperable web authentication---leverages strong, hardware-backed second factors. However, practical challenges hinder wider FIDO2 user adoption for 2FA tokens, such as the extra costs (20-30 per token) or the risk of inaccessible accounts upon token loss/theft. Fabian Schwarz, Khue Do, Gunnar Heide, Lucjan Hanzlik, Christian Rossow |
CCS | 4 |
| 2022 | PI-Cut-Choo and Friends: Compact Blind Signatures via Parallel Instance Cut-and-Choose and More
Rutchathon Chairattana-Apirom, Lucjan Hanzlik, Julian Loss, Anna Lysyanskaya, Benedikt Wagner |
CRYPTO (3) | 2 |
| 2022 | A Framework for Constructing Single Secret Leader Election from MPC
Michael Backes 0001, Pascal Berrang, Lucjan Hanzlik, Ivan Pryvalov |
ESORICS (2) | 3 |
| 2022 | How Not to Handle Keys: Timing Attacks on FIDO Authenticator PrivacyabstractThis paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by the FIDO industry alliance for secure token online authentication. It complements the W3C WebAuthn specification by providing means to use a USB token or other authenticator (which holds the secret authenticating material and implements FIDO protocols) as a second factor during the authentication process. From a cryptographic perspective, the protocol is a simple challenge-response where the elliptic curve digital signature algorithm is used to sign challenges. To protect the privacy of the user the token uses unique key pairs per service. To accommodate for small memory, tokens use various techniques that make use of a special parameter called a key handle sent by the service to the token with which the token can securely produce an authentication key (through generation or decryption). We identify and analyse a vulnerability in the way the processing of key handles is implemented that allows attackers to remotely link user accounts on multiple services. We show that for vulnerable authenticators there is a difference between the time it takes to process a key handle for a different service but correct authenticator, and for a different authenticator but correct service. This difference can be used to perform a timing attack allowing an adversary to link user’s accounts across services. We present several real world examples of adversaries that are in a position to execute our attack and can benefit from linking accounts. We found that two of the eight hardware authenticators we tested were vulnerable despite FIDO level 1 certification, indicating a not insignificant problem. This vulnerability cannot be easily mitigated on authenticators because, for security reasons, they usually do not allow firmware updates. In addition, we show that due to the way existing browsers implement the WebAuthn standard, the attack can be executed remotely. However, we discuss countermeasures that can be implemented by browser providers to mitigate the remote form of the attack. Michal Kepkowski, Lucjan Hanzlik, Ian D. Wood, Mohamed Ali Kâafar |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | With a Little Help from My Friends: Constructing Practical Anonymous CredentialsabstractAnonymous credentials (ACs) are a powerful cryptographic tool for the secure use of digital services, when simultaneously aiming for strong privacy guarantees of users combined with strong authentication guarantees for providers of services. They allow users to selectively prove possession of attributes encoded in a credential without revealing any other meaningful information about themselves. While there is a significant body of research on AC systems, modern use-cases of ACs such as mobile applications come with various requirements not sufficiently considered so far. These include preventing the sharing of credentials and coping with resource constraints of the platforms (e.g., smart cards such as SIM cards in smartphones). Such aspects are typically out of scope of AC constructions, and, thus AC systems that can be considered entirely practical have been elusive so far. Lucjan Hanzlik, Daniel Slamanig |
CCS | 1 |
| 2020 | TrollThrottle - Raising the Cost of Astroturfing
Ilkan Esiyok, Lucjan Hanzlik, Robert Künnemann, Lena Marie Budde, Michael Backes 0001 |
ACNS (2) | 2 |
| 2020 | Single Secret Leader ElectionabstractIn a Single Secret Leader Election (SSLE), a group of participants aim to randomly choose exactly one leader from the group with the restriction that the identity of the leader will be known to the chosen leader and nobody else. At a later time, the elected leader should be able to publicly reveal her identity and prove that she has won the election. The election process itself should work properly even if many registered users are passive and do not send any messages. Among the many applications of SSLEs, their potential for enabling more efficient proof-of-stake based cryptocurrencies have recently received increased attention. Dan Boneh, Saba Eskandarian, Lucjan Hanzlik, Nicola Greco |
AFT | 3 |
| 2019 | Membership Privacy for Fully Dynamic Group SignaturesabstractGroup signatures present a compromise between the traditional goals of digital signatures and the need for signer privacy, allowing for the creation of unforgeable signatures in the name of a group which reveal nothing about the actual signer's identity beyond their group membership. An important consideration that is absent in prevalent models is that group membership itself may be sensitive information, especially if group membership is dynamic, i.e. membership status may change over time. We address this issue by introducing formal notions of membership privacy for fully dynamic group signature schemes, which can be easily integrated into the most expressive models of group signature security to date. We then propose a generic construction for a fully dynamic group signature scheme with membership privacy that is based on signatures with flexible public key (SFPK) and signatures on equivalence classes (SPSEQ). Finally, we devise novel techniques for SFPK to construct a highly efficient standard model scheme (i.e. without random oracles) that provides shorter signatures than even the non-private state-of-the-art from standard assumptions. This shows that, although the strictly stronger security notions we introduce have been completely unexplored in the study of fully dynamic group signatures so far, they do not come at an additional cost in practice. Michael Backes 0001, Lucjan Hanzlik, Jonas Schneider-Bensch |
CCS | 2 |
| 2019 | Ring Signatures: Logarithmic-Size, No Setup - from Standard Assumptions
Michael Backes 0001, Nico Döttling, Lucjan Hanzlik, Kamil Kluczniak, Jonas Schneider-Bensch |
EUROCRYPT (3) | 3 |
| 2019 | simTPM: User-centric TPM for Mobile Devices
Dhiman Chakraborty 0001, Lucjan Hanzlik, Sven Bugiel |
USENIX Security Symposium | 2 |
| 2019 | CTRL-PACE: Controlled Randomness for e-Passport Password AuthenticationabstractSecurity of many cryptographic protocols is conditioned by the quality of the random elements generated in the course of the protocol execution. On the other hand, cryptographic devices implementing these protocols are designed given technical limitations, usability requirements and cost constraint s. This frequently results in a black box solution. Unfortunately, black box random number generators may enable creating backdoors for stealing signing keys, breaking authentication protocols and encrypted communication. In this paper we deal with this problem and extend our approach proposed during MYCRYPT’2016. The solution discussed is generating random parameters so that: (a) the protocols are backwards compatible (a user gets additional data that can be simply ignored), (b) verification of randomness might be executed any time without notice, so a device is forced to behave honestly, (c) the solution makes almost no intrusion in the existing protocols and is easy to implement, (d) the owner of a cryptographic device becomes secured against its designer and manufacturer that may even predict the output of the generator. In this paper we focus on a case when Diffie-Hellman protocol is executed for a generator that itself is a secret – this case has not been solved in our paper from MYCRYPT’2016. On the other hand, exactly this case occurs for the PACE protocol from the ICAO standard specifying electronic travel documents. For the sake of the proof we develop a framework of nested security games that aims to enable security proofs of modified protocols without redoing the proofs designed for their original versions. Lucjan Hanzlik, Kamil Kluczniak, Miroslaw Kutylowski |
Fundam. Informaticae | 1 |
| 2018 | Signatures with Flexible Public Key: Introducing Equivalence Classes for Public Keys
Michael Backes 0001, Lucjan Hanzlik, Kamil Kluczniak, Jonas Schneider-Bensch |
ASIACRYPT (2) | 2 |
| 2016 | Pseudonymous Signature on eIDAS Token - Implementation Based Privacy Threats
Miroslaw Kutylowski, Lucjan Hanzlik, Kamil Kluczniak |
ACISP (2) | 2 |
| 2016 | A Formal Concept of Domain Pseudonymous Signatures
Kamil Kluczniak, Lucjan Hanzlik, Miroslaw Kutylowski |
ISPEC | 2 |
| 2016 | Chip Authentication for E-Passports: PACE with Chip Authentication Mapping v2
Lucjan Hanzlik, Miroslaw Kutylowski |
ISC | 1 |
| 2016 | Thermal Imaging Attacks on Keypad Security SystemsabstractThe paper discusses the issue of thermal imaging attacks on a variety of keyboard devices, such as cash machines, payment terminals, combination locks or computer keyboards. The aim of the research was to obtain the entered code or password in the most non-invasive way. As it turned out, attacks based on images from thermal imaging cameras are very easy to carry out and work in almost every case, which calls for extra safety measures. The authors consider various attack scenarios and come up with recommendations for both manufacturers and users of electronic keyboard security systems. Wojciech Wodo, Lucjan Hanzlik |
SECRYPT | 2 |
| 2016 | Computations on Private Sets and their Application to Biometric based Authentication SystemsabstractIn this paper we investigate the concept of cancelable biometrics and propose a new scheme for user authorisation providing anonymity based on privacy-preserving computations on sets. We define a problem called (t;n) -Threshold Subset Problem and apply it to a biometric-based security system. Our solution implements biometric template protection based on one-way transformations and Bloom filters. Users authentication data is stored in form of a whitelist and the authorisation process is based on a zero-knowledge proof approach. Using oblivious polynomial evaluation (OPE) a legitimate user is able to recreate a secret polynomial and answer the challenge send by a verifier. We assume that biometric data can be acquired and digitized to the form of a vector representation. Wojciech Wodo, Lucjan Hanzlik, Kamil Kluczniak |
SECRYPT | 2 |
| 2015 | Recovering Lost Device-Bound Credentials
Foteini Baldimtsi, Jan Camenisch, Lucjan Hanzlik, Stephan Krenn, Anja Lehmann, Gregory Neven |
ACNS | 3 |
| 2015 | Tracing Attacks on U-Prove with Revocation Mechanism: Tracing Attacks for U-ProveabstractAnonymous credential systems have to provide strong privacy protection: a user may prove his (chosen) attributes without leaking neither his identity nor other attributes. In this paper we consider U-Prove - one of the major commercial anonymous credential systems. Lucjan Hanzlik, Przemyslaw Kubiak 0001, Miroslaw Kutylowski |
AsiaCCS | 1 |
| 2015 | Hard Invalidation of Electronic Signatures
Lucjan Hanzlik, Miroslaw Kutylowski, Moti Yung |
ISPEC | 1 |
| 2015 | Anonymous Evaluation System
Kamil Kluczniak, Lucjan Hanzlik, Przemyslaw Kubiak 0001, Miroslaw Kutylowski |
NSS | 2 |
| 2014 | Stand-by Attacks on E-ID Password Authentication
Lucjan Hanzlik, Przemyslaw Kubiak 0001, Miroslaw Kutylowski |
Inscrypt | 1 |
| 2014 | Forbidden City Model - Towards a Practice Relevant Framework for Designing Cryptographic Protocols
Miroslaw Kutylowski, Lucjan Hanzlik, Kamil Kluczniak, Przemyslaw Kubiak 0001, Lukasz Krzywiecki |
ISPEC | 2 |
| 2014 | Attack against a Pairing Based Anonymous Authentication Protocol
Lucjan Hanzlik, Kamil Kluczniak |
SOFSEM | 1 |
| 2013 | Simplified PACE|AA Protocol
Lucjan Hanzlik, Lukasz Krzywiecki, Miroslaw Kutylowski |
ISPEC | 1 |
| 2013 | Identity Security in Biometric Systems based on Keystroking
Lucjan Hanzlik, Wojciech Wodo |
SECRYPT | 1 |
| 2012 | Restricted Identification without Group KeysabstractWe present a variant of the protocol stack for anonymous authentication implemented in German personal identity documents. We strengthen the system by eliminating group keys - a potential target of attack for a powerful adversary aiming to undermine Restricted Identification mechanisms. We provide a mechanism of authentication that merges Chip Authentication protocol with Restricted Identification. Lucjan Hanzlik, Kamil Kluczniak, Przemyslaw Kubiak 0001, Miroslaw Kutylowski |
TrustCom | 1 |