VLDB 2026 Research / reviewers in the wild / expert
Lior Rotem
dblp:168/7887
· DBLP profile ↗
23ranked-venue papers
13as first author
15since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 13 first-author · 15 since 2021Theory of computation · 6 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Context-Dependent Threshold Decryption and Its Applications
Dan Boneh, Benedikt Bünz, Kartik Nayak, Lior Rotem, Victor Shoup |
ASIACRYPT (6) | 4 |
| 2025 | Traceable Verifiable Random Functions
Dan Boneh, Aditi Partap, Lior Rotem |
CRYPTO (2) | 3 |
| 2025 | Straight-Line Knowledge Extraction for Multi-Round Protocols
Lior Rotem, Stefano Tessaro |
CRYPTO (7) | 1 |
| 2024 | Traceable Secret Sharing: Strong Security and Efficient Constructions
Dan Boneh, Aditi Partap, Lior Rotem |
CRYPTO (5) | 3 |
| 2024 | Accountability for Misbehavior in Threshold Decryption via Threshold Traitor Tracing
Dan Boneh, Aditi Partap, Lior Rotem |
CRYPTO (7) | 3 |
| 2024 | Proactive Refresh for Accountable Threshold Signatures
Dan Boneh, Aditi Partap, Lior Rotem |
FC (2) | 3 |
| 2024 | From One-Time to Two-Round Reusable Multi-signatures Without Nested Forking
Lior Rotem, Gil Segev 0001, Eylon Yogev |
TCC (3) | 1 |
| 2024 | Tighter Security for Schnorr Identification and Signatures: A High-Moment Forking Lemma for $\varvec{\Sigma }$-Protocols
Lior Rotem, Gil Segev 0001 |
J. Cryptol. | 1 |
| 2023 | Post-Quantum Single Secret Leader Election (SSLE) from Publicly Re-Randomizable CommitmentsabstractA Single Secret Leader Election (SSLE) enables a group of parties to randomly choose exactly one leader from the group with the restriction that the identity of the leader will be known to the chosen leader and nobody else. At a later time, the elected leader should be able to publicly reveal her identity and prove that she is the elected leader. The election process itself should work properly even if many registered users are passive and do not send any messages. SSLE is used to strengthen the security of proof-of-stake consensus protocols by ensuring that the identity of the block proposer remains unknown until the proposer publishes a block. Boneh, Eskandarian, Hanzlik, and Greco (AFT'20) defined the concept of an SSLE and gave several constructions. Their most efficient construction is based on the difficulty of the Decision Diffie-Hellman problem in a cyclic group. In this work we construct the first efficient SSLE protocols based on the standard Learning With Errors (LWE) problem on integer lattices, as well as the Ring-LWE problem. Both are believed to be post-quantum secure. Our constructions generalize the paradigm of Boneh et al. by introducing the concept of a re-randomizable commitment (RRC). We then construct several post-quantum RRC schemes from lattice assumptions and prove the security of the derived SSLE protocols. Constructing a lattice-based RRC scheme is non-trivial, and may be of independent interest. Dan Boneh, Aditi Partap, Lior Rotem |
AFT | 3 |
| 2023 | Non-malleable Vector Commitments via Local Equivocability
Lior Rotem, Gil Segev 0001 |
J. Cryptol. | 1 |
| 2022 | From Fairness to Full Security in Multiparty Computation
Ran Cohen, Iftach Haitner, Eran Omri, Lior Rotem |
J. Cryptol. | 4 |
| 2021 | Tighter Security for Schnorr Identification and Signatures: A High-Moment Forking Lemma for ${\varSigma }$-Protocols
Lior Rotem, Gil Segev 0001 |
CRYPTO (1) | 1 |
| 2021 | Non-malleable Vector Commitments via Local Equivocability
Lior Rotem, Gil Segev 0001 |
TCC (3) | 1 |
| 2021 | Simple and Efficient Batch Verification Techniques for Verifiable Delay Functions
Lior Rotem |
TCC (3) | 1 |
| 2021 | Injective Trapdoor Functions via Derandomization: How Strong is Rudich's Black-Box Barrier?
Lior Rotem, Gil Segev 0001 |
J. Cryptol. | 1 |
| 2020 | Generically Speeding-Up Repeated Squaring Is Equivalent to Factoring: Sharp Thresholds for All Generic-Ring Delay Functions
Lior Rotem, Gil Segev 0001 |
CRYPTO (3) | 1 |
| 2020 | Generic-Group Delay Functions Require Hidden-Order Groups
Lior Rotem, Gil Segev 0001, Ido Shahaf |
EUROCRYPT (3) | 1 |
| 2020 | Algebraic Distinguishers: From Discrete Logarithms to Decisional Uber Assumptions
Lior Rotem, Gil Segev 0001 |
TCC (3) | 1 |
| 2020 | The Security of Lazy Users in Out-of-Band AuthenticationabstractFaced with the threats posed by man-in-the-middle attacks, messaging platforms rely on “out-of-band” authentication, assuming that users have access to an external channel for authenticating one short value. For example, assuming that users recognizing each other’s voice can authenticate a short value, Telegram and WhatApp ask their users to compare 288-bit and 200-bit values, respectively. The existing protocols, however, do not take into account the plausible behavior of users who may be “lazy” and only compare parts of these values (rather than their entirety). Motivated by such a security-critical user behavior, we study the security of lazy users in out-of-band authentication. We start by showing that both the protocol implemented by WhatsApp and the statistically optimal protocol of Naor, Segev, and Smith (CRYPTO’06) are completely vulnerable to man-in-the-middle attacks when the users consider only a half of the out-of-band authenticated value. In this light, we put forward a framework that captures the behavior and security of lazy users. Our notions of security consider both statistical security and computational security, and for each flavor we derive a lower bound on the tradeoff between the number of positions that are considered by the lazy users and the adversary’s forgery probability. Within our framework, we then provide two authentication protocols. First, in the statistical setting, we present a transformation that converts any out-of-band authentication protocol into one that is secure even when executed by lazy users. Instantiating our transformation with a new refinement of the protocol of Naor et al. results in a protocol whose tradeoff essentially matches our lower bound in the statistical setting. Then, in the computational setting, we show that the computationally optimal protocol of Vaudenay (CRYPTO’05) is secure even when executed by lazy users—and its tradeoff matches our lower bound in the computational setting. Moni Naor, Lior Rotem, Gil Segev 0001 |
ACM Trans. Priv. Secur. | 2 |
| 2018 | Out-of-Band Authentication in Group Messaging: Computational, Statistical, Optimal
Lior Rotem, Gil Segev 0001 |
CRYPTO (1) | 1 |
| 2018 | The Security of Lazy Users in Out-of-Band Authentication
Moni Naor, Lior Rotem, Gil Segev 0001 |
TCC (2) | 2 |
| 2018 | Injective Trapdoor Functions via Derandomization: How Strong is Rudich's Black-Box Barrier?
Lior Rotem, Gil Segev 0001 |
TCC (1) | 1 |
| 2018 | Characterization of Secure Multiparty Computation Without Broadcast
Ran Cohen, Iftach Haitner, Eran Omri, Lior Rotem |
J. Cryptol. | 4 |