VLDB 2026 Research / reviewers in the wild / expert
Alessandra Scafuro
dblp:72/7642
· DBLP profile ↗
26ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0003-1797-9457ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 2 first-author · 7 since 2021Theory of computation · 6Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | sfPri tt FHEsfte: Achieving Full-Privacy in Account-Based Cryptocurrencies is Possible
Varun Madathil, Alessandra Scafuro |
ASIACRYPT (7) | 2 |
| 2025 | How to Recover a Cryptographic Secret From the CloudabstractClouds have replaced most local backup systems as they offer strong availability and reliability guarantees. Clouds, however, are not (and should not be) used as backup for cryptographic secrets. Cryptographic secrets might control financial assets (e.g., crypto wallets), hence, storing such secrets on the cloud corresponds to sharing ownership of the financial assets with the cloud, and makes the cloud a more attractive target for insider attacks. Can we have the best of the two worlds, where a user, Alice, can conveniently store a copy of her cryptographic secrets on the cloud and she is the only one who can recover them? Can she do so even when she loses her devices and forgets all credentials, while at the same time retaining full ownership of her secrets? In this paper, we provide a cloud-based secret-recovery mechanism using trusted execution environments (TEE) where confidentiality is always guaranteed when Alice has not lost her credentials, even in the presence of a malicious cloud fitted with a TEE. If Alice loses all her credentials, she can still recover her secrets (in most circumstances). This is in contrast with all previous work that relies on the assumption that Alice remembers some authentication secret. We prove our system secure in the Universally Composable framework. Further, we implement our protocols and evaluate their performance. David Adei, Chris Orsini, Alessandra Scafuro, Tanner Verber |
CCS | 3 |
| 2024 | Jäger: Automated Telephone Call TracebackabstractUnsolicited telephone calls that facilitate fraud or unlawful telemarketing continue to overwhelm network users and the regulators who prosecute them. The first step in prosecuting phone abuse is traceback --- identifying the call originator. This fundamental investigative task currently requires hours of manual effort per call. In this paper, we introduce Jäger, a distributed secure call traceback system. Jäger can trace a call in a few seconds, even with partial deployment, while cryptographically preserving the privacy of call parties, carrier trade secrets like peers and call volume, and limiting the threat of bulk analysis. We establish definitions and requirements of secure traceback, then develop a suite of protocols that meet these requirements using witness encryption, oblivious pseudorandom functions, and group signatures. We prove these protocols secure in the universal composibility framework. We then demonstrate that Jäger has low compute and bandwidth costs per call, and these costs scale linearly with call volume. Jäger provides an efficient, secure, privacy-preserving system to revolutionize telephone abuse investigation with minimal costs to operators. David Adei, Varun Madathil, Sathvik Prasad, Bradley Reaves, Alessandra Scafuro |
CCS | 5 |
| 2022 | Private Signaling
Varun Madathil, Alessandra Scafuro, István András Seres, Omer Shlomovits, Denis Varlakov |
USENIX Security Symposium | 2 |
| 2021 | One-Time Traceable Ring Signatures
Alessandra Scafuro, Bihan Zhang |
ESORICS (2) | 1 |
| 2021 | On the Anonymity Guarantees of Anonymous Proof-of-Stake ProtocolsabstractIn proof-of-stake (PoS) blockchains, stakeholders that extend the chain are selected according to the amount of stake they own. In S&P 2019 the "Ouroboros Crypsinous" system of Kerber et al. (and concurrently Ganesh et al. in EUROCRYPT 2019) presented a mechanism that hides the identity of the stakeholder when adding blocks, hence preserving anonymity of stakeholders both during payment and mining in the Ouroboros blockchain. They focus on anonymizing the messages of the blockchain protocol, but suggest that potential identity leaks from the network-layer can be removed as well by employing anonymous broadcast channels.In this work we show that this intuition is flawed. Even ideal anonymous broadcast channels do not suffice to protect the identity of the stakeholder who proposes a block.We make the following contributions. First, we show a formal network-attack against Ouroboros Crypsinous, where the adversary can leverage network delays to distinguish who is the stakeholder that added a block on the blockchain. Second, we abstract the above attack and show that whenever the adversary has control over the network delay – within the synchrony bound – loss of anonymity is inherent for any protocol that provides liveness guarantees. We do so, by first proving that it is impossible to devise a (deterministic) state-machine replication protocol that achieves basic liveness guarantees and better than (1−2f) anonymity at the same time (where f is the fraction of corrupted parties). We then connect this result to the PoS setting by presenting the tagging and reverse tagging attack that allows an adversary, across several executions of the PoS protocol, to learn the stake of a target node, by simply delaying messages for the target. We demonstrate that our assumption on the delaying power of the adversary is realistic by describing how our attack could be mounted over the Zcash blockchain network (even when Tor is used). We conclude by suggesting approaches that can mitigate such attacks. Markulf Kohlweiss, Varun Madathil, Kartik Nayak, Alessandra Scafuro |
SP | 4 |
| 2021 | Anonymous device authorization for cellular networksabstractCellular networks connect nearly every human on the planet; they consequently have visibility into location data and voice, SMS, and data contacts and communications. Such near-universal visibility represents a significant threat to the privacy of mobile subscribers. In 5G networks, end-user mobile device manufacturers assign a Permanent Equipment Identifier (PEI) to every new device. Mobile operators legitimately use the PEI to blocklist stolen devices from the network to discourage device theft, but the static PEI also provides a mechanism to uniquely identify and track subscribers. Advertisers and data brokers have also historically abused the PEI for data fusion of location and analytics data, including private data sold by cellular providers. Abida Haque, Varun Madathil, Bradley Reaves, Alessandra Scafuro |
WISEC | 4 |
| 2020 | Anonymous Lottery In The Proof-of-Stake SettingabstractWhen Proof-of-Stake (PoS) underlies a consensus protocol, parties who are eligible to participate in the protocol are selected via a public selection function that depends on the stake they own. Identity and stake of the selected parties must then be disclosed in order to allow verification of their eligibility, and this can raise privacy concerns. In this paper, we present a modular approach for addressing the identity leaks of selection functions, decoupling the problem of implementing an anonymous selection of the participants, from the problem of implementing others task, e.g. consensus. We present an ideal functionality for anonymous selection that can be more easily composed with other protocols. We then show an instantiation of our anonymous selection functionality based on the selection function of Algorand. Foteini Baldimtsi, Varun Madathil, Alessandra Scafuro, Linfeng Zhou |
CSF | 3 |
| 2018 | Population Stability: Regulating Size in the Presence of an Adversary
Shafi Goldwasser, Rafail Ostrovsky, Alessandra Scafuro, Adam Sealfon |
PODC | 3 |
| 2017 | Server-Aided Secure Computation with Off-line Parties
Foteini Baldimtsi, Dimitrios Papadopoulos 0001, Stavros Papadopoulos 0001, Alessandra Scafuro, Nikos Triandopoulos |
ESORICS (1) | 4 |
| 2017 | Sublinear Zero-Knowledge Arguments for RAM Programs
Payman Mohassel, Mike Rosulek, Alessandra Scafuro |
EUROCRYPT (1) | 3 |
| 2017 | TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub
Ethan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro, Sharon Goldberg |
NDSS | 4 |
| 2017 | Adaptively Indistinguishable Garbled Circuits
Zahra Jafargholi, Alessandra Scafuro, Daniel Wichs |
TCC (2) | 2 |
| 2016 | NIZKs with an Untrusted CRS: Security in the Face of Parameter Subversion
Mihir Bellare, Georg Fuchsbauer, Alessandra Scafuro |
ASIACRYPT (2) | 3 |
| 2016 | Adaptively Secure Garbled Circuits from One-Way Functions
Brett Hemenway, Zahra Jafargholi, Rafail Ostrovsky, Alessandra Scafuro, Daniel Wichs |
CRYPTO (3) | 4 |
| 2016 | Online/Offline OR Composition of Sigma Protocols
Michele Ciampi, Giuseppe Persiano, Alessandra Scafuro, Luisa Siniscalchi, Ivan Visconti |
EUROCRYPT (2) | 3 |
| 2015 | Round-Optimal Black-Box Two-Party Computation
Rafail Ostrovsky, Silas Richelson, Alessandra Scafuro |
CRYPTO (2) | 3 |
| 2015 | Garbled RAM From One-Way FunctionsabstractYao's garbled circuit construction is a very fundamental result in cryptography and recent efficiency optimizations have brought it much closer to practice. However these constructions work only for circuits and garbling a RAM program involves the inefficient process of first converting it into a circuit. Towards the goal of avoiding this inefficiency, Lu and Ostrovsky (Eurocrypt 2013) introduced the notion of "garbled RAM" as a method to garble RAM programs directly. It can be seen as a RAM analogue of Yao's garbled circuits such that, the size of the garbled program and the time it takes to create and evaluate it, is proportional only to the running time on the RAM program rather than its circuit size. Known realizations of this primitive, either need to rely on strong computational assumptions or do not achieve the aforementioned efficiency (Gentry, Halevi, Lu, Ostrovsky, Raykova and Wichs, EUROCRYPT 2014). In this paper we provide the first construction with strictly poly-logarithmic overhead in both space and time based only on the minimal assumption that one-way functions exist. Our scheme allows for garbling multiple programs being executed on a persistent database, and has the additional feature that the program garbling is decoupled from the database garbling. This allows a client to provide multiple garbled programs to the server as part of a pre-processing phase and then later determine the order and the inputs on which these programs are to be executed, doing work independent of the running times of the programs itself. Sanjam Garg, Steve Lu 0001, Rafail Ostrovsky, Alessandra Scafuro |
STOC | 4 |
| 2015 | Resettably Sound Zero-Knowledge Arguments from OWFs - The (Semi) Black-Box Way
Rafail Ostrovsky, Alessandra Scafuro, Muthuramakrishnan Venkitasubramaniam |
TCC (1) | 2 |
| 2014 | Practical UC security with a Global Random OracleabstractContrary to prior belief, we show that there exist commitment, zero-knowledge and general function evaluation protocols with universally composable security, in a model where all parties and all protocols have access to a single, global, random oracle and no other trusted setup. This model provides significantly stronger composable security guarantees than the traditional random oracle model of Bellare and Rogaway [CCS'93] or even the common reference string model. Indeed, these latter models provide no security guarantees in the presence of arbitrary protocols that use the {\em same} random oracle (or reference string or hash function). Ran Canetti, Abhishek Jain 0002, Alessandra Scafuro |
CCS | 3 |
| 2014 | Black-box non-black-box zero knowledgeabstractMotivated by theoretical and practical interest, the challenging task of designing cryptographic protocols having only black-box access to primitives has generated various breakthroughs in the last decade. Despite such positive results, even though nowadays we know black-box constructions for secure two-party and multi-party computation even in constant rounds, there still are in Cryptography several constructions that critically require non-black-box use of primitives in order to securely realize some fundamental tasks. As such, the study of the gap between black-box and nonblack-box constructions still includes major open questions. Vipul Goyal, Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti |
STOC | 3 |
| 2013 | Unconditionally Secure and Universally Composable Commitments from Physical Assumptions
Ivan Damgård, Alessandra Scafuro |
ASIACRYPT (2) | 2 |
| 2013 | Universally Composable Secure Computation with (Malicious) Physically Uncloneable Functions
Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti, Akshay Wadia |
EUROCRYPT | 2 |
| 2013 | Revisiting Lower and Upper Bounds for Selective Decommitments
Rafail Ostrovsky, Vanishree Rao, Alessandra Scafuro, Ivan Visconti |
TCC | 3 |
| 2012 | On Round-Optimal Zero Knowledge in the Bare Public-Key Model
Alessandra Scafuro, Ivan Visconti |
EUROCRYPT | 1 |
| 2012 | Simultaneously Resettable Arguments of Knowledge
Chongwon Cho, Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti |
TCC | 3 |