EDBT 2026 Demo / reviewers in the wild / expert
Alfredo Rial
dblp:09/154
· DBLP profile ↗
21ranked-venue papers
8as first author
3since 2021 · last 2023
0000-0003-1107-4841ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 5 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorTheory of computation · 3 · 2 first-authorSystems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Compact and Divisible E-Cash with Threshold IssuanceabstractDecentralized, offline, and privacy-preserving e-cash could fulfil the need for both scalable and byzantine fault-resistant payment systems. Existing offline anonymous e-cash schemes are unsuitable for distributed environments due to a central bank. We construct a distributed offline anonymous e-cash scheme, in which the role of the bank is performed by a quorum of authorities, and present its two instantiations. Our first scheme is compact, i.e. the cost of the issuance protocol and the size of a wallet are independent of the number of coins issued, but the cost of payment grows linearly with the number of coins spent. Our second scheme is divisible and thus the cost of payments is also independent of the number of coins spent, but the verification of deposits is more costly. We provide formal security proof of both schemes and compare the efficiency of their implementations. Alfredo Rial, Ania M. Piotrowska |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Concise UC Zero-Knowledge Proofs for Oblivious Updatable DatabasesabstractWe propose an ideal functionalityFCDand a construction ΠCDfor oblivious and updatable committed databases.FCDallows a proverPto read, write, and update values in a database and to prove to a verifierVin zero-knowledge (ZK) that a value is read from or written into a certain position. The following properties must hold: (1) values stored in the database remain hidden fromV; (2) a value read from a certain position is equal to the value previously written into that position; (3) (obliviousness) both the value read or written and its position remain hidden fromV.ΠCDis based on vector commitments. After the initialization phase, the cost of read and write operations is independent of the database size, outperforming other techniques that achieve cost sublinear in the dataset size for prover and/or verifier. Therefore, our construction is especially appealing for large datasets. In existing “commit-and-prove” two-party protocols, the task of maintaining a committed database betweenPandVand reading and writing values into it is not separated from the task of proving statements about the values read or written.FCDallows us to improve modularity in protocol design by separating those tasks. In comparison to simply using a commitment scheme to maintain a committed database,FCDallowsPto hide efficiently the positions read or written fromV. Thanks to this property, we design protocols for e.g. privacy-preserving e-commerce and location-based services whereVgathers aggregate statistics about the statements thatPproves in ZK. Jan Camenisch, Maria Dubovitskaya, Alfredo Rial |
CSF | 3 |
| 2021 | Unlinkable Updatable Hiding Databases and Privacy-Preserving Loyalty Programs
Aditya Damodaran, Alfredo Rial |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | Unlinkable Updatable Databases and Oblivious Transfer with Access Control
Aditya Damodaran, Alfredo Rial |
ACISP | 2 |
| 2020 | Universal Unconditional Verifiability in E-Voting without Trusted PartiesabstractIn e-voting protocols, cryptographers must balance usability with strong security guarantees, such as privacy and verifiability. In traditional e-voting protocols, privacy is often provided by a trusted authority that learns the votes and computes the tally. Some protocols replace the trusted authority by a set of authorities, and privacy is guaranteed if less than a threshold number of authorities are corrupt. For verifiability, stronger security is demanded. Typically, corrupt authorities that try to fake the tally result must always be detected.To provide verifiability, many e-voting protocols use Non-Interactive Zero-Knowledge proofs (NIZK). Thanks to their non-interactive nature, NIZK allow anybody, including third parties that do not participate in the protocol, to verify the correctness of the tally. Therefore, NIZK can be used to obtain universal verifiability. Additionally, NIZK also improve usability because they allow voters to cast a vote non-interactively.The disadvantage of NIZK is that their security is based on setup assumptions such as the common reference string (CRS) or the random oracle model. The former requires a trusted party to generate a CRS. The latter, though a popular model for secure protocol design, has been shown to be unsound.We address the design of e-voting protocols that provide verifiability without any trust assumptions. We show that Non-Interactive Witness-Indistinguishable proofs can be used for this purpose. Our e-voting protocols are private under the Decision Linear assumption, while perfect individual verifiability, i.e. a fake tally is detected with probability 1, holds unconditionally. Perfect universal verifiability requires a trusted public bulletin board. We remark that our definition of verifiability does not consider eligibility or end-to-end verifiability. First, we present a general construction that supports any tally function. Then, we show how to efficiently instantiate it for specific types of elections through Groth-Sahai proofs. Vincenzo Iovino, Alfredo Rial, Peter B. Rønne, Peter Y. A. Ryan |
CSF | 2 |
| 2020 | "The simplest protocol for oblivious transfer" revisited
Ziya Alper Genç, Vincenzo Iovino, Alfredo Rial |
Inf. Process. Lett. | 3 |
| 2019 | A conditional access system with revocation for mobile pay-TV systems revisited
Alfredo Rial |
Inf. Process. Lett. | 1 |
| 2018 | Private Mobile Pay-TV From Priced Oblivious TransferabstractIn pay-TV, a service provider offers TV programs and channels to users. To ensure that only authorized users gain access, conditional access systems (CAS) have been proposed. In existing CAS, users disclose to the service provider the TV programs and channels they purchase. We propose a pay-per-view and a pay-per-channel CAS that protect users' privacy. Our pay-per-view CAS employs priced oblivious transfer (POT) to allow a user to purchase TV programs without disclosing which programs were bought to the service provider. In our pay-per-channel CAS, POT is employed together with broadcast attribute-based encryption to achieve low storage overhead, collusion resistance, efficient revocation, and broadcast efficiency. We propose a new POT scheme and show its feasibility by implementing and testing our CAS on a representative mobile platform. Wouter Biesmans, Josep Balasch, Alfredo Rial, Bart Preneel, Ingrid Verbauwhede |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Issuer-free oblivious transfer with access control revisited
Alfredo Rial |
Inf. Process. Lett. | 1 |
| 2016 | On the Insecurity of a Method for Providing Secure and Private Fine-Grained Access to Outsourced DataabstractThe protection of sensitive data stored in the cloud is paramount. Among the techniques proposed to provide protection, attribute-based access control, which frequently uses ciphertext-policy attribute-based encryption (CPABE), has received a lot of attention in the last years. Recently, Jahan et al.~(IEEE 40th Conference on Local Computer Networks, 2015) propose a scheme based on CPABE where users have reading and writing access to the outsourced data. We analyze the scheme by Jahan et al. and we show that it has several security vulnerabilities. For instance, the cloud server can get information about encrypted messages by using a stored ciphertext and an update of that ciphertext. As another example, users with writing access are able to decrypt all the messages regardless of their attributes. We discuss the security claims made by Jahan et al. and point out the reasons why they do not hold. We also explain that existing schemes can already provide the advantages claimed by Jahan et al. Alfredo Rial |
CloudCom | 1 |
| 2016 | UC Commitments for Modular Protocol Design and Applications to Revocation and Attribute Tokens
Jan Camenisch, Maria Dubovitskaya, Alfredo Rial |
CRYPTO (3) | 3 |
| 2016 | Blind attribute-based encryption and oblivious transfer with fine-grained access control
Alfredo Rial |
Des. Codes Cryptogr. | 1 |
| 2015 | Anonymous Split E-Cash - Toward Mobile Anonymous PaymentsabstractAnonymous E-Cash was first introduced in 1982 as a digital, privacy-preserving alternative to physical cash. A lot of research has since then been devoted to extend and improve its properties, leading to the appearance of multiple schemes. Despite this progress, the practical feasibility of E-Cash systems is still today an open question. Payment tokens are typically portable hardware devices in smart card form, resource constrained due to their size, and therefore not suited to support largely complex protocols such as E-Cash. Migrating to more powerful mobile platforms, for instance, smartphones, seems a natural alternative. However, this implies moving computations from trusted and dedicated execution environments to generic multiapplication platforms, which may result in security vulnerabilities. In this work, we propose a new anonymous E-Cash system to overcome this limitation. Motivated by existing payment schemes based on MTM (Mobile Trusted Module) architectures, we consider at design time a model in which user payment tokens are composed of two modules: an untrusted but powerful execution platform (e.g., smartphone) and a trusted but constrained platform (e.g., secure element). We show how the protocol’s computational complexity can be relaxed by a secure split of computations: nonsensitive operations are delegated to the powerful platform, while sensitive computations are kept in a secure environment. We provide a full construction of our proposed Anonymous Split E-Cash scheme and show that it fully complies with the main properties of an ideal E-Cash system. Finally, we test its performance by implementing it on an Android smartphone equipped with a Java-Card-compatible secure element. Marijn Scheir, Josep Balasch, Alfredo Rial, Bart Preneel, Ingrid Verbauwhede |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2014 | Privacy-Preserving Auditing for Attribute-Based Credentials
Jan Camenisch, Anja Lehmann, Gregory Neven, Alfredo Rial |
ESORICS (2) | 4 |
| 2014 | Practical privacy-preserving location-sharing based services with aggregate statisticsabstractLocation-sharing-based services (LSBSs) allow users to share their location with their friends in a sporadic manner. In currently deployed LSBSs users must disclose their location to the service provider in order to share it with their friends. This default disclosure of location data introduces privacy risks. We define the security properties that a privacy-preserving LSBS should fulfill and propose two constructions. First, a construction based on identity based broadcast encryption (IBBE) in which the service provider does not learn the user's location, but learns which other users are allowed to receive a location update. Second, a construction based on anonymous IBBE in which the service provider does not learn the latter either. As advantages with respect to previous work, in our schemes the LSBS provider does not need to perform any operations to compute the reply to a location data request, but only needs to forward IBBE ciphertexts to the receivers. We implement both constructions and present a performance analysis that shows their practicality. Furthermore, we extend our schemes such that the service provider, performing some verification work, is able to collect privacy-preserving aggregate statistics on the locations users share with each other. Michael Herrmann 0003, Alfredo Rial, Claudia Díaz, Bart Preneel |
WISEC | 2 |
| 2012 | Private Client-Side Profiling with Random Forests and Hidden Markov Models
George Danezis, Markulf Kohlweiss, Benjamin Livshits, Alfredo Rial |
Privacy Enhancing Technologies | 4 |
| 2011 | A Privacy-Preserving Buyer-Seller Watermarking Protocol Based on Priced Oblivious TransferabstractBuyer-seller watermarking protocols allow copyright protection of digital goods. To protect privacy, some of those protocols provide buyers with anonymity. However, anonymous e-commerce protocols pose several disadvantages, like hindering customer management or requiring anonymous payment mechanisms. Additionally, no existing buyer-seller watermarking protocol provides fair exchange. We propose a novel approach for the design of privacy-preserving buyer-seller watermarking protocols. In our approach, the seller authenticates buyers but does not learn which items are purchased. Since buyers are not anonymous, customer management is eased and currently deployed methods of payment can be utilized. We define an ideal functionality for privacy-preserving copyright protection protocols. To realize our functionality, a protocol must ensure that buyers pay the right price without disclosing the purchased item, and that sellers are able to identify buyers that released pirated copies. We construct a protocol based on priced oblivious transfer and on existing techniques for asymmetric watermark embedding. Furthermore, we implement and evaluate the efficiency of our protocol, and we explain how to extend it in order to achieve optimistic fair exchange. Alfredo Rial, Josep Balasch, Bart Preneel |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | PrETP: Privacy-Preserving Electronic Toll Pricing
Josep Balasch, Alfredo Rial, Carmela Troncoso, Bart Preneel, Ingrid Verbauwhede, Christophe Geuens |
USENIX Security Symposium | 2 |
| 2010 | Scalable Anonymous Communication with Provable Security
Prateek Mittal, Nikita Borisov, Carmela Troncoso, Alfredo Rial |
HotSec | 4 |
| 2010 | A Provably Secure Anonymous Buyer-Seller Watermarking ProtocolabstractBuyer-seller watermarking (BSW) protocols allow copyright protection of digital content. The protocol is anonymous when the identity of buyers is not revealed if they do not release pirated copies. Existing BSW protocols are not provided with a formal analysis of their security properties. We employ the ideal-world/real-world paradigm to propose a formal security definition for copyright protection protocols, and we analyze an anonymous BSW protocol and prove that it fulfills our definition. Additionally, we implement the protocol and measure its efficiency. Alfredo Rial, Mina Deng, Tiziano Bianchi, Alessandro Piva, Bart Preneel |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2009 | Universally Composable Adaptive Priced Oblivious Transfer
Alfredo Rial, Markulf Kohlweiss, Bart Preneel |
Pairing | 1 |