EDBT 2026 Demo / reviewers in the wild / expert
Renas Bacho
dblp:320/2171
· DBLP profile ↗
15ranked-venue papers
14as first author
15since 2021 · last 2026
0009-0007-7037-2458ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 14 first-author · 14 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptively Secure (Aggregatable) PVSS from Standard Assumptions
Renas Bacho, Yanbo Chen 0002, Julian Loss |
CRYPTO (2) | 1 |
| 2026 | Earpicks: Tightly Secure Two-Round Multi and Threshold Signatures
Renas Bacho, Yanbo Chen 0002 |
EUROCRYPT (1) | 1 |
| 2026 | Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGM
Renas Bacho, Yanbo Chen 0002, Julian Loss, Stefano Tessaro, Chenzhi Zhu |
EUROCRYPT (1) | 1 |
| 2026 | Nearly Quadratic Asynchronous Distributed Key Generation from Recursive Consensus
Ittai Abraham, Renas Bacho, Julian Loss, Gilad Stern |
PODC | 2 |
| 2025 | Adaptively Secure Three-Round Threshold Schnorr Signatures from DDH
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001 |
CRYPTO (6) | 1 |
| 2025 | T-Spoon: Tightly Secure Two-Round Multi-signatures with Key Aggregation
Renas Bacho, Benedikt Wagner |
CRYPTO (6) | 1 |
| 2025 | Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security
Renas Bacho, Sourav Das 0001, Julian Loss, Ling Ren 0001 |
EUROCRYPT (2) | 1 |
| 2025 | SoK: Dlog-Based Distributed Key GenerationabstractDistributed Key Generation (DKG) protocols are fundamental components of threshold cryptography, enabling key generation in a trustless manner for a range of crypto-graphic operations such as threshold encryption and signing. Of particular widespread use are DKG protocols for discrete-logarithm based cryptosystems. In this Systematization of Knowledge (SoK), we present a comprehensive analysis of existing DKG protocols in the discrete-logarithm setting, with the goal of identifying cryptographic techniques and design principles that facilitate the development of secure and resilient protocols. To offer a structured overview of the literature, we adopt a modular approach and classify DKG protocols based on their underlying network assumption and cryptographic tools. These two factors determine how DKG protocols manage secret sharing and reach consensus as their essential building blocks. We also highlight various insights and suggest future research directions that could drive further advancements in this area. Renas Bacho, Alireza Kavousi |
SP | 1 |
| 2024 | HARTS: High-Threshold, Adaptively Secure, and Robust Threshold Schnorr Signatures
Renas Bacho, Julian Loss, Gilad Stern, Benedikt Wagner |
ASIACRYPT (3) | 1 |
| 2024 | Tightly Secure Non-interactive BLS Multi-signatures
Renas Bacho, Benedikt Wagner |
ASIACRYPT (2) | 1 |
| 2024 | GRandLine: Adaptively Secure DKG and Randomness Beacon with (Log-)Quadratic Communication ComplexityabstractA randomness beacon is a source of continuous and publicly verifiable randomness which is of crucial importance for many applications. Existing works on randomness beacons suffer from at least one of the following drawbacks: (i) security only against static (i.e., non-adaptive) adversaries, (ii) each epoch takes many rounds of communication, or (iii) computationally expensive tools such as proof-of-work (PoW) or verifiable delay functions (VDF). In this work, we introduce GRandLine, the first adaptively secure randomness beacon protocol that overcomes all these limitations while preserving simplicity and optimal resilience in the synchronous network setting. We achieve our result in two steps. First, we design a novel distributed key generation (DKG) protocol GRand that runs in O(λ n2 log n ) bits of communication but, unlike most conventional DKG protocols, outputs both secret and public keys as group elements. Here, λ denotes the security parameter. Second, following termination of GRand, parties can use their keys to derive a sequence of randomness beacon values, where each random value costs only a single asynchronous round and O(λ n2) bits of communication. We implement GRandLine and evaluate it using a network of up to 64 parties running in geographically distributed AWS instances. Our evaluation shows that GRandLine can produce about 2 beacon outputs per second in a network of 64 parties. We compare our protocol to the state-of-the-art randomness beacon protocols OptRand (NDSS '23), BRandPiper (CCS '21), and Drand, in the same setting and observe that it vastly outperforms them. Renas Bacho, Christoph Lenzen 0001, Julian Loss, Simon Ochsenreither, Dimitrios Papachristoudis |
CCS | 1 |
| 2024 | Twinkle: Threshold Signatures from DDH with Full Adaptive Security
Renas Bacho, Julian Loss, Stefano Tessaro, Benedikt Wagner, Chenzhi Zhu |
EUROCRYPT (1) | 1 |
| 2023 | Adaptively Secure (Aggregatable) PVSS and Application to Distributed Randomness BeaconsabstractPublicly Verifiable Secret Sharing (PVSS) is a fundamental primitive that allows to share a secret S among n parties via a publicly verifiable transcript T. Existing (efficient) PVSS are only proven secure against static adversaries who must choose who to corrupt ahead of a protocol execution. As a result, any protocol (e.g., a distributed randomness beacon) that builds on top of such a PVSS scheme inherits this limitation. To overcome this barrier, we revisit the security of PVSS under adaptive corruptions and show that, surprisingly, many protocols from the literature already achieve it in a meaningful way: Renas Bacho, Julian Loss |
CCS | 1 |
| 2023 | Network-Agnostic Security Comes (Almost) for Free in DKG and MPC
Renas Bacho, Daniel Collins 0001, Chen-Da Liu-Zhang, Julian Loss |
CRYPTO (1) | 1 |
| 2022 | On the Adaptive Security of the Threshold BLS Signature SchemeabstractThreshold signatures are a crucial tool for many distributed protocols. As shown by Cachin, Kursawe, and Shoup (PODC '00), schemes with unique signatures are of particular importance, as they allow to implement distributed coin flipping very efficiently and without any timing assumptions. This makes them an ideal building block for (inherently randomized) asynchronous consensus protocols. The threshold-BLS signature of Boldyreva (PKC '03) is both unique and very compact, but unfortunately lacks a security proof against adaptive adversaries. Thus, current consensus protocols either rely on less efficient alternatives or are not adaptively secure. In this work, we revisit the security of the threshold BLS signature by showing the following results, assuming t adaptive corruptions: - We give a modular security proof that follows a two-step approach: 1) We introduce a new security notion for distributed key generation protocols (DKG). We show that it is satisfied by several protocols that previously only had a static security proof. 2) Assuming any DKG protocol with this property, we then prove unforgeability of the threshold BLS scheme. Our reductions are tight and can be used to substantiate real-world parameter choices. - To justify our use of strong assumptions such as the algebraic group model (AGM) and the hardness of one-more-discrete logarithm (OMDL), we prove an impossibility result: Even in the AGM, a strong interactive assumption is required in order to prove the scheme secure. Renas Bacho, Julian Loss |
CCS | 1 |