EDBT 2026 Demo / reviewers in the wild / expert
Lorenzo Grassi 0001
dblp:166/8773-1
· DBLP profile ↗
29ranked-venue papers
18as first author
14since 2021 · last 2026
0000-0003-1140-0520ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 18 first-author · 14 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The ABC of Symmetric Primitives over Integer Rings: Milk Before Meat
Tim Beyne, Lorenzo Grassi 0001, Morten Øygarden, Berenika Richterová, Arne Sandrib |
CRYPTO (6) | 2 |
| 2025 | On generalizations of the Lai-Massey schemeabstractAbstract In this paper, we re-investigate the Lai–Massey scheme, originally proposed in the cipher IDEA. Due to the similarity with the Feistel networks, and due to the existence of invariant subspace attacks as originally pointed out by Vaudenay at FSE 1999, the Lai–Massey scheme has received only little attention by the community. As first contribution, we propose two new generalizations of such scheme that are not (extended) affine equivalent to any generalized Feistel network proposed in the literature so far. Then, inspired by the recent construction, we propose the structure as a generalization of the Lai–Massey scheme, in which the linear combination in the Lai–Massey scheme can be replaced by a non-linear one. Besides proposing concrete examples of the construction, we analyze its cryptographic properties in the context of MPC-/HE-/ZK-friendly symmetric primitives. Lorenzo Grassi 0001 |
Des. Codes Cryptogr. | 1 |
| 2024 | General Practical Cryptanalysis of the Sum of Round-Reduced Block Ciphers and ZIP-AES
Antonio Flórez-Gutiérrez, Lorenzo Grassi 0001, Gregor Leander, Ferdinand Sibleyras, Yosuke Todo |
ASIACRYPT (9) | 2 |
| 2024 | Generalized Feistel Ciphers for Efficient Prime Field Masking
Lorenzo Grassi 0001, Loïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier Standaert |
EUROCRYPT (3) | 1 |
| 2024 | Minimize the Randomness in Rasta-Like Designs: How Far Can We Go? - Application to Pasta
Lorenzo Grassi 0001, Fukang Liu, Christian Rechberger, Fabian Schmid, Roman Walch, Qingju Wang 0001 |
SAC (2) | 1 |
| 2023 | Cryptanalysis of Symmetric Primitives over Rings and a Key Recovery Attack on Rubato
Lorenzo Grassi 0001, Irati Manterola Ayala, Martha Norberg Hovd, Morten Øygarden, Håvard Raddum, Qingju Wang 0001 |
CRYPTO (3) | 1 |
| 2023 | Horst Meets Fluid-SPN: Griffin for Zero-Knowledge Applications
Lorenzo Grassi 0001, Yonglin Hao, Christian Rechberger, Markus Schofnegger, Roman Walch, Qingju Wang 0001 |
CRYPTO (3) | 1 |
| 2023 | Coefficient Grouping for Complex Affine Layers
Fukang Liu, Lorenzo Grassi 0001, Clémence Bouvier, Willi Meier, Takanori Isobe 0001 |
CRYPTO (3) | 2 |
| 2023 | From Farfalle to Megafono via Ciminion: The PRF Hydra for MPC Applications
Lorenzo Grassi 0001, Morten Øygarden, Markus Schofnegger, Roman Walch |
EUROCRYPT (4) | 1 |
| 2022 | Truncated Differential Properties of the Diagonal Set of Inputs for 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger |
ACISP | 1 |
| 2022 | Security of Truncated Permutation Without Initial Value
Lorenzo Grassi 0001, Bart Mennink |
ASIACRYPT (2) | 1 |
| 2022 | Reinforced Concrete: A Fast Hash Function for Verifiable ComputationabstractWe propose a new hash function Reinforced Concrete, which is the first generic purpose hash that is fast both for a zero-knowledge prover and in native x86 computations. It is suitable for a various range of zero-knowledge proofs and protocols, from set membership to generic purpose verifiable computation. Being up to 15x faster than its predecessor Poseidon hash, Reinforced Concrete inherits security from traditional time-tested schemes such as AES, whereas taking the zero-knowledge performance from a novel and efficient decomposition of a prime field into compact buckets. Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger, Roman Walch |
CCS | 1 |
| 2021 | Ciminion: Symmetric Encryption Based on Toffoli-Gates over Large Finite Fields
Christoph Dobraunig, Lorenzo Grassi 0001, Anna Guinet, Daniël Kuijsters |
EUROCRYPT (2) | 2 |
| 2021 | Poseidon: A New Hash Function for Zero-Knowledge Proof Systems
Lorenzo Grassi 0001, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 0005, Markus Schofnegger |
USENIX Security Symposium | 1 |
| 2020 | An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC
Maria Eichlseder, Lorenzo Grassi 0001, Reinhard Lüftenegger, Morten Øygarden, Christian Rechberger, Markus Schofnegger, Qingju Wang 0001 |
ASIACRYPT (1) | 2 |
| 2020 | On a Generalization of Substitution-Permutation Networks: The HADES Design Strategy
Lorenzo Grassi 0001, Reinhard Lüftenegger, Christian Rechberger, Dragos Rotaru, Markus Schofnegger |
EUROCRYPT (2) | 1 |
| 2020 | Algebraic Key-Recovery Attacks on Reduced-Round Xoofff
Tingting Cui, Lorenzo Grassi 0001 |
SAC | 2 |
| 2020 | Weak-Key Distinguishers for AES
Lorenzo Grassi 0001, Gregor Leander, Christian Rechberger, Cihangir Tezcan, Friedrich Wiemer |
SAC | 1 |
| 2020 | Revisiting Gilbert's known-key distinguisherabstractAbstract Known-key distinguishers have been introduced by Knudsen and Rijmen in 2007 to better understand the security of block ciphers in situations where the key can not be considered to be secret, i.e. the “thing between secret-key model and hash function use-cases”. Trying to find a rigorous model to fit this intuition is still ongoing. The most recent advance by Gilbert (Asiacrypt 2014) describes a new model that—even if it is well justified—seemingly does not match this intuition. AES is often considered as a target of such analyses, simply because AES or its building blocks are used in many settings that go beyond classical encryption. Consider AES-128. Results in the secret-key model cover up to 6 rounds, while results in the chosen-key model reach up to 9 rounds. Gilbert however showed a result in the known-key model that goes even further, covering 10 rounds. Does it mean that the use cases corresponding to the cryptanalysis of hash-function use-cases are inherently less efficient, or is it rather an artifact of the new model? In this paper we give strong evidence for the latter. In Gilbert’s work, two types of arguments or rather conjectures are put forward suggesting that the new model is meaningful. Firstly that the number of “extension rounds” due to the new model is limited to two. And secondly that only a distinguisher that exploits the uniform distribution property can be extended in such way. We disprove both conjectures and arrive at the following results: First, we are also able to show that more than two extension rounds are possible. As a result of this, we describe the first known-key distinguishers on 12 rounds of AES that fit into Gilbert’s model. The second conjecture is disproven by showing that the technique proposed by Gilbert can also be used to extend a known-key distinguisher based on another property: truncated differentials. A potential conclusion of this work would be that the counter-intuitive gap between Gilbert’s known-key model and the chosen-key model is wider than initially thought. We however conclude that results in Gilbert’s model are due to an artifact in the model. To remedy this situation, we propose a refinement of the known-key model which restores its original intent to fit the original intuition. Lorenzo Grassi 0001, Christian Rechberger |
Des. Codes Cryptogr. | 1 |
| 2019 | Algebraic Cryptanalysis of STARK-Friendly Designs: Application to MARVELlous and MiMC
Martin R. Albrecht, Carlos Cid, Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger |
ASIACRYPT (3) | 3 |
| 2019 | Feistel Structures for MPC, and More
Martin R. Albrecht, Lorenzo Grassi 0001, Léo Perrin, Sebastian Ramacher, Christian Rechberger, Dragos Rotaru, Arnab Roy 0005, Markus Schofnegger |
ESORICS (2) | 2 |
| 2019 | Probabilistic Mixture Differential Cryptanalysis on Round-Reduced AES
Lorenzo Grassi 0001 |
SAC | 1 |
| 2018 | Quantum Algorithms for the k -xor Problem
Lorenzo Grassi 0001, María Naya-Plasencia, André Schrottenloher |
ASIACRYPT (1) | 1 |
| 2018 | Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger |
CRYPTO (1) | 3 |
| 2018 | MixColumns Properties and Attacks on (Round-Reduced) AES with a Single Secret S-Box
Lorenzo Grassi 0001 |
CT-RSA | 1 |
| 2018 | Zero-Sum Partitions of PHOTON Permutations
Qingju Wang 0001, Lorenzo Grassi 0001, Christian Rechberger |
CT-RSA | 2 |
| 2017 | A New Structural-Differential Property of 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger, Sondre Rønjom |
EUROCRYPT (2) | 1 |
| 2016 | MiMC: Efficient Encryption and Cryptographic Hashing with Minimal Multiplicative Complexity
Martin R. Albrecht, Lorenzo Grassi 0001, Christian Rechberger, Arnab Roy 0005, Tyge Tiessen |
ASIACRYPT (1) | 2 |
| 2016 | MPC-Friendly Symmetric Key PrimitivesabstractWe discuss the design of symmetric primitives, in particular Pseudo-Random Functions (PRFs) which are suitable for use in a secret-sharing based MPC system. We consider three different PRFs: the Naor-Reingold PRF, a PRF based on the Legendre symbol, and a specialized block cipher design called MiMC. We present protocols for implementing these PRFs within a secret-sharing based MPC system, and discuss possible applications. We then compare the performance of our protocols. Depending on the application, different PRFs may offer different optimizations and advantages over the classic AES benchmark. Thus, we cannot conclude that there is one optimal PRF to be used in all situations. Lorenzo Grassi 0001, Christian Rechberger, Dragos Rotaru, Peter Scholl, Nigel P. Smart |
CCS | 1 |