Felix Günther 0001

dblp:34/10042 · DBLP profile ↗
← Back
39ranked-venue papers
9as first author
20since 2021 · last 2025
0000-0002-8495-6610ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 36 · 8 first-author · 19 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 Breaking and Fixing Content-Defined Chunking
abstract
Content-defined chunking (CDC) algorithms split streams of data into smaller blocks, called chunks, in a way that preserves chunk boundaries when the data is partially changed. CDC is ubiquitous in applications that deduplicate data such as backup solutions, software patching systems, and file hosting platforms. Much like compression, CDC can introduce leakage when combined with encryption: fingerprinting attacks can exploit chunk length patterns to infer information about the data.
Kien Tuong Truong, Simon-Philipp Merz, Matteo Scarlata, Felix Günther 0001, Kenneth G. Paterson
CCS4
2025 sfXHMQV: Better Efficiency and Stronger Security for Signal's Initial Handshake based on HMQV
Rune Fiedler, Felix Günther 0001, Jiaxin Pan 0001, Runzhi Zeng
CRYPTO (8)2
2025 Verifiable Decapsulation: Recognizing Faulty Implementations of Post-quantum KEMs
Lewis Glabush, Felix Günther 0001, Kathrin Hövelmanns, Douglas Stebila
CRYPTO (3)2
2025 Hybrid Obfuscated Key Exchange and KEMs
Felix Günther 0001, Michael Rosenberg, Douglas Stebila, Shannon Veitch
CRYPTO (3)1
2025 Key Derivation Functions Without a Grain of Salt
Matilda Backendal, Sebastian Clermont, Marc Fischlin, Felix Günther 0001
EUROCRYPT (8)4
2025 Security Analysis of Signal's PQXDH Handshake
Rune Fiedler, Felix Günther 0001
PKC (2)2
2024 Obfuscated Key Exchange
abstract
Censorship circumvention tools enable clients to access endpoints in a network despite the presence of a censor. Censors use a variety of techniques to identify content they wish to block, including filtering traffic patterns that are characteristic of proxy or circumvention protocols and actively probing potential proxy servers. Circumvention practitioners have developed fully encrypted protocols (FEPs), intended to have traffic that appears indistinguishable from random. A FEP is typically composed of a key exchange protocol to establish shared secret keys, and then a secure channel protocol to encrypt application data; both must avoid revealing to observers that an obfuscated protocol is in use.
Felix Günther 0001, Douglas Stebila, Shannon Veitch
CCS1
2024 A Formal Treatment of End-to-End Encrypted Cloud Storage
Matilda Backendal, Hannah Davis, Felix Günther 0001, Miro Haller, Kenneth G. Paterson
CRYPTO (2)3
2024 Robust Channels: Handling Unreliable Networks in the Record Layers of QUIC and DTLS 1.3
abstract
Abstract The common approach in secure communication channel protocols is to rely on ciphertexts arriving in-order and to close the connection upon any rogue ciphertext. Cryptographic security models for channels generally reflect such design. This is reasonable when running atop lower-level transport protocols like TCP ensuring in-order delivery, as for example, is the case with TLS or SSH. However, protocols like QUIC or DTLS which run over a non-reliable transport such as UDP, do not—and in fact cannot—close the connection if packets are lost or arrive in a different order. Those protocols instead have to carefully catch effects arising naturally in unreliable networks, usually by using a sliding-window technique where ciphertexts can be decrypted correctly as long as they are not misplaced too far. In order to be able to capture QUIC and the newest DTLS version 1.3, we introduce a generalized notion of robustness of cryptographic channels. This property can capture unreliable network behavior and guarantees that adversarial tampering cannot hinder ciphertexts that can be decrypted correctly from being accepted. We show that robustness is orthogonal to the common notion of integrity for channels, but together with integrity and chosen-plaintext security it provides a robust analog of chosen-ciphertext security of channels. In contrast to prior work, robustness allows us to study packet encryption in the record layer protocols of QUIC and of DTLS 1.3 and the novel sliding-window techniques both protocols employ. We show that both protocols achieve robust chosen-ciphertext security based on certain properties of their sliding-window techniques and the underlying AEAD schemes. Notably, the robustness needed in handling unreliable network messages requires both record layer protocols to tolerate repeated adversarial forgery attempts. This means we can only establish non-tight security bounds (in terms of AEAD integrity), a security degradation that was missed in earlier protocol drafts. Our bounds led the responsible IETF working groups to introduce concrete forgery limits for both protocols and the IRTF CFRG to consider AEAD usage limits more broadly.
Marc Fischlin, Felix Günther 0001, Christian Janson
J. Cryptol.2
2023 Verifiable Verification in Cryptographic Protocols
abstract
Common verification steps in cryptographic protocols, such as signature or message authentication code checks or the validation of elliptic curve points, are crucial for the overall security of the protocol. Yet implementation errors omitting these steps easily remain unnoticed, as often the protocol will function perfectly anyways. One of the most prominent examples is Apple's goto fail bug where the erroneous certificate verification skipped over several of the required steps, marking invalid certificates as correctly verified. This vulnerability went undetected for at least 17 months.
Marc Fischlin, Felix Günther 0001
CCS2
2023 When Messages Are Keys: Is HMAC a Dual-PRF?
Matilda Backendal, Mihir Bellare, Felix Günther 0001, Matteo Scarlata
CRYPTO (3)3
2023 Careful with MAc-then-SIGn: A Computational Analysis of the EDHOC Lightweight Authenticated Key Exchange Protocol
abstract
EDHOC is a lightweight authenticated key exchange protocol for IoT communication, currently being standardized by the IETF. Its design is a trimmed-down version of similar protocols like TLS 1.3, building on the SIGn-then-MAc (SIGMA) rationale. In its trimming, however, EDHOC notably deviates from the SIGMA design by sending only short, non-unique credential identifiers, and letting recipients perform trial verification to determine the correct communication partner. Done naively, this can lead to identity misbinding attacks when an attacker can control some of the user keys, invalidating the original SIGMA security analysis and contesting the security of EDHOC.In this work, we formalize a multi-stage key exchange security model capturing the potential attack vectors introduced by non-unique credential identifiers. We show that EDHOC, in its draft version 17, indeed achieves session key security and user authentication even in a strong model where the adversary can register malicious keys with colliding identifiers, given that the employed signature scheme provides so-called exclusive ownership. Through our security result, we confirm cryptographic improvements integrated by the IETF working group in recent draft versions of EDHOC based on recommendations from our and others’ analysis.
Felix Günther 0001, Marc Ilunga Tshibumbu Mukendi
EuroS&P1
2022 KEMTLS with Delayed Forward Identity Protection in (Almost) a Single Round Trip
Felix Günther 0001, Simon Rastikian, Patrick Towa, Thom Wiggers
ACNS1
2022 Puncturable Key Wrapping and Its Applications
Matilda Backendal, Felix Günther 0001, Kenneth G. Paterson
ASIACRYPT (2)2
2022 Continuous Authentication in Secure Messaging
Benjamin Dowling, Felix Günther 0001, Alexandre Poirrier
ESORICS (2)2
2022 On the Concrete Security of TLS 1.3 PSK Mode
Hannah Davis, Denis Diemert, Felix Günther 0001, Tibor Jager
EUROCRYPT (2)3
2021 Tighter Proofs for the SIGMA and TLS 1.3 Key Exchange Protocols
Hannah Davis, Felix Günther 0001
ACNS (2)2
2021 The Security of ChaCha20-Poly1305 in the Multi-User Setting
abstract
The ChaCha20-Poly1305 AEAD scheme is being increasingly widely deployed in practice. Practitioners need proven security bounds in order to set data limits and rekeying intervals for the scheme. But the formal security analysis of ChaCha20-Poly1305 currently lags behind that of AES-GCM. The only extant analysis (Procter, 2014) contains a flaw and is only for the single-user setting. We rectify this situation. We prove a multi-user security bound on the AEAD security of ChaCha20-Poly1305 and establish the tightness of each term in our bound through matching attacks. We show how our bound differs both qualitatively and quantitatively from the known bounds for AES-GCM, highlighting how subtle design choices lead to distinctive security properties. We translate our bound to the nonce-randomized setting employed in TLS 1.3 and elsewhere, and we additionally improve the corresponding security bounds for GCM. Finally, we provide a simple yet stronger variant of ChaCha20-Poly1305 that addresses the deficiencies highlighted by our analysis.
Jean Paul Degabriele, Jérôme Govinden, Felix Günther 0001, Kenneth G. Paterson
CCS3
2021 A Cryptographic Analysis of the TLS 1.3 Handshake Protocol
abstract
Abstract We analyze the handshake protocol of the Transport Layer Security (TLS) protocol, version 1.3. We address both the full TLS 1.3 handshake (the one round-trip time mode, with signatures for authentication and (elliptic curve) Diffie–Hellman ephemeral ((EC)DHE) key exchange), and the abbreviated resumption/“PSK” mode which uses a pre-shared key for authentication (with optional (EC)DHE key exchange and zero round-trip time key establishment). Our analysis in the reductionist security framework uses a multi-stage key exchange security model, where each of the many session keys derived in a single TLS 1.3 handshake is tagged with various properties (such as unauthenticated versus unilaterally authenticated versus mutually authenticated, whether it is intended to provide forward security, how it is used in the protocol, and whether the key is protected against replay attacks). We show that these TLS 1.3 handshake protocol modes establish session keys with their desired security properties under standard cryptographic assumptions.
Benjamin Dowling, Marc Fischlin, Felix Günther 0001, Douglas Stebila
J. Cryptol.3
2021 The Status of Quantum-Key-Distribution-Based Long-Term Secure Internet Communication
abstract
A large amount of sensitive data must remain accessible for decades or even centuries (e.g, electronic health records, governmental documents). Communicating such data over the Internet requires long-term secure communication channels, which, in turn, require robust key distribution protocols. Currently used key distribution protocols, however, are not designed for long-term security. Their security is either threatened by quantum computers, or, in principle, due to their reliance on computational problems. Quantum key distribution (QKD) protocols are information-theoretically secure and thereby offer long-term security against computational attacks. However, significant obstacles to their real-world use remain. This position paper, which is a multidisciplinary effort of computer scientists and physicists, systematizes knowledge about challenges of and strategies for realizing long-term secure Internet communication from QKD. We first analyze the performance and security of existing point-to-point QKD technology. Then, we discuss several approaches to enabling QKD in large-scale multi-user networks. Finally, we list important challenges that need to be addressed in order to make QKD-based long-term secure communication on the Internet practical.
Matthias Geihs, Oleg Nikiforov, Denise Demirel, Alexander Sauer, Denis Butin, Felix Günther 0001, Gernot Alber, Thomas Walther, Johannes Buchmann 0001
IEEE Trans. Sustain. Comput.6
2020 Modeling Memory Faults in Signature and Authenticated Encryption Schemes
Marc Fischlin, Felix Günther 0001
CT-RSA2
2020 Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only Indifferentiability
Mihir Bellare, Hannah Davis, Felix Günther 0001
EUROCRYPT (2)3
2020 Information-Theoretic Security of Cryptographic Channels
Marc Fischlin, Felix Günther 0001, Philipp Muth
ICICS2
2020 Towards Post-Quantum Security for Signal's X3DH Handshake
Jacqueline Brendel, Marc Fischlin, Felix Günther 0001, Christian Janson, Douglas Stebila
SAC3
2019 Breakdown Resilience of Key Exchange Protocols: NewHope, TLS 1.3, and Hybrids
Jacqueline Brendel, Marc Fischlin, Felix Günther 0001
ESORICS (2)3
2017 A Formal Treatment of Multi-key Channels
Felix Günther 0001, Sogol Mazaheri
CRYPTO (3)1
2017 PRF-ODH: Relations, Instantiations, and Impossibility Results
Jacqueline Brendel, Marc Fischlin, Felix Günther 0001, Christian Janson
CRYPTO (3)3
2017 0-RTT Key Exchange with Full Forward Secrecy
Felix Günther 0001, Britta Hale, Tibor Jager, Sebastian Lauer
EUROCRYPT (3)1
2017 Replay Attacks on Zero Round-Trip Time: The Case of the TLS 1.3 Handshake Candidates
abstract
We investigate security of key exchange protocols supporting so-called zero round-trip time (0-RTT), enabling a client to establish a fresh provisional key without interaction, based only on cryptographic material obtained in previous connections. This key can then be already used to protect early application data, transmitted to the server before both parties interact further to switch to fully secure keys. Two recent prominent examples supporting such 0-RTT modes are Google's QUIC protocol and the latest drafts for the upcoming TLS version 1.3. We are especially interested in the question how replay attacks, enabled through the lack of contribution from the server, affect security in the 0-RTT case. Whereas the first proposal of QUIC uses state on the server side to thwart such attacks, the latest version of QUIC and TLS 1.3 rather accept them as inevitable. We analyze what this means for the key secrecy of both the preshared-key-based 0-RTT handshake in draft-14 of TLS 1.3 as well as the Diffie-Hellman-based 0-RTT handshake in TLS 1.3 draft-12. As part of this we extend previous security models to capture such cases, also shedding light on the limitations and options for 0-RTT security under replay attacks.
Marc Fischlin, Felix Günther 0001
EuroS&P2
2017 CogniCrypt: supporting developers in using cryptography
abstract
Previous research suggests that developers often struggle using low-level cryptographic APIs and, as a result, produce insecure code. When asked, developers desire, among other things, more tool support to help them use such APIs. In this paper, we present CogniCrypt, a tool that supports developers with the use of cryptographic APIs. CogniCrypt assists the developer in two ways. First, for a number of common cryptographic tasks, CogniCrypt generates code that implements the respective task in a secure manner. Currently, CogniCrypt supports tasks such as data encryption, communication over secure channels, and long-term archiving. Second, CogniCrypt continuously runs static analyses in the background to ensure a secure integration of the generated code into the developer's workspace. This video demo showcases the main features of CogniCrypt: youtube.com/watch?v=JUq5mRHfAWY.
Stefan Krüger, Sarah Nadi, Michael Reif, Karim Ali 0001, Mira Mezini, Eric Bodden, Florian Göpfert, Felix Günther 0001, Christian Weinert, Daniel Demmler, Ram Kamath
ASE8
2016 Secure Logging Schemes and Certificate Transparency
Benjamin Dowling, Felix Günther 0001, Udyani Herath, Douglas Stebila
ESORICS (2)2
2016 Key Confirmation in Key Exchange: A Formal Treatment and Implications for TLS 1.3
abstract
Key exchange protocols allow two parties at remote locations to compute a shared secret key. The common security notions for such protocols are secrecy and authenticity, but many widely deployed protocols and standards name another property, called key confirmation, as a major design goal. This property should guarantee that a party in the key exchange protocol is assured that another party also holds the shared key. Remarkably, while secrecy and authenticity definitions have been studied extensively, key confirmation has been treated rather informally so far. In this work, we provide the first rigorous formalization of key confirmation, leveraging the game-based security framework well-established for secrecy and authentication notions for key exchange. We define two flavors of key confirmation, full and almost-full key confirmation, taking into account the inevitable asymmetry of the roles of the parties with respect to the transmission of the final protocol message. These notions capture the strongest level of key confirmation reasonably expectable for the two communication partners of the key exchange. We demonstrate the benefits of having precise security definitions for key-confirmation by applying them to the next version of the Transport Layer Security (TLS) protocol, version 1.3, currently developed by the Internet Engineering Task Force (IETF). Our analysis shows that the full handshake as specified in the TLS 1.3 draft draft-ietf-tls-tls13-10 achieves desirable notions of key confirmation for both clients and servers. While key confirmation is generally understood and in the TLS 1.3 draft described as being obtained from the Finished messages exchanged, interestingly we can show that the full TLS 1.3 handshake provides key confirmation even without those messages, shedding a formal light on the security properties different handshake messages entail. We further demonstrate the usefulness of rigorous definition by revisiting a folklore approach to establish key confirmation (as discussed for example in SP 800-56A of NIST). We provide a formalization as a generic protocol transformation and show that the resulting protocols enjoy strong key confirmation guarantees, thus confirming its beneficial use in both theoretical and practical protocol designs.
Marc Fischlin, Felix Günther 0001, Bogdan Warinschi
IEEE Symposium on Security and Privacy2
2015 Linkable Message Tagging: Solving the Key Distribution Problem of Signature Schemes
Felix Günther 0001, Bertram Poettering
ACISP1
2015 A Cryptographic Analysis of the TLS 1.3 Handshake Protocol Candidates
abstract
The Internet Engineering Task Force (IETF) is currently developing the next version of the Transport Layer Security (TLS) protocol, version 1.3. The transparency of this standardization process allows comprehensive cryptographic analysis of the protocols prior to adoption, whereas previous TLS versions have been scrutinized in the cryptographic literature only after standardization. This is even more important as there are two related, yet slightly different, candidates in discussion for TLS 1.3, called draft-ietf-tls-tls13-05 and draft-ietf-tls-tls13-dh-based. We give a cryptographic analysis of the primary ephemeral Diffie-Hellman-based handshake protocol, which authenticates parties and establishes encryption keys, of both TLS 1.3 candidates. We show that both candidate handshakes achieve the main goal of providing secure authenticated key exchange according to an augmented multi-stage version of the Bellare-Rogaway model. Such a multi-stage approach is convenient for analyzing the design of the candidates, as they establish multiple session keys during the exchange.
Benjamin Dowling, Marc Fischlin, Felix Günther 0001, Douglas Stebila
CCS3
2015 Data Is a Stream: Security of Stream-Based Channels
Marc Fischlin, Felix Günther 0001, Giorgia Azzurra Marson, Kenneth G. Paterson
CRYPTO (2)2
2014 Privacy-Enhanced Participatory Sensing with Collusion Resistance and Data Aggregation
Felix Günther 0001, Mark Manulis, Andreas Peter 0001
CANS1
2014 Multi-Stage Key Exchange and the Case of Google's QUIC Protocol
abstract
The traditional approach to build a secure connection is to run a key exchange protocol and, once the key has been established, to use this key afterwards in a secure channel protocol. The security of key exchange and channel protocols, and to some extent also of the composition of both, has been scrutinized extensively in the literature. However, this approach usually falls short of capturing some key exchange protocols in which, due to practical motivation, the originally separated phases become intertwined and keys are established continuously. Two prominent examples of such protocols are TLS (with resumption), and Google's recently proposed low-latency protocol QUIC. In this work we revisit the previous security of model of Brzuska et al. (CCS'11) and expand it into a multi-stage key exchange model in the style of Bellare and Rogaway. In our model, parties can establish multiple keys in different stages and use these keys between stages, even to establish the next key. The advantage of using the formalization of Brzuska et al. is that it has been designed with the aim to provide compositional guarantees. Hence, we can, too, give sufficient conditions under which multi-stage key exchange protocols compose securely with any symmetric-key application protocol, like a secure channel protocol. We then exercise our model for the case of the QUIC protocol. Basically, we show that QUIC is an adequately secure multi-stage key exchange protocol and meets the suggested security properties of the designers. We continue by proposing some slight changes to QUIC to make it more amenable to our composition result and to allow reasoning about its security as a combined connection establishment protocol when composed with a secure channel protocol.
Marc Fischlin, Felix Günther 0001
CCS2
2013 Pseudorandom signatures
abstract
We develop a three-level hierarchy of privacy notions for (unforgeable) digital signature schemes. We first prove mutual independence of existing notions of anonymity and confidentiality, and then show that these are implied by higher privacy goals. The top notion in our hierarchy is pseudorandomness: signatures with this property hide the entire information about the signing process and cannot be recognized as signatures when transmitted over a public network. This implies very strong unlinkability guarantees across different signers and even different signing algorithms, and gives rise to new forms of private public-key authentication.
Nils Fleischhacker, Felix Günther 0001, Franziskus Kiefer, Mark Manulis, Bertram Poettering
AsiaCCS2
2011 Key management in distributed online social networks
abstract
Decentralized approaches for online social networks (OSNs) have been of recent research interest, enabling users to create profiles and share data like in other OSNs as, e.g., Facebook. Since the decentralized architecture does not contain a central authority that is able perform access control, encryption is needed to ensure the confidentiality of published data. This paper outlines strict requirements and weak constraints for the encryption of data attributes in decentralized OSNs. Subsequently, an overview of possible cryptographic solutions is given and their suitability according to these requirements is analyzed. As a result, the differences and trade-offs between and within the given approaches are expounded. The outcome of this paper can be used as a foundation for further investigations on this topic.
Felix Günther 0001, Mark Manulis, Thorsten Strufe
WOWMOM1