VLDB 2026 Research / reviewers in the wild / expert
Andreas Hülsing
dblp:27/1744
· DBLP profile ↗
39ranked-venue papers
10as first author
22since 2021 · last 2026
0000-0003-2215-4134ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 10 first-author · 22 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Starfighters-On the General Applicability of X-Wing
Deirdre Connolly, Kathrin Hövelmanns, Andreas Hülsing, Stavros Kousidis, Matthias Meijers |
SP | 3 |
| 2025 | How Hard can it be to Formalize a Proof? - Lessons from Formalizing CryptoBox Three Times in EasyCrypt
François Dupressoir, Andreas Hülsing, Cameron Low, Matthias Meijers, Charlotte Mylog, Sabine Oechsner |
ASIACRYPT (2) | 2 |
| 2025 | Hybrid-Query Bounds with Partial Input Control Framework and Application to Tight M-eTCR
Andreas Hülsing, Mikhail A. Kudinov, Christian Majenz |
ASIACRYPT (8) | 1 |
| 2025 | A Key-Update Mechanism for the Space Data Link Security Protocol
Andreas Hülsing, Tanja Lange 0001, Fiona Johanna Weber |
CANS | 1 |
| 2025 | (Un)breakable Curses - Re-encryption in the Fujisaki-Okamoto Transform
Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz, Fabrizio Sisinni |
EUROCRYPT (2) | 2 |
| 2024 | A Tight Security Proof for SPHINCS+, Formally Verified
Manuel Barbosa, François Dupressoir, Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub |
ASIACRYPT (4) | 3 |
| 2024 | Towards Post-quantum Secure PAKE - A Tight Security Proof for OCAKE in the BPR Model
Nouri Alnahawi, Kathrin Hövelmanns, Andreas Hülsing, Silvia Ritsch |
CANS (2) | 3 |
| 2024 | On Round Elimination for Special-Sound Multi-round Identification and the Generality of the Hypercube for MPCitH
Andreas Hülsing, David Joseph, Christian Majenz, Anand Kumar Narayanan |
CRYPTO (1) | 1 |
| 2024 | Batch Signatures, Revisited
Carlos Aguilar Melchor, Martin R. Albrecht, Thomas Bailleux, Nina Bindel, James Howe, Andreas Hülsing, David Joseph, Marc Manzano |
CT-RSA | 6 |
| 2023 | SDitH in the QROM
Carlos Aguilar Melchor, Andreas Hülsing, David Joseph, Christian Majenz, Eyal Ronen, Dongze Yue |
ASIACRYPT (7) | 2 |
| 2023 | Fixing and Mechanizing the Security Proof of Fiat-Shamir with Aborts and Dilithium
Manuel Barbosa, Gilles Barthe, Christian Doczkal, Jelle Don, Serge Fehr, Benjamin Grégoire, Yu-Hsuan Huang 0003, Andreas Hülsing, Yi Lee, Xiaodi Wu 0001 |
CRYPTO (5) | 8 |
| 2023 | Machine-Checked Security for rmXMSS as in RFC 8391 and $\mathrm {SPHINCS^{+}} $
Manuel Barbosa, François Dupressoir, Benjamin Grégoire, Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub |
CRYPTO (5) | 4 |
| 2023 | The Return of the SDitH
Carlos Aguilar Melchor, Nicolas Gama, James Howe, Andreas Hülsing, David Joseph, Dongze Yue |
EUROCRYPT (5) | 4 |
| 2023 | SPHINCS+C: Compressing SPHINCS+ With (Almost) No CostabstractSPHINCS+ [CCS ’19] is one of the selected post-quantum digital signature schemes of NIST’s post-quantum standardization process. The scheme is a hash-based signature and is considered one of the most secure and robust proposals. The proposal includes a fast (but larger) variant and a small (but slower) variant for each security level. The main problem that might hinder its adoption is its large signature size. Although SPHINCS+ supports a trade-off between signature size and the computational cost of signing, further reducing the signature size (below the small variants) results in a prohibitively high computational cost for the signer.This paper presents several novel methods for further compressing the signature size while requiring negligible added computational costs for the signer and further reducing verification time. Moreover, our approach enables a much more efficient trade-off curve between signature size and the computational costs of the signer. In many parameter settings, we achieve small signatures and faster running times simultaneously. For example, for 128-bit (classical) security, the small signature variant of SPHINCS+ is 7856 bytes long, while our variant is only 6304 bytes long: a compression of approximately 20% while still reducing the signer’s running time. However, other trade-offs that focus, e.g., on verification speed, are possible.The main insight behind our scheme is that there are predefined specific subsets of messages for which the WOTS+ and FORS signatures (that SPHINCS+ uses) can be compressed, and generation can be made faster while maintaining the same security guarantees. Although most messages will not come from these subsets, we can search for suitable hashed values to sign. We sign a hash of the message concatenated with a counter that was chosen such that the hashed value is in the subset. The resulting signature is both smaller and faster to sign and verify.Our schemes are simple to describe and implement. We provide an implementation, a theoretical analysis of speed and security, as well as benchmark results. Andreas Hülsing, Mikhail A. Kudinov, Eyal Ronen, Eylon Yogev |
SP | 1 |
| 2022 | Failing Gracefully: Decryption Failures and the Fujisaki-Okamoto Transform
Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz |
ASIACRYPT (4) | 2 |
| 2022 | Recovering the Tight Security Proof of SPHINCS+
Andreas Hülsing, Mikhail A. Kudinov |
ASIACRYPT (4) | 1 |
| 2022 | Post Quantum NoiseabstractWe introduce PQNoise, a post-quantum variant of the Noise framework. We demonstrate that it is possible to replace the Diffie-Hellman key-exchanges in Noise with KEMs in a secure way. A challenge is the inability to combine key pairs of KEMs, which can be resolved by certain forms of randomness-hardening for which we introduce a formal abstraction. We provide a generic recipe to turn classical Noise patterns into PQNoise patterns. We prove that the resulting PQNoise patterns achieve confidentiality and authenticity in the fACCE model. Moreover we show that for those classical Noise-patterns that have been conjectured or proven secure in the fACCE model our matching PQNoise patterns eventually achieve the same security. Our security proof is generic and applies to any valid PQNoise pattern. This is made possible by another abstraction, called a hash-object, which hides the exact workings of how keying material is processed in an abstract stateful object that outputs pseudorandom keys under different corruption patterns. We also show that the hash chains used in Noise are a secure hash-object. Finally, we demonstrate the practicality of PQNoise delivering benchmarks for several base patterns. Yawning Angel, Benjamin Dowling, Andreas Hülsing, Peter Schwabe, Florian Weber |
CCS | 3 |
| 2022 | Formal Verification of Saber's Public-Key Encryption Scheme in EasyCrypt
Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub |
CRYPTO (1) | 1 |
| 2021 | Tight Adaptive Reprogramming in the QROM
Alex Bredariol Grilo, Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz |
ASIACRYPT (1) | 3 |
| 2021 | Verifying Post-Quantum Signatures in 8 kB of RAM
Andreas Hülsing, Matthias J. Kannwischer, Juliane Krämer, Tanja Lange 0001, Marc Stöttinger, Elisabeth Waitz, Thom Wiggers, Bo-Yin Yang |
PQCrypto | 2 |
| 2021 | Post-quantum WireGuardabstractIn this paper we present PQ-WireGuard, a post-quantum variant of the handshake in the WireGuard VPN protocol (NDSS 2017). Unlike most previous work on post-quantum security for real-world protocols, this variant does not only consider post-quantum confidentiality (or forward secrecy) but also post-quantum authentication. To achieve this, we replace the Diffie-Hellman-based handshake by a more generic approach only using key-encapsulation mechanisms (KEMs). We establish security of PQ-WireGuard, adapting the security proofs for WireGuard in the symbolic model and in the standard model to our construction. We then instantiate this generic construction with concrete post-quantum secure KEMs, which we carefully select to achieve high security and speed. We demonstrate competitiveness of PQ-WireGuard presenting extensive bench-marking results comparing to widely deployed VPN solutions. Andreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber, Philip R. Zimmermann |
SP | 1 |
| 2021 | Epochal Signatures for Deniable Group ChatsabstractIn this work we take a formal look at deniability in group chat applications and introduce the concept of "epochal signatures" that allows to turn many secure group chat protocols into deniable ones. Intuitively, the transform works for protocols that use signatures for authentication and that become deniable if the signatures are removed. In contrast to previous proposals that use signatures for entity authentication, like mpOTR (CCS’09), our construction does not require pairwise key establishment of participants and allows to add and remove participants without requiring to re-initialize the chat. These properties allow the deployment in protocols that are also designed to scale to very large groups. Finally, we construct a practical epochal signature scheme from generic primitives and prove it secure. Andreas Hülsing, Florian Weber |
SP | 1 |
| 2019 | Decisional Second-Preimage Resistance: When Does SPR Imply PRE?
Daniel J. Bernstein, Andreas Hülsing |
ASIACRYPT (3) | 2 |
| 2019 | The SPHINCS+ Signature FrameworkabstractWe introduce SPHINCS+, a stateless hash-based signature framework. SPHINCS+ has significant advantages over the state of the art in terms of speed, signature size, and security, and is among the nine remaining signature schemes in the second round of the NIST PQC standardization project. One of our main contributions in this context is a new few-time signature scheme that we call FORS. Our second main contribution is the introduction of tweakable hash functions and a demonstration how they allow for a unified security analysis of hash-based signature schemes. We give a security reduction for SPHINCS+ using this abstraction and derive secure parameters in accordance with the resulting bound. Finally, we present speed results for our optimized implementation of SPHINCS+ and compare to SPHINCS-256, Gravity-SPHINCS, and Picnic. Daniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, Peter Schwabe |
CCS | 2 |
| 2019 | Quantum Indistinguishability of Random Sponges
Jan Czajkowski, Andreas Hülsing, Christian Schaffner |
CRYPTO (2) | 2 |
| 2019 | Tighter Proofs of CCA Security in the Quantum Random Oracle Model
Nina Bindel, Michael Hamburg, Kathrin Hövelmanns, Andreas Hülsing, Edoardo Persichetti |
TCC (2) | 4 |
| 2018 | Post-quantum Security of the Sponge Construction
Jan Czajkowski, Leon Groot Bruinderink, Andreas Hülsing, Christian Schaffner, Dominique Unruh |
PQCrypto | 3 |
| 2017 | High-Speed Key Encapsulation from NTRU
Andreas Hülsing, Joost Rijneveld, John M. Schanck, Peter Schwabe |
CHES | 1 |
| 2017 | "Oops, I Did It Again" - Security of One-Time Signatures Under Two-Message Attacks
Leon Groot Bruinderink, Andreas Hülsing |
SAC | 2 |
| 2016 | From 5-Pass MQ -Based Identification to MQ -Based SignaturesabstractThis paper presents MQDSS, the first signature scheme with a security reduction based on the problem of solving a multivariate system of quadratic equations ( $$\mathcal {MQ}$$ problem). In order to construct this scheme we give a new security reduction for the Fiat-Shamir transform from a large class of 5-pass identification schemes and show that a previous attempt from the literature to obtain such a proof does not achieve the desired goal. We give concrete parameters for MQDSS and provide a detailed security analysis showing that the resulting instantiation MQDSS-31-64 achieves 128 bits of post-quantum security. Finally, we describe an optimized implementation of MQDSS-31-64 for recent Intel processors with full protection against timing attacks and report benchmarks of this implementation. Ming-Shing Chen, Andreas Hülsing, Joost Rijneveld, Simona Samardjiska, Peter Schwabe |
ASIACRYPT (2) | 2 |
| 2016 | Flush, Gauss, and Reload - A Cache Attack on the BLISS Lattice-Based Signature Scheme
Leon Groot Bruinderink, Andreas Hülsing, Tanja Lange 0001, Yuval Yarom |
CHES | 2 |
| 2016 | Semantic Security and Indistinguishability in the Quantum World
Tommaso Gagliardoni, Andreas Hülsing, Christian Schaffner |
CRYPTO (3) | 2 |
| 2015 | PALPAS - PAssword Less PAssword SynchronizationabstractTools that synchronize passwords over several user devices typically store the encrypted passwords in a central online database. For encryption, a low-entropy, password-based key is used. Such a database may be subject to unauthorized access which can lead to the disclosure of all passwords by an offline brute-force attack. In this paper, we present PALPAS, a secure and user-friendly tool that synchronizes passwords between user devices without storing information about them centrally. The idea of PALPAS is to generate a password from a high entropy secret shared by all devices and a random salt value for each service. Only the salt values are stored on a server but not the secret. The salt enables the user devices to generate the same password but is statistically independent of the password. In order for PALPAS to generate passwords according to different password policies, we also present a mechanism that automatically retrieves and processes the password requirements of services. PALPAS users need to only memorize a single password and the setup of PALPAS on a further device demands only a one-time transfer of few static data. Moritz Horsch, Andreas Hülsing, Johannes Buchmann 0001 |
ARES | 2 |
| 2015 | Bad Directions in Cryptographic Hash Functions
Daniel J. Bernstein, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen |
ACISP | 2 |
| 2015 | SPHINCS: Practical Stateless Hash-Based SignaturesabstractThis paper introduces a high-security post-quantum stateless hash-based signature scheme that signs hundreds of messages per second on a modern 4-core 3.5GHz Intel CPU. Signatures are 41 KB, public keys are 1 KB, and private keys are 1 KB. The signature scheme is designed to provide long-term $$2^{128}$$ security even against attackers equipped with quantum computers. Unlike most hash-based designs, this signature scheme is stateless, allowing it to be a drop-in replacement for current signature schemes. Daniel J. Bernstein, Daira Hopwood, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen, Louiza Papachristodoulou, Michael Schneider 0002, Peter Schwabe, Zooko Wilcox-O'Hearn |
EUROCRYPT (1) | 3 |
| 2014 | Developing and testing SCoP - a visual hash schemeabstractPurpose – The purpose of this study was to develop and test SCoP. Users find comparing long meaningless strings of alphanumeric characters difficult. While visual hashes – where users compare images rather than strings – have been proposed as an alternative, people are unable to sufficiently distinguish more than 30 bits, which does not provide adequate security against collision attacks. Our goal is to improve the situation. Design/methodology/approach – A visual hash scheme was developed using shapes, colours, patterns and position parameters. It was evaluated in a series of pilot user studies and improved iteratively, leading to SCoP, which encodes 60 distinguishable bits. We tested SCoP further in two follow-up studies, simulating verifying in remote electronic voting and https certificate validation. Findings – Participants attained an average accuracy rate of 97 per cent with SCoP when comparing two visual hash images, one placed above the other. From the follow-up studies, SCoP was seen to be more promising for the https certificate validation use case, with direct image comparison, while a low average accuracy rate in simulating verifiability in remote electronic voting limits its applicability in an image-recall use case. Research limitations/implications – Participants achieved high accuracy rates in unrealistic situations, where the images appeared on the screen at the same time and in the same size. Studies in more realistic situations are therefore necessary. Originality/value – We identify a visual hash scheme encoding a higher number of distinguishable bits than previously reported in literature, and extend the testing to realistic scenarios. Maina M. Olembo, Timo Kilian, Simon Stockhardt, Andreas Hülsing, Melanie Volkamer |
Inf. Manag. Comput. Secur. | 4 |
| 2013 | Discrete Ziggurat: A Time-Memory Trade-Off for Sampling from a Gaussian Distribution over the Integers
Johannes Buchmann 0001, Daniel Cabarcas, Florian Göpfert, Andreas Hülsing, Patrick Weiden |
Selected Areas in Cryptography | 4 |
| 2012 | Forward Secure Signatures on Smart Cards
Andreas Hülsing, Christoph Busold, Johannes Buchmann 0001 |
Selected Areas in Cryptography | 1 |
| 2011 | XMSS - A Practical Forward Secure Signature Scheme Based on Minimal Security Assumptions
Johannes Buchmann 0001, Erik Dahmen, Andreas Hülsing |
PQCrypto | 3 |