EDBT 2026 Demo / reviewers in the wild / expert
Bernardo Machado David
dblp:15/10106 · also Bernardo David
· DBLP profile ↗
35ranked-venue papers
12as first author
19since 2021 · last 2025
0000-0002-1872-7799ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 11 first-author · 18 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Rumors MPC: GOD for Dynamic Committees, Low Communication via Constant-Round Chat
Bernardo Machado David, Arup Mondal, Rahul Satish |
ASIACRYPT (5) | 1 |
| 2025 | Universally Composable Interactive and Ordered Multi-signatures
Carsten Baum, Bernardo Machado David, Elena Pagnin, Akira Takahashi 0002 |
PKC (2) | 2 |
| 2025 | pod: An Optimal-Latency, Censorship-Free, and Accountable Generalized Consensus LayerabstractThis work addresses the inherent issues of high latency in blockchains and low scalability in traditional consensus protocols. We present pod, a novel notion of consensus whose first priority is to achieve the physically-optimal latency of 2δ, or one round-trip, i.e., requiring only one network trip (duration δ) for writing a transaction and one for reading it. To accomplish this, we first eliminate inter-replica communication. Instead, clients send transactions directly to all replicas, which independently process transactions and append them to local logs. Replicas assign a timestamp and a sequence number to each transaction in their logs, allowing clients to extract valuable metadata about the transactions and the system state. Later on, clients retrieve these logs and extract transactions (and associated metadata) from them. Necessarily, this construction achieves weaker properties than a total-order broadcast protocol, due to existing lower bounds. Our work models the primitive of pod and defines its security properties. We then show pod-core, a protocol that satisfies properties such as transaction confirmation within 2δ, censorship resistance against Byzantine replicas, and accountability for safety violations. We show that single-shot auctions can be realized using the pod notion and observe that it is also sufficient for other popular applications. Orestis Alpos, Bernardo Machado David, Jakov Mitrovski, Odysseas Sofikitis, Dionysis Zindros |
DISC | 2 |
| 2024 | Updatable Privacy-Preserving Blueprints
Bernardo Machado David, Felix Engelmann, Tore Kasper Frederiksen, Markulf Kohlweiss, Elena Pagnin, Mikhail Volkhov |
ASIACRYPT (1) | 1 |
| 2024 | Publicly Verifiable Secret Sharing Over Class Groups and Applications to DKG and YOSO
Ignacio Cascudo, Bernardo Machado David |
EUROCRYPT (5) | 2 |
| 2023 | Mt. Random: Multi-tiered Randomness Beacons
Ignacio Cascudo, Bernardo Machado David, Omer Shlomovits, Denis Varlakov |
ACNS | 2 |
| 2023 | SoK: Privacy-Enhancing Technologies in FinanceabstractRecent years have seen the emergence of practical advanced cryptographic tools that not only protect data privacy and authenticity, but also allow for jointly processing data from different institutions without sacrificing privacy. The ability to do so has enabled implementations of a number of traditional and decentralized financial applications that would have required sacrificing privacy or trusting a third party. The main catalyst of this revolution was the advent of decentralized cryptocurrencies that use public ledgers to register financial transactions, which must be verifiable by any third party, while keeping sensitive data private. Zero Knowledge (ZK) proofs rose to prominence as a solution to this challenge, allowing for the owner of sensitive data (e.g. the identities of users involved in an operation) to convince a third party verifier that a certain operation has been correctly executed without revealing said data. It quickly became clear that performing arbitrary computation on private data from multiple sources by means of secure Multiparty Computation (MPC) and related techniques allows for more powerful financial applications, also in traditional finance. In this SoK, we categorize the main traditional and decentralized financial applications that can benefit from state-of-the-art Privacy-Enhancing Technologies (PETs) and identify design patterns commonly used when applying PETs in the context of these applications. In particular, we consider the following classes of applications: 1. Identity Management, KYC & AML; 2. Markets & Settlement; 3. Legal; and 4. Digital Asset Custody. We examine how ZK proofs, MPC and related PETs have been used to tackle the main security challenges in each of these applications. Moreover, we provide an assessment of the technological readiness of each PET in the context of different financial applications according to the availability of: theoretical feasibility results, preliminary benchmarks (in scientific papers) or benchmarks achieving real-world performance (in commercially deployed solutions). Finally, we propose future applications of PETs as Fintech solutions to currently unsolved issues. While we systematize financial applications of PETs at large, we focus mainly on those applications that require privacy preserving computation on data from multiple parties. Carsten Baum, James Hsin-yu Chiang, Bernardo Machado David, Tore Kasper Frederiksen |
AFT | 3 |
| 2023 | FairPoS: Input Fairness in Permissionless ConsensusabstractAutomated Market Makers (AMMs) are decentralized applications that allow users to exchange crypto-tokens without the need for a matching exchange order. AMMs are one of the most successful DeFi use cases: indeed, major AMM platforms process a daily volume of transactions worth USD billions. Despite their popularity, AMMs are well-known to suffer from transaction-ordering issues: adversaries can influence the ordering of user transactions, and possibly front-run them with their own, to extract value from AMMs, to the detriment of users. We devise an effective procedure to construct a strategy through which an adversary can maximize the value extracted from user transactions. James Hsin-yu Chiang, Bernardo Machado David, Ittay Eyal, Tiantian Gong |
AFT | 2 |
| 2023 | Correlated-Output Differential Privacy and Applications to Dark PoolsabstractIn the classical setting of differential privacy, a privacy-preserving query is performed on a private database, after which the query result is released to the analyst; a differentially private query ensures that the presence of a single database entry is protected from the analyst’s view. In this work, we contribute the first definitional framework for differential privacy in the trusted curator setting (Fig. 1); clients submit private inputs to the trusted curator, which then computes individual outputs privately returned to each client. The adversary is more powerful than the standard setting; it can corrupt up to n-1 clients and subsequently decide inputs and learn outputs of corrupted parties. In this setting, the adversary also obtains leakage from the honest output that is correlated with a corrupted output. Standard differentially private mechanisms protect client inputs but do not mitigate output correlation leaking arbitrary client information, which can forfeit client privacy completely. We initiate the investigation of a novel notion of correlated-output differential privacy to bound the leakage from output correlation in the trusted curator setting. We define the satisfaction of both standard and correlated-output differential privacy as round differential privacy and highlight the relevance of this novel privacy notion to all application domains in the trusted curator model. We explore round differential privacy in traditional "dark pool" market venues, which promise privacy-preserving trade execution to mitigate front-running; privately submitted trade orders and trade execution are kept private by the trusted venue operator. We observe that dark pools satisfy neither classic nor correlated-output differential privacy; in markets with low trade activity, the adversary may trivially observe recurring, honest trading patterns, and anticipate and front-run future trades. In response, we present the first round differentially private market mechanisms that formally mitigate information leakage from all trading activity of a user. This is achieved with fuzzy order matching, inspired by the standard randomized response mechanism; however, this also introduces a liquidity mismatch as buy and sell orders are not guaranteed to execute pairwise, thereby weakening output correlation; this mismatch is compensated for by a round differentially private liquidity provider mechanism, which freezes a noisy amount of assets from the liquidity provider for the duration of a privacy epoch, but leaves trader balances unaffected. We propose oblivious algorithms for realizing our proposed market mechanisms with secure multi-party computation (MPC) and implement these in the Scale-Mamba Framework using Shamir Secret Sharing based MPC. We demonstrate practical, round differentially private trading with comparable throughput as prior work implementing (traditional) dark pool algorithms in MPC; our experiments demonstrate practicality for both traditional finance and decentralized finance settings. James Hsin-yu Chiang, Bernardo Machado David, Mariana Gama, Christian Janos Lebeda |
AFT | 2 |
| 2023 | Perfect MPC over Layered Graphs
Bernardo Machado David, Giovanni Deligios, Aarushi Goel, Yuval Ishai, Anders Konring, Eyal Kushilevitz, Chen-Da Liu-Zhang, Varun Narayanan |
CRYPTO (1) | 1 |
| 2023 | PAPR: Publicly Auditable Privacy Revocation for Anonymous Credentials
Joakim Brorsson, Bernardo Machado David, Lorenzo Gentile, Elena Pagnin, Paul Stankovski Wagner |
CT-RSA | 2 |
| 2023 | Eagle: Efficient Privacy Preserving Smart Contracts
Carsten Baum, James Hsin-yu Chiang, Bernardo Machado David, Tore Kasper Frederiksen |
FC (1) | 3 |
| 2022 | FAST: Fair Auctions via Secret Transactions
Bernardo Machado David, Lorenzo Gentile, Mohsen Pourpouneh |
ACNS | 1 |
| 2022 | Encryption to the Future - A Paradigm for Sending Secret Messages to Future (Anonymous) Committees
Matteo Campanelli, Bernardo Machado David, Hamidreza Khoshakhlagh, Anders Konring, Jesper Buus Nielsen |
ASIACRYPT (3) | 2 |
| 2022 | YOLO YOSO: Fast and Simple Encryption and Secret Sharing in the YOSO Model
Ignacio Cascudo, Bernardo Machado David, Lydia Garms, Anders Konring |
ASIACRYPT (1) | 2 |
| 2022 | GearBox: Optimal-size Shard Committees by Leveraging the Safety-Liveness DichotomyabstractSharding is an emerging technique to overcome scalability issues on blockchain based public ledgers. Without sharding, every node in the network has to listen to and process all ledger protocol messages. The basic idea of sharding is to parallelize the ledger protocol: the nodes are divided into smaller subsets that each take care of a fraction of the original load by executing lighter instances of the ledger protocol, also called shards. The smaller the shards, the higher the efficiency, as by increasing parallelism there is less overhead in the shard consensus. Bernardo Machado David, Bernardo Magri, Christian Matt 0002, Jesper Buus Nielsen, Daniel Tschudi |
CCS | 1 |
| 2022 | (Public) Verifiability for Composable Protocols Without Adaptivity or Zero-Knowledge
Carsten Baum, Bernardo Machado David, Rafael Dowsley |
ProvSec | 2 |
| 2021 | P2DEX: Privacy-Preserving Decentralized Cryptocurrency Exchange
Carsten Baum, Bernardo Machado David, Tore Kasper Frederiksen |
ACNS (1) | 2 |
| 2021 | TARDIS: A Foundation of Time-Lock Puzzles in UC
Carsten Baum, Bernardo Machado David, Rafael Dowsley, Jesper Buus Nielsen, Sabine Oechsner |
EUROCRYPT (3) | 2 |
| 2020 | ALBATROSS: Publicly AttestabLe BATched Randomness Based On Secret Sharing
Ignacio Cascudo, Bernardo Machado David |
ASIACRYPT (3) | 2 |
| 2020 | Efficient Composable Oblivious Transfer from CDH in the Global Random Oracle Model
Bernardo Machado David, Rafael Dowsley |
CANS | 1 |
| 2019 | Efficient UC Commitment Extension with Homomorphism for Free (and Applications)
Ignacio Cascudo, Ivan Damgård, Bernardo Machado David, Nico Döttling, Rafael Dowsley, Irene Giacomelli |
ASIACRYPT (2) | 3 |
| 2018 | 21 - Bringing Down the Complexity: Fast Composable Protocols for Card Games Without Secret State
Bernardo Machado David, Rafael Dowsley, Mario Larangeira |
ACISP | 1 |
| 2018 | Ouroboros Praos: An Adaptively-Secure, Semi-synchronous Proof-of-Stake Blockchain
Bernardo Machado David, Peter Gazi, Aggelos Kiayias, Alexander Russell |
EUROCRYPT (2) | 1 |
| 2017 | SCRAPE: Scalable Randomness Attested by Public Entities
Ignacio Cascudo, Bernardo Machado David |
ACNS | 2 |
| 2017 | Ouroboros: A Provably Secure Proof-of-Stake Blockchain Protocol
Aggelos Kiayias, Alexander Russell, Bernardo Machado David, Roman Oliynykov |
CRYPTO (1) | 3 |
| 2016 | Rate-1, Linear Time and Additively Homomorphic UC Commitments
Ignacio Cascudo, Ivan Damgård, Bernardo Machado David, Nico Döttling, Jesper Buus Nielsen |
CRYPTO (3) | 3 |
| 2016 | Constant-Size Structure-Preserving Signatures: Generic Constructions and Simple Assumptions
Masayuki Abe, Melissa Chase, Bernardo Machado David, Markulf Kohlweiss, Ryo Nishimaki, Miyako Ohkubo |
J. Cryptol. | 3 |
| 2016 | Unconditionally Secure, Universally Composable Privacy Preserving Linear AlgebraabstractLinear algebra operations on private distributed data are frequently required in several practical scenarios (e.g., statistical analysis and privacy preserving databases). We present universally composable two-party protocols to compute inner products, determinants, eigenvalues, and eigenvectors. These protocols are built for a two-party scenario where the inputs are provided by mutually distrustful parties. After execution, the protocols yield the results of the intended operation while preserving the privacy of their inputs. Universal composability is obtained in the trusted initializer model, ensuring information theoretical security under arbitrary protocol composition in complex environments. Furthermore, our protocols are computationally efficient since they only require field multiplication and addition operations. Bernardo Machado David, Rafael Dowsley, Jeroen van de Graaf, Davidson Marques, Anderson C. A. Nascimento, Adriana C. B. Pinto |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Efficient Unconditionally Secure Comparison and Privacy Preserving Machine Learning Classification Protocols
Bernardo Machado David, Rafael Dowsley, Rajendra S. Katti, Anderson C. A. Nascimento |
ProvSec | 1 |
| 2014 | Compact VSS and Efficient Homomorphic UC CommitmentsabstractWe present a new compact verifiable secret sharing scheme, based on this we present the first construction of a homomorphic UC commitment scheme that requires only cheap symmetric cryptography, except for a small number of seed OTs. To commit to a k -bit string, the amortized communication cost is O ( k ) bits. Assuming a sufficiently efficient pseudorandom generator, the computational complexity is O ( k ) for the verifier and O ( k 1 + ε ) for the committer (where ε < 1 is a constant). In an alternative variant of the construction, all complexities are O ( k · polylog ( k )). Our commitment scheme extends to vectors over any finite field and is additively homomorphic. By sending one extra message, the prover can allow the verifier to also check multiplicative relations on committed strings, as well as verifying that committed vectors a , b satisfy a = φ ( b ) for a linear function φ . These properties allow us to non-interactively implement any one-sided functionality where only one party has input (this includes UC secure zero-knowledge proofs of knowledge). We also present a perfectly secure implementation of any multiparty functionality, based directly on our VSS. The communication required is proportional to a circuit implementing the functionality, up to a logarithmic factor. For a large natural class of circuits the overhead is even constant. We also improve earlier results by Ranellucci et al. on the amount of correlated randomness required for string commitments with individual opening of bits. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Ivan Damgård, Bernardo Machado David, Irene Giacomelli, Jesper Buus Nielsen |
ASIACRYPT (2) | 2 |
| 2014 | Universally Composable Oblivious Transfer Based on a Variant of LPN
Bernardo Machado David, Rafael Dowsley, Anderson C. A. Nascimento |
CANS | 1 |
| 2012 | Constant-Size Structure-Preserving Signatures: Generic Constructions and Simple Assumptions
Masayuki Abe, Melissa Chase, Bernardo Machado David, Markulf Kohlweiss, Ryo Nishimaki, Miyako Ohkubo |
ASIACRYPT | 3 |
| 2011 | Efficient fully simulatable oblivious transfer from the McEliece assumptionsabstractWe introduce the first efficient fully simulatable construction of oblivious transfer based on the McEliece assumptions in the common reference string model. Bernardo Machado David, Anderson C. A. Nascimento |
ITW | 1 |
| 2011 | Universally Composable Private Proximity Testing
Rafael Tonicelli, Bernardo Machado David, Vinícius de Morais Alves |
ProvSec | 2 |