EDBT 2026 Demo / reviewers in the wild / expert
Julian Loss
dblp:184/3870
· DBLP profile ↗
66ranked-venue papers
5as first author
52since 2021 · last 2026
0000-0002-7979-3810ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 58 · 3 first-author · 46 since 2021Theory of computation · 7 · 2 first-author · 4 since 2021Systems, architecture and hardware · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptively Secure (Aggregatable) PVSS from Standard Assumptions
Renas Bacho, Yanbo Chen 0002, Julian Loss |
CRYPTO (2) | 3 |
| 2026 | Tight Lattice-Based Signatures Without Trapdoors from Search LWE
Rutchathon Chairattana-Apirom, Nico Döttling, Julian Loss, Stefano Tessaro, Benedikt Wagner |
CRYPTO (3) | 3 |
| 2026 | Optimal Best-of-Both-Worlds Consensus
Fatima Elsheimy, Simon Holmgaard Kamp, Julian Loss, Jesper Buus Nielsen |
CRYPTO (10) | 3 |
| 2026 | Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGM
Renas Bacho, Yanbo Chen 0002, Julian Loss, Stefano Tessaro, Chenzhi Zhu |
EUROCRYPT (1) | 3 |
| 2026 | Ipotane: Balancing the Good and Bad Cases of Asynchronous BFT
Xiaohai Dai, Chaozheng Ding, Hai Jin 0001, Julian Loss, Ling Ren 0001 |
NDSS | 4 |
| 2026 | Nearly Quadratic Asynchronous Distributed Key Generation from Recursive Consensus
Ittai Abraham, Renas Bacho, Julian Loss, Gilad Stern |
PODC | 3 |
| 2026 | Early-Stabilizing CountingabstractSynchronous Counting is the task of reaching agreement on a common round counter in a synchronous system of n nodes with up to t Byzantine faults in a self-stabilizing manner. That is, after transient faults may have arbitrarily corrupted the system state and ceased, the at least n - t non-faulty nodes need to (re-)establish that (i) their local outputs are identical and (ii) increase by 1 modulo C in each round. An overhead-free reduction from consensus shows that all known lower bounds and impossibilities for consensus carry over to the counting problem. In the other direction, prior work has established that a consensus algorithm A can be turned into a counting algorithm at small overhead relative to the running time and bit complexity of A, without losing resilience. Christoph Lenzen 0001, Julian Loss |
PODC | 2 |
| 2026 | Byzantine Consensus in the Partially Authenticated SettingabstractByzantine Agreement and Broadcast are traditionally studied in one of two extremes: the authenticated setting, where a public key infrastructure (PKI) enables universally verifiable signatures and yields higher fault tolerance, and the unauthenticated setting, where no PKI is available and resilience necessarily drops. Motivated by Proof-of-Stake blockchains, where only a stable subset of participants (e.g., validators) have registered long-term keys while others do not, we initiate a systematic study of consensus in the partially authenticated setting, where a subset of parties are registered in a PKI and the remaining parties are unregistered. Christoph Lenzen 0001, Julian Loss, Kecheng Shi 0001, Benedikt Wagner |
PODC | 2 |
| 2025 | BIP32-Compatible Threshold WalletsabstractCryptographic wallets are an essential tool to securely store and maintain users’ secret keys and consequently their funds in Blockchain networks. A compelling approach to construct such wallets is to share the user’s secret key among several devices, such that an adversary must corrupt multiple machines to extract the entire secret key. Indeed, many leading cryptocurrency companies such as Coinbase, Binance, or ZenGo have started offering such distributed wallets to their customers. An important feature of a cryptographic wallet is its compatibility with the so-called BIP32 specification, the most widely adopted standard for cryptographic wallets. Essentially, BIP32 specifies the notion of a hierarchical deterministic wallet, which allows to create a key hierarchy in a deterministic fashion. Unfortunately, despite significant interest, no practically efficiently solution for a fully distributed wallet scheme, that also follows the BIP32 standard, exists. In this work, we show the first concretely efficient construction of a fully distributed wallet that is compliant with the BIP32 standard. To this end, we first provide a game-based notion of threshold signatures with rerandomizable keys and show an instantiation via the Gennaro and Goldfeder threshold ECDSA scheme (CCS’18). We then observe that one of BIP32’s key derivation mechanisms, the so-called hardened derivation, cannot efficiently be translated to the threshold setting. Instead, we devise a novel and efficient hardened derivation mechanism for the threshold setting that satisfies the same properties as the original mechanism as specified by BIP32. As a final contribution, we evaluate our solution with respect to its running time and communication cost. Poulami Das 0003, Andreas Erwig, Sebastian Faust, Philipp-Florens Lehwalder, Julian Loss, Ziyan Qu, Siavash Riahi 0002 |
AsiaCCS | 5 |
| 2025 | Adaptively Secure Three-Round Threshold Schnorr Signatures from DDH
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001 |
CRYPTO (6) | 3 |
| 2025 | Leader Election with Poly-Logarithmic Communication Per Party
Amey Bhangale, Chen-Da Liu-Zhang, Julian Loss, Kartik Nayak, Sravya Yandamuri |
CRYPTO (2) | 3 |
| 2025 | Nearly Optimal Parallel Broadcast in the Plain Public Key Model
Ran Gelles, Christoph Lenzen 0001, Julian Loss, Sravya Yandamuri |
CRYPTO (2) | 3 |
| 2025 | Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001 |
EUROCRYPT (2) | 3 |
| 2025 | Towards Optimal Parallel Broadcast Under a Dishonest Majority
Daniel Collins 0001, Sisi Duan, Julian Loss, Charalampos Papamanthou, Giorgos Tsimos |
FC | 3 |
| 2025 | Kleptographic Attacks Against Implicit Rejection
Antoine Joux, Julian Loss, Benedikt Wagner |
PKC (4) | 2 |
| 2025 | Sublinear-Round Broadcast without Trusted SetupabstractByzantine broadcast is one of the fundamental problems in distributed computing. Many of its practical applications, from multiparty computation to consensus mechanisms for blockchains, require increasingly weaker trust assumptions, as well as scalability for an ever-growing number of users n. This rules out existing solutions which run in a linear number of rounds in n or rely on trusted setup requirements. In this paper, we propose the first sublinear-round and trustless Byzantine broadcast protocol for the dishonest majority setting. Unlike previous sublinear-round protocols, our protocol assumes neither the existence of a trusted dealer who honestly issues keys and correlated random strings to the parties nor random oracles. Instead, we present a solution whose setup is limited to an unstructured uniform reference string and a plain public key infrastructure (a.k.a. bulletin-board PKI). Andreea B. Alexandru, Julian Loss, Charalampos Papamanthou, Giorgos Tsimos, Benedikt Wagner |
SODA | 2 |
| 2025 | Dimensional esfROSion: Improving the sfROS Attack with Decomposition in Higher Bases
Antoine Joux, Julian Loss, Giacomo Santato |
TCC (3) | 2 |
| 2024 | HARTS: High-Threshold, Adaptively Secure, and Robust Threshold Schnorr Signatures
Renas Bacho, Julian Loss, Gilad Stern, Benedikt Wagner |
ASIACRYPT (3) | 2 |
| 2024 | Early Stopping Byzantine Agreement in (1+ε ) · f Rounds
Fatima Elsheimy, Julian Loss, Charalampos Papamanthou |
ASIACRYPT (6) | 2 |
| 2024 | GRandLine: Adaptively Secure DKG and Randomness Beacon with (Log-)Quadratic Communication ComplexityabstractA randomness beacon is a source of continuous and publicly verifiable randomness which is of crucial importance for many applications. Existing works on randomness beacons suffer from at least one of the following drawbacks: (i) security only against static (i.e., non-adaptive) adversaries, (ii) each epoch takes many rounds of communication, or (iii) computationally expensive tools such as proof-of-work (PoW) or verifiable delay functions (VDF). In this work, we introduce GRandLine, the first adaptively secure randomness beacon protocol that overcomes all these limitations while preserving simplicity and optimal resilience in the synchronous network setting. We achieve our result in two steps. First, we design a novel distributed key generation (DKG) protocol GRand that runs in O(λ n2 log n ) bits of communication but, unlike most conventional DKG protocols, outputs both secret and public keys as group elements. Here, λ denotes the security parameter. Second, following termination of GRand, parties can use their keys to derive a sequence of randomness beacon values, where each random value costs only a single asynchronous round and O(λ n2) bits of communication. We implement GRandLine and evaluate it using a network of up to 64 parties running in geographically distributed AWS instances. Our evaluation shows that GRandLine can produce about 2 beacon outputs per second in a network of 64 parties. We compare our protocol to the state-of-the-art randomness beacon protocols OptRand (NDSS '23), BRandPiper (CCS '21), and Drand, in the same setting and observe that it vastly outperforms them. Renas Bacho, Christoph Lenzen 0001, Julian Loss, Simon Ochsenreither, Dimitrios Papachristoudis |
CCS | 3 |
| 2024 | Blind Multisignatures for Anonymous Tokens with Decentralized IssuanceabstractWe propose the first constructions of anonymous tokens with decentralized issuance. Namely, we consider a dynamic set of signers/issuers; a user can obtain a token from any subset of the signers, which is publicly verifiable and unlinkable to the issuance process. To realize this new primitive we formalize the notion of blind multi-signatures (BMS), which allow a user to interact with multiple signers to obtain a (compact) signature; even if all the signers collude they are unable to link a signature to an interaction with any of them. We then present two BMS constructions, one based on BLS signatures and a second based on discrete logarithms without pairings. We prove security of both our constructions in the Algebraic Group Model. We also provide a proof-of-concept implementation and show that it has low-cost verification, which is the most critical operation in blockchain applications. Ioanna Karantaidou, Omar Renawi, Foteini Baldimtsi, Nikolaos Kamarinakis, Jonathan Katz, Julian Loss |
CCS | 6 |
| 2024 | Twinkle: Threshold Signatures from DDH with Full Adaptive Security
Renas Bacho, Julian Loss, Stefano Tessaro, Benedikt Wagner, Chenzhi Zhu |
EUROCRYPT (1) | 2 |
| 2024 | A Holistic Security Analysis of Monero Transactions
Cas Cremers, Julian Loss, Benedikt Wagner |
EUROCRYPT (3) | 2 |
| 2024 | Early Stopping for Any Number of Corruptions
Julian Loss, Jesper Buus Nielsen |
EUROCRYPT (3) | 1 |
| 2024 | Efficient Agreement Over Byzantine Gossip
Ran Cohen, Julian Loss, Tal Moran |
FC (1) | 2 |
| 2024 | Sweep-UC: Swapping Coins PrivatelyabstractFair exchange (also referred to as atomic swap) is a fundamental operation in any cryptocurrency that allows users to atomically exchange coins. While a large body of work has been devoted to this problem, most solutions lack on-chain privacy. Thus, coins retain a public transaction history which is known to degrade the fungibility of a currency. This has led to a flourishing line of related research on fair exchange with privacy guarantees. Existing protocols either rely on heavy scripting (which also degrades fungibility and leads to high transaction fees), do not support atomic swaps across a wide range of currencies, or come with incomplete security proofs.To overcome these limitations, we introduce Sweep-UC1, the first fair exchange protocol that simultaneously is efficient, minimizes scripting, and is compatible with a wide range of currencies (more than the state of the art). We build SweepUC from modular sub-protocols and give a rigorous security analysis in the UC framework. Many of our tools and security definitions can be used in standalone fashion and may serve as useful components for future constructions of fair exchange. Lucjan Hanzlik, Julian Loss, Sri Aravinda Krishnan Thyagarajan, Benedikt Wagner |
SP | 2 |
| 2024 | Consensus in the Presence of Overlapping Faults and Total Omission
Julian Loss, Kecheng Shi 0001, Gilad Stern |
TCC (1) | 1 |
| 2023 | A New Look at Blockchain Leader Election: Simple, Efficient, Sustainable and Post-QuantumabstractIn this work, we study the blockchain leader election problem. The purpose of such protocols is to elect a leader who decides on the next block to be appended to the blockchain, for each block proposal round. Solutions to this problem are vital for the security of blockchain systems. We introduce an efficient blockchain leader election method with security based solely on standard assumptions for cryptographic hash functions (rather than public-key cryptographic assumptions) and that does not involve a racing condition as in Proof-of-Work based approaches. Thanks to the former feature, our solution provides the highest confidence in security, even in the post-quantum era. A particularly scalable application of our solution is in the Proof-of-Stake setting, and we investigate our solution in the Algorand blockchain system. We believe our leader election approach can be easily adapted to a range of other blockchain settings. Muhammed F. Esgin, Oguzhan Ersoy, Veronika Kuchta, Julian Loss, Amin Sakzad, Ron Steinfeld, Xiangwen Yang, Raymond K. Zhao |
AsiaCCS | 4 |
| 2023 | Adaptively Secure (Aggregatable) PVSS and Application to Distributed Randomness BeaconsabstractPublicly Verifiable Secret Sharing (PVSS) is a fundamental primitive that allows to share a secret S among n parties via a publicly verifiable transcript T. Existing (efficient) PVSS are only proven secure against static adversaries who must choose who to corrupt ahead of a protocol execution. As a result, any protocol (e.g., a distributed randomness beacon) that builds on top of such a PVSS scheme inherits this limitation. To overcome this barrier, we revisit the security of PVSS under adaptive corruptions and show that, surprisingly, many protocols from the literature already achieve it in a meaningful way: Renas Bacho, Julian Loss |
CCS | 2 |
| 2023 | Abraxas: Throughput-Efficient Hybrid Asynchronous ConsensusabstractProtocols for state-machine replication (SMR) often trade off performance for resilience to network delay. In particular, protocols for asynchronous SMR tolerate arbitrary network delay but sacrifice throughput/latency when the network is fast, while partially synchronous protocols have good performance in a fast network but fail to make progress if the network experiences high delay. Existing hybrid protocols are resilient to arbitrary network delay and have good performance when the network is fast, but suffer from high overhead (''thrashing'') if the network repeatedly switches between being fast and slow, e.g., in a network that is typically fast but has intermittent message delays. Erica Blum, Jonathan Katz, Julian Loss, Kartik Nayak, Simon Ochsenreither |
CCS | 3 |
| 2023 | Analyzing the Real-World Security of the Algorand BlockchainabstractThe Algorand consensus protocol is interesting both in theory and in practice. On the theoretical side, to achieve adaptive security, it introduces the novel idea of player replaceability, where each step of the protocol is executed by a different randomly selected committee whose members remain secret until they send their first and only message. The protocol provides consistency under arbitrary network conditions and liveness under intermittent network partitions. On the practical side, the protocol is used to secure the Algorand cryptocurrency, whose total value is approximately 850M at the time of writing. Erica Blum, Derek Leung, Julian Loss, Jonathan Katz, Tal Rabin |
CCS | 3 |
| 2023 | Concurrent Security of Anonymous Credentials Light, RevisitedabstractWe revisit the concurrent security guarantees of the well-known Anonymous Credentials Light (ACL) scheme (Baldimtsi and Lysyanskaya, CCS'13). This scheme was originally proven secure when executed sequentially, and its concurrent security was left as an open problem. A later work of Benhamouda et al. (EUROCRYPT'21) gave an efficient attack on ACL when executed concurrently, seemingly resolving this question once and for all. Julia Kastner 0001, Julian Loss, Omar Renawi |
CCS | 2 |
| 2023 | Network-Agnostic Security Comes (Almost) for Free in DKG and MPC
Renas Bacho, Daniel Collins 0001, Chen-Da Liu-Zhang, Julian Loss |
CRYPTO (1) | 4 |
| 2023 | Rai-Choo! Evolving Blind Signatures to the Next Level
Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
EUROCRYPT (5) | 2 |
| 2023 | Token meets Wallet: Formalizing Privacy and Revocation for FIDO2abstractThe FIDO2 standard is a widely-used class of challenge-response type protocols that allows to authenticate to an online service using a hardware token. Barbosa et al. (CRYPTO ‘21) provided the first formal security model and analysis for the FIDO2 standard. However, their model has two shortcomings: (1) It does not include privacy, one of the key features claimed by FIDO2. (2) It only covers tokens that store all secret keys locally. In contrast, due to limited memory, most existing FIDO2 tokens either derive all secret keys from a common seed or store keys on the server (the latter approach is also known as key wrapping).In this paper, we revisit the security of the WebAuthn component of FIDO2 as implemented in practice. Our contributions are as follows. (1) We adapt the model of Barbosa et al. so as to capture authentication tokens using key derivation or key wrapping. (2) We provide the first formal definition of privacy for the WebAuthn component of FIDO2. We then prove the privacy of this component in common FIDO2 token implementations if the underlying building blocks are chosen appropriately. (3) We address the unsolved problem of global key revocation in FIDO2. To this end, we introduce and analyze a simple revocation procedure that builds on the popular BIP32 standard used in cryptocurrency wallets and can efficiently be implemented with existing FIDO2 servers. Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
SP | 2 |
| 2023 | Zombies and Ghosts: Optimal Byzantine Agreement in the Presence of Omission Faults
Julian Loss, Gilad Stern |
TCC (4) | 1 |
| 2022 | How Byzantine is a Send Corruption?
Karim M. El Defrawy, Julian Loss, Ben Terner |
ACNS | 2 |
| 2022 | State Machine Replication Under Changing Network Conditions
Andreea B. Alexandru, Erica Blum, Jonathan Katz, Julian Loss |
ASIACRYPT (1) | 4 |
| 2022 | Efficient Adaptively-Secure Byzantine Agreement for Long Messages
Amey Bhangale, Chen-Da Liu-Zhang, Julian Loss, Kartik Nayak |
ASIACRYPT (1) | 3 |
| 2022 | The Abe-Okamoto Partially Blind Signature Scheme Revisited
Julia Kastner 0001, Julian Loss, Jiayu Xu 0001 |
ASIACRYPT (4) | 2 |
| 2022 | On the Adaptive Security of the Threshold BLS Signature SchemeabstractThreshold signatures are a crucial tool for many distributed protocols. As shown by Cachin, Kursawe, and Shoup (PODC '00), schemes with unique signatures are of particular importance, as they allow to implement distributed coin flipping very efficiently and without any timing assumptions. This makes them an ideal building block for (inherently randomized) asynchronous consensus protocols. The threshold-BLS signature of Boldyreva (PKC '03) is both unique and very compact, but unfortunately lacks a security proof against adaptive adversaries. Thus, current consensus protocols either rely on less efficient alternatives or are not adaptively secure. In this work, we revisit the security of the threshold BLS signature by showing the following results, assuming t adaptive corruptions: - We give a modular security proof that follows a two-step approach: 1) We introduce a new security notion for distributed key generation protocols (DKG). We show that it is satisfied by several protocols that previously only had a static security proof. 2) Assuming any DKG protocol with this property, we then prove unforgeability of the threshold BLS scheme. Our reductions are tight and can be used to substantiate real-world parameter choices. - To justify our use of strong assumptions such as the algebraic group model (AGM) and the hardness of one-more-discrete logarithm (OMDL), we prove an impossibility result: Even in the AGM, a strong interactive assumption is required in order to prove the scheme secure. Renas Bacho, Julian Loss |
CCS | 2 |
| 2022 | (Nondeterministic) Hardness vs. Non-malleability
Marshall Ball, Dana Dachman-Soled, Julian Loss |
CRYPTO (1) | 3 |
| 2022 | PI-Cut-Choo and Friends: Compact Blind Signatures via Parallel Instance Cut-and-Choose and More
Rutchathon Chairattana-Apirom, Lucjan Hanzlik, Julian Loss, Anna Lysyanskaya, Benedikt Wagner |
CRYPTO (3) | 3 |
| 2022 | Gossiping for Communication-Efficient Broadcast
Georgios Tsimos, Julian Loss, Charalampos Papamanthou |
CRYPTO (3) | 2 |
| 2022 | Optimal Clock Synchronization with SignaturesabstractCryptographic signatures can be used to increase the resilience of distributed systems against adversarial attacks, by increasing the number of faulty parties that can be tolerated. While this is well-studied for consensus, it has been underexplored in the context of fault-tolerant clock synchronization, even in fully connected systems. Here, the honest parties of an n-node system are required to compute output clocks of small skew (i.e., phase offset) despite local clock rates varying between 1 and ϑ > 1, end-to-end communication delays varying between d - u and d, and the interference from malicious parties. Known algorithms with (trivially optimal) resilience of [n/2] - 1 improve over the tight bound of [n/3] - 1 holding without signatures for any skew bound [6, 18], but incur skew d [1] or Ω(n(u + (ϑ - 1)d)) [14]. Since typically d >> u and ϑ - 1 « 1, this is far from the lower bound of u + (ϑ - 1)d that applies even in the fault-free case [3]. Christoph Lenzen 0001, Julian Loss |
PODC | 2 |
| 2022 | On the (in)Security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova 0001 |
J. Cryptol. | 3 |
| 2021 | Algebraic Adversaries in the Universal Composability Framework
Michel Abdalla, Manuel Barbosa, Jonathan Katz, Julian Loss, Jiayu Xu 0001 |
ASIACRYPT (3) | 4 |
| 2021 | Tardigrade: An Atomic Broadcast Protocol for Arbitrary Network Conditions
Erica Blum, Jonathan Katz, Julian Loss |
ASIACRYPT (2) | 3 |
| 2021 | Boosting the Security of Blind Signature Schemes
Jonathan Katz, Julian Loss, Michael Rosenberg |
ASIACRYPT (4) | 2 |
| 2021 | The Exact Security of BIP32 WalletsabstractIn many cryptocurrencies, the problem of key management has become one of the most fundamental security challenges. Typically, keys are kept in designated schemes called wallets, whose main purpose is to store these keys securely. One such system is the BIP32 wallet (Bitcoin Improvement Proposal 32), which since its introduction in 2012 has been adopted by countless Bitcoin users and is one of the most frequently used wallet system today. Surprisingly, very little is known about the concrete security properties offered by this system. In this work, we propose the first formal analysis of the BIP32 system in its entirety and without any modification. Building on the recent work of Das et al. (CCS '19), we put forth a formal model for hierarchical deterministic wallet systems (such as BIP32) and give a security reduction in this model from the existential unforgeability of the ECDSA signature algorithm that is used in BIP32. We conclude by giving concrete security parameter estimates achieved by the BIP32 standard, and show that by moving to an alternative key derivation method we can achieve a tighter reduction offering an additional 20 bits of security (111 vs. 91 bits of security) at no additional costs. Poulami Das 0003, Andreas Erwig, Sebastian Faust, Julian Loss, Siavash Riahi 0002 |
CCS | 4 |
| 2021 | On the (in)security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova 0001 |
EUROCRYPT (1) | 3 |
| 2021 | A New Way to Achieve Round-Efficient Byzantine AgreementabstractMinimizing the round complexity of Byzantine Agreement (BA) protocols is a fundamental problem in distributed computing. The typical approach to achieve round efficient (randomized) BA is to have a weak form of BA, called graded consensus (GC), followed by a distributed coin, and to repeat this process until some termination condition is met---as introduced by Feldman and Micali (STOC'88). Matthias Fitzi, Chen-Da Liu-Zhang, Julian Loss |
PODC | 3 |
| 2020 | MPC with Synchronous Security and Asynchronous Responsiveness
Chen-Da Liu-Zhang, Julian Loss, Ueli Maurer, Tal Moran, Daniel Tschudi |
ASIACRYPT (3) | 2 |
| 2020 | A Classification of Computational Assumptions in the Algebraic Group Model
Balthazar Bauer, Georg Fuchsbauer, Julian Loss |
CRYPTO (2) | 3 |
| 2020 | Always Have a Backup Plan: Fully Secure Synchronous MPC with Asynchronous Fallback
Erica Blum, Chen-Da Liu-Zhang, Julian Loss |
CRYPTO (2) | 3 |
| 2020 | Lattice-Based Blind Signatures, Revisited
Eduard Hauck, Eike Kiltz, Julian Loss, Ngoc Khanh Nguyen 0001 |
CRYPTO (2) | 3 |
| 2020 | Asynchronous Byzantine Agreement with Subquadratic Communication
Erica Blum, Jonathan Katz, Chen-Da Liu-Zhang, Julian Loss |
TCC (1) | 4 |
| 2020 | On the Security of Time-Lock Puzzles and Timed Commitments
Jonathan Katz, Julian Loss, Jiayu Xu 0001 |
TCC (3) | 2 |
| 2019 | A Formal Treatment of Deterministic WalletsabstractIn cryptocurrencies such as Bitcoin or Ethereum, users control funds via secret keys. To transfer funds from one user to another, the owner of the money signs a new transaction that transfers the funds to the new recipient. This makes secret keys a highly attractive target for attacks, and has lead to prominent examples where millions of dollars worth in cryptocurrency have been stolen. To protect against these attacks, a widely used approach are so-called hot/cold wallets. In a hot/cold wallet system, the hot wallet is permanently connected to the network, while the cold wallet stores the secret key and is kept without network connection. In this work, we propose the first comprehensive security model for hot/cold wallets and develop wallet schemes that are provable secure within these models. At the technical level our main contribution is to provide a new provably secure ECDSA-based hot/cold wallet scheme that can be integrated into legacy cryptocurrencies such as Bitcoin. Our construction and security analysis uses a modular approach, where we show how to generically build secure hot/cold wallets from signature schemes that exhibit a rerandomizing property of the keys. Poulami Das 0003, Sebastian Faust, Julian Loss |
CCS | 3 |
| 2019 | A Modular Treatment of Blind Signatures from Identification Schemes
Eduard Hauck, Eike Kiltz, Julian Loss |
EUROCRYPT (3) | 3 |
| 2019 | On the Security of Two-Round Multi-SignaturesabstractA multi-signature scheme allows a group of signers to collaboratively sign a message, creating a single signature that convinces a verifier that every individual signer approved the message. The increased interest in technologies to decentralize trust has triggered the proposal of highly efficient two-round Schnorr-based multi-signature schemes designed to scale up to thousands of signers, namely BCJ by Bagherzandi et al. (CCS 2008), MWLD by Ma et al. (DCC 2010), CoSi by Syta et al. (S&P 2016), and MuSig by Maxwell et al. (ePrint 2018). In this work, we point out serious security issues in all currently known two-round multi-signature schemes (without pairings). First, we prove that none of the schemes can be proved secure without radically departing from currently known techniques. Namely, we show that if the one-more discrete-logarithm problem is hard, then no algebraic reduction exists that proves any of these schemes secure under the discrete-logarithm or one-more discrete-logarithm problem. We point out subtle flaws in the published security proofs of the above schemes (except CoSi, which was not proved secure) to clarify the contradiction between our result and the existing proofs. Next, we describe practical sub-exponential attacks on all schemes, providing further evidence to their insecurity. Being left without two-round multi-signature schemes, we present mBCJ, a variant of the BCJ scheme that we prove secure under the discrete-logarithm assumption in the random-oracle model. Our experiments show that mBCJ barely affects scalability compared to CoSi, allowing 16384 signers to collaboratively sign a message in about 2 seconds, making it a highly practical and provably secure alternative for large-scale deployments. Manu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz, Julian Loss, Gregory Neven, Igors Stepanovs |
IEEE Symposium on Security and Privacy | 5 |
| 2019 | Synchronous Consensus with Optimal Asynchronous Fallback Guarantees
Erica Blum, Jonathan Katz, Julian Loss |
TCC (1) | 3 |
| 2018 | The Algebraic Group Model and its Applications
Georg Fuchsbauer, Eike Kiltz, Julian Loss |
CRYPTO (2) | 3 |
| 2018 | Strong Separations Between Broadcast and Authenticated ChannelsabstractIn the theory of distributed systems and cryptography one considers a setting with n parties, (often) connected via authenticated bilateral channels, who want to achieve a certain goal even if some fraction of the parties is dishonest. A classical goal of this type is to construct a broadcast channel. A broadcast channel guarantees that all honest recipients get the same value v (consistency) and, if the sender is honest, that v is the sender's input (validity). Lamport et al. showed that it is possible to construct broadcast if and only if the fraction of cheaters is less than a third. A natural question, first raised by Lamport, is whether there are weaker, still useful primitives achievable from authenticated channels. He proposed weak broadcast, where the validity condition must hold only if all parties are honest, and showed that it can be achieved with an unbounded number of protocol rounds, while broadcast cannot, suggesting that weak broadcast is in a certain sense weaker than broadcast. The purpose of this paper is to deepen the investigation of the separation between broadcast and authenticated channels. This is achieved by proving the following results. First, we prove a stronger impossibility result for 3-party broadcast. Even if two of the parties can broadcast, one can not achieve broadcast for the third party. Second, we prove a strong separation between authenticated channels and broadcast by exhibiting a new primitive, called XOR-cast, which satisfies two conditions: (1) XOR-cast is strongly unachievable (even with small error probability) from authenticated channels (which is not true for weak broadcast), and (2) broadcast is strongly unachievable from XOR-cast (and authenticated channels). This demonstrates that the hierarchy of primitives has a more complex structure than previously known. Third, we prove a strong separation between weak broadcast and broadcast which is not implied by Lamport's results. The proofs of these results requires the generalization of known techniques for impossibility proofs. Julian Loss, Ueli Maurer, Daniel Tschudi |
DISC | 1 |
| 2017 | Tightly-Secure Signatures from Five-Move Identification Protocols
Eike Kiltz, Julian Loss, Jiaxin Pan 0001 |
ASIACRYPT (3) | 2 |
| 2016 | Hierarchy of three-party consistency specificationsabstractIn the theory of distributed systems and in cryptography one considers a set of n parties which wish to securely perform a certain computation, even if some of the parties are dishonest. Broadcast, one of the most fundamental and widely used such primitives, allows one (possibly cheating) party to distribute a value m consistently to the other parties, in a context where only bilateral (authenticated) channels between parties are available. A well-known result [LSP82] states that this is possible if and only if strictly less than a third of the parties are dishonest. Broadcast guarantees a very strong form of consistency. This paper investigates generalizations of the broadcast setting in two directions: weaker forms of consistency guarantees are considered, and other resources than merely bilateral channels are assumed to be available. The ultimate goal of this line of work is to arrive at a complete classification of consistency specifications [Mau04]. As a concrete result in this direction we present a complete classification of three-party specifications with a binary input and binary outputs. Julian Loss, Ueli Maurer, Daniel Tschudi |
ISIT | 1 |