EDBT 2026 Demo / reviewers in the wild / expert
Pooya Farshim
dblp:64/5418
· DBLP profile ↗
29ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0003-2746-3585ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 4 first-author · 5 since 2021Theory of computation · 5 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Block Ciphers in Idealized Models: Automated Proofs and New Security ResultsabstractWe develop and implement AlgoROM, a tool to systematically analyze the security of a wide class of symmetric primitives in idealized models of computation. The schemes that we consider are those that can be expressed over an alphabet consisting of XOR and function symbols for hash functions, permutations, or block ciphers. We implement our framework in OCaml and apply it to a number of prominent constructions, which include the Luby-Rackoff (LR), key-alternating Feistel (KAF), and iterated Even-Mansour (EM) ciphers, as well as substitution-permutation networks (SPN). The security models we consider are (S)PRP, and strengthenings thereof under related-key (RK), key-dependent message (KD), and more generally key-correlated (KC) attacks. Using AlgoROM, we are able to reconfirm a number of classical and previously established security theorems, and in one case we identify a gap in a proof from the literature (Connolly et al., ToSC'19). However, most results that we prove with AlgoROM are new. In particular, we obtain new positive results for LR, KAF, EM, and SPN in the above models. Our results better reflect the configurations actually implemented in practice, as they use a single idealized primitive. In contrast to many existing tools, our automated proofs do not operate in symbolic models, but rather in the standard probabilistic model for cryptography. Miguel Ambrona, Pooya Farshim, Patrick Harasser |
CCS | 2 |
| 2024 | The Brave New World of Global Generic Groups and UC-Secure Zero-Overhead SNARKs
Jan Bobolz, Pooya Farshim, Markulf Kohlweiss, Akira Takahashi 0002 |
TCC (1) | 2 |
| 2022 | Beyond Uber: Instantiating Generic Groups via PGGs
Balthazar Bauer, Pooya Farshim, Patrick Harasser, Adam O'Neill |
TCC (3) | 2 |
| 2021 | The Key-Dependent Message Security of Key-Alternating Feistel Ciphers
Pooya Farshim, Louiza Khati, Yannick Seurin, Damien Vergnaud |
CT-RSA | 1 |
| 2021 | Password Hashing and Preprocessing
Pooya Farshim, Stefano Tessaro |
EUROCRYPT (2) | 1 |
| 2021 | Black-Box Uselessness: Composing Separations in CryptographyabstractBlack-box separations have been successfully used to identify the limits of a powerful set of tools in cryptography, namely those of black-box reductions. They allow proving that a large set of techniques are not capable of basing one primitive 𝒫 on another 𝒬. Such separations, however, do not say anything about the power of the combination of primitives 𝒬₁,𝒬₂ for constructing 𝒫, even if 𝒫 cannot be based on 𝒬₁ or 𝒬₂ alone. By introducing and formalizing the notion of black-box uselessness, we develop a framework that allows us to make such conclusions. At an informal level, we call primitive 𝒬 black-box useless (BBU) for 𝒫 if 𝒬 cannot help constructing 𝒫 in a black-box way, even in the presence of another primitive 𝒵. This is formalized by saying that 𝒬 is BBU for 𝒫 if for any auxiliary primitive 𝒵, whenever there exists a black-box construction of 𝒫 from (𝒬,𝒵), then there must already also exist a black-box construction of 𝒫 from 𝒵 alone. We also formalize various other notions of black-box uselessness, and consider in particular the setting of efficient black-box constructions when the number of queries to 𝒬 is below a threshold. Impagliazzo and Rudich (STOC'89) initiated the study of black-box separations by separating key agreement from one-way functions. We prove a number of initial results in this direction, which indicate that one-way functions are perhaps also black-box useless for key agreement. In particular, we show that OWFs are black-box useless in any construction of key agreement in either of the following settings: (1) the key agreement has perfect correctness and one of the parties calls the OWF a constant number of times; (2) the key agreement consists of a single round of interaction (as in Merkle-type protocols). We conjecture that OWFs are indeed black-box useless for general key agreement. We also show that certain techniques for proving black-box separations can be lifted to the uselessness regime. In particular, we show that the lower bounds of Canetti, Kalai, and Paneth (TCC'15) as well as Garg, Mahmoody, and Mohammed (Crypto'17 & TCC'17) for assumptions behind indistinguishability obfuscation (IO) can be extended to derive black-box uselessness of a variety of primitives for obtaining (approximately correct) IO. These results follow the so-called "compiling out" technique, which we prove to imply black-box uselessness. Eventually, we study the complementary landscape of black-box uselessness, namely black-box helpfulness. We put forth the conjecture that one-way functions are black-box helpful for building collision-resistant hash functions. We define two natural relaxations of this conjecture, and prove that both of these conjectures are implied by a natural conjecture regarding random permutations equipped with a collision finder oracle, as defined by Simon (Eurocrypt'98). This conjecture may also be of interest in other contexts, such as amplification of hardness. Geoffroy Couteau, Pooya Farshim, Mohammad Mahmoody |
ITCS | 2 |
| 2020 | Towards Defeating Backdoored Random Oracles: Indifferentiability with Bounded Adaptivity
Yevgeniy Dodis, Pooya Farshim, Sogol Mazaheri, Stefano Tessaro |
TCC (3) | 2 |
| 2020 | Multilinear Maps from ObfuscationabstractAbstract We provide constructions of multilinear groups equipped with natural hard problems from indistinguishability obfuscation, homomorphic encryption, and NIZKs. This complements known results on the constructions of indistinguishability obfuscators from multilinear maps in the reverse direction. We provide two distinct, but closely related constructions and show that multilinear analogues of the $${\text {DDH}} $$ DDH assumption hold for them. Our first construction is symmetric and comes with a $$\kappa $$ κ -linear map $$\mathbf{e }: {{\mathbb {G}}}^\kappa \longrightarrow {\mathbb {G}}_T$$ e:Gκ⟶GT for prime-order groups $${\mathbb {G}}$$ G and $${\mathbb {G}}_T$$ GT . To establish the hardness of the $$\kappa $$ κ -linear $${\text {DDH}} $$ DDH problem, we rely on the existence of a base group for which the $$\kappa $$ κ -strong $${\text {DDH}} $$ DDH assumption holds. Our second construction is for the asymmetric setting, where $$\mathbf{e }: {\mathbb {G}}_1 \times \cdots \times {\mathbb {G}}_{\kappa } \longrightarrow {\mathbb {G}}_T$$ e:G1×⋯×Gκ⟶GT for a collection of $$\kappa +1$$ κ+1 prime-order groups $${\mathbb {G}}_i$$ Gi and $${\mathbb {G}}_T$$ GT , and relies only on the 1-strong $${\text {DDH}} $$ DDH assumption in its base group. In both constructions, the linearity $$\kappa $$ κ can be set to any arbitrary but a priori fixed polynomial value in the security parameter. We rely on a number of powerful tools in our constructions: probabilistic indistinguishability obfuscation, dual-mode NIZK proof systems (with perfect soundness, witness-indistinguishability, and zero knowledge), and additively homomorphic encryption for the group $$\mathbb {Z}_N^{+}$$ ZN+ . At a high level, we enable “bootstrapping” multilinear assumptions from their simpler counterparts in standard cryptographic groups and show the equivalence of PIO and multilinear maps under the existence of the aforementioned primitives. Martin R. Albrecht, Pooya Farshim, Shuai Han 0001, Dennis Hofheinz, Enrique Larraia, Kenneth G. Paterson |
J. Cryptol. | 2 |
| 2018 | Indifferentiable Authenticated Encryption
Manuel Barbosa, Pooya Farshim |
CRYPTO (1) | 2 |
| 2018 | Combiners for Backdoored Random Oracles
Balthazar Bauer, Pooya Farshim, Sogol Mazaheri |
CRYPTO (2) | 2 |
| 2016 | Modeling Random Oracles Under Unpredictable Queries
Pooya Farshim, Arno Mittelbach |
FSE | 1 |
| 2016 | Polly Cracker, revisited
Martin R. Albrecht, Jean-Charles Faugère, Pooya Farshim, Gottfried Herold, Ludovic Perret |
Des. Codes Cryptogr. | 3 |
| 2015 | A More Cautious Approach to Security Against Mass Surveillance
Jean Paul Degabriele, Pooya Farshim, Bertram Poettering |
FSE | 2 |
| 2015 | The Related-Key Security of Iterated Even-Mansour Ciphers
Pooya Farshim, Gordon Procter |
FSE | 1 |
| 2015 | Random-Oracle Uninstantiability from Indistinguishability Obfuscation
Christopher Brzuska, Pooya Farshim, Arno Mittelbach |
TCC (2) | 2 |
| 2014 | Indistinguishability Obfuscation and UCEs: The Case of Computationally Unpredictable Sources
Christopher Brzuska, Pooya Farshim, Arno Mittelbach |
CRYPTO (1) | 2 |
| 2014 | The Related-Key Analysis of Feistel Constructions
Manuel Barbosa, Pooya Farshim |
FSE | 2 |
| 2013 | Ideal-Cipher (Ir)reducibility for Blockcipher-Based Hash Functions
Paul Baecher, Pooya Farshim, Marc Fischlin, Martijn Stam |
EUROCRYPT | 2 |
| 2013 | On the Relationship between Functional Encryption, Obfuscation, and Fully Homomorphic Encryption
Joël Alwen, Manuel Barbosa, Pooya Farshim, Rosario Gennaro, S. Dov Gordon, Stefano Tessaro, David A. Wilson |
IMACC | 3 |
| 2012 | On the Joint Security of Signature and Encryption Schemes under Randomness Reuse: Efficiency and Security Amplification
Afonso Arriaga, Manuel Barbosa, Pooya Farshim |
ACNS | 3 |
| 2012 | Delegatable Homomorphic Encryption with Applications to Secure Outsourcing of Computation
Manuel Barbosa, Pooya Farshim |
CT-RSA | 2 |
| 2011 | Polly Cracker, Revisited
Martin R. Albrecht, Pooya Farshim, Jean-Charles Faugère, Ludovic Perret |
ASIACRYPT | 2 |
| 2011 | On Cipher-Dependent Related-Key Attacks in the Ideal-Cipher Model
Martin R. Albrecht, Pooya Farshim, Kenneth G. Paterson, Gaven J. Watson |
FSE | 2 |
| 2010 | Relations among Notions of Complete Non-malleability: Indistinguishability Characterisation and Efficient Construction without Random Oracles
Manuel Barbosa, Pooya Farshim |
ACISP | 2 |
| 2010 | Strong Knowledge Extractors for Public-Key Encryption Schemes
Manuel Barbosa, Pooya Farshim |
ACISP | 2 |
| 2008 | Certificateless signcryptionabstractCertificateless cryptography inherits a solution to the certificate management problem in public-key encryption from identity-based techniques, whilst removing the secret key escrow functionality inherent to the identity-based setting. Signcryption schemes achieve confidentiality and authentication simultaneously by combining public-key encryption and digital signatures, offering better overall performance and security. In this paper, we introduce the notion of certificateless signcryption and present an efficient construction which guarantees security under insider attacks, and therefore provides forward secrecy and non-repudiation. Manuel Barbosa, Pooya Farshim |
AsiaCCS | 2 |
| 2008 | Generic Constructions of Identity-Based and Certificateless KEMs
Kamel Bentahar, Pooya Farshim, John Malone-Lee, Nigel P. Smart |
J. Cryptol. | 2 |
| 2007 | Randomness Reuse: Extensions and Improvements
Manuel Barbosa, Pooya Farshim |
IMACC | 2 |
| 2005 | Efficient Identity-Based Key Encapsulation to Multiple Parties
Manuel Barbosa, Pooya Farshim |
IMACC | 2 |