EDBT 2026 Demo / reviewers in the wild / expert
Gregory M. Zaverucha
dblp:64/5417 · also Greg Zaverucha
· DBLP profile ↗
17ranked-venue papers
1as first author
5since 2021 · last 2025
0009-0000-7513-6728ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-author · 5 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MicroNova: Folding-Based Arguments with Efficient (On-Chain) VerificationabstractWe describe the design and implementation of MicroNova, a folding-based recursive argument for producing proofs of incremental computations of the form$y=F^{(\ell)}(x)$, where$F$is a possibly non-deterministic computation (encoded using a constraint system such as R1CS),$x$is the initial input,$y$is the output, and$\ell > 0$The proof of an$e$-step computation is produced step-by-step such that the proof size nor the time to verify it depends on$e$. The proof at the final iteration is then compressed, to achieve further succinctness in terms of proof size and verification time. Compared to prior folding-based arguments, a distinguishing aspect of MicroNova is the concrete efficiency of the verifier-even in a resource-constrained environment such as Ethereum's blockchain. In particular, the compressed proof consists of O(log N) group elements and it can be verified with O(log N) group scalar multiplications and two pairing operations, where$N$is the number of constraints for a single invocation of$F$MicroNova requires a universal trusted setup and can employ any existing setup material created for the popular KZG univariate polynomial commitment scheme. Finally, we implement and experimentally evaluate MicroNova. We find that MicroNova's proofs can be efficiently verified on the Ethereum blockchain with ≈2.2M gas. Furthermore, MicroNova's prover incurs minimal overheads atop its baseline Nova's prover. Jiaxing Zhao, Srinath Setty, Weidong Cui, Gregory M. Zaverucha |
SP | 4 |
| 2024 | Oblivious Issuance of Proofs
Michele Orrù, Stefano Tessaro, Gregory M. Zaverucha, Chenzhi Zhu |
CRYPTO (9) | 3 |
| 2022 | Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key CryptoabstractSignature schemes based on the MPC-in-the-head approach (MPCitH) have either been designed by taking a proof system and selecting a suitable symmetric-key primitive (Picnic, CCS16), or starting with an existing primitive such as AES and trying to find the most suitable proof system (BBQ, SAC19 or Banquet, PKC21). In this work we do both: we improve certain symmetric-key primitives to better fit existing signature schemes, and we also propose a new signature scheme that combines a new, minimalist one-way function with changes to a proof system to make their combination even more efficient. Our concrete results are as follows. Christoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger, Gregory M. Zaverucha |
CCS | 5 |
| 2022 | Proof-of-Possession for KEM Certificates using Verifiable GenerationabstractCertificate authorities in public key infrastructures typically require entities to prove possession of the secret key corresponding to the public key they want certified. While this is straightforward for digital signature schemes, the most efficient solution for public key encryption and key encapsulation mechanisms (KEMs) requires an interactive challenge-response protocol, requiring a departure from current issuance processes. In this work we investigate how to non-interactively prove possession of a KEM secret key, specifically for lattice-based KEMs, motivated by the recently proposed KEMTLS protocol which replaces signature-based authentication in TLS 1.3 with KEM-based authentication. Although there are various zero-knowledge (ZK) techniques that can be used to prove possession of a lattice key, they yield large proofs or are inefficient to generate. We propose a technique called verifiable generation, in which a proof of possession is generated at the same time as the key itself is generated. Our technique is inspired by the Picnic signature scheme and uses the multi-party-computation-in-the-head (MPCitH) paradigm; this similarity to a signature scheme allows us to bind attribute data to the proof of possession, as required by certificate issuance protocols. We show how to instantiate this approach for two lattice-based KEMs in Round 3 of the NIST post-quantum cryptography standardization project, Kyber and FrodoKEM, and achieve reasonable proof sizes and performance. Our proofs of possession are faster and an order of magnitude smaller than the previous best MPCitH technique for knowledge of a lattice key, and in size-optimized cases can be comparable to even state-of-the-art direct lattice-based ZK proofs for Kyber. Our approach relies on a new result showing the uniqueness of Kyber and FrodoKEM secret keys, even if the requirement that all secret key components are small is partially relaxed, which may be of independent interest for improving efficiency of zero-knowledge proofs for other lattice-based statements. Tim Güneysu, Philip W. Hodges, Georg Land, Mike Ounsworth, Douglas Stebila, Gregory M. Zaverucha |
CCS | 6 |
| 2021 | MPC-Friendly Symmetric Cryptography from Alternating Moduli: Candidates, Protocols, and Applications
Itai Dinur, Steven Goldfeder, Tzipora Halevi, Yuval Ishai, Mahimna Kelkar, Gregory M. Zaverucha |
CRYPTO (4) | 7 |
| 2020 | An Attack on Some Signature Schemes Constructed from Five-Pass Identification Schemes
Daniel Kales, Gregory M. Zaverucha |
CANS | 2 |
| 2020 | The Signal Private Group System and Anonymous Credentials Supporting Efficient Verifiable EncryptionabstractIn this paper we present a system for maintaining a membership list of users in a group, designed for use in the Signal Messenger secure messaging app. The goal is to support private groups where membership information is readily available to all group members but hidden from the service provider or anyone outside the group. In the proposed solution, a central server stores the group membership in the form of encrypted entries. Members of the group authenticate to the server in a way that reveals only that they correspond to some encrypted entry, then read and write the encrypted entries. Melissa Chase, Trevor Perrin, Gregory M. Zaverucha |
CCS | 3 |
| 2020 | Security of Hedged Fiat-Shamir Signatures Under Fault AttacksabstractDeterministic generation of per-signature randomness has been a widely accepted solution to mitigate the catastrophic risk of randomness failure in Fiat–Shamir type signature schemes. However, recent studies have practically demonstrated that such de-randomized schemes, including EdDSA, are vulnerable to differential fault attacks, which enable adversaries to recover the entire secret signing key, by artificially provoking randomness reuse or corrupting computation in other ways. In order to balance concerns of both randomness failures and the threat of fault injection, some signature designs are advocating a “hedged” derivation of the per-signature randomness, by hashing the secret key, message, and a nonce. Despite the growing popularity of the hedged paradigm in practical signature schemes, to the best of our knowledge, there has been no attempt to formally analyze the fault resilience of hedged signatures. We perform a formal security analysis of the fault resilience of signature schemes constructed via the Fiat–Shamir transform. We propose a model to characterize bit-tampering fault attacks, and investigate their impact across different steps of the signing operation. We prove that, for some types of faults, attacks are mitigated by the hedged paradigm, while attacks remain possible for others. As concrete case studies, we then apply our results to XEdDSA, a hedged version of EdDSA used in the Signal messaging protocol, and to Picnic2, a hedged Fiat–Shamir signature scheme in Round 2 of the NIST Post-Quantum standardization process. Diego F. Aranha, Claudio Orlandi, Akira Takahashi 0002, Gregory M. Zaverucha |
EUROCRYPT (1) | 4 |
| 2017 | Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesabstractWe propose a new class of post-quantum digital signature schemes that: (a) derive their security entirely from the security of symmetric-key primitives, believed to be quantum-secure, and (b) have extremely small keypairs, and, (c) are highly parameterizable. Melissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi, Sebastian Ramacher, Christian Rechberger, Daniel Slamanig, Gregory M. Zaverucha |
CCS | 8 |
| 2016 | Authenticated Network Time Synchronization
Benjamin Dowling, Douglas Stebila, Gregory M. Zaverucha |
USENIX Security Symposium | 3 |
| 2014 | Algebraic MACs and Keyed-Verification Anonymous CredentialsabstractWe consider the problem of constructing anonymous credentials for use in a setting where the issuer of credentials is also the verifier, or more generally where the issuer and verifier have a shared key. In this setting we can use message authentication codes (MACs) instead of public key signatures as the basis for the credential system. Melissa Chase, Sarah Meiklejohn, Gregory M. Zaverucha |
CCS | 3 |
| 2013 | Montgomery Multiplication Using Vector Instructions
Joppe W. Bos, Peter L. Montgomery, Daniel Shumow, Gregory M. Zaverucha |
Selected Areas in Cryptography | 4 |
| 2010 | Constant-Size Commitments to Polynomials and Their Applications
Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
ASIACRYPT | 2 |
| 2010 | Anonymity in shared symmetric key primitives
Gregory M. Zaverucha, Douglas Robert Stinson |
Des. Codes Cryptogr. | 1 |
| 2010 | Pairing-Based Onion Routing with Improved Forward SecrecyabstractThis article presents new protocols for onion routing anonymity networks. We define a provably secure privacy-preserving key agreement scheme in an identity-based infrastructure setting, and use it to design new onion routing circuit constructions. These constructions, based on a user’s selection, offer immediate or eventual forward secrecy at each node in a circuit and require significantly less computation and communication than the telescoping mechanism used by the Tor project. Further, the use of an identity-based infrastructure also leads to a reduction in the required amount of authenticated directory information. Therefore, our constructions provide practical ways to allow onion routing anonymity networks to scale gracefully. Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2008 | Some Improved Bounds for Secure Frameproof Codes and Related Separating Hash FamiliesabstractWe present some improved bounds on necessary conditions for separating hash families of type {w, w} and type {w, w - 1}. In particular, these bounds apply to secure frame- proof codes, which are equivalent to separating hash families of type {w, w}. We also consider existence results for separating hash families of type {w, w2} that can be obtained from the probabilistic method. The asymptotic behavior of these bounds is analyzed. Douglas Robert Stinson, Gregory M. Zaverucha |
IEEE Trans. Inf. Theory | 2 |
| 2007 | Pairing-Based Onion Routing
Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 2 |