Xingye Lu

dblp:180/8214 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-3595-044XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Efficient Construction of Threshold BBS+ Signatures and Its Extensions
Yang Heng, Mengling Liu, Xingye Lu, Haiyang Xue, Zijian Bao, Man Ho Au
PKC (3)3
2025 Compact Adaptively Secure Identity-Based Encryption from Middle-Product Learning with Errors
Xingye Lu, Man Ho Au, Siu-Ming Yiu
ICICS (1)2
2025 JesseQ: Efficient Zero-Knowledge Proofs for Circuits Over Any Field
abstract
Recent advances in Vector Oblivious Linear Evaluation (VOLE) protocols have enabled constant-round, fast, and scalable (designated-verifier) zero-knowledge proofs, significantly reducing prover computational cost. Existing protocols, such as QuickSilver [CCS'21] and LPZKv2 [CCS'22], achieve efficiency with prover costs of 4 multiplications in the extension field per AND gate for Boolean circuits, with one multiplication requiring a O (k log k) -bit operation where k== 128 is the security parameter, and 3–4 field multiplications per multiplication gate for arithmetic circuits over a large field. We introduce JesseQ, a suite of two VOLE-based protocols: JQv1 and JQv2, which advance state of the art. JQv1 requires only 2 scalar multiplications in an extension field per AND gate for Boolean circuits, with one scalar needing a$O(\kappa)$bit operation, and 2 field multiplications per multiplication gate for arithmetic circuits over a large field. In terms of communication costs, JQv1 needs just 1 field element per gate. JQv2 further reduces communication costs by half at the cost of doubling the prover's computation. Experiments show that, compared to the current state of the art, both JQv1 and JQv2 achieve at least 3.9× improvement in the online phase for Boolean circuits. For large field circuits, JQv1 has a similar performance, while JQv2 offers a 1.3× improvement. Additionally, both JQv1 and JQv2 maintain the same communication cost as the current state of the art. No-tably, on the cheapest AWS instances, JQv1 can prove 9.2 tril-lion AND gates (or 5.8 trillion multiplication gates over a 61-bit field) for just one US dollar. JesseQ excels in applications like inner products, matrix multiplication, and lattice problems, delivering 40% – 200% performance improvements compared to QuickSilver. Additionally, JesseQ integrates seamlessly with the sublinear Batchman framework [CCS'23], enabling further efficiency gains for batched disjunctive statements.
Mengling Liu, Yang Heng, Xingye Lu, Man Ho Au
SP3
2024 Efficient Linkable Ring Signatures: New Framework and Post-quantum Instantiations
Yuxi Xue, Xingye Lu, Man Ho Au, Chengru Zhang
ESORICS (4)2
2023 Adaptively Secure Identity-Based Encryption from Middle-Product Learning with Errors
Xingye Lu, Man Ho Au
ACISP2
2019 Raptor: A Practical Lattice-Based (Linkable) Ring Signature
Xingye Lu, Man Ho Au, Zhenfei Zhang
ACNS1
2018 Practical Signatures from the Partial Fourier Recovery Problem Revisited: A Provably-Secure and Gaussian-Distributed Construction
Xingye Lu, Zhenfei Zhang, Man Ho Au
ACISP1
2016 Anonymous Identification for Ad Hoc Group
abstract
An anonymous identification scheme for ad hoc group allows a participant to identify himself as a member of a group of users in a way that his actual identity is not revealed. We propose a highly efficient construction of this cryptographic primitive in the symmetric key setting based on the idea of program obfuscation. The salient feature of our scheme is that only hash evaluations are needed. Consequently, our scheme outperforms all existing constructions for a reasonably large ad hoc group size (of around 50000 users) since no exponentiation nor pairing operation is involved. Technically, the participant only needs to evaluate one hash operation to identify himself. While the time complexity of the verifier is linearly in the size of the ad hoc group, the actual running time is rather insignificant since the constant factor of this linear dependence is the time of a single hash evaluation. To analyse the security of our proposal, we develop a security model to capture the security requirements of this primitive and prove that our construction satisfies these requirements in the random oracle model against unbounded attackers. Similar to other identification schemes secure in the random oracle model, our proposed protocol requires only two message flow.
Xingye Lu, Man Ho Au
AsiaCCS1