VLDB 2026 Research / reviewers in the wild / expert
David Galindo
dblp:21/2415
· DBLP profile ↗
34ranked-venue papers
19as first author
5since 2021 · last 2025
0000-0003-3563-5551ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 11 first-author · 4 since 2021Theory of computation · 7 · 5 first-authorDatabases, data management, data science and information retrieval · 3 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Bringing Smart Contract Confidentiality via Trusted Hardware: Fact and FictionabstractTrusted Execution Environment (TEE)-assisted confidential smart contracts (TCSC) have attracted extensive attention from both academia and industry. Despite an enormous number of TCSC projects, the extent of confidentiality offered by them remains being questioned: the factual and fictional aspects are not well distinguished, which limits their adoption. In this paper, we provide a formal treatment of TCSC, endowing them with an expressive syntax and security definitions. Based on these definitions, we propose a provably secure TCSC instantiation. Then, we investigate each algorithm and identify the implementation flaws that may make a TCSC system violate its security properties. Our analysis reveals the gap between theoretical security models and real-world implementations: even assuming a TCSC is provably secure by design, it may still fail in practice. We further compare our TCSC instantiation with 16 representative TCSC systems. Our results show that, surprisingly, all these surveyed projects are subject to practical attacks. Finally, we implement a TCSC prototype and conduct a comprehensive evaluation, revealing the overheads of distributed key management and the performance challenges of executing complex contracts within TEEs. Rujia Li 0001, Qin Wang 0008, Yuanzhao Li, Sisi Duan, Qi Wang 0012, David Galindo |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Transparent Registration-Based Encryption through BlockchainabstractGarg et al. (TCC 2018) defined the notion of registration-based encryption (RBE) where the private key generator (PKG) is decoupled from key management and replaced by a key curator (KC). KC does not possess any cryptographic secrets and only plays the role of aggregating the public keys of all the registered users and updating the public parameters whenever a new user joins the system, which solves the key escrow issue. Notwithstanding, RBE still places a significant amount of trust in KC, whose actions are not accountable, e.g., it could secretly register multiple keys for already registered users. In this article, we propose a blockchain-based RBE framework, which provides total transparency and decentralization of KC by leveraging smart contracts. Our framework transfers the right of key management from KC to individual participants and keeps publicly upgradable parameters on-chain. We provide a basic construction that calculates the public parameter on-chain and an extended construction with better efficiency, which merely calculates the roots of trees on-chain. Our basic version is theoretically feasible, while the extended version is practically feasible. In particular, the enhanced scheme reduces computing complexity to a constant level. Our prototype implementation and evaluation results demonstrate that our extended construction is satisfactorily efficient. Qin Wang 0008, Rujia Li 0001, Qi Wang 0012, David Galindo, Shiping Chen 0001, Yang Xiang 0001 |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2022 | Robust Subgroup Multi-signatures for Consensus
David Galindo, Jia Liu 0003 |
CT-RSA | 1 |
| 2022 | SoK: TEE-Assisted Confidential Smart ContractabstractThe blockchain-based smart contract lacks privacy, since the contract state and instruction code are exposed to the public. Combining smart-contract execution with Trusted Execution Environments provides an efficient solution, called TEE-assisted smart contracts (TCSC), for protecting the confidentiality of contract states. However, the combination approaches are varied, and a systematic study is absent. Newly released systems may fail to draw upon the experience learned from existing protocols, such as repeating known design mistakes or applying TEE technology in insecure ways. In this paper, we first investigate and categorize existing systems into two types: the layer-one solution and the layer-two solution. Then, we establish an analysis framework to capture their common aspects, covering desired properties (for contract services), threat models, and security considerations (for underlying systems). Based on our taxonomy, we identify their ideal functionalities, and uncover fundamental flaws and challenges in each specification’s design. We believe that this work would provide a guide for the development of TEE-assisted smart contracts, as well as a framework to evaluate future TCSC systems. Rujia Li 0001, Qin Wang 0008, Qi Wang 0012, David Galindo, Mark Ryan 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | Fully Distributed Verifiable Random Functions and their Application to Decentralised Random BeaconsabstractWe provide a systematic analysis of two related multiparty protocols, namely (Non-Interactive Fully) Distributed Verifiable Random Functions (DVRFs) and Decentralised Random Beacons (DRBs), including their syntax and definition of robustness and privacy properties. These two protocols are run by multiple network nodes where each node contributes with a partial evaluation and the collection of these partial values is used to evaluate a pseudorandom function. We refine current pseudorandomness definitions for distributed functions and show that the privacy provided by strong pseudorandomness, where an adversary is allowed to make partial function evaluation queries on the challenge value, is strictly better than that provided by standard pseudorandomness, where such adversarial queries are disallowed. We provide two new DVRF instantiations, named DDH-DVRF and GLOW-DVRF, that meet strong pseudorandomness under widely accepted cryptographic assumptions. We show the usefulness of our DRB formalism in two different ways. Firstly, we give a rigorous treatment of a folklore generic construction that builds a Decentralized Random Beacon from any DVRF instance and prove that it satisfies robustness and pseudorandomness provided that the original DVRF protocol is secure. Secondly, we capture several existing DRB protocols from academia and industry within our framework, which serves as an evidence of its wider applicability. Finally, we report on experimental evaluations of our newly introduced DVRFs with implementations under different cryptographic libraries, and we also report preliminary benchmark results on two of the DRBs obtained from the generic DVRF-to-DRB transformation. Our benchmarks can be independently verified as we provide an open source C++ reference implementation of the new DVRFs. Finally, we conclude that our new DRB instantiations are the most efficient instantiations currently available while enjoying strong and formally proven security properties. David Galindo, Jia Liu 0003, Mihai Ordean, Jin-Mann Wong |
EuroS&P | 1 |
| 2020 | An Accountable Decryption System Based on Privacy-Preserving Smart Contracts
Rujia Li 0001, Qin Wang 0008, Feng Liu 0059, Qi Wang 0012, David Galindo |
ISC | 5 |
| 2019 | CAOS: Concurrent-Access Obfuscated StoreabstractThis paper proposes Concurrent-Access Obfuscated Store (CAOS), a construction for remote data storage that provides access-pattern obfuscation in a honest-but-curious adversarial model, while allowing for low bandwidth overhead and client storage. Compared to other approaches, the main advantage of CAOS is that it supports concurrent access without a proxy, for multiple read-only clients and a single read-write client. Concurrent access is achieved by letting clients maintain independent maps that describe how the data is stored. Even though the maps might diverge from client to client, the protocol guarantees that clients will always have access to the data. Efficiency and concurrency are achieved at the expense of perfect obfuscation: in CAOS the extent to which access patterns are hidden is determined by the resources allocated to its built-in obfuscation mechanism. To assess this trade-off we provide both a security and a performance analysis of CAOS. We additionally provide a proof-of-concept implementation available at https://github.com/meehien/caos. Mihai Ordean, Mark Ryan 0001, David Galindo |
SACMAT | 3 |
| 2018 | A Formal Analysis of the Neuchatel e-Voting ProtocolabstractRemote electronic voting is used in several countries for legally binding elections. Unlike academic voting protocols, these systems are not always documented and their security is rarely analysed rigorously. In this paper, we study a voting system that has been used for electing political representatives and in citizen-driven referenda in the Swiss canton of Neuchâtel. We design a detailed model of the protocol in ProVerif for both privacy and verifiability properties. Our analysis mostly confirms the security of the underlying protocol: we show that the Neuchâtel protocol guarantees ballot privacy, even against a corrupted server; it also ensures cast-as-intended and recorded-as-cast verifiability, even if the voter's device is compromised. To our knowledge, this is the first time a full-fledged automatic symbolic analysis of an e-voting system used for politicallybinding elections has been realized. Véronique Cortier, David Galindo, Mathieu Turuani |
EuroS&P | 2 |
| 2016 | BeleniosRF: A Non-interactive Receipt-Free Electronic Voting SchemeabstractWe propose a new voting scheme, BeleniosRF, that offers both receipt-freeness and end-to-end verifiability. It is receipt-free in a strong sense, meaning that even dishonest voters cannot prove how they voted. We provide a game-based definition of receipt-freeness for voting protocols with non-interactive ballot casting, which we name strong receipt-freeness (sRF). To our knowledge, sRF is the first game-based definition of receipt-freeness in the literature, and it has the merit of being particularly concise and simple. Built upon the Helios protocol, BeleniosRF inherits its simplicity and does not require any anti-coercion strategy from the voters. We implement BeleniosRF and show its feasibility on a number of platforms, including desktop computers and smartphones. Pyrros Chaidos, Véronique Cortier, Georg Fuchsbauer, David Galindo |
CCS | 4 |
| 2016 | Transitioning to a Javascript Voting Client for Remote Online VotingabstractVoters in remote electronic voting systems typically cast their votes from their own devices, such as PCs
and smartphones. The software executed at their devices in charge of performing the ballot presentation,
navigation and most of the cryptographic operations required to protect the integrity and privacy of the ballot,
is referred to as the voting client. The first voting clients were developed as Java Applets. However, the use of
this technology has become relegated in front of web technologies such as Javascript, which provide a better
multi-platform user experience. This is the reason why in 2013 Scytl decided it was imperative to develop
a voting client purely based on Javascript. This industrial paper shows the implementation experiences and
lessons learned during the development and deployment of Javascript voting clients for our remote electronic
voting systems. The paper is complemented with a performance study of 1) the main cryptographic primitives
used in voting clients and 2) the voting casting process of one of the voting clients used in a real election. Jordi Cucurull-Juan, Sandra Guasch, David Galindo |
SECRYPT | 3 |
| 2016 | SoK: Verifiability Notions for E-Voting ProtocolsabstractThere have been intensive research efforts in the last two decades or so to design and deploy electronic voting (e-voting) protocols/systems which allow voters and/or external auditors to check that the votes were counted correctly. This security property, which not least was motivated by numerous problems in even national elections, is called verifiability. It is meant to defend against voting devices and servers that have programming errors or are outright malicious. In order to properly evaluate and analyze e-voting protocols w.r.t.~verifiability, one fundamental challenge has been to formally capture the meaning of this security property. While the first formal definitions of verifiability were devised in the late 1980s already, new verifiability definitions are still being proposed. The definitions differ in various aspects, including the classes of protocols they capture and even their formulations of the very core of the meaning of verifiability. This is an unsatisfying state of affairs, leaving the research on the verifiability of e-voting protocols in a fuzzy state. In this paper, we review all formal definitions of verifiability proposed in the literature and cast them in a framework proposed by Kuesters, Truderung, and Vogt (the KTV framework), yielding a uniform treatment of verifiability. This enables us to provide a detailed comparison of the various definitions of verifiability from the literature. We thoroughly discuss advantages and disadvantages, and point to limitations and problems. Finally, from these discussions and based on the KTV framework, we distill a general definition of verifiability, which can be instantiated in various ways, and provide precise guidelines for its instantiation. The concepts for verifiability we develop should be widely applicable also beyond the framework used here. Altogether, our work offers a well-founded reference point for future research on the verifiability of e-voting systems. Véronique Cortier, David Galindo, Ralf Küsters, Johannes Müller 0001, Tomasz Truderung |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | Extended security arguments for signature schemes
Özgür Dagdelen, David Galindo, Pascal Véron, Sidi Mohamed El Yousfi Alaoui, Pierre-Louis Cayrel |
Des. Codes Cryptogr. | 2 |
| 2015 | SoK: A Comprehensive Analysis of Game-Based Ballot Privacy DefinitionsabstractWe critically survey game-based security definitions for the privacy of voting schemes. In addition to known limitations, we unveil several previously unnoticed shortcomings. Surprisingly, the conclusion of our study is that none of the existing definitions is satisfactory: they either provide only weak guarantees, or can be applied only to a limited class of schemes, or both. Based on our findings, we propose a new game-based definition of privacy which we call BPRIV. We also identify a new property which we call strong consistency, needed to express that tallying does not leak sensitive information. We validate our security notions by showing that BPRIV, strong consistency (and an additional simple property called strong correctness) for a voting scheme imply its security in a simulation-based sense. This result also yields a proof technique for proving entropy-based notions of privacy which offer the strongest security guarantees but are hard to prove directly: first prove your scheme BPRIV, strongly consistent (and correct), then study the entropy-based privacy of the result function of the election, which is a much easier task. David Bernhard, Véronique Cortier, David Galindo, Olivier Pereira, Bogdan Warinschi |
IEEE Symposium on Security and Privacy | 3 |
| 2014 | Election Verifiability for Helios under Weaker Trust Assumptions
Véronique Cortier, David Galindo, Stéphane Glondu, Malika Izabachène |
ESORICS (2) | 2 |
| 2014 | Limits of a conjecture on a leakage-resilient cryptosystem
David Galindo, Srinivas Vivek 0001 |
Inf. Process. Lett. | 1 |
| 2013 | A Leakage-Resilient Pairing-Based Variant of the Schnorr Signature Scheme
David Galindo, Srinivas Vivek 0001 |
IMACC | 1 |
| 2013 | A note on an IND-CCA2 secure Paillier-based cryptosystem
David Galindo |
Inf. Process. Lett. | 1 |
| 2012 | Identity-Based Encryption with Master Key-Dependent Message Security and Leakage-Resilience
David Galindo, Javier Herranz, Jorge Luis Villar |
ESORICS | 1 |
| 2012 | A Practical Leakage-Resilient Signature Scheme in the Generic Group Model
David Galindo, Srinivas Vivek 0001 |
Selected Areas in Cryptography | 1 |
| 2012 | On the energy cost of authenticated key agreement in wireless sensor networksabstractAbstract Wireless sensors are battery‐powered devices which are highly constrained in terms of computational capabilities, memory and communication bandwidth. While battery life is their main limitation, they require considerable energy to communicate data. Due to this, it turns out that the energy saving of computationally inexpensive primitives (like symmetric key cryptography (SKC)) can be nullified by the bigger amount of data they require to be sent. In this work, we study the energy cost of key agreement protocols between peers in a network using asymmetric key cryptography. Our main concern is to reduce the amount of data to be exchanged, which can be done by using special cryptographic paradigms like identity‐based and self‐certified cryptography. The main news is that an intensive computational primitive for resource‐constrained devices, such as non‐interactive identity‐based authenticated key exchange, performs comparably or even better than traditional authenticated key exchange (AKE) in a variety of scenarios. Moreover, protocols based in this primitive can provide better security properties in real deployments than other simple protocols based on symmetric cryptography. Our findings illustrate to what extent the latest implementation advancements push the efficiency boundaries of public key cryptography (PKC) in wireless sensor networks (WSNs). Copyright © 2010 John Wiley & Sons, Ltd. David Galindo, Rodrigo Roman, Javier López 0001 |
Wirel. Commun. Mob. Comput. | 1 |
| 2010 | Chosen-Ciphertext Secure Identity-Based Encryption from Computational Bilinear Diffie-Hellman
David Galindo |
Pairing | 1 |
| 2009 | Breaking and Repairing Damgård et al. Public Key Encryption Scheme with Non-interactive Opening
David Galindo |
CT-RSA | 1 |
| 2009 | Direct chosen-ciphertext secure identity-based key encapsulation without random oracles
Eike Kiltz, David Galindo |
Theor. Comput. Sci. | 2 |
| 2008 | A Killer Application for Pairings: Authenticated Key Establishment in Underwater Wireless Sensor Networks
David Galindo, Rodrigo Roman, Javier López 0001 |
CANS | 1 |
| 2008 | Computational Soundness of Non-Malleable Commitments
David Galindo, Flavio D. Garcia, Peter van Rossum |
ISPEC | 1 |
| 2008 | On the security of public key cryptosystems with a double decryption mechanism
David Galindo, Javier Herranz |
Inf. Process. Lett. | 1 |
| 2008 | Improved certificate-based encryption in the standard model
David Galindo, Paz Morillo, Carla Ràfols |
J. Syst. Softw. | 1 |
| 2006 | Direct Chosen-Ciphertext Secure Identity-Based Key Encapsulation Without Random Oracles
Eike Kiltz, David Galindo |
ACISP | 2 |
| 2006 | On the Generic Construction of Identity-Based Signatures with Additional Properties
David Galindo, Javier Herranz, Eike Kiltz |
ASIACRYPT | 1 |
| 2006 | A Separation Between Selective and Full-Identity Security Notions for Identity-Based Encryption
David Galindo |
ICCSA (3) | 1 |
| 2006 | Relations Among Notions of Security for Identity Based Encryption Schemes
Nuttapong Attrapadung, Yang Cui 0001, David Galindo, Goichiro Hanaoka, Ichiro Hasuo, Hideki Imai, Kanta Matsuura, Peng Yang 0002, Rui Zhang 0002 |
LATIN | 3 |
| 2005 | Boneh-Franklin Identity Based Encryption Revisited
David Galindo |
ICALP | 1 |
| 2003 | Easy Verifiable Primitives and Practical Public Key Cryptosystems
David Galindo, Sebastià Martín Molleví, Paz Morillo, Jorge Luis Villar |
ISC | 1 |
| 2003 | An IND-CPA cryptosystem from Demytko's primitiveabstractAn encryption scheme should satisfy semantic security or indistinguishability of encryptions against chosen plaintext attack (IND-CPA). We propose an elliptic curve scheme over the ring /spl Zopf/(n/sup 2/), which is efficient and semantically secure in the standard model. It is based on factoring, and it has expansion factor 2 (previous schemes with these features present expansion factors greater than or equal to 4). Demytko's primitive has been used to obtain efficiency and probabilistic encryption. Semantic security of this scheme is based on a new decisional assumption, namely, the decisional small root assumption. Confidence in this assumption is also discussed. David Galindo, Sebastià Martín Molleví, Paz Morillo, Jorge Luis Villar |
ITW | 1 |