EDBT 2026 Demo / reviewers in the wild / expert
Emmanuela Orsini
dblp:38/2316
· DBLP profile ↗
33ranked-venue papers
4as first author
15since 2021 · last 2025
0000-0002-1917-1833ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 2 first-author · 14 since 2021Theory of computation · 5 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Shorter, Tighter, FAESTer: Optimizations and Improved (QROM) Analysis for VOLE-in-the-Head Signatures
Carsten Baum, Ward Beullens, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Christian Majenz, Shibam Mukherjee, Emmanuela Orsini, Sebastian Ramacher, Christian Rechberger, Lawrence Roy, Peter Scholl |
CRYPTO (6) | 8 |
| 2025 | Row Reduction Techniques for n-Party Garbling
Kelong Cong, Emmanuela Orsini, Erik Pohle, Oliver Zajonc |
CRYPTO (4) | 2 |
| 2024 | One Tree to Rule Them All: Optimizing GGM Trees and OWFs for Post-Quantum Signatures
Carsten Baum, Ward Beullens, Shibam Mukherjee, Emmanuela Orsini, Sebastian Ramacher, Christian Rechberger, Lawrence Roy, Peter Scholl |
ASIACRYPT (1) | 4 |
| 2024 | Black-Box (and Fast) Non-malleable Zero Knowledge
Vincenzo Botta, Michele Ciampi, Emmanuela Orsini, Luisa Siniscalchi, Ivan Visconti |
CRYPTO (9) | 3 |
| 2024 | Scooby: Improved multi-party homomorphic secret sharing based on FHE
Ilaria Chillotti, Emmanuela Orsini, Peter Scholl, Barry Van Leeuwen |
Inf. Comput. | 2 |
| 2023 | MPC with Delayed Parties over Star-Like Networks
Mariana Gama, Emad Heydari Beni, Emmanuela Orsini, Nigel P. Smart, Oliver Zajonc |
ASIACRYPT (1) | 3 |
| 2023 | Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures from VOLE-in-the-HeadabstractWe present a new method for transforming zero-knowledge protocols in the designated verifier setting into public-coin protocols, which can be made non-interactive and publicly verifiable. Our transformation applies to a large class of ZK protocols based on oblivious transfer. In particular, we show that it can be applied to recent, fast protocols based on vector oblivious linear evaluation (VOLE), with a technique we call VOLE-in-the-head, upgrading these protocols to support public verifiability. Our resulting ZK protocols have linear proof size, and are simpler, smaller and faster than related approaches based on MPC-in-the-head. To build VOLE-in-the-head while supporting both binary circuits and large finite fields, we develop several new technical tools. One of these is a new proof of security for the SoftSpokenOT protocol (Crypto 2022), which generalizes it to produce certain types of VOLE correlations over large fields. Secondly, we present a new ZK protocol that is tailored to take advantage of this form of VOLE, which leads to a publicly verifiable VOLE-in-the-head protocol with only 2x more communication than the best, designated-verifier VOLE-based protocols. We analyze the soundness of our approach when made non-interactive using the Fiat-Shamir transform, using round-by-round soundness. As an application of the resulting NIZK, we present $$\textsf{FAEST}$$ , a post-quantum signature scheme based on AES. FAEST is the first AES-based signature scheme to be smaller than SPHINCS+, with signature sizes between 5.6 and 6.6kB at the 128-bit security level. Compared with the smallest version of SPHINCS+ (7.9kB), FAEST verification is slower, but the signing times are between 8x and 40x faster. Carsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Emmanuela Orsini, Lawrence Roy, Peter Scholl |
CRYPTO (5) | 5 |
| 2023 | ZK-for-Z2K: MPC-in-the-Head Zero-Knowledge Proofs for $\mathbb {Z}_{2^k}$abstractIn this work, we extend the MPC-in-the-Head framework, used in recent efficient zero-knowledge protocols, to work over the ring $$\mathbb {Z}_{2^k}$$ , which is the primary operating domain for modern CPUs. The proposed schemes are compatible with any threshold linear secret sharing scheme and draw inspiration from MPC protocols adapted for ring operations. Additionally, we explore various batching methodologies, leveraging Shamir’s secret sharing schemes and Galois ring extensions, and show the applicability of our approach in RAM program verification. Finally, we analyse different options for instantiating the resulting ZK scheme over rings and compare their communication costs. Lennart Braun, Cyprien Delpech de Saint Guilhem, Robin Jadoul, Emmanuela Orsini, Nigel P. Smart, Titouan Tanguy |
IMACC | 4 |
| 2022 | Feta: Efficient Threshold Designated-Verifier Zero-Knowledge ProofsabstractZero-Knowledge protocols have increasingly become both popular and practical in recent years due to their applicability in many areas such as blockchain systems. Unfortunately, public verifiability and small proof sizes of zero-knowledge protocols currently come at the price of strong assumptions, large prover time, or both, when considering statements with millions of gates. In this regime, the most prover-efficient protocols are in the designated verifier setting, where proofs are only valid to a single party that must keep a secret state. Carsten Baum, Robin Jadoul, Emmanuela Orsini, Peter Scholl, Nigel P. Smart |
CCS | 3 |
| 2022 | Four-Round Black-Box Non-malleable Schemes from One-Way Permutations
Michele Ciampi, Emmanuela Orsini, Luisa Siniscalchi |
TCC (2) | 2 |
| 2022 | TinyKeys: A New Approach to Efficient Multi-Party Computation
Carmit Hazay, Emmanuela Orsini, Peter Scholl, Eduardo Soria-Vazquez |
J. Cryptol. | 2 |
| 2021 | Limbo: Efficient Zero-knowledge MPCitH-based ArgumentsabstractThis work introduces a new interactive oracle proof system based on the MPC-in-the-Head paradigm. To improve concrete efficiency and offer flexibility between computation time and communication size, a generic proof construction based on multi-round MPC protocols is proposed, instantiated with a specific protocol and implemented and compared to similar proof systems. Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan Tanguy |
CCS | 2 |
| 2021 | Compilation of Function Representations for Secure Computing Paradigms
Karim Baghery, Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Nigel P. Smart, Titouan Tanguy |
CT-RSA | 3 |
| 2021 | Large Scale, Actively Secure Computation from LPN and Free-XOR Garbled Circuits
Aner Ben-Efraim, Kelong Cong, Eran Omri, Emmanuela Orsini, Nigel P. Smart, Eduardo Soria-Vazquez |
EUROCRYPT (3) | 4 |
| 2021 | High-Performance Multi-party Computation for Binary Circuits Based on Oblivious TransferabstractWe present a unified view of the two-party and multi-party computation protocols based on oblivious transfer first outlined in Nielsen et al. (CRYPTO 2012) and Larraia et al. (CRYPTO 2014). We present a number of modifications and improvements to these earlier presentations, as well as full proofs of the entire protocol. Improvements include a unified pre-processing and online MAC methodology, mechanisms to pass between different MAC variants and fixing a minor bug in the protocol of Larraia et al. in relation to a selective failure attack. It also fixes a minor bug in Nielsen et al. resulting from using Jensen’s inequality in the wrong direction in an analysis. Sai Sheshank Burra, Enrique Larraia, Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi, Emmanuela Orsini, Peter Scholl, Nigel P. Smart |
J. Cryptol. | 6 |
| 2020 | Semi-commutative Masking: A Framework for Isogeny-Based Protocols, with an Application to Fully Secure Two-Round Isogeny-Based OT
Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Christophe Petit 0001, Nigel P. Smart |
CANS | 2 |
| 2020 | Efficient Constant-Round MPC with Identifiable Abort and Public Verifiability
Carsten Baum, Emmanuela Orsini, Peter Scholl, Eduardo Soria-Vazquez |
CRYPTO (2) | 2 |
| 2020 | Overdrive2k: Efficient Secure MPC over $\mathbb {Z}_{2^k}$ from Somewhat Homomorphic Encryption
Emmanuela Orsini, Nigel P. Smart, Frederik Vercauteren |
CT-RSA | 1 |
| 2020 | Efficient, Actively Secure MPC with a Dishonest Majority: A Survey
Emmanuela Orsini |
WAIFI | 1 |
| 2019 | BBQ: Using AES in Picnic Signatures
Cyprien Delpech de Saint Guilhem, Lauren De Meyer, Emmanuela Orsini, Nigel P. Smart |
SAC | 3 |
| 2018 | Concretely Efficient Large-Scale MPC with Active Security (or, TinyKeys for TinyOT)
Carmit Hazay, Emmanuela Orsini, Peter Scholl, Eduardo Soria-Vazquez |
ASIACRYPT (3) | 2 |
| 2018 | TinyKeys: A New Approach to Efficient Multi-Party ComputationabstractWe present a new approach to designing concretely efficient MPC protocols with semi-honest security in the dishonest majority setting. Motivated by the fact that within the dishonest majority setting the efficiency of most practical protocols does not depend on the number of honest parties, we investigate how to construct protocols which improve in efficiency as the number of honest parties increases. Our central idea is to take a protocol which is secure for $$n-1$$ corruptions and modify it to use short symmetric keys, with the aim of basing security on the concatenation of all honest parties’ keys. This results in a more efficient protocol tolerating fewer corruptions, whilst also introducing an LPN-style syndrome decoding assumption. We first apply this technique to a modified version of the semi-honest GMW protocol, using OT extension with short keys, to improve the efficiency of standard GMW with fewer corruptions. We also obtain more efficient constant-round MPC, using BMR-style garbled circuits with short keys, and present an implementation of the online phase of this protocol. Our techniques start to improve upon existing protocols when there are around $$n=20$$ parties with $$h=6$$ honest parties, and as these increase we obtain up to a 13 times reduction (for $$n=400, h=120$$ ) in communication complexity for our GMW variant, compared with the best-known GMW-based protocol modified to use the same threshold. Carmit Hazay, Emmanuela Orsini, Peter Scholl, Eduardo Soria-Vazquez |
CRYPTO (3) | 2 |
| 2017 | Faster Secure Multi-party Computation of AES and DES Using Lookup Tables
Marcel Keller, Emmanuela Orsini, Dragos Rotaru, Peter Scholl, Eduardo Soria-Vazquez, Srinivas Vivek 0001 |
ACNS | 2 |
| 2017 | Actively Secure 1-out-of-N OT Extension with Application to Private Set Intersection
Michele Orrù, Emmanuela Orsini, Peter Scholl |
CT-RSA | 2 |
| 2017 | Tightly Secure Ring-LWE Based Key Encapsulation with Short Ciphertexts
Martin R. Albrecht, Emmanuela Orsini, Kenneth G. Paterson, Guy Peer, Nigel P. Smart |
ESORICS (1) | 2 |
| 2017 | On the Shape of the General Error Locator Polynomial for Cyclic CodesabstractGeneral error locator polynomials were introduced in 2005 as an alternative decoding for cyclic codes. We now present a conjecture on their sparsity, which would imply polynomial-time decoding for all cyclic codes. A general result on the explicit form of the general error locator polynomial for all cyclic codes is given, along with several results for specific code families, providing evidence to our conjecture. From these, a theoretical justification of the sparsity of general error locator polynomials is obtained for all binary cyclic codes with t ≤ 2 and n <; 105, as well as for t = 3 and n <; 63, except for some cases where the conjectured sparsity is proved by a computer check. Moreover, we summarize all related results, previously published, and we show how they provide further evidence to our conjecture. Finally, we discuss the link between our conjecture and the complexity of bounded-distance decoding of the cyclic codes. Fabrizio Caruso, Emmanuela Orsini, Massimiliano Sala, Claudia Tinnirello |
IEEE Trans. Inf. Theory | 2 |
| 2016 | MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferabstractWe consider the task of secure multi-party computation of arithmetic circuits over a finite field. Unlike Boolean circuits, arithmetic circuits allow natural computations on integers to be expressed easily and efficiently. In the strongest setting of malicious security with a dishonest majority --- where any number of parties may deviate arbitrarily from the protocol --- most existing protocols require expensive public-key cryptography for each multiplication in the preprocessing stage of the protocol, which leads to a high total cost. We present a new protocol that overcomes this limitation by using oblivious transfer to perform secure multiplications in general finite fields with reduced communication and computation. Our protocol is based on an arithmetic view of oblivious transfer, with careful consistency checks and other techniques to obtain malicious security at a cost of less than 6 times that of semi-honest security. We describe a highly optimized implementation together with experimental results for up to five parties. By making extensive use of parallelism and SSE instructions, we improve upon previous runtimes for MPC over arithmetic circuits by more than 200 times. Marcel Keller, Emmanuela Orsini, Peter Scholl |
CCS | 2 |
| 2016 | Bootstrapping BGV ciphertexts with a wider choice of p and qabstractThe authors describe a method to bootstrap a packed BGV ciphertext which does not depend (as much) on any special properties of the plaintext and ciphertext moduli. Prior ‘efficient’ methods such as that of Gentry et al . (PKC 2012) required a ciphertext modulus q which was close to a power of the plaintext modulus p . This enables the authors’ method to be applied in a larger number of situations. The authors’ basic bootstrapping technique makes use of a representation based on polynomials of the group over the finite field , followed by polynomial interpolation of the reduction mod p map over the coefficients of the algebraic group. This technique is then extended to the full BGV packed ciphertext space, using a method whose depth depends only logarithmically on the number of packed elements. This method may be of interest as an alternative to the method of Alperin‐Sheriff and Peikert (CRYPTO 2013). To aid efficiency, the authors utilise the ring/field switching technique of Gentry et al . (SCN 2012, JCS 2013). Emmanuela Orsini, Joop van de Pol, Nigel P. Smart |
IET Inf. Secur. | 1 |
| 2015 | A Unified Approach to MPC with Preprocessing Using OT
Tore Kasper Frederiksen, Marcel Keller, Emmanuela Orsini, Peter Scholl |
ASIACRYPT (1) | 3 |
| 2015 | Actively Secure OT Extension with Optimal Overhead
Marcel Keller, Emmanuela Orsini, Peter Scholl |
CRYPTO (1) | 2 |
| 2014 | Dishonest Majority Multi-Party Computation for Binary Circuits
Enrique Larraia, Emmanuela Orsini, Nigel P. Smart |
CRYPTO (2) | 2 |
| 2013 | Between a Rock and a Hard Place: Interpolating between MPC and FHE
Ashish Choudhury, Jake Loftus, Emmanuela Orsini, Arpita Patra, Nigel P. Smart |
ASIACRYPT (2) | 3 |
| 2007 | General Error Locator Polynomials for Binary Cyclic Codes With t<=2 and n<63abstractIn this paper, we show that a recently proposed algorithm for decoding cyclic codes may be applied efficiently to all binary cyclic codes with tles2 and n<63. This is accomplished by providing structure theorems for the codes in this range and classifying the relevant cases Emmanuela Orsini, Massimiliano Sala |
IEEE Trans. Inf. Theory | 1 |