Bart Mennink

dblp:50/8321 · DBLP profile ↗
← Back
71ranked-venue papers
22as first author
20since 2021 · last 2026
0000-0001-6679-1878ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 67 · 21 first-author · 18 since 2021Theory of computation · 4 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorComputer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Permutation-Based Hashing with Stronger (Second) Preimage Resistance
Siwei Sun, Shun Li 0004, Zhiyu Zhang 0009, Charlotte Lefevre, Bart Mennink, Dengguo Feng
CRYPTO (6)5
2026 How to Build a Short-Input Random Oracle from Public Random Permutations
Ritam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha 0001, Sougata Mandal, Bart Mennink, Hrithik Nandi, Yaobin Shen
EUROCRYPT6
2025 Generic Security of GCM-SST
Akiko Inoue, Ashwin Jha 0001, Bart Mennink, Kazuhiko Minematsu
ACNS (2)3
2025 A Decomposition Approach for Evaluating Security of Masking
Vahid Jahandideh, Bart Mennink, Lejla Batina
ASIACRYPT (1)2
2025 Efficient Instances of Docked Double Decker with AES, and Application to Authenticated Encryption
Christoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander Tereschenko
EUROCRYPT (1)3
2024 Generalized Initialization of the Duplex Construction
Christoph Dobraunig, Bart Mennink
ACNS (2)2
2024 Generic Security of the Ascon Mode: On the Power of Key Blinding
Charlotte Lefevre, Bart Mennink
SAC (2)2
2024 The COLM Authenticated Encryption Scheme
Elena Andreeva 0001, Andrey Bogdanov, Nilanjan Datta, Atul Luykx, Bart Mennink, Mridul Nandi, Elmar Tischhauser, Kan Yasuda
J. Cryptol.5
2023 Generic Security of the SAFE API and Its Applications
Dmitry Khovratovich, Mario Marhuenda Beltrán, Bart Mennink
ASIACRYPT (8)3
2023 Revisiting the Indifferentiability of the Sum of Permutations
Aldo Gunsing, Ritam Bhaumik, Ashwin Jha 0001, Bart Mennink, Yaobin Shen
CRYPTO (3)4
2023 Secure Distributed Modular Exponentiation: Systematic Analysis and New Results
abstract
Modular exponentiation is a vital function in public key cryptography. Dozens of protocols, including encryption schemes, signature schemes, pseudorandom functions, and more, perform this operation on a secret base and/or a secret exponent. In a multiparty computation setting, these secret data might be shared over multiple parties who wish to compute this modular exponentiation in a secure and distributed way. However, whereas typical frameworks for secure multiparty computation based on secret sharing provide a basic tool box of secure distributed computation of, most importantly, randomness generation, addition, and multiplication, the status quo of secure distributed modular exponentiation is unsatisfactory. In this work, we provide a complete and comprehensive overview on existing protocols for perfectly secure distributed exponentiation differing depending on whether the inputs and outcomes are public or shared. We perform a detailed complexity computation of the currently existing protocols, observing that earlier authors have overestimated the complexity of their own protocols, and close the remaining open problem: protocols for secure distributed exponentiation with secret base, secret exponent, and public outcome. We prove that the presented protocol is universally composably secure in the presence of malicious adversaries. We finally exemplify the practical relevance of the new protocol by demonstrating how it can be used for pseudorandom generation and signing.
Bart Mennink
IEEE Trans. Inf. Forensics Secur.1
2022 Security of Truncated Permutation Without Initial Value
Lorenzo Grassi 0001, Bart Mennink
ASIACRYPT (2)2
2022 Leakage and Tamper Resilient Permutation-Based Cryptography
abstract
Implementation attacks such as power analysis and fault attacks have shown that, if potential attackers have physical access to a cryptographic device, achieving practical security requires more considerations apart from just cryptanalytic security. In recent years, and with the advent of micro-architectural or hardware-oriented attacks, it became more and more clear that similar attack vectors can also be exploited on larger computing platforms and without the requirement of physical proximity of an attacker. While newly discovered attacks typically come with implementation recommendations that help counteract a specific attack vector, the process of constantly patching cryptographic code is quite time consuming in some cases, and simply not possible in other cases.
Christoph Dobraunig, Bart Mennink, Robert Primas
CCS2
2022 Tight Preimage Resistance of the Sponge Construction
Charlotte Lefevre, Bart Mennink
CRYPTO (4)2
2022 HERMES: Scalable, Secure, and Privacy-Enhancing Vehicular Sharing-Access System
abstract
We propose HERMES, a scalable, secure, and privacy-enhancing system for users to share and access vehicles. HERMES securely outsources operations of vehicle access token (AT) generation to a set of untrusted servers. It builds on an earlier proposal, namely, SePCAR, and extends the system design for improved efficiency and scalability. To cater to system and user needs for secure and private computations, HERMES utilizes and combines several cryptographic primitives with secure multiparty computation (MPC) efficiently. It conceals secret keys of vehicles and transaction details from the servers, including vehicle booking details, AT information, and user and vehicle identities. It also provides user accountability in case of disputes. Besides, we provide semantic security analysis and prove that HERMES meets its security and privacy requirements. Last but not least, we demonstrate that HERMES is efficient and, in contrast to SePCAR, scales to a large number of users and vehicles, making it practical for real-world deployments. We build our evaluations with two different MPC protocols: 1) HtMAC-MiMC and 2) CBC-MAC-AES. Our results demonstrate that HERMES is in the range of milliseconds for generating an AT, whether it operates for a single-vehicle owner or a large rental-company branch with over 1000 vehicles; handling 546 and 84 AT generations per second, respectively. As a result, HERMES is an order of magnitude faster compared to SePCAR. Specifically, it delivers 696 (with HtMAC-MiMC) and 42 (with CBC-MAC-AES) more ATs compared to in SePCAR for a single-vehicle owner AT generation. Furthermore, we show that HERMES is practical on the vehicle side, too, as AT operations performed on a prototype vehicle on-board unit take only$\approx 62 $ms.
Iraklis Symeonidis, Dragos Rotaru, Mustafa A. Mustafa, Bart Mennink, Bart Preneel, Panagiotis Papadimitratos
IEEE Internet Things J.4
2021 Categorization of Faulty Nonce Misuse Resistant Message Authentication
Yu Long Chen, Bart Mennink, Bart Preneel
ASIACRYPT (3)2
2021 Leakage Resilient Value Comparison with Application to Message Authentication
Christoph Dobraunig, Bart Mennink
EUROCRYPT (2)2
2021 Multi-user Security of the Elephant v2 Authenticated Encryption Mode
Tim Beyne, Yu Long Chen, Christoph Dobraunig, Bart Mennink
SAC4
2021 On the Resilience of Even-Mansour to Invariant Permutations
abstract
Abstract Symmetric cryptographic primitives are often exposed to invariances: deterministic relations between plaintexts and ciphertexts that propagate through the primitive. Recent invariant subspace attacks have shown that these can be a serious issue. One way to mitigate invariant subspace attacks is at the primitive level, namely by proper use of round constants (Beierle et al., CRYPTO 2017). In this work, we investigate how to thwart invariance exploitation at the mode level, namely by assuring that a mode never evaluates its underlying primitive under any invariance. We first formalize the use of invariant cryptographic permutations from a security perspective, and analyze the Even-Mansour block cipher construction. We further demonstrate how the model composes, and apply it to the keyed sponge construction. The security analyses exactly pinpoint how the presence of linear invariances affects the bounds compared with analyses in the random permutation model. As such, they give an exact indication how invariances can be exploited. From a practical side, we apply the derived security bounds to the case where the Even-Mansour construction is instantiated with the 512-bit ChaCha permutation, and derive a distinguishing attack against Even-Mansour-ChaCha in $$2^{128}$$ 2 128 queries, faster than the birthday bound. Comparable results are derived for instantiation using the 200-bit Keccak permutation without round constants (attack in $$2^{50}$$ 2 50 queries), the 1024-bit CubeHash permutation (attack in $$2^{256}$$ 2 256 queries), and the 384-bit Gimli permutation without round constants (attack in $$2^{96}$$ 2 96 queries). The attacks do not invalidate the security of the permutations themselves, but rather they demonstrate the tightness of our bounds and confirm that care should be taken when employing a cryptographic primitive that has nontrivial linear invariances.
Bart Mennink, Samuel Neves
Des. Codes Cryptogr.1
2021 Systematic Security Analysis of Stream Encryption With Key Erasure
abstract
We consider a generalized construction of stream ciphers with forward security. The design framework is modular: it is built from a so-called layer function that updates the key and (optionally) the nonce and generates a new pseudorandom output stream. We analyze the generalized construction for four different instantiations: two possible layer functions that are in turn instantiated with either a block cipher or a pseudorandom function. We prove that each of these instantiations gives a stream cipher that is pseudorandom and forward secure in the multi-user setting with a very tight bound. A comprehensive analysis shows that the two block cipher based instantiations achieve very similar bounds. For the pseudorandom function based instantiations there is no clear winner: either layer can be beneficial over the other one, depending on the choice of parameters. By instantiating the pseudorandom function with a generic construction such as the sum of permutations, we obtain a highly efficient and competitive stream cipher based on an n-bit block cipher that is secure beyond the$2^{\text {n}/2}$birthday bound.
Yu Long Chen, Atul Luykx, Bart Mennink, Bart Preneel
IEEE Trans. Inf. Theory3
2020 Beyond Birthday Bound Secure Fresh Rekeying: Application to Authenticated Encryption
Bart Mennink
ASIACRYPT (1)1
2020 The Summation-Truncation Hybrid: Reusing Discarded Bits for Free
Aldo Gunsing, Bart Mennink
CRYPTO (1)2
2020 Collapseability of Tree Hashes
Aldo Gunsing, Bart Mennink
PQCrypto2
2020 Practical forgeries for ORANGE
abstract
We analyze the authenticated encryption algorithm of ORANGE, a submission to the NIST lightweight cryptography standardization process. We show that it is practically possible to craft forgeries out of two observed transmitted messages that encrypt the same plaintext. The authors of ORANGE have confirmed the attack, and they discuss a fix for this attack in their second-round submission of ORANGE to the NIST lightweight cryptography competition.
Christoph Dobraunig, Florian Mendel, Bart Mennink
Inf. Process. Lett.3
2019 Leakage Resilience of the Duplex Construction
Christoph Dobraunig, Bart Mennink
ASIACRYPT (3)2
2019 How to Build Pseudorandom Functions from Public Random Permutations
Yu Long Chen, Eran Lambooij, Bart Mennink
CRYPTO (1)3
2019 Linking Stam's Bounds with Generalized Truncation
Bart Mennink
CT-RSA1
2019 Beyond Conventional Security in Sponge-Based Authenticated Encryption Modes
abstract
The Sponge function is known to achieve $$2^{c/2}$$ security, where c is its capacity. This bound was carried over to its keyed variants, such as SpongeWrap, to achieve a $$\min \{2^{c/2},2^\kappa \}$$ security bound, with $$\kappa $$ the key length. Similarly, many CAESAR competition submissions were designed to comply with the classical $$2^{c/2}$$ security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of $$\min \{2^{b/2},2^c,2^\kappa \}$$ , with $$b>c$$ the permutation size, by proving that the CAESAR submission NORX achieves this bound. The proof relies on rigorous computation of multi-collision probabilities, which may be of independent interest. We additionally derive a generic attack based on multi-collisions that matches the bound. We show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of some of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. We finally consider the remaining one of the three PRIMATEs, APE, and derive a blockwise adaptive attack in the nonce-respecting setting with complexity $$2^{c/2}$$ , therewith demonstrating that the techniques cannot be applied to APE.
Philipp Jovanovic, Atul Luykx, Bart Mennink, Yu Sasaki 0001, Kan Yasuda
J. Cryptol.3
2018 Short Variable Length Domain Extenders with Beyond Birthday Bound Security
Yu Long Chen, Bart Mennink, Mridul Nandi
ASIACRYPT (1)2
2018 The Relation Between CENC and NEMO
Bart Mennink
CANS1
2018 Towards Tight Security of Cascaded LRW2
Bart Mennink
TCC (2)1
2018 Connecting tweakable and multi-key blockcipher security
abstract
The significance of understanding blockcipher security in the multi-key setting is highlighted by the extensive literature on attacks, and how effective key size can be significantly reduced. Nevertheless, little attention has been paid in formally understanding the design of multi-key secure blockciphers. In this work, we formalize the multi-key security of tweakable blockciphers in case of general key derivation functions. We show an equivalence between blockcipher multi-key security and tweakable blockcipher security. Our equivalence connects two objects of study, the iterated Even–Mansour (EUROCRYPT 2012) and the iterated Tweakable Even–Mansour (CRYPTO 2015), which establishes that results in both areas are, to a certain extent, transferable. Using our novel equivalence relation, we derive new bounds for both constructions, pave the path towards the solution of two well-studied conjectures, and show that, contrary to common knowledge, key derivation functions need not necessarily be pseudorandom functions in order to provide security: for the iterated Even–Mansour universal hash functions suffice.
Jooyoung Lee 0001, Atul Luykx, Bart Mennink, Kazuhiko Minematsu
Des. Codes Cryptogr.3
2017 Full-State Keyed Duplex with Built-In Multi-user Support
Joan Daemen, Bart Mennink, Gilles Van Assche
ASIACRYPT (2)2
2017 Analyzing Multi-key Security Degradation
Atul Luykx, Bart Mennink, Kenneth G. Paterson
ASIACRYPT (2)2
2017 Insuperability of the Standard Versus Ideal Model Gap for Tweakable Blockcipher Security
Bart Mennink
CRYPTO (2)1
2017 Encrypted Davies-Meyer and Its Dual: Towards Optimal Security Using Mirror Theory
Bart Mennink, Samuel Neves
CRYPTO (3)1
2017 Weak Keys for AEZ, and the External Key Padding Attack
Bart Mennink
CT-RSA1
2017 SePCAR: A Secure and Privacy-Enhancing Protocol for Car Access Provision
Iraklis Symeonidis, Abdelrahaman Aly, Mustafa A. Mustafa, Bart Mennink, Siemen Dhooghe, Bart Preneel
ESORICS (2)4
2017 XOR of PRPs in a Quantum World
Bart Mennink, Alan Szepieniec
PQCrypto1
2017 Optimal collision security in double block length hashing with single length key
Bart Mennink
Des. Codes Cryptogr.1
2016 Improving the Sphinx Mix Network
Filipe Beato, Kimmo Halunen, Bart Mennink
CANS3
2016 XPX: Generalized Tweakable Even-Mansour with Improved Security Guarantees
Bart Mennink
CRYPTO (1)1
2016 Improved Masking for Tweakable Blockciphers with Applications to Authenticated Encryption
Robert Granger, Philipp Jovanovic, Bart Mennink, Samuel Neves
EUROCRYPT (1)3
2016 Damaging, Simplifying, and Salvaging p-OMD
Tomer Ashur, Bart Mennink
ISC2
2015 On the XOR of Multiple Random Permutations
Bart Mennink, Bart Preneel
ACNS1
2015 On the Impact of Known-Key Attacks on Hash Functions
Bart Mennink, Bart Preneel
ASIACRYPT (2)1
2015 Security of Full-State Keyed Sponge and Duplex: Applications to Authenticated Encryption
Bart Mennink, Reza Reyhanitabar, Damian Vizár
ASIACRYPT (2)1
2015 Security of Keyed Sponge Constructions Using a Modular Proof Approach
Elena Andreeva 0001, Joan Daemen, Bart Mennink, Gilles Van Assche
FSE3
2015 Optimally Secure Tweakable Blockciphers
Bart Mennink
FSE1
2015 Forgery and Subkey Recovery on CAESAR Candidate iFeed
Willem Schroé, Bart Mennink, Elena Andreeva 0001, Bart Preneel
SAC2
2015 Open problems in hash function security
Elena Andreeva 0001, Bart Mennink, Bart Preneel
Des. Codes Cryptogr.2
2014 How to Securely Release Unverified Plaintext in Authenticated Encryption
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda
ASIACRYPT (1)4
2014 Beyond 2 c/2 Security in Sponge-Based Authenticated Encryption Modes
Philipp Jovanovic, Atul Luykx, Bart Mennink
ASIACRYPT (1)3
2014 Breaking and Fixing Cryptophia's Short Combiner
Bart Mennink, Bart Preneel
CANS1
2014 The Security of Multiple Encryption in the Ideal Cipher Model
Yuanxi Dai, Jooyoung Lee 0001, Bart Mennink, John P. Steinberger
CRYPTO (1)3
2014 APE: Authenticated Permutation-Based Encryption for Lightweight Cryptography
Elena Andreeva 0001, Begül Bilgin, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda
FSE5
2014 COBRA: A Parallelizable Authenticated Online Cipher Without Block Cipher Inverse
Elena Andreeva 0001, Atul Luykx, Bart Mennink, Kan Yasuda
FSE3
2014 Chaskey: An Efficient MAC Algorithm for 32-bit Microcontrollers
Nicky Mouha, Bart Mennink, Anthony Van Herrewege, Dai Watanabe, Bart Preneel, Ingrid Verbauwhede
Selected Areas in Cryptography2
2014 On the collision and preimage security of MDC-4 in the ideal cipher model
Bart Mennink
Des. Codes Cryptogr.1
2013 Parallelizable and Authenticated Online Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan Yasuda
ASIACRYPT (1)4
2013 On the Indifferentiability of Key-Alternating Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Yevgeniy Dodis, Bart Mennink, John P. Steinberger
CRYPTO (1)4
2013 Towards Understanding the Known-Key Security of Block Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Bart Mennink
FSE3
2013 Indifferentiability of Double Length Compression Functions
Bart Mennink
IMACC1
2012 Optimal Collision Security in Double Block Length Hashing with Single Length Key
Bart Mennink
ASIACRYPT1
2012 A Simple Key-Recovery Attack on McOE-X
Florian Mendel, Bart Mennink, Vincent Rijmen, Elmar Tischhauser
CANS2
2012 Hash Functions Based on Three Permutations: A Generic Security Analysis
Bart Mennink, Bart Preneel
CRYPTO1
2012 Provable Security of BLAKE with Non-ideal Compression Function
Elena Andreeva 0001, Atul Luykx, Bart Mennink
Selected Areas in Cryptography3
2012 Increasing the flexibility of the herding attack
Bart Mennink
Inf. Process. Lett.1
2010 Anonymous Credential Schemes with Encrypted Attributes
Jorge Guajardo, Bart Mennink, Berry Schoenmakers
CANS2
2010 Security Reductions of the Second Round SHA-3 Candidates
Elena Andreeva 0001, Bart Mennink, Bart Preneel
ISC2
2010 On Side-Channel Resistant Block Cipher Usage
Jorge Guajardo, Bart Mennink
ISC2