VLDB 2026 Research / reviewers in the wild / expert
Bart Mennink
dblp:50/8321
· DBLP profile ↗
71ranked-venue papers
22as first author
20since 2021 · last 2026
0000-0001-6679-1878ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 67 · 21 first-author · 18 since 2021Theory of computation · 4 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Permutation-Based Hashing with Stronger (Second) Preimage Resistance
Siwei Sun, Shun Li 0004, Zhiyu Zhang 0009, Charlotte Lefevre, Bart Mennink, Dengguo Feng |
CRYPTO (6) | 5 |
| 2026 | How to Build a Short-Input Random Oracle from Public Random Permutations
Ritam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha 0001, Sougata Mandal, Bart Mennink, Hrithik Nandi, Yaobin Shen |
EUROCRYPT | 6 |
| 2025 | Generic Security of GCM-SST
Akiko Inoue, Ashwin Jha 0001, Bart Mennink, Kazuhiko Minematsu |
ACNS (2) | 3 |
| 2025 | A Decomposition Approach for Evaluating Security of Masking
Vahid Jahandideh, Bart Mennink, Lejla Batina |
ASIACRYPT (1) | 2 |
| 2025 | Efficient Instances of Docked Double Decker with AES, and Application to Authenticated Encryption
Christoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander Tereschenko |
EUROCRYPT (1) | 3 |
| 2024 | Generalized Initialization of the Duplex Construction
Christoph Dobraunig, Bart Mennink |
ACNS (2) | 2 |
| 2024 | Generic Security of the Ascon Mode: On the Power of Key Blinding
Charlotte Lefevre, Bart Mennink |
SAC (2) | 2 |
| 2024 | The COLM Authenticated Encryption Scheme
Elena Andreeva 0001, Andrey Bogdanov, Nilanjan Datta, Atul Luykx, Bart Mennink, Mridul Nandi, Elmar Tischhauser, Kan Yasuda |
J. Cryptol. | 5 |
| 2023 | Generic Security of the SAFE API and Its Applications
Dmitry Khovratovich, Mario Marhuenda Beltrán, Bart Mennink |
ASIACRYPT (8) | 3 |
| 2023 | Revisiting the Indifferentiability of the Sum of Permutations
Aldo Gunsing, Ritam Bhaumik, Ashwin Jha 0001, Bart Mennink, Yaobin Shen |
CRYPTO (3) | 4 |
| 2023 | Secure Distributed Modular Exponentiation: Systematic Analysis and New ResultsabstractModular exponentiation is a vital function in public key cryptography. Dozens of protocols, including encryption schemes, signature schemes, pseudorandom functions, and more, perform this operation on a secret base and/or a secret exponent. In a multiparty computation setting, these secret data might be shared over multiple parties who wish to compute this modular exponentiation in a secure and distributed way. However, whereas typical frameworks for secure multiparty computation based on secret sharing provide a basic tool box of secure distributed computation of, most importantly, randomness generation, addition, and multiplication, the status quo of secure distributed modular exponentiation is unsatisfactory. In this work, we provide a complete and comprehensive overview on existing protocols for perfectly secure distributed exponentiation differing depending on whether the inputs and outcomes are public or shared. We perform a detailed complexity computation of the currently existing protocols, observing that earlier authors have overestimated the complexity of their own protocols, and close the remaining open problem: protocols for secure distributed exponentiation with secret base, secret exponent, and public outcome. We prove that the presented protocol is universally composably secure in the presence of malicious adversaries. We finally exemplify the practical relevance of the new protocol by demonstrating how it can be used for pseudorandom generation and signing. Bart Mennink |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Security of Truncated Permutation Without Initial Value
Lorenzo Grassi 0001, Bart Mennink |
ASIACRYPT (2) | 2 |
| 2022 | Leakage and Tamper Resilient Permutation-Based CryptographyabstractImplementation attacks such as power analysis and fault attacks have shown that, if potential attackers have physical access to a cryptographic device, achieving practical security requires more considerations apart from just cryptanalytic security. In recent years, and with the advent of micro-architectural or hardware-oriented attacks, it became more and more clear that similar attack vectors can also be exploited on larger computing platforms and without the requirement of physical proximity of an attacker. While newly discovered attacks typically come with implementation recommendations that help counteract a specific attack vector, the process of constantly patching cryptographic code is quite time consuming in some cases, and simply not possible in other cases. Christoph Dobraunig, Bart Mennink, Robert Primas |
CCS | 2 |
| 2022 | Tight Preimage Resistance of the Sponge Construction
Charlotte Lefevre, Bart Mennink |
CRYPTO (4) | 2 |
| 2022 | HERMES: Scalable, Secure, and Privacy-Enhancing Vehicular Sharing-Access SystemabstractWe propose HERMES, a scalable, secure, and privacy-enhancing system for users to share and access vehicles. HERMES securely outsources operations of vehicle access token (AT) generation to a set of untrusted servers. It builds on an earlier proposal, namely, SePCAR, and extends the system design for improved efficiency and scalability. To cater to system and user needs for secure and private computations, HERMES utilizes and combines several cryptographic primitives with secure multiparty computation (MPC) efficiently. It conceals secret keys of vehicles and transaction details from the servers, including vehicle booking details, AT information, and user and vehicle identities. It also provides user accountability in case of disputes. Besides, we provide semantic security analysis and prove that HERMES meets its security and privacy requirements. Last but not least, we demonstrate that HERMES is efficient and, in contrast to SePCAR, scales to a large number of users and vehicles, making it practical for real-world deployments. We build our evaluations with two different MPC protocols: 1) HtMAC-MiMC and 2) CBC-MAC-AES. Our results demonstrate that HERMES is in the range of milliseconds for generating an AT, whether it operates for a single-vehicle owner or a large rental-company branch with over 1000 vehicles; handling 546 and 84 AT generations per second, respectively. As a result, HERMES is an order of magnitude faster compared to SePCAR. Specifically, it delivers 696 (with HtMAC-MiMC) and 42 (with CBC-MAC-AES) more ATs compared to in SePCAR for a single-vehicle owner AT generation. Furthermore, we show that HERMES is practical on the vehicle side, too, as AT operations performed on a prototype vehicle on-board unit take only$\approx 62 $ms. Iraklis Symeonidis, Dragos Rotaru, Mustafa A. Mustafa, Bart Mennink, Bart Preneel, Panagiotis Papadimitratos |
IEEE Internet Things J. | 4 |
| 2021 | Categorization of Faulty Nonce Misuse Resistant Message Authentication
Yu Long Chen, Bart Mennink, Bart Preneel |
ASIACRYPT (3) | 2 |
| 2021 | Leakage Resilient Value Comparison with Application to Message Authentication
Christoph Dobraunig, Bart Mennink |
EUROCRYPT (2) | 2 |
| 2021 | Multi-user Security of the Elephant v2 Authenticated Encryption Mode
Tim Beyne, Yu Long Chen, Christoph Dobraunig, Bart Mennink |
SAC | 4 |
| 2021 | On the Resilience of Even-Mansour to Invariant PermutationsabstractAbstract Symmetric cryptographic primitives are often exposed to invariances: deterministic relations between plaintexts and ciphertexts that propagate through the primitive. Recent invariant subspace attacks have shown that these can be a serious issue. One way to mitigate invariant subspace attacks is at the primitive level, namely by proper use of round constants (Beierle et al., CRYPTO 2017). In this work, we investigate how to thwart invariance exploitation at the mode level, namely by assuring that a mode never evaluates its underlying primitive under any invariance. We first formalize the use of invariant cryptographic permutations from a security perspective, and analyze the Even-Mansour block cipher construction. We further demonstrate how the model composes, and apply it to the keyed sponge construction. The security analyses exactly pinpoint how the presence of linear invariances affects the bounds compared with analyses in the random permutation model. As such, they give an exact indication how invariances can be exploited. From a practical side, we apply the derived security bounds to the case where the Even-Mansour construction is instantiated with the 512-bit ChaCha permutation, and derive a distinguishing attack against Even-Mansour-ChaCha in $$2^{128}$$ 2 128 queries, faster than the birthday bound. Comparable results are derived for instantiation using the 200-bit Keccak permutation without round constants (attack in $$2^{50}$$ 2 50 queries), the 1024-bit CubeHash permutation (attack in $$2^{256}$$ 2 256 queries), and the 384-bit Gimli permutation without round constants (attack in $$2^{96}$$ 2 96 queries). The attacks do not invalidate the security of the permutations themselves, but rather they demonstrate the tightness of our bounds and confirm that care should be taken when employing a cryptographic primitive that has nontrivial linear invariances. Bart Mennink, Samuel Neves |
Des. Codes Cryptogr. | 1 |
| 2021 | Systematic Security Analysis of Stream Encryption With Key ErasureabstractWe consider a generalized construction of stream ciphers with forward security. The design framework is modular: it is built from a so-called layer function that updates the key and (optionally) the nonce and generates a new pseudorandom output stream. We analyze the generalized construction for four different instantiations: two possible layer functions that are in turn instantiated with either a block cipher or a pseudorandom function. We prove that each of these instantiations gives a stream cipher that is pseudorandom and forward secure in the multi-user setting with a very tight bound. A comprehensive analysis shows that the two block cipher based instantiations achieve very similar bounds. For the pseudorandom function based instantiations there is no clear winner: either layer can be beneficial over the other one, depending on the choice of parameters. By instantiating the pseudorandom function with a generic construction such as the sum of permutations, we obtain a highly efficient and competitive stream cipher based on an n-bit block cipher that is secure beyond the$2^{\text {n}/2}$birthday bound. Yu Long Chen, Atul Luykx, Bart Mennink, Bart Preneel |
IEEE Trans. Inf. Theory | 3 |
| 2020 | Beyond Birthday Bound Secure Fresh Rekeying: Application to Authenticated Encryption
Bart Mennink |
ASIACRYPT (1) | 1 |
| 2020 | The Summation-Truncation Hybrid: Reusing Discarded Bits for Free
Aldo Gunsing, Bart Mennink |
CRYPTO (1) | 2 |
| 2020 | Collapseability of Tree Hashes
Aldo Gunsing, Bart Mennink |
PQCrypto | 2 |
| 2020 | Practical forgeries for ORANGEabstractWe analyze the authenticated encryption algorithm of ORANGE, a submission to the NIST lightweight cryptography standardization process. We show that it is practically possible to craft forgeries out of two observed transmitted messages that encrypt the same plaintext. The authors of ORANGE have confirmed the attack, and they discuss a fix for this attack in their second-round submission of ORANGE to the NIST lightweight cryptography competition. Christoph Dobraunig, Florian Mendel, Bart Mennink |
Inf. Process. Lett. | 3 |
| 2019 | Leakage Resilience of the Duplex Construction
Christoph Dobraunig, Bart Mennink |
ASIACRYPT (3) | 2 |
| 2019 | How to Build Pseudorandom Functions from Public Random Permutations
Yu Long Chen, Eran Lambooij, Bart Mennink |
CRYPTO (1) | 3 |
| 2019 | Linking Stam's Bounds with Generalized Truncation
Bart Mennink |
CT-RSA | 1 |
| 2019 | Beyond Conventional Security in Sponge-Based Authenticated Encryption ModesabstractThe Sponge function is known to achieve $$2^{c/2}$$ security, where c is its capacity. This bound was carried over to its keyed variants, such as SpongeWrap, to achieve a $$\min \{2^{c/2},2^\kappa \}$$ security bound, with $$\kappa $$ the key length. Similarly, many CAESAR competition submissions were designed to comply with the classical $$2^{c/2}$$ security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of $$\min \{2^{b/2},2^c,2^\kappa \}$$ , with $$b>c$$ the permutation size, by proving that the CAESAR submission NORX achieves this bound. The proof relies on rigorous computation of multi-collision probabilities, which may be of independent interest. We additionally derive a generic attack based on multi-collisions that matches the bound. We show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of some of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. We finally consider the remaining one of the three PRIMATEs, APE, and derive a blockwise adaptive attack in the nonce-respecting setting with complexity $$2^{c/2}$$ , therewith demonstrating that the techniques cannot be applied to APE. Philipp Jovanovic, Atul Luykx, Bart Mennink, Yu Sasaki 0001, Kan Yasuda |
J. Cryptol. | 3 |
| 2018 | Short Variable Length Domain Extenders with Beyond Birthday Bound Security
Yu Long Chen, Bart Mennink, Mridul Nandi |
ASIACRYPT (1) | 2 |
| 2018 | The Relation Between CENC and NEMO
Bart Mennink |
CANS | 1 |
| 2018 | Towards Tight Security of Cascaded LRW2
Bart Mennink |
TCC (2) | 1 |
| 2018 | Connecting tweakable and multi-key blockcipher securityabstractThe significance of understanding blockcipher security in the multi-key setting is highlighted by the extensive literature on attacks, and how effective key size can be significantly reduced. Nevertheless, little attention has been paid in formally understanding the design of multi-key secure blockciphers. In this work, we formalize the multi-key security of tweakable blockciphers in case of general key derivation functions. We show an equivalence between blockcipher multi-key security and tweakable blockcipher security. Our equivalence connects two objects of study, the iterated Even–Mansour (EUROCRYPT 2012) and the iterated Tweakable Even–Mansour (CRYPTO 2015), which establishes that results in both areas are, to a certain extent, transferable. Using our novel equivalence relation, we derive new bounds for both constructions, pave the path towards the solution of two well-studied conjectures, and show that, contrary to common knowledge, key derivation functions need not necessarily be pseudorandom functions in order to provide security: for the iterated Even–Mansour universal hash functions suffice. Jooyoung Lee 0001, Atul Luykx, Bart Mennink, Kazuhiko Minematsu |
Des. Codes Cryptogr. | 3 |
| 2017 | Full-State Keyed Duplex with Built-In Multi-user Support
Joan Daemen, Bart Mennink, Gilles Van Assche |
ASIACRYPT (2) | 2 |
| 2017 | Analyzing Multi-key Security Degradation
Atul Luykx, Bart Mennink, Kenneth G. Paterson |
ASIACRYPT (2) | 2 |
| 2017 | Insuperability of the Standard Versus Ideal Model Gap for Tweakable Blockcipher Security
Bart Mennink |
CRYPTO (2) | 1 |
| 2017 | Encrypted Davies-Meyer and Its Dual: Towards Optimal Security Using Mirror Theory
Bart Mennink, Samuel Neves |
CRYPTO (3) | 1 |
| 2017 | Weak Keys for AEZ, and the External Key Padding Attack
Bart Mennink |
CT-RSA | 1 |
| 2017 | SePCAR: A Secure and Privacy-Enhancing Protocol for Car Access Provision
Iraklis Symeonidis, Abdelrahaman Aly, Mustafa A. Mustafa, Bart Mennink, Siemen Dhooghe, Bart Preneel |
ESORICS (2) | 4 |
| 2017 | XOR of PRPs in a Quantum World
Bart Mennink, Alan Szepieniec |
PQCrypto | 1 |
| 2017 | Optimal collision security in double block length hashing with single length key
Bart Mennink |
Des. Codes Cryptogr. | 1 |
| 2016 | Improving the Sphinx Mix Network
Filipe Beato, Kimmo Halunen, Bart Mennink |
CANS | 3 |
| 2016 | XPX: Generalized Tweakable Even-Mansour with Improved Security Guarantees
Bart Mennink |
CRYPTO (1) | 1 |
| 2016 | Improved Masking for Tweakable Blockciphers with Applications to Authenticated Encryption
Robert Granger, Philipp Jovanovic, Bart Mennink, Samuel Neves |
EUROCRYPT (1) | 3 |
| 2016 | Damaging, Simplifying, and Salvaging p-OMD
Tomer Ashur, Bart Mennink |
ISC | 2 |
| 2015 | On the XOR of Multiple Random Permutations
Bart Mennink, Bart Preneel |
ACNS | 1 |
| 2015 | On the Impact of Known-Key Attacks on Hash Functions
Bart Mennink, Bart Preneel |
ASIACRYPT (2) | 1 |
| 2015 | Security of Full-State Keyed Sponge and Duplex: Applications to Authenticated Encryption
Bart Mennink, Reza Reyhanitabar, Damian Vizár |
ASIACRYPT (2) | 1 |
| 2015 | Security of Keyed Sponge Constructions Using a Modular Proof Approach
Elena Andreeva 0001, Joan Daemen, Bart Mennink, Gilles Van Assche |
FSE | 3 |
| 2015 | Optimally Secure Tweakable Blockciphers
Bart Mennink |
FSE | 1 |
| 2015 | Forgery and Subkey Recovery on CAESAR Candidate iFeed
Willem Schroé, Bart Mennink, Elena Andreeva 0001, Bart Preneel |
SAC | 2 |
| 2015 | Open problems in hash function security
Elena Andreeva 0001, Bart Mennink, Bart Preneel |
Des. Codes Cryptogr. | 2 |
| 2014 | How to Securely Release Unverified Plaintext in Authenticated Encryption
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda |
ASIACRYPT (1) | 4 |
| 2014 | Beyond 2 c/2 Security in Sponge-Based Authenticated Encryption Modes
Philipp Jovanovic, Atul Luykx, Bart Mennink |
ASIACRYPT (1) | 3 |
| 2014 | Breaking and Fixing Cryptophia's Short Combiner
Bart Mennink, Bart Preneel |
CANS | 1 |
| 2014 | The Security of Multiple Encryption in the Ideal Cipher Model
Yuanxi Dai, Jooyoung Lee 0001, Bart Mennink, John P. Steinberger |
CRYPTO (1) | 3 |
| 2014 | APE: Authenticated Permutation-Based Encryption for Lightweight Cryptography
Elena Andreeva 0001, Begül Bilgin, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda |
FSE | 5 |
| 2014 | COBRA: A Parallelizable Authenticated Online Cipher Without Block Cipher Inverse
Elena Andreeva 0001, Atul Luykx, Bart Mennink, Kan Yasuda |
FSE | 3 |
| 2014 | Chaskey: An Efficient MAC Algorithm for 32-bit Microcontrollers
Nicky Mouha, Bart Mennink, Anthony Van Herrewege, Dai Watanabe, Bart Preneel, Ingrid Verbauwhede |
Selected Areas in Cryptography | 2 |
| 2014 | On the collision and preimage security of MDC-4 in the ideal cipher model
Bart Mennink |
Des. Codes Cryptogr. | 1 |
| 2013 | Parallelizable and Authenticated Online Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan Yasuda |
ASIACRYPT (1) | 4 |
| 2013 | On the Indifferentiability of Key-Alternating Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Yevgeniy Dodis, Bart Mennink, John P. Steinberger |
CRYPTO (1) | 4 |
| 2013 | Towards Understanding the Known-Key Security of Block Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Bart Mennink |
FSE | 3 |
| 2013 | Indifferentiability of Double Length Compression Functions
Bart Mennink |
IMACC | 1 |
| 2012 | Optimal Collision Security in Double Block Length Hashing with Single Length Key
Bart Mennink |
ASIACRYPT | 1 |
| 2012 | A Simple Key-Recovery Attack on McOE-X
Florian Mendel, Bart Mennink, Vincent Rijmen, Elmar Tischhauser |
CANS | 2 |
| 2012 | Hash Functions Based on Three Permutations: A Generic Security Analysis
Bart Mennink, Bart Preneel |
CRYPTO | 1 |
| 2012 | Provable Security of BLAKE with Non-ideal Compression Function
Elena Andreeva 0001, Atul Luykx, Bart Mennink |
Selected Areas in Cryptography | 3 |
| 2012 | Increasing the flexibility of the herding attack
Bart Mennink |
Inf. Process. Lett. | 1 |
| 2010 | Anonymous Credential Schemes with Encrypted Attributes
Jorge Guajardo, Bart Mennink, Berry Schoenmakers |
CANS | 2 |
| 2010 | Security Reductions of the Second Round SHA-3 Candidates
Elena Andreeva 0001, Bart Mennink, Bart Preneel |
ISC | 2 |
| 2010 | On Side-Channel Resistant Block Cipher Usage
Jorge Guajardo, Bart Mennink |
ISC | 2 |