Antonio Faonio

dblp:138/9001 · DBLP profile ↗
← Back
26ranked-venue papers
15as first author
12since 2021 · last 2026
0000-0002-7152-6478ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 12 first-author · 11 since 2021Theory of computation · 7 · 4 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Updatable Private Set Intersection and Beyond: Efficient Constructions via Circuit PSI
Ferran Alborch Escobar, Tom Chauvier, Antonio Faonio, Alexandre Fontaine, Ferhat Karakoç, Alptekin Küpçü, Camille Malek, Melek Önen
ACNS (1)3
2026 Sumcheck-Based zkSNARKs are Non-malleable
Antonio Faonio, Luigi Russo 0001
CRYPTO (9)1
2025 SNARKs for Virtual Machines Are Non-malleable
Matteo Campanelli, Antonio Faonio, Luigi Russo 0001
EUROCRYPT (4)2
2024 Real-World Universal zkSNARKs are Non-Malleable
abstract
Simulation extractability is a strong security notion of zkSNARKs that guarantees that an attacker who produces a valid proof must know the corresponding witness, even if the attacker had prior access to proofs generated by other users. Notably, simulation extractability implies that proofs are non-malleable and is of fundamental importance for applications of zkSNARKs in distributed systems. In this work, we study sufficient and necessary conditions for constructing simulation-extractable universal zkSNARKs via the popular design approach based on compiling polynomial interactive oracle proofs (PIOP). Our main result is the first security proof that popular universal zkSNARKs, such as PLONK and Marlin, as deployed in the real world, are simulation-extractable. Our result fills a gap left from previous work (Faonio et al. TCC'23, and Kohlweiss et al. TCC'23) which could only prove the simulation extractability of the "textbook" versions of these schemes and does not capture their optimized variants, with all the popular optimization tricks in place, that are eventually implemented and deployed in software libraries.
Antonio Faonio, Dario Fiore 0001, Luigi Russo 0001
CCS1
2023 From Polynomial IOP and Commitments to Non-malleable zkSNARKs
Antonio Faonio, Dario Fiore 0001, Markulf Kohlweiss, Luigi Russo 0001, Michal Zajac 0001
TCC (3)1
2022 Auditable Asymmetric Password Authenticated Public Key Establishment
Antonio Faonio, María Isabel González Vasco, Claudio Soriente, Hien Thi Thu Truong
CANS1
2022 Subversion-Resilient Enhanced Privacy ID
Antonio Faonio, Dario Fiore 0001, Luca Nizzardo, Claudio Soriente
CT-RSA1
2022 The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for Free
abstract
We show that the most common flavors of noisy leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to a small statistical simulation error and a slight loss in the leakage parameter. The latter holds true in particular for one of the most used noisy-leakage models, where the noisiness is measured using the conditional average min-entropy (Naor and Segev, CRYPTO’09 and SICOMP’12). Our reductions between noisy and bounded leakage are achieved in two steps. First, we put forward a new leakage model (dubbed the dense leakage model) and prove that dense leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to small statistical distance. Second, we show that the most common noisy-leakage models fall within the class of dense leakage, with good parameters. Third, we prove lower bounds on the amount of bounded leakage required for simulation with sub-constant error, showing that our reductions are nearly optimal. In particular, our results imply that useful general simulation of noisy leakage based on statistical distance and mutual information is impossible. We also provide a complete picture of the relationships between different noisy-leakage models. Our result finds applications to leakage-resilient cryptography, where we are often able to lift security in the presence of bounded leakage to security in the presence of noisy leakage, both in the information-theoretic and in the computational setting. Remarkably, this lifting procedure makes only black-box use of the underlying schemes. Additionally, we show how to use lower bounds in communication complexity to prove that bounded-collusion protocols (Kumar, Meka, and Sahai, FOCS’19) for certain functions do not only require long transcripts, but also necessarily need to reveal enough information about the inputs.
Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001
IEEE Trans. Inf. Theory2
2021 Lunar: A Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions
Matteo Campanelli, Antonio Faonio, Dario Fiore 0001, Anaïs Querol, Hadrián Rodríguez
ASIACRYPT (3)2
2021 Practical Continuously Non-malleable Randomness Encoders in the Random Oracle Model
Antonio Faonio
CANS1
2021 The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for Free
Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001
EUROCRYPT (2)2
2021 Continuously Non-malleable Secret Sharing: Joint Tampering, Plain Model and Capacity
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001
TCC (2)2
2020 Improving the Efficiency of Re-randomizable and Replayable CCA Secure Public Key Encryption
Antonio Faonio, Dario Fiore 0001
ACNS (1)1
2020 Non-malleable Secret Sharing Against Bounded Joint-Tampering Attacks in the Plain Model
Gianluca Brian, Antonio Faonio, Maciej Obremski, Mark Simkin 0001, Daniele Venturi 0001
CRYPTO (3)2
2019 Rate-Optimizing Compilers for Continuously Non-malleable Codes
Sandro Coretti, Antonio Faonio, Daniele Venturi 0001
ACNS2
2019 Structure-Preserving and Re-randomizable RCCA-Secure Public Key Encryption and Its Applications
Antonio Faonio, Dario Fiore 0001, Javier Herranz, Carla Ràfols
ASIACRYPT (3)1
2019 Non-malleable Secret Sharing in the Computational Setting: Adaptive Tampering, Noisy-Leakage Resilience, and Improved Rate
Antonio Faonio, Daniele Venturi 0001
CRYPTO (2)1
2019 Efficient Fully-Leakage Resilient One-More Signature Schemes
Antonio Faonio
CT-RSA1
2019 Continuously Non-malleable Secret Sharing for General Access Structures
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001
TCC (2)2
2019 Continuously non-malleable codes with split-state refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001
Theor. Comput. Sci.1
2018 Continuously Non-malleable Codes with Split-State Refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001
ACNS1
2017 Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model
Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001
Theor. Comput. Sci.1
2016 Efficient Public-Key Cryptography with Bounded Leakage and Tamper Resilience
Antonio Faonio, Daniele Venturi 0001
ASIACRYPT (1)1
2015 Mind Your Coins: Fully Leakage-Resilient Signatures with Graceful Degradation
abstract
We construct a new leakage-resilient signature scheme. Our scheme remains unforgeable in the noisy leakage model, where the only restriction on the leakage is that it does not decrease the min-entropy of the secret key by too much. The leakage information can depend on the entire state of the signer; this property is sometimes known as fully leakage resilience. An additional feature of our construction, is that it offers a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen et al. (PKC 2014) in the bounded leakage model, to deal with settings in which the secret key is much larger than the size of a signature. For security parameter $$\kappa $$ , our scheme tolerates leakage on the entire state of the signer until $$\omega (\log \kappa )$$ bits of min-entropy are left in the secret key, and is proven secure in the standard model. While we describe our scheme in terms of generic building blocks, we also explain how to instantiate it efficiently under fairly standard number-theoretic assumptions.
Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001
ICALP (1)1
2015 Leakage-Resilient Identification Schemes from Zero-Knowledge Proofs of Storage
Giuseppe Ateniese, Antonio Faonio, Seny Kamara
IMACC2
2014 Certified Bitcoins
Giuseppe Ateniese, Antonio Faonio, Bernardo Magri, Breno de Medeiros
ACNS2