Benedikt Wagner

dblp:244/9639 · DBLP profile ↗
← Back
25ranked-venue papers
0as first author
25since 2021 · last 2026
0000-0002-4620-7264ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 23 since 2021Systems, architecture and hardware · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Tight Lattice-Based Signatures Without Trapdoors from Search LWE
Rutchathon Chairattana-Apirom, Nico Döttling, Julian Loss, Stefano Tessaro, Benedikt Wagner
CRYPTO (3)5
2026 Aborting Random Oracles: How to Build Them, How to Use Them
Gottfried Herold, Dmitry Khovratovich, Mikhail A. Kudinov, Stefano Tessaro, Benedikt Wagner
CRYPTO (6)5
2026 Byzantine Consensus in the Partially Authenticated Setting
abstract
Byzantine Agreement and Broadcast are traditionally studied in one of two extremes: the authenticated setting, where a public key infrastructure (PKI) enables universally verifiable signatures and yields higher fault tolerance, and the unauthenticated setting, where no PKI is available and resilience necessarily drops. Motivated by Proof-of-Stake blockchains, where only a stable subset of participants (e.g., validators) have registered long-term keys while others do not, we initiate a systematic study of consensus in the partially authenticated setting, where a subset of parties are registered in a PKI and the remaining parties are unregistered.
Christoph Lenzen 0001, Julian Loss, Kecheng Shi 0001, Benedikt Wagner
PODC4
2026 Generic Constructions of Compact and Tightly Selective-Opening Secure Public-Key Encryption Schemes
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng
J. Cryptol.2
2025 T-Spoon: Tightly Secure Two-Round Multi-signatures with Key Aggregation
Renas Bacho, Benedikt Wagner
CRYPTO (6)2
2025 At the Top of the Hypercube - Better Size-Time Tradeoffs for Hash-Based Signatures
Dmitry Khovratovich, Mikhail A. Kudinov, Benedikt Wagner
CRYPTO (6)3
2025 Kleptographic Attacks Against Implicit Rejection
Antoine Joux, Julian Loss, Benedikt Wagner
PKC (4)3
2025 Sublinear-Round Broadcast without Trusted Setup
abstract
Byzantine broadcast is one of the fundamental problems in distributed computing. Many of its practical applications, from multiparty computation to consensus mechanisms for blockchains, require increasingly weaker trust assumptions, as well as scalability for an ever-growing number of users n. This rules out existing solutions which run in a linear number of rounds in n or rely on trusted setup requirements. In this paper, we propose the first sublinear-round and trustless Byzantine broadcast protocol for the dishonest majority setting. Unlike previous sublinear-round protocols, our protocol assumes neither the existence of a trusted dealer who honestly issues keys and correlated random strings to the parties nor random oracles. Instead, we present a solution whose setup is limited to an unstructured uniform reference string and a plain public key infrastructure (a.k.a. bulletin-board PKI).
Andreea B. Alexandru, Julian Loss, Charalampos Papamanthou, Giorgos Tsimos, Benedikt Wagner
SODA5
2024 HARTS: High-Threshold, Adaptively Secure, and Robust Threshold Schnorr Signatures
Renas Bacho, Julian Loss, Gilad Stern, Benedikt Wagner
ASIACRYPT (3)4
2024 Tightly Secure Non-interactive BLS Multi-signatures
Renas Bacho, Benedikt Wagner
ASIACRYPT (2)2
2024 Jackpot: Non-interactive Aggregatable Lotteries
Nils Fleischhacker, Mathias Hall-Andersen, Mark Simkin 0001, Benedikt Wagner
ASIACRYPT (6)4
2024 Practical Blind Signatures in Pairing-Free Groups
Michael Klooß, Michael Reichle, Benedikt Wagner
ASIACRYPT (1)3
2024 FRIDA: Data Availability Sampling from FRI
Mathias Hall-Andersen, Mark Simkin 0001, Benedikt Wagner
CRYPTO (6)3
2024 Twinkle: Threshold Signatures from DDH with Full Adaptive Security
Renas Bacho, Julian Loss, Stefano Tessaro, Benedikt Wagner, Chenzhi Zhu
EUROCRYPT (1)4
2024 A Holistic Security Analysis of Monero Transactions
Cas Cremers, Julian Loss, Benedikt Wagner
EUROCRYPT (3)3
2024 Toothpicks: More Efficient Fork-Free Two-Round Multi-signatures
Jiaxin Pan 0001, Benedikt Wagner
EUROCRYPT (1)2
2024 Sweep-UC: Swapping Coins Privately
abstract
Fair exchange (also referred to as atomic swap) is a fundamental operation in any cryptocurrency that allows users to atomically exchange coins. While a large body of work has been devoted to this problem, most solutions lack on-chain privacy. Thus, coins retain a public transaction history which is known to degrade the fungibility of a currency. This has led to a flourishing line of related research on fair exchange with privacy guarantees. Existing protocols either rely on heavy scripting (which also degrades fungibility and leads to high transaction fees), do not support atomic swaps across a wide range of currencies, or come with incomplete security proofs.To overcome these limitations, we introduce Sweep-UC1, the first fair exchange protocol that simultaneously is efficient, minimizes scripting, and is compatible with a wide range of currencies (more than the state of the art). We build SweepUC from modular sub-protocols and give a rigorous security analysis in the UC framework. Many of our tools and security definitions can be used in standalone fashion and may serve as useful components for future constructions of fair exchange.
Lucjan Hanzlik, Julian Loss, Sri Aravinda Krishnan Thyagarajan, Benedikt Wagner
SP4
2024 Generic constructions of master-key KDM secure attribute-based encryption
Jiaxin Pan 0001, Chen Qian 0002, Benedikt Wagner
Des. Codes Cryptogr.3
2023 Tighter Security for Generic Authenticated Key Exchange in the QROM
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng
ASIACRYPT (4)2
2023 Lattice-Based Authenticated Key Exchange with Tight Security
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng
CRYPTO (5)2
2023 Rai-Choo! Evolving Blind Signatures to the Next Level
Lucjan Hanzlik, Julian Loss, Benedikt Wagner
EUROCRYPT (5)3
2023 Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive Assumptions
Jiaxin Pan 0001, Benedikt Wagner
EUROCRYPT (5)2
2023 Token meets Wallet: Formalizing Privacy and Revocation for FIDO2
abstract
The FIDO2 standard is a widely-used class of challenge-response type protocols that allows to authenticate to an online service using a hardware token. Barbosa et al. (CRYPTO ‘21) provided the first formal security model and analysis for the FIDO2 standard. However, their model has two shortcomings: (1) It does not include privacy, one of the key features claimed by FIDO2. (2) It only covers tokens that store all secret keys locally. In contrast, due to limited memory, most existing FIDO2 tokens either derive all secret keys from a common seed or store keys on the server (the latter approach is also known as key wrapping).In this paper, we revisit the security of the WebAuthn component of FIDO2 as implemented in practice. Our contributions are as follows. (1) We adapt the model of Barbosa et al. so as to capture authentication tokens using key derivation or key wrapping. (2) We provide the first formal definition of privacy for the WebAuthn component of FIDO2. We then prove the privacy of this component in common FIDO2 token implementations if the underlying building blocks are chosen appropriately. (3) We address the unsolved problem of global key revocation in FIDO2. To this end, we introduce and analyze a simple revocation procedure that builds on the popular BIP32 standard used in cryptocurrency wallets and can efficiently be implemented with existing FIDO2 servers.
Lucjan Hanzlik, Julian Loss, Benedikt Wagner
SP3
2022 PI-Cut-Choo and Friends: Compact Blind Signatures via Parallel Instance Cut-and-Choose and More
Rutchathon Chairattana-Apirom, Lucjan Hanzlik, Julian Loss, Anna Lysyanskaya, Benedikt Wagner
CRYPTO (3)5
2021 Short Identity-Based Signatures with Tight Security from Lattices
Jiaxin Pan 0001, Benedikt Wagner
PQCrypto2