VLDB 2026 Research / reviewers in the wild / expert
Foteini Baldimtsi
dblp:46/7643
· DBLP profile ↗
35ranked-venue papers
17as first author
18since 2021 · last 2026
0000-0003-3296-5336ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 17 first-author · 17 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Batched & Non-interactive Blind Signatures from Lattices
Foteini Baldimtsi, Rishab Goyal, Aayush Yadav |
PKC (1) | 1 |
| 2025 | An Analytical Performance Evaluation on Sui Move Object-Centric Models
Nahid Ebrahimi Majd, Andres Hinojosa, Calvary Fisher, Fernando Landeros, Foteini Baldimtsi |
ICBC | 5 |
| 2025 | A Study on The Performances of Sui Move Object-Centric ModelsabstractThe Sui Move has emerged as a next-generation smart contract language solution, emphasizing scalability, low latency, security, and robustness. Sui Move is built around a unique and innovative object-centric model, which introduces a new paradigm of flexibility in asset management. The Sui Move object-centric data storage model is particularly advantageous for managing complex assets, offering a more efficient and secure way to interact with other on-chain objects. Due to its high-performance and scalable architecture, Sui has emerged as one of the fastest growing Layer 1 blockchains in industry, particularly in the DeFi and gaming sectors. In this paper, we present the first analytical study on the performances of Sui object-centric models. We will describe the Sui gas pricing mechanism. We will discuss the rich Sui Move object-centric models, including wrapped objects, dynamic fields, dynamic object fields, and dynamic collections. We will comprehensively study the fees, object hierarchies, and object accessibilities in these models in both small scale and large scale. We will also provide sample smart contract code to implement these models. This is the first paper that provides a comprehensive analysis on Sui Move object-centric models and recommendations for Sui developers to develop efficient and cost-aware smart contracts. Our results indicated that developers could save significant fees by selecting an appropriate model for their smart contracts. Nahid Ebrahimi Majd, Andres Hinojosa, Calvary Fisher, Fernando Landeros, Foteini Baldimtsi |
SERA | 5 |
| 2024 | SoK: Zero-Knowledge Range ProofsabstractZero-knowledge range proofs (ZKRPs) allow a prover to convince a verifier that a secret value lies in a given interval. ZKRPs have numerous applications: from anonymous credentials and auctions, to confidential transactions in cryptocurrencies. At the same time, a plethora of ZKRP constructions exist in the literature, each with its own trade-offs. In this work, we systematize the knowledge around ZKRPs. We create a classification of existing constructions based on the underlying building techniques, and we summarize their properties. We provide comparisons between schemes both in terms of properties as well as efficiency levels, and construct a guideline to assist in the selection of an appropriate ZKRP for different application requirements. Finally, we discuss a number of interesting open research problems. Miranda Christ, Foteini Baldimtsi, Kostas Kryptos Chalkias, Sai Krishna Deepak Maram, Arnab Roy 0001, Joy Wang |
AFT | 2 |
| 2024 | Non-Interactive Blind Signatures: Post-Quantum and Stronger Security
Foteini Baldimtsi, Jiaqi Cheng 0001, Rishab Goyal, Aayush Yadav |
ASIACRYPT (2) | 1 |
| 2024 | zkLogin: Privacy-Preserving Blockchain Authentication with Existing Credentialsabstractstatus: Published Foteini Baldimtsi, Kostas Kryptos Chalkias, Yan Ji 0001, Jonas Lindstrøm, Sai Krishna Deepak Maram, Ben Riva, Arnab Roy 0001, Mahdi Sedaghat, Joy Wang |
CCS | 1 |
| 2024 | Blind Multisignatures for Anonymous Tokens with Decentralized IssuanceabstractWe propose the first constructions of anonymous tokens with decentralized issuance. Namely, we consider a dynamic set of signers/issuers; a user can obtain a token from any subset of the signers, which is publicly verifiable and unlinkable to the issuance process. To realize this new primitive we formalize the notion of blind multi-signatures (BMS), which allow a user to interact with multiple signers to obtain a (compact) signature; even if all the signers collude they are unable to link a signature to an interaction with any of them. We then present two BMS constructions, one based on BLS signatures and a second based on discrete logarithms without pairings. We prove security of both our constructions in the Algebraic Group Model. We also provide a proof-of-concept implementation and show that it has low-cost verification, which is the most critical operation in blockchain applications. Ioanna Karantaidou, Omar Renawi, Foteini Baldimtsi, Nikolaos Kamarinakis, Jonathan Katz, Julian Loss |
CCS | 3 |
| 2024 | Advancing Scalability in Decentralized Storage: A Novel Approach to Proof-of-Replication via Polynomial Evaluation
Giuseppe Ateniese, Foteini Baldimtsi, Matteo Campanelli, Danilo Francati, Ioanna Karantaidou |
CRYPTO (2) | 2 |
| 2024 | Atomic Swaps for Boneh-Lynn-Shacham (BLS) Based Blockchains
Huseyin Gokay, Foteini Baldimtsi, Giuseppe Ateniese |
ESORICS (3) | 2 |
| 2024 | Truncator: Time-Space Tradeoff of Cryptographic Primitives
Foteini Baldimtsi, Kostas Kryptos Chalkias, Panagiotis Chatzigiannis, Mahimna Kelkar |
FC (2) | 1 |
| 2024 | Subset-Optimized BLS Multi-signature with Key Aggregation
Foteini Baldimtsi, Kostas Kryptos Chalkias, François Garillot, Jonas Lindstrøm, Ben Riva, Arnab Roy 0001, Mahdi Sedaghat, Alberto Sonnino, Pun Waiwitlikhit, Joy Wang |
FC (2) | 1 |
| 2022 | Batching, Aggregation, and Zero-Knowledge Proofs in Bilinear AccumulatorsabstractAn accumulator is a cryptographic primitive that allows a prover to succinctly commit to a set of values while being able to provide proofs of (non-)membership. A batch proof is an accumulator proof that can be used to prove (non-)membership of multiple values simultaneously. Shravan Srinivasan, Ioanna Karantaidou, Foteini Baldimtsi, Charalampos Papamanthou |
CCS | 3 |
| 2022 | gOTzilla: Efficient Disjunctive Zero-Knowledge Proofs from MPC in the Head, with Application to Proofs of Assets in CryptocurrenciesabstractWe present gOTzilla, a protocol for interactive zero-knowledge proofs for very large disjunctive statements of the following format: given publicly known circuit C, and set of values Y = {y1 , . . . , yn }, prove knowledge of a witness x such that C(x) = y1 ∨ C(x) = y2 ∨ · · · ∨ C(x) = yn . These type of statements are extremely important for the proof of assets (PoA) problem in cryptocurrencies where a prover wants to prove the knowledge of a secret key sk that associates with the hash of a public key H(pk) posted on the ledger. We note that the size of n in popular cryptocurrencies, such as Bitcoin, is estimated to 80 million. For the construction of gOTzilla, we start by observing that if we restructure the proof statement to an equivalent of proving knowledge of (x, y) such that (C(x) = y) ∧ (y = y1 ∨ · · · ∨ y = yn )), then we can reduce the disjunction of equalities to 1-out-of-N oblivious transfer (OT). Our overall protocol is based on the MPC in the head (MPCitH) paradigm. We additionally provide a concrete, efficient extension of our protocol for the case where C combines algebraic and non-algebraic statements (which is the case in the PoA application). We achieve an asymptotic communication cost of O(log n) plus the proof size of the underlying MPCitH protocol. While related work has similar asymptotic complexity, our approach results in concrete performance improvements. We implement our protocol and provide benchmarks. Concretely, for a set of size 1 million entries, the total run-time of our protocol is 14.89 seconds using 48 threads, with 6.18 MB total communication, which is about 4x faster compared to the state of the art when considering a disjunctive statement with algebraic and non-algebraic elements. Foteini Baldimtsi, Panagiotis Chatzigiannis, S. Dov Gordon, Phi Hung Le, Daniel McVicker |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | (∈, δ)-Indistinguishable Mixing for Cryptocurrencies
Mingyu Liang, Ioanna Karantaidou, Foteini Baldimtsi, S. Dov Gordon, Mayank Varia |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | SoK: Auditability and Accountability in Distributed Payment Systems
Panagiotis Chatzigiannis, Foteini Baldimtsi, Kostas Kryptos Chalkias |
ACNS (2) | 2 |
| 2021 | Efficient Constructions of Pairing Based AccumulatorsabstractCryptographic accumulators are a crucial building block for a variety of applications where you need to represent a set of elements in a compact format while still being able to provide proofs of (non)membership. In this work, we give a number of accumulator constructions for the bilinear pairing setting in the trapdoor-based scenario, where a trusted manager maintains the accumulator. Using modular accumulator techniques, we first present the first optimally efficient (in terms of communication cost) dynamic, positive accumulators in the pairing setting. Additionally, we present a novel modular approach to construct universal accumulators that avoid costly non-membership proofs. We instantiate our generic construction and present the first universal accumulator in the bilinear pairing setting, that achieves constant parameter size, constant cost for element additions/deletions and witness generation by the manager, constant witness updates by the users and constant (non)membership verification. We finally show how our proposed universal accumulator construction can give rise to efficient ZK accumulators with constant non-membership witness updates. Ioanna Karantaidou, Foteini Baldimtsi |
CSF | 2 |
| 2021 | MiniLedger: Compact-Sized Anonymous and Auditable Distributed Payments
Panagiotis Chatzigiannis, Foteini Baldimtsi |
ESORICS (1) | 2 |
| 2021 | Watermarking public-key cryptographic functionalities and implementations: The case of encryption and signaturesabstractAbstract A watermarking scheme for a public‐key cryptographic functionality enables the embedding of a mark in the instance of the secret‐key algorithm such that the functionality of the original scheme is maintained, while it is infeasible for an adversary to remove the mark (unremovability) or mark a fresh object without the marking key (unforgeability). A number of works have appeared in the literature proposing different definitional frameworks and schemes secure under a wide range of assumptions. In the previous work [1, 2], the authors proposed a meaningful relaxation of the watermarking model and gave constructions that allow direct watermarking of popular cryptographic schemes (e.g. ElGamal Encryption). A definitional framework for watermarking public‐key cryptographic functionalities and implementations which covers both deterministic (e.g. decryption) and probabilistic (e.g. signing) secret‐key algorithms is provided. The authors’ work unifies the previous results of [1, 2] where deterministic and probabilistic circuits to be watermarked as separate cases are considered. The constructions of [1, 2] were previously presented as extended abstracts missing rigorous security proofs. The authors prove those constructions secure under their new, unified framework. In the authors’ schemes secret detection of the watermark is provided, and security under minimal hardness assumptions assuming only the existence of one‐way functions, is proved. Foteini Baldimtsi, Aggelos Kiayias, Katerina Samari |
IET Inf. Secur. | 1 |
| 2020 | Crowd Verifiable Zero-Knowledge and End-to-End Verifiable Multiparty Computation
Foteini Baldimtsi, Aggelos Kiayias, Thomas Zacharias 0001, Bingsheng Zhang |
ASIACRYPT (3) | 1 |
| 2020 | Anonymous Lottery In The Proof-of-Stake SettingabstractWhen Proof-of-Stake (PoS) underlies a consensus protocol, parties who are eligible to participate in the protocol are selected via a public selection function that depends on the stake they own. Identity and stake of the selected parties must then be disclosed in order to allow verification of their eligibility, and this can raise privacy concerns. In this paper, we present a modular approach for addressing the identity leaks of selection functions, decoupling the problem of implementing an anonymous selection of the participants, from the problem of implementing others task, e.g. consensus. We present an ideal functionality for anonymous selection that can be more easily composed with other protocols. We then show an instantiation of our anonymous selection functionality based on the selection function of Algorand. Foteini Baldimtsi, Varun Madathil, Alessandra Scafuro, Linfeng Zhou |
CSF | 1 |
| 2020 | Universally Composable Accumulators
Foteini Baldimtsi, Ran Canetti, Sophia Yakoubov |
CT-RSA | 1 |
| 2020 | Guest Editorial Special Issue on Blockchain and Economic Knowledge AutomationabstractBlockchain, as an emerging decentralized architecture and distributed computing paradigm underlying Bitcoin and other cryptocurrencies, has attracted intensive attention in both research and applications recently. Blockchain, especially powered by chain-coded smart contracts, has the full potential of revolutionizing increasingly centralized cyber-physical-social systems (CPSSs) for constructions and applications, and reshaping traditional knowledge automation workflows. The key advantage of blockchain technology lies in the fact that it can enable the establishment of secured, trusted, and decentralized autonomous ecosystems for various scenarios, especially for better usage of the legacy devices, infrastructure, and resources. Yong Yuan 0003, Shou-Yang Wang, David L. Olson, James H. Lambert, Fei-Yue Wang 0001, Chunming Rong, Angelos Stavrou, Jun Jason Zhang, Qiang Tang 0005, Foteini Baldimtsi, Laurence T. Yang, Desheng Dash Wu |
IEEE Trans. Syst. Man Cybern. Syst. | 10 |
| 2019 | Efficient Noninteractive Certification of RSA Moduli and Beyond
Sharon Goldberg, Leonid Reyzin, Omar Sagga, Foteini Baldimtsi |
ASIACRYPT (3) | 4 |
| 2019 | Leakage-resilient lattice-based partially blind signaturesabstractBlind signature schemes (BSS) play a pivotal role in privacy‐oriented cryptography. However, with BSS, the signed message remains unintelligible to the signer, giving them no guarantee that the blinded message he signed actually contained valid information. Partially BSS (PBSS) were introduced to address precisely this problem. In this study, the authors present the first leakage‐resilient, lattice‐based PBSS in the literature. The proposed construction is provably secure in the random oracle model and offers quasi‐linear complexity w.r.t. key/signature sizes and signing speed. In addition, it offers statistical partial blindness and its unforgeability is based on the computational hardness of worst‐case ideal lattice problems for approximation factors in in dimension n . The proposed scheme benefits from the subexponential hardness of ideal lattice problems and remains secure even if a fraction of the signer's secret key leaks to an adversary via arbitrary side‐channels. Several extensions of the security model, such as honest‐user unforgeability and selective failure blindness, are also considered and concrete parameters for instantiation are proposed. Dimitrios Papachristoudis, Dimitrios Hristu-Varsakelis, Foteini Baldimtsi, George Stephanides |
IET Inf. Secur. | 3 |
| 2017 | Server-Aided Secure Computation with Off-line Parties
Foteini Baldimtsi, Dimitrios Papadopoulos 0001, Stavros Papadopoulos 0001, Alessandra Scafuro, Nikos Triandopoulos |
ESORICS (1) | 1 |
| 2017 | Accumulators with Applications to Anonymity-Preserving RevocationabstractMembership revocation is essential for cryptographic applications, from traditional PKIs to group signatures and anonymous credentials. Of the various solutions for the revocation problem that have been explored, dynamic accumulators are one of the most promising. We propose Braavos, a new, RSA-based, dynamic accumulator. It has optimal communication complexity and, when combined with efficient zero-knowledge proofs, provides an ideal solution for anonymous revocation. For the construction of Braavos we use a modular approach: we show how to build an accumulator with better functionality and security from accumulators with fewer features and weaker security guarantees. We then describe an anonymous revocation component (ARC) that can be instantiated using any dynamic accumulator. ARC can be added to any anonymous system, such as anonymous credentials or group signatures, in order to equip it with a revocation functionality. Finally, we implement ARC with Braavos and plug it into Idemix, the leading implementation of anonymous credentials. This work resolves, for the first time, the problem of practical revocation for anonymous credential systems. Foteini Baldimtsi, Jan Camenisch, Maria Dubovitskaya, Anna Lysyanskaya, Leonid Reyzin, Kai Samelin, Sophia Yakoubov |
EuroS&P | 1 |
| 2017 | Watermarking Public-Key Cryptographic Functionalities and Implementations
Foteini Baldimtsi, Aggelos Kiayias, Katerina Samari |
ISC | 1 |
| 2017 | TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub
Ethan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro, Sharon Goldberg |
NDSS | 3 |
| 2016 | Indistinguishable Proofs of Work or Knowledge
Foteini Baldimtsi, Aggelos Kiayias, Thomas Zacharias 0001, Bingsheng Zhang |
ASIACRYPT (2) | 1 |
| 2015 | Recovering Lost Device-Bound Credentials
Foteini Baldimtsi, Jan Camenisch, Lucjan Hanzlik, Stephan Krenn, Anja Lehmann, Gregory Neven |
ACNS | 1 |
| 2015 | Cryptographic Theory Meets Practice: Efficient and Privacy-Preserving Payments for Public TransportabstractWe propose a new lightweight cryptographic payment scheme for transit systems, called P4R (Privacy-Preserving Pre-Payments with Refunds), which is suitable for low-cost user devices with limited capabilities. Using P4R, users deposit money to obtain one-show credentials, where each credential allows the user to make an arbitrary ride on the system. The trip fare is determined on-the-fly at the end of the trip. If the deposit for the credential exceeds this fare, the user obtains a refund. Refund values collected over several trips are aggregated in a single token, thereby saving memory and increasing privacy. Our solution builds on Brands’s e-cash scheme to realize the prepayment system and on Boneh-Lynn-Shacham (BLS) signatures to implement the refund capabilities. Compared to a Brands-only solution for transportation payment systems, P4R allows us to minimize the number of coins a user needs to pay for his rides and thus minimizes the number of expensive withdrawal transactions, as well as storage requirements for the fairly large coins. Moreover, P4R enables flexible pricing because it allows for exact payments of arbitrary amounts (within a certain range) using a single fast paying (and refund) transaction. Fortunately, the mechanisms enabling these features require very little computational overhead. Choosing contemporary security parameters, we implemented P4R on a prototyping payment device and show its suitability for future transit payment systems. Estimation results demonstrate that the data required for 20 rides consume less than 10KB of memory, and the payment and refund transactions during a ride take less than half a second. We show that malicious users are not able to cheat the system by receiving a refund that exceeds the overall deposit minus the overall fare and can be identified during double-spending checks. At the same time, the system protects the privacy of honest users in that transactions are anonymous (except for deposits) and trips are unlinkable. Andy Rupp, Foteini Baldimtsi, Gesine Hinterwälder, Christof Paar |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2013 | On the Security of One-Witness Blind Signature Schemes
Foteini Baldimtsi, Anna Lysyanskaya |
ASIACRYPT (2) | 1 |
| 2013 | Anonymous credentials lightabstractWe define and propose an efficient and provably secure construction of blind signatures with attributes. Prior notions of blind signatures did not yield themselves to the construction of anonymous credential systems, not even if we drop the unlinkability requirement of anonymous credentials. Our new notion in contrast is a convenient building block for anonymous credential systems. The construction we propose is efficient: it requires just a few exponentiations in a prime-order group in which the decisional Diffie-Hellman problem is hard. Thus, for the first time, we give a provably secure construction of anonymous credentials that can work in the elliptic group setting without bilinear pairings and is based on the DDH assumption. In contrast, prior provably secure constructions were based on the RSA group or on groups with pairings, which made them prohibitively inefficient for mobile devices, RFIDs and smartcards. The only prior efficient construction that could work in such elliptic curve groups, due to Brands, does not have a proof of security. Foteini Baldimtsi, Anna Lysyanskaya |
CCS | 1 |
| 2013 | Efficient E-Cash in Practice: NFC-Based Payments for Public Transportation Systems
Gesine Hinterwälder, Christian T. Zenger, Foteini Baldimtsi, Anna Lysyanskaya, Christof Paar, Wayne P. Burleson |
Privacy Enhancing Technologies | 3 |
| 2008 | An Implementation Infrastructure for Server-Passive Timed-Release CryptographyabstractAs online transactions become increasingly practical, a broad range of industrial and e-government applications have emerged which depend on time-based protection of confidential data. Despite theoretical progress in timed-release cryptography (TRC), there is still no implementation infrastructure that takes advantage of the latest TRC algorithms. The purpose of this paper is to propose such an infrastructure for pairing-based timed-release cryptography (PB-TRC) systems. Our model uses key generation centers (KGCs) which publish decryption keys periodically, and satisfies the security requirements of modern third party-based TRC schemes. Our approach combines the best features of existing models into a generic and complete infrastructure which is to support TRC. It is also "lighter" in terms of complexity and communication, and is as effective (in terms of security and related properties) as the TRC protocol it is used with. Kostas Kryptos Chalkias, Foteini Baldimtsi, Dimitrios Hristu-Varsakelis, George Stephanides |
IAS | 2 |