Marcus Brinkmann

dblp:76/6564 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-5649-6357ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 3 first-author · 7 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Halfspace Learning for Lattice Signature Key Recovery from Signs
Marcus Brinkmann, Nicolai Kraus, Alexander May 0001
CRYPTO (3)1
2025 Finding SSH Strict Key Exchange Violations by State Learning
abstract
SSH is an important protocol for secure remote shell access to servers on the Internet. At USENIX 2024, Bäumer et al. presented the Terrapin attack on SSH, which relies on the attacker injecting optional messages during the key exchange. To mitigate this attack, SSH vendors adopted an extension developed by OpenSSH called strict key exchange (''strict KEX''). With strict KEX, optional messages are forbidden during the handshake, preventing the attack. In practice, this should simplify the state machine of an SSH handshake to a linear message flow similar to that of TLS. In this work, we analyze the design, implementation, and security of strict KEX in popular SSH servers, using black-box state learning, which can uncover the hidden state machine of an implementation. In practice, it is limited by the number of learned messages and the complexity of the state machine. Thus, learning the complete state machine of SSH is infeasible. Previous research on SSH, therefore, excluded optional messages, learning only a partial state machine. However, these messages are a critical part of the Terrapin attack. We propose to instead learn the complete state machine of the handshake phase of an SSH server, but with strict KEX enabled. We investigate the security of ten SSH implementations supporting strict KEX for up to five key exchange algorithms. In total, we learn 33 state machines, revealing significant differences in the implementations. We show that seven implementations violate the strict KEX specification and find two critical security vulnerabilities. One results in a rogue session attack in the proprietary Tectia SSH implementation. Another affects the official SSH implementation of the Erlang Open Telecom Platform, and enables unauthenticated remote code execution in the security context of the SSH server.
Fabian Bäumer 0001, Marcel Maehren, Marcus Brinkmann, Jörg Schwenk
CCS3
2025 On the Security of SSH Client Signatures
abstract
Administrators and developers use SSH client keys and signatures for authentication, for example, to access internet backbone servers or to commit new code on platforms like GitHub. However, unlike servers, SSH clients cannot be measured through internet scans. We close this gap in two steps. First, we collect SSH client public keys. Such keys are regularly published by their owners on open development platforms like GitHub and GitLab. We systematize previous non-academic work by subjecting these keys to various security tests in a longitudinal study. Second, in a series of black-box lab experiments, we analyze the implementations of algorithms for SSH client signatures in 24 popular SSH clients for Linux, Windows, and macOS. We extracted 31,622,338 keys from three public sources in two scans. Compared to previous work, we see a clear tendency to abandon RSA signatures in favor of EdDSA signatures. Still, in January 2025, we found 98 broken short keys, 139 keys generated from weak randomness, and 149 keys with common or small factors—the large majority of the retrieved keys exposed no weakness. Weak randomness can not only compromise a secret key through its public key, but also through signatures. It is well-known that a bias in random nonces in ECDSA can reveal the secret key through public signatures. For the first time, we show that the use of deterministic nonces in ECDSA can also be dangerous: The private signing key of a PuTTY client can be recovered from just 58 valid signatures if ECDSA with NIST curve P-521 is used. PuTTY acknowledged our finding in CVE-2024-31497, and they subsequently replaced the nonce generation algorithm.
Fabian Bäumer 0001, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk, Juraj Somorovsky
CCS2
2024 Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation
Fabian Bäumer 0001, Marcus Brinkmann, Jörg Schwenk
USENIX Security Symposium2
2023 Isolated and Exhausted: Attacking Operating Systems via Site Isolation in the Browser
Matthias Gierlings, Marcus Brinkmann, Jörg Schwenk
USENIX Security Symposium2
2021 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Marcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Jörg Schwenk, Sebastian Schinzel
USENIX Security Symposium1
2021 Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)
Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky, Johannes Mittmann, Jörg Schwenk
USENIX Security Symposium2
2021 Linearly Self-Equivalent APN Permutations in Small Dimension
abstract
All almost perfect nonlinear (APN) permutations that we know to date admit a special kind of linear self-equivalence, i.e., there exists a permutation G in their CCZ-equivalence class and two linear permutations A and B, such that G °A = B °G. After providing a survey on the known APN functions with a focus on the existence of self-equivalences, we search for APN permutations in dimension 6, 7, and 8 that admit such a linear self-equivalence. In dimension six, we were able to conduct an exhaustive search and obtain that there is only one such APN permutation up to CCZ-equivalence. In dimensions 7 and 8, we performed an exhaustive search for all but a few classes of linear self-equivalences and we did not find any new APN permutation. As one interesting result in dimension 7, we obtain that all APN permutation polynomials with coefficients in \mathbb F2must be (up to CCZ-equivalence) monomial functions.
Christof Beierle, Marcus Brinkmann, Gregor Leander
IEEE Trans. Inf. Theory2
2020 Mitigation of Attacks on Email End-to-End Encryption
abstract
OpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem.
Jörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Sebastian Schinzel
CCS2
2019 Re: What's Up Johnny? - Covert Content Attacks on Email End-to-End Encryption
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel, Jörg Schwenk
ACNS2
2019 "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in Emails
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Hanno Böck, Sebastian Schinzel, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium2
2008 On the classification of APN functions up to dimension five
Marcus Brinkmann, Gregor Leander
Des. Codes Cryptogr.1