VLDB 2026 Research / reviewers in the wild / expert
Daniele Venturi 0001
dblp:98/7881
· DBLP profile ↗
67ranked-venue papers
0as first author
29since 2021 · last 2026
0000-0003-2379-8564ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 47 · 22 since 2021Theory of computation · 20 · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Practical Committee Sizes in YOSO MPC
Pawel Kedzior, Marcin Mielniczuk, Daniele Venturi 0001 |
CRYPTO (8) | 3 |
| 2026 | Robust Non-interactive Zero-Knowledge Combiners
Michele Ciampi, Lorenzo Magliocco, Daniele Venturi 0001, Yu Xia 0008 |
EUROCRYPT (7) | 3 |
| 2026 | The Coding Limits of Robust Watermarking for Generative ModelsabstractWe study a basic question about cryptographic watermarking for generative models: how reliable can a watermark remain when an adversary is allowed to corrupt the encoded signal? To address this question, we introduce a minimal coding abstraction that we call a zero-bit tamper-detection code. This is a secret-key procedure that samples a pseudorandom codeword and, given a candidate word, decides whether it should be treated as unmarked content or as the result of tampering with a valid codeword. It captures the two core requirements of robust watermarking: soundness and tamper detection. Within this abstraction we prove a sharp unconditional limit on robustness to independent symbol corruption. For an alphabet of size $q$, there is a critical corruption rate of $1-1/q$ such that no scheme with soundness, even relaxed to allow a fixed constant false positive probability on random content, can reliably detect tampering once an adversary can change more than this fraction of symbols. In particular, in the binary case no cryptographic watermark can remain robust if more than half of the encoded bits are modified. We also show that this threshold is tight by giving simple information-theoretic constructions that achieve soundness and tamper detection for all strictly smaller corruption rates. We then test experimentally whether this limit appears in practice by looking at the recent watermarking for images of Gunn, Zhao, and Song (ICLR 2025). We show that a simple crop and resize operation reliably flipped about half of the latent signs and consistently prevented belief-propagation decoding from recovering the codeword, erasing the watermark while leaving the image visually intact. Danilo Francati, Yevin Nikhel Goonatilake, Shubham Vivek Pawar, Daniele Venturi 0001, Giuseppe Ateniese |
EuroS&P | 4 |
| 2026 | WiSNA: Edge-Assisted Nonce-Safe Lightweight Authenticated Encryption for Lossy IEEE 802.15.4 IoT Networks
Mario Raso, Daniele Venturi 0001 |
IWCMC | 2 |
| 2025 | Registered Matchmaking Encryption
Danilo Francati, Valeria Huang, Daniele Venturi 0001 |
ACNS (1) | 3 |
| 2025 | Taming Adaptive Security and New Access Structures in Evolving Secret Sharing
Danilo Francati, Sara Giammusso, Daniele Venturi 0001 |
ASIACRYPT (8) | 3 |
| 2025 | Malleable SNARKs and Their Applications
Suvradip Chakraborty, Dennis Hofheinz, Roman Langrehr, Jesper Buus Nielsen, Christoph Striecks, Daniele Venturi 0001 |
EUROCRYPT (4) | 6 |
| 2025 | Evolving secret sharing revisited: computational security and succinctnessabstractAbstract Evolving secret sharing (Komargodski, Naor, and Yogev, TCC’16) generalizes the notion of secret sharing to the setting of evolving access structures, in which the share holders are added to the system in an online manner, and where the dealer does not know neither the access structure nor the maximum psnber of parties in advance. Here, the main difficulty is to distribute shares to the new players without updating the shares of old players; moreover, one would like to minimize the share size as a function of the psnber of players. In this paper, we initiate a systematic study of evolving secret sharing in the computational setting, where the maximum psnber of parties is polynomial in the security parameter, but the dealer still does not know this value, neither it knows the access structure in advance. Moreover, the privacy guarantee only holds against computationally bounded adversaries corrupting an unauthorized subset of the players. Our main result is that for many interesting, and practically relevant, evolving access structures, under standard hardness assumptions, there exist efficient secret sharing schemes with computational privacy and in which the shares are succinct (i.e., much smaller compared to the size of a natural computational representation of the evolving access structure). These access structures include evolving graphs access structures, threshold access structures, and monotone circuits/DNF/CNF access structures meeting an additional rigidity property that we show to be necessary if one wants to avoid updating the shares of old parties. Danilo Francati, Daniele Venturi 0001 |
Des. Codes Cryptogr. | 2 |
| 2025 | Compact Proofs of Partial Knowledge for Overlapping CNF Formulae
Gennaro Avitabile, Vincenzo Botta, Daniele Friolo, Daniele Venturi 0001, Ivan Visconti |
J. Cryptol. | 4 |
| 2024 | Non-malleable Fuzzy Extractors
Danilo Francati, Daniele Venturi 0001 |
ACNS (1) | 2 |
| 2024 | Key Exchange in the Post-snowden Era: Universally Composable Subversion-Resilient PAKE
Suvradip Chakraborty, Lorenzo Magliocco, Bernardo Magri, Daniele Venturi 0001 |
ASIACRYPT (5) | 4 |
| 2024 | Evolving Secret Sharing Made Short
Danilo Francati, Daniele Venturi 0001 |
ASIACRYPT (7) | 2 |
| 2024 | Improved Reductions from Noisy to Bounded and Probing Leakages via Hockey-Stick Divergences
Maciej Obremski, João Ribeiro 0002, Lawrence Roy, François-Xavier Standaert, Daniele Venturi 0001 |
CRYPTO (6) | 5 |
| 2024 | Watermarks in the Sand: Impossibility of Strong Watermarking for Language ModelsabstractWatermarking generative models consists of planting a statistical signal (watermark) in a model’s output so that it can be later verified that the output was generated by the given model. A strong watermarking scheme satisfies the property that a computationally bounded attacker cannot erase the watermark without causing significant quality degradation. In this paper, we study the (im)possibility of strong watermarking schemes. We prove that, under well-specified and natural assumptions, strong watermarking is impossible to achieve. This holds even in the private detection algorithm setting, where the watermark insertion and detection algorithms share a secret key, unknown to the attacker. To prove this result, we introduce a generic efficient watermark attack; the attacker is not required to know the private key of the scheme or even which scheme is used. Our attack is based on two assumptions: (1) The attacker has access to a "quality oracle" that can evaluate whether a candidate output is a high-quality response to a prompt, and (2) The attacker has access to a "perturbation oracle" which can modify an output with a nontrivial probability of maintaining quality, and which induces an efficiently mixing random walk on high-quality outputs. We argue that both assumptions can be satisfied in practice by an attacker with weaker computational capabilities than the watermarked model itself, to which the attacker has only black-box access. Furthermore, our assumptions will likely only be easier to satisfy over time as models grow in capabilities and modalities. We demonstrate the feasibility of our attack by instantiating it to attack three existing watermarking schemes for large language models: Kirchenbauer et al. (2023), Kuditipudi et al. (2023), and Zhao et al. (2023), and include preliminary results on vision-language models. The same attack successfully removes the watermarks planted by all schemes, with only minor quality degradation. Hanlin Zhang 0002, Benjamin L. Edelman, Danilo Francati, Daniele Venturi 0001, Giuseppe Ateniese, Boaz Barak |
ICML | 4 |
| 2024 | Multi-key and Multi-input Predicate Encryption (for Conjunctions) from Learning with ErrorsabstractAbstract We put forward two natural generalizations of predicate encryption (PE), dubbed multi-key and multi-input PE. More in details, our contributions are threefold. Definitions. We formalize security of multi-key PE and multi-input PE following the standard indistinguishability paradigm, and modeling security both against malicious senders (i.e., corruption of encryption keys) and malicious receivers (i.e., collusions). Constructions. We construct adaptively secure multi-key and multi-input PE supporting the conjunction of poly-many arbitrary single-input predicates, assuming the sub-exponential hardness of the learning with errors (LWE) problem. Applications. We show that multi-key and multi-input PE for expressive enough predicates suffices for interesting cryptographic applications, including non-interactive multi-party computation (NI-MPC) and matchmaking encryption (ME). In particular, plugging in our constructions of multi-key and multi-input PE, under the sub-exponential LWE assumption, we obtain the first ME supporting arbitrary policies with unbounded collusions, as well as robust (resp. non-robust) NI-MPC for so-called all-or-nothing functions satisfying a non-trivial notion of reusability and supporting a constant (resp. polynomial) number of parties. Prior to our work, both of these applications required much heavier tools such as indistinguishability obfuscation or compact functional encryption. Danilo Francati, Daniele Friolo, Giulio Malavolta, Daniele Venturi 0001 |
J. Cryptol. | 4 |
| 2023 | On the Complete Non-malleability of the Fujisaki-Okamoto Transform
Daniele Friolo, Matteo Salvino, Daniele Venturi 0001 |
ACNS | 3 |
| 2023 | Registered (Inner-Product) Functional Encryption
Danilo Francati, Daniele Friolo, Monosij Maitra, Giulio Malavolta, Ahmadreza Rahimi, Daniele Venturi 0001 |
ASIACRYPT (5) | 6 |
| 2023 | MARTSIA: Enabling Data Confidentiality for Blockchain-Based Process Execution
Edoardo Marangone, Claudio Di Ciccio, Daniele Friolo, Eugenio Nerio Nemmi, Daniele Venturi 0001, Ingo Weber |
EDOC | 5 |
| 2023 | Multi-key and Multi-input Predicate Encryption from Learning with Errors
Danilo Francati, Daniele Friolo, Giulio Malavolta, Daniele Venturi 0001 |
EUROCRYPT (3) | 4 |
| 2022 | Continuously Non-malleable Codes Against Bounded-Depth Tampering
Gianluca Brian, Sebastian Faust, Elena Micheli, Daniele Venturi 0001 |
ASIACRYPT (4) | 4 |
| 2022 | Universally Composable Subversion-Resilient Cryptography
Suvradip Chakraborty, Bernardo Magri, Jesper Buus Nielsen, Daniele Venturi 0001 |
EUROCRYPT (1) | 4 |
| 2022 | Cryptographic and Financial FairnessabstractA recent trend in multi-party computation is to achieve cryptographic fairness via monetary penalties, i.e. each honest player either obtains the output or receives a compensation in the form of a cryptocurrency. We pioneer another type of fairness, financial fairness, that is closer to the real-world valuation of financial transactions. Intuitively, a penalty protocol is financially fair if the net present cost of participation (the total value of cash inflows less cash outflows, weighted by the relative discount rate) is the same for all honest participants, even when some parties cheat. We formally define the notion, show several impossibility results based on game theory, and analyze the practical effects of (lack of) financial fairness if one was to run the protocols for real on Bitcoin using Bloomberg’s dark pool trading. For example, we show that the ladder protocol (CRYPTO’14), and its variants (CCS’15 and CCS’16), fail to achieve financial fairness both in theory and in practice, while the penalty protocols of Kumaresan and Bentov (CCS’14) and Baum, David and Dowsley (FC’20) are financially fair. Daniele Friolo, Fabio Massacci, Chan Nam Ngo, Daniele Venturi 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for FreeabstractWe show that the most common flavors of noisy leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to a small statistical simulation error and a slight loss in the leakage parameter. The latter holds true in particular for one of the most used noisy-leakage models, where the noisiness is measured using the conditional average min-entropy (Naor and Segev, CRYPTO’09 and SICOMP’12). Our reductions between noisy and bounded leakage are achieved in two steps. First, we put forward a new leakage model (dubbed the dense leakage model) and prove that dense leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to small statistical distance. Second, we show that the most common noisy-leakage models fall within the class of dense leakage, with good parameters. Third, we prove lower bounds on the amount of bounded leakage required for simulation with sub-constant error, showing that our reductions are nearly optimal. In particular, our results imply that useful general simulation of noisy leakage based on statistical distance and mutual information is impossible. We also provide a complete picture of the relationships between different noisy-leakage models. Our result finds applications to leakage-resilient cryptography, where we are often able to lift security in the presence of bounded leakage to security in the presence of noisy leakage, both in the information-theoretic and in the computational setting. Remarkably, this lifting procedure makes only black-box use of the underlying schemes. Additionally, we show how to use lower bounds in communication complexity to prove that bounded-collusion protocols (Kumar, Meka, and Sahai, FOCS’19) for certain functions do not only require long transcripts, but also necessarily need to reveal enough information about the inputs. Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001 |
IEEE Trans. Inf. Theory | 7 |
| 2021 | The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for Free
Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001 |
EUROCRYPT (2) | 7 |
| 2021 | Continuously Non-malleable Secret Sharing: Joint Tampering, Plain Model and Capacity
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001 |
TCC (2) | 3 |
| 2021 | Match Me if You Can: Matchmaking Encryption and Its Applications
Giuseppe Ateniese, Danilo Francati, David Nuñez 0001, Daniele Venturi 0001 |
J. Cryptol. | 4 |
| 2021 | Immunization against complete subversion without random oracles
Giuseppe Ateniese, Danilo Francati, Bernardo Magri, Daniele Venturi 0001 |
Theor. Comput. Sci. | 4 |
| 2021 | Cryptographic reverse firewalls for interactive proof systemsabstractWe study interactive proof systems (IPSes) in a strong adversarial setting where the machines of honest parties might be corrupted and under control of the adversary. Our aim is to answer the following, seemingly paradoxical, questions: • Can Peggy convince Vic of the veracity of an NP statement, without leaking any information about the witness even in case Vic is malicious and Peggy does not trust her computer? • Can we avoid that Peggy fools Vic into accepting false statements, even if Peggy is malicious and Vic does not trust her computer? At EUROCRYPT 2015, Mironov and Stephens-Davidowitz introduced cryptographic reverse firewalls (RFs) as an attractive approach to tackling such questions. Intuitively, a RF for Peggy/Vic is an external party that sits between Peggy/Vic and the outside world and whose scope is to sanitize Peggy's/Vic's incoming and outgoing messages in the face of subversion of her/his computer, e.g. in order to destroy subliminal channels . In this paper, we put forward several natural security properties for RFs in the concrete setting of IPSes. As our main contribution, we construct efficient RFs for different IPSes derived from a large class of Sigma protocols that we call malleable . A nice feature of our design is that it is completely transparent, in the sense that our RFs can be directly applied to already deployed IPSes, without the need to re-implement them. Chaya Ganesh, Bernardo Magri, Daniele Venturi 0001 |
Theor. Comput. Sci. | 3 |
| 2021 | A compiler for multi-key homomorphic signatures for Turing machines
Somayeh Dolatnezhad Samarin, Dario Fiore 0001, Daniele Venturi 0001, Morteza Amini |
Theor. Comput. Sci. | 3 |
| 2020 | Non-malleable Secret Sharing Against Bounded Joint-Tampering Attacks in the Plain Model
Gianluca Brian, Antonio Faonio, Maciej Obremski, Mark Simkin 0001, Daniele Venturi 0001 |
CRYPTO (3) | 5 |
| 2020 | Cryptographic Reverse Firewalls for Interactive Proof SystemsabstractWe study interactive proof systems (IPSes) in a strong adversarial setting where the machines of honest parties might be corrupted and under control of the adversary. Our aim is to answer the following, seemingly paradoxical, questions: Can Peggy convince Vic of the veracity of an NP statement, without leaking any information about the witness even in case Vic is malicious and Peggy does not trust her computer? Can we avoid that Peggy fools Vic into accepting false statements, even if Peggy is malicious and Vic does not trust her computer? At EUROCRYPT 2015, Mironov and Stephens-Davidowitz introduced cryptographic reverse firewalls (RFs) as an attractive approach to tackling such questions. Intuitively, a RF for Peggy/Vic is an external party that sits between Peggy/Vic and the outside world and whose scope is to sanitize Peggy's/Vic's incoming and outgoing messages in the face of subversion of her/his computer, e.g. in order to destroy subliminal channels. In this paper, we put forward several natural security properties for RFs in the concrete setting of IPSes. As our main contribution, we construct efficient RFs for different IPSes derived from a large class of Sigma protocols that we call malleable. A nice feature of our design is that it is completely transparent, in the sense that our RFs can be directly applied to already deployed IPSes, without the need to re-implement them. Chaya Ganesh, Bernardo Magri, Daniele Venturi 0001 |
ICALP | 3 |
| 2020 | Non-malleable Encryption: Simpler, Shorter, StrongerabstractOne approach toward basing public-key encryption (PKE) schemes on weak and credible assumptions is to build “stronger” or more general schemes generically from “weaker” or more restricted ones. One particular line of work in this context was initiated by Myers and Shelat (FOCS ’09) and continued by Hohenberger, Lewko, and Waters (Eurocrypt ’12), who provide constructions of multi-bit CCA-secure PKE from single-bit CCA-secure PKE. It is well known that encrypting each bit of a plaintext string independently is not CCA-secure—the resulting scheme is malleable. We therefore investigate whether this malleability can be dealt with using the conceptually simple approach of applying a suitable non-malleable code (Dziembowski et al., ICS ’10) to the plaintext and subsequently encrypting the resulting codeword bit by bit. We find that an attacker’s ability to ask multiple decryption queries requires that the underlying code be continuously non-malleable (Faust et al., TCC ’14). Since, as we show, this flavor of non-malleability can only be achieved if the code is allowed to “self-destruct,” the resulting scheme inherits this property and therefore only achieves a weaker variant of CCA security. We formalize this new notion of so-called indistinguishability under self-destruct attacks (IND-SDA) as CCA security with the restriction that the decryption oracle stops working once the attacker submits an invalid ciphertext. We first show that the above approach based on non-malleable codes yields a solution to the problem of domain extension for IND-SDA-secure PKE, provided that the underlying code is continuously non-malleable against (a reduced form of) bit-wise tampering. Then, we prove that the code of Dziembowski et al. is actually already continuously non-malleable against bit-wise tampering. We further investigate the notion of security under self-destruct attacks and combine IND-SDA security with non-malleability under chosen-ciphertext attacks (NM-CPA) to obtain the strictly stronger notion of non-malleability under self-destruct attacks (NM-SDA). We show that NM-SDA security can be obtained from basic IND-CPA security by means of a black-box construction based on the seminal work by Choi et al. (TCC ’08). Finally, we provide a domain extension technique for building a multi-bit NM-SDA scheme from a single-bit NM-SDA scheme. To achieve this goal, we define and construct a novel type of continuous non-malleable code, called secret-state NMC, since, as we show, standard continuous NMCs are insufficient for the natural “encode-then-encrypt-bit-by-bit” approach to work. Sandro Coretti, Yevgeniy Dodis, Ueli Maurer, Björn Tackmann, Daniele Venturi 0001 |
J. Cryptol. | 5 |
| 2020 | Continuously Non-malleable Codes in the Split-State ModelabstractAbstract Non-malleable codes (Dziembowski et al., ICS’10 and J. ACM’18) are a natural relaxation of error correcting/detecting codes with useful applications in cryptography. Informally, a code is non-malleable if an adversary trying to tamper with an encoding of a message can only leave it unchanged or modify it to the encoding of an unrelated value. This paper introduces continuous non-malleability, a generalization of standard non-malleability where the adversary is allowed to tamper continuously with the same encoding. This is in contrast to the standard definition of non-malleable codes, where the adversary can only tamper a single time. The only restriction is that after the first invalid codeword is ever generated, a special self-destruct mechanism is triggered and no further tampering is allowed; this restriction can easily be shown to be necessary. We focus on the split-state model, where an encoding consists of two parts and the tampering functions can be arbitrary as long as they act independently on each part. Our main contributions are outlined below. We show that continuous non-malleability in the split-state model is impossible without relying on computational assumptions. We construct a computationally secure split-state code satisfying continuous non-malleability in the common reference string (CRS) model. Our scheme can be instantiated assuming the existence of collision-resistant hash functions and (doubly enhanced) trapdoor permutations, but we also give concrete instantiations based on standard number-theoretic assumptions. We revisit the application of non-malleable codes to protecting arbitrary cryptographic primitives against related-key attacks. Previous applications of non-malleable codes in this setting required perfect erasures and the adversary to be restricted in memory. We show that continuously non-malleable codes allow to avoid these restrictions. Sebastian Faust, Pratyay Mukherjee, Jesper Buus Nielsen, Daniele Venturi 0001 |
J. Cryptol. | 4 |
| 2020 | Subversion-resilient signatures: Definitions, constructions and applications
Giuseppe Ateniese, Bernardo Magri, Daniele Venturi 0001 |
Theor. Comput. Sci. | 3 |
| 2019 | Public Immunization Against Complete Subversion Without Random Oracles
Giuseppe Ateniese, Danilo Francati, Bernardo Magri, Daniele Venturi 0001 |
ACNS | 4 |
| 2019 | Rate-Optimizing Compilers for Continuously Non-malleable Codes
Sandro Coretti, Antonio Faonio, Daniele Venturi 0001 |
ACNS | 3 |
| 2019 | Match Me if You Can: Matchmaking Encryption and Its Applications
Giuseppe Ateniese, Danilo Francati, David Nuñez 0001, Daniele Venturi 0001 |
CRYPTO (2) | 4 |
| 2019 | Non-malleable Secret Sharing in the Computational Setting: Adaptive Tampering, Noisy-Leakage Resilience, and Improved Rate
Antonio Faonio, Daniele Venturi 0001 |
CRYPTO (2) | 2 |
| 2019 | Continuously Non-malleable Secret Sharing for General Access Structures
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001 |
TCC (2) | 3 |
| 2019 | A Black-Box Construction of Fully-Simulatable, Round-Optimal Oblivious Transfer from Strongly Uniform Key Agreement
Daniele Friolo, Daniel Masny, Daniele Venturi 0001 |
TCC (1) | 3 |
| 2019 | Continuously non-malleable codes with split-state refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
Theor. Comput. Sci. | 4 |
| 2018 | Continuously Non-malleable Codes with Split-State Refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
ACNS | 4 |
| 2018 | Continuously Non-Malleable Codes in the Split-State Model from Minimal Assumptions
Rafail Ostrovsky, Giuseppe Persiano, Daniele Venturi 0001, Ivan Visconti |
CRYPTO (3) | 3 |
| 2018 | Secure Outsourcing of Cryptographic Circuits Manufacturing
Giuseppe Ateniese, Aggelos Kiayias, Bernardo Magri, Yiannis Tselekounis, Daniele Venturi 0001 |
ProvSec | 5 |
| 2018 | FuturesMEX: Secure, Distributed Futures Market ExchangeabstractIn a Futures-Exchange, such as the Chicago Mercantile Exchange, traders buy and sell contractual promises (futures) to acquire or deliver, at some future pre-specified date, assets ranging from wheat to crude oil and from bacon to cash in a desired currency. The interactions between economic and security properties and the exchange's essentially non-monotonic security behavior; a valid trader's valid action can invalidate other traders' previously valid positions, are a challenge for security research. We show the security properties that guarantee an Exchange's economic viability (availability of trading information, liquidity, confidentiality of positions, absence of price discrimination, risk-management) and an attack when traders' anonymity is broken. We describe all key operations for a secure, fully distributed Futures-Exchange, hereafter referred to as simply the 'Exchange'. Our distributed, asynchronous protocol simulates the centralized functionality under the assumptions of anonymity of the physical layer and availability of a distributed ledger. We consider security with abort (in absence of honest majority) and extend it to penalties. Our proof of concept implementation and its optimization (based on zk-SNARKs and SPDZ) demonstrate that the computation of actual trading days (along Thomson-Reuters Tick History DB) is feasible for low-frequency markets; however, more research is needed for high-frequency ones. Fabio Massacci, Chan Nam Ngo, Daniele Venturi 0001, Julian Williams |
IEEE Symposium on Security and Privacy | 4 |
| 2018 | Fiat-Shamir for highly sound protocols is instantiable
Arno Mittelbach, Daniele Venturi 0001 |
Theor. Comput. Sci. | 2 |
| 2017 | Non-Malleable Codes for Space-Bounded Tampering
Sebastian Faust, Kristina Hostáková, Pratyay Mukherjee, Daniele Venturi 0001 |
CRYPTO (2) | 4 |
| 2017 | Redactable Blockchain - or - Rewriting History in Bitcoin and FriendsabstractWe put forward a new framework that makes it possible to re-write or compress the content of any number of blocks in decentralized services exploiting the blockchain technology. As we argue, there are several reasons to prefer an editable blockchain, spanning from the necessity to remove inappropriate content and the possibility to support applications requiring re-writable storage, to "the right to be forgotten." Our approach generically leverages so-called chameleon hash functions (Krawczyk and Rabin, NDSS '00), which allow determining hash collisions efficiently, given a secret trapdoor information. We detail how to integrate a chameleon hash function in virtually any blockchain-based technology, for both cases where the power of redacting the blockchain content is in the hands of a single trusted entity and where such a capability is distributed among several distrustful parties (as is the case with Bitcoin). We also report on a proof-of-concept implementation of a redactable blockchain, building on top of Nakamoto's Bitcoin core. The prototype only requires minimal changes to the way current client software interprets the information stored in the blockchain and to the current blockchain, block, or transaction structures. Moreover, our experiments show that the overhead imposed by a redactable blockchain is small compared to the case of an immutable one. Giuseppe Ateniese, Bernardo Magri, Daniele Venturi 0001, Ewerton R. Andrade |
EuroS&P | 3 |
| 2017 | Bounded Tamper Resilience: How to Go Beyond the Algebraic Barrier
Ivan Damgård, Sebastian Faust, Pratyay Mukherjee, Daniele Venturi 0001 |
J. Cryptol. | 4 |
| 2017 | Efficient Authentication from Hard Learning Problems
Eike Kiltz, Krzysztof Pietrzak, Daniele Venturi 0001, David Cash, Abhishek Jain 0002 |
J. Cryptol. | 3 |
| 2017 | Naor-Yung paradigm with shared randomness and applications
Silvio Biagioni, Daniel Masny, Daniele Venturi 0001 |
Theor. Comput. Sci. | 3 |
| 2017 | Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model
Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
Theor. Comput. Sci. | 3 |
| 2016 | Efficient Public-Key Cryptography with Bounded Leakage and Tamper Resilience
Antonio Faonio, Daniele Venturi 0001 |
ASIACRYPT (1) | 2 |
| 2016 | Entangled cloud storage
Giuseppe Ateniese, Özgür Dagdelen, Ivan Damgård, Daniele Venturi 0001 |
Future Gener. Comput. Syst. | 4 |
| 2016 | Rate-limited secure function evaluation
Özgür Dagdelen, Payman Mohassel, Daniele Venturi 0001 |
Theor. Comput. Sci. | 3 |
| 2016 | Efficient Non-Malleable Codes and Key Derivation for Poly-Size Tampering CircuitsabstractNon-malleable codes, defined by Dziembowski, Pietrzak, and Wichs (ICS '10), provide roughly the following guarantee: if a codeword c encoding some message x is tampered to c'= f (c) such that c' ≠ c, then the tampered message x' contained in c' reveals no information about x. The nonmalleable codes have applications to immunizing cryptosystems against tampering attacks and related-key attacks. One cannot have an efficient non-malleable code that protects against all efficient tampering functions f . However, in this paper we show “the next best thing”: for any polynomial bound s given a-priori, there is an efficient non-malleable code that protects against all tampering functions f computable by a circuit of size s. More generally, for any family of tampering functions F of size |F| ≤ 2s, there is an efficient non-malleable code that protects against all f ∈ F. The rate of our codes, defined as the ratio of message to codeword size, approaches 1. Our results are information-theoretic and our main proof technique relies on a careful probabilistic method argument using limited independence. As a result, we get an efficiently samplable family of efficient codes, such that a random member of the family is non-malleable with overwhelming probability. Alternatively, we can view the result as providing an efficient non-malleable code in the “common reference string” model. We also introduce a new notion of non-malleable key derivation, which uses randomness x to derive a secret key y = h(x) in such a way that, even if x is tampered to a different value x'= f (x), the derived key y' = h(x') does not reveal any information about y. Our results for non-malleable key derivation are analogous to those for non-malleable codes. As a useful tool in our analysis, we rely on the notion of “leakage-resilient storage” of Davi, Dziembowski, and Venturi (SCN '10), and, as a result of independent interest, we also significantly improve on the parameters of such schemes. Sebastian Faust, Pratyay Mukherjee, Daniele Venturi 0001, Daniel Wichs |
IEEE Trans. Inf. Theory | 3 |
| 2015 | Subversion-Resilient Signature SchemesabstractWe provide a formal treatment of security of digital signatures against subversion attacks (SAs). Our model of subversion generalizes previous work in several directions, and is inspired by the proliferation of software attacks (e.g., malware and buffer overflow attacks), and by the recent revelations of Edward Snowden about intelligence agencies trying to surreptitiously sabotage cryptographic algorithms. The main security requirement we put forward demands that a signature scheme should remain unforgeable even in the presence of an attacker applying SAs (within a certain class of allowed attacks) in a fully-adaptive and continuous fashion. Previous notions---e.g., security against algorithm-substitution attacks introduced by Bellare et al. (CRYPTO '14) for symmetric encryption---were non-adaptive and non-continuous. Giuseppe Ateniese, Bernardo Magri, Daniele Venturi 0001 |
CCS | 3 |
| 2015 | Mind Your Coins: Fully Leakage-Resilient Signatures with Graceful DegradationabstractWe construct a new leakage-resilient signature scheme. Our scheme remains unforgeable in the noisy leakage model, where the only restriction on the leakage is that it does not decrease the min-entropy of the secret key by too much. The leakage information can depend on the entire state of the signer; this property is sometimes known as fully leakage resilience. An additional feature of our construction, is that it offers a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen et al. (PKC 2014) in the bounded leakage model, to deal with settings in which the secret key is much larger than the size of a signature. For security parameter $$\kappa $$ , our scheme tolerates leakage on the entire state of the signer until $$\omega (\log \kappa )$$ bits of min-entropy are left in the secret key, and is proven secure in the standard model. While we describe our scheme in terms of generic building blocks, we also explain how to instantiate it efficiently under fairly standard number-theoretic assumptions. Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
ICALP (1) | 3 |
| 2015 | From Single-Bit to Multi-bit Public-Key Encryption via Non-malleable Codes
Sandro Coretti, Ueli Maurer, Björn Tackmann, Daniele Venturi 0001 |
TCC (1) | 4 |
| 2014 | Efficient Non-malleable Codes and Key-Derivation for Poly-size Tampering Circuits
Sebastian Faust, Pratyay Mukherjee, Daniele Venturi 0001, Daniel Wichs |
EUROCRYPT | 3 |
| 2014 | Continuous Non-malleable Codes
Sebastian Faust, Pratyay Mukherjee, Jesper Buus Nielsen, Daniele Venturi 0001 |
TCC | 4 |
| 2013 | Bounded Tamper Resilience: How to Go beyond the Algebraic Barrier
Ivan Damgård, Sebastian Faust, Pratyay Mukherjee, Daniele Venturi 0001 |
ASIACRYPT (2) | 4 |
| 2013 | Outsourced Pattern Matching
Sebastian Faust, Carmit Hazay, Daniele Venturi 0001 |
ICALP (2) | 3 |
| 2013 | Anonymity-Preserving Public-Key Encryption: A Constructive Approach
Markulf Kohlweiss, Ueli Maurer, Cristina Onete, Björn Tackmann, Daniele Venturi 0001 |
Privacy Enhancing Technologies | 5 |
| 2011 | Efficient Authentication from Hard Learning Problems
Eike Kiltz, Krzysztof Pietrzak, David Cash, Abhishek Jain 0002, Daniele Venturi 0001 |
EUROCRYPT | 5 |
| 2011 | Tamper-Proof Circuits: How to Trade Leakage for Tamper-Resilience
Sebastian Faust, Krzysztof Pietrzak, Daniele Venturi 0001 |
ICALP (1) | 3 |
| 2009 | Inadequacy of the Queue-Based Max-Weight Optimal Scheduler on Wireless Links with TCP SourcesabstractThe interaction between wireless optimized scheduling algorithms and TCP congestion control mechanisms can have adverse effects on the performance of the system. We focus on the queue based max-weight (QBMW) scheduler, a scheduling strategy which is known to be throughput-optimal under unregulated traffic sources. We use fluid modeling to describe the time evolution of the congestion window size and of the wireless buffer, and show by numerical results that under TCP traffic sources the QBMW scheduling policy leads to a very unfair outcome, in which some users may be completely shut off. We also evaluate and discuss the performance achieved by other scheduling policies: the proportional fair (PF) scheduler, and the queue age (QA) scheduler, which takes account of the age of the packets stored in the wireless buffers. Alfredo Todini, Andrea Baiocchi, Daniele Venturi 0001 |
ICC | 3 |