Rafaël Del Pino

dblp:179/6846 · also Rafaël del Pino · DBLP profile ↗
← Back
13ranked-venue papers
9as first author
8since 2021 · last 2026
0009-0001-8638-787XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 9 first-author · 8 since 2021
YearPublicationVenuePosition
2026 IND-CCA Lattice Threshold KEM Under 30 KiB
Katharina Boudgoust, Rafaël Del Pino, Oleksandra Lapiha, Thomas Prest
PKC (1)2
2025 Poster: Efficient Threshold ML-DSA up to 6 Parties
abstract
Threshold signature schemes enable a group of users to collaboratively produce digital signatures without revealing any individual share. With the current NIST post-quantum standardization underway, the lack of efficient and practical threshold variants of standardized schemes hinders adoption. We introduce the first threshold signature scheme compatible with the ML-DSA standard (Module-Lattice-based Digital Signature Algorithm), supporting up to 6 parties, while retaining efficient signing. Our work uses advanced short secret sharing techniques and optimized rejection sampling to balance communication and correctness in distributed settings. We implement our construction in Go and benchmark it in local, LAN, and WAN deployments. Results show that our threshold ML-DSA is both practical and compatible with real-world applications such as multi-device cryptocurrency wallets, threshold TLS, and Tor's directory authorities.
Sofía Celi, Rafaël Del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest
CCS2
2025 Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort Protocol
Rafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle, Kaoru Takemure
CRYPTO (6)1
2025 Finally! A Compact Lattice-Based Threshold Signature
Rafaël Del Pino, Guilhem Niot
PKC (3)1
2024 Raccoon: A Masking-Friendly Signature Proven in the Probing Model
Rafaël Del Pino, Shuichi Katsumata, Thomas Prest, Melissa Rossi
CRYPTO (1)1
2024 Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions
Rafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem, Thomas Prest, Markku-Juhani O. Saarinen
EUROCRYPT (2)1
2023 High-Order Masking of Lattice Signatures in Quasilinear Time
abstract
In recent years, lattice-based signature schemes have emerged as the most prominent post-quantum solutions, as illustrated by NIST’s selection of Falcon and Dilithium for standardization. Both schemes enjoy good performance characteristics. However, their efficiency dwindles in the presence of side-channel protections, particularly masking – perhaps the strongest generic side-channel countermeasure. Masking at order d-1 requires randomizing all sensitive intermediate variables into d shares. With existing schemes, signature generation complexity grows quadratically with the number of shares, making high-order masking prohibitively slow.In this paper, we turn the problem upside-down: We design a lattice-based signature scheme specifically for side-channel resistance and optimize the masked efficiency as a function of the number of shares. Our design avoids costly operations such as conversions between arithmetic and boolean encodings (A2B/B2A), masked rejection sampling, and does not require a masked SHAKE implementation or other symmetric primitives. The resulting scheme is called Raccoon and belongs to the family of Fiat-Shamir with aborts lattice-based signatures. Raccoon is the first lattice-based signature whose key generation and signing running time has only an O(d log(d)) overhead, with d being the number of shares.Our Reference C implementation confirms that Raccoon’s performance is comparable to other state-of-the-art signature schemes, except that increasing the number of shares has a near-linear effect on its latency. We also present an FPGA implementation and perform a physical leakage assessment to verify its basic security properties.
Rafaël Del Pino, Thomas Prest, Melissa Rossi, Markku-Juhani O. Saarinen
SP1
2022 A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor Sampling
Rafaël Del Pino, Shuichi Katsumata
CRYPTO (2)1
2018 Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism Stability
abstract
We present a group signature scheme, based on the hardness of lattice problems, whose outputs are more than an order of magnitude smaller than the currently most efficient schemes in the literature. Since lattice-based schemes are also usually non-trivial to efficiently implement, we additionally provide the first experimental implementation of lattice-based group signatures demonstrating that our construction is indeed practical -- all operations take less than half a second on a standard laptop. A key component of our construction is a new zero-knowledge proof system for proving that a committed value belongs to a particular set of small size. The sets for which our proofs are applicable are exactly those that contain elements that remain stable under Galois automorphisms of the underlying cyclotomic number field of our lattice-based protocol. We believe that these proofs will find applications in other settings as well. The motivation of the new zero-knowledge proof in our construction is to allow the efficient use of the selectively-secure signature scheme (i.e. a signature scheme in which the adversary declares the forgery message before seeing the public key) of Agrawal et al. (Eurocrypt 2010) in constructions of lattice-based group signatures and other privacy protocols. For selectively-secure schemes to be meaningfully converted to standard signature schemes, it is crucial that the size of the message space is not too large. Using our zero-knowledge proofs, we can strategically pick small sets for which we can provide efficient zero-knowledge proofs of membership.
Rafaël Del Pino, Vadim Lyubashevsky, Gregor Seiler
CCS1
2018 Sub-linear Lattice-Based Zero-Knowledge Arguments for Arithmetic Circuits
Carsten Baum, Jonathan Bootle, Andrea Cerulli, Rafaël Del Pino, Jens Groth, Vadim Lyubashevsky
CRYPTO (2)4
2017 Practical Quantum-Safe Voting from Lattices
abstract
We propose a lattice-based electronic voting scheme, EVOLVE (Electronic Voting from Lattices with Verification), which is conjectured to resist attacks by quantum computers. Our protocol involves a number of voting authorities so that vote privacy is maintained as long as at least one of the authorities is honest, while the integrity of the result is guaranteed even when all authorities collude. Furthermore, the result of the vote can be independently computed by any observer. At the core of the protocol is the utilization of a homomorphic commitment scheme with strategically orchestrated zero-knowledge proofs: voters use approximate but efficient "Fiat-Shamir with Aborts" proofs to show the validity of their vote, while the authorities use amortized exact proofs to show that the commitments are well-formed. We also present a novel efficient zero-knowledge proof that one of two lattice-based statements is true (so-called OR proof) and a new mechanism to control the size of the randomness when applying the homomorphism to commitments. We give concrete parameter choices to securely instantiate and evaluate the efficiency of our scheme. Our prototype implementation shows that the voters require $8$ milliseconds to submit a vote of size about $20$KB to each authority and it takes each authority $0.15$ seconds per voter to create a proof that his vote was valid. The size of the vote share that each authority produces is approximately $15$KB per voter, which we believe is well within the practical bounds for a large-scale election.
Rafaël Del Pino, Vadim Lyubashevsky, Gregory Neven, Gregor Seiler
CCS1
2017 Amortization with Fewer Equations for Proving Knowledge of Small Secrets
Rafaël Del Pino, Vadim Lyubashevsky
CRYPTO (3)1
2016 FHE Circuit Privacy Almost for Free
Florian Bourse, Rafaël Del Pino, Michele Minelli, Hoeteck Wee
CRYPTO (2)2