EDBT 2026 Demo / reviewers in the wild / expert
Hong-Sheng Zhou
dblp:23/6726
· DBLP profile ↗
50ranked-venue papers
0as first author
20since 2021 · last 2026
0000-0003-3534-6629ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 17 since 2021Theory of computation · 10 · 1 since 2021Systems, architecture and hardware · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bandwidth-Efficient Robust Threshold ECDSA in Three RoundsabstractThreshold ECDSA schemes distribute the capability of issuing signatures to multiple parties. They have been used in practical MPC wallets holding cryptocurrencies. However, most prior protocols are not robust, wherein even one misbehaving or non-responsive party would mandate an abort. Robust schemes have been proposed (Wong et al., NDSS ’23, ’24), but they do not match state-of-the-art number of rounds which is only three (Doerner et al., S&P ’24). In this work, we propose robust threshold ECDSA schemes RompSig-Q and RompSig-L that each take three rounds (where the first two are broadcasts, whereas the non-robust scheme of Doerner et al. uses no broadcasts). Building on the works of Wong et al. and further optimized towards saving bandwidth, they respectively take each signer (1.0t+ 1.6) KiB and 3.0 KiB outbound broadcast communication, and thus exhibit bandwidth efficiency that is competitive in practical scenarios where broadcasts are natively handled. RompSig-Q preprocesses multiplications and features fast online signing; RompSig-L leverages threshold CL encryption for scalability and dynamic participation. Yingjie Lyu, Zengpeng Li 0001, Hong-Sheng Zhou, Haiyang Xue, Mei Wang 0003, Shuchao Wang, Mengling Liu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Attention is still what you need: Another Round of Exploring Shoup's GGM
Taiyu Wang, Cong Zhang 0001, Hong-Sheng Zhou, Xin Wang 0001, Kui Ren 0001, Chun Chen 0001 |
ASIACRYPT (4) | 3 |
| 2025 | Threshold ECDSA in Two RoundsabstractWe propose the first two-round multi-party signing protocol for the Elliptic Curve Digital Signature Algorithm (ECDSA) in the threshold-optimal setting, reducing the number of rounds by one compared to the state of the art (Doerner et al., S&P '24). We also resolve the security issue of presigning pointed out by Groth and Shoup (Eurocrypt '22), evading a security loss that increases with the number of pre-released, unused presignatures, for the first time among threshold-optimal schemes. Our construction builds on Non-Interactive Multiplication (NIM), a notion proposed by Boyle et al. (PKC '25), which allows parties to evaluate multiplications on secret-shared values in one round. In particular, we use the construction of Abram et al. (Eurocrypt '24) instantiated with class groups. The setup is minimal and transparent, consisting of only two class-group generators. The signing protocol is efficient in bandwidth, with a message size of 1.9 KiB at 128-bit security, and has competitive computational performance. Yingjie Lyu, Zengpeng Li 0001, Hong-Sheng Zhou |
CCS | 3 |
| 2025 | Best-Possible Unpredictable Proof-of-Stake: An Impossibility and a Practical DesignabstractThe proof-of-stake (PoS) protocols aim to reduce the unnecessary computing power waste seen in Bitcoin. Various practical and provably secure designs have been proposed, like Ouroboros Praos (Eurocrypt 2018) and Snow White (FC 2019). However, the essential security property of unpredictability in these protocols remains insufficiently explored. This paper delves into this property in the cryptographic setting to achieve the "best possible" unpredictability for PoS protocols.We first present an impossibility result for all PoS protocols under the single-extension design framework, where each honest player extends one chain per round. The state-of-the-art permissionless PoS protocols (e.g., Praos, Snow White, and more), are all under this single-extension framework. Our impossibility result states that, if a single-extension PoS protocol achieves the best possible unpredictability, then this protocol cannot be proven secure unless more than 73% of stake is honest.To overcome this impossibility, we introduce a new design framework called multi-extension PoS, allowing each honest player to extend multiple chains using greedy strategy in a round. This strategy allows us to construct a class of PoS protocols that achieve the best possible unpredictability. Additionally, we design a new tiebreak rule for the multi-extension protocol to choose the best chain that can be extended faster, ensuring that the adversary cannot slow-down the chain growth of honest players. It is noteworthy that these protocols can be proven secure, assuming a much smaller fraction (e.g., 57%) of stake to be honest.For a comprehensive security analysis in the cryptographic setting, we develop several new techniques. Analyzing chain growth becomes highly non-trivial as players can extend multiple chains. We introduce a new analysis framework using the Markov chain to assess the chain growth of a multi-extension protocol. To prove the common prefix property, we introduce a concept called "virtual chains" and present a reduction from the regular version of the common prefix to "common prefix w.r.t. virtual chains." Lei Fan 0002, Jonathan Katz, Zhenghao Lu, Phuc Thai, Hong-Sheng Zhou |
EuroS&P | 5 |
| 2025 | EquiBFT: A Framework for Achieving Fairness in BFT ConsensusabstractByzantine Fault-Tolerant (BFT) consensus protocols are increasingly utilized in blockchain environments. In such protocols, the leader node holds the authority to dictate the transaction order, potentially impacting the fairness of decentralized finance (DeFi) applications. For instance, attackers can exploit this to manipulate transaction order and conduct front-running attacks. The concept of order-fairness, which recently emerged, has become a critical property for preventing a single node from unilaterally determining transaction order. Protocols designed to uphold order-fairness often rely on the sequence in which transactions appear across the network, a factor that can be influenced by the network’s topology. However, this approach has inherent limitations, such as challenges in avoiding Condorcet cycles (Kelkar et al., Crypto 2020).To address these challenges, we propose a novel definition of fairness that requires concealing transaction content before ordering. Additionally, we extend the definitions of liveness and safety of consensus protocols to cover the transaction decryption process, guaranteeing the successful decryption of transactions. Based on the existing BFT protocol and utilizing threshold encryption algorithms, we designed a framework called EquiBFT which can incorporate fairness to BFT protocols. We have proven that the EquiBFT satisfies fairness while ensuring the liveness and safety. We implemented this framework based on HotStuff (Yin et al., PODC 2019) and validated its feasibility in a real-world network environment. Siwei Cai, Lei Fan 0002, Shengyun Liu, Hong-Sheng Zhou |
ICDCS | 4 |
| 2025 | Single-Input Functionality Against a Dishonest Majority: Practical and Round-Optimal
Zhelei Zhou, Bingsheng Zhang, Hong-Sheng Zhou, Kui Ren 0001 |
PKC (4) | 3 |
| 2025 | Efficient Garbled Pseudorandom Functions and Lookup Tables from Minimal Assumption
Wei-Kai Lin, Zhenghao Lu, Hong-Sheng Zhou |
TCC (1) | 3 |
| 2025 | Brief Announcement: Single-Round Broadcast: Impossibility, Feasibility, and More
Zhelei Zhou, Bingsheng Zhang, Hong-Sheng Zhou, Kui Ren 0001 |
DISC | 3 |
| 2024 | On the Complexity of Cryptographic Groups and Generic Group Models
Keyu Ji, Cong Zhang 0001, Taiyu Wang, Bingsheng Zhang, Hong-Sheng Zhou, Xin Wang 0001, Kui Ren 0001 |
ASIACRYPT (7) | 5 |
| 2024 | Practical Constructions for Single Input Functionality Against a Dishonest MajorityabstractSingle Input Functionality (SIF) is a special case of MPC, where only one distinguished party called dealer holds the secret input. SIF allows the dealer to complete a computation task and send to other parties their respective outputs without revealing any additional information about its secret input. SIF has many applications, including multiple-verifier zero-knowledge and verifiable relation sharing, etc. Recently, several works devote to round-efficient realization of SIF, and achieve 2-round communication in the honest majority setting (Applebaum et al., Crypto 2022; Baum et al., CCS 2022; Yang and Wang, Asiacrypt 2022). In this work, we focus on concrete efficiency and propose the first practical construction for SIF against a dishonest majority in the preprocessing model; moreover, the online phase of our protocol is only 2-round and is highly efficient, as it requires no cryptographic operations and achieves information theoretical security. For SIF among 5 parties, our scheme takes 152.34ms (total) to evaluate an AES-128 circuit with 7.36ms online time. Compared to the state-of-the-art (honest majority) solution (Baum et al., CCS 2022), our protocol is roughly 2 × faster in the online phase, although more preprocessing time is needed. Compared to the state-of-the-art generic MPC against a dishonest majority (Wang et al., CCS 2017; Cramer et al., Crypto 2018), our protocol outperforms them with respect to both total running time and online running time. Zhelei Zhou, Bingsheng Zhang, Hong-Sheng Zhou, Kui Ren 0001 |
EuroS&P | 3 |
| 2024 | Scalable Private Set Union, with Stronger Security
Yanxue Jia, Shifeng Sun 0001, Hong-Sheng Zhou, Dawu Gu |
USENIX Security Symposium | 3 |
| 2024 | Brief Announcement: Best-Possible Unpredictable Proof-Of-StakeabstractThe proof-of-stake (PoS) protocols aim to reduce the unnecessary computing power waste seen in Bitcoin. Various practical and provably secure designs have been proposed, like Ouroboros Praos (Eurocrypt 2018) and Snow White (FC 2019). However, the essential security property of unpredictability in these protocols remains insufficiently explored. This paper delves into this property in the cryptographic setting to achieve the "best possible" unpredictability for PoS. We first present an impossibility result for all PoS protocols under the single-extension design framework, where each honest player extends one chain per round. The state-of-the-art permissionless PoS protocols (e.g., Praos, Snow White, and more), are all under this single-extension framework. Our impossibility result states that, if a single-extension PoS protocol achieves the best possible unpredictability, then this protocol cannot be proven secure unless more than 73% of stake is honest. To overcome this impossibility, we introduce a new design framework called multi-extension PoS, allowing each honest player to extend multiple chains using a greedy strategy in a round. This strategy allows us to construct a class of PoS protocols that achieve the best possible unpredictability. It is noteworthy that these protocols can be proven secure, assuming a much smaller fraction (e.g., 57%) of stake to be honest. Lei Fan 0002, Jonathan Katz, Zhenghao Lu, Phuc Thai, Hong-Sheng Zhou |
DISC | 5 |
| 2023 | Endemic Oblivious Transfer via Random Oracles, Revisited
Zhelei Zhou, Bingsheng Zhang, Hong-Sheng Zhou, Kui Ren 0001 |
EUROCRYPT (1) | 3 |
| 2022 | A Universally Composable Non-interactive Aggregate Cash System
Yanxue Jia, Shifeng Sun 0001, Hong-Sheng Zhou, Dawu Gu |
ASIACRYPT (1) | 3 |
| 2022 | An Analysis of the Algebraic Group Model
Cong Zhang 0001, Hong-Sheng Zhou, Jonathan Katz |
ASIACRYPT (4) | 2 |
| 2022 | GUC-Secure Commitments via Random Oracles: New Impossibility and Feasibility
Zhelei Zhou, Bingsheng Zhang, Hong-Sheng Zhou, Kui Ren 0001 |
ASIACRYPT (4) | 3 |
| 2022 | Shuffle-based Private Set Union: Faster and More Secure
Yanxue Jia, Shifeng Sun 0001, Hong-Sheng Zhou, Jiajun Du, Dawu Gu |
USENIX Security Symposium | 3 |
| 2022 | Scriptable and composable SNARKs in the trusted hardware modelabstractNon-interactive zero-knowledge proof or argument (NIZK) systems are widely used in many security sensitive applications to enhance computation integrity, privacy and scalability. In such systems, a prover wants to convince one or more verifiers that the result of a public function is correctly computed without revealing the (potential) private input, such as the witness. In this work, we introduce a new notion, called scriptable SNARK, where the prover and verifier(s) can specify the function (or language instance) to be proven via a script. We formalize this notion in UC framework and provide a generic trusted hardware based solution. We then instantiate our solution in both SGX and Trustzone with Lua script engine. The system can be easily used by typical programmers without any cryptographic background. The benchmark result shows that our solution is better than all the known SNARK proof systems w.r.t. prover’s running time (1000 times faster), verifier’s running time, and the proof size. In addition, we also give a lightweight scriptable SNARK protocol for hardware with limited state, e.g., Θ ( λ ) bits. Finally, we show how the proposed scriptable SNARK can be readily deployed to solve many well-known problems in the blockchain context, e.g. verifier’s dilemma, fast joining for new players, etc. Zhelei Zhou, Bingsheng Zhang, Jiaqi Li 0023, Yajin Zhou, Yibiao Lu, Kui Ren 0001, Phuc Thai, Hong-Sheng Zhou |
J. Comput. Secur. | 9 |
| 2021 | Correlated Randomness Teleportation via Semi-trusted Hardware - Enabling Silent Multi-party Computation
Yibiao Lu, Bingsheng Zhang, Hong-Sheng Zhou, Lei Zhang 0006, Kui Ren 0001 |
ESORICS (2) | 3 |
| 2021 | Succinct Scriptable NIZK via Trusted Hardware
Bingsheng Zhang, Jiaqi Li 0023, Yajin Zhou, Phuc Thai, Hong-Sheng Zhou, Kui Ren 0001 |
ESORICS (1) | 6 |
| 2020 | 2-hop Blockchain: Combining Proof-of-Work and Proof-of-Stake Securely
Tuyet Duong, Lei Fan 0002, Jonathan Katz, Phuc Thai, Hong-Sheng Zhou |
ESORICS (2) | 5 |
| 2020 | Locally Decodable and Updatable Non-malleable Codes and Their Applications
Dana Dachman-Soled, Feng-Hao Liu, Elaine Shi, Hong-Sheng Zhou |
J. Cryptol. | 4 |
| 2019 | (Efficient) Universally Composable Oblivious Transfer Using a Minimal Number of Stateless Tokens
Seung Geol Choi, Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich, Hong-Sheng Zhou |
J. Cryptol. | 5 |
| 2019 | Leakage Resilience from Program Obfuscation
Dana Dachman-Soled, S. Dov Gordon, Feng-Hao Liu, Adam O'Neill, Hong-Sheng Zhou |
J. Cryptol. | 5 |
| 2018 | Leakage-Resilient Cryptography from Puncturable Primitives and Obfuscation
Yu Chen 0003, Yuyu Wang 0001, Hong-Sheng Zhou |
ASIACRYPT (2) | 3 |
| 2018 | Correcting Subverted Random Oracles
Alexander Russell, Qiang Tang 0005, Moti Yung, Hong-Sheng Zhou |
CRYPTO (2) | 4 |
| 2018 | A Generic Paradigm for Blockchain DesignabstractCryptocurrencies have recently gained huge popularity. It is desirable to come up with effective approaches to constructing better blockchain protocols. In this paper, inspired by the 2-hop design by Duong et al (ePrint 2016/716), we put forth a generic paradigm for blockchain design, called n-hop blockchain. It includes one main chain, which is supported by (n -- 1) supporting chains; hence, the main chain can achieve better security performance. In our paradigm, we show that our n-hop design can be easily extended to (n + 1)-hop design. To demonstrate the power of our paradigm, we showcase two instantiations: 2-hop blockchain variant, a combination of proof-of-stake and proof-of-work, and 3-hop blockchain variant, which is extended from 2-hop blockchain variant by adding Byzantine fault tolerance blockchain in 3rd hop. Phuc Thai, Laurent Njilla, Tuyet Duong, Lei Fan 0002, Hong-Sheng Zhou |
MobiQuitous | 5 |
| 2018 | Multi-key FHE for multi-bit messages
Zengpeng Li 0001, Chunguang Ma, Hong-Sheng Zhou |
Sci. China Inf. Sci. | 3 |
| 2017 | Generic Semantic Security against a Kleptographic AdversaryabstractNotable recent security incidents have generated intense interest in adversaries which attempt to subvert---perhaps covertly---crypto\-graphic algorithms. In this paper we develop (IND-CPA) Semantically Secure encryption in this challenging setting. This fundamental encryption primitive has been previously studied in the "kleptographic setting," though existing results must relax the model by introducing trusted components or otherwise constraining the subversion power of the adversary: designing a Public Key System that is kletographically semantically secure (with minimal trust) has remained elusive to date. In this work, we finally achieve such systems, even when all relevant cryptographic algorithms are subject to adversarial (kleptographic) subversion. To this end we exploit novel inter-component randomized cryptographic checking techniques (with an offline checking component), combined with common and simple software engineering modular programming techniques (applied to the system's black box specification level). Moreover, our methodology yields a strong generic technique for the preservation of any semantically secure cryptosystem when incorporated into the strong kleptographic adversary setting. Alexander Russell, Qiang Tang 0005, Moti Yung, Hong-Sheng Zhou |
CCS | 4 |
| 2017 | Brief Announcement: Statement Voting and Liquid DemocracyabstractThe existing (election) voting systems, e.g., representative democracy, have many limitations and often fail to serve the best interest of the people in collective decision making. To address this issue, the concept of liquid democracy has been emerging as an alternative decision-making model to make better use of "the wisdom of crowds". Very recently, a few liquid democracy implementations, e.g. Google Votes and Decentralized Autonomous Organization (DAO), are released; however, those systems only focus on the functionality aspect, as no privacy/anonymity is considered. In this work, we, for the first time, provide a rigorous study of liquid democracy under the Universal Composability (UC) frame- work. In the literature, liquid democracy was achieved via two separate stages -- delegation and voting. We propose an efficient liquid democracy e-voting scheme that uni es these two stages. At the core of our design is a new voting concept called statement voting, which can be viewed as a natural extension of the conventional voting approaches. We remark that our statement voting can be extended to enable more complex voting and generic ledger-based non-interactive multi-party computation. We believe that the statement voting concept opens a door for constructing a new class of e-voting schemes. Bingsheng Zhang, Hong-Sheng Zhou |
PODC | 2 |
| 2016 | Cliptography: Clipping the Power of Kleptographic Attacks
Alexander Russell, Qiang Tang 0005, Moti Yung, Hong-Sheng Zhou |
ASIACRYPT (2) | 4 |
| 2016 | Fair and Robust Multi-party Computation Using a Global Transaction Ledger
Aggelos Kiayias, Hong-Sheng Zhou, Vassilis Zikas |
EUROCRYPT (2) | 2 |
| 2016 | Cryptography for Parallel RAM from Indistinguishability ObfuscationabstractSince many cryptographic schemes are about performing computation on data, it is important to consider a computation model which captures the prominent features of modern system architecture. Parallel random access machine (PRAM) is such an abstraction which not only models multiprocessor platforms, but also new frameworks supporting massive parallel computation such as MapReduce. Yu-Chi Chen 0001, Sherman S. M. Chow, Kai-Min Chung, Russell W. F. Lai, Wei-Kai Lin, Hong-Sheng Zhou |
ITCS | 6 |
| 2015 | Incoercible Multi-party Computation and Universally Composable Receipt-Free Voting
Joël Alwen, Rafail Ostrovsky, Hong-Sheng Zhou, Vassilis Zikas |
CRYPTO (2) | 3 |
| 2015 | Leakage-Resilient Circuits Revisited - Optimal Number of Computing Components Without Leak-Free Hardware
Dana Dachman-Soled, Feng-Hao Liu, Hong-Sheng Zhou |
EUROCRYPT (2) | 3 |
| 2015 | Locally Decodable and Updatable Non-malleable Codes and Their Applications
Dana Dachman-Soled, Feng-Hao Liu, Elaine Shi, Hong-Sheng Zhou |
TCC (1) | 4 |
| 2015 | Multi-Client Verifiable Computation with Stronger Security Guarantees
S. Dov Gordon, Jonathan Katz, Feng-Hao Liu, Elaine Shi, Hong-Sheng Zhou |
TCC (2) | 5 |
| 2014 | Multi-input Functional Encryption
Shafi Goldwasser, S. Dov Gordon, Vipul Goyal, Abhishek Jain 0002, Jonathan Katz, Feng-Hao Liu, Amit Sahai, Elaine Shi, Hong-Sheng Zhou |
EUROCRYPT | 9 |
| 2014 | Distributing the setup in universally composable multi-party computationabstractUniversally composable (UC) protocols retain their security properties even when run concurrently alongside arbitrary other protocols. Unfortunately, it is known that UC multiparty computation (for general functionalities, and without assuming honest majority) is impossible without some form of setup. To circumvent this impossibility, various complete setup assumptions have been proposed. With only a few exceptions, past work has viewed these setup assumptions as being implemented by some ideal, incorruptible entity. Any such entity is thus a single point of failure, and security fails catastrophically in case the setup entity is subverted by an adversary. We propose here a clean, general, and generic approach for distributing trust among m arbitrary setups, by modeling potential corruption of setups within the UC framework, where such corruption might be fail-stop, passive, or arbitrary and is in addition to possible corruption of the parties themselves. We show several feasibility and impossibility results in this model, for different specifications of the corruptible sets. For example, we show that given m complete setups, up to t of which might be actively corrupted in an adaptive manner, general multiparty computation with no honest majority is possible if and only if t < m/2. Jonathan Katz, Aggelos Kiayias, Hong-Sheng Zhou, Vassilis Zikas |
PODC | 3 |
| 2014 | (Efficient) Universally Composable Oblivious Transfer Using a Minimal Number of Stateless Tokens
Seung Geol Choi, Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich, Hong-Sheng Zhou |
TCC | 5 |
| 2013 | Functional Encryption from (Small) Hardware Tokens
Kai-Min Chung, Jonathan Katz, Hong-Sheng Zhou |
ASIACRYPT (2) | 3 |
| 2013 | Feasibility and Completeness of Cryptographic Tasks in the Quantum World
Serge Fehr, Jonathan Katz, Fang Song 0001, Hong-Sheng Zhou, Vassilis Zikas |
TCC | 4 |
| 2012 | On the Security of the "Free-XOR" Technique
Seung Geol Choi, Jonathan Katz, Ranjit Kumaresan, Hong-Sheng Zhou |
TCC | 4 |
| 2011 | Adaptively secure broadcast, revisitedabstractWe consider the classical problem of synchronous broadcast with dishonest majority, when a public-key infrastructure and digital signatures are available. In a surprising result, Hirt and Zikas (Eurocrypt 2010) recently observed that all existing protocols for this task are insecure against an adaptive adversary who can choose which parties to corrupt as the protocol progresses. Moreover, they prove an impossibility result for adaptively secure broadcast in their setting. We argue that the communication model adopted by Hirt and Zikas is unrealistically pes-simistic. We revisit the problem of adaptively secure broadcast in a more natural synchronous model (with rushing), and show that broadcast is possible in this setting for an arbitrary num-ber of corruptions. Our positive result holds under a strong, simulation-based definition in the universal-composability framework. We also study the impact of adaptive attacks on protocols for secure multi-party computation where broadcast is used as a sub-routine. 1 Juan A. Garay 0001, Jonathan Katz, Ranjit Kumaresan, Hong-Sheng Zhou |
PODC | 4 |
| 2010 | A Framework for the Sound Specification of Cryptographic TasksabstractNowadays it is widely accepted to formulate the security of a protocol carrying out a given task via the “trustedparty paradigm,” where the protocol execution is compared with an ideal process where the outputs are computed by a trusted party that sees all the inputs. A protocol is said to securely carry out a given task if running the protocol with a realistic adversary amounts to “emulating” the ideal process with the appropriate trusted party. In the Universal Composability (UC) framework the program run by the trusted party is called an ideal functionality. While this simulation-based security formulation provides strong security guarantees, its usefulness is contingent on the properties and correct specification of the ideal functionality, which, as demonstrated in recent years by the coexistence of complex, multiple functionalities for the same task as well as by their “unstable” nature, does not seem to be an easy task. In this paper we address this problem, by introducing a general methodology for the sound specification of ideal functionalities. First, we introduce the class of canonical ideal functionalities for a cryptographic task, which unifies the syntactic specification of a large class of cryptographic tasks under the same basic template functionality. Furthermore, this representation enables the isolation of the individual properties of a cryptographic task as separate members of the corresponding class. By endowing the class of canonical functionalities with an algebraic structure we are able to combine basic functionalities to a single final canonical functionality for a given task. Effectively, this puts forth a bottom-up approach for the specification of ideal functionalities: first one defines a set of basic constituent functionalities for the task at hand, and then combines them into a single ideal functionality taking advantage of the algebraic structure. In our framework, the constituent functionalities of a task can be derived either directly or, following a translation strategy we introduce, from existing game-based definitions; such definitions have in many cases captured desired individual properties of cryptographic tasks, albeit in less adversarial settings. Our translation methodology entails a sequence of steps that systematically derive a corresponding canonical functionality given a game-based definition, effectively “lifting” the game-based definition to its composition-safe version. We showcase our methodology by applying it to a variety of basic cryptographic tasks, including commitments, digital signatures, zero-knowledge proofs, and oblivious transfer. While in some cases our derived canonical functionalities are equivalent to existing formulations, thus attesting to the validity of our approach, in others they differ, enabling us to “debug” previous definitions and pinpoint their shortcomings. Juan A. Garay 0001, Aggelos Kiayias, Hong-Sheng Zhou |
CSF | 3 |
| 2009 | Somewhat Non-committing Encryption and Efficient Adaptively Secure Oblivious Transfer
Juan A. Garay 0001, Daniel Wichs, Hong-Sheng Zhou |
CRYPTO | 3 |
| 2009 | Secure Function Collection with Sublinear Storage
Maged H. Ibrahim, Aggelos Kiayias, Moti Yung, Hong-Sheng Zhou |
ICALP (2) | 4 |
| 2009 | Hidden identity-based signaturesabstractThis study introduces hidden identity-based signatures (Hidden-IBS), a type of digital signatures that provide mediated signer-anonymity on top of Shamir's identity-based signatures. The motivation of the new signature primitive is to resolve an important issue with the kind of anonymity offered by ‘group signatures’ where it is required that either the group membership list be public for opening signatures or that the opening authority be dependent on the group manager for its operation. Contrary to this, Hidden-IBS does not require the maintenance of a group membership list for opening signatures and they enable an opening authority that is totally independent of the group manager. As the authors argue this makes Hidden-IBS much more attractive than group signatures for a number of applications. In this study, the authors provide a formal model of Hidden-IBS as well as two efficient constructions that realise the new primitive. To demonstrate the power of the new primitive, the authors apply it to solve a problem of current onion-routing systems focusing on the Tor system in particular. Aggelos Kiayias, Hong-Sheng Zhou |
IET Inf. Secur. | 2 |
| 2008 | Equivocal Blind Signatures and Adaptive UC-Security
Aggelos Kiayias, Hong-Sheng Zhou |
TCC | 2 |
| 2007 | Trading Static for Adaptive Security in Universally Composable Zero-Knowledge
Aggelos Kiayias, Hong-Sheng Zhou |
ICALP | 2 |