VLDB 2026 Research / reviewers in the wild / expert
Jens Groth
dblp:94/1408
· DBLP profile ↗
54ranked-venue papers
30as first author
3since 2021 · last 2025
0000-0001-6291-7832ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 49 · 28 first-author · 3 since 2021Theory of computation · 8 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Constraint-Friendly Map-to-Elliptic-Curve-Group Relations and Their Applications
Jens Groth, Harjasleen Malvai, Andrew Miller 0001, Yi-Nuo Zhang |
ASIACRYPT (2) | 1 |
| 2024 | Fast Batched Asynchronous Distributed Key Generation
Jens Groth, Victor Shoup |
EUROCRYPT (5) | 1 |
| 2022 | On the Security of ECDSA with Additive Key Derivation and Presignatures
Jens Groth, Victor Shoup |
EUROCRYPT (1) | 1 |
| 2020 | Linear-Time Arguments with Sublinear Verification from Tensor Codes
Jonathan Bootle, Alessandro Chiesa, Jens Groth |
TCC (2) | 3 |
| 2020 | Foundations of Fully Dynamic Group SignaturesabstractAbstract Group signatures allow members of a group to anonymously sign on behalf of the group. Membership is administered by a designated group manager. The group manager can also reveal the identity of a signer if and when needed to enforce accountability and deter abuse. For group signatures to be applicable in practice, they need to support fully dynamic groups, i.e., users may join and leave at any time. Existing security definitions for fully dynamic group signatures are informal, have shortcomings, and are mutually incompatible. We fill the gap by providing a formal rigorous security model for fully dynamic group signatures. Our model is general and is not tailored toward a specific design paradigm and can therefore, as we show, be used to argue about the security of different existing constructions following different design paradigms. Our definitions are stringent and when possible incorporate protection against maliciously chosen keys. We consider both the case where the group management and tracing signatures are administered by the same authority, i.e., a single group manager, and also the case where those roles are administered by two separate authorities, i.e., a group manager and an opening authority. We also show that a specialization of our model captures existing models for static and partially dynamic schemes. In the process, we identify a subtle gap in the security achieved by group signatures using revocation lists. We show that in such schemes new members achieve a slightly weaker notion of traceability. The flexibility of our security model allows to capture such relaxation of traceability. Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Essam Ghadafi, Jens Groth |
J. Cryptol. | 5 |
| 2019 | Efficient Fully Structure-Preserving Signatures and Shrinking Commitments
Masayuki Abe, Jens Groth, Markulf Kohlweiss, Miyako Ohkubo, Mehdi Tibouchi |
J. Cryptol. | 2 |
| 2018 | Arya: Nearly Linear-Time Zero-Knowledge Proofs for Correct Program Execution
Jonathan Bootle, Andrea Cerulli, Jens Groth, Sune K. Jakobsen, Mary Maller |
ASIACRYPT (1) | 3 |
| 2018 | Sub-linear Lattice-Based Zero-Knowledge Arguments for Arithmetic Circuits
Carsten Baum, Jonathan Bootle, Andrea Cerulli, Rafaël Del Pino, Jens Groth, Vadim Lyubashevsky |
CRYPTO (2) | 5 |
| 2018 | Updatable and Universal Common Reference Strings with Applications to zk-SNARKs
Jens Groth, Markulf Kohlweiss, Mary Maller, Sarah Meiklejohn, Ian Miers |
CRYPTO (3) | 1 |
| 2017 | Linear-Time Zero-Knowledge Proofs for Arithmetic Circuit Satisfiability
Jonathan Bootle, Andrea Cerulli, Essam Ghadafi, Jens Groth, Mohammad Hajiabadi, Sune K. Jakobsen |
ASIACRYPT (3) | 4 |
| 2017 | Towards a Classification of Non-interactive Computational Assumptions in Cyclic Groups
Essam Ghadafi, Jens Groth |
ASIACRYPT (2) | 2 |
| 2017 | Snarky Signatures: Minimal Signatures of Knowledge from Simulation-Extractable SNARKs
Jens Groth, Mary Maller |
CRYPTO (2) | 1 |
| 2016 | Foundations of Fully Dynamic Group Signatures
Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Essam Ghadafi, Jens Groth |
ACNS | 5 |
| 2016 | Efficient Zero-Knowledge Arguments for Arithmetic Circuits in the Discrete Log Setting
Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Jens Groth, Christophe Petit 0001 |
EUROCRYPT (2) | 4 |
| 2016 | On the Size of Pairing-Based Non-interactive Arguments
Jens Groth |
EUROCRYPT (2) | 1 |
| 2016 | Structure-Preserving Signatures and Commitments to Group Elements
Masayuki Abe, Georg Fuchsbauer, Jens Groth, Kristiyan Haralambiev, Miyako Ohkubo |
J. Cryptol. | 3 |
| 2015 | Efficient Fully Structure-Preserving Signatures for Large Messages
Jens Groth |
ASIACRYPT (1) | 1 |
| 2015 | Short Accountable Ring Signatures Based on DDHabstractRing signatures and group signatures are prominent cryptographic primitives offering a combination of privacy and authentication. They enable individual users to anonymously sign messages on behalf of a group of users. In ring signatures, the group, i.e. the ring, is chosen in an ad hoc manner by the signer. In group signatures, group membership is controlled by a group manager. Group signatures additionally enforce accountability by providing the group manager with a secret tracing key that can be used to identify the otherwise anonymous signer when needed. Accountable ring signatures, introduced by Xu and Yung (CARDIS 2004), bridge the gap between the two notions. They provide maximal flexibility in choosing the ring, and at the same time maintain accountability by supporting a designated opener that can identify signers when needed. We revisit accountable ring signatures and offer a formal security model for the primitive. Our model offers strong security definitions incorporating protection against maliciously chosen keys and at the same time flexibility both in the choice of the ring and the opener. We give a generic construction using standard tools. We give a highly efficient instantiation of our generic construction in the random oracle model by meticulously combining Camenisch’s group signature scheme (CRYPTO 1997) with a generalization of the one-out-of-many proofs of knowledge by Groth and Kohlweiss (EUROCRYPT 2015). Our instantiation yields signatures of logarithmic size (in the size of the ring) while relying solely on the well-studied decisional Diffie-Hellman assumption. In the process, we offer a number of optimizations for the recent Groth and Kohlweiss one-out-of-many proofs, which may be useful for other applications. Accountable ring signatures imply traditional ring and group signatures. We therefore also obtain highly efficient instantiations of those primitives with signatures shorter than all existing ring signatures as well as existing group signatures relying on standard assumptions. Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Essam Ghadafi, Jens Groth, Christophe Petit 0001 |
ESORICS (1) | 5 |
| 2015 | One-Out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin
Jens Groth, Markulf Kohlweiss |
EUROCRYPT (2) | 1 |
| 2015 | Using Fully Homomorphic Hybrid Encryption to Minimize Non-interative Zero-Knowledge Proofs
Craig Gentry, Jens Groth, Yuval Ishai, Chris Peikert, Amit Sahai, Adam D. Smith 0001 |
J. Cryptol. | 2 |
| 2014 | Square Span Programs with Applications to Succinct NIZK Arguments
George Danezis, Cédric Fournet, Jens Groth, Markulf Kohlweiss |
ASIACRYPT (1) | 3 |
| 2014 | Converting Cryptographic Schemes from Symmetric to Asymmetric Bilinear Groups
Masayuki Abe, Jens Groth, Miyako Ohkubo, Takeya Tango |
CRYPTO (1) | 2 |
| 2014 | Structure-Preserving Signatures from Type II Pairings
Masayuki Abe, Jens Groth, Miyako Ohkubo, Mehdi Tibouchi |
CRYPTO (1) | 2 |
| 2014 | Unified, Minimal and Selectively Randomizable Structure-Preserving Signatures
Masayuki Abe, Jens Groth, Miyako Ohkubo, Mehdi Tibouchi |
TCC | 2 |
| 2014 | Cryptography in the Multi-string Model
Jens Groth, Rafail Ostrovsky |
J. Cryptol. | 1 |
| 2013 | Zero-Knowledge Argument for Polynomial Evaluation with Application to Blacklists
Stephanie Bayer, Jens Groth |
EUROCRYPT | 2 |
| 2012 | Efficient Zero-Knowledge Argument for Correctness of a Shuffle
Stephanie Bayer, Jens Groth |
EUROCRYPT | 2 |
| 2012 | New Techniques for Noninteractive Zero-KnowledgeabstractNoninteractive zero-knowledge (NIZK) proof systems are fundamental primitives used in many cryptographic constructions, including public-key encryption secure against chosen ciphertext attack, digital signatures, and various other cryptographic protocols. We introduce new techniques for constructing NIZK proofs based on groups with a bilinear map. Compared to previous constructions of NIZK proofs, our techniques yield dramatic reduction in the length of the common reference string (proportional to security parameter) and the size of the proofs (proportional to security parameter times the circuit size). Our novel techniques allow us to answer several long-standing open questions in the theory of noninteractive proofs. We construct the first perfect NIZK argument system for all NP. We construct the first universally composable NIZK argument for all NP in the presence of an adaptive adversary. We construct a non-interactive zap for all NP, which is the first that is based on a standard cryptographic security assumption. Jens Groth, Rafail Ostrovsky, Amit Sahai |
J. ACM | 1 |
| 2012 | Efficient Noninteractive Proof Systems for Bilinear Groups
Jens Groth, Amit Sahai |
SIAM J. Comput. | 1 |
| 2011 | Separating Short Structure-Preserving Signatures from Non-interactive Assumptions
Masayuki Abe, Jens Groth, Miyako Ohkubo |
ASIACRYPT | 2 |
| 2011 | Efficient Zero-Knowledge Arguments from Two-Tiered Homomorphic Commitments
Jens Groth |
ASIACRYPT | 1 |
| 2011 | Optimal Structure-Preserving Signatures in Asymmetric Bilinear Groups
Masayuki Abe, Jens Groth, Kristiyan Haralambiev, Miyako Ohkubo |
CRYPTO | 2 |
| 2011 | Optimal Structure-Preserving Signatures
Jens Groth |
ProvSec | 1 |
| 2010 | Short Pairing-Based Non-interactive Zero-Knowledge Arguments
Jens Groth |
ASIACRYPT | 1 |
| 2010 | Short Non-interactive Zero-Knowledge Proofs
Jens Groth |
ASIACRYPT | 1 |
| 2010 | Structure-Preserving Signatures and Commitments to Group Elements
Masayuki Abe, Georg Fuchsbauer, Jens Groth, Kristiyan Haralambiev, Miyako Ohkubo |
CRYPTO | 3 |
| 2010 | Pairing-Based Non-interactive Zero-Knowledge Proofs
Jens Groth |
Pairing | 1 |
| 2010 | A Verifiable Secret Shuffle of Homomorphic Encryptions
Jens Groth |
J. Cryptol. | 1 |
| 2009 | Linear Algebra with Sub-linear Zero-Knowledge Arguments
Jens Groth |
CRYPTO | 1 |
| 2008 | Sub-linear Zero-Knowledge Argument for Correctness of a Shuffle
Jens Groth, Yuval Ishai |
EUROCRYPT | 1 |
| 2008 | Efficient Non-interactive Proof Systems for Bilinear GroupsabstractNon-interactive zero-knowledge proofs and non-interactive witness-indistinguishable proofs have played a significant role in the theory of cryptography. However, lack of efficiency has prevented them from being used in practice. One of the roots of this inefficiency is that non-interactive zero-knowledge proofs have been constructed for general NP-complete languages such as Circuit Satisfiability, causing an expensive blowup in the size of the statement when reducing it to a circuit. The contribution of this paper is a general methodology for constructing very simple and efficient non-interactive zero-knowledge proofs and non-interactive witness-indistinguishable proofs that work directly for groups with a bilinear map, without needing a reduction to Circuit Satisfiability. Groups with bilinear maps have enjoyed tremendous success in the field of cryptography in recent years and have been used to construct a plethora of protocols. This paper provides non-interactive witness-indistinguishable proofs and non-interactive zero-knowledge proofs that can be used in connection with these protocols. Our goal is to spread the use of non-interactive cryptographic proofs from mainly theoretical purposes to the large class of practical cryptographic protocols based on bilinear groups. Jens Groth, Amit Sahai |
EUROCRYPT | 1 |
| 2007 | Fully Anonymous Group Signatures Without Random Oracles
Jens Groth |
ASIACRYPT | 1 |
| 2007 | A Non-interactive Shuffle with Pairing Based Verifiability
Jens Groth, Steve Lu 0001 |
ASIACRYPT | 1 |
| 2007 | Cryptography in the Multi-string Model
Jens Groth, Rafail Ostrovsky |
CRYPTO | 1 |
| 2007 | Ring Signatures of Sub-linear Size Without Random Oracles
Nishanth Chandran, Jens Groth, Amit Sahai |
ICALP | 2 |
| 2006 | Simulation-Sound NIZK Proofs for a Practical Language and Constant Size Group Signatures
Jens Groth |
ASIACRYPT | 1 |
| 2006 | Non-interactive Zaps and New Techniques for NIZK
Jens Groth, Rafail Ostrovsky, Amit Sahai |
CRYPTO | 1 |
| 2006 | Perfect Non-interactive Zero Knowledge for NP
Jens Groth, Rafail Ostrovsky, Amit Sahai |
EUROCRYPT | 1 |
| 2006 | An Adaptively Secure Mix-Net Without Erasures
Douglas Wikström, Jens Groth |
ICALP (2) | 2 |
| 2005 | Non-interactive Zero-Knowledge Arguments for Voting
Jens Groth |
ACNS | 1 |
| 2005 | Cryptography in Subgroups of Zn
Jens Groth |
TCC | 1 |
| 2004 | Evaluating Security of Voting Schemes in the Universal Composability Framework
Jens Groth |
ACNS | 1 |
| 2004 | Rerandomizable and Replayable Adaptive Chosen Ciphertext Attack Secure Cryptosystems
Jens Groth |
TCC | 1 |
| 2003 | Non-interactive and reusable non-malleable commitment schemesabstractWe consider non-malleable (NM) and universally composable (UC) commitment schemes in the common reference string (CRS) model. We show how to construct non-interactive NM commitments that remain non-malleable even if the adversary has access to an arbitrary number of commitments from honest players - rather than one, as in several previous schemes. We show this is a strictly stronger security notion. Our construction is the first non-interactive scheme achieving this that can be based on the minimal assumption of existence of one-way functions. But it can also be instantiated in a very efficient version based on the strong RSA assumption. For UC commitments, we show that existence of a UC commitment scheme in the CRS model (interactive or not) implies key exchange and - for a uniform reference string - even implies oblivious transfer. This indicates that UC commitment is a strictly stronger primitive than NM. Finally, we show that our strong RSA based construction can be used to improve the most efficient known UC commitment scheme so it can work with a CRS of size independent of the number of players, without loss of efficiency. Ivan Damgård, Jens Groth |
STOC | 2 |