Bertram Poettering

dblp:48/8243 · DBLP profile ↗
← Back
40ranked-venue papers
6as first author
6since 2021 · last 2024
0000-0001-6525-5141ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 40 · 6 first-author · 6 since 2021Theory of computation · 1
YearPublicationVenuePosition
2024 Digital Signatures with Outsourced Hashing
Bertram Poettering, Simon Rastikian
ASIACRYPT (2)1
2023 Attribute-based Single Sign-On: Secure, Private, and Efficient
abstract
A Single Sign-On (SSO) system allows users to access different remote services while authenticating only once. SSO can greatly improve the usability and security of online activities by dispensing with the need to securely remember or store tens or hundreds of authentication secrets. On the downside, today's SSO providers can track users' online behavior, and collect personal data that service providers want to see asserted before letting a user access their resources. In this work, we propose a new policy-based Single Sign-On service, i.e., a system that produces access tokens that are conditioned on the user's attributes fulfilling a specified policy. Our solution is based on multi-party computation and threshold cryptography, and generates access tokens of standardized format. The central idea is to distribute the role of the SSO provider among several entities, in order to shield user attributes and access patterns from each individual entity. We provide a formal security model and analysis in the Universal Composability framework, against proactive adversaries. Our implementation and benchmarking show the practicality of our system for many real-world use cases.
Tore Kasper Frederiksen, Julia Hesse, Bertram Poettering, Patrick Towa
Proc. Priv. Enhancing Technol.3
2022 On Secure Ratcheting with Immediate Decryption
Jeroen Pijnenburg, Bertram Poettering
ASIACRYPT (3)2
2022 Sequential Digital Signatures for Cryptographic Software-Update Authentication
Bertram Poettering, Simon Rastikian
ESORICS (2)1
2021 On the (In)Security of ElGamal in OpenPGP
abstract
Roughly four decades ago, Taher ElGamal put forward what is today one of the most widely known and best understood public key encryption schemes. ElGamal encryption has been used in many different contexts, chiefly among them by the OpenPGP standard. Despite its simplicity, or perhaps because of it, in reality there is a large degree of ambiguity on several key aspects of the cipher. Each library in the OpenPGP ecosystem seems to have implemented a slightly different "flavour" of ElGamal encryption. While --taken in isolation-- each implementation may be secure, we reveal that in the interoperable world of OpenPGP, unforeseen cross-configuration attacks become possible. Concretely, we propose different such attacks and show their practical efficacy by recovering plaintexts and even secret keys.
Luca De Feo, Bertram Poettering, Alessandro Sorniotti
CCS2
2021 SoK: Game-Based Security Models for Group Key Exchange
Bertram Poettering, Paul Rösler, Jörg Schwenk, Douglas Stebila
CT-RSA1
2020 Encrypt-to-Self: Securely Outsourcing Storage
Jeroen Pijnenburg, Bertram Poettering
ESORICS (1)2
2020 Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering
J. Cryptol.4
2019 Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering
CRYPTO (1)4
2019 Lossy Trapdoor Permutations with Improved Lossiness
Benedikt Auerbach, Eike Kiltz, Bertram Poettering, Stefan Schoenen
CT-RSA3
2019 Subverting Decryption in AEAD
Marcel Armour, Bertram Poettering
IMACC2
2018 Towards Bidirectional Ratcheted Key Exchange
Bertram Poettering, Paul Rösler
CRYPTO (1)1
2018 A Cryptographic Look at Multi-party Channels
abstract
Cryptographic channels aim to enable authenticated and confidential communication over the Internet. The general understanding seems to be that providing security in the sense of authenticated encryption for every (unidirectional) point-to-point link suffices to achieve this goal. As recently shown (in FSE17/ToSC17), however, the security properties of the unidirectional links do not extend, in general, to the bidirectional channel as a whole. Intuitively, the reason for this is that the increased interaction in bidirectional communication can be exploited by an adversary. The same applies, a fortiori, in a multi-party setting where several users operate concurrently and the communication develops in more directions. In the cryptographic literature, however, the targeted goals for group communication in terms of channel security are still unexplored. Applying the methodology of provable security, we fill this gap by defining exact (game-based) authenticity and confidentiality goals for broadcast communication, and showing how to achieve them. Importantly, our security notions also account for the causal dependencies between exchanged messages, thus naturally extending the bidirectional case where causal relationships are automatically captured by preserving the sending order. On the constructive side we propose a modular and yet efficient protocol that, assuming only point-to-point links between users, leverages (non-cryptographic) broadcast and standard cryptographic primitives to a full-fledged broadcast channel that provably meets the security notions we put forth.
Patrick Eugster, Giorgia Azzurra Marson, Bertram Poettering
CSF3
2017 On the One-Per-Message Unforgeability of (EC)DSA and Its Variants
Manuel Fersch, Eike Kiltz, Bertram Poettering
TCC (2)3
2017 Cryptographic enforcement of information flow policies without public information via tree partitions
abstract
We may enforce an information flow policy by encrypting a protected resource and ensuring that only users authorized by the policy are able to decrypt the resource. In most schemes in the literature that use symmetric cryptographic primitives, each user is assigned a single secret and derives decry ption keys using this secret and publicly available information. Recent work has challenged this approach by developing schemes, based on a chain partition of the information flow policy, that do not require public information for key derivation, the trade-off being that a user may need to be assigned more than one secret. In general, many different chain partitions exist for the same policy and, until now, it was not known how to compute an appropriate one. In this paper, we introduce the notion of a tree partition, of which chain partitions are a special case. We show how a tree partition may be used to define a cryptographic enforcement scheme and prove that such schemes can be instantiated in such a way as to preserve the strongest security properties known for cryptographic enforcement schemes. We establish a number of results linking the amount of secret material that needs to be distributed to users with a weighted acyclic graph derived from the tree partition. These results enable us to develop efficient algorithms for deriving tree and chain partitions that minimize the total amount of secret material that needs to be distributed.
Jason Crampton, Naomi Farley, Gregory Z. Gutin, Mark Jones 0001, Bertram Poettering
J. Comput. Secur.5
2016 From Identification to Signatures, Tightly: A Framework and Generic Transforms
Mihir Bellare, Bertram Poettering, Douglas Stebila
ASIACRYPT (2)2
2016 Selective Opening Security from Simulatable Data Encapsulation
Felix Heuer, Bertram Poettering
ASIACRYPT (2)2
2016 On the Provable Security of (EC)DSA Signatures
abstract
Among the signature schemes most widely deployed in practice are the DSA (Digital Signature Algorithm) and its elliptic curves variant ECDSA. They are represented in many international standards, including IEEE P1363, ANSI X9.62, and FIPS 186-4. Their popularity stands in stark contrast to the absence of rigorous security analyses: Previous works either study modified versions of (EC)DSA or provide a security analysis of unmodified ECDSA in the generic group model. Unfortunately, works following the latter approach assume abstractions of non-algebraic functions over generic groups for which it remains unclear how they translate to the security of ECDSA in practice. For instance, it has been pointed out that prior results in the generic group model actually establish strong unforgeability of ECDSA, a property that the scheme de facto does not possess. As, further, no formal results are known for DSA, understanding the security of both schemes remains an open problem. In this work we propose GenericDSA, a signature framework that subsumes both DSA and ECDSA in unmodified form. It carefully models the "modulo q" conversion function of (EC)DSA as a composition of three independent functions. The two outer functions mimic algebraic properties in the function's domain and range, the inner one is modeled as a bijective random oracle. We rigorously prove results on the security of GenericDSA that indicate that forging signatures in (EC)DSA is as hard as solving discrete logarithms. Importantly, our proofs do not assume generic group behavior.
Manuel Fersch, Eike Kiltz, Bertram Poettering
CCS3
2015 Linkable Message Tagging: Solving the Key Distribution Problem of Signature Schemes
Felix Günther 0001, Bertram Poettering
ACISP2
2015 Cryptographic Enforcement of Information Flow Policies Without Public Information
Jason Crampton, Naomi Farley, Gregory Z. Gutin, Mark Jones 0001, Bertram Poettering
ACNS5
2015 Cold Boot Attacks in the Discrete Logarithm Setting
Bertram Poettering, Dale L. Sibborn
CT-RSA1
2015 A More Cautious Approach to Security Against Mass Surveillance
Jean Paul Degabriele, Pooya Farshim, Bertram Poettering
FSE3
2014 Big Bias Hunting in Amazonia: Large-Scale Computation and Exploitation of RC4 Biases (Invited Paper)
Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt
ASIACRYPT (1)2
2014 Multi-recipient encryption, revisited
abstract
A variant of public key encryption that promises efficiency gains due to batch processing is multi-recipient public key encryption (MR-PKE). Precisely, in MR-PKE, a dedicated encryption routine takes a vector of messages and a vector of public keys and outputs a vector of ciphertexts, where the latter can be decrypted individually, as in regular PKE. In this paper we revisit the established security notions of MR-PKE and the related primitive MR-KEM. We identify a subtle flaw in a security model by Bellare, Boldyreva, and Staddon, that also appears in later publications by different authors. We further observe that these security models rely on the knowledge-of-secret-key (KOSK) assumption---a requirement that is rarely met in practice. We resolve this situation by proposing strengthened security notions for MR-PKE and MR-KEMs, together with correspondingly secure yet highly efficient schemes. Importantly, our models abstain from restricting the set of considered adversaries in the way prior models did, and in particular do not require the KOSK setting. We prove our constructions secure assuming hardness of the static Diffie-Hellman problem, in the random oracle model.
Alexandre Miranda Pinto, Bertram Poettering, Jacob C. N. Schuldt
AsiaCCS2
2014 Even More Practical Secure Logging: Tree-Based Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering
ESORICS (2)2
2014 Double-Authentication-Preventing Signatures
Bertram Poettering, Douglas Stebila
ESORICS (1)1
2014 Plaintext Recovery Attacks Against WPA/TKIP
Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt
FSE2
2013 Pseudorandom signatures
abstract
We develop a three-level hierarchy of privacy notions for (unforgeable) digital signature schemes. We first prove mutual independence of existing notions of anonymity and confidentiality, and then show that these are implied by higher privacy goals. The top notion in our hierarchy is pseudorandomness: signatures with this property hide the entire information about the signing process and cannot be recognized as signatures when transmitted over a public network. This implies very strong unlinkability guarantees across different signers and even different signing algorithms, and gives rise to new forms of private public-key authentication.
Nils Fleischhacker, Felix Günther 0001, Franziskus Kiefer, Mark Manulis, Bertram Poettering
AsiaCCS5
2013 Simple, Efficient and Strongly KI-Secure Hierarchical Key Assignment Schemes
Eduarda S. V. Freire 0001, Kenneth G. Paterson, Bertram Poettering
CT-RSA3
2013 ASICS: Authenticated Key Exchange Security Incorporating Certification Systems
Colin Boyd, Cas Cremers, Michèle Feltz, Kenneth G. Paterson, Bertram Poettering, Douglas Stebila
ESORICS5
2013 Practical Secure Logging: Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering
ESORICS2
2013 On the Security of RC4 in TLS
Nadhem J. AlFardan, Daniel J. Bernstein, Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt
USENIX Security Symposium4
2013 Publicly verifiable ciphertexts
Juan Manuel González Nieto, Mark Manulis, Bertram Poettering, Jothi Rangasamy, Douglas Stebila
J. Comput. Secur.3
2011 Private Discovery of Common Social Contacts
Emiliano De Cristofaro, Mark Manulis, Bertram Poettering
ACNS3
2011 Practical affiliation-hiding authentication from improved polynomial interpolation
abstract
Among the plethora of privacy-friendly authentication techniques, affiliation-hiding (AH) protocols are valuable for their ability to hide not only identities of communicating users behind their affiliations (memberships to groups), but also these affiliations from non-members. These qualities become increasingly important in our highly computerized user-centric information society, where privacy is an elusive good.
Mark Manulis, Bertram Poettering
AsiaCCS2
2011 Affiliation-Hiding Authentication with Minimal Bandwidth Consumption
Mark Manulis, Bertram Poettering
WISTP2
2010 Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder
ACNS10
2010 Privacy-Preserving Group Discovery with Linear Complexity
Mark Manulis, Benny Pinkas, Bertram Poettering
ACNS3
2010 Affiliation-Hiding Key Exchange with Untrusted Group Authorities
Mark Manulis, Bertram Poettering, Gene Tsudik
ACNS2
2010 Taming Big Brother Ambitions: More Privacy for Secret Handshakes
Mark Manulis, Bertram Poettering, Gene Tsudik
Privacy Enhancing Technologies2