VLDB 2026 Research / reviewers in the wild / expert
Jesper Buus Nielsen
dblp:43/4040
· DBLP profile ↗
81ranked-venue papers
9as first author
16since 2021 · last 2026
0000-0002-7074-0683ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 8 first-author · 16 since 2021Theory of computation · 15 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Optimal Best-of-Both-Worlds Consensus
Fatima Elsheimy, Simon Holmgaard Kamp, Julian Loss, Jesper Buus Nielsen |
CRYPTO (10) | 4 |
| 2025 | Malleable SNARKs and Their Applications
Suvradip Chakraborty, Dennis Hofheinz, Roman Langrehr, Jesper Buus Nielsen, Christoph Striecks, Daniele Venturi 0001 |
EUROCRYPT (4) | 4 |
| 2025 | OCash: Fully Anonymous Payments Between Blockchain Light Clients
Adam Blatchley Hansen, Jesper Buus Nielsen, Mark Simkin 0001 |
PKC (5) | 2 |
| 2024 | Early Stopping for Any Number of Corruptions
Julian Loss, Jesper Buus Nielsen |
EUROCRYPT (3) | 2 |
| 2023 | Practical Large-Scale Proof-Of-Stake Asynchronous Total-Order BroadcastabstractWe present simple and practical protocols for generating randomness as used by asynchronous total-order broadcast. The protocols are secure in a proof-of-stake setting with dynamically changing stake. They can be plugged into existing protocols for asynchronous total-order broadcast and will turn these into asynchronous total-order broadcast with dynamic stake. Our contribution relies on two important techniques. The paper "Random Oracles in Constantinople: Practical Asynchronous Byzantine Agreement using Cryptography" [Cachin, Kursawe, and Shoup, PODC 2000] has influenced the design of practical total-order broadcast through its use of threshold cryptography. However, it needs a setup protocol to be efficient. In a proof-of-stake setting with dynamic stake this setup would have to be continually recomputed, making the protocol impractical. The work "Asynchronous Byzantine Agreement with Subquadratic Communication" [Blum, Katz, Liu-Zhang, and Loss, TCC 2020] showed how to use an initial setup for broadcast to asymptotically efficiently generate sub-sequent setups. The protocol, however, resorted to fully homomorphic encryption and was therefore not practically efficient. We adopt their approach to the proof-of-stake setting with dynamic stake, apply it to the Constantinople paper, and remove the need for fully homomorphic encryption. This results in simple and practical proof-of-stake protocols. Orestis Alpos, Christian Cachin, Simon Holmgaard Kamp, Jesper Buus Nielsen |
AFT | 4 |
| 2023 | On Valiant's Conjecture - Impossibility of Incrementally Verifiable Computation from Random Oracles
Mathias Hall-Andersen, Jesper Buus Nielsen |
EUROCRYPT (2) | 2 |
| 2022 | Encryption to the Future - A Paradigm for Sending Secret Messages to Future (Anonymous) Committees
Matteo Campanelli, Bernardo Machado David, Hamidreza Khoshakhlagh, Anders Konring, Jesper Buus Nielsen |
ASIACRYPT (3) | 5 |
| 2022 | GearBox: Optimal-size Shard Committees by Leveraging the Safety-Liveness DichotomyabstractSharding is an emerging technique to overcome scalability issues on blockchain based public ledgers. Without sharding, every node in the network has to listen to and process all ledger protocol messages. The basic idea of sharding is to parallelize the ledger protocol: the nodes are divided into smaller subsets that each take care of a fraction of the original load by executing lighter instances of the ledger protocol, also called shards. The smaller the shards, the higher the efficiency, as by increasing parallelism there is less overhead in the shard consensus. Bernardo Machado David, Bernardo Magri, Christian Matt 0002, Jesper Buus Nielsen, Daniel Tschudi |
CCS | 4 |
| 2022 | Formalizing Delayed Adaptive Corruptions and the Security of Flooding NetworksabstractMany decentralized systems rely on flooding protocols for message dissemination. In such a protocol, the sender of a message sends it to a randomly selected set of peers. These peers again send the message to their randomly selected peers, until every network participant has received the message. This type of protocols clearly fail in face of an adaptive adversary who can simply corrupt all peers of the sender and thereby prevent the message from being delivered. Nevertheless, flooding protocols are commonly used within protocols that aim to be cryptographically secure, most notably in blockchain protocols. While it is possible to revert to static corruptions, this gives unsatisfactory security guarantees, especially in the setting of a blockchain that is supposed to run for an extended period of time. To be able to provide meaningful security guarantees in such settings, we give precise semantics to what we call $$\delta $$ -delayed adversaries in the Universal Composability (UC) framework. Such adversaries can adaptively corrupt parties, but there is a delay of time $$\delta $$ from when an adversary decides to corrupt a party until they succeed in overtaking control of the party. Within this model, we formally prove the intuitive result that flooding protocols are secure against $$\delta $$ -delayed adversaries when $$\delta $$ is at least the time it takes to send a message from one peer to another plus the time it takes the recipient to resend the message. To this end, we show how to reduce the adaptive setting with a $$\delta $$ -delayed adversary to a static experiment with an Erdős-Rényi graph. Using the established theory of Erdős-Rényi graphs, we provide upper bounds on the propagation time of the flooding functionality for different neighborhood sizes of the gossip network. More concretely, we show the following for security parameter $$\kappa $$ , point-to-point channels with delay at most $$\varDelta $$ , and n parties in total, with a sufficiently delayed adversary that can corrupt any constant fraction of the parties: If all parties send to $$\varOmega (\kappa )$$ parties on average, then we can realize a flooding functionality with maximal delay $$\mathcal {O}\bigl (\varDelta \cdot \log (n) \bigr )$$ ; and if all parties send to $$\varOmega \bigl ( \sqrt{\kappa n} \bigr )$$ parties on average, we can realize a flooding functionality with maximal delay $$\mathcal {O}(\varDelta )$$ . Christian Matt 0002, Jesper Buus Nielsen, Søren Eller Thomsen |
CRYPTO (2) | 2 |
| 2022 | Public Randomness Extraction with Ephemeral Roles and Worst-Case Corruptions
Jesper Buus Nielsen, João Ribeiro 0002, Maciej Obremski |
CRYPTO (1) | 1 |
| 2022 | Universally Composable Subversion-Resilient Cryptography
Suvradip Chakraborty, Bernardo Magri, Jesper Buus Nielsen, Daniele Venturi 0001 |
EUROCRYPT (1) | 3 |
| 2022 | Fast threshold ECDSA with honest majorityabstractECDSA is a widely adopted digital signature standard. A number of threshold protocols for ECDSA have been developed that let a set of parties jointly generate the secret signing key and compute signatures, without ever revealing the signing key. Threshold protocols for ECDSA have seen recent interest, in particular due to the need for additional security in cryptocurrency wallets where leakage of the signing key is equivalent to an immediate loss of money. We propose a threshold ECDSA protocol secure against an active adversary in the honest majority model with abort. Our protocol is efficient in terms of both computation and bandwidth usage, and it allows the parties to pre-process parts of the signature, such that once the message to sign becomes known, they can compute a secret sharing of the signature very efficiently, using only local operations. We also show how to obtain guaranteed output delivery (and hence also fairness) in the online phase at the cost of some additional pre-processing work, i.e., such that it either aborts during the pre-processing phase, in which case nothing is revealed, or the signature is guaranteed to be delivered to all honest parties online. Ivan Damgård, Thomas P. Jakobsen, Jesper Buus Nielsen, Jakob Illeborg Pagter, Michael Bæksvang Østergaard |
J. Comput. Secur. | 3 |
| 2021 | YOSO: You Only Speak Once - Secure MPC with Stateless Ephemeral Roles
Craig Gentry, Shai Halevi, Hugo Krawczyk, Bernardo Magri, Jesper Buus Nielsen, Tal Rabin, Sophia Yakoubov |
CRYPTO (2) | 5 |
| 2021 | TARDIS: A Foundation of Time-Lock Puzzles in UC
Carsten Baum, Bernardo Machado David, Rafael Dowsley, Jesper Buus Nielsen, Sabine Oechsner |
EUROCRYPT (3) | 4 |
| 2021 | Random-Index PIR and ApplicationsabstractPrivate information retrieval (PIR) lets a client retrieve an entry from a database without the server learning which entry was retrieved. Here we study a weaker variant that we call random-index PIR (RPIR), where the retrieved index is an output rather than an input of the protocol, and is chosen at random. RPIR is clearly weaker than PIR, but it suffices for some interesting applications and may be realized more efficiently than full-blown PIR.We report here on two lines of work, both tied to RPIR but otherwise largely unrelated. The first line of work studies RPIR as a primitive on its own. Perhaps surprisingly, we show that RPIR is in fact equivalent to PIR when there are no restrictions on the number of communication rounds. On the other hand, RPIR can be implemented in a “noninteractive” setting (with pre-processing), which is clearly impossible for PIR. For two-server RPIR we even show a truly noninteractive solution, offering information-theoretic security without any pre-processing.The other line of work, which was the original motivation for our work, uses RPIR to improve on the recent work of Benhamouda et al. (TCC’20) for maintaining secret values on public blockchains. Their solution depends on a method for selecting many random public keys from a PKI while hiding most of the selected keys from an adversary. However, the method they proposed is vulnerable to a double-dipping attack, limiting its resilience. Here we observe that a RPIR protocol, where the client is implemented via secure MPC, can eliminate that vulnerability. We thus get a secrets-on-blockchain protocol (and more generally large-scale MPC) which is resilient to any fraction \(f < 1/2\) of corrupted parties, resolving the main open problem left from the work of Benhamouda et al.As the client in this solution is implemented via secure MPC, it really brings home the need to make it as efficient as possible. We thus strive to explore whatever efficiency gains we can get by using RPIR rather than PIR. We achieve more gains by using batch RPIR where multiple indexes are retrieved at once. Lastly, we observe that this application can make do with a weaker security guarantee than full RPIR, and show that this weaker variant can be realized even more efficiently. We discuss one protocol in particular that may be attractive for practical implementations. Craig Gentry, Shai Halevi, Bernardo Magri, Jesper Buus Nielsen, Sophia Yakoubov |
TCC (3) | 4 |
| 2021 | High-Performance Multi-party Computation for Binary Circuits Based on Oblivious TransferabstractWe present a unified view of the two-party and multi-party computation protocols based on oblivious transfer first outlined in Nielsen et al. (CRYPTO 2012) and Larraia et al. (CRYPTO 2014). We present a number of modifications and improvements to these earlier presentations, as well as full proofs of the entire protocol. Improvements include a unified pre-processing and online MAC methodology, mechanisms to pass between different MAC variants and fixing a minor bug in the protocol of Larraia et al. in relation to a selective failure attack. It also fixes a minor bug in Nielsen et al. resulting from using Jensen’s inequality in the wrong direction in an analysis. Sai Sheshank Burra, Enrique Larraia, Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi, Emmanuela Orsini, Peter Scholl, Nigel P. Smart |
J. Cryptol. | 3 |
| 2020 | Reverse Firewalls for Actively Secure MPCs
Suvradip Chakraborty, Stefan Dziembowski, Jesper Buus Nielsen |
CRYPTO (2) | 3 |
| 2020 | Lower Bounds for Leakage-Resilient Secret Sharing
Jesper Buus Nielsen, Mark Simkin 0001 |
EUROCRYPT (1) | 1 |
| 2020 | Continuously Non-malleable Codes in the Split-State ModelabstractAbstract Non-malleable codes (Dziembowski et al., ICS’10 and J. ACM’18) are a natural relaxation of error correcting/detecting codes with useful applications in cryptography. Informally, a code is non-malleable if an adversary trying to tamper with an encoding of a message can only leave it unchanged or modify it to the encoding of an unrelated value. This paper introduces continuous non-malleability, a generalization of standard non-malleability where the adversary is allowed to tamper continuously with the same encoding. This is in contrast to the standard definition of non-malleable codes, where the adversary can only tamper a single time. The only restriction is that after the first invalid codeword is ever generated, a special self-destruct mechanism is triggered and no further tampering is allowed; this restriction can easily be shown to be necessary. We focus on the split-state model, where an encoding consists of two parts and the tampering functions can be arbitrary as long as they act independently on each part. Our main contributions are outlined below. We show that continuous non-malleability in the split-state model is impossible without relying on computational assumptions. We construct a computationally secure split-state code satisfying continuous non-malleability in the common reference string (CRS) model. Our scheme can be instantiated assuming the existence of collision-resistant hash functions and (doubly enhanced) trapdoor permutations, but we also give concrete instantiations based on standard number-theoretic assumptions. We revisit the application of non-malleable codes to protecting arbitrary cryptographic primitives against related-key attacks. Previous applications of non-malleable codes in this setting required perfect erasures and the adversary to be restricted in memory. We show that continuously non-malleable codes allow to avoid these restrictions. Sebastian Faust, Pratyay Mukherjee, Jesper Buus Nielsen, Daniele Venturi 0001 |
J. Cryptol. | 3 |
| 2019 | Stronger Leakage-Resilient and Non-Malleable Secret Sharing Schemes for General Access Structures
Divesh Aggarwal, Ivan Damgård, Jesper Buus Nielsen, Maciej Obremski, Erick Purwanto, João Ribeiro 0002, Mark Simkin 0001 |
CRYPTO (2) | 3 |
| 2019 | Communication Lower Bounds for Statistically Secure MPC, With or Without Preprocessing
Ivan Damgård, Kasper Green Larsen, Jesper Buus Nielsen |
CRYPTO (2) | 3 |
| 2019 | Continuous Non-Malleable Codes in the 8-Split-State Model
Divesh Aggarwal, Nico Döttling, Jesper Buus Nielsen, Maciej Obremski, Erick Purwanto |
EUROCRYPT (1) | 3 |
| 2019 | Lower Bounds for Oblivious Data StructuresabstractAn oblivious data structure is a data structure where the memory access patterns reveals no information about the operations performed on it. Such data structures were introduced by Wang et al. [ACM SIGSAC’14] and are intended for situations where one wishes to store the data structure at an untrusted server. One way to obtain an oblivious data structure is simply to run a classic data structure on an oblivious RAM (ORAM). Until very recently, this resulted in an overhead of ω(lg n) for the most natural setting of parameters. Moreover, a recent lower bound for ORAMs by Larsen and Nielsen [CRYPTO’18] show that they always incur an overhead of at least Ω(lg n) if used in a black box manner. To circumvent the ω(lg n) overhead, researchers have instead studied classic data structure problems more directly and have obtained efficient solutions for many such problems such as stacks, queues, deques, priority queues and search trees. However, none of these data structures process operations faster than Θ(lg n), leaving open the question of whether even faster solutions exist. In this paper, we rule out this possibility by proving Ω(lg n) lower bounds for oblivious stacks, queues, deques, priority queues and search trees. Riko Jacob, Kasper Green Larsen, Jesper Buus Nielsen |
SODA | 3 |
| 2019 | Continuously non-malleable codes with split-state refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
Theor. Comput. Sci. | 2 |
| 2018 | Continuously Non-malleable Codes with Split-State Refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
ACNS | 2 |
| 2018 | Yes, There is an Oblivious RAM Lower Bound!
Kasper Green Larsen, Jesper Buus Nielsen |
CRYPTO (2) | 2 |
| 2017 | Maliciously Secure Oblivious Linear Function Evaluation with Constant Overhead
Satrajit Ghosh, Jesper Buus Nielsen, Tobias Nilges |
ASIACRYPT (1) | 2 |
| 2017 | TinyOLE: Efficient Actively Secure Two-Party Computation from Oblivious Linear Function EvaluationabstractWe introduce a new approach to actively secure two-party computation based on so-called oblivious linear function evaluation (OLE), a natural generalisation of oblivious transfer (OT) and a special case of the notion of oblivious polynomial evaluation introduced by Naor and Pinkas at STOC 1999. OLE works over a finite field F. In an OLE the sender inputs two field elements a ƒ F and b ƒ F, and the receiver inputs a field element x ∈ F and learns only ƒx) = ax + b. Our protocol can evaluate an arithmetic circuit over a finite field F given black-box access to OLE for F. The protocol is unconditionally secure and consumes only a constant number of OLEs per multiplication gate. An OLE over a field F of size O(2κ) be implemented with communication O(κ). This gives a protocol with communication complexity O(C κ) for large enough fields, where C is an arithmetic circuit computing the desired function. Nico Döttling, Satrajit Ghosh, Jesper Buus Nielsen, Tobias Nilges, Roberto Trifiletti |
CCS | 3 |
| 2017 | DUPLO: Unifying Cut-and-Choose for Garbled CircuitsabstractCut-and-choose (CC) is the standard approach to making Yao's garbled circuit two-party computation (2PC) protocol secure against malicious adversaries. Traditional cut-and-choose operates at the level of entire circuits, whereas the LEGO paradigm (Nielsen & Orlandi, TCC 2009) achieves asymptotic improvements by performing cut-and-choose at the level of individual gates. In this work we propose a unified approach called DUPLO that spans the entire continuum between these two extremes. The cut-and-choose step in our protocol operates on the level of arbitrary circuit "components," which can range in size from a single gate to the entire circuit itself. Vladimir Kolesnikov, Jesper Buus Nielsen, Mike Rosulek, Ni Trieu, Roberto Trifiletti |
CCS | 2 |
| 2017 | The TinyTable Protocol for 2-Party Secure Computation, or: Gate-Scrambling Revisited
Ivan Damgård, Jesper Buus Nielsen, Michael Nielsen 0001, Samuel Ranellucci |
CRYPTO (1) | 2 |
| 2017 | Constant Round Maliciously Secure 2PC with Function-independent Preprocessing using LEGO
Jesper Buus Nielsen, Thomas Schneider 0003, Roberto Trifiletti |
NDSS | 1 |
| 2017 | Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model
Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
Theor. Comput. Sci. | 2 |
| 2016 | Reactive Garbling: Foundation, Instantiation, Application
Jesper Buus Nielsen, Samuel Ranellucci |
ASIACRYPT (2) | 1 |
| 2016 | Rate-1, Linear Time and Additively Homomorphic UC Commitments
Ignacio Cascudo, Ivan Damgård, Bernardo Machado David, Nico Döttling, Jesper Buus Nielsen |
CRYPTO (3) | 5 |
| 2016 | On the Communication Required for Unconditionally Secure Multiplication
Ivan Damgård, Jesper Buus Nielsen, Antigoni Polychroniadou, Mikhail A. Raskin |
CRYPTO (2) | 2 |
| 2016 | Unconditionally Secure Computation with Reduced Interaction
Ivan Damgård, Jesper Buus Nielsen, Rafail Ostrovsky, Adi Rosén |
EUROCRYPT (2) | 2 |
| 2016 | Signature Schemes Secure Against Hard-to-Invert Leakage
Sebastian Faust, Carmit Hazay, Jesper Buus Nielsen, Peter Sebastian Nordholt, Angela Zottarel |
J. Cryptol. | 3 |
| 2015 | Privacy-Free Garbled Circuits with Applications to Efficient Zero-Knowledge
Tore Kasper Frederiksen, Jesper Buus Nielsen, Claudio Orlandi |
EUROCRYPT (2) | 2 |
| 2015 | Mind Your Coins: Fully Leakage-Resilient Signatures with Graceful DegradationabstractWe construct a new leakage-resilient signature scheme. Our scheme remains unforgeable in the noisy leakage model, where the only restriction on the leakage is that it does not decrease the min-entropy of the secret key by too much. The leakage information can depend on the entire state of the signer; this property is sometimes known as fully leakage resilience. An additional feature of our construction, is that it offers a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen et al. (PKC 2014) in the bounded leakage model, to deal with settings in which the secret key is much larger than the size of a signature. For security parameter $$\kappa $$ , our scheme tolerates leakage on the entire state of the signer until $$\omega (\log \kappa )$$ bits of min-entropy are left in the secret key, and is proven secure in the standard model. While we describe our scheme in terms of generic building blocks, we also explain how to instantiate it efficiently under fairly standard number-theoretic assumptions. Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
ICALP (1) | 2 |
| 2014 | Compact VSS and Efficient Homomorphic UC CommitmentsabstractWe present a new compact verifiable secret sharing scheme, based on this we present the first construction of a homomorphic UC commitment scheme that requires only cheap symmetric cryptography, except for a small number of seed OTs. To commit to a k -bit string, the amortized communication cost is O ( k ) bits. Assuming a sufficiently efficient pseudorandom generator, the computational complexity is O ( k ) for the verifier and O ( k 1 + ε ) for the committer (where ε < 1 is a constant). In an alternative variant of the construction, all complexities are O ( k · polylog ( k )). Our commitment scheme extends to vectors over any finite field and is additively homomorphic. By sending one extra message, the prover can allow the verifier to also check multiplicative relations on committed strings, as well as verifying that committed vectors a , b satisfy a = φ ( b ) for a linear function φ . These properties allow us to non-interactively implement any one-sided functionality where only one party has input (this includes UC secure zero-knowledge proofs of knowledge). We also present a perfectly secure implementation of any multiparty functionality, based directly on our VSS. The communication required is proportional to a circuit implementing the functionality, up to a logarithmic factor. For a large natural class of circuits the overhead is even constant. We also improve earlier results by Ranellucci et al. on the amount of correlated randomness required for string commitments with individual opening of bits. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Ivan Damgård, Bernardo Machado David, Irene Giacomelli, Jesper Buus Nielsen |
ASIACRYPT (2) | 4 |
| 2014 | Adaptive versus Static Security in the UC Model
Ivan Damgård, Jesper Buus Nielsen |
ProvSec | 2 |
| 2014 | Continuous Non-malleable Codes
Sebastian Faust, Pratyay Mukherjee, Jesper Buus Nielsen, Daniele Venturi 0001 |
TCC | 3 |
| 2013 | Fast and Maliciously Secure Two-Party Computation Using the GPU
Tore Kasper Frederiksen, Jesper Buus Nielsen |
ACNS | 2 |
| 2013 | Limits on the Power of Cryptographic Cheap TalkabstractWe revisit the question of whether cryptographic protocols can replace correlated equilibria mediators in two-player strategic games. This problem was first addressed by Dodis, Halevi and Rabin (CRYPTO 2000), who suggested replacing the mediator with a secure protocol and proved that their solution is stable in the Nash equilibrium (NE) sense, provided that the players are computationally bounded. We show that there exist two-player games for which no cryptographic protocol can implement the mediator in a sequentially rational way; that is, without introducing empty threats. This explains why all solutions so far were either sequentially unstable, or were restricted to a limited class of correlated equilibria (specifically, those that do not dominate any NE, and hence playing them does not offer a clear advantage over playing any NE). In the context of computational NE, we classify necessary and sufficient cryptographic assumptions for implementing a mediator that allows to achieve a given utility profile of a correlated equilibrium. The picture that emerges is somewhat different than the one arising in semi-honest secure two-party computation. Specifically, while in the latter case every functionality is either “complete” (i.e., implies Oblivious Transfer) or “trivial” (i.e., can be securely computed unconditionally), in the former there exist some “intermediate” utility profiles whose implementation is equivalent to the existence of one-way functions. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Pavel Hubácek, Jesper Buus Nielsen, Alon Rosen |
CRYPTO (1) | 2 |
| 2013 | MiniLEGO: Efficient Secure Two-Party Computation from General Assumptions
Tore Kasper Frederiksen, Thomas P. Jakobsen, Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi |
EUROCRYPT | 3 |
| 2013 | Secure Key Management in the CloudabstractWe consider applications involving a number of servers in the cloud that go through a sequence of online periods where the servers communicate, separated by offline periods where the servers are idle. During the offline periods, we assume that the servers need to securely store sensitive information such as cryptographic keys. Applications like this include many cases where secure multiparty computation is outsourced to the cloud, and in particular a number of online auctions and benchmark computations with confidential inputs. We consider fully autonomous servers that switch between online and offline periods without communicating with anyone from outside the cloud, and semi-autonomous servers that need a limited kind of assistance from outside the cloud when doing the transition. We study the levels of security one can – and cannot – obtain in this model, propose light-weight protocols achieving maximal security, and report on their practical performance. Ivan Damgård, Thomas P. Jakobsen, Jesper Buus Nielsen, Jakob Illeborg Pagter |
IMACC | 3 |
| 2012 | Signature Schemes Secure against Hard-to-Invert Leakage
Sebastian Faust, Carmit Hazay, Jesper Buus Nielsen, Peter Sebastian Nordholt, Angela Zottarel |
ASIACRYPT | 3 |
| 2012 | Actively Secure Two-Party Evaluation of Any Quantum Operation
Frédéric Dupuis, Jesper Buus Nielsen, Louis Salvail |
CRYPTO | 2 |
| 2012 | A New Approach to Practical Active-Secure Two-Party Computation
Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi, Sai Sheshank Burra |
CRYPTO | 1 |
| 2011 | Lower and Upper Bounds for Deniable Public-Key Encryption
Rikke Bendlin, Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi |
ASIACRYPT | 2 |
| 2011 | Perfectly Secure Oblivious RAM without Random Oracles
Ivan Damgård, Sigurd Meldgaard, Jesper Buus Nielsen |
TCC | 3 |
| 2010 | Secure Two-Party Quantum Evaluation of Unitaries against Specious Adversaries
Frédéric Dupuis, Jesper Buus Nielsen, Louis Salvail |
CRYPTO | 2 |
| 2010 | On the theoretical gap between synchronous and asynchronous MPC protocolsabstractMultiparty computation (MPC) protocols among n parties secure against t active faults are known to exist if and only if Zuzana Beerliová-Trubíniová, Martin Hirt, Jesper Buus Nielsen |
PODC | 3 |
| 2010 | From Passive to Covert Security at Low Cost
Ivan Damgård, Martin Geisler 0001, Jesper Buus Nielsen |
TCC | 3 |
| 2010 | On the Necessary and Sufficient Assumptions for UC Computation
Ivan Damgård, Jesper Buus Nielsen, Claudio Orlandi |
TCC | 2 |
| 2009 | Privacy-Enhancing Auctions Using Rational Cryptography
Peter Bro Miltersen, Jesper Buus Nielsen, Nikos Triandopoulos |
CRYPTO | 2 |
| 2009 | Universally Composable Multiparty Computation with Partially Isolated Parties
Ivan Damgård, Jesper Buus Nielsen, Daniel Wichs |
TCC | 2 |
| 2009 | LEGO for Two-Party Secure Computation
Jesper Buus Nielsen, Claudio Orlandi |
TCC | 1 |
| 2009 | A Tree Based Method for the Rapid Screening of Chemical Fingerprints
Thomas Greve Kristensen, Jesper Buus Nielsen, Christian N. S. Pedersen |
WABI | 2 |
| 2009 | On the Number of Synchronous Rounds Sufficient for Authenticated Byzantine Agreement
Matthias Fitzi, Jesper Buus Nielsen |
DISC | 2 |
| 2008 | Scalable Multiparty Computation with Nearly Optimal Work and Resilience
Ivan Damgård, Yuval Ishai, Mikkel Krøigaard, Jesper Buus Nielsen, Adam D. Smith 0001 |
CRYPTO | 4 |
| 2008 | Isolated Proofs of Knowledge and Isolated Zero Knowledge
Ivan Damgård, Jesper Buus Nielsen, Daniel Wichs |
EUROCRYPT | 2 |
| 2008 | Asynchronous Multi-Party Computation with Quadratic Communication
Martin Hirt, Jesper Buus Nielsen, Bartosz Przydatek |
ICALP (2) | 2 |
| 2008 | OT-Combiners via Secure Computation
Danny Harnik, Yuval Ishai, Eyal Kushilevitz, Jesper Buus Nielsen |
TCC | 4 |
| 2008 | SNPFile - A software library and file format for large scale association mapping and population genetics studiesabstractBACKGROUND: High-throughput genotyping technology has enabled cost effective typing of thousands of individuals in hundred of thousands of markers for use in genome wide studies. This vast improvement in data acquisition technology makes it an informatics challenge to efficiently store and manipulate the data. While spreadsheets and at text files were adequate solutions earlier, the increased data size mandates more efficient solutions. RESULTS: We describe a new binary file format for SNP data, together with a software library for file manipulation. The file format stores genotype data together with any kind of additional data, using a flexible serialisation mechanism. The format is designed to be IO efficient for the access patterns of most multi-locus analysis methods. CONCLUSION: The new file format has been very useful for our own studies where it has significantly reduced the informatics burden in keeping track of various secondary data, and where the memory and IO efficiency has greatly simplified analysis runs. A main limitation with the file format is that it is only supported by the very limited set of analysis tools developed in our own lab. This is somewhat alleviated by a scripting interfaces that makes it easy to write converters to and from the format. Jesper Buus Nielsen, Thomas Mailund |
BMC Bioinform. | 1 |
| 2007 | Secure Protocols with Asymmetric Trust
Ivan Damgård, Yvo Desmedt, Matthias Fitzi, Jesper Buus Nielsen |
ASIACRYPT | 4 |
| 2007 | Scalable and Unconditionally Secure Multiparty Computation
Ivan Damgård, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2006 | Robust Multiparty Computation with Linear Communication Complexity
Martin Hirt, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2006 | Simplified Threshold RSA with Adaptive and Proactive Security
Jesús F. Almansa, Ivan Damgård, Jesper Buus Nielsen |
EUROCRYPT | 3 |
| 2006 | Unconditionally Secure Constant-Rounds Multi-party Computation for Equality, Comparison, Bits and Exponentiation
Ivan Damgård, Matthias Fitzi, Eike Kiltz, Jesper Buus Nielsen, Tomas Toft |
TCC | 4 |
| 2005 | Upper Bounds on the Communication Complexity of Optimally Resilient Cryptographic Multiparty Computation
Martin Hirt, Jesper Buus Nielsen |
ASIACRYPT | 2 |
| 2005 | Cryptographic Asynchronous Multi-party Computation with Optimal Resilience (Extended Abstract)
Martin Hirt, Jesper Buus Nielsen, Bartosz Przydatek |
EUROCRYPT | 2 |
| 2004 | Universally Composable Protocols with Relaxed Set-Up AssumptionsabstractA desirable goal for cryptographic protocols is to guarantee security when the protocol is composed with other protocol instances. Universally composable (UC) protocols provide this guarantee in a strong sense: A protocol remains secure even when composed concurrently with an unbounded number of instances of arbitrary protocols. However, UC protocols for carrying out general tasks are known to exist only if a majority of the participants are honest, or in the common reference string (CRS) model where all parties are assumed to have access to a common string that is drawn from some pre-defined distribution. Furthermore, carrying out many interesting tasks in a UC manner and without honest majority or set-up assumptions is impossible, even if ideally authenticated communication is provided. A natural question is thus whether there exist more relaxed set-up assumptions than the CRS model that still allow for UC protocols. We answer this question in the affirmative: we propose alternative and relaxed set-up assumptions and show that they suffice for reproducing the general feasibility results for UC protocols in the CRS model. These alternative assumptions have the flavor of a "public-key infrastructure": parties have registered public keys, no single registration authority needs to be fully trusted, and no single piece of information has to be globally trusted and available. In addition, unlike known protocols in the CRS model, the proposed protocols guarantee some basic level of security even if the set-up assumption is violated. Boaz Barak, Ran Canetti, Jesper Buus Nielsen, Rafael Pass |
FOCS | 3 |
| 2003 | Relaxing Chosen-Ciphertext Security
Ran Canetti, Hugo Krawczyk, Jesper Buus Nielsen |
CRYPTO | 3 |
| 2003 | Universally Composable Efficient Multiparty Computation from Threshold Homomorphic Encryption
Ivan Damgård, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2002 | Expanding Pseudorandom Functions; or: From Known-Plaintext Security to Chosen-Plaintext Security
Ivan Damgård, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2002 | Perfect Hiding and Perfect Binding Universally Composable Commitment Schemes with Constant Expansion Factor
Ivan Damgård, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2002 | Separating Random Oracle Proofs from Complexity Theoretic Proofs: The Non-committing Encryption Case
Jesper Buus Nielsen |
CRYPTO | 1 |
| 2002 | A Threshold Pseudorandom Function Construction and Its Applications
Jesper Buus Nielsen |
CRYPTO | 1 |
| 2001 | Multiparty Computation from Threshold Homomorphic Encryption
Ronald Cramer, Ivan Damgård, Jesper Buus Nielsen |
EUROCRYPT | 3 |
| 2000 | Improved Non-committing Encryption Schemes Based on a General Complexity Assumption
Ivan Damgård, Jesper Buus Nielsen |
CRYPTO | 2 |