EDBT 2026 Demo / reviewers in the wild / expert
Kristian Gjøsteen
dblp:90/4628
· DBLP profile ↗
30ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0001-7317-8625ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 9 first-author · 11 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Honest Users Make Honest Mistakes: A Framework for Analysing eID Protocols
Ole Martin Edstrøm, Kristian Gjøsteen, Hans Heum, Sjouke Mauw, Felix Stutz |
EuroS&P | 2 |
| 2023 | Verifiable Mix-Nets and Distributed Decryption for Voting from Lattice-Based AssumptionsabstractCryptographic voting protocols have recently seen much interest from practitioners due to their (planned) use in countries such as Estonia, Switzerland, France, and Australia. Practical protocols usually rely on tested designs such as the mixing-and-decryption paradigm. There, multiple servers verifiably shuffle encrypted ballots, which are then decrypted in a distributed manner. While several efficient protocols implementing this paradigm exist from discrete log-type assumptions, the situation is less clear for post-quantum alternatives such as lattices. This is because the design ideas of the discrete log-based voting protocols do not carry over easily to the lattice setting, due to specific problems such as noise growth and approximate relations. Diego F. Aranha, Carsten Baum, Kristian Gjøsteen, Tjerand Silde |
CCS | 3 |
| 2023 | On Optimal Tightness for Key Exchange with Full Forward Secrecy via Key Confirmation
Kai Gellert, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager |
CRYPTO (4) | 2 |
| 2023 | Machine-Checked Proofs of Accountability: How to sElect Who is to Blame
Constantin Catalin Dragan, François Dupressoir, Kristian Gjøsteen, Thomas Haines, Peter B. Rønne, Morten Rotvold Solberg |
ESORICS (3) | 3 |
| 2023 | Hybrid Group Key Exchange with Application to Constrained Networks
Colin Boyd, Elsie Mestl Fondevik, Kristian Gjøsteen, Lise Millerjord |
ISC | 3 |
| 2023 | Security Model for Privacy-Preserving Blockchain-Based Cryptocurrency Systems
Mayank Raikwar, Kristian Gjøsteen |
NSS | 3 |
| 2023 | Machine-checked proofs of privacy against malicious boards for Selene & CoabstractPrivacy is a notoriously difficult property to achieve in complicated systems and especially in electronic voting schemes. Moreover, electronic voting schemes is a class of systems that require very high assurance. The literature contains a number of ballot privacy definitions along with security proofs for common systems. Some machine-checked security proofs have also appeared. We define a new ballot privacy notion that captures a larger class of voting schemes. This notion improves on the state of the art by taking into account that verification in many schemes will happen or must happen after the tally has been published, not before as in previous definitions. As a case study we give a machine-checked proof of privacy for Selene, which is a remote electronic voting scheme which offers an attractive mix of security properties and usability. Prior to our work, the computational privacy of Selene has never been formally verified. Finally, we also prove that MiniVoting and Belenios satisfies our definition. Constantin Catalin Dragan, François Dupressoir, Ehsan Estaji, Kristian Gjøsteen, Thomas Haines, Peter Y. A. Ryan, Peter B. Rønne, Morten Rotvold Solberg |
J. Comput. Secur. | 4 |
| 2022 | Verifiable Decryption in the Head
Kristian Gjøsteen, Thomas Haines, Johannes Müller 0001, Peter B. Rønne, Tjerand Silde |
ACISP | 1 |
| 2022 | Machine-Checked Proofs of Privacy Against Malicious Boards for Selene & CoabstractPrivacy is a notoriously difficult property to achieve in complicated systems and especially in electronic voting schemes. Moreover, electronic voting schemes is a class of systems that require very high assurance. The literature contains a number of ballot privacy definitions along with security proofs for common systems. Some machine-checked security proofs have also appeared. We define a new ballot privacy notion that captures a larger class of voting schemes. This notion improves on the state of the art by taking into account that verification in many schemes will happen or must happen after the tally has been published, not before as in previous definitions. As a case study we give a machine-checked proof of privacy for Selene, which is a remote electronic voting scheme which offers an attractive mix of security properties and usability. Prior to our work, the computational privacy of Selene has never been formally verified. Finally, we also prove that MiniVoting and Belenios satisfies our definition. Constantin Catalin Dragan, François Dupressoir, Ehsan Estaji, Kristian Gjøsteen, Thomas Haines, Peter Y. A. Ryan, Peter B. Rønne, Morten Rotvold Solberg |
CSF | 4 |
| 2022 | PriBank: Confidential Blockchain Scaling Using Short Commit-and-Proof NIZK Argument
Kristian Gjøsteen, Mayank Raikwar |
CT-RSA | 1 |
| 2021 | Lattice-Based Proof of Shuffle and Applications to Electronic Voting
Diego F. Aranha, Carsten Baum, Kristian Gjøsteen, Tjerand Silde, Thor Tunge |
CT-RSA | 3 |
| 2020 | Cloud-Assisted Asynchronous Key Transport with Post-Quantum Security
Gareth T. Davies, Herman Galteland, Kristian Gjøsteen, Yao Jiang Galteland |
ACISP | 3 |
| 2020 | Fast and Secure Updatable Encryption
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao Jiang Galteland |
CRYPTO (1) | 3 |
| 2020 | Practical Isogeny-Based Key-Exchange with Optimal Tightness
Bor de Kock, Kristian Gjøsteen, Mattia Veroni |
SAC | 2 |
| 2019 | Highly Efficient Key Exchange Protocols with Optimal Tightness
Katriel Cohn-Gordon, Cas Cremers, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager |
CRYPTO (3) | 3 |
| 2018 | Definitions for Plaintext-Existence Hiding in Cloud StorageabstractCloud storage services use deduplication for saving bandwidth and storage. An adversary can exploit side-channel information in several attack scenarios when deduplication takes place at the client side, leaking information on whether a specific plaintext exists in the cloud storage. Generalising existing security definitions, we introduce formal security games for a number of possible adversaries in this domain, and show that games representing all natural adversarial behaviors are in fact equivalent. These results allow users and practitioners alike to accurately assess the vulnerability of deployed systems to this real-world concern. Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Håvard Raddum, Mohsen Toorani |
ARES | 3 |
| 2018 | Practical and Tightly-Secure Digital Signatures and Authenticated Key Exchange
Kristian Gjøsteen, Tibor Jager |
CRYPTO (2) | 1 |
| 2018 | Offline Assisted Group Key Exchange
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao Jiang Galteland |
ISC | 3 |
| 2018 | Security Notions for Cloud Storage and Deduplication
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Håvard Raddum, Mohsen Toorani |
ProvSec | 3 |
| 2017 | Side Channels in Deduplication: Trade-offs between Leakage and EfficiencyabstractDeduplication removes redundant copies of files or data blocks stored on the cloud. Client-side deduplication, where the client only uploads the file upon the request of the server, provides major storage and bandwidth savings, but introduces a number of security concerns. Harnik et al. (2010) showed how cross-user client-side deduplication inherently gives the adversary access to a (noisy) side-channel that may divulge whether or not a particular file is stored on the server, leading to leakage of user information. We provide formal definitions for deduplication strategies and their security in terms of adversarial advantage. Using these definitions, we provide a criterion for designing good strategies and then prove a bound characterizing the necessary trade-off between security and efficiency. Frederik Armknecht, Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Mohsen Toorani |
AsiaCCS | 4 |
| 2015 | Spreading Alerts Quietly and the Subgroup Escape Problem
James Aspnes, Zoë Diamadi, Aleksandr Yampolskiy, Kristian Gjøsteen, René Peralta 0001 |
J. Cryptol. | 4 |
| 2013 | Towards Privacy Preserving Mobile Internet Communications - How Close Can We Get?
Kristian Gjøsteen, George Petrides, Asgeir Steine |
ACISP | 1 |
| 2011 | A Novel Framework for Protocol Analysis
Kristian Gjøsteen, George Petrides, Asgeir Steine |
ProvSec | 1 |
| 2008 | A Latency-Free Election Scheme
Kristian Gjøsteen |
CT-RSA | 1 |
| 2008 | Round-Optimal Blind Signatures from Waters Signatures
Kristian Gjøsteen, Lillian Kråkmo |
ProvSec | 1 |
| 2008 | A framework for compositional verification of security protocols
Suzana Andova, Cas Cremers, Kristian Gjøsteen, Sjouke Mauw, Stig Fr. Mjølsnes, Sasa Radomirovic |
Inf. Comput. | 3 |
| 2007 | A Security Analysis of the NIST SP 800-90 Elliptic Curve Random Number Generator
Daniel R. L. Brown, Kristian Gjøsteen |
CRYPTO | 2 |
| 2006 | A New Security Proof for Damgård's ElGamal
Kristian Gjøsteen |
CT-RSA | 1 |
| 2005 | Spreading Alerts Quietly and the Subgroup Escape Problem
James Aspnes, Zoë Diamadi, Kristian Gjøsteen, René Peralta 0001, Aleksandr Yampolskiy |
ASIACRYPT | 3 |
| 2005 | Security Notions for Disk Encryption
Kristian Gjøsteen |
ESORICS | 1 |