Renas Bacho

dblp:320/2171 · DBLP profile ↗
← Back
15ranked-venue papers
14as first author
15since 2021 · last 2026
0009-0007-7037-2458ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 14 first-author · 14 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adaptively Secure (Aggregatable) PVSS from Standard Assumptions
Renas Bacho, Yanbo Chen 0002, Julian Loss
CRYPTO (2)1
2026 Earpicks: Tightly Secure Two-Round Multi and Threshold Signatures
Renas Bacho, Yanbo Chen 0002
EUROCRYPT (1)1
2026 Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGM
Renas Bacho, Yanbo Chen 0002, Julian Loss, Stefano Tessaro, Chenzhi Zhu
EUROCRYPT (1)1
2026 Nearly Quadratic Asynchronous Distributed Key Generation from Recursive Consensus
Ittai Abraham, Renas Bacho, Julian Loss, Gilad Stern
PODC2
2025 Adaptively Secure Three-Round Threshold Schnorr Signatures from DDH
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001
CRYPTO (6)1
2025 T-Spoon: Tightly Secure Two-Round Multi-signatures with Key Aggregation
Renas Bacho, Benedikt Wagner
CRYPTO (6)1
2025 Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001
EUROCRYPT (2)1
2025 SoK: Dlog-Based Distributed Key Generation
abstract
Distributed Key Generation (DKG) protocols are fundamental components of threshold cryptography, enabling key generation in a trustless manner for a range of crypto-graphic operations such as threshold encryption and signing. Of particular widespread use are DKG protocols for discrete-logarithm based cryptosystems. In this Systematization of Knowledge (SoK), we present a comprehensive analysis of existing DKG protocols in the discrete-logarithm setting, with the goal of identifying cryptographic techniques and design principles that facilitate the development of secure and resilient protocols. To offer a structured overview of the literature, we adopt a modular approach and classify DKG protocols based on their underlying network assumption and cryptographic tools. These two factors determine how DKG protocols manage secret sharing and reach consensus as their essential building blocks. We also highlight various insights and suggest future research directions that could drive further advancements in this area.
Renas Bacho, Alireza Kavousi
SP1
2024 HARTS: High-Threshold, Adaptively Secure, and Robust Threshold Schnorr Signatures
Renas Bacho, Julian Loss, Gilad Stern, Benedikt Wagner
ASIACRYPT (3)1
2024 Tightly Secure Non-interactive BLS Multi-signatures
Renas Bacho, Benedikt Wagner
ASIACRYPT (2)1
2024 GRandLine: Adaptively Secure DKG and Randomness Beacon with (Log-)Quadratic Communication Complexity
abstract
A randomness beacon is a source of continuous and publicly verifiable randomness which is of crucial importance for many applications. Existing works on randomness beacons suffer from at least one of the following drawbacks: (i) security only against static (i.e., non-adaptive) adversaries, (ii) each epoch takes many rounds of communication, or (iii) computationally expensive tools such as proof-of-work (PoW) or verifiable delay functions (VDF). In this work, we introduce GRandLine, the first adaptively secure randomness beacon protocol that overcomes all these limitations while preserving simplicity and optimal resilience in the synchronous network setting. We achieve our result in two steps. First, we design a novel distributed key generation (DKG) protocol GRand that runs in O(λ n2 log n ) bits of communication but, unlike most conventional DKG protocols, outputs both secret and public keys as group elements. Here, λ denotes the security parameter. Second, following termination of GRand, parties can use their keys to derive a sequence of randomness beacon values, where each random value costs only a single asynchronous round and O(λ n2) bits of communication. We implement GRandLine and evaluate it using a network of up to 64 parties running in geographically distributed AWS instances. Our evaluation shows that GRandLine can produce about 2 beacon outputs per second in a network of 64 parties. We compare our protocol to the state-of-the-art randomness beacon protocols OptRand (NDSS '23), BRandPiper (CCS '21), and Drand, in the same setting and observe that it vastly outperforms them.
Renas Bacho, Christoph Lenzen 0001, Julian Loss, Simon Ochsenreither, Dimitrios Papachristoudis
CCS1
2024 Twinkle: Threshold Signatures from DDH with Full Adaptive Security
Renas Bacho, Julian Loss, Stefano Tessaro, Benedikt Wagner, Chenzhi Zhu
EUROCRYPT (1)1
2023 Adaptively Secure (Aggregatable) PVSS and Application to Distributed Randomness Beacons
abstract
Publicly Verifiable Secret Sharing (PVSS) is a fundamental primitive that allows to share a secret S among n parties via a publicly verifiable transcript T. Existing (efficient) PVSS are only proven secure against static adversaries who must choose who to corrupt ahead of a protocol execution. As a result, any protocol (e.g., a distributed randomness beacon) that builds on top of such a PVSS scheme inherits this limitation. To overcome this barrier, we revisit the security of PVSS under adaptive corruptions and show that, surprisingly, many protocols from the literature already achieve it in a meaningful way:
Renas Bacho, Julian Loss
CCS1
2023 Network-Agnostic Security Comes (Almost) for Free in DKG and MPC
Renas Bacho, Daniel Collins 0001, Chen-Da Liu-Zhang, Julian Loss
CRYPTO (1)1
2022 On the Adaptive Security of the Threshold BLS Signature Scheme
abstract
Threshold signatures are a crucial tool for many distributed protocols. As shown by Cachin, Kursawe, and Shoup (PODC '00), schemes with unique signatures are of particular importance, as they allow to implement distributed coin flipping very efficiently and without any timing assumptions. This makes them an ideal building block for (inherently randomized) asynchronous consensus protocols. The threshold-BLS signature of Boldyreva (PKC '03) is both unique and very compact, but unfortunately lacks a security proof against adaptive adversaries. Thus, current consensus protocols either rely on less efficient alternatives or are not adaptively secure. In this work, we revisit the security of the threshold BLS signature by showing the following results, assuming t adaptive corruptions: - We give a modular security proof that follows a two-step approach: 1) We introduce a new security notion for distributed key generation protocols (DKG). We show that it is satisfied by several protocols that previously only had a static security proof. 2) Assuming any DKG protocol with this property, we then prove unforgeability of the threshold BLS scheme. Our reductions are tight and can be used to substantiate real-world parameter choices. - To justify our use of strong assumptions such as the algebraic group model (AGM) and the hardness of one-more-discrete logarithm (OMDL), we prove an impossibility result: Even in the AGM, a strong interactive assumption is required in order to prove the scheme secure.
Renas Bacho, Julian Loss
CCS1