VLDB 2026 Research / reviewers in the wild / expert
Constantin Catalin Dragan
dblp:77/7303
· DBLP profile ↗
20ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0002-4033-9880ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 8 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-authorSystems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ringslip: Ring Signatures from the Lattice Isomorphism Problem
Callum London, Daniel Gardham, Constantin Catalin Dragan |
SECRYPT (1) | 3 |
| 2025 | Dynamic Group Signatures with Verifier-Local RevocationabstractGroup Signatures are fundamental cryptographic primitives that allow users to sign a message on behalf of a predefined set of users, curated by the group manager. The security properties ensure that members of the group can sign anonymously and without fear of being framed. In dynamic group signatures, the group manager has finer-grained control over group updates while ensuring membership privacy (i.e., hiding when users join and leave). The only known scheme that achieves standard security properties and membership privacy has been proposed by Backes et al. CCS 2019. However, they rely on an inefficient revocation mechanism that re-issues credentials to all active members during every group update, and users have to rely on a secure and private channel to join the group. In this paper, we introduce a dynamic group signature that supports verifier local revocation, while achieving strong security properties, including membership privacy for users joining over a public channel. Moreover, when our scheme is paired with structure-preserving signatures over equivalence class it enjoys a smaller signature size compared to Backes et al. Finally, as a stand-alone contribution we extend the primitive Asynchronous Remote Key Generation (Frymann et al. CCS 2020) with trapdoors and introduce new security properties to capture this new functionality, which is fundamental to the design of our revocation mechanism. Callum London, Daniel Gardham, Constantin Catalin Dragan |
CSF | 3 |
| 2024 | Towards End-to-End Verifiable Online Voting: Adding Verifiability to Established Voting SystemsabstractOnline voting for independent elections is generally supported by trusted election providers. Typically these providers do not offer any way in which a voter can verify their vote, and hence the providers are trusted with ballot privacy and in ensuring correctness. Despite the desire to offer online voting for political elections, this lack of transparency and verifiability is often seen as a significant barrier to the large-scale adoption of online elections. Adding verifiability to an online election increases transparency and integrity, as well as allowing voters to verify that the vote they cast has been recorded correctly and included in the tally. However, replacing existing online systems with those that provide verifiable voting requires new algorithms and code to be deployed, and this presents a significant business risk to commercial election providers, as well as the societal risk for official elections selecting for public office. In this paper we present the first step in an incremental approach which minimises the business risk but demonstrates the advantages of verifiability, by developing an implementation of key elements of a Selene-based verifiability layer and adding it to an operational online voting system. Selene is a verifiable voting protocol that publishes votes in plaintext alongside a voter's tracker. These trackers enable voters to confirm that their votes have been captured correctly by the system, such that the election provider does not know which tracker has been allocated to which voter. This results in a system where even a “dishonest but cautious” election authority running the system cannot be sure of changing the result in an undetectable way, and hence gives stronger guarantees on the integrity of the election than were previously present. We explore the challenges presented by adding a verifiability layer to an operational system. The system was used in two initial trials conducted within real contested elections. We conclude by outlining the further steps in the road-map towards the deployment of a fully trustworthy online voting system. Mohammed Alsadi 0001, Matthew Casey 0001, Constantin Catalin Dragan, François Dupressoir, Luke Riley, Muntadher Fadhil Sallal, Steve A. Schneider, Helen Treharne, Joe Wadsworth, Phil Wright |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Machine-Checked Proofs of Accountability: How to sElect Who is to Blame
Constantin Catalin Dragan, François Dupressoir, Kristian Gjøsteen, Thomas Haines, Peter B. Rønne, Morten Rotvold Solberg |
ESORICS (3) | 1 |
| 2023 | Machine-checked proofs of privacy against malicious boards for Selene & CoabstractPrivacy is a notoriously difficult property to achieve in complicated systems and especially in electronic voting schemes. Moreover, electronic voting schemes is a class of systems that require very high assurance. The literature contains a number of ballot privacy definitions along with security proofs for common systems. Some machine-checked security proofs have also appeared. We define a new ballot privacy notion that captures a larger class of voting schemes. This notion improves on the state of the art by taking into account that verification in many schemes will happen or must happen after the tally has been published, not before as in previous definitions. As a case study we give a machine-checked proof of privacy for Selene, which is a remote electronic voting scheme which offers an attractive mix of security properties and usability. Prior to our work, the computational privacy of Selene has never been formally verified. Finally, we also prove that MiniVoting and Belenios satisfies our definition. Constantin Catalin Dragan, François Dupressoir, Ehsan Estaji, Kristian Gjøsteen, Thomas Haines, Peter Y. A. Ryan, Peter B. Rønne, Morten Rotvold Solberg |
J. Comput. Secur. | 1 |
| 2022 | Machine-Checked Proofs of Privacy Against Malicious Boards for Selene & CoabstractPrivacy is a notoriously difficult property to achieve in complicated systems and especially in electronic voting schemes. Moreover, electronic voting schemes is a class of systems that require very high assurance. The literature contains a number of ballot privacy definitions along with security proofs for common systems. Some machine-checked security proofs have also appeared. We define a new ballot privacy notion that captures a larger class of voting schemes. This notion improves on the state of the art by taking into account that verification in many schemes will happen or must happen after the tally has been published, not before as in previous definitions. As a case study we give a machine-checked proof of privacy for Selene, which is a remote electronic voting scheme which offers an attractive mix of security properties and usability. Prior to our work, the computational privacy of Selene has never been formally verified. Finally, we also prove that MiniVoting and Belenios satisfies our definition. Constantin Catalin Dragan, François Dupressoir, Ehsan Estaji, Kristian Gjøsteen, Thomas Haines, Peter Y. A. Ryan, Peter B. Rønne, Morten Rotvold Solberg |
CSF | 1 |
| 2022 | TAPESTRY: A De-Centralized Service for Trusted Interaction OnlineabstractWe present a novel de-centralised service for proving the provenance of online digital identity, exposed as an assistive tool to help non-expert users make better decisions about whom to trust online. Our service harnesses the digital personhood (DP); the longitudinal and multi-modal signals created through users’ lifelong digital interactions, as a basis for evidencing the provenance of identity. We describe how users may exchange trust evidence derived from their DP, in a granular and privacy-preserving manner, with other users in order to demonstrate coherence and longevity in their behaviour online. This is enabled through a novel secure infrastructure combining hybrid on- and off-chain storage combined with deep learning for DP analytics and visualization. We show how our tools enable users to make more effective decisions on whether to trust unknown third parties online, and also to spot behavioural deviations in their own social media footprints indicative of account hijacking. Daniel Cooper, John P. Collomosse, Constantin Catalin Dragan, Mark Manulis, Jamie Steane, Arthi Kanchana Manohar, Jo Briggs, Helen S. Jones, Wendy Moncur |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Mechanised Models and Proofs for Distance-BoundingabstractIn relay attacks, a man-in-the-middle adversary impersonates a legitimate party and makes it this party appear to be of an authenticator, when in fact they are not. In order to counteract relay attacks, distance-bounding protocols provide a means for a verifier (e.g., an payment terminal) to estimate his relative distance to a prover (e.g., a bankcard). We propose FlexiDB, a new cryptographic model for distance bounding, parameterised by different types of fine-grained corruptions. FlexiDB allows to consider classical cases but also new, generalised corruption settings. In these settings, we exhibit new attack strategies on existing protocols. Finally, we propose a proof-of-concept mechanisation of FlexiDB in the interactive cryptographic prover EasyCrypt. We use this to exhibit a flavour of man-in-the-middle security on a variant of MasterCard's contactless-payment protocol. Ioana Boureanu, Constantin Catalin Dragan, François Dupressoir, David Gérault, Pascal Lafourcade 0001 |
CSF | 2 |
| 2021 | Asymptotically ideal Chinese remainder theorem -based secret sharing schemes for multilevel and compartmented access structuresabstractAbstract Multilevel and compartmented access structures are two important classes of access structures where participants are grouped into levels/compartments with different degrees of trust and privileges. The construction of secret sharing schemes for such access structures has been the attention of researchers for a long time. Two main approaches have been taken so far, one of them is based on polynomial interpolation and the other one is based on the Chinese Remainder Theorem (CRT). In this article the first asymptotically ideal CRT‐based secret sharing schemes for (disjunctive, conjunctive) multilevel and compartmented access structures are proposed. Our approach is compositional and it is based on a variant of the Asmuth‐Bloom secret sharing scheme where some participants may have public shares. Based on this, the proposed secret sharing schemes for multilevel and compartmented access structures are asymptotically ideal if and only if they are based on 1‐compact sequences of co‐primes. Possible applications for secret image and multi‐secret sharing are pointed‐out. Ferucio Laurentiu Tiplea, Constantin Catalin Dragan |
IET Inf. Secur. | 2 |
| 2020 | Biometric-Authenticated Searchable Encryption
Daniel Gardham, Mark Manulis, Constantin Catalin Dragan |
ACNS (2) | 3 |
| 2020 | Augmenting an Internet Voting System with Selene Verifiability using Permissioned Distributed LedgerabstractThis paper discusses an approach for incremental change to an online voting system, introducing a verifiability layer based on the Selene protocol to a trusted-third-party-based system, resulting in a fully verifiable and transparent e-voting system. The paper also describes how to use Distributed Ledger Technology as a component of the implementation of Selene to manage the verifiability data in a distributed way for resilience and trust. Muntadher Fadhil Sallal, Steve A. Schneider, Matthew Casey 0001, François Dupressoir, Helen Treharne, Constantin Catalin Dragan, Luke Riley, Phil Wright |
ICDCS | 6 |
| 2019 | Private Votes on Untrusted Platforms: Models, Attacks and Provable SchemeabstractModern e-voting systems deploy cryptographic protocols on a complex infrastructure involving different computing platforms and agents. It is crucial to have appropriate specification and evaluation methods to perform rigorous analysis of such systems, taking into account the corruption and computational capabilities of a potential attacker. In particular, the platform used for voting may be corrupted, e.g. infected by malware, and we need to ensure privacy and integrity of votes even in that case. We propose a new definition of vote privacy, formalized as a computational indistinguishability game, that allows to take into account such refined attacker models; we show that the definition captures both known and novel attacks against several voting schemes; and we propose a scheme that is provably secure in this setting. We moreover formalize and machine-check the proof in the EasyCrypt theorem prover. Sergiu Bursuc, Constantin Catalin Dragan, Steve Kremer |
EuroS&P | 2 |
| 2018 | Hierarchical Attribute-Based Signatures
Constantin Catalin Dragan, Daniel Gardham, Mark Manulis |
CANS | 1 |
| 2018 | Machine-Checked Proofs for Electronic Voting: Privacy and Verifiability for BeleniosabstractWe present a machine-checked security analysis of Belenios - a deployed voting protocol used already in more than 200 elections. Belenios extends Helios with an explicit registration authority to obtain eligibility guarantees. We offer two main results. First, we build upon a recent framework for proving ballot privacy in EasyCrypt. Inspired by our application to Belenios, we adapt and extend the privacy security notions to account for protocols that include a registration phase. Our analysis identifies a trust assumption which is missing in the existing (pen and paper) analysis of Belenios: ballot privacy does not hold if the registrar misbehaves, even if the role of the registrar is seemingly to provide eligibility guarantees. Second, we develop a novel framework for proving strong verifiability in EasyCrypt and apply it to Belenios. In the process, we clarify several aspects of the pen-and-paper proof, such as how to deal with revote policies. Together, our results yield the first machine-checked analysis of both ballot privacy and verifiability properties for a deployed electronic voting protocol. Perhaps more importantly, we identify several issues regarding the applicability of existing definitions of privacy and verifiability to systems other than Helios. While we show how to adapt the definitions to the particular case of Belenios, our findings indicate the need for more general security notions for electronic voting protocols with registration authorities. Véronique Cortier, Constantin Catalin Dragan, François Dupressoir, Bogdan Warinschi |
CSF | 2 |
| 2018 | On the asymptotic idealness of the Asmuth-Bloom threshold secret sharing scheme
Constantin Catalin Dragan, Ferucio Laurentiu Tiplea |
Inf. Sci. | 1 |
| 2017 | Machine-Checked Proofs of Privacy for Electronic Voting ProtocolsabstractWe provide the first machine-checked proof of privacy-related properties (including ballot privacy) for an electronic voting protocol in the computational model. We target the popular Helios family of voting protocols, for which we identify appropriate levels of abstractions to allow the simplification and convenient reuse of proof steps across many variations of the voting scheme. The resulting framework enables machine-checked security proofs for several hundred variants of Helios and should serve as a stepping stone for the analysis of further variations of the scheme. In addition, we highlight some of the lessons learned regarding the gap between pen-and-paper and machine-checked proofs, and report on the experience with formalizing the security of protocols at this scale. Véronique Cortier, Constantin Catalin Dragan, François Dupressoir, Pierre-Yves Strub, Bogdan Warinschi |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | Distributive weighted threshold secret sharing schemes
Constantin Catalin Dragan, Ferucio Laurentiu Tiplea |
Inf. Sci. | 1 |
| 2014 | A necessary and sufficient condition for the asymptotic idealness of the GRS threshold secret sharing scheme
Ferucio Laurentiu Tiplea, Constantin Catalin Dragan |
Inf. Process. Lett. | 2 |
| 2013 | Compact sequences of co-primes and their applications to the security of CRT-based threshold schemes
Mihai Barzu, Ferucio Laurentiu Tiplea, Constantin Catalin Dragan |
Inf. Sci. | 3 |
| 2009 | Interactive Secret Share Management
Constantin Catalin Dragan |
SECRYPT | 1 |