EDBT 2026 Demo / reviewers in the wild / expert
Dario Fiore 0001
dblp:99/2744-1
· DBLP profile ↗
64ranked-venue papers
12as first author
26since 2021 · last 2026
0000-0001-7274-6600ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 59 · 11 first-author · 24 since 2021Theory of computation · 8 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Splitting Bilinear Groups: New Translations from Composite- to Prime-Order with Applications to Batch Arguments for NP
David Balbás, Dario Fiore 0001 |
CRYPTO (9) | 2 |
| 2026 | On Verifiable Delay Functions from Time-Lock Puzzles
Hamza Abusalah, Karen Azari, Dario Fiore 0001, Chethan Kamath, Erkan Tairi |
PKC (4) | 3 |
| 2026 | On Composing AGM-Secure Functionalities with Cryptographic Proofs - Applications to Unbounded-Depth IVC and More
Matteo Campanelli, Dario Fiore 0001, Mahak Pancholi |
PKC (3) | 2 |
| 2025 | Algebraic Zero Knowledge Contingent Payment
Javier Gomez-Martinez, Dimitrios Vasilopoulos, Pedro Moreno-Sanchez, Dario Fiore 0001 |
ACNS (2) | 4 |
| 2025 | Verifiable Computation for Approximate Homomorphic Encryption Schemes
Ignacio Cascudo, Anamaria Costache, Daniele Cozzo, Dario Fiore 0001, Antonio Guimarães, Eduardo Soria-Vazquez |
CRYPTO (7) | 4 |
| 2025 | $\mathfrak {Tetris}$! Traceable Extendable Threshold Ring Signatures and More
Gennaro Avitabile, Vincenzo Botta, Dario Fiore 0001 |
ESORICS (2) | 3 |
| 2025 | Verification-Efficient Homomorphic Signatures for Verifiable Computation over Data Streams
Gaspard Anthoine, Daniele Cozzo, Dario Fiore 0001 |
FC (2) | 3 |
| 2025 | Natively Compatible Super-Efficient Lookup Arguments and How to Apply Them
Matteo Campanelli, Dario Fiore 0001, Rosario Gennaro |
J. Cryptol. | 2 |
| 2024 | Real-World Universal zkSNARKs are Non-MalleableabstractSimulation extractability is a strong security notion of zkSNARKs that guarantees that an attacker who produces a valid proof must know the corresponding witness, even if the attacker had prior access to proofs generated by other users. Notably, simulation extractability implies that proofs are non-malleable and is of fundamental importance for applications of zkSNARKs in distributed systems. In this work, we study sufficient and necessary conditions for constructing simulation-extractable universal zkSNARKs via the popular design approach based on compiling polynomial interactive oracle proofs (PIOP). Our main result is the first security proof that popular universal zkSNARKs, such as PLONK and Marlin, as deployed in the real world, are simulation-extractable. Our result fills a gap left from previous work (Faonio et al. TCC'23, and Kohlweiss et al. TCC'23) which could only prove the simulation extractability of the "textbook" versions of these schemes and does not capture their optimized variants, with all the popular optimization tricks in place, that are eventually implemented and deployed in software libraries. Antonio Faonio, Dario Fiore 0001, Luigi Russo 0001 |
CCS | 2 |
| 2024 | Fully-Succinct Multi-key Homomorphic Signatures from Standard Assumptions
Gaspard Anthoine, David Balbás, Dario Fiore 0001 |
CRYPTO (3) | 3 |
| 2023 | Cuckoo Commitments: Registration-Based Encryption and Key-Value Map Commitments for Large Spaces
Dario Fiore 0001, Dimitris Kolonelos, Paola de Perthuis |
ASIACRYPT (5) | 1 |
| 2023 | Modular Sumcheck Proofs with Applications to Machine Learning and Image ProcessingabstractCryptographic proof systems provide integrity, fairness, and privacy in applications that outsource data processing tasks. However, general-purpose proof systems do not scale well to large inputs. At the same time, ad-hoc solutions for concrete applications - e.g., machine learning or image processing - are more efficient but lack modularity, hence they are hard to extend or to compose with other tools of a data-processing pipeline. David Balbás, Dario Fiore 0001, María Isabel González Vasco, Damien Robissout, Claudio Soriente |
CCS | 2 |
| 2023 | Chainable Functional Commitments for Unbounded-Depth Circuits
David Balbás, Dario Catalano, Dario Fiore 0001, Russell W. F. Lai |
TCC (3) | 3 |
| 2023 | From Polynomial IOP and Commitments to Non-malleable zkSNARKs
Antonio Faonio, Dario Fiore 0001, Markulf Kohlweiss, Luigi Russo 0001, Michal Zajac 0001 |
TCC (3) | 2 |
| 2023 | Zero-knowledge proofs for set membership: efficient, succinct, modularabstractAbstract We consider the problem of proving in zero knowledge that an element of a public set satisfies a given property without disclosing the element, i.e., for some u , “ $$u \in S$$ u ∈ S and P ( u ) holds”. This problem arises in many applications (anonymous cryptocurrencies, credentials or whitelists) where, for privacy or anonymity reasons, it is crucial to hide certain data while ensuring properties of such data. We design new modular and efficient constructions for this problem through new commit-and-prove zero-knowledge systems for set membership , i.e. schemes proving $$u \in S$$ u ∈ S for a value u that is in a public commitment $$c_u$$ c u . We also extend our results to support non-membership proofs , i.e. proving $$u \notin S$$ u ∉ S . Being commit-and-prove, our solutions can act as plug-and-play modules in statements of the form “ $$u \in S$$ u ∈ S and P ( u ) holds” by combining our set (non-)membership systems with any other commit-and-prove scheme for P ( u ). Also, they work with Pedersen commitments over prime order groups which makes them compatible with popular systems such as Bulletproofs or Groth16. We implemented our schemes as a software library, and tested experimentally their performance. Compared to previous work that achieves similar properties—the clever techniques combining zkSNARKs and Merkle Trees in Zcash—our solutions offer more flexibility, shorter public parameters and $$3.7 \times $$ 3.7 × – $$30\times $$ 30 × faster proving time for a set of size $$2^{64}$$ 2 64 . Daniel Benarroch, Matteo Campanelli, Dario Fiore 0001, Kobi Gurkan, Dimitris Kolonelos |
Des. Codes Cryptogr. | 3 |
| 2022 | Progressive and Efficient Verification for Digital Signatures
Cecilia Boschini, Dario Fiore 0001, Elena Pagnin |
ACNS | 2 |
| 2022 | Additive-Homomorphic Functional Commitments and Applications to Homomorphic Signatures
Dario Catalano, Dario Fiore 0001, Ida Tucker |
ASIACRYPT (4) | 2 |
| 2022 | Efficient Zero-Knowledge Proofs on Signed Data with Applications to Verifiable Computation on Data StreamsabstractWe study the problem of privacy-preserving proofs on streamed authenticated data. In this setting, a server receives a continuous stream of data from a trusted data provider, and is requested to prove computations over the data to third parties in a correct and private way. In particular, the third party learns no information on the data beyond the validity of claimed results. A challenging requirement here, is that the third party verifies the validity with respect to the specific data authenticated by the provider, while communicating only with the server. This problem is motivated by various application areas, ranging from stock-market monitoring and prediction services; to the publication of government-ran statistics on large healthcare databases. All of these applications require a reliable and scalable solution, in order to see practical adoption. Dario Fiore 0001, Ida Tucker |
CCS | 1 |
| 2022 | Succinct Zero-Knowledge Batch Proofs for Set AccumulatorsabstractCryptographic accumulators are a common solution to proving information about a large set S. They allow one to compute a short digest of S and short certificates of some of its basic properties, notably membership of an element. Accumulators also allow one to track set updates: a new accumulator is obtained by inserting/deleting a given element. In this work we consider the problem of generating membership and update proofs for \em batches of elements so that we can succinctly prove additional properties of the elements (i.e., proofs are of constant size regardless of the batch size), and we can preserve privacy. Solving this problem would allow obtaining blockchain systems with improved privacy and scalability. Matteo Campanelli, Dario Fiore 0001, Semin Han, Jihye Kim 0001, Dimitris Kolonelos, Hyunok Oh |
CCS | 2 |
| 2022 | Subversion-Resilient Enhanced Privacy ID
Antonio Faonio, Dario Fiore 0001, Luca Nizzardo, Claudio Soriente |
CT-RSA | 2 |
| 2022 | Ring Signatures with User-Controlled Linkability
Dario Fiore 0001, Lydia Garms, Dimitris Kolonelos, Claudio Soriente, Ida Tucker |
ESORICS (2) | 1 |
| 2022 | Adaptively Secure Single Secret Leader Election from DDHabstractSingle Secret Leader Election protocols (SSLE, for short) allow a group of users to select a random leader so that the latter remains secret until she decides to reveal herself. Thanks to this feature, SSLE can be used to build an election mechanism for proof-of-stake based blockchains. In particular, a recent work by Azouvi and Cappelletti (ACM AFT 2021) shows that in comparison to probabilistic leader election methods, SSLE-based proof-of-stake blockchains have significant security gains, both with respect to grinding attacks and with respect to the private attack. Yet, as of today, very few concrete constructions of SSLE are known. In particular, all existing protocols are only secure in a model where the adversary is supposed to corrupt participants before the protocol starts -- an assumption that clashes with the highly dynamic nature of decentralized blockchain protocols. In this paper we make progress in the study of SSLE by proposing new efficient constructions that achieve stronger security guarantees than previous work. In particular, we propose the first SSLE protocol that achieves adaptive security. Our scheme is proven secure in the universal composability model and achieves efficiency comparable to previous, less secure, realizations in the state of the art. Dario Catalano, Dario Fiore 0001, Emanuele Giunta |
PODC | 2 |
| 2022 | On the Impossibility of Algebraic Vector Commitments in Pairing-Free Groups
Dario Catalano, Dario Fiore 0001, Rosario Gennaro, Emanuele Giunta |
TCC (2) | 2 |
| 2021 | Lunar: A Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions
Matteo Campanelli, Antonio Faonio, Dario Fiore 0001, Anaïs Querol, Hadrián Rodríguez |
ASIACRYPT (3) | 3 |
| 2021 | Controlled Functional Encryption Revisited: Multi-Authority Extensions and Efficient Schemes for Quadratic FunctionsabstractAbstract In a Functional Encryption scheme (FE), a trusted authority enables designated parties to compute specific functions over encrypted data. As such, FE promises to break the tension between industrial interest in the potential of data mining and user concerns around the use of private data. FE allows the authority to decide who can compute and what can be computed, but it does not allow the authority to control which ciphertexts can be mined. This issue was recently addressed by Naveed et al., that introduced so-called Controlled Functional encryption (or C-FE), a cryptographic framework that extends FE and allows the authority to exert fine-grained control on the ciphertexts being mined. In this work we extend C-FE in several directions. First, we distribute the role of (and the trust in) the authority across several parties by defining multi-authority C-FE (or mCFE). Next, we provide an efficient instantiation that enables computation of quadratic functions on inputs provided by multiple data-owners, whereas previous work only provides an instantiation for linear functions over data supplied by a single data-owner and resorts to garbled circuits for more complex functions. Our scheme leverages CCA2 encryption and linearly-homomorphic encryption. We also implement a prototype and use it to showcase the potential of our instantiation. Miguel Ambrona, Dario Fiore 0001, Claudio Soriente |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | A compiler for multi-key homomorphic signatures for Turing machines
Somayeh Dolatnezhad Samarin, Dario Fiore 0001, Daniele Venturi 0001, Morteza Amini |
Theor. Comput. Sci. | 2 |
| 2020 | Improving the Efficiency of Re-randomizable and Replayable CCA Secure Public Key Encryption
Antonio Faonio, Dario Fiore 0001 |
ACNS (1) | 2 |
| 2020 | Incrementally Aggregatable Vector Commitments and Applications to Verifiable Decentralized Storage
Matteo Campanelli, Dario Fiore 0001, Nicola Greco, Dimitris Kolonelos, Luca Nizzardo |
ASIACRYPT (2) | 2 |
| 2019 | Structure-Preserving and Re-randomizable RCCA-Secure Public Key Encryption and Its Applications
Antonio Faonio, Dario Fiore 0001, Javier Herranz, Carla Ràfols |
ASIACRYPT (3) | 2 |
| 2019 | LegoSNARK: Modular Design and Composition of Succinct Zero-Knowledge ProofsabstractWe study the problem of building non-interactive proof systems modularly by linking small specialized "gadget" SNARKs in a lightweight manner. Our motivation is both theoretical and practical. On the theoretical side, modular SNARK designs would be flexible and reusable. Also, previous works (e.g., Geppetto) consider They have been successfully employed in previous works.(cite prev papers ). These approaches, however, tend to be ad-hoc and to reinventing the wheel. We propose to fill this gap. In practice, specialized SNARKs have the potential to be more efficient than general-purpose schemes, on which most existing works have focused. If a computation naturally presents different "components" (e.g. one arithmetic circuit and one boolean circuit), a general-purpose scheme would homogenize them to a single representation with a subsequent cost in performance. Through a modular approach one could instead exploit the nuances of a computation and choose the best gadget for each component. Our contribution is LegoSNARK, a "toolbox" (or framework) for commit-and-prove zkSNARKs (CP-SNARKs) that includes: 1) General composition tools: build new CP-SNARKs from proof gadgets for basic relationssimply. Formalize notion of cc-SNARK. 2) A "lifting" tool: a compiler to add commit-and-prove capabilities to a broad class of existing zkSNARKsefficiently. This makes them interoperable (linkable) within the same computation. For example, one QAP-based scheme can be used prove one component; another GKR-based scheme can be used to prove another. 3) A collection of succinct proof gadgets for a variety of relations. Additionally, through our framework and gadgets, we are able to obtain new succinct proof systems. Notably: -- LegoGro16, a commit-and-prove version of Groth16 zkSNARK, that operates over data committed with a classical Pedersen vector commitment, and that achieves a 5000× speedup in proving time. -- LegoUAC, a pairing-based SNARK for arithmetic circuits that has a universal, circuit-independent, CRS, and proving time linear in the number of circuit gates (vs. the recent scheme of Groth et al. (CRYPTO'18) with quadratic CRS and quasilinear proving time). -- LegoMM, a CP-SNARK for matrix multiplication that achieves optimal proving complexity. Matteo Campanelli, Dario Fiore 0001, Anaïs Querol |
CCS | 2 |
| 2019 | Multi-key homomorphic authenticatorsabstractHomomorphic authenticators (HAs) enable a client to authenticate a large collection of data elements and outsource them, along with the corresponding authenticators, to an untrusted server. At any later point, the server can generate a short authenticator vouching for the correctness of the output y of a function f computed on the outsourced data, i.e. . The notion of HAs studied so far, however, only supports executions of computations over data authenticated by a single user. Motivated by realistic scenarios in which large datasets include data provided by multiple users, we study the concept of multi‐key homomorphic authenticators. In a nutshell, multi‐key HAs are like HAs with the extra feature of allowing the holder of public evaluation keys to compute on data authenticated under different secret keys. In this paper, we introduce and formally define multi‐key HAs. Secondly, we propose a construction of a multi‐key homomorphic signature based on standard lattices and supporting the evaluation of circuits of bounded polynomial depth. Thirdly, we provide a construction of multi‐key homomorphic MACs based only on pseudorandom functions and supporting the evaluation of low‐degree arithmetic circuits. Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin |
IET Inf. Secur. | 1 |
| 2019 | Automated Analysis of Cryptographic Assumptions in Generic Group Models
Gilles Barthe, Edvard Fagerholm, Dario Fiore 0001, John C. Mitchell, Andre Scedrov |
J. Cryptol. | 3 |
| 2018 | On the Security Notions for Homomorphic Signatures
Dario Catalano, Dario Fiore 0001, Luca Nizzardo |
ACNS | 2 |
| 2018 | Multi-Input Functional Encryption for Inner Products: Function-Hiding Realizations and Constructions Without Pairings
Michel Abdalla, Dario Catalano, Dario Fiore 0001, Romain Gay, Bogdan Ursu |
CRYPTO (1) | 3 |
| 2018 | Homomorphic signatures with sublinear public keys via asymmetric programmable hash functions
Dario Catalano, Dario Fiore 0001, Luca Nizzardo |
Des. Codes Cryptogr. | 2 |
| 2018 | Practical Homomorphic Message Authenticators for Arithmetic Circuits
Dario Catalano, Dario Fiore 0001 |
J. Cryptol. | 2 |
| 2017 | Practical Functional Encryption for Quadratic Functions with Applications to Predicate Encryption
Carmen Elisabetta Zaira Baltico, Dario Catalano, Dario Fiore 0001, Romain Gay |
CRYPTO (1) | 3 |
| 2017 | Labeled Homomorphic Encryption - Scalable and Privacy-Preserving Processing of Outsourced Data
Manuel Barbosa, Dario Catalano, Dario Fiore 0001 |
ESORICS (1) | 3 |
| 2017 | Partitioned Group Password-Based Authenticated Key ExchangeabstractGroup Password-Based Authenticated Key Exchange (GPAKE) allows a group of users to establish a secret key, as long as all of them share the same password. However, in existing GPAKE protocols as soon as one user runs the protocol with a non-matching password, all the others abort and no key is established. In this paper we seek for a more flexible, yet secure, GPAKE and put forward the notion of partitionedGPAKE. Partitioned GPAKE tolerates users that run the protocol on different passwords. Through a protocol run, any subgroup of users that indeed share a password, establish a session key, factoring out the ‘noise’ of inputs by users holding different passwords. At the same time any two keys, each established by a different subgroup of users, are pair-wise independent if the corresponding subgroups hold different passwords. We also introduce the notion of password-privacy for partitioned GPAKE, which is a kind of affiliation hiding property, ensuring that an adversary should not be able to tell whether any given set of users share a password. Finally, we propose an efficient instantiation of partitioned GPAKE building on an unforgeable symmetric encryption scheme and a PAKE by Bellare et al. Our proposal is proven secure in the random oracle/ideal cipher model, and requires only two communication rounds. Dario Fiore 0001, María Isabel González Vasco, Claudio Soriente |
Comput. J. | 1 |
| 2016 | Multi-key Homomorphic Authenticators
Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin |
ASIACRYPT (2) | 1 |
| 2016 | Hash First, Argue Later: Adaptive Verifiable Computations on Outsourced DataabstractProof systems for verifiable computation (VC) have the potential to make cloud outsourcing more trustworthy. Recent schemes enable a verifier with limited resources to delegate large computations and verify their outcome based on succinct arguments: verification complexity is linear in the size of the inputs and outputs (not the size of the computation). However, cloud computing also often involves large amounts of data, which may exceed the local storage and I/O capabilities of the verifier, and thus limit the use of VC. In this paper, we investigate multi-relation hash & prove schemes for verifiable computations that operate on succinct data hashes. Hence, the verifier delegates both storage and computation to an untrusted worker. She uploads data and keeps hashes; exchanges hashes with other parties; verifies arguments that consume and produce hashes; and selectively downloads the actual data she needs to access. Dario Fiore 0001, Cédric Fournet, Esha Ghosh, Markulf Kohlweiss, Olga Ohrimenko, Bryan Parno |
CCS | 1 |
| 2016 | Strongly-optimal structure preserving signatures from Type II pairings: synthesis and lower boundsabstractRecent work on structure‐preserving signatures (SPS) studies optimality of these schemes in terms of the number of group elements needed in the verification key and the signature, and the number of pairing‐product equations in the verification algorithm. While these measures are crucial for many applications, another important aspect to consider for performance is verification time, which for these schemes is dominated by pairings computation. Although prior work considers optimality in terms of number of pairing‐product equations, this measure does not capture the exact number of pairings needed in verification. To fill this gap, we study the minimal number of pairings needed in verification of SPS. First, we prove lower bounds for schemes in the Type~II setting secure under chosen message attacks in the generic group model. We show that three pairings are necessary and at most one of these pairings can be precomputed. Second, we build an automated tool to search for schemes matching our lower bounds. Using this tool, we find a new randomisable SPS in the Type~II setting that is optimal with respect to our lower bound on the number of pairings, and minimal in terms of group operations to be computed during verification. Gilles Barthe, Edvard Fagerholm, Dario Fiore 0001, Andre Scedrov, Mehdi Tibouchi |
IET Inf. Secur. | 3 |
| 2015 | Using Linearly-Homomorphic Encryption to Evaluate Degree-2 Functions on Encrypted DataabstractWe show a technique to transform a linearly-homomorphic encryption into a scheme capable of evaluating degree-2 computations on ciphertexts. Our transformation is surprisingly simple and requires only one very mild property on the underlying linearly-homomorphic scheme: the message space must be a public ring in which it is possible to sample elements uniformly at random. This allows us to instantiate our transformation with virtually all existing number-theoretic linearly-homomorphic schemes, such as Goldwasser-Micali, Paillier, or ElGamal. Our resulting schemes achieve circuit privacy and are compact when considering a subclass of degree-2 polynomials where the number of additions of degree-2 terms is bounded by a constant. Dario Catalano, Dario Fiore 0001 |
CCS | 2 |
| 2015 | Programmable Hash Functions Go Private: Constructions and Applications to (Homomorphic) Signatures with Shorter Public Keys
Dario Catalano, Dario Fiore 0001, Luca Nizzardo |
CRYPTO (2) | 2 |
| 2015 | ADSNARK: Nearly Practical and Privacy-Preserving Proofs on Authenticated DataabstractWe study the problem of privacy-preserving proofs on authenticated data, where a party receives data from a trusted source and is requested to prove computations over the data to third parties in a correct and private way, i.e., The third party learns no information on the data but is still assured that the claimed proof is valid. Our work particularly focuses on the challenging requirement that the third party should be able to verify the validity with respect to the specific data authenticated by the source -- even without having access to that source. This problem is motivated by various scenarios emerging from several application areas such as wearable computing, smart metering, or general business-to-business interactions. Furthermore, these applications also demand any meaningful solution to satisfy additional properties related to usability and scalability. In this paper, we formalize the above three-party model, discuss concrete application scenarios, and then we design, build, and evaluate ADSNARK, a nearly practical system for proving arbitrary computations over authenticated data in a privacy-preserving manner. ADSNARK improves significantly over state-of-the-art solutions for this model. For instance, compared to corresponding solutions based on Pinocchio (Oakland'13), ADSNARK achieves up to 25x improvement in proof-computation time and a 20x reduction in prover storage space. Michael Backes 0001, Manuel Barbosa, Dario Fiore 0001, Raphael M. Reischuk |
IEEE Symposium on Security and Privacy | 3 |
| 2015 | Algebraic (trapdoor) one-way functions: Constructions and applications
Dario Catalano, Dario Fiore 0001, Rosario Gennaro, Konstantinos Vamvourellis |
Theor. Comput. Sci. | 2 |
| 2014 | Efficiently Verifiable Computation on Encrypted DataabstractWe study the task of verifiable delegation of computation on encrypted data. We improve previous definitions in order to tolerate adversaries that learn whether or not clients accept the result of a delegated computation. In this strong model, we construct a scheme for arbitrary computations and highly efficient schemes for delegation of various classes of functions, such as linear combinations, high-degree univariate polynomials, and multivariate quadratic polynomials. Notably, the latter class includes many useful statistics. Using our solution, a client can store a large encrypted dataset on a server, query statistics over this data, and receive encrypted results that can be efficiently verified and decrypted. Dario Fiore 0001, Rosario Gennaro, Valerio Pastro |
CCS | 1 |
| 2014 | Automated Analysis of Cryptographic Assumptions in Generic Group Models
Gilles Barthe, Edvard Fagerholm, Dario Fiore 0001, John C. Mitchell, Andre Scedrov |
CRYPTO (1) | 3 |
| 2014 | Homomorphic Signatures with Efficient Verification for Polynomial Functions
Dario Catalano, Dario Fiore 0001, Bogdan Warinschi |
CRYPTO (1) | 2 |
| 2014 | Verifiable Random Functions: Relations to Identity-Based Key Encapsulation and New Constructions
Michel Abdalla, Dario Catalano, Dario Fiore 0001 |
J. Cryptol. | 3 |
| 2013 | Verifiable delegation of computation on outsourced dataabstractWe address the problem in which a client stores a large amount of data with an untrusted server in such a way that, at any moment, the client can ask the server to compute a function on some portion of its outsourced data. In this scenario, the client must be able to efficiently verify the correctness of the result despite no longer knowing the inputs of the delegated computation, it must be able to keep adding elements to its remote storage, and it does not have to fix in advance (i.e., at data outsourcing time) the functions that it will delegate. Even more ambitiously, clients should be able to verify in time independent of the input-size -- a very appealing property for computations over huge amounts of data. Michael Backes 0001, Dario Fiore 0001, Raphael M. Reischuk |
CCS | 2 |
| 2013 | Privacy-Preserving Accountable Computation
Michael Backes 0001, Dario Fiore 0001, Esfandiar Mohammadi |
ESORICS | 2 |
| 2013 | Practical Homomorphic MACs for Arithmetic Circuits
Dario Catalano, Dario Fiore 0001 |
EUROCRYPT | 2 |
| 2013 | Algebraic (Trapdoor) One-Way Functions and Their Applications
Dario Catalano, Dario Fiore 0001, Rosario Gennaro, Konstantinos Vamvourellis |
TCC | 2 |
| 2012 | Publicly verifiable delegation of large polynomials and matrix computations, with applicationsabstractOutsourced computations (where a client requests a server to perform some computation on its behalf) are becoming increasingly important due to the rise of Cloud Computing and the proliferation of mobile devices. Since cloud providers may not be trusted, a crucial problem is the verification of the integrity and correctness of such computation, possibly in a public way, i.e., the result of a computation can be verified by any third party, and requires no secret key -- akin to a digital signature on a message. We present new protocols for publicly verifiable secure outsourcing of Evaluation of High Degree Polynomials and Matrix Multiplication. Compared to previously proposed solutions, ours improve in efficiency and offer security in a stronger model. The paper also discusses several practical applications of our protocols. Dario Fiore 0001, Rosario Gennaro |
CCS | 1 |
| 2012 | Uniqueness Is a Different Story: Impossibility of Verifiable Random Functions from Trapdoor Permutations
Dario Fiore 0001, Dominique Schröder |
TCC | 1 |
| 2011 | Fully Non-interactive Onion Routing with Forward-Secrecy
Dario Catalano, Mario Di Raimondo, Dario Fiore 0001, Rosario Gennaro, Orazio Puglisi |
ACNS | 3 |
| 2011 | Adaptive Pseudo-free Groups and Applications
Dario Catalano, Dario Fiore 0001, Bogdan Warinschi |
EUROCRYPT | 2 |
| 2011 | Zero-Knowledge Sets With Short ProofsabstractZero knowledge sets (ZKS), introduced by Micali, Rabin, and Kilian in 2003, allow a prover to commit to a secret set$S$in a way such that it can later prove, non interactively, statements of the form$x\in S$(or$x\notin S$), without revealing any further information (on top of what explicitly revealed by the inclusion/exclusion statements above) on$S$, not even its size. Later, Chaseabstracted away the Micali, Rabin, and Kilian's construction by introducing an elegant new variant of commitments that they called (trapdoor) mercurial commitments. Using this primitive, it was shown how to construct zero knowledge sets from a variety of assumptions (both general and number theoretic). This paper introduces the notion of trapdoor$q$-mercurial commitments (${\ssr qTMC}$s), a notion of mercurial commitment that allows the sender to commit to an ordered sequence of exactly$q$messages, rather than to a single one. Following the previous work, it is shown how to construct ZKS from${\ssr qTMC}$s and collision resistant hash functions. Then, it is presented an efficient realization of${\ssr qTMC}$s that is secure under the so called Strong Diffie Hellman (SDH) assumption, a number theoretic conjecture recently introduced by Boneh and Boyen. Using such scheme as basic building block, it is obtained a construction of ZKS that allows for proofs that are much shorter with respect to the best previously known implementations. In particular, for an appropriate choice of the parameters, our proofs are up to 33% shorter for the case of proofs of membership, and up to 73% shorter for the case of proofs of nonmembership. Experimental tests confirm practical time performances. Dario Catalano, Mario Di Raimondo, Dario Fiore 0001, Mariagrazia Messina |
IEEE Trans. Inf. Theory | 3 |
| 2010 | Making the Diffie-Hellman Protocol Identity-Based
Dario Fiore 0001, Rosario Gennaro |
CT-RSA | 1 |
| 2010 | Constructing Certificateless Encryption and ID-Based Encryption from ID-Based Key Agreement
Dario Fiore 0001, Rosario Gennaro, Nigel P. Smart |
Pairing | 1 |
| 2009 | Certificateless onion routingabstractOnion routing protocols allow users to establish anonymous channels to preserve their privacy over a public network. Several protocols implementing this primitive have been proposed in recent years, and TOR, a real-life implementation, provides an onion routing service to thousands of users over the internet. Dario Catalano, Dario Fiore 0001, Rosario Gennaro |
CCS | 2 |
| 2009 | Verifiable Random Functions from Identity-Based Key Encapsulation
Michel Abdalla, Dario Catalano, Dario Fiore 0001 |
EUROCRYPT | 3 |
| 2008 | Zero-Knowledge Sets with Short Proofs
Dario Catalano, Dario Fiore 0001, Mariagrazia Messina |
EUROCRYPT | 2 |