Lior Rotem

dblp:168/7887 · DBLP profile ↗
← Back
23ranked-venue papers
13as first author
15since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 13 first-author · 15 since 2021Theory of computation · 6 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Context-Dependent Threshold Decryption and Its Applications
Dan Boneh, Benedikt Bünz, Kartik Nayak, Lior Rotem, Victor Shoup
ASIACRYPT (6)4
2025 Traceable Verifiable Random Functions
Dan Boneh, Aditi Partap, Lior Rotem
CRYPTO (2)3
2025 Straight-Line Knowledge Extraction for Multi-Round Protocols
Lior Rotem, Stefano Tessaro
CRYPTO (7)1
2024 Traceable Secret Sharing: Strong Security and Efficient Constructions
Dan Boneh, Aditi Partap, Lior Rotem
CRYPTO (5)3
2024 Accountability for Misbehavior in Threshold Decryption via Threshold Traitor Tracing
Dan Boneh, Aditi Partap, Lior Rotem
CRYPTO (7)3
2024 Proactive Refresh for Accountable Threshold Signatures
Dan Boneh, Aditi Partap, Lior Rotem
FC (2)3
2024 From One-Time to Two-Round Reusable Multi-signatures Without Nested Forking
Lior Rotem, Gil Segev 0001, Eylon Yogev
TCC (3)1
2024 Tighter Security for Schnorr Identification and Signatures: A High-Moment Forking Lemma for $\varvec{\Sigma }$-Protocols
Lior Rotem, Gil Segev 0001
J. Cryptol.1
2023 Post-Quantum Single Secret Leader Election (SSLE) from Publicly Re-Randomizable Commitments
abstract
A Single Secret Leader Election (SSLE) enables a group of parties to randomly choose exactly one leader from the group with the restriction that the identity of the leader will be known to the chosen leader and nobody else. At a later time, the elected leader should be able to publicly reveal her identity and prove that she is the elected leader. The election process itself should work properly even if many registered users are passive and do not send any messages. SSLE is used to strengthen the security of proof-of-stake consensus protocols by ensuring that the identity of the block proposer remains unknown until the proposer publishes a block. Boneh, Eskandarian, Hanzlik, and Greco (AFT'20) defined the concept of an SSLE and gave several constructions. Their most efficient construction is based on the difficulty of the Decision Diffie-Hellman problem in a cyclic group. In this work we construct the first efficient SSLE protocols based on the standard Learning With Errors (LWE) problem on integer lattices, as well as the Ring-LWE problem. Both are believed to be post-quantum secure. Our constructions generalize the paradigm of Boneh et al. by introducing the concept of a re-randomizable commitment (RRC). We then construct several post-quantum RRC schemes from lattice assumptions and prove the security of the derived SSLE protocols. Constructing a lattice-based RRC scheme is non-trivial, and may be of independent interest.
Dan Boneh, Aditi Partap, Lior Rotem
AFT3
2023 Non-malleable Vector Commitments via Local Equivocability
Lior Rotem, Gil Segev 0001
J. Cryptol.1
2022 From Fairness to Full Security in Multiparty Computation
Ran Cohen, Iftach Haitner, Eran Omri, Lior Rotem
J. Cryptol.4
2021 Tighter Security for Schnorr Identification and Signatures: A High-Moment Forking Lemma for ${\varSigma }$-Protocols
Lior Rotem, Gil Segev 0001
CRYPTO (1)1
2021 Non-malleable Vector Commitments via Local Equivocability
Lior Rotem, Gil Segev 0001
TCC (3)1
2021 Simple and Efficient Batch Verification Techniques for Verifiable Delay Functions
Lior Rotem
TCC (3)1
2021 Injective Trapdoor Functions via Derandomization: How Strong is Rudich's Black-Box Barrier?
Lior Rotem, Gil Segev 0001
J. Cryptol.1
2020 Generically Speeding-Up Repeated Squaring Is Equivalent to Factoring: Sharp Thresholds for All Generic-Ring Delay Functions
Lior Rotem, Gil Segev 0001
CRYPTO (3)1
2020 Generic-Group Delay Functions Require Hidden-Order Groups
Lior Rotem, Gil Segev 0001, Ido Shahaf
EUROCRYPT (3)1
2020 Algebraic Distinguishers: From Discrete Logarithms to Decisional Uber Assumptions
Lior Rotem, Gil Segev 0001
TCC (3)1
2020 The Security of Lazy Users in Out-of-Band Authentication
abstract
Faced with the threats posed by man-in-the-middle attacks, messaging platforms rely on “out-of-band” authentication, assuming that users have access to an external channel for authenticating one short value. For example, assuming that users recognizing each other’s voice can authenticate a short value, Telegram and WhatApp ask their users to compare 288-bit and 200-bit values, respectively. The existing protocols, however, do not take into account the plausible behavior of users who may be “lazy” and only compare parts of these values (rather than their entirety). Motivated by such a security-critical user behavior, we study the security of lazy users in out-of-band authentication. We start by showing that both the protocol implemented by WhatsApp and the statistically optimal protocol of Naor, Segev, and Smith (CRYPTO’06) are completely vulnerable to man-in-the-middle attacks when the users consider only a half of the out-of-band authenticated value. In this light, we put forward a framework that captures the behavior and security of lazy users. Our notions of security consider both statistical security and computational security, and for each flavor we derive a lower bound on the tradeoff between the number of positions that are considered by the lazy users and the adversary’s forgery probability. Within our framework, we then provide two authentication protocols. First, in the statistical setting, we present a transformation that converts any out-of-band authentication protocol into one that is secure even when executed by lazy users. Instantiating our transformation with a new refinement of the protocol of Naor et al. results in a protocol whose tradeoff essentially matches our lower bound in the statistical setting. Then, in the computational setting, we show that the computationally optimal protocol of Vaudenay (CRYPTO’05) is secure even when executed by lazy users—and its tradeoff matches our lower bound in the computational setting.
Moni Naor, Lior Rotem, Gil Segev 0001
ACM Trans. Priv. Secur.2
2018 Out-of-Band Authentication in Group Messaging: Computational, Statistical, Optimal
Lior Rotem, Gil Segev 0001
CRYPTO (1)1
2018 The Security of Lazy Users in Out-of-Band Authentication
Moni Naor, Lior Rotem, Gil Segev 0001
TCC (2)2
2018 Injective Trapdoor Functions via Derandomization: How Strong is Rudich's Black-Box Barrier?
Lior Rotem, Gil Segev 0001
TCC (1)1
2018 Characterization of Secure Multiparty Computation Without Broadcast
Ran Cohen, Iftach Haitner, Eran Omri, Lior Rotem
J. Cryptol.4