VLDB 2026 Research / reviewers in the wild / expert
Michael Klooß
dblp:207/6587
· DBLP profile ↗
24ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0003-3466-0675ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 8 first-author · 20 since 2021Theory of computation · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Blind Signatures from Arguments of Inequality
Michael Klooß, Russell W. F. Lai, Michael Reichle |
CRYPTO (7) | 1 |
| 2026 | Threshold Public-Key Encryption: Definitions, Relations, and CPA-to-CCA Transforms
Christopher Brzuska, Michael Klooß, Ivy K. Y. Woo |
PKC (4) | 2 |
| 2026 | Scalable Registration-Based Encryption from Lattices
Michael Klooß, Russell W. F. Lai, Jan Niklas Siemer, Monisha Swarnakar |
SP | 1 |
| 2026 | The Fiat - Shamir Transformation of $(\varGamma _1,\dots ,\varGamma _\mu )$-Special-Sound Interactive ProofsabstractAbstract The Fiat–Shamir transformation is a general principle to turn any public-coin interactive proof into non-interactive one (with security then typically analyzed in the random oracle model). While initially used for 3-round protocols, many recent constructions use it for multi-round protocols. However, in general the soundness error of the Fiat–Shamir transformed protocol degrades exponentially in the number of rounds. On the positive side, it was shown that for the special class of $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound $$\varSigma $$ Σ -protocols, which is a natural multi-round generalization of the well-known class of special-sound protocols, the loss is actually only linear in the number of random oracle queries, and independent of the number of rounds, which is optimal. A natural next question is whether this positive result extends to the Fiat–Shamir transformation of so-called $$(\varGamma _1,\dots ,\varGamma _\mu )$$ ( Γ 1 , ⋯ , Γ μ ) -special-sound protocols. This notion was recently defined and analyzed in the interactive case; it captures a larger class of protocols, namely where the special-soundness property is characterized by a general access structure, rather than a threshold. We show in this work that this is indeed the case. Concretely, we show that the Fiat–Shamir transformation of any $$(\varGamma _1, \ldots , \varGamma _\mu )$$ ( Γ 1 , … , Γ μ ) -special-sound interactive proof is knowledge sound under the same condition on $$\varGamma _1,\dots ,\varGamma _\mu $$ Γ 1 , ⋯ , Γ μ for which the original interactive proof is knowledge sound. Furthermore, also here the loss is linear in the number of random oracle queries and independent of the number of rounds. In light of the above, one might suspect that our argument follows as a straightforward combination of the above mentioned prior works. However, this is not the case. The approach used for $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound protocols, which is based on an extractor that samples without replacement, does not (seem to) generalize; on the other hand, the other approach, which uses an extractor based on sampling with replacement, comes with an additional loss that would blow up in the recursive multi-round analysis. Thus, new techniques are necessary to handle the above complications. Thomas Attema, Serge Fehr, Michael Klooß, Nicolas Resch |
J. Cryptol. | 3 |
| 2025 | Tightly-Secure Blind Signatures in Pairing-Free GroupsabstractWe construct the first blind signature scheme that achieves all of the following properties simultaneously: The third property enables a reasonably efficient solution, and in fact signatures in our scheme comprise 10 group elements and 29 $$\mathbb {Z} _p$$ -elements. Our scheme starts from a pairing-based non-blind signature scheme (Abe et al., JoC 2023), and uses recent techniques of Chairattana-Apirom, Tessaro, and Zhu (CRYPTO 2024) to replace the pairings used in this scheme with non-interactive zero-knowledge proofs in the random oracle model. This conversion is not generic or straightforward (also because prior works have converted only significantly simpler signature schemes), and we are required to improve upon and innovate existing techniques in several places. As an interesting side note, and unlike previous works, our techniques only require a non-programmable random oracle, and our signature scheme achieves predicate blindness (which means that the user can prove statements about the signed message during the signing process). Nicholas Brandt, Dennis Hofheinz, Michael Klooß, Michael Reichle |
ASIACRYPT (6) | 3 |
| 2025 | RoK and Roll - Verifier-Efficient Random Projection for O~(λ)-Size Lattice Arguments - (Extended Abstract)
Michael Klooß, Russell W. F. Lai, Ngoc Khanh Nguyen 0001, Michal Osadnik |
ASIACRYPT (3) | 1 |
| 2025 | Shorter, Tighter, FAESTer: Optimizations and Improved (QROM) Analysis for VOLE-in-the-Head Signatures
Carsten Baum, Ward Beullens, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Christian Majenz, Shibam Mukherjee, Emmanuela Orsini, Sebastian Ramacher, Christian Rechberger, Lawrence Roy, Peter Scholl |
CRYPTO (6) | 5 |
| 2025 | Blind Signatures from Proofs of Inequality
Michael Klooß, Michael Reichle |
CRYPTO (6) | 1 |
| 2025 | Lattice-Based Proof-Friendly Signatures from Vanishing Short Integer Solutions
Adrien Dubois, Michael Klooß, Russell W. F. Lai, Ivy K. Y. Woo |
PKC (1) | 2 |
| 2024 | RoK, Paper, SISsors Toolkit for Lattice-Based Succinct Arguments - (Extended Abstract)
Michael Klooß, Russell W. F. Lai, Ngoc Khanh Nguyen 0001, Michal Osadnik |
ASIACRYPT (5) | 1 |
| 2024 | Practical Blind Signatures in Pairing-Free Groups
Michael Klooß, Michael Reichle, Benedikt Wagner |
ASIACRYPT (1) | 1 |
| 2023 | Universally Composable Auditable Surveillance
Valerie Fetzer, Michael Klooß, Jörn Müller-Quade, Markus Raiber, Andy Rupp |
ASIACRYPT (2) | 2 |
| 2023 | Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures from VOLE-in-the-HeadabstractWe present a new method for transforming zero-knowledge protocols in the designated verifier setting into public-coin protocols, which can be made non-interactive and publicly verifiable. Our transformation applies to a large class of ZK protocols based on oblivious transfer. In particular, we show that it can be applied to recent, fast protocols based on vector oblivious linear evaluation (VOLE), with a technique we call VOLE-in-the-head, upgrading these protocols to support public verifiability. Our resulting ZK protocols have linear proof size, and are simpler, smaller and faster than related approaches based on MPC-in-the-head. To build VOLE-in-the-head while supporting both binary circuits and large finite fields, we develop several new technical tools. One of these is a new proof of security for the SoftSpokenOT protocol (Crypto 2022), which generalizes it to produce certain types of VOLE correlations over large fields. Secondly, we present a new ZK protocol that is tailored to take advantage of this form of VOLE, which leads to a publicly verifiable VOLE-in-the-head protocol with only 2x more communication than the best, designated-verifier VOLE-based protocols. We analyze the soundness of our approach when made non-interactive using the Fiat-Shamir transform, using round-by-round soundness. As an application of the resulting NIZK, we present $$\textsf{FAEST}$$ , a post-quantum signature scheme based on AES. FAEST is the first AES-based signature scheme to be smaller than SPHINCS+, with signature sizes between 5.6 and 6.6kB at the 128-bit security level. Compared with the smallest version of SPHINCS+ (7.9kB), FAEST verification is slower, but the signing times are between 8x and 40x faster. Carsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Emmanuela Orsini, Lawrence Roy, Peter Scholl |
CRYPTO (5) | 4 |
| 2023 | Composable Long-Term Security with Rewinding
Robin Berger, Brandon Broadnax, Michael Klooß, Jeremias Mechler, Jörn Müller-Quade, Astrid Ottenhues, Markus Raiber |
TCC (4) | 3 |
| 2023 | Fiat-Shamir Transformation of Multi-Round Interactive Proofs (Extended Version)abstractAbstract The celebrated Fiat–Shamir transformation turns any public-coin interactive proof into a non-interactive one, which inherits the main security properties (in the random oracle model) of the interactive version. While originally considered in the context of 3-move public-coin interactive proofs, i.e., so-called $$\varSigma $$ Σ -protocols, it is now applied to multi-round protocols as well. Unfortunately, the security loss for a $$(2\mu + 1)$$ (2μ+1) -move protocol is, in general, approximately $$Q^\mu $$ Qμ , whereQis the number of oracle queries performed by the attacker. In general, this is the best one can hope for, as it is easy to see that this loss applies to the $$\mu $$ μ -fold sequential repetition of $$\varSigma $$ Σ -protocols, but it raises the question whether certain (natural) classes of interactive proofs feature a milder security loss. In this work, we give positive and negative results on this question. On the positive side, we show that for $$(k_1, \ldots , k_\mu )$$ (k1,…,kμ) -special-sound protocols (which cover a broad class of use cases), the knowledge error degrades linearly inQ, instead of $$Q^\mu $$ Qμ . On the negative side, we show that fort-foldparallel repetitionsof typical $$(k_1, \ldots , k_\mu )$$ (k1,…,kμ) -special-sound protocols with $$t \ge \mu $$ t≥μ (and assuming for simplicity thattandQare integer multiples of $$\mu $$ μ ), there is an attack that results in a security loss of approximately $$\frac{1}{2} Q^\mu /\mu ^{\mu +t}$$ 12Qμ/μμ+t . Thomas Attema, Serge Fehr, Michael Klooß |
J. Cryptol. | 3 |
| 2022 | Sharp: Short Relaxed Range ProofsabstractWe provide optimized range proofs, called Sharp, in discrete logarithm and hidden order groups, based on square decomposition. In the former setting, we build on the paradigm of Couteau et al. (Eurocrypt '21) and optimize their range proof (from now on, CKLR) in several ways: (1) We introduce batching via vector commitments and an adapted ∑;-protocol. (2) We introduce a new group switching strategy to reduce communication. (3) As repetitions are necessary to instantiate CKLR in standard groups, we provide a novel batch shortness test that allows for cheaper repetitions. The analysis of our test is nontrivial and forms a core technical contribution of our work. For example, for λ = 128 bit security and B = 64 bit ranges for N = 1 (resp. N = 8) proof(s), we reduce the proof size by 34% (resp. 75%) in arbitrary groups, and by 66% (resp. 88%) in groups of order 256-bit, compared to CKLR. Geoffroy Couteau, Dahmun Goudarzi, Michael Klooß, Michael Reichle |
CCS | 3 |
| 2022 | Fiat-Shamir Transformation of Multi-round Interactive Proofs
Thomas Attema, Serge Fehr, Michael Klooß |
TCC (1) | 3 |
| 2021 | Efficient Range Proofs with Transparent Setup from Bounded Integer Commitments
Geoffroy Couteau, Michael Klooß, Huang Lin, Michael Reichle |
EUROCRYPT (3) | 2 |
| 2021 | Black-Box Accumulation Based on Lattices
Sebastian H. Faller, Pascal Baumer, Michael Klooß, Alexander Koch 0001, Astrid Ottenhues, Markus Raiber |
IMACC | 3 |
| 2021 | On Expected Polynomial Runtime in Cryptography
Michael Klooß |
TCC (1) | 1 |
| 2020 | Black-Box Wallets: Fast Anonymous Two-Way Payments for Constrained DevicesabstractBlack-box accumulation (BBA) is a building block which enables a privacy-preserving implementation of point collection and redemption, a functionality required in a variety of user-centric applications including loyalty programs, incentive systems, and mobile payments. By definition, BBA+ schemes (Hartung et al. CCS ‘17) offer strong privacy and security guarantees, such as unlinkability of transactions and correctness of the balance flows of all (even malicious) users. Unfortunately, the instantiation of BBA+ presented at CCS ‘17 is, on modern smartphones, just fast enough for comfortable use. It is too slow for wearables, let alone smart-cards. Moreover, it lacks a crucial property: For the sake of efficiency, the user’s balance is presented in the clear when points are deducted. This may allow to track owners by just observing revealed balances, even though privacy is otherwise guaranteed. The authors intentionally forgo the use of costly range proofs, which would remedy this problem. Max Hoffmann 0001, Michael Klooß, Markus Raiber, Andy Rupp |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Efficient Zero-Knowledge Arguments in the Discrete Log Setting, RevisitedabstractZero-knowledge arguments have become practical, and widely used, especially in the world of Blockchain, for example in Zcash. This work revisits zero-knowledge proofs in the discrete logarithm setting. First, we identify and carve out basic techniques (partly being used implicitly before) to optimise proofs in this setting. In particular, the linear combination of protocols is a useful tool to obtain zero-knowledge and/or reduce communication. With these techniques, we are able to devise zero-knowledge variants of the logarithmic communication arguments by Bootle et al. (EUROCRYPT '16) and Bünz et al. (S&P '18) thereby introducing almost no overhead. We then construct a conceptually simple commit-and-prove argument for satisfiability of a set of quadratic equations. Unlike previous work, we are not restricted to rank 1 constraint systems (R1CS). This is, to the best of our knowledge, the first work demonstrating that general quadratic constraints, not just R1CS, are a natural relation in the dlog (or ideal linear commitment) setting. This enables new possibilities for optimisation, as, eg., any degree n2 polynomial f(X) can now be "evaluated" with at most 2n quadratic constraints. Our protocols are modular. We easily construct an efficient, logarithmic size shuffle proof, which can be used in electronic voting. Additionally, we take a closer look at quantitative security measures, eg. the efficiency of an extractor. We formalise short-circuit extraction, which allows us to give tighter bounds on the efficiency of an extractor. Max Hoffmann 0001, Michael Klooß, Andy Rupp |
CCS | 2 |
| 2019 | (R)CCA Secure Updatable Encryption with Integrity Protection
Michael Klooß, Anja Lehmann, Andy Rupp |
EUROCRYPT (1) | 1 |
| 2017 | New Techniques for Structural Batch Verification in Bilinear Groups with Applications to Groth-Sahai ProofsabstractBilinear groups form the algebraic setting for a multitude of important cryptographic protocols including anonymous credentials, e-cash, e-voting, e-coupon, and loyalty systems. It is typical of such crypto protocols that participating parties need to repeatedly verify that certain equations over bilinear groups are satisfied, e.g., to check that computed signatures are valid, commitments can be opened, or non-interactive zero-knowledge proofs verify correctly. Depending on the form and number of equations this part can quickly become a performance bottleneck due to the costly evaluation of the bilinear map. Gottfried Herold, Max Hoffmann 0001, Michael Klooß, Carla Ràfols, Andy Rupp |
CCS | 3 |