VLDB 2026 Research / reviewers in the wild / expert
Alejandro Ranchal-Pedrosa
dblp:220/1266
· DBLP profile ↗
5ranked-venue papers
4as first author
3since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | ZLB: A Blockchain to Tolerate Colluding MajoritiesabstractIn general, consensus cannot be solved if an adversary controls a third of the system. Yet, blockchain participants typically reach consensus “eventually” despite an adversary controlling a minority of the system. Exceeding this$\frac{1}{3}$cap is made possible by tolerating transient disagreements, where distinct participants select distinct blocks for the same index, before eventually agreeing on the same block. Until now, no blockchain could tolerate an attacker controlling a majority of the system. In this paper, we present Zero-Loss Blockchain ZLB, the first blockchain that tolerates an adversary controlling more than half of the system. ZLB is an open blockchain that combines recent theoretical advances in accountable Byzantine agreement to exclude undeniably faulty replicas. Interestingly, ZLB does not need a known bound on the delay of messages but progressively reduces the portion of alive but corrupt replicas below$\frac{1}{3}$, and reaches consensus. Geo-distributed experiments show that ZLB outperforms HotStuff that cannot tolerate$n/3$faults and is almost as fast as the scalable Redbelly Blockchain. Alejandro Ranchal-Pedrosa, Vincent Gramoli |
DSN | 1 |
| 2023 | Basilic: Resilient-Optimal Consensus Protocols with Benign and Deceitful FaultsabstractThe problem of Byzantine consensus has been key to designing secure distributed systems. However, it is particularly difficult, mainly due to the presence of Byzantine processes that act arbitrarily and the unknown message delays in general networks. Although it is well known that both safety and liveness are at risk as soon as$n/3$Byzantine processes fail, very few works attempted to characterize precisely the faults that produce safety violations from the faults that produce termination violations. In this paper, we present a new lower bound on the solvability of the consensus problem by distinguishing deceitful faults violating safety and benign faults violating termination from the more general Byzantine faults, in what we call the Byzantine-deceitful-benign fault model. We show that one cannot solve consensus if$n\leq 3t+d+2q$with$t$Byzantine processes,$d$deceitful processes, and$q$benign processes. In addition, we show that this bound is tight by presenting the Basilic class of consensus protocols that solve consensus when$n > 3t+d+2q$. These protocols differ in the number of processes from which they wait to receive messages before progressing. Each of these protocols is thus better suited for some applications depending on the predominance of benign or deceitful faults. Alejandro Ranchal-Pedrosa, Vincent Gramoli |
CSF | 1 |
| 2022 | TRAP: The Bait of Rational Players to Solve Byzantine ConsensusabstractIt is impossible to solve the Byzantine consensus problem in an open network of n participants if only 2n/3 or less of them are correct. As blockchains need to solve consensus, one might think that blockchains need more than 2n/3 correct participants. But it is yet unknown whether consensus can be solved when less than 2n/3 participants are correct and k participants are rational players, which misbehave if they can gain the loot. Trading correct participants for rational players may not seem helpful to solve consensus since rational players can misbehave whereas correct participants, by definition, cannot. Alejandro Ranchal-Pedrosa, Vincent Gramoli |
AsiaCCS | 1 |
| 2019 | On the Difficulty of Hiding the Balance of Lightning Network ChannelsabstractThe Lightning Network is a second layer technology running on top of Bitcoin and other Blockchains. It is composed of a peer-to-peer network, used to transfer raw information data. Some of the links in the peer-to-peer network are identified as payment channels, used to conduct payments between two Lightning Network clients (i.e., the two nodes of the channel). Payment channels are created with a fixed credit amount, the channel capacity. The channel capacity, together with the IP address of the nodes, is published to allow a routing algorithm to find an existing path between two nodes that do not have a direct payment channel. However, to preserve users' privacy, the precise balance of the pair of nodes of a given channel (i.e. the bandwidth of the channel in each direction), is kept secret. Since balances are not announced, second-layer nodes probe routes iteratively, until they find a successful route to the destination for the amount required, if any. This feature makes the routing discovery protocol less efficient but preserves the privacy of channel balances. In this paper, we present an attack to disclose the balance of a channel in the Lightning Network. Our attack is based on performing multiple payments ensuring that none of them is finalized, minimizing the economical cost of the attack. We present experimental results that validate our claims, and countermeasures to handle the attack. Jordi Herrera-Joancomartí, Guillermo Navarro-Arribas, Alejandro Ranchal-Pedrosa, Cristina Pérez-Solà, Joaquín García 0001 |
AsiaCCS | 3 |
| 2019 | Platypus: Offchain Protocol Without SynchronyabstractOffchain protocols aim at bypassing the scalability and privacy limitations of classic blockchains by allowing a subset of participants to execute multiple transactions outside the blockchain. While existing solutions like payment networks and factories depend on a complex routing protocol, other solutions simply require participants to build a childchain, a secondary blockchain where their transactions are privately executed. Unfortunately, all childchain solutions assume either synchrony or a trusted execution environment. In this paper we present Platypus, an offchain protocol that requires neither synchony nor a trusted execution environment. Relieving the need for a trusted execution environment allows Platypus to ensure privacy without trusting a central authority, like Intel, that manufactures dedicated hardware chipset, like SGX. Relieving the need for synchrony means that no attacker can steal coins by leveraging clock drifts or message delays to lure timelocks. In order to prove our algorithm correct, we formalize the chilchain problem as a Byzantine variant of the classic Atomic Commit problem, where closing an offchain protocol is equivalent to committing the whole set of payments previously recorded on the childchain “atomically” on the main chain. Platypus is resilience optimal and we explain how to generalize it to crosschain payments. Alejandro Ranchal-Pedrosa, Vincent Gramoli |
NCA | 1 |