EDBT 2026 Demo / reviewers in the wild / expert
Helger Lipmaa
dblp:l/HelgerLipmaa
· DBLP profile ↗
55ranked-venue papers
28as first author
14since 2021 · last 2026
0000-0001-8393-6821ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 49 · 26 first-author · 14 since 2021Theory of computation · 8 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cyclo: Lightweight Lattice-Based Folding via Partial Range Checks
Albert Garreta, Helger Lipmaa, Urmas Luhaäär, Michal Osadnik |
EUROCRYPT (7) | 2 |
| 2026 | Special Soundness and Binding Properties: A Framework for Tightly Secure zk-SNARKs
Erki Külaots, Helger Lipmaa, Roberto Parisella, Janno Siim |
EUROCRYPT (7) | 2 |
| 2025 | On Knowledge-Soundness of Plonk in ROM from Falsifiable Assumptions
Helger Lipmaa, Roberto Parisella, Janno Siim |
CRYPTO (7) | 1 |
| 2025 | Plonk is Simulation Extractable in ROM Under Falsifiable Assumptions
Helger Lipmaa |
TCC (4) | 1 |
| 2024 | Polymath: Groth16 Is Not the Limit
Helger Lipmaa |
CRYPTO (10) | 1 |
| 2024 | Constant-Size zk-SNARKs in ROM from Falsifiable Assumptions
Helger Lipmaa, Roberto Parisella, Janno Siim |
EUROCRYPT (6) | 1 |
| 2023 | On Black-Box Knowledge-Sound Commit-And-Prove SNARKs
Helger Lipmaa |
ASIACRYPT (2) | 1 |
| 2023 | Algebraic Group Model with Oblivious Sampling
Helger Lipmaa, Roberto Parisella, Janno Siim |
TCC (4) | 1 |
| 2022 | Counting Vampires: From Univariate Sumcheck to Updatable ZK-SNARK
Helger Lipmaa, Janno Siim, Michal Zajac 0001 |
ASIACRYPT (2) | 1 |
| 2021 | Efficient NIZKs for Algebraic Sets
Geoffroy Couteau, Helger Lipmaa, Roberto Parisella, Arne Tobias Ødegaard |
ASIACRYPT (3) | 2 |
| 2021 | Verifiably-Extractable OWFs and Their Applications to Subversion Zero-Knowledge
Prastudy Fauzi, Helger Lipmaa, Janno Siim, Michal Zajac 0001, Arne Tobias Ødegaard |
ASIACRYPT (4) | 2 |
| 2021 | Gentry-Wichs is Tight: a Falsifiable Non-adaptively Sound SNARG
Helger Lipmaa, Kateryna Pavlyk |
ASIACRYPT (3) | 1 |
| 2021 | More Efficient Shuffle Argument from Unique Factorization
Toomas Krips, Helger Lipmaa |
CT-RSA | 2 |
| 2021 | On Subversion-Resistant SNARKs
Behzad Abdolmaleki, Helger Lipmaa, Janno Siim, Michal Zajac 0001 |
J. Cryptol. | 2 |
| 2020 | Succinct Functional Commitment for a Large Class of Arithmetic Circuits
Helger Lipmaa, Kateryna Pavlyk |
ASIACRYPT (3) | 1 |
| 2019 | DL-Extractable UC-Commitment Schemes
Behzad Abdolmaleki, Karim Baghery, Helger Lipmaa, Janno Siim, Michal Zajac 0001 |
ACNS | 3 |
| 2017 | A Subversion-Resistant SNARK
Behzad Abdolmaleki, Karim Baghery, Helger Lipmaa, Michal Zajac 0001 |
ASIACRYPT (3) | 3 |
| 2017 | An Efficient Pairing-Based Shuffle Argument
Prastudy Fauzi, Helger Lipmaa, Janno Siim, Michal Zajac 0001 |
ASIACRYPT (2) | 2 |
| 2016 | A Shuffle Argument Secure in the Generic Model
Prastudy Fauzi, Helger Lipmaa, Michal Zajac 0001 |
ASIACRYPT (2) | 2 |
| 2016 | Efficient Culpably Sound NIZK Shuffle Argument Without Random Oracles
Prastudy Fauzi, Helger Lipmaa |
CT-RSA | 2 |
| 2015 | Analysis and Implementation of an Efficient Ring-LPN Based Commitment Scheme
Helger Lipmaa, Kateryna Pavlyk |
CANS | 1 |
| 2015 | Communication Optimal Tardos-Based Asymmetric Fingerprinting
Aggelos Kiayias, Nikos Leonardos, Helger Lipmaa, Kateryna Pavlyk, Qiang Tang 0005 |
CT-RSA | 3 |
| 2015 | Optimal Rate Private Information Retrieval from Homomorphic EncryptionabstractAbstract We consider the problem of minimizing the communication in single-database private information retrieval protocols in the case where the length of the data to be transmitted is large. We present first rate-optimal protocols for 1-out-of-n computationallyprivate information retrieval (CPIR), oblivious transfer (OT), and strong conditional oblivious transfer (SCOT). These protocols are based on a new optimalrate leveled homomorphic encryption scheme for large-output polynomial-size branching programs, that might be of independent interest. The analysis of the new scheme is intricate: the optimal rate is achieved if a certain parameter s is set equal to the only positive root of a degree-(m + 1) polynomial, where m is the length of the branching program. We show, by using Galois theory, that even when m = 4, this polynomial cannot be solved in radicals. We employ the Newton-Puiseux algorithm to find a Puiseux series for s, and based on this, propose a Θ (logm)-time algorithm to find an integer approximation to s. Aggelos Kiayias, Nikos Leonardos, Helger Lipmaa, Kateryna Pavlyk, Qiang Tang 0005 |
Proc. Priv. Enhancing Technol. | 3 |
| 2013 | Succinct Non-Interactive Zero Knowledge Arguments from Span Programs and Linear Error-Correcting Codes
Helger Lipmaa |
ASIACRYPT (1) | 1 |
| 2013 | Efficient Modular NIZK Arguments from Shift and Product
Prastudy Fauzi, Helger Lipmaa, Bingsheng Zhang |
CANS | 2 |
| 2013 | Secure Equality and Greater-Than Tests with Sublinear Online Complexity
Helger Lipmaa, Tomas Toft |
ICALP (2) | 1 |
| 2013 | A more efficient computationally sound non-interactive zero-knowledge shuffle argumentabstractWe propose a new non-interactive perfect zero-knowledge (NIZK) shuffle argument that, when compared with the only previously known efficient NIZK shuffle argument by Groth and Lu, has a small constant factor times smaller computation and communication, and is based on more standard computational as sumptions. Differently from Groth and Lu who only prove the co-soundness of their argument under purely computational assumptions, we prove computational soundness under a necessary knowledge assumption. We also present a general transformation that results in a shuffle argument that has a quadratically smaller common reference string (CRS) and a small constant factor times longer argument than the original shuffle. This can be interpreted as a general technique of decreasing the offline cost of an arbitrary shuffle argument. Helger Lipmaa, Bingsheng Zhang |
J. Comput. Secur. | 1 |
| 2012 | Secure Accumulators from Euclidean Rings without Trusted Setup
Helger Lipmaa |
ACNS | 1 |
| 2012 | Progression-Free Sets and Sublinear Pairing-Based Non-Interactive Zero-Knowledge Arguments
Helger Lipmaa |
TCC | 1 |
| 2010 | Additive Combinatorics and Discrete Logarithm Based Range Protocols
Rafik Chaabouni, Helger Lipmaa, Abhi Shelat |
ACISP | 2 |
| 2010 | Two New Efficient PIR-Writing Protocols
Helger Lipmaa, Bingsheng Zhang |
ACNS | 1 |
| 2010 | On the CCA1-Security of Elgamal and Damgård's Elgamal
Helger Lipmaa |
Inscrypt | 1 |
| 2010 | On E-Vote Integrity in the Case of Malicious Voter Computers
Sven Heiberg, Helger Lipmaa, Filip van Laenen |
ESORICS | 2 |
| 2009 | Efficient Generalized Selective Private Function Evaluation with Applications in Biometric Authentication
Helger Lipmaa, Bingsheng Zhang |
Inscrypt | 1 |
| 2008 | Hybrid Damgård Is CCA1-Secure under the DDH Assumption
Yvo Desmedt, Helger Lipmaa, Duong Hieu Phan |
CANS | 2 |
| 2008 | Succinct NP Proofs from an Extractability Assumption
Giovanni Di Crescenzo, Helger Lipmaa |
CiE | 2 |
| 2008 | 3-Message NP Arguments in the BPK Model with Optimal Soundness and Zero-Knowledge
Giovanni Di Crescenzo, Helger Lipmaa |
ISAAC | 2 |
| 2008 | New Communication-Efficient Oblivious Transfer Protocols Based on Pairings
Helger Lipmaa |
ISC | 1 |
| 2007 | A New Protocol for Conditional Disclosure of Secrets and Its Applications
Sven Laur, Helger Lipmaa |
ACNS | 2 |
| 2006 | Cryptographically private support vector machinesabstractWe propose private protocols implementing the Kernel Adatron and Kernel Perceptron learning algorithms, give private classification protocols and private polynomial kernel computation protocols. The new protocols return their outputs - either the kernel value, the classifier or the classifications - in encrypted form so that they can be decrypted only by a common agreement by the protocol participants. We show how to use the encrypted classifications to privately estimate many properties of the data and the classifier. The new SVM classifiers are the first to be proven private according to the standard cryptographic definitions. Sven Laur, Helger Lipmaa, Taneli Mielikäinen |
KDD | 2 |
| 2005 | Designated Verifier Signature Schemes: Attacks, New Security Notions and a New Construction
Helger Lipmaa, Guilin Wang, Feng Bao 0001 |
ICALP | 1 |
| 2005 | Private Itemset Support Counting
Sven Laur, Helger Lipmaa, Taneli Mielikäinen |
ICICS | 2 |
| 2005 | On Delegatability of Four Designated Verifier Signatures
Yong Li 0002, Helger Lipmaa, Dingyi Pei |
ICICS | 2 |
| 2005 | Hybrid Voting Protocols and Hardness of Manipulation
Edith Elkind, Helger Lipmaa |
ISAAC | 2 |
| 2005 | An Oblivious Transfer Protocol with Log-Squared Communication
Helger Lipmaa |
ISC | 1 |
| 2004 | On the Additive Differential Probability of Exclusive-Or
Helger Lipmaa, Johan Wallén, Philippe Dumas 0001 |
FSE | 1 |
| 2003 | On Diophantine Complexity and Statistical Zero-Knowledge Arguments
Helger Lipmaa |
ASIACRYPT | 1 |
| 2003 | Verifiable Homomorphic Oblivious Transfer and Private Equality Test
Helger Lipmaa |
ASIACRYPT | 1 |
| 2002 | Fast Software Implementations of SC2000
Helger Lipmaa |
ISC | 1 |
| 2002 | On Optimal Hash Tree Traversal for Interval Time-Stamping
Helger Lipmaa |
ISC | 1 |
| 2002 | Eliminating Counterevidence with Applications to Accountable Certificate ManagementabstractThis paper presents a method to increase the accountability of certificate management by making it intractable for the certification authority (CA) to create contradictory statements about the validity of a certificate. The core of the method is a new primitive, undeniable attester, that allows som eone to commit to some set S of bitstrings by publishing a short digest of S and to give attestations for any x that it is or is not a member of S. Such an attestation can be verified by obtaining in authenticated way the published digest and applying a verification algorithm to the triple of the bitstring, the attestation and the digest. The most important feature of this primitive is intractability of creating two contradictory proofs for the same candidate element x and digest. We give an efficient construction for undeniable attesters based on authenticated search trees. We show that the construction also applies to sets of more structured elements. We also show that undeniable attesters exist iff collision-resistant hash functions exist. Ahto Buldas, Peeter Laud, Helger Lipmaa |
J. Comput. Secur. | 3 |
| 2001 | Efficient Algorithms for Computing Differential Properties of Addition
Helger Lipmaa, Shiho Moriai |
FSE | 1 |
| 2000 | Accountable certificate management using undeniable attestationsabstractThis paper initiates a study of accountable certificate management methods, necessary to support long-term authenticity of digital documents.Our main contribution is a model for accountable certificate management, where clients receive attestations confirming inclusion/removal of their certificates from the database of valid certificates.We explain why accountability depends on the inability of the third parties to create contradictory attestations.After that we define an undeniable attester as a primitive that provides efficient attestation creation, publishing and verification, so that it is intractable to create contradictory attestations.We introduce authenticated search trees and build an efficient undeniable attester upon them.The proposed system is the first accountable long-term certificate management system.Moreover, authenticated search trees can be used in many security-critical applications instead of the (sorted) hash trees to reduce trust in the authorities, without decrease in efficiency.Therefore, the undeniable attester promises looks like a very useful cryptographic primitive with a wide range of applications. Ahto Buldas, Peeter Laud, Helger Lipmaa |
CCS | 3 |
| 1998 | Time-Stamping with Binary Linking Schemes
Ahto Buldas, Peeter Laud, Helger Lipmaa, Jan Willemson |
CRYPTO | 3 |
| 1998 | IDEA: A Cipher For Multimedia Architectures?
Helger Lipmaa |
Selected Areas in Cryptography | 1 |