EDBT 2026 Demo / reviewers in the wild / expert
Vadim Lyubashevsky
dblp:25/2540
· DBLP profile ↗
53ranked-venue papers
24as first author
12since 2021 · last 2026
0009-0003-5149-264XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 20 first-author · 12 since 2021Theory of computation · 6 · 5 first-authorSystems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Orthus: Practical Sublinear Batch-Verification of Lattice Relations from Standard Assumptions
Madalina Bolboceanu, Jonathan Bootle, Vadim Lyubashevsky, Antonio Merino-Gallardo, Gregor Seiler |
CRYPTO (3) | 3 |
| 2025 | Efficient Verifiable Mixnets from Lattices, Revisited
Jonathan Bootle, Vadim Lyubashevsky, Antonio Merino-Gallardo |
PKC (2) | 2 |
| 2024 | The LaZer Library: Lattice-Based Zero Knowledge and Succinct Proofs for Quantum-Safe PrivacyabstractThe hardness of lattice problems offers one of the most promising security foundations for quantum-safe cryptography. Basic schemes for public key encryption and digital signatures are already close to standardization at NIST and several other standardization bodies, and the research frontier has moved on to building primitives with more advanced privacy features. At the core of many such primitives are zero-knowledge proofs. In recent years, zero-knowledge proofs for (and using) lattice relations have seen a dramatic jump in efficiency and they currently provide arguably the shortest, and most computationally efficient, quantum-safe proofs for many scenarios. The main difficulty in using these proofs by non-experts (and experts!) is that they have a lot of moving parts and a lot of internal parameters depend on the particular instance that one is trying to prove. Vadim Lyubashevsky, Gregor Seiler, Patrick Steuer |
CCS | 1 |
| 2023 | Lattice-Based Blind Signatures: Short, Efficient, and Round-OptimalabstractWe propose a 2-round blind signature protocol based on the random oracle heuristic and the hardness of standard lattice problems (Ring/Module-SIS/LWE and NTRU) with a signature size of 20 KB. The protocol is round-optimal and has a transcript size that can be as small as 60 KB. This blind signature is around 4 times shorter than the most compact lattice-based scheme based on standard assumptions of del Pino and Katsumata (Crypto 2022) and around 2 times shorter than the scheme of Agrawal et al. (CCS 2022) based on their newly-proposed one-more-ISIS assumption. We also propose a "keyed-verification'' blind signature scheme in which the verifier and the signer need to share a secret key. This scheme has a smaller signature size of only 48 bytes, but further work is needed to explore the efficiency of its signature generation protocol. Ward Beullens, Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Gregor Seiler |
CCS | 2 |
| 2023 | A Framework for Practical Anonymous Credentials from Lattices
Jonathan Bootle, Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Alessandro Sorniotti |
CRYPTO (2) | 2 |
| 2022 | BLOOM: Bimodal Lattice One-out-of-Many Proofs and Applications
Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001 |
ASIACRYPT (4) | 1 |
| 2022 | Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More General
Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Maxime Plançon |
CRYPTO (2) | 1 |
| 2022 | Practical Non-interactive Publicly Verifiable Secret Sharing with Thousands of Parties
Craig Gentry, Shai Halevi, Vadim Lyubashevsky |
EUROCRYPT (1) | 3 |
| 2021 | Shorter Lattice-Based Group Signatures via "Almost Free" Encryption and Other Optimizations
Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Maxime Plançon, Gregor Seiler |
ASIACRYPT (4) | 1 |
| 2021 | Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto Transform Using Prefix HashingabstractConstructing an efficient CCA-secure KEM is generally done by first constructing a passively-secure PKE scheme, and then applying the Fujisaki-Okamoto (FO) transformation. The original FO transformation was designed to offer security in a single user setting. A stronger notion, known as multi-user security, considers the attacker's advantage in breaking one of many user's ciphertexts. Bellare et al. (EUROCRYPT 2000) showed that standard single user security implies multi-user security with a multiplicative tightness gap equivalent to the number of users. Julien Duman, Kathrin Hövelmanns, Eike Kiltz, Vadim Lyubashevsky, Gregor Seiler |
CCS | 4 |
| 2021 | SMILE: Set Membership from Ideal Lattices with Applications to Ring Signatures and Confidential Transactions
Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Gregor Seiler |
CRYPTO (2) | 1 |
| 2021 | More Efficient Amortization of Exact Zero-Knowledge Proofs for LWE
Jonathan Bootle, Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Gregor Seiler |
ESORICS (2) | 2 |
| 2020 | Practical Lattice-Based Zero-Knowledge Proofs for Integer RelationsabstractWe present a novel lattice-based zero-knowledge proof system for showing that (arbitrary-sized) committed integers satisfy additive and multiplicative relationships. The proof sizes of our schemes are between two to three orders of magnitude smaller than in the lattice proof system of Libert et al. (CRYPTO 2018) for the same relations. Because the proof sizes of our protocols grow linearly in the integer length, our proofs will eventually be longer than those produced by quantum-safe succinct proof systems for general circuits (e.g. Ligero, Aurora, etc.). But for relations between reasonably-sized integers (e.g. $512$-bit), our proofs still result in the smallest zero-knowledge proof system based on a quantum-safe assumption. Of equal importance, the run-time of our proof system is at least an order of magnitude faster than any other quantum-safe scheme. Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Gregor Seiler |
CCS | 1 |
| 2020 | Practical Product Proofs for Lattice Commitments
Thomas Attema, Vadim Lyubashevsky, Gregor Seiler |
CRYPTO (2) | 2 |
| 2020 | A Non-PCP Approach to Succinct Quantum-Safe Zero-Knowledge
Jonathan Bootle, Vadim Lyubashevsky, Ngoc Khanh Nguyen 0001, Gregor Seiler |
CRYPTO (2) | 2 |
| 2020 | Compact Privacy Protocols from Post-quantum and Timed Classical Assumptions
Jonathan Bootle, Anja Lehmann, Vadim Lyubashevsky, Gregor Seiler |
PQCrypto | 3 |
| 2019 | Algebraic Techniques for Short(er) Exact Lattice-Based Zero-Knowledge Proofs
Jonathan Bootle, Vadim Lyubashevsky, Gregor Seiler |
CRYPTO (1) | 2 |
| 2019 | Worst-Case Hardness for LPN and Cryptographic Hashing via Code Smoothing
Zvika Brakerski, Vadim Lyubashevsky, Vinod Vaikuntanathan, Daniel Wichs |
EUROCRYPT (3) | 2 |
| 2018 | Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism StabilityabstractWe present a group signature scheme, based on the hardness of lattice problems, whose outputs are more than an order of magnitude smaller than the currently most efficient schemes in the literature. Since lattice-based schemes are also usually non-trivial to efficiently implement, we additionally provide the first experimental implementation of lattice-based group signatures demonstrating that our construction is indeed practical -- all operations take less than half a second on a standard laptop. A key component of our construction is a new zero-knowledge proof system for proving that a committed value belongs to a particular set of small size. The sets for which our proofs are applicable are exactly those that contain elements that remain stable under Galois automorphisms of the underlying cyclotomic number field of our lattice-based protocol. We believe that these proofs will find applications in other settings as well. The motivation of the new zero-knowledge proof in our construction is to allow the efficient use of the selectively-secure signature scheme (i.e. a signature scheme in which the adversary declares the forgery message before seeing the public key) of Agrawal et al. (Eurocrypt 2010) in constructions of lattice-based group signatures and other privacy protocols. For selectively-secure schemes to be meaningfully converted to standard signature schemes, it is crucial that the size of the message space is not too large. Using our zero-knowledge proofs, we can strategically pick small sets for which we can provide efficient zero-knowledge proofs of membership. Rafaël Del Pino, Vadim Lyubashevsky, Gregor Seiler |
CCS | 2 |
| 2018 | Sub-linear Lattice-Based Zero-Knowledge Arguments for Arithmetic Circuits
Carsten Baum, Jonathan Bootle, Andrea Cerulli, Rafaël Del Pino, Jens Groth, Vadim Lyubashevsky |
CRYPTO (2) | 6 |
| 2018 | A Concrete Treatment of Fiat-Shamir Signatures in the Quantum Random-Oracle Model
Eike Kiltz, Vadim Lyubashevsky, Christian Schaffner |
EUROCRYPT (3) | 2 |
| 2018 | Short, Invertible Elements in Partially Splitting Cyclotomic Rings and Applications to Lattice-Based Zero-Knowledge Proofs
Vadim Lyubashevsky, Gregor Seiler |
EUROCRYPT (1) | 1 |
| 2018 | CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEMabstractRapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security. Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé |
EuroS&P | 5 |
| 2018 | Asymptotically Efficient Lattice-Based Digital Signatures
Vadim Lyubashevsky, Daniele Micciancio |
J. Cryptol. | 1 |
| 2017 | Practical Quantum-Safe Voting from LatticesabstractWe propose a lattice-based electronic voting scheme, EVOLVE (Electronic Voting from Lattices with Verification), which is conjectured to resist attacks by quantum computers. Our protocol involves a number of voting authorities so that vote privacy is maintained as long as at least one of the authorities is honest, while the integrity of the result is guaranteed even when all authorities collude. Furthermore, the result of the vote can be independently computed by any observer. At the core of the protocol is the utilization of a homomorphic commitment scheme with strategically orchestrated zero-knowledge proofs: voters use approximate but efficient "Fiat-Shamir with Aborts" proofs to show the validity of their vote, while the authorities use amortized exact proofs to show that the commitments are well-formed. We also present a novel efficient zero-knowledge proof that one of two lattice-based statements is true (so-called OR proof) and a new mechanism to control the size of the randomness when applying the homomorphism to commitments. We give concrete parameter choices to securely instantiate and evaluate the efficiency of our scheme. Our prototype implementation shows that the voters require $8$ milliseconds to submit a vote of size about $20$KB to each authority and it takes each authority $0.15$ seconds per voter to create a proof that his vote was valid. The size of the vote share that each authority produces is approximately $15$KB per voter, which we believe is well within the practical bounds for a large-scale election. Rafaël Del Pino, Vadim Lyubashevsky, Gregory Neven, Gregor Seiler |
CCS | 2 |
| 2017 | Amortization with Fewer Equations for Proving Knowledge of Small Secrets
Rafaël Del Pino, Vadim Lyubashevsky |
CRYPTO (3) | 2 |
| 2017 | One-Shot Verifiable Encryption from Lattices
Vadim Lyubashevsky, Gregory Neven |
EUROCRYPT (1) | 1 |
| 2016 | Digital Signatures Based on the Hardness of Ideal Lattice Problems in All Rings
Vadim Lyubashevsky |
ASIACRYPT (2) | 1 |
| 2016 | Tightly Secure Signatures From Lossy Identification Schemes
Michel Abdalla, Pierre-Alain Fouque, Vadim Lyubashevsky, Mehdi Tibouchi |
J. Cryptol. | 3 |
| 2015 | Efficient Zero-Knowledge Proofs for Commitments from Learning with Errors over RingsabstractWe extend a commitment scheme based on the learning with errors over rings ( $$\mathsf{RLWE}$$ ) problem, and present efficient companion zero-knowledge proofs of knowledge. Our scheme maps elements from the ring (or equivalently, n elements from $$\mathbb F_q$$ ) to a small constant number of ring elements. We then construct $$\varSigma $$ -protocols for proving, in a zero-knowledge manner, knowledge of the message contained in a commitment. We are able to further extend our basic protocol to allow us to prove additive and multiplicative relations among committed values. Our protocols have a communication complexity of $$\mathcal {O}(Mn\log q)$$ and achieve a negligible knowledge error in one run. Here M is the constant from a rejection sampling technique that we employ, and can be set close to 1 by adjusting other parameters. Previously known $$\varSigma $$ -protocols for LWE-related languages only achieved a noticeable or even constant knowledge error (thus requiring many repetitions of the protocol), or relied on “smudging” out the error (which necessitates working over large fields, resulting in poor efficiency). Fabrice Benhamouda, Stephan Krenn, Vadim Lyubashevsky, Krzysztof Pietrzak |
ESORICS (1) | 3 |
| 2015 | Quadratic Time, Linear Space Algorithms for Gram-Schmidt Orthogonalization and Gaussian Sampling in Structured Lattices
Vadim Lyubashevsky, Thomas Prest |
EUROCRYPT (1) | 1 |
| 2015 | Lattice-Based Signatures: Optimization and Implementation on Reconfigurable HardwareabstractNearly all of the currently used signature schemes, such as RSA or DSA, are based either on the factoring assumption or the presumed intractability of the discrete logarithm problem. As a consequence, the appearance of quantum computers or algorithmic advances on these problems may lead to the unpleasant situation that a large number of today's schemes will most likely need to be replaced with more secure alternatives. In this work we present such an alternative-an efficient signature scheme whose security is derived from the hardness of lattice problems. It is based on recent theoretical advances in lattice-based cryptography and is highly optimized for practicability and use in embedded systems. The public and secret keys are roughly 1.5 kB and 0.3 kB long, while the signature size is approximately 1.1 kB for a security level of around 80 bits. We provide implementation results on reconfigurable hardware (Spartan/Virtex-6) and demonstrate that the scheme is scalable, has low area consumption, and even outperforms classical schemes. Tim Güneysu, Vadim Lyubashevsky, Thomas Pöppelmann |
IEEE Trans. Computers | 2 |
| 2014 | Better Zero-Knowledge Proofs for Lattice Encryption and Their Application to Group Signatures
Fabrice Benhamouda, Jan Camenisch, Stephan Krenn, Vadim Lyubashevsky, Gregory Neven |
ASIACRYPT (1) | 4 |
| 2014 | Efficient Identity-Based Encryption over NTRU Lattices
Léo Ducas, Vadim Lyubashevsky, Thomas Prest |
ASIACRYPT (2) | 2 |
| 2013 | Lattice Signatures and Bimodal Gaussians
Léo Ducas, Alain Durmus, Tancrède Lepoint, Vadim Lyubashevsky |
CRYPTO (1) | 4 |
| 2013 | Man-in-the-Middle Secure Authentication Schemes from LPN and Weak PRFs
Vadim Lyubashevsky, Daniel Masny |
CRYPTO (2) | 1 |
| 2013 | A Toolkit for Ring-LWE Cryptography
Vadim Lyubashevsky, Chris Peikert, Oded Regev 0001 |
EUROCRYPT | 1 |
| 2013 | On Ideal Lattices and Learning with Errors over RingsabstractThe “learning with errors” (LWE) problem is to distinguish random linear equations, which have been perturbed by a small amount of noise, from truly uniform ones. The problem has been shown to be as hard as worst-case lattice problems, and in recent years it has served as the foundation for a plethora of cryptographic applications. Unfortunately, these applications are rather inefficient due to an inherent quadratic overhead in the use of LWE. A main open question was whether LWE and its applications could be made truly efficient by exploiting extra algebraic structure, as was done for lattice-based hash functions (and related primitives). We resolve this question in the affirmative by introducing an algebraic variant of LWE called ring-LWE , and proving that it too enjoys very strong hardness guarantees. Specifically, we show that the ring-LWE distribution is pseudorandom, assuming that worst-case problems on ideal lattices are hard for polynomial-time quantum algorithms. Applications include the first truly practical lattice-based public-key cryptosystem with an efficient security reduction; moreover, many of the other applications of LWE can be made much more efficient through the use of ring-LWE. Vadim Lyubashevsky, Chris Peikert, Oded Regev 0001 |
J. ACM | 1 |
| 2012 | Practical Lattice-Based Cryptography: A Signature Scheme for Embedded Systems
Tim Güneysu, Vadim Lyubashevsky, Thomas Pöppelmann |
CHES | 2 |
| 2012 | Tightly-Secure Signatures from Lossy Identification Schemes
Michel Abdalla, Pierre-Alain Fouque, Vadim Lyubashevsky, Mehdi Tibouchi |
EUROCRYPT | 3 |
| 2012 | Lattice Signatures without Trapdoors
Vadim Lyubashevsky |
EUROCRYPT | 1 |
| 2012 | Lapin: An Efficient Authentication Protocol Based on Ring-LPN
Stefan Heyse, Eike Kiltz, Vadim Lyubashevsky, Christof Paar, Krzysztof Pietrzak |
FSE | 3 |
| 2011 | Search to decision reduction for the learning with errors over rings problemabstractIn this short note, we give a self-contained proof of equivalence between the search and decision versions of the Learning with Error Problem over Rings problem (Lyuba-shevsky, Peikert, Regev 2010) for spherical noise distributions. Vadim Lyubashevsky |
ITW | 1 |
| 2010 | On Ideal Lattices and Learning with Errors over Rings
Vadim Lyubashevsky, Chris Peikert, Oded Regev 0001 |
EUROCRYPT | 1 |
| 2010 | Public-Key Cryptographic Primitives Provably as Secure as Subset Sum
Vadim Lyubashevsky, Adriana Palacio, Gil Segev 0001 |
TCC | 1 |
| 2009 | Fiat-Shamir with Aborts: Applications to Lattice and Factoring-Based Signatures
Vadim Lyubashevsky |
ASIACRYPT | 1 |
| 2009 | On Bounded Distance Decoding, Unique Shortest Vectors, and the Minimum Distance Problem
Vadim Lyubashevsky, Daniele Micciancio |
CRYPTO | 1 |
| 2009 | A Note on the Distribution of the Distance from a Lattice
Ishay Haviv, Vadim Lyubashevsky, Oded Regev 0001 |
Discret. Comput. Geom. | 2 |
| 2008 | SWIFFT: A Modest Proposal for FFT Hashing
Vadim Lyubashevsky, Daniele Micciancio, Chris Peikert, Alon Rosen |
FSE | 1 |
| 2008 | Asymptotically Efficient Lattice-Based Digital Signatures
Vadim Lyubashevsky, Daniele Micciancio |
TCC | 1 |
| 2006 | On Bounded Distance Decoding for General Lattices
Yi-Kai Liu 0001, Vadim Lyubashevsky, Daniele Micciancio |
APPROX-RANDOM | 2 |
| 2006 | Generalized Compact Knapsacks Are Collision Resistant
Vadim Lyubashevsky, Daniele Micciancio |
ICALP (2) | 1 |
| 2005 | The Parity Problem in the Presence of Noise, Decoding Random Linear Codes, and the Subset Sum Problem
Vadim Lyubashevsky |
APPROX-RANDOM | 1 |