Gustavo Zambonin

I am a PhD student at the Computer Security Lab of the Universidade Federal de Santa Catarina (UFSC), researching novel combinatorial (un)ranking algorithms to generate random objects in quantum-safe cryptosystems.

I also work as a consultant, helping private and public institutions to solve complex problems related to information security and computer science in general. Before starting my PhD, I worked in the reference implementation and technical specifications of the Brazilian Digital Signature Standard.

On a personal note, I’m enthusiastic about astronomy, immersive sim games, IBM keyboards specifically older than myself, and most songs with a saxophone line. 8)

A list of my publications. See also my dblp, Google Scholar, and ORCID profiles.

From ElGamal to Lattice-Based: Enhancing the Helios Voting System with Quantum-Safe Cryptography
J. P. C. Barbosa, G. Zambonin, T. B. Idalino, R. Custódio.
ACNS (3) 2025, pp. 29–49, June 2025.
Enhanced SIM Swap Security Practices via Ceremony Modeling
L. G. Rosa, G. Zambonin, J. E. Martina.
AINA (5) 2025, pp. 201–211, April 2025.
Practical algorithms and parameters for modification-tolerant signature scheme
A. B. Kamers, P. O. Abel, T. B. Idalino, G. Zambonin, J. E. Martina.
SBSeg 2024, pp. 522–537, September 2024.
A concrete LIP-based KEM with simple lattices
G. C. Biage, G. Zambonin, T. B. Idalino, D. Panario, R. Custódio.
IEEE Access 12, pp. 16408–16420, January 2024.
Monitoring key pair usage through distributed ledgers and one-time signatures
L. Mayr, L. Palma, G. Zambonin, W. Silvano, R. Custódio.
Information 14, no. 10, September 2023.
Improved constant-sum encodings for hash-based signatures
L. P. Perin, G. Zambonin, R. Custódio, L. Moura, D. Panario.
Journal of Cryptographic Engineering 11, no. 4, pp. 329–351, June 2021.
On the randomness of Rainbow signatures
G. Zambonin.
Master's thesis in Computer Science, Universidade Federal de Santa Catarina, October 2020.
Handling Vinegar Variables to Shorten Rainbow Private Keys
G. Zambonin, M. S. P. Bittencourt, R. Custódio.
AFRICACRYPT 2019, pp. 391–408, July 2019.
Tuning the Winternitz Hash-Based Digital Signature Scheme
L. P. Perin, G. Zambonin, D. M. B. Martins, R. Custódio, J. E. Martina.
ISCC 2018, pp. 537–542, June 2018.
Otimização de desempenho do esquema de assinatura digital Winternitz
[Performance optimization of the Winternitz digital signature scheme]
G. Zambonin.
Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, June 2018.

Ongoing supervisions

Analysis of ranking and unranking algorithms applied to post-quantum cryptography
D. L. L. Machado. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina.
Optimization of a library for lattice-based zero-knowledge proofs
P. C. Casotti. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina.
Security analysis of the Knet HSM
G. G. Farias. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina.
Computational limitations of compression and ranking functions
T. F. Siqueira. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina.
Emergency financial lock: mitigating financial fraud in smartphone thefts
V. L. Souza. Bachelor thesis in Information Systems, Universidade Federal de Santa Catarina.
Energy-aware phase ordering in compilers: a heuristic-based solution
A. P. Gretter. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina.

Completed supervisions

Geração e análise de grafos curriculares para planejamento acadêmico
[Generation and analysis of curriculum graphs for academic planning]
M. P. Novais. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2025.
Fuzzing para detecção de vulnerabilidades em Java: uma taxonomia unificada e análise do estado da arte
[Fuzzing for vulnerability detection in Java: a unified taxonomy and state-of-the-art analysis]
E. Moraes. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2025.
Provas de conhecimento zero: um estudo sobre zk-SNARKs e sua aplicação em sistemas de autenticação
[Zero-knowledge proofs: a study of zk-SNARKs and applications in authentication systems]
A. D. N. Silva. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, November 2025.
Implementação otimizada de um esquema de assinaturas digitais tolerantes a modificações com suporte à remoção de conteúdo
[Optimized implementation of a modification-tolerant digital signature scheme with support for content removal]
L. C. T. Machado. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, June 2025.
Assinaturas digitais com referências externas para certificados de chave pública
[Digital signatures with external references to public-key certificates]
M. Tomaszewski. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2024.
Modeling the SIM swap ceremony: integrating human behavior and formal analysis
L. G. Rosa. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, July 2024.
Votação eletrônica pós-quântica aplicada no Helios Voting
[Post-quantum electronic voting in the Helios framework]
J. P. C. Barbosa. Bachelor thesis in Information Systems, Universidade Federal de Santa Catarina, July 2024.
Homomorphic encryption: introduction and applicabilities
A. B. Kamers. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2023.
Esquema de assinatura digital tolerante a modificações
[A modification-tolerant digital signature scheme]
P. O. Abel. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, June 2023.
Estudo de esquema de assinatura digital Dilithium
[A study of the Dilithium digital signature scheme]
G. C. Biage. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, July 2022.
Reducing keys in Rainbow-like signature schemes
M. S. P. Bittencourt. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2019.

Assistantships

Security & AI Ago/25 – Dec/25
Class INE5448-08208 (Special Topics in Technological Applications I), Bachelor's in Computer Science, Universidade Federal de Santa Catarina.
Security & AI Mar/25 – Jul/25
Class INE5448-08208 (Special Topics in Technological Applications I), Bachelor's in Computer Science, Universidade Federal de Santa Catarina.
Post Quantum Cryptography and Computation Aug/19 – Nov/19
Class INE410134-41000025DO/ME, Graduate Program in Computer Science, Universidade Federal de Santa Catarina.
Mathematical Foundations of Informatics Aug/18 – Dec/18
Class INE5601-01238A, Bachelor's in Information Systems, Universidade Federal de Santa Catarina.
Probability and Statistics Mar/15 – Jul/15
Class INE5405-02208A, Bachelor's in Computer Science, Universidade Federal de Santa Catarina.
Probability and Statistics Aug/14 – Dec/14
Class INE5405-02208A, Bachelor's in Computer Science, Universidade Federal de Santa Catarina.

Research visits

Mitacs-CALAREO Globalink Research Award Mar/20 – Jun/20
Visiting researcher at Carleton University. Granted as the result of a project to study the security of Rainbow-like signature schemes. Part of my master's research.

Talks

Random generation of combinatorial objects in cryptographic systems Oct/24
Speaker at the 2024 CS & IS Academic Week (Universidade Federal de Santa Catarina). Brief introduction on using combinatorial unranking to perform uniform random generation of objects for cryptosystems.
Cryptographic applications of restricted integer compositions Aug/24
Speaker at the IV Workshop on Finite Fields and Applications (Universidade Federal de Minas Gerais). Combinatorial view of 10.1007/s13389-021-00264-9 and preliminary improvements.
Cryptographic applications of weak restricted integer compositions Jun/21
Speaker at the 25th Ontario Combinatorics Workshop (Queen's University). Combinatorial view of 10.1007/s13389-021-00264-9 and preliminary improvements.
Security analysis of the Rainbow-eta signature scheme Mar/21
Speaker at the 2021 International Research Mobility Symposium (Carleton University). Results of a research award.
Data analysis with SEstatNet Oct/14
Lecturer at the 13th SEPEX (Universidade Federal de Santa Catarina). Held a workshop on data analysis and processing with a specialized tool developed at the university.

Evaluation boards

Anonimização como pilar de segurança em interações com modelos de linguagem: potenciais e limitações
[Anonymization as a pillar of security in interactions with language models: potential and limitations]
L. C. P. Sousa. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2025.
Prescrições médicas auto-soberanas: fortalecendo a segurança e a privacidade
[Self-sovereign medical prescriptions: strengthening security and privacy]
T. V. Junckes. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2023.
Protocolo ACME pós-quântico
[Post-quantum ACME protocol]
M. O. Saldanha. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, March 2022.
Interoperabilidade em aplicações distribuídas: um estudo de DLTs como infraestrutura para hospedagem de aplicações web
[Interoperability in distributed applications: using DLTs to host web applications]
R. S. A. Palma. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, September 2021.
Implementing a library to provide Winternitz signatures with lightweight primitive using the Rust Programming Language
L. M. Athayde. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, May 2021.
Verificação de eleição utilizando blockchain
[Verifiable elections with blockchain]
V. Macelai. Bachelor thesis in Computer Science, Universidade Federal de Santa Catarina, December 2019.

Other service

Peer reviewer Jan/20 – Today
Reviewed for Designs, Codes and Cryptography, Applicable Algebra in Engineering, Communication and Computing, SAC 2025, and LATINCRYPT 2023.
Student representative May/19 – May/20
Elected by peers for the Graduate Program's governing bodies (colegiados). Represented other students in decision-making and served on the Scholarships Committee.
Student member Sep/19 – Oct/19
Volunteered to be part of the Election Commission for the Graduate Program's directorship. Audited the election and verified its results for the 2019–2021 term.
Co-organizer Apr/18 – Dec/18
19th Biology Academic Week at the Universidade Federal de Santa Catarina. Developed an attendance system to accurately provide certificates to students and community.

Independent work

Consultant on digital signatures Apr/24 – Today
In partnership with the National Operator of the Civil Registry of Brazil. I design and develop solutions to enhance digital signature adoption in civil registration and notary public processes.
Consultant on trusted lists Sep/22 – Mar/23
In partnership with the Electronic Government Network of Latin America and the Caribbean (Red Gealc). Developed tools to assist the usage of digital signatures in cross-border operations via trusted lists, pursuant to ETSI standards. Featured in the news at least three times.
Consultant on digital signature standards Jan/22 – Mar/22
In partnership with private companies. Developed a tool to validate digital diplomas, and accompanying files, according to the standards maintained by the Ministry of Education of Brazil.
Computer forensic examiner Dec/20 – Mar/21
In partnership with an intelligent transportation systems company. Processed a complex dataset with native GNU/Linux tools and used statistical techniques to verify the accuracy of the classification of pictures taken by speed enforcement cameras.
Security ceremony agent Oct/18 – Nov/20
In partnership with several Brazilian public institutions. Provisioned secure servers to run online elections through the end-to-end verifiable voting system Helios, with reduced need for human-computer interaction.
Researcher of quantum-safe blockchain protocols Sep/18 – Mar/19
In partnership with a novel blockchain platform. Co-developed a protocol to quantum-proof a blockchain, with secure substitution of wallets, replacement of cryptographic algorithms and zero downtime for the platform.
Computer forensic examiner Sep/17 – Apr/18
In partnership with an intelligent transportation systems company. Built a time series from various evidence sources forming a complex dataset, used to ascertain the authenticity and accuracy of pictures taken by speed enforcement cameras.

Computer Security Lab (UFSC)

Technical lead and researcher Jan/20 – Feb/24
Supervised research and development efforts to add support for quantum-safe cryptography, JAdES and trusted lists to normatives, as well as further development of desktop, web and mobile tools used in the Brazilian Public-Key Infrastructure (ICP-Brasil) to generate and validate digital signatures.
Software developer and systems administrator Jan/18 – Dec/19
Led a major development effort towards modernizing the official digital signature validation tool of ICP-Brasil, that resulted in a responsive new web interface, an API that enables headless/batch signature validation, enforced automated unit testing and continuous deployment practices.
Junior software developer Nov/16 – Dec/17
Developed a proof-of-concept signature validation module for PDF.js and a small library able to easily customize and instantiate most artifacts in a public-key infrastructure.
Junior software developer May/16 – Oct/16
Implemented support for CMS signatures (attached, detached or embedded in PDFs) in the official digital signature validation tool of ICP-Brasil.