VLDB 2026 Research / reviewers in the wild / expert
Hugo Krawczyk
dblp:46/6715
· DBLP profile ↗
98ranked-venue papers
17as first author
11since 2021 · last 2025
0000-0003-3130-1888ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 80 · 15 first-author · 11 since 2021Theory of computation · 11 · 1 first-authorSystems, architecture and hardware · 4 · 1 first-authorComputer networks · 2Databases, data management, data science and information retrieval · 2Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Encrypted Matrix-Vector Products from Secret Dual CodesabstractMotivated by applications to efficient secure computation, we consider the following problem of encrypted matrix-vector product (EMVP). Let ⅇ be a finite field. In an offline phase, a client uploads an encryption of a matrix M∈ ⅇmxℓ to a server, keeping only a short secret key. The server stores the encrypted matrix M. In the online phase, the client may repeatedly send encryptions qi of query vectors qi∈ ⅇℓ, which enables the client and the server to locally compute compact shares of the matrix-vector product M qi. The server learns nothing about M or qi. The shared output can either be revealed to the client or processed by another protocol. Fabrice Benhamouda, Caicai Chen, Shai Halevi, Yuval Ishai, Hugo Krawczyk, Tamer Mour, Tal Rabin, Alon Rosen |
CCS | 5 |
| 2025 | Gold OPRF: Post-Quantum Oblivious Power-Residue PRFabstractWe propose plausible post-quantum (PQ) oblivious pseudorandom functions (OPRFs) based on the Power-Residue PRF (Damgård CRYPTO'88), a generalization of the Legendre PRF. For security parameter$\lambda$, we consider the PRF Gold$k(x)$that maps an integer$x$modulo a public prime$p=2^{\lambda}\cdot g+1$to the element$(k+x)^{g}\text{mod}\ p$, where$g$is public and$\log g\approx 2\lambda$. At the core of our constructions are efficient novel methods for evaluating Gold within two-party computation (2PC-Gold), achieving different security requirements. Here, the server$\mathcal{P}_{s}$holds the PRF key$k$whereas the client$\mathcal{P}_{c}$holds the PRF input$x$, and they jointly evaluate Gold in$2\mathbf{PC}$. 2 PC-Gold uses standard Vector Oblivious Linear Evaluation (VOLE) correlations and is information-theoretic and constant-round in the (V)OLE-hybrid model. We show: •For a semi-honest$\mathcal{P}_{s}$and a malicious$\mathcal{P}_{c}$: a 2PC-Gold that just uses a single (V)OLE correlation, and has a communication complexity of 3 field elements (2 field elements if we only require a uniformly sampled key) and a computational complexity of$\mathcal{O}(\lambda)$field operations. We refer to this as half-malicious security. •For malicious$\mathcal{P}_{s}$and$\mathcal{P}_{c}$: a 2PC-Gold that just uses$\frac{\lambda}{4}+\mathcal{O}(1)$VOLE correlations, and has a communication complexity of$\frac{\lambda}{4}+\mathcal{O}(1)$field elements and a computational complexity of$\mathcal{O}(\lambda)$field operations. These constructions support additional features and extensions, e.g., batched evaluations with better amortized costs where$\mathcal{P}_{c}$repeatedly evaluates the PRF under the same key. Furthermore, we extend 2PC-Gold to Verifiable OPRFs and use the methodology from Beullens et al. (Eurocrypt'25) to get strong OPRF security in the universally composable setting. All the protocols are efficient in practice. We implemented 2PC-Gold-with (PQ) VOLEs-and benchmarked them. For example, our half-malicious (resp. malicious) n-batched PQ OPRFs incur about 100B (resp. 1.9KB) of amortized communication for$\lambda=128$. Yibin Yang 0001, Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Tal Rabin |
SP | 4 |
| 2025 | Building and Testing a Hidden-Password Online Password ManagerabstractThe most commonly adopted password management technique is to store web account passwords on a password manager and lock them using a master password. However, current online password managers do not hide the account passwords or the master password from the password manager itself, which highlights their real-world vulnerability and lack of user confidence in the face of malicious insiders and outsiders that compromise the password management service especially given its online nature. We attempt to address this crucial vulnerability in the design of online password managers by proposing a cloud-based password manager that does not learn or store master passwords and account passwords. We introduce the protocol design and report on a full implementation of the system. Our implementation provides several security features, including enforcement of a unique and secure password per each service, robustness to online password guessing attacks against the password manager and the web service, robustness to password dictionary attacks upon compromise of the password manager and the web service, and security against phishing attacks. Furthermore, to assess users’ perceptions of the security and usability of our password manager, we conducted a lab-based study. The findings from the study suggest that our system is close to being practical for everyday use and is viewed by users as both usable and more secure/trustworthy. Mohammed Jubur, Christopher Robert Price, Maliheh Shirvanian, Nitesh Saxena, Stanislaw Jarecki, Hugo Krawczyk |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Password-Protected Threshold Signatures
Stefan Dziembowski, Stanislaw Jarecki, Pawel Kedzior, Hugo Krawczyk, Chan Nam Ngo, Jiayu Xu 0001 |
ASIACRYPT (3) | 4 |
| 2024 | SPRINT: High-Throughput Robust Distributed Schnorr Signatures
Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Yiping Ma 0001, Tal Rabin |
EUROCRYPT (5) | 3 |
| 2023 | Password-Authenticated TLS via OPAQUE and Post-Handshake Authentication
Julia Hesse, Stanislaw Jarecki, Hugo Krawczyk, Christopher A. Wood |
EUROCRYPT (5) | 3 |
| 2022 | Threshold Cryptography as a Service (in the Multiserver and YOSO Models)abstractWe consider large deployments of threshold cryptographic services that can run in traditional multi-server settings and, at a much larger scale, in blockchain environments. We present a set of techniques that improve performance and meet the requirements of settings with large number of servers and high rate of threshold operations. More fundamentally, our techniques enable threshold cryptographic applications to run in more challenging decentralized permissionless systems, such as contemporary blockchains. In particular, we design and implement a novel threshold solution for the recently introduced YOSO (You Only Speak Once) model. The model builds on ever changing, unpredictable committees that perform ephemeral roles in a way that evades targeting by attackers and enables virtually unlimited scalability in very large networks. Our solution allows for the maintenance of system-wide keys that can be generated, used and proactivized as needed. The specific techniques build on optimized protocols for multi-secret multi-dealer verifiable secret sharing and their adaptation to the YOSO model. Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Alex Miao, Tal Rabin |
CCS | 3 |
| 2022 | Asymmetric PAKE with Low Computation and communication
Bruno Freitas Dos Santos, Yanqi Gu, Stanislaw Jarecki, Hugo Krawczyk |
EUROCRYPT (2) | 4 |
| 2021 | YOSO: You Only Speak Once - Secure MPC with Stateless Ephemeral Roles
Craig Gentry, Shai Halevi, Hugo Krawczyk, Bernardo Magri, Jesper Buus Nielsen, Tal Rabin, Sophia Yakoubov |
CRYPTO (2) | 3 |
| 2021 | KHAPE: Asymmetric PAKE from Key-Hiding Key Exchange
Yanqi Gu, Stanislaw Jarecki, Hugo Krawczyk |
CRYPTO (4) | 3 |
| 2021 | Two-factor Password-authenticated Key Exchange with End-to-end SecurityabstractWe present a secure two-factor authentication (TFA) scheme based on the user’s possession of a password and a crypto-capable device. Security is “end-to-end” in the sense that the attacker can attack all parts of the system, including all communication links and any subset of parties (servers, devices, client terminals), can learn users’ passwords, and perform active and passive attacks, online and offline. In all cases the scheme provides the highest attainable security bounds given the set of compromised components. Our solution builds a TFA scheme using any Device-enhanced Password-authenticated Key Exchange (PAKE), defined by Jarecki et al., and any Short Authenticated String (SAS) Message Authentication, defined by Vaudenay. We show an efficient instantiation of this modular construction, which utilizes any password-based client-server authentication method, with or without reliance on public-key infrastructure. The security of the proposed scheme is proven in a formal model that we formulate as an extension of the traditional PAKE model. We also report on a prototype implementation of our schemes, including TLS-based and PKI-free variants, as well as several instantiations of the SAS mechanism, all demonstrating the practicality of our approach. Finally, we present a usability study evaluating the viability of our protocol contrasted with the traditional PIN-based TFA approach in terms of efficiency, potential for errors, user experience, and security perception of the underlying manual process.1 Stanislaw Jarecki, Mohammed Jubur, Hugo Krawczyk, Nitesh Saxena, Maliheh Shirvanian |
ACM Trans. Priv. Secur. | 3 |
| 2020 | On the Cryptographic Deniability of the Signal Protocol
Nihal Vatandas, Rosario Gennaro, Bertrand Ithurburn, Hugo Krawczyk |
ACNS (2) | 4 |
| 2020 | Can a Public Blockchain Keep a Secret?
Fabrice Benhamouda, Craig Gentry, Sergey Gorbunov 0001, Shai Halevi, Hugo Krawczyk, Chengyu Lin 0001, Tal Rabin, Leonid Reyzin |
TCC (1) | 5 |
| 2019 | Updatable Oblivious Key Management for Storage SystemsabstractWe introduce Oblivious Key Management Systems (KMS) as a much more secure alternative to traditional wrapping-based KMS that form the backbone of key management in large-scale data storage deployments. The new system, that builds on Oblivious Pseudorandom Functions (OPRF), hides keys and object identifiers from the KMS, offers unconditional security for key transport, provides key verifiability, reduces storage, and more. Further, we show how to provide all these features in a distributed threshold implementation that enhances protection against server compromise. Stanislaw Jarecki, Hugo Krawczyk, Jason K. Resch |
CCS | 2 |
| 2019 | PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity AssetsabstractUser's digital identity information has privacy and security requirements. Privacy requirements include confidentiality of the identity information itself, anonymity of those who verify and consume a user's identity information and unlinkability of online transactions which involve a user's identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's identity information. Such privacy and security requirements, although conflicting, are critical for identity management systems enabling the exchange of users' identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security. Hasini Gunasinghe, Ashish Kundu, Elisa Bertino, Hugo Krawczyk, Suresh Chari, Kapil Singh, Dong Su |
WWW | 4 |
| 2019 | Cryptography for #MeTooabstractAbstract Reporting sexual assault and harassment is an important and difficult problem. Since late 2017, it has received increased attention as the viral #MeToo movement has brought about accusations against high-profile individuals and a wider discussion around the prevalence of sexual violence. Addressing occurrences of sexual assault requires a system to record and process accusations. It is natural to ask what security guarantees are necessary and achievable in such a system. In particular, we focus on detecting repeat offenders: only when a set number of accusations are lodged against the same party will the accusations be revealed to a legal counselor. Previous solutions to this privacy-preserving reporting problem, such as the Callisto Protocol of Rajan et al., have focused on the confidentiality of accusers. This paper proposes a stronger security model that ensures the confidentiality of the accuser and the accused as well as the traceability of false accusations. We propose the WhoToo protocol to achieve this notion of security using suitable cryptographic techniques. The protocol design emphasizes practicality, preferring fast operations that are implemented in existing software libraries. We estimate that an implementation would be suitably performant for real-world deployment. Benjamin Kuykendall, Hugo Krawczyk, Tal Rabin |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Building and Studying a Password Store that Perfectly Hides Passwords from ItselfabstractWe introduce a novel approach to password management, called SPHINX, which remains secure even when the password manager itself has been compromised. In SPHINX, the information stored on the device is theoretically independent of the user's master password. Moreover, an attacker with full control of the device, even at the time the user interacts with it, learns nothing about the master password - the password is not entered into the device in plaintext form or in any other way that may leak information on it. Unlike existing managers, SPHINX produces strictly high-entropy passwords and makes it compulsory for the users to register these passwords with the web services, which defeats online guessing attacks and offline dictionary attack upon service compromise. We present the design, implementation and performance evaluation of SPHINX, offering prototype browser plugins, smartphone apps and transparent device-client communication. We further provide a comparative analytical evaluation of SPHINX with other password managers based on a formal framework consisting of security, usability, and deployability metrics. Maliheh Shirvanian, Nitesh Saxena, Stanislaw Jarecki, Hugo Krawczyk |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2018 | OPAQUE: An Asymmetric PAKE Protocol Secure Against Pre-computation Attacks
Stanislaw Jarecki, Hugo Krawczyk, Jiayu Xu 0001 |
EUROCRYPT (3) | 2 |
| 2017 | TOPPSS: Cost-Minimal Password-Protected Secret Sharing Based on Threshold OPRF
Stanislaw Jarecki, Aggelos Kiayias, Hugo Krawczyk, Jiayu Xu 0001 |
ACNS | 3 |
| 2017 | Robust Non-interactive Multiparty Computation Against Constant-Size Collusion
Fabrice Benhamouda, Hugo Krawczyk, Tal Rabin |
CRYPTO (1) | 2 |
| 2017 | SPHINX: A Password Store that Perfectly Hides Passwords from ItselfabstractPassword managers (aka stores or vaults) allow a user to store and retrieve (usually high-entropy) passwords for her multiple password-protected services by interacting with a "device" serving the role of the manager (e.g., a smartphone or an online third-party service) on the basis of a single memorable (low-entropy) master password. Existing password managers work well to defeat offline dictionary attacks upon web service compromise, assuming the use of high-entropy passwords is enforced. However, they are vulnerable to leakage of all passwords in the event the device is compromised, due to the need to store the passwords encrypted under the master password and/or the need to input the master password to the device (as in smartphone managers). Evidence exists that password managers can be attractive attack targets. In this paper, we introduce a novel approach to password management, called SPHINX, which remains secure even when the password manager itself has been compromised. In SPHINX, the information stored on the device is information theoretically independent of the user's master password - an attacker breaking into the device learns no information about the master password or the user's site-specific passwords. Moreover, an attacker with full control of the device, even at the time the user interacts with it, learns nothing about the master password - the password is not entered into the device in plaintext form or in any other way that may leak information on it. Unlike existing managers, SPHINX produces strictly high-entropy passwords and makes it compulsory for the users to register these randomized passwords with the web services, hence fully defeating offline dictionary attack upon service compromise. The design and security of SPHINX is based on the device-enhanced PAKE model of Jarecki et al. that provides the theoretical basis for this construction and is backed by rigorous cryptographic proofs of security. While SPHINX is suitable for different device and online platforms, in this paper, we report on its concrete instantiation on smartphones given their popularity and trustworthiness as password managers (or even two-factor authentication). We present the design, implementation and performance evaluation of SPHINX, offering prototype browser plugins, smartphone apps and transparent device-client communication. Based on our inspection analysis, the overall user experience of SPHINX improves upon current managers. We also report on a lab-based usability study of SPHINX, which indicates that users' perception of SPHINX security and usability is high and satisfactory when compared to regular password-based authentication. Finally, we discuss how SPHINX may be extended to an online service for the purpose of back-up or as an independent password manager. Maliheh Shirvanian, Stanislaw Jarecki, Hugo Krawczyk, Nitesh Saxena |
ICDCS | 3 |
| 2016 | Device-Enhanced Password Protocols with Optimal Online-Offline ProtectionabstractWe introduce a setting that we call Device-Enhanced PAKE (DE-PAKE), where PAKE (password-authenticated key exchange) protocols are strengthened against online and offline attacks through the use of an auxiliary device that aids the user in the authentication process. We build such schemes and show that their security, properly formalized, achieves maximal-attainable resistance to online and offline attacks in both PKI and PKI-free settings. In particular, an online attacker must guess the user's password and also corrupt the user's auxiliary device to authenticate, while an attacker who corrupts the server cannot learn the users' passwords via an offline dictionary attack. Notably, our solutions do not require secure channels, and nothing (in an information-theoretic sense) is learned about the password by the device (or a malicious software running on the device) or over the device-client channel, even without any external protection of this channel. An attacker taking over the device still requires a full online attack to impersonate the user. Importantly, our DE-PAKE scheme can be deployed at the user end without the need to modify the server and without the server having to be aware that the user is using a DE-PAKE scheme. In particular, the schemes can work with standard servers running the usual password-over-TLS authentication. We use these protocols to implement a practical DE-PAKE system and we evaluate its performance. To improve usability the implemented system utilizes automated and user-transparent data channel between the mobile device and the client, falling back to localized communication if the device looses primary connectivity. Stanislaw Jarecki, Hugo Krawczyk, Maliheh Shirvanian, Nitesh Saxena |
AsiaCCS | 2 |
| 2016 | Attribute-based Key Exchange with General PoliciesabstractAttribute-based methods provide authorization to parties based on whether their set of attributes (e.g., age, organization, etc.) fulfills a policy. In attribute-based encryption (ABE), authorized parties can decrypt, and in attribute-based credentials (ABCs), authorized parties can authenticate themselves. In this paper, we combine elements of ABE and ABCs together with garbled circuits to construct attribute-based key exchange (ABKE). Our focus is on an interactive solution involving a client that holds a certificate (issued by an authority) vouching for that client's attributes and a server that holds a policy computable on such a set of attributes. The goal is for the server to establish a shared key with the client but only if the client's certified attributes satisfy the policy. Our solution enjoys strong privacy guarantees for both the client and the server, including attribute privacy and unlinkability of client sessions. Vladimir Kolesnikov, Hugo Krawczyk, Yehuda Lindell, Alex J. Malozemoff, Tal Rabin |
CCS | 2 |
| 2016 | A Unilateral-to-Mutual Authentication Compiler for Key Exchange (with Applications to Client Authentication in TLS 1.3)abstractWe study the question of how to build "compilers" that transform a unilaterally authenticated (UA) key-exchange protocol into a mutually-authenticated (MA) one. We present a simple and efficient compiler and characterize the UA protocols that the compiler upgrades to the MA model, showing this to include a large and important class of UA protocols. The question, while natural, has not been studied widely. Our work is motivated in part by the ongoing work on the design of TLS 1.3, specifically the design of the client authentication mechanisms including the challenging case of post-handshake authentication. Our approach supports the analysis of these mechanisms in a general and modular way, in particular aided by the notion of "functional security" that we introduce as a generalization of key exchange models and which may be of independent interest. Hugo Krawczyk |
CCS | 1 |
| 2016 | Highly-Efficient and Composable Password-Protected Secret Sharing (Or: How to Protect Your Bitcoin Wallet Online)abstractPPSS is a central primitive introduced by Bagherzandi et al. [2] which allows a user to store a secret among n servers such that the user can later reconstruct the secret with the sole possession of a single password by contacting t + 1 (t <; n) servers. At the same time, an attacker breaking into t of these servers - and controlling all communication channels - learns nothing about the secret (or the password). Thus, PPSS schemes are ideal for on-line storing of valuable secrets when retrieval solely relies on a memorizable password. We show the most efficient Password-Protected Secret Sharing (PPSS) to date (and its implied Threshold-PAKE scheme), which is optimal in round communication as in Jarecki et al. [10] but which improves computation and communication complexity over that scheme requiring a single per-server exponentiation for the client and a single exponentiation for the server. As with the schemes from [10] and Camenisch et al. [4] we do not require secure channels or PKI other than in the initialization stage. We prove the security of our PPSS scheme in the Universally Composable (UC) model. For this we present a UC definition of PPSS that relaxes the UC formalism of [4] in a way that enables more efficient PPSS schemes (by dispensing with the need to extract the user's password in the simulation) and present a UC-based definition of Oblivious PRF (OPRF) that is more general than the (Verifiable) OPRF definition from [10] and is also crucial for enabling our performance optimization. Stanislaw Jarecki, Aggelos Kiayias, Hugo Krawczyk, Jiayu Xu 0001 |
EuroS&P | 3 |
| 2016 | The OPTLS Protocol and TLS 1.3abstractWe present the OPTLS key-exchange protocol, its design, rationale and cryptographic analysis. OPTLS design has been motivated by the ongoing work in the TLS working group of the IETF for specifying TLS 1.3, the next-generation TLS protocol. The latter effort is intended to revamp the security of TLS that has been shown inadequate in many instances as well as to add new security and functional features. The main additions that influence the cryptographic design of TLS 1.3 (hence also of OPTLS) are a new "0-RTT requirement" (0-RTT stands for "zero round trip time") to allow clients that have previously retrieved or cached the public key of the server to send protected data already in the first flow of the protocol, making perfect forward secrecy (PFS) a mandatory requirement, and moving to elliptic curves as the main cryptographic basis for the protocol (for performance and security reasons). Accommodating these requirements calls for moving away from the RSA-centric design of TLS in favor of a protocol based on Diffie-Hellman techniques. OPTLS offers a simple design framework that supports all the above requirements from the protocol with a uniform and modular logic that helps in the specification, analysis, performance optimization, and future maintenance of the protocol. The current (draft) specification of TLS 1.3 builds upon the OPTLS framework as a basis for the cryptographic core of the handshake protocol adapting the different modes of OPTLS to the TLS 1.3 context. Hugo Krawczyk, Hoeteck Wee |
EuroS&P | 1 |
| 2015 | Rich Queries on Encrypted Data: Beyond Exact Matches
Sky Faber, Stanislaw Jarecki, Hugo Krawczyk, Quan Nguyen 0006, Marcel-Catalin Rosu, Michael Steiner 0001 |
ESORICS (2) | 3 |
| 2014 | Round-Optimal Password-Protected Secret Sharing and T-PAKE in the Password-Only Model
Stanislaw Jarecki, Aggelos Kiayias, Hugo Krawczyk |
ASIACRYPT (2) | 3 |
| 2014 | Dynamic Searchable Encryption in Very-Large Databases: Data Structures and Implementation
David Cash, Joseph Jaeger, Stanislaw Jarecki, Charanjit S. Jutla, Hugo Krawczyk, Marcel-Catalin Rosu, Michael Steiner 0001 |
NDSS | 5 |
| 2013 | Outsourced symmetric private information retrievalabstractIn the setting of searchable symmetric encryption (SSE), a data owner D outsources a database (or document/file collection) to a remote server E in encrypted form such that D can later search the collection at E while hiding information about the database and queries from E. Leakage to E is to be confined to well-defined forms of data-access and query patterns while preventing disclosure of explicit data and query plaintext values. Recently, Cash et al. presented a protocol, OXT, which can run arbitrary boolean queries in the SSE setting and which is remarkably efficient even for very large databases. Stanislaw Jarecki, Charanjit S. Jutla, Hugo Krawczyk, Marcel-Catalin Rosu, Michael Steiner 0001 |
CCS | 3 |
| 2013 | Highly-Scalable Searchable Symmetric Encryption with Support for Boolean Queries
David Cash, Stanislaw Jarecki, Charanjit S. Jutla, Hugo Krawczyk, Marcel-Catalin Rosu, Michael Steiner 0001 |
CRYPTO (1) | 4 |
| 2013 | On the Security of the TLS Protocol: A Systematic Analysis
Hugo Krawczyk, Kenneth G. Paterson, Hoeteck Wee |
CRYPTO (1) | 1 |
| 2012 | Computational Extractors and Pseudorandomness
Dana Dachman-Soled, Rosario Gennaro, Hugo Krawczyk, Tal Malkin |
TCC | 3 |
| 2012 | On Compression of Data Encrypted With Block CiphersabstractThis paper investigates compression of data encrypted with block ciphers, such as the Advanced Encryption Standard. It is shown that such data can be feasibly compressed without knowledge of the secret key. Block ciphers operating in various chaining modes are considered and it is shown how compression can be achieved without compromising security of the encryption scheme. Further, it is shown that there exists a fundamental limitation to the practical compressibility of block ciphers when no chaining is used between blocks. Some performance results for practical code constructions used to compress binary sources are presented. Demijan Klinc, Carmit Hazay, Ashish Jagmohan, Hugo Krawczyk, Tal Rabin |
IEEE Trans. Inf. Theory | 4 |
| 2011 | Leftover Hash Lemma, Revisited
Boaz Barak, Yevgeniy Dodis, Hugo Krawczyk, Olivier Pereira, Krzysztof Pietrzak, François-Xavier Standaert, Yu Yu 0001 |
CRYPTO | 3 |
| 2010 | Okamoto-Tanaka Revisited: Fully Authenticated Diffie-Hellman with Minimal Overhead
Rosario Gennaro, Hugo Krawczyk, Tal Rabin |
ACNS | 2 |
| 2010 | Cryptographic Extraction and Key Derivation: The HKDF Scheme
Hugo Krawczyk |
CRYPTO | 1 |
| 2009 | On Compression of Data Encrypted with Block CiphersabstractThis paper investigates compression of encrypted data. It has been previously shown that data encrypted with Vernam's scheme, also known as the one-time pad, can be compressed without knowledge of the secret key, therefore this result can be applied to stream ciphers used in practice. However, it was not known how to compress data encrypted with non-stream ciphers. In this paper, we address the problem of compressing data encrypted with block ciphers, such as the advanced encryption standard (AES) used in conjunction with one of the commonly employed chaining modes. We show that such data can be feasibly compressed without knowledge of the key. We present performance results for practical code constructions used to compress binary sources. Demijan Klinc, Carmit Hazay, Ashish Jagmohan, Hugo Krawczyk, Tal Rabin |
DCC | 4 |
| 2008 | Strongly-Resilient and Non-interactive Hierarchical Key-Agreement in MANETs
Rosario Gennaro, Shai Halevi, Hugo Krawczyk, Tal Rabin, Steffen Reidt, Stephen D. Wolthusen |
ESORICS | 3 |
| 2008 | Threshold RSA for Dynamic and Ad-Hoc Groups
Rosario Gennaro, Shai Halevi, Hugo Krawczyk, Tal Rabin |
EUROCRYPT | 3 |
| 2007 | Security under key-dependent inputsabstractКваліфікаційна робота присвячена питанню по дослідженню безпеки операційних систем. Мета роботи полягає у вивченні та використанні сучасних технологій у забезпечені інформаційної безпеки для здобуття досвіду задля працевлаштування в майбутньому на одну з наступних позицій: «Адміністратор безпеки», «Аналітик кібербезпеки» чи «Системний адміністратор». В першому розділі кваліфікаційної роботи досліджується інформаційна діяльність, структура та інформаційно-комунікаційна система філії ТзОВ «Телесвіт» телекомунікаційної компанії Воля. В другому розділі кваліфікаційної роботи досліджуються та проводиться аналіз загроз. В ході роботи розробляється модель порушника. В третьому розділі розробляються політики безпеки, а також надаються рекомендації щодо посилення безпеки діючих в ІКС операційних систем. Shai Halevi, Hugo Krawczyk |
CCS | 2 |
| 2007 | Secure Distributed Key Generation for Discrete-Log Based Cryptosystems
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
J. Cryptol. | 3 |
| 2007 | Robust and Efficient Sharing of RSA Functions
Rosario Gennaro, Tal Rabin, Stanislaw Jarecki, Hugo Krawczyk |
J. Cryptol. | 4 |
| 2007 | RSA-Based Undeniable Signatures
Rosario Gennaro, Tal Rabin, Hugo Krawczyk |
J. Cryptol. | 3 |
| 2006 | Deniable authentication and key exchangeabstractWe extend the definitional work of Dwork,Naor and Sahai from deniable authentication to deniable key-exchange protocols. We then use these definitions to prove the deniability features of SKEME and SIGMA, two natural and efficient protocols which serve as basis for the Internet Key Exchange (IKE)protocol.SKEME is an encryption-based protocol for which we prove full deniability based on the plaintext awareness of the underlying encryption scheme. Interestingly SKEME's deniability is possibly the first "natural" application which essentially requires plaintext awareness (until now this notion has been mainly used as a tool for proving chosen-ciphertext security).SIGMA, on the other hand,uses non-repudiable signatures for authentication and hence cannot be proven to be fully deniable. Yet we are able to prove a weaker, but meaningful, "partial deniability" property: a party may not be able to deny that it was "alive" at some point in time but can fully deny the contents of its communications and the identity of its interlocutors.We remark that the deniability of SKEME and SIGMA holds in a concurrent setting and does not essentially rely on the random oracle model. Mario Di Raimondo, Rosario Gennaro, Hugo Krawczyk |
CCS | 3 |
| 2006 | Strengthening Digital Signatures Via Randomized Hashing
Shai Halevi, Hugo Krawczyk |
CRYPTO | 2 |
| 2005 | HMQV: A High-Performance Secure Diffie-Hellman Protocol
Hugo Krawczyk |
CRYPTO | 1 |
| 2004 | Randomness Extraction and Key Derivation Using the CBC, Cascade and HMAC Modes
Yevgeniy Dodis, Rosario Gennaro, Johan Håstad, Hugo Krawczyk, Tal Rabin |
CRYPTO | 4 |
| 2004 | Secure Hashed Diffie-Hellman over Non-DDH Groups
Rosario Gennaro, Hugo Krawczyk, Tal Rabin |
EUROCRYPT | 2 |
| 2003 | Relaxing Chosen-Ciphertext Security
Ran Canetti, Hugo Krawczyk, Jesper Buus Nielsen |
CRYPTO | 2 |
| 2003 | SIGMA: The 'SIGn-and-MAc' Approach to Authenticated Diffie-Hellman and Its Use in the IKE-Protocols
Hugo Krawczyk |
CRYPTO | 1 |
| 2003 | Secure Applications of Pedersen's Distributed Key Generation Protocol
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
CT-RSA | 3 |
| 2003 | Authenticating Mandatory Access Controls and Preserving Privacy for a High-Assurance Smart Card
Helmut Scherzer, Ran Canetti, Paul A. Karger, Hugo Krawczyk, Tal Rabin, David C. Toll |
ESORICS | 4 |
| 2002 | Security Analysis of IKE's Signature-Based Key-Exchange Protocol
Ran Canetti, Hugo Krawczyk |
CRYPTO | 2 |
| 2002 | Universally Composable Notions of Key Exchange and Secure Channels
Ran Canetti, Hugo Krawczyk |
EUROCRYPT | 2 |
| 2001 | The Order of Encryption and Authentication for Protecting Communications (or: How Secure Is SSL?)
Hugo Krawczyk |
CRYPTO | 1 |
| 2001 | Analysis of Key-Exchange Protocols and Their Use for Building Secure Channels
Ran Canetti, Hugo Krawczyk |
EUROCRYPT | 2 |
| 2001 | Robust Threshold DSS Signatures
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
Inf. Comput. | 3 |
| 2000 | Simple forward-secure signatures from any signature scheme
Hugo Krawczyk |
CCS | 1 |
| 2000 | Chameleon Signatures
Hugo Krawczyk, Tal Rabin |
NDSS | 1 |
| 2000 | Robust and Efficient Sharing of RSA Functions
Rosario Gennaro, Tal Rabin, Stanislaw Jarecki, Hugo Krawczyk |
J. Cryptol. | 4 |
| 2000 | RSA-Based Undeniable Signatures
Rosario Gennaro, Tal Rabin, Hugo Krawczyk |
J. Cryptol. | 3 |
| 2000 | Design, implementation, and deployment of the iKP secure electronic payment systemabstractThis paper discusses the design, implementation, and deployment of a secure and practical payment system for electronic commerce on the Internet. The system is based on the iKP family of protocols-(i=1,2,3)-developed at IBM Research. The protocols implement credit card-based transactions between buyers and merchants while the existing financial network is used for payment clearing and authorization. The protocols are extensible and can be readily applied to other account-based payment models, such as debit cards. They are based on careful and minimal use of public-key cryptography, and can be implemented in either software or hardware. Individual protocols differ in both complexity and degree of security. In addition to being both a precursor and a direct ancestor of the well-known SET standard, iKP-based payment systems have been in continuous operation on the Internet since mid-1996. This longevity-as well as the security and relative simplicity of the underlying mechanisms-makes the iKP experience unique. For this reason, this paper also reports on, and addresses, a number of practical issues arising in the course of implementation and real-world deployment of a secure payment system. Mihir Bellare, Juan A. Garay 0001, Ralf C. Hauser, Amir Herzberg, Hugo Krawczyk, Michael Steiner 0001, Gene Tsudik, Els Van Herreweghen, Michael Waidner |
IEEE J. Sel. Areas Commun. | 5 |
| 1999 | Stateless Evaluation of Pseudorandom Functions: Security beyond the Birthday Barrier
Mihir Bellare, Oded Goldreich 0001, Hugo Krawczyk |
CRYPTO | 3 |
| 1999 | UMAC: Fast and Secure Message Authentication
John Black, Shai Halevi, Hugo Krawczyk, Ted Krovetz, Phillip Rogaway |
CRYPTO | 3 |
| 1999 | Adaptive Security for Threshold Cryptosystems
Ran Canetti, Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
CRYPTO | 4 |
| 1999 | Secure Distributed Key Generation for Discrete-Log Based Cryptosystems
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
EUROCRYPT | 3 |
| 1999 | Untraceable mobility or how to travel incognito
Giuseppe Ateniese, Amir Herzberg, Hugo Krawczyk, Gene Tsudik |
Comput. Networks | 3 |
| 1999 | Public-Key Cryptography and Password ProtocolsabstractWe study protocols for strong authentication and key exchange in asymmetric scenarios where the authentication server possesses ~a pair of private and public keys while the client has only a weak human-memorizable password as its authentication key. We present and analyze several simple password authentication protocols in this scenario, and show that the security of these protocols can be formally proven based on standard cryptographic assumptions. Remarkably, our analysis shows optimal resistance to off-line password guessing attacks under the choice of suitable public key encryption functions. In addition to user authentication, we describe ways to enhance these protocols to provide two-way authentication, authenticated key exchange, defense against server's compromise, and user anonymity. We complement these results with a proof that strongly indicates that public key techniques are unavoidable for password protocols that resist off-line guessing attacks. As a further contribution, we introduce the notion ofpublic passwordsthat enables the use of the above protocols in situations where the client's machine does not have the means to validate the server's public key. Public passwords serve as "hand-held certificates" that the user can carry without the need for specal computing devices. Shai Halevi, Hugo Krawczyk |
ACM Trans. Inf. Syst. Secur. | 2 |
| 1998 | Public-Key Cryptography and Password ProtocolsabstractWe study protocols for strong authentication and key exchange in asymmetric scenarios where the authentication server possesses ~a pair of private and public keys while the client has only a weak human-memorizable password as its authentication key. We present and analyze several simple password authentication protocols in this scenario, and show that the security of these protocols can be formally proven based on standard cryptographic assumptions. Remarkably, our analysis shows optimal resistance to off-line password guessing attacks under the choice of suitable public key encryption functions. In addition to user authentication, we describe ways to enhance these protocols to provide two-way authentication, authenticated key exchange, defense against server's compromise, and user anonymity. We complement these results with a proof that strongly indicates that public key techniques are unavoidable for password protocols that resist off-line guessing attacks.As a further contribution, we introduce the notion of public passwords that enables the use of the above protocols in situations where the client's machine does not have the means to validate the server's public key. Public passwords serve as hand-held certificates that the user can carry without the need for specal computing devices. Shai Halevi, Hugo Krawczyk |
CCS | 2 |
| 1998 | A Modular Approach to the Design and Analysis of Authentication and Key Exchange Protocols (Extended Abstract)abstractWe prcscnt a general framework for constructing and analyzing authentication protocols in realistic models of communication networks.This framework provides a sound formalization for the authentication problem and suggests simple and attractive design principles for general authentication and key exchange protocols.The key element in our appronch io a modular treatment of the authentication problem in cryptographic protocols; thii applies to the definition of accurity, to the design of the protocols, and to their analysis.In particulnr, following this modular approach, we show how to systematically transform solutions that work in a model of idaalizcd authenticated communications into solutions that are secure in the realistic setting of communication channels controlled by an active adversary.Using these principles we construct and prove the security of simple and practical authentication and key-exchange protocols.In particular, we provide a security analysis of aomo well-known key exchange protocols (e.g.authenticated Dlfllc-Hcllman key exchange), and of some of the techniques underlying the design of several authentication protocols that are currently being deployed on a large scale for the Intornot Protocol and other applications. Mihir Bellare, Ran Canetti, Hugo Krawczyk |
STOC | 3 |
| 1997 | Proactive Public Key and Signature SystemsabstractEmerging applications like electronic commerce and secure communications over open networks have made clear the fundamental role of public key cryptography as a unique enabler for world-wide scale security solutions. On the other hand, these solutions clearly expose the fact that the protection of private keys is a security bottleneck in these sensitive applications. This problem is further worsened in the cases where a single and unchanged private key must be kept secret for very long time (such is the case of certification authority keys, bank and e-cash keys, etc.). One crucial defense against exposure of private keys is offered by threshold cryptography where the private key functions (like signatures or decryption) are distributed among several parties such that a predetermined number of parties must cooperate in order to correctly perform these operations. This protects keys from any single point of failure. An attacker needs to break into a multiplicity of locations before it c... Amir Herzberg, Markus Jakobsson, Stanislaw Jarecki, Hugo Krawczyk, Moti Yung |
CCS | 4 |
| 1997 | RSA-Based Undeniable Signatures
Rosario Gennaro, Hugo Krawczyk, Tal Rabin |
CRYPTO | 2 |
| 1997 | MMH: Software Message Authentication in the Gbit/Second Rates
Shai Halevi, Hugo Krawczyk |
FSE | 2 |
| 1996 | Keying Hash Functions for Message Authentication
Mihir Bellare, Ran Canetti, Hugo Krawczyk |
CRYPTO | 3 |
| 1996 | Robust and Efficient Sharing of RSA Functions
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
CRYPTO | 3 |
| 1996 | Robust Threshold DSS Signatures
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, Tal Rabin |
EUROCRYPT | 3 |
| 1996 | Pseudorandom Functions Revisited: The Cascade Construction and Its Concrete SecurityabstractPseudorandom function families are a powerful cryptographic primitive, yielding, in particular simple solutions for the main problems in private key cryptography. Their existence based on general assumptions (namely the existence of one-way functions) has been established. The authors investigate new ways of designing pseudorandom function families. The goal is to find constructions that are both efficient and secure, and thus eventually to bring the benefits of pseudorandom functions to practice. The basic building blocks in the design are certain limited versions of pseudorandom function families, called finite length input pseudorandom function families, for which very efficient realizations exist impractical cryptography. Thus rather than starting from one-way functions, they propose constructions of "full-fledged" pseudorandom function families from these limited ones. In particular they propose the cascade construction, and provide a concrete security analysis which relates the strength of the cascade to that of the underlying finite pseudorandom function family in a precise and quantitative way. Mihir Bellare, Ran Canetti, Hugo Krawczyk |
FOCS | 3 |
| 1996 | SKEME: a versatile secure key exchange mechanism for InternetabstractA secure and versatile key exchange protocol for key management over Internet is presented. SKEME constitutes a compact protocol that supports a variety of realistic scenarios and security models over Internet. It provides clear tradeoffs between security and performance as required by the different scenarios without incurring in unnecessary system complexity. The protocol supports key exchange based on public key, key distribution centers, or manual installation, and provides for fast and secure key refreshment. In addition, SKEME selectively provides perfect forward secrecy, allows for replaceability and negotiation of the underlying cryptographic primitives, and addresses privacy issues as anonymity and repudiatability. Hugo Krawczyk |
NDSS | 1 |
| 1996 | On the Composition of Zero-Knowledge Proof SystemsabstractThe wide applicability of zero-knowledge interactive proofs comes from the possibility of using these proofs as subroutines in cryptographic protocols. A basic question concerning this use is whether the (sequential and/or parallel) composition of zero-knowledge protocols is zero-knowledge too. We demonstrate the limitations of the composition of zero-knowledge protocols by proving that the original definition of zero-knowledge is not closed under sequential composition; and that even the strong formulations of zero-knowledge (e.g., black-box simulation) are not closed under parallel execution. We present lower bounds on the round complexity of zero-knowledge proofs, with significant implications for the parallelization of zero-knowledge protocols. We prove that three-round interactive proofs and constant-round Arthur-Merlin proofs that are black-box simulation zero-knowledge exist only for languages in BPP. In particular, it follows that the “parallel versions” of the first interactive proofs systems presented for quadratic residuosity, graph isomorphism, and any language in NP, are not black-box simulation zero-knowledge, unless the corresponding languages are in BPP Whether these parallel versions constitute zero-knowledge proofs was an intriguing open questions arising from the early works on zero-knowledge. Other consequences are a proof of optimality for the round complexity of various known zero-knowledge protocols and the necessity of using secret coins in the design of “parallelizable” constant-round zero-knowledge proofs. Oded Goldreich 0001, Hugo Krawczyk |
SIAM J. Comput. | 2 |
| 1995 | Proactive Secret Sharing Or: How to Cope With Perpetual Leakage
Amir Herzberg, Stanislaw Jarecki, Hugo Krawczyk, Moti Yung |
CRYPTO | 3 |
| 1995 | New Hash Functions For Message Authentication
Hugo Krawczyk |
EUROCRYPT | 1 |
| 1995 | Securing the Internet (Abstract)abstractNo abstract available. Pau-Chen Cheng, Juan A. Garay 0001, Amir Herzberg, Hugo Krawczyk |
PODC | 4 |
| 1995 | Design and Implementation of Modular Key Management Protocol and IP Secure Tunnel on AIX
Pau-Chen Cheng, Juan A. Garay 0001, Amir Herzberg, Hugo Krawczyk |
USENIX Security Symposium | 4 |
| 1994 | LFSR-based Hashing and Authentication
Hugo Krawczyk |
CRYPTO | 1 |
| 1993 | The Shrinking Generator
Don Coppersmith, Hugo Krawczyk, Yishay Mansour |
CRYPTO | 2 |
| 1993 | Secret Sharing Made Short
Hugo Krawczyk |
CRYPTO | 1 |
| 1993 | The Shrinking Generator: Some Practical Considerations
Hugo Krawczyk |
FSE | 1 |
| 1993 | Distributed Fingerprints and Secure Information DispersalabstractArticle Distributed fingerprints and secure information dispersal Share on Author: Hugo Krawczyk View Profile Authors Info & Claims PODC '93: Proceedings of the twelfth annual ACM symposium on Principles of distributed computingSeptember 1993 Pages 207–218https://doi.org/10.1145/164051.164075Online:01 September 1993Publication History 54citation1,025DownloadsMetricsTotal Citations54Total Downloads1,025Last 12 Months6Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Hugo Krawczyk |
PODC | 1 |
| 1993 | On the Existence of Pseudorandom GeneratorsabstractPseudorandom generators (suggested and developed by Blum and Micali and Yao) are efficient deterministic programs that expand a randomly selected k-bit seed into a much longer pseudorandom bit sequence that is indistinguishable in polynomial time from an (equally long) sequence of unbiased coin tosses. A fundamental question is to find simple conditions, as the existence of one-way functions, which suffice for constructing pseudorandom generators. This paper considers regular functions, in which every image of a k-bit string has the same number of preimages of length k. This paper shows how to construct pseudorandom generators from any regular one-way function. Oded Goldreich 0001, Hugo Krawczyk, Michael Luby |
SIAM J. Comput. | 2 |
| 1991 | Code Duplication: An Assist for Global Instruction SchedulingabstractArticle Code duplication: an assist for global instruction scheduling Share on Authors: David Bernstein IBM Israel Scientific Center, The Technion City, Haifa 32000, Israel IBM Israel Scientific Center, The Technion City, Haifa 32000, IsraelView Profile , Doron Cohen IBM Israel Scientific Center, The Technion City, Haifa 32000, Israel IBM Israel Scientific Center, The Technion City, Haifa 32000, IsraelView Profile , Hugo Krawczyk Computer Science Department, Princeton University, New Jersey and IBM Israel Scientific Center, The Technion City, Haifa 32000, Israel Computer Science Department, Princeton University, New Jersey and IBM Israel Scientific Center, The Technion City, Haifa 32000, IsraelView Profile Authors Info & Claims MICRO 24: Proceedings of the 24th annual international symposium on MicroarchitectureSeptember 1991 Pages 103–113https://doi.org/10.1145/123465.123486Online:01 September 1991Publication History 24citation364DownloadsMetricsTotal Citations24Total Downloads364Last 12 Months5Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access David Bernstein, Doron Cohen 0001, Hugo Krawczyk |
MICRO | 3 |
| 1990 | On the Composition of Zero-Knowledge Proof Systems
Oded Goldreich 0001, Hugo Krawczyk |
ICALP | 2 |
| 1989 | Sparse Pseudorandom Distributions
Oded Goldreich 0001, Hugo Krawczyk |
CRYPTO | 2 |
| 1989 | How to Predict Congruential Generators
Hugo Krawczyk |
CRYPTO | 1 |
| 1989 | Spill Code Minimization Techniques for Optimizing CompilersabstractGlobal register allocation and spilling is commonly performed by solving a graph coloring problem. In this paper we present a new coherent set of heuristic methods for reducing the amount of spill code generated. This results in more efficient (and shorter) compiled code. Our approach has been compared to both standard and priority-based coloring algorithms, universally outperforming them. David Bernstein, Dina Q. Goldin, Martin Charles Golumbic, Hugo Krawczyk, Yishay Mansour, Itai Nahshon, Ron Y. Pinter |
PLDI | 4 |
| 1989 | The diophantine problem of Frobenius: A close bound
Hugo Krawczyk, Azaria Paz |
Discret. Appl. Math. | 1 |
| 1988 | On the Existence of Pseudorandom Generators
Oded Goldreich 0001, Hugo Krawczyk, Michael Luby |
CRYPTO | 2 |
| 1988 | On the Existence of Pseudorandom Generators (Extended Abstract)abstractPseudorandom generators are known to exist, assuming the existence of functions that cannot be efficiently inverted on the distributions induced by applying the function iteratively polynomially many times. This sufficient condition is also necessary, but it is difficult to check whether particular functions, assumed to be one-way, are also one-way on their iterates. This raises the fundamental question of whether the mere existence of one-way functions suffices for the construction of pseudorandom generators. Progress toward resolving this question is presented. Regular functions in which every image of a k-bit string has the same number of preimages of length k are considered. It is shown that if a regular function is one-way, then pseudorandom generators do exist. In particular, assuming the intractability of general factoring, it can be proved that the pseudorandom generators do exist. Another application is the construction of a pseudorandom generator based on the assumed intractability of decoding random linear codes.> Oded Goldreich 0001, Hugo Krawczyk, Michael Luby |
FOCS | 2 |