Eleftherios Kokoris-Kogias

dblp:176/5301 · also Lefteris Kokoris-Kogias · DBLP profile ↗
← Back
33ranked-venue papers
5as first author
24since 2021 · last 2026
0000-0002-8827-3382ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 3 first-author · 14 since 2021Systems, architecture and hardware · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Thunderbolt: Concurrent Smart Contract Execution with Non-blocking Reconfiguration for Sharded DAGs
Junchao Chen 0003, Alberto Sonnino, Eleftherios Kokoris-Kogias, Mohammad Sadoghi
EDBT3
2025 RACS-SADL: Robust and Understandable Randomized Consensus in the Cloud
abstract
Widely deployed consensus protocols in the cloud are often leader-based and optimized for low latency under synchronous network conditions. However, cloud networks can experience disruptions such as network partitions, high-loss links, and configuration errors. These disruptions interfere with the operation of leader-based protocols, as their view change mechanisms interrupt the normal case replication and cause the system to stall. We propose RACS, a novel randomized consensus protocol that ensures robustness against adversarial network conditions. RACS achieves optimal one-round trip latency under synchronous network conditions while remaining resilient to adversarial network conditions. RACS follows a simple design inspired by Raft, the most widely used consensus protocol in the cloud, and therefore enables seamless integration with the existing cloud software stack. Experiments with a prototype running on Amazon EC2 show that RACS achieves 28k cmd/sec throughput, ninefold higher than Raft under adversarial cloud network conditions. Under synchronous network conditions, RACS matches the performance of Multi-Paxos and Raft, achieving a throughput of 200k cmd/sec with a median latency of 300ms, confirming that RACS introduces no unnecessary overhead. Finally, SADL-RACS, a throughput-optimized version of RACS, achieves a throughput of 500k cmd/sec, delivering 150 percent higher throughput than Raft.
Pasindu Tennage, Antoine Desjardins, Eleftherios Kokoris-Kogias
CLOUD3
2025 Pilotfish: Distributed Execution for Scalable Blockchains
Quentin Kniep, Eleftherios Kokoris-Kogias, Alberto Sonnino, Igor Zablotchi, Nuda Zhang
FC2
2025 Anthemius: Efficient and Modular Block Assembly for Concurrent Execution
Ray Neiheiser, Eleftherios Kokoris-Kogias
FC2
2025 Seahorse: Efficiently Mixing Encrypted and Normal Transactions
Ben Riva, Alberto Sonnino, Eleftherios Kokoris-Kogias
FC (2)3
2025 Mahi-Mahi: Low-Latency Asynchronous BFT DAG-Based Consensus
abstract
We present Mahi-Mahi, the first asynchronous BFT consensus protocol that achieves sub-second latency in a wide-area network setting while processing over 100,000 transactions per second. Mahi-Mahi achieves such high performance by leveraging an uncertified structured Directed Acyclic Graph (DAG) to forgo explicit certification. This reduces the number of messages required to commit and the CPU overhead for certificate verification, significantly. Mahi-Mahi introduces a novel commit rule that enables committing multiple blocks in each asynchronous DAG round. Mahi-Mahi can be parametrized either with a 5 network hops commit delay, maximizing the commit probability under a continuously active asynchronous adversary, or with a 4 network hops commit delay, reducing latency under a more moderate and realistic asynchronous adversary. We demonstrate safety and liveness of Mahi-Mahi in a Byzantine context for all of these parametrizations. Finally, we evaluate Mahi-Mahi in a geo-replicated setting and compare its performance to state-of-the-art asynchronous consensus protocols, showcasing Mahi-Mahi’s significantly lower latency.
Philipp Jovanovic, Eleftherios Kokoris-Kogias, Bryan Kumara, Alberto Sonnino, Pasindu Tennage, Igor Zablotchi
ICDCS2
2025 Mysticeti: Reaching the Latency Limits with Uncertified DAGs
Kushal Babel, Andrey Chursin, George Danezis, Anastasios Kichidis, Eleftherios Kokoris-Kogias, Arun Koshy, Alberto Sonnino, Mingwei Tian
NDSS5
2025 Securing Consensus from Long-Range Attacks Through Collaboration
abstract
Decentralized systems built around blockchain technology promise clients an immutable ledger. They add a transaction to the ledger after it undergoes consensus among the replicas that run a Proof-of-Stake (PoS) or Byzantine Fault-Tolerant (BFT) consensus protocol. Unfortunately, these protocols face a long-range attack where an adversary having access to the private keys of the replicas can rewrite the ledger. An existing solution to this problem forces each committed block from these protocols to undergo another consensus, Proof-of-Work (PoW) consensus; POW protocol wastes computational resources as miners compete to solve complex puzzles. In this paper, we present the design of our Power-of-Collaboration (POC) protocol, which guards existing POS/BFT blockchains against long-range attacks and requires miners to collaborate rather than compete. POC guarantees fairness and accountability and only marginally degrades the throughput of the underlying system.
Junchao Chen 0003, Suyash Gupta 0001, Alberto Sonnino, Eleftherios Kokoris-Kogias, Mohammad Sadoghi
SRDS4
2025 Byzantine Consensus in the Random Asynchronous Model
abstract
We propose a novel relaxation of the classic asynchronous network model, called the random asynchronous model, which removes adversarial message scheduling while preserving unbounded message delays and Byzantine faults. Instead of an adversary dictating message order, delivery follows a random schedule. We analyze Byzantine consensus at different resilience thresholds (n = 3f+1, n = 2f+1, and n = f+2) and show that our relaxation allows consensus with probabilistic guarantees which are impossible in the standard asynchronous model or even the partially synchronous model. We complement these protocols with corresponding impossibility results, establishing the limits of consensus in the random asynchronous model.
George Danezis, Jovan Komatovic, Eleftherios Kokoris-Kogias, Alberto Sonnino, Igor Zablotchi
DISC3
2024 An Empirical Study of Consensus Protocols' DoS Resilience
abstract
With the proliferation of blockchain technology in high-value sectors, consensus protocols are becoming critical infrastructures. The rapid innovation cycle in Byzantine fault tolerant (BFT) consensus protocols has culminated in HotStuff, which provides linear message complexity in the partially synchronous setting. To achieve this, HotStuff leverages a leader that collects, aggregates, and broadcasts the messages of other validators. This paper analyzes the security implications of such approaches in practice, from the perspective of liveness and availability.
Giacomo Giuliari, Alberto Sonnino, Marc Frei, Fabio Streun, Eleftherios Kokoris-Kogias, Adrian Perrig
AsiaCCS5
2024 Sui Lutris: A Blockchain Combining Broadcast and Consensus
abstract
Sui Lutris is the first smart-contract platform to sustainably achieve sub-second finality. It achieves this significant decrease by employing consensusless agreement not only for simple payments but for a large variety of transactions. Unlike prior work, Sui Lutris neither compromises expressiveness nor throughput and can run perpetually without restarts. Sui Lutris achieves this by safely integrating consensuless agreement with a high-throughput consensus protocol that is invoked out of the critical finality path but ensures that when a transaction is at risk of inconsistent concurrent accesses, its settlement is delayed until the total ordering is resolved. Building such a hybrid architecture is especially delicate during reconfiguration events, where the system needs to preserve the safety of the consensusless path without compromising the long-term liveness of potentially misconfigured clients. We thus develop a novel reconfiguration protocol, the first to provably show the safe and efficient reconfiguration of a consensusless blockchain. Sui Lutris is currently running in production and underpins the Sui smart-contract platform. Combined with the use of Objects instead of accounts it enables the safe execution of smart contracts that expose objects as a first-class resource. In our experiments Sui Lutris achieves latency lower than 0.5 seconds for throughput up to 5,000 certificates per second (150k ops/s with transaction blocks), compared to the state-of-the-art real-world consensus latencies of 3 seconds. Furthermore, it gracefully handles validators crash-recovery and does not suffer visible performance degradation during reconfiguration.
Sam Blackshear, Andrey Chursin, George Danezis, Anastasios Kichidis, Eleftherios Kokoris-Kogias, Xun Li 0001, Mark Logan, Ashok Menon, Todd Nowacki, Alberto Sonnino, Brandon Williams, Lu Zhang 0092
CCS5
2024 HammerHead: Leader Reputation for Dynamic Scheduling
abstract
Recent advancements on DAG-based consensus protocols allow for blockchains with improved metrics and properties, such as throughput and censorship-resistance. Variants of the Bullshark [18] consensus protocol are adopted for practical use by the Sui blockchain, for improved latency. However, the protocol is leader-based, and is strongly affected by crashed leaders that can lead to various performance issues, for example, decreased transaction throughput. In this paper, we propose HammerHead, a DAG-based consensus protocol, that is inspired by Carousel [8] and provides Leader-Utilization. Our proposal differs from Carousel, which is built for a chained consensus protocol; in HammerHead chain quality is inherited by the DAG. HammerHead needs to preserve safety and liveness, despite validators committing leader vertices asynchronously. The key idea is to update leader schedules dynamically, based on the validators' scores during the previous schedule. We implement HammerHead and show a minor improvement in performance for cases without faults. The major improvements in comparison to Bullshark appear in faulty settings. Specifically, we show a drastic, 2x-latency improvement and up to 40% increased throughput when crash faults occur (100 validators, 33 faults).
Giorgos Tsimos, Anastasios Kichidis, Alberto Sonnino, Eleftherios Kokoris-Kogias
ICDCS4
2023 STROBE: Streaming Threshold Random Beacons
Donald Beaver, Kostas Kryptos Chalkias, Mahimna Kelkar, Eleftherios Kokoris-Kogias, Kevin Lewi, Ladi de Naurois, Valeria Nikolaenko, Arnab Roy 0001, Alberto Sonnino
AFT4
2023 Proof of Availability and Retrieval in a Modular Blockchain Architecture
Shir Cohen, Guy Goren, Eleftherios Kokoris-Kogias, Alberto Sonnino, Alexander Spiegelman
FC3
2023 Executing and Proving Over Dirty Ledgers
Christos Stefo, Zhuolun Xiang, Eleftherios Kokoris-Kogias
FC (1)3
2023 Parakeet: Practical Key Transparency for End-to-End Encrypted Messaging
Harjasleen Malvai, Eleftherios Kokoris-Kogias, Alberto Sonnino, Esha Ghosh, Ercan Ozturk, Kevin Lewi, Sean F. Lawlor
NDSS2
2023 Divide & Scale: Formalization and Roadmap to Robust Sharding
Zeta Avarikioti, Antoine Desjardins, Eleftherios Kokoris-Kogias, Roger Wattenhofer
SIROCCO3
2023 QuePaxa: Escaping the tyranny of timeouts in consensus
abstract
Leader-based consensus algorithms are fast and efficient under normal conditions, but lack robustness to adverse conditions due to their reliance on timeouts for liveness. We present QuePaxa, the first protocol offering state-of-the-art normal-case efficiency without depending on timeouts. QuePaxa uses a novel randomized asynchronous consensus core to tolerate adverse conditions such as denial-of-service (DoS) attacks, while a one-round-trip fast path preserves the normal-case efficiency of Multi-Paxos or Raft. By allowing simultaneous proposers without destructive interference, and using short hedging delays instead of conservative timeouts to limit redundant effort, QuePaxa permits rapid recovery after leader failure without risking costly view changes due to false timeouts. By treating leader choice and hedging delay as a multi-armed-bandit optimization, QuePaxa achieves responsiveness to prevalent conditions, and can choose the best leader even if the current one has not failed. Experiments with a prototype confirm that QuePaxa achieves normal-case LAN and WAN performance of 584k and 250k cmd/sec in throughput, respectively, comparable to Multi-Paxos. Under conditions such as DoS attacks, misconfigurations, or slow leaders that severely impact existing protocols, we find that QuePaxa remains live with median latency under 380ms in WAN experiments.
Pasindu Tennage, Cristina Basescu, Eleftherios Kokoris-Kogias, Ewa Syta, Philipp Jovanovic, Vero Estrada-Galiñanes, Bryan Ford
SOSP3
2023 Practical Asynchronous High-threshold Distributed Key Generation and Distributed Polynomial Sampling
Sourav Das 0001, Zhuolun Xiang, Eleftherios Kokoris-Kogias, Ling Ren 0001
USENIX Security Symposium3
2022 Bullshark: DAG BFT Protocols Made Practical
abstract
We present Bullshark, the first directed acyclic graph (DAG) based asynchronous Byzantine Atomic Broadcast protocol that is optimized for the common synchronous case. Like previous DAG-based BFT protocols [19, 25], Bullshark requires no extra communication to achieve consensus on top of building the DAG. That is, parties can totally order the vertices of the DAG by interpreting their local view of the DAG edges. Unlike other asynchronous DAG-based protocols, Bullshark provides a practical low latency fast-path that exploits synchronous periods and deprecates the need for notoriously complex view-change and view-synchronization mechanisms. Bullshark achieves this while maintaining all the desired properties of its predecessor DAG-Rider [25]. Namely, it has optimal amortized communication complexity, it provides fairness and asynchronous liveness, and safety is guaranteed even under a quantum adversary.
Alexander Spiegelman, Neil Giridharan, Alberto Sonnino, Eleftherios Kokoris-Kogias
CCS4
2022 Narwhal and Tusk: a DAG-based mempool and efficient BFT consensus
abstract
We propose separating the task of reliable transaction dissemination from transaction ordering, to enable high-performance Byzantine fault-tolerant quorum-based consensus. We design and evaluate a mempool protocol, Narwhal, specializing in high-throughput reliable dissemination and storage of causal histories of transactions. Narwhal tolerates an asynchronous network and maintains high performance despite failures. Narwhal is designed to easily scale-out using multiple workers at each validator, and we demonstrate that there is no foreseeable limit to the throughput we can achieve.
George Danezis, Eleftherios Kokoris-Kogias, Alberto Sonnino, Alexander Spiegelman
EuroSys2
2022 Practical Asynchronous Distributed Key Generation
abstract
Distributed Key Generation (DKG) is a technique to bootstrap threshold cryptosystems without a trusted third party and is a building block to decentralized protocols such as randomness beacons, threshold signatures, and general multiparty computation. Until recently, DKG protocols have assumed the synchronous model and thus are vulnerable when their underlying network assumptions do not hold. The recent advancements in asynchronous DKG protocols are insufficient as they either have poor efficiency or limited functionality, resulting in a lack of concrete implementations. In this paper, we present a simple and concretely efficient asynchronous DKG (ADKG) protocol. In a network of n nodes, our ADKG protocol can tolerate up to $t\lt n/3$ malicious nodes and have an expected $O(\kappa n^{3})$ communication cost, where $\kappa$ is the security parameter. Our ADKG protocol produces a field element as the secret and is thus compatible with off-the-shelf threshold cryptosystems. We implement our ADKG protocol and evaluate it using a network of up to 128 nodes in geographically distributed AWS instances. Our evaluation shows that our protocol takes as low as 3 and 9.5 seconds to terminate for 32 and 64 nodes, respectively. Also, each node sends only 0.7 Megabytes and 2.9 Megabytes of data during the two experiments, respectively.
Sourav Das 0001, Thomas Yurek, Zhuolun Xiang, Andrew Miller 0001, Eleftherios Kokoris-Kogias, Ling Ren 0001
SP5
2021 Brief Announcement: Be Prepared When Network Goes Bad: An Asynchronous View-Change Protocol
abstract
The popularity of permissioned blockchain systems demands BFT SMR protocols that are efficient under good network conditions (synchrony) and robust under bad network conditions (asynchrony). The state-of-the-art partially synchronous BFT SMR protocols provide optimal linear communication cost per decision under synchrony and good leaders, but lose liveness under asynchrony. On the other hand, the state-of-the-art asynchronous BFT SMR protocols are live even under asynchrony, but always pay quadratic cost even under synchrony. In this paper, we propose a BFT SMR protocol that achieves the best of both worlds -- optimal linear cost per decision under good networks and leaders, optimal quadratic cost per decision under bad networks, and remains always live.
Rati Gelashvili, Eleftherios Kokoris-Kogias, Alexander Spiegelman, Zhuolun Xiang
PODC2
2021 All You Need is DAG
abstract
We present DAG-Rider, the first asynchronous Byzantine Atomic Broadcast protocol that achieves optimal resilience, optimal amortized communication complexity, and optimal time complexity. DAG-Rider is post-quantum safe and ensures that all values proposed by correct processes eventually get delivered. We construct DAG-Rider in two layers: In the first layer, processes reliably broadcast their proposals and build a structured Directed Acyclic Graph (DAG) of the communication among them. In the second layer, processes locally observe their DAGs and totally order all proposals with no extra communication.
Idit Keidar, Eleftherios Kokoris-Kogias, Oded Naor, Alexander Spiegelman
PODC2
2020 Asynchronous Distributed Key Generation for Computationally-Secure Randomness, Consensus, and Threshold Signatures
abstract
In this paper, we present the first Asynchronous Distributed Key Generation (ADKG) algorithm which is also the first distributed key generation algorithm that can generate cryptographic keys with a dual (f,2f+1)-threshold (where f is the number of faulty parties). As a result, using our ADKG we remove the trusted setup assumption that the most scalable consensus algorithms make. In order to create a DKG with a dual (f,2f+1)- threshold we first answer in the affirmative the open question posed by Cachin et al. [7] on how to create an Asynchronous Verifiable Secret Sharing (AVSS) protocol with a reconstruction threshold of f+1
Eleftherios Kokoris-Kogias, Dahlia Malkhi, Alexander Spiegelman
CCS1
2020 CALYPSO: Private Data Management for Decentralized Ledgers
abstract
Distributed ledgers provide high availability and integrity , making them a key enabler for practical and secure computation of distributed workloads among mutually distrustful parties. Many practical applications also require strong confidentiality , however. This work enhances permissioned and permissionless blockchains with the ability to manage confidential data without forfeiting availability or decentralization. The proposed Calypso architecture addresses two orthogonal challenges confronting modern distributed ledgers: (a) enabling the auditable management of secrets and (b) protecting distributed computations against arbitrage attacks when their results depend on the ordering and secrecy of inputs. Calypso introduces on-chain secrets, a novel abstraction that enforces atomic deposition of an auditable trace whenever users access confidential data. Calypso provides user-controlled consent management that ensures revocation atomicity and accountable anonymity. To enable permissionless deployment, we introduce an incentive scheme and provide users with the option to select their preferred trustees. We evaluated our Calypso prototype with a confidential document-sharing application and a decentralized lottery. Our benchmarks show that transaction-processing latency increases linearly in terms of security (number of trustees) and is in the range of 0.2 to 8 seconds for 16 to 128 trustees.
Eleftherios Kokoris-Kogias, Enis Ceyhun Alp, Linus Gasser, Philipp Jovanovic, Ewa Syta, Bryan Ford
Proc. VLDB Endow.1
2019 Rethinking General-Purpose Decentralized Computing
abstract
While showing great promise, smart contracts are difficult to program correctly, as they need a deep understanding of cryptography and distributed algorithms, and offer limited functionality, as they have to be deterministic and cannot operate on secret data. In this paper we present Protean, a general-purpose decentralized computing platform that addresses these limitations by moving from a monolithic execution model, where all participating nodes store all the state and execute every computation, to a modular execution-model. Protean employs secure specialized modules, called functional units, for building decentralized applications that are currently insecure or impossible to implement with smart contracts. Each functional unit is a distributed system that provides a special-purpose functionality by exposing atomic transactions to the smart-contract developer. Combining these transactions into arbitrarily-defined workflows, developers can build a larger class of decentralized applications, such as provably-secure and fair lotteries or e-voting.
Enis Ceyhun Alp, Eleftherios Kokoris-Kogias, Georgia Fragkouli, Bryan Ford
HotOS2
2018 Channels: Horizontal Scaling and Confidentiality on Permissioned Blockchains
Elli Androulaki, Christian Cachin, Angelo De Caro, Eleftherios Kokoris-Kogias
ESORICS (1)4
2018 OmniLedger: A Secure, Scale-Out, Decentralized Ledger via Sharding
abstract
Designing a secure permissionless distributed ledger (blockchain) that performs on par with centralized payment processors, such as Visa, is a challenging task. Most existing distributed ledgers are unable to scale-out, i.e., to grow their total processing capacity with the number of validators; and those that do, compromise security or decentralization. We present OmniLedger, a novel scale-out distributed ledger that preserves longterm security under permissionless operation. It ensures security and correctness by using a bias-resistant public-randomness protocol for choosing large, statistically representative shards that process transactions, and by introducing an efficient cross-shard commit protocol that atomically handles transactions affecting multiple shards. OmniLedger also optimizes performance via parallel intra-shard transaction processing, ledger pruning via collectively-signed state blocks, and low-latency "trust-but-verify" validation for low-value transactions. An evaluation of our experimental prototype shows that OmniLedger's throughput scales linearly in the number of active validators, supporting Visa-level workloads and beyond, while confirming typical transactions in under two seconds.
Eleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly, Ewa Syta, Bryan Ford
IEEE Symposium on Security and Privacy1
2017 Scalable Bias-Resistant Distributed Randomness
abstract
Bias-resistant public randomness is a critical component in many (distributed) protocols. Generating public randomness is hard, however, because active adversaries may behave dishonestly to bias public random choices toward their advantage. Existing solutions do not scale to hundreds or thousands of participants, as is needed in many decentralized systems. We propose two large-scale distributed protocols, RandHound and RandHerd, which provide publicly-verifiable, unpredictable, and unbiasable randomness against Byzantine adversaries. RandHound relies on an untrusted client to divide a set of randomness servers into groups for scalability, and it depends on the pigeonhole principle to ensure output integrity, even for non-random, adversarial group choices. RandHerd implements an efficient, decentralized randomness beacon. RandHerd is structurally similar to a BFT protocol, but uses RandHound in a one-time setup to arrange participants into verifiably unbiased random secret-sharing groups, which then repeatedly produce random output at predefined intervals. Our prototype demonstrates that RandHound and RandHerd achieve good performance across hundreds of participants while retaining a low failure probability by properly selecting protocol parameters, such as a group size and secret-sharing threshold. For example, when sharding 512 nodes into groups of 32, our experiments show that RandHound can produce fresh random output after 240 seconds. RandHerd, after a setup phase of 260 seconds, is able to generate fresh random output in intervals of approximately 6 seconds. For this configuration, both protocols operate at a failure probability of at most 0.08% against a Byzantine adversary.
Ewa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Michael J. Fischer, Bryan Ford
IEEE Symposium on Security and Privacy3
2017 CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified Builds
Kirill Nikitin 0001, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Justin Cappos, Bryan Ford
USENIX Security Symposium2
2016 TRM-SIoT: A scalable hybrid trust & reputation model for the social Internet of Things
abstract
The integration of social networking concepts into Internet of Things systems is a burgeoning topic of research that promises to support novel and more powerful applications. In this paper we focus on the design and implementation of a highly scalable Trust and Reputation Model for the Internet of Things based on the social approach that the COSMOS project introduces, as part of its final results. We create our model by combining popular solutions proposed for Peer-to-Peer and mobile ad-hoc networks and adapting them on the Internet of Things concept. Each Thing can compute the Trust index of another Thing based on its own experiences, while it has the capability of determining its Reputation Index either by consulting its other “friends” (Followees) or referring to the Platform, a management system used in COSMOS. The model is tested through simulations of the proposed social system, demonstrating the ability of TRM-SIoT to achieve the Social Exclusion of malicious nodes and collectives from the network, with low computational overhead and high scalability. Furthermore, due to the adaptive nature of the system, Social Reintegration of these nodes is also possible.
Eleftherios Kokoris-Kogias, Orfefs Voutyras, Theodora A. Varvarigou
ETFA1
2016 Enhancing Bitcoin Security and Performance with Strong Consistency via Collective Signing
Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Ismail Khoffi, Linus Gasser, Bryan Ford
USENIX Security Symposium1