Lorenzo Grassi 0001

dblp:166/8773-1 · DBLP profile ↗
← Back
29ranked-venue papers
18as first author
14since 2021 · last 2026
0000-0003-1140-0520ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 18 first-author · 14 since 2021
YearPublicationVenuePosition
2026 The ABC of Symmetric Primitives over Integer Rings: Milk Before Meat
Tim Beyne, Lorenzo Grassi 0001, Morten Øygarden, Berenika Richterová, Arne Sandrib
CRYPTO (6)2
2025 On generalizations of the Lai-Massey scheme
abstract
Abstract In this paper, we re-investigate the Lai–Massey scheme, originally proposed in the cipher IDEA. Due to the similarity with the Feistel networks, and due to the existence of invariant subspace attacks as originally pointed out by Vaudenay at FSE 1999, the Lai–Massey scheme has received only little attention by the community. As first contribution, we propose two new generalizations of such scheme that are not (extended) affine equivalent to any generalized Feistel network proposed in the literature so far. Then, inspired by the recent construction, we propose the structure as a generalization of the Lai–Massey scheme, in which the linear combination in the Lai–Massey scheme can be replaced by a non-linear one. Besides proposing concrete examples of the construction, we analyze its cryptographic properties in the context of MPC-/HE-/ZK-friendly symmetric primitives.
Lorenzo Grassi 0001
Des. Codes Cryptogr.1
2024 General Practical Cryptanalysis of the Sum of Round-Reduced Block Ciphers and ZIP-AES
Antonio Flórez-Gutiérrez, Lorenzo Grassi 0001, Gregor Leander, Ferdinand Sibleyras, Yosuke Todo
ASIACRYPT (9)2
2024 Generalized Feistel Ciphers for Efficient Prime Field Masking
Lorenzo Grassi 0001, Loïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier Standaert
EUROCRYPT (3)1
2024 Minimize the Randomness in Rasta-Like Designs: How Far Can We Go? - Application to Pasta
Lorenzo Grassi 0001, Fukang Liu, Christian Rechberger, Fabian Schmid, Roman Walch, Qingju Wang 0001
SAC (2)1
2023 Cryptanalysis of Symmetric Primitives over Rings and a Key Recovery Attack on Rubato
Lorenzo Grassi 0001, Irati Manterola Ayala, Martha Norberg Hovd, Morten Øygarden, Håvard Raddum, Qingju Wang 0001
CRYPTO (3)1
2023 Horst Meets Fluid-SPN: Griffin for Zero-Knowledge Applications
Lorenzo Grassi 0001, Yonglin Hao, Christian Rechberger, Markus Schofnegger, Roman Walch, Qingju Wang 0001
CRYPTO (3)1
2023 Coefficient Grouping for Complex Affine Layers
Fukang Liu, Lorenzo Grassi 0001, Clémence Bouvier, Willi Meier, Takanori Isobe 0001
CRYPTO (3)2
2023 From Farfalle to Megafono via Ciminion: The PRF Hydra for MPC Applications
Lorenzo Grassi 0001, Morten Øygarden, Markus Schofnegger, Roman Walch
EUROCRYPT (4)1
2022 Truncated Differential Properties of the Diagonal Set of Inputs for 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger
ACISP1
2022 Security of Truncated Permutation Without Initial Value
Lorenzo Grassi 0001, Bart Mennink
ASIACRYPT (2)1
2022 Reinforced Concrete: A Fast Hash Function for Verifiable Computation
abstract
We propose a new hash function Reinforced Concrete, which is the first generic purpose hash that is fast both for a zero-knowledge prover and in native x86 computations. It is suitable for a various range of zero-knowledge proofs and protocols, from set membership to generic purpose verifiable computation. Being up to 15x faster than its predecessor Poseidon hash, Reinforced Concrete inherits security from traditional time-tested schemes such as AES, whereas taking the zero-knowledge performance from a novel and efficient decomposition of a prime field into compact buckets.
Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger, Roman Walch
CCS1
2021 Ciminion: Symmetric Encryption Based on Toffoli-Gates over Large Finite Fields
Christoph Dobraunig, Lorenzo Grassi 0001, Anna Guinet, Daniël Kuijsters
EUROCRYPT (2)2
2021 Poseidon: A New Hash Function for Zero-Knowledge Proof Systems
Lorenzo Grassi 0001, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 0005, Markus Schofnegger
USENIX Security Symposium1
2020 An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC
Maria Eichlseder, Lorenzo Grassi 0001, Reinhard Lüftenegger, Morten Øygarden, Christian Rechberger, Markus Schofnegger, Qingju Wang 0001
ASIACRYPT (1)2
2020 On a Generalization of Substitution-Permutation Networks: The HADES Design Strategy
Lorenzo Grassi 0001, Reinhard Lüftenegger, Christian Rechberger, Dragos Rotaru, Markus Schofnegger
EUROCRYPT (2)1
2020 Algebraic Key-Recovery Attacks on Reduced-Round Xoofff
Tingting Cui, Lorenzo Grassi 0001
SAC2
2020 Weak-Key Distinguishers for AES
Lorenzo Grassi 0001, Gregor Leander, Christian Rechberger, Cihangir Tezcan, Friedrich Wiemer
SAC1
2020 Revisiting Gilbert's known-key distinguisher
abstract
Abstract Known-key distinguishers have been introduced by Knudsen and Rijmen in 2007 to better understand the security of block ciphers in situations where the key can not be considered to be secret, i.e. the “thing between secret-key model and hash function use-cases”. Trying to find a rigorous model to fit this intuition is still ongoing. The most recent advance by Gilbert (Asiacrypt 2014) describes a new model that—even if it is well justified—seemingly does not match this intuition. AES is often considered as a target of such analyses, simply because AES or its building blocks are used in many settings that go beyond classical encryption. Consider AES-128. Results in the secret-key model cover up to 6 rounds, while results in the chosen-key model reach up to 9 rounds. Gilbert however showed a result in the known-key model that goes even further, covering 10 rounds. Does it mean that the use cases corresponding to the cryptanalysis of hash-function use-cases are inherently less efficient, or is it rather an artifact of the new model? In this paper we give strong evidence for the latter. In Gilbert’s work, two types of arguments or rather conjectures are put forward suggesting that the new model is meaningful. Firstly that the number of “extension rounds” due to the new model is limited to two. And secondly that only a distinguisher that exploits the uniform distribution property can be extended in such way. We disprove both conjectures and arrive at the following results: First, we are also able to show that more than two extension rounds are possible. As a result of this, we describe the first known-key distinguishers on 12 rounds of AES that fit into Gilbert’s model. The second conjecture is disproven by showing that the technique proposed by Gilbert can also be used to extend a known-key distinguisher based on another property: truncated differentials. A potential conclusion of this work would be that the counter-intuitive gap between Gilbert’s known-key model and the chosen-key model is wider than initially thought. We however conclude that results in Gilbert’s model are due to an artifact in the model. To remedy this situation, we propose a refinement of the known-key model which restores its original intent to fit the original intuition.
Lorenzo Grassi 0001, Christian Rechberger
Des. Codes Cryptogr.1
2019 Algebraic Cryptanalysis of STARK-Friendly Designs: Application to MARVELlous and MiMC
Martin R. Albrecht, Carlos Cid, Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger
ASIACRYPT (3)3
2019 Feistel Structures for MPC, and More
Martin R. Albrecht, Lorenzo Grassi 0001, Léo Perrin, Sebastian Ramacher, Christian Rechberger, Dragos Rotaru, Arnab Roy 0005, Markus Schofnegger
ESORICS (2)2
2019 Probabilistic Mixture Differential Cryptanalysis on Round-Reduced AES
Lorenzo Grassi 0001
SAC1
2018 Quantum Algorithms for the k -xor Problem
Lorenzo Grassi 0001, María Naya-Plasencia, André Schrottenloher
ASIACRYPT (1)1
2018 Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger
CRYPTO (1)3
2018 MixColumns Properties and Attacks on (Round-Reduced) AES with a Single Secret S-Box
Lorenzo Grassi 0001
CT-RSA1
2018 Zero-Sum Partitions of PHOTON Permutations
Qingju Wang 0001, Lorenzo Grassi 0001, Christian Rechberger
CT-RSA2
2017 A New Structural-Differential Property of 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger, Sondre Rønjom
EUROCRYPT (2)1
2016 MiMC: Efficient Encryption and Cryptographic Hashing with Minimal Multiplicative Complexity
Martin R. Albrecht, Lorenzo Grassi 0001, Christian Rechberger, Arnab Roy 0005, Tyge Tiessen
ASIACRYPT (1)2
2016 MPC-Friendly Symmetric Key Primitives
abstract
We discuss the design of symmetric primitives, in particular Pseudo-Random Functions (PRFs) which are suitable for use in a secret-sharing based MPC system. We consider three different PRFs: the Naor-Reingold PRF, a PRF based on the Legendre symbol, and a specialized block cipher design called MiMC. We present protocols for implementing these PRFs within a secret-sharing based MPC system, and discuss possible applications. We then compare the performance of our protocols. Depending on the application, different PRFs may offer different optimizations and advantages over the classic AES benchmark. Thus, we cannot conclude that there is one optimal PRF to be used in all situations.
Lorenzo Grassi 0001, Christian Rechberger, Dragos Rotaru, Peter Scholl, Nigel P. Smart
CCS1