EDBT 2026 Demo / reviewers in the wild / expert
Matteo Campanelli
dblp:22/7530
· DBLP profile ↗
22ranked-venue papers
18as first author
17since 2021 · last 2026
0000-0001-8184-4704ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 17 first-author · 17 since 2021Theory of computation · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Practical Subvector Commitments with Optimal Opening Complexity
Matteo Campanelli |
ACNS (1) | 1 |
| 2026 | On the Simulation-Extractability of Proof-Carrying Data
Behzad Abdolmaleki, Matteo Campanelli, Quang Dao, Hamidreza Khoshakhlagh |
PKC (3) | 2 |
| 2026 | On Composing AGM-Secure Functionalities with Cryptographic Proofs - Applications to Unbounded-Depth IVC and More
Matteo Campanelli, Dario Fiore 0001, Mahak Pancholi |
PKC (3) | 1 |
| 2026 | General Techniques for Building SNARKs over the Integers
Matteo Campanelli, Mathias Hall-Andersen |
PKC (3) | 1 |
| 2025 | Universally Composable SNARKs with Transparent Setup without Programmable Random Oracle
Christian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo 0001, Luisa Siniscalchi |
CRYPTO (7) | 2 |
| 2025 | SNARKs for Virtual Machines Are Non-malleable
Matteo Campanelli, Antonio Faonio, Luigi Russo 0001 |
EUROCRYPT (4) | 1 |
| 2025 | Short Paper: Curve Forests - Transparent Zero-Knowledge Set Membership with Batching and Strong Security
Matteo Campanelli, Mathias Hall-Andersen, Simon Holmgaard Kamp |
FC | 1 |
| 2025 | Natively Compatible Super-Efficient Lookup Arguments and How to Apply Them
Matteo Campanelli, Dario Fiore 0001, Rosario Gennaro |
J. Cryptol. | 1 |
| 2024 | Advancing Scalability in Decentralized Storage: A Novel Approach to Proof-of-Replication via Polynomial Evaluation
Giuseppe Ateniese, Foteini Baldimtsi, Matteo Campanelli, Danilo Francati, Ioanna Karantaidou |
CRYPTO (2) | 3 |
| 2023 | Witness-Authenticated Key Exchange, Revisited: Extensions to Groups, Improved Models, Simpler ConstructionsabstractWe study witness-authenticated key exchange (WAKE), in which parties authenticate through knowledge of a witness to any NP statement. WAKE achieves generic authenticated key exchange in the absence of trusted parties; WAKE is most suitable when a certificate authority is either unavailable or undesirable, as in highly decentralized networks. In practice WAKE approximates witness encryption, its elusive non-interactive analogue, at the cost of minimal interaction. This work is the first to propose, model and build witness-authenticated key exchange amongst groups of more than two parties, as well as the first to provide practical and provably secure constructions in the two-party case for general NP statements. Specifically our contributions are: both game-based and universally composable (Canetti, FOCS ’01) definitions for WAKE along with equivalence conditions between the two definitions, a highly general compiler that introduces witness-authentication to any key exchange protocol along with, as a direct consequence, a three-round group WAKE protocol from DDH and signatures of knowledge (SOK), and an optimized two-round group WAKE construction from DDH and SOK along with experimental benchmarks to demonstrate concrete practicality. Additionally, we study the specialized two-party case and provide a critique of prior work on this topic (Ngo et al., Financial Crypto ’21) by pinpointing nontrivial weaknesses in the model, constructions and security proofs seen therein. We rectify those limitations with this work, significantly diverging in our techniques, design and approach. Matteo Campanelli, Rosario Gennaro, Kelsey Melissaris, Luca Nizzardo |
FC (1) | 1 |
| 2023 | Curve Trees: Practical and Transparent Zero-Knowledge Accumulators
Matteo Campanelli, Mathias Hall-Andersen, Simon Holmgaard Kamp |
USENIX Security Symposium | 1 |
| 2023 | Zero-knowledge proofs for set membership: efficient, succinct, modularabstractAbstract We consider the problem of proving in zero knowledge that an element of a public set satisfies a given property without disclosing the element, i.e., for some u , “ $$u \in S$$ u ∈ S and P ( u ) holds”. This problem arises in many applications (anonymous cryptocurrencies, credentials or whitelists) where, for privacy or anonymity reasons, it is crucial to hide certain data while ensuring properties of such data. We design new modular and efficient constructions for this problem through new commit-and-prove zero-knowledge systems for set membership , i.e. schemes proving $$u \in S$$ u ∈ S for a value u that is in a public commitment $$c_u$$ c u . We also extend our results to support non-membership proofs , i.e. proving $$u \notin S$$ u ∉ S . Being commit-and-prove, our solutions can act as plug-and-play modules in statements of the form “ $$u \in S$$ u ∈ S and P ( u ) holds” by combining our set (non-)membership systems with any other commit-and-prove scheme for P ( u ). Also, they work with Pedersen commitments over prime order groups which makes them compatible with popular systems such as Bulletproofs or Groth16. We implemented our schemes as a software library, and tested experimentally their performance. Compared to previous work that achieves similar properties—the clever techniques combining zkSNARKs and Merkle Trees in Zcash—our solutions offer more flexibility, shorter public parameters and $$3.7 \times $$ 3.7 × – $$30\times $$ 30 × faster proving time for a set of size $$2^{64}$$ 2 64 . Daniel Benarroch, Matteo Campanelli, Dario Fiore 0001, Kobi Gurkan, Dimitris Kolonelos |
Des. Codes Cryptogr. | 2 |
| 2022 | Veksel: Simple, Efficient, Anonymous Payments with Large Anonymity Sets from Well-Studied AssumptionsabstractWe propose Veksel, a simple generic paradigm for constructing efficient non-interactive coin mixes. The central component in our work is a concretely efficient proof π1-many that a homomorphic commitment c* is a rerandomization of a commitment c ∈ {c1, …,cℓ} without revealing c. We formalize anonymous account-based cryptocurrency as a universally composable functionality and show how to efficiently instantiate it using π1-many in a straightforward way. We instantiate and implement π1-many from Strong-RSA, DDH and random oracles targeting ≈ 112 bits of security. The resulting NIZK has constant size (|π1-many| = 5.3 KB) and constant proving/verification time (≈ 90 ms), on an already accumulated set. Compared to ZCash---which offers comparable marginal verification cost and an anonymity set consisting of every existing transaction---our transactions are larger (6.2 KB) and verification is slower. On the other hand, Veksel relies on better studied assumptions, has no expensive trusted setup for proofs and is arguably simpler to implement. Additionally we think that π1-many might be interesting in other applications, e.g. proving possession of some credential posted on-chain. The efficiency of our concrete NIZK relies on a new Ristretto-friendly elliptic curve, Jabberwock, that is of independent interest: it can be used to efficiently prove statements on "committments on commitments'' in Bulletproofs. Matteo Campanelli, Mathias Hall-Andersen |
AsiaCCS | 1 |
| 2022 | Encryption to the Future - A Paradigm for Sending Secret Messages to Future (Anonymous) Committees
Matteo Campanelli, Bernardo Machado David, Hamidreza Khoshakhlagh, Anders Konring, Jesper Buus Nielsen |
ASIACRYPT (3) | 1 |
| 2022 | Linear-Map Vector Commitments and Their Practical Applications
Matteo Campanelli, Anca Nitulescu, Carla Ràfols, Alexandros Zacharakis, Arantxa Zapico |
ASIACRYPT (4) | 1 |
| 2022 | Succinct Zero-Knowledge Batch Proofs for Set AccumulatorsabstractCryptographic accumulators are a common solution to proving information about a large set S. They allow one to compute a short digest of S and short certificates of some of its basic properties, notably membership of an element. Accumulators also allow one to track set updates: a new accumulator is obtained by inserting/deleting a given element. In this work we consider the problem of generating membership and update proofs for \em batches of elements so that we can succinctly prove additional properties of the elements (i.e., proofs are of constant size regardless of the batch size), and we can preserve privacy. Solving this problem would allow obtaining blockchain systems with improved privacy and scalability. Matteo Campanelli, Dario Fiore 0001, Semin Han, Jihye Kim 0001, Dimitris Kolonelos, Hyunok Oh |
CCS | 1 |
| 2021 | Lunar: A Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions
Matteo Campanelli, Antonio Faonio, Dario Fiore 0001, Anaïs Querol, Hadrián Rodríguez |
ASIACRYPT (3) | 1 |
| 2020 | Incrementally Aggregatable Vector Commitments and Applications to Verifiable Decentralized Storage
Matteo Campanelli, Dario Fiore 0001, Nicola Greco, Dimitris Kolonelos, Luca Nizzardo |
ASIACRYPT (2) | 1 |
| 2019 | LegoSNARK: Modular Design and Composition of Succinct Zero-Knowledge ProofsabstractWe study the problem of building non-interactive proof systems modularly by linking small specialized "gadget" SNARKs in a lightweight manner. Our motivation is both theoretical and practical. On the theoretical side, modular SNARK designs would be flexible and reusable. Also, previous works (e.g., Geppetto) consider They have been successfully employed in previous works.(cite prev papers ). These approaches, however, tend to be ad-hoc and to reinventing the wheel. We propose to fill this gap. In practice, specialized SNARKs have the potential to be more efficient than general-purpose schemes, on which most existing works have focused. If a computation naturally presents different "components" (e.g. one arithmetic circuit and one boolean circuit), a general-purpose scheme would homogenize them to a single representation with a subsequent cost in performance. Through a modular approach one could instead exploit the nuances of a computation and choose the best gadget for each component. Our contribution is LegoSNARK, a "toolbox" (or framework) for commit-and-prove zkSNARKs (CP-SNARKs) that includes: 1) General composition tools: build new CP-SNARKs from proof gadgets for basic relationssimply. Formalize notion of cc-SNARK. 2) A "lifting" tool: a compiler to add commit-and-prove capabilities to a broad class of existing zkSNARKsefficiently. This makes them interoperable (linkable) within the same computation. For example, one QAP-based scheme can be used prove one component; another GKR-based scheme can be used to prove another. 3) A collection of succinct proof gadgets for a variety of relations. Additionally, through our framework and gadgets, we are able to obtain new succinct proof systems. Notably: -- LegoGro16, a commit-and-prove version of Groth16 zkSNARK, that operates over data committed with a classical Pedersen vector commitment, and that achieves a 5000× speedup in proving time. -- LegoUAC, a pairing-based SNARK for arithmetic circuits that has a universal, circuit-independent, CRS, and proving time linear in the number of circuit gates (vs. the recent scheme of Groth et al. (CRYPTO'18) with quadratic CRS and quasilinear proving time). -- LegoMM, a CP-SNARK for matrix multiplication that achieves optimal proving complexity. Matteo Campanelli, Dario Fiore 0001, Anaïs Querol |
CCS | 1 |
| 2018 | Fine-Grained Secure Computation
Matteo Campanelli, Rosario Gennaro |
TCC (2) | 1 |
| 2017 | Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesabstractZero Knowledge Contingent Payment (ZKCP) protocols allow fair exchange of sold goods and payments over the Bitcoin network. In this paper we point out two main shortcomings of current proposals for ZKCP, and propose ways to address them. Matteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca Nizzardo |
CCS | 1 |
| 2009 | A New Algorithm for Efficient Pattern Matching with Swaps
Matteo Campanelli, Domenico Cantone, Simone Faro |
IWOCA | 1 |