Christopher Brzuska

dblp:88/5874 · also Chris Brzuska, Christina Brzuska · DBLP profile ↗
← Back
36ranked-venue papers
21as first author
15since 2021 · last 2026
0009-0001-7485-1217ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 33 · 21 first-author · 14 since 2021Theory of computation · 5 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Simple Attacks Against (Extended) Fiat-Shamir
Christopher Brzuska, Pavel Hubácek, Aleksi Kalsta
PKC (1)1
2026 Threshold Public-Key Encryption: Definitions, Relations, and CPA-to-CCA Transforms
Christopher Brzuska, Michael Klooß, Ivy K. Y. Woo
PKC (4)1
2026 Project Everest: Perspectives from Developing Industrial-Grade High-Assurance Software
abstract
Project Everest began at Microsoft Research in 2016, aiming to spur research in program verification to produce industrial-grade software. In collaboration with INRIA and Carnegie Mellon University, Project Everest’s goal was to produce drop-in verified replacements of secure communications software used in the HTTPS ecosystem, including TLS, the underlying cryptography, and related subprotocols. Now, almost a decade later, we reflect on the project, sharing both its successes and failures, and look ahead to the next decade of program verification research.
Danel Ahman, Karthikeyan Bhargavan, Barry Bond, Jay Bosamiya, Christopher Brzuska, Antoine Delignat-Lavaud, Cédric Fournet, Aymeric Fromherz, Sydney Gibson, Chris Hawblitzel, Catalin Hritcu, Markulf Kohlweiss, Guido Martínez, Haobin Ni, Bryan Parno, Jonathan Protzenko, Tahina Ramananandro, Aseem Rastogi, Exequiel Rivas, Nikhil Swamy, Santiago Zanella-Béguelin
ACM Trans. Program. Lang. Syst.5
2025 Succinct PPRFs via Memory-Tight Reductions
Joël Alwen, Christopher Brzuska, Jérôme Govinden, Patrick Harasser, Stefano Tessaro
CRYPTO (5)2
2025 On Building Fine-Grained One-Way Functions from Strong Average-Case Hardness
abstract
Abstract Constructing one-way functions from average-case hardness is a long-standing open problem. A positive result would exclude Pessiland (Impagliazzo ’95) and establish a highly desirable win–win situation: either (symmetric) cryptography exists unconditionally, or all $$\textsf{NP} $$ NP problems can be solved efficiently on the average. Motivated by the lack of progress on this seemingly very hard question, we initiate the investigation of weaker yet meaningful candidate win–win results of the following type: either there are fine-grained one-way functions (FGOWF), or non-trivial speedups can be obtained for all $$\textsf{NP} $$ NP problems on the average. FGOWFs only require a fixed polynomial gap (as opposed to superpolynomial) between the running time of the function and the running time of an inverter. We obtain three main results: Construction. We show that if there is an $$\textsf{NP} $$ NP language having a very strong form of average-case hardness, which we call block finding hardness, then FGOWF exist. We provide heuristic support for this very strong average-case hardness notion by showing that it holds for a random language. Then, we study whether weaker (and more natural) forms of average-case hardness could already suffice to obtain FGOWF and obtain two negative results: Separation I. We provide a strong oracle separation for the implication ( $$\exists $$ ∃ exponentially average-case hard $$\textsf{NP} $$ NP language $$\implies $$ ⇒ $$\exists $$ ∃ FGOWF). Separation II. We provide a second strong negative result for an even weaker candidate win–win result. Namely, we rule out a relativizing proof for the implication ( $$\exists $$ ∃ exponentially average-case $$\textsf{NP} $$ NP hard language whose hardness amplifies optimally through parallel repetitions $$\implies $$ ⇒ $$\exists $$ ∃ FGOWF). This separation forms the core technical contribution of our work.
Christopher Brzuska, Geoffroy Couteau
J. Cryptol.1
2024 Breaking DPA-Protected Kyber via the Pair-Pointwise Multiplication
Estuardo Alpirez Bock, Gustavo Banegas, Christopher Brzuska, Lukasz Chmielewski, Kirthivaasan Puniamurthy, Milan Sorf
ACNS (2)3
2024 CryptoZoo: A Viewer for Reduction Proofs
Christopher Brzuska, Christoph Egger 0001, Kirthivaasan Puniamurthy
ACNS (1)1
2024 Evasive LWE Assumptions: Definitions, Classes, and Counterexamples
Christopher Brzuska, Akin Ünal, Ivy K. Y. Woo
ASIACRYPT (4)1
2024 On Bounded Storage Key Agreement and One-Way Functions
Christopher Brzuska, Geoffroy Couteau, Christoph Egger 0001, Willy Quach
TCC (1)1
2023 Adaptive Distributional Security for Garbling Schemes with 𝒪(|x|) Online Complexity
Estuardo Alpirez Bock, Christopher Brzuska, Pihla Karanko, Sabine Oechsner, Kirthivaasan Puniamurthy
ASIACRYPT (1)2
2023 A State-Separating Proof for Yao's Garbling Scheme
abstract
Secure multiparty computation enables mutually distrusting parties to compute a public function of their secret inputs. One of the main approaches for designing MPC protocols are garbled circuits whose core component is usually referred to as a garbling scheme. In this work, we revisit the security of Yao's garbling scheme and provide a modular security proof which composes the security of multiple layer garblings to prove security of the full circuit garbling. We perform our security proof in the style of state-separating proofs (ASIACRYPT 2018).
Christopher Brzuska, Sabine Oechsner
CSF1
2022 Key-Schedule Security for the TLS 1.3 Standard
Christopher Brzuska, Antoine Delignat-Lavaud, Christoph Egger 0001, Cédric Fournet, Konrad Kohbrok, Markulf Kohlweiss
ASIACRYPT (1)1
2022 On Building Fine-Grained One-Way Functions from Strong Average-Case Hardness
Christopher Brzuska, Geoffroy Couteau
EUROCRYPT (2)1
2022 Security Analysis of the MLS Key Derivation
abstract
Cryptographic communication protocols provide confidentiality, integrity and authentication properties for end-to-end communication under strong corruption attacks, including, notably, post-compromise security (PCS). Most protocols are designed for one-to-one communication. Protocols for group communication are less common, less efficient, and tend to provide weaker security guarantees. This is because group communication poses unique challenges, such as coordinated key updates, changes to group membership and complex post-compromise recovery procedures. We need to tackle this complex challenge as a community. Thus, the Internet Engineering Task Force (IETF) has created a working group with the goal of developing a sound standard for a continuous asynchronous key-exchange protocol for dynamic groups that is secure and remains efficient for large group sizes. The current version of the Messaging Layer Security (MLS) security protocol is in a feature freeze, i.e., no changes are made in order to provide a stable basis for cryptographic analysis. The key schedule and TreeKEM design are of particular concern since they are crucial to distribute and combine several keys to achieve PCS. In this work, we study the MLS continuous group key derivation (CGKD) which comprises the MLS key schedule, TreeKEM and their composition, as specified in Draft 11 of the MLS RFC, while abstracting away signatures, message flow and authentication guarantees. We establish the uniqueness and key indistinguishability properties of the MLS CGKD as computational security properties.
Christopher Brzuska, Eric Cornelissen, Konrad Kohbrok
SP1
2021 On Derandomizing Yao's Weak-to-Strong OWF Construction
Christopher Brzuska, Geoffroy Couteau, Pihla Karanko, Felix Rohrbach
TCC (2)1
2020 Security Reductions for White-Box Key-Storage in Mobile Payments
Estuardo Alpirez Bock, Christopher Brzuska, Marc Fischlin, Christian Janson, Wil Michiels
ASIACRYPT (1)2
2019 Doubly Half-Injective PRGs for Incompressible White-Box Cryptography
Estuardo Alpirez Bock, Alessandro Amadori, Joppe W. Bos, Christopher Brzuska, Wil Michiels
CT-RSA4
2019 White-Box Cryptography: Don't Forget About Grey-Box Attacks
Estuardo Alpirez Bock, Joppe W. Bos, Christopher Brzuska, Charles Hubain, Wil Michiels, Cristofaro Mune, Eloi Sanfelix Gonzalez, Philippe Teuwen, Alexander Treff
J. Cryptol.3
2018 On the Ineffectiveness of Internal Encodings - Revisiting the DCA Attack on White-Box Cryptography
Estuardo Alpirez Bock, Christopher Brzuska, Wil Michiels, Alexander Treff
ACNS2
2018 State Separation for Code-Based Game-Playing Proofs
Christopher Brzuska, Antoine Delignat-Lavaud, Cédric Fournet, Konrad Kohbrok, Markulf Kohlweiss
ASIACRYPT (3)1
2017 Arithmetic Cryptography
abstract
We study the possibility of computing cryptographic primitives in a fully black-box arithmetic model over a finite field F . In this model, the input to a cryptographic primitive (e.g., encryption scheme) is given as a sequence of field elements, the honest parties are implemented by arithmetic circuits that make only a black-box use of the underlying field, and the adversary has a full (non-black-box) access to the field. This model captures many standard information-theoretic constructions. We prove several positive and negative results in this model for various cryptographic tasks. On the positive side, we show that, under coding-related intractability assumptions, computational primitives like commitment schemes, public-key encryption, oblivious transfer, and general secure two-party computation can be implemented in this model. On the negative side, we prove that garbled circuits, additively homomorphic encryption, and secure computation with low online complexity cannot be achieved in this model. Our results reveal a qualitative difference between the standard Boolean model and the arithmetic model, and explain, in retrospect, some of the limitations of previous constructions.
Benny Applebaum, Jonathan Avron, Christopher Brzuska
J. ACM3
2016 On Statistically Secure Obfuscation with Approximate Correctness
Zvika Brakerski, Christopher Brzuska, Nils Fleischhacker
CRYPTO (2)2
2016 Safely Exporting Keys from Secure Channels - On the Security of EAP-TLS and TLS Key Exporters
Christopher Brzuska, Håkon Jacobsen, Douglas Stebila
EUROCRYPT (1)1
2016 Downgrade Resilience in Key-Exchange Protocols
abstract
Key-exchange protocols such as TLS, SSH, IPsec, and ZRTP are highly configurable, with typical deployments supporting multiple protocol versions, cryptographic algorithms and parameters. In the first messages of the protocol, the peers negotiate one specific combination: the protocol mode, based on their local configurations. With few notable exceptions, most cryptographic analyses of configurable protocols consider a single mode at a time. In contrast, downgrade attacks, where a network adversary forces peers to use a mode weaker than the one they would normally negotiate, are a recurrent problem in practice. How to support configurability while at the same time guaranteeing the preferred mode is negotiated? We set to answer this question by designing a formal framework to study downgrade resilience and its relation to other security properties of key-exchange protocols. First, we study the causes of downgrade attacks by dissecting and classifying known and novel attacks against widely used protocols. Second, we survey what is known about the downgrade resilience of existing standards. Third, we combine these findings to define downgrade security, and analyze the conditions under which several protocols achieve it. Finally, we discuss patterns that guarantee downgrade security by design, and explain how to use them to strengthen the security of existing protocols, including a newly proposed draft of TLS 1.3.
Karthikeyan Bhargavan, Christopher Brzuska, Cédric Fournet, Matthew Green 0001, Markulf Kohlweiss, Santiago Zanella-Béguelin
IEEE Symposium on Security and Privacy2
2015 Arithmetic Cryptography: Extended Abstract
abstract
We study the possibility of computing cryptographic primitives in a fully-black-box arithmetic model over a finite field $\F$. In this model, the input to a cryptographic primitive (e.g., encryption scheme) is given as a sequence of field elements, the honest parties are implemented by arithmetic circuits which make only a black-box use of the underlying field, and the adversary has a full (non-black-box) access to the field. This model captures many standard information-theoretic constructions.
Benny Applebaum, Jonathan Avron, Christopher Brzuska
ITCS3
2015 On Basing Size-Verifiable One-Way Functions on NP-Hardness
Andrej Bogdanov, Christopher Brzuska
TCC (1)2
2015 Random-Oracle Uninstantiability from Indistinguishability Obfuscation
Christopher Brzuska, Pooya Farshim, Arno Mittelbach
TCC (2)1
2014 Using Indistinguishability Obfuscation via UCEs
Christopher Brzuska, Arno Mittelbach
ASIACRYPT (2)1
2014 Indistinguishability Obfuscation versus Multi-bit Point Obfuscation with Auxiliary Input
Christopher Brzuska, Arno Mittelbach
ASIACRYPT (2)1
2014 Indistinguishability Obfuscation and UCEs: The Case of Computationally Unpredictable Sources
Christopher Brzuska, Pooya Farshim, Arno Mittelbach
CRYPTO (1)1
2013 Notions of Black-Box Reductions, Revisited
Paul Baecher, Christopher Brzuska, Marc Fischlin
ASIACRYPT (1)2
2013 Reset Indifferentiability and Its Consequences
Paul Baecher, Christopher Brzuska, Arno Mittelbach
ASIACRYPT (1)2
2013 An analysis of the EMV channel establishment protocol
abstract
With over 1.6 billion debit and credit cards in use worldwide, the EMV system (a.k.a. "Chip-and-PIN") has become one of the most important deployed cryptographic protocol suites. Recently, the EMV consortium has decided to upgrade the existing RSA based system with a new system relying on Elliptic Curve Cryptography (ECC). One of the central components of the new system is a protocol that enables a card to establish a secure channel with a card reader. In this paper we provide a security analysis of the proposed protocol, we propose minor changes/clarifications to the "Request for Comments" issued in Nov 2012, and demonstrate that the resulting protocol meets the intended security goals.
Christopher Brzuska, Nigel P. Smart, Bogdan Warinschi, Gaven J. Watson
CCS1
2011 Composability of bellare-rogaway key exchange protocols
abstract
In this paper we examine composability properties for the fundamental task of key exchange. Roughly speaking, we show that key exchange protocols secure in the prevalent model of Bellare and Rogaway can be composed with arbitrary protocols that require symmetrically distributed keys. This composition theorem holds if the key exchange protocol satisfies an additional technical requirement that our analysis brings to light: it should be possible to determine which sessions derive equal keys given only the publicly available information. What distinguishes our results from virtually all existing work is that we do not rely, neither directly nor indirectly, on the simulation paradigm. Instead, our security notions and composition theorems exclusively use a game-based formalism.We thus avoid several undesirable consequences of simulation-based security notions and support applicability to a broader class of protocols. In particular, we offer an abstract formalization of game-based security that should be of independent interest in other investigations using game-based formalisms.
Christopher Brzuska, Marc Fischlin, Bogdan Warinschi, Stephen C. Williams
CCS1
2011 Physically Uncloneable Functions in the Universal Composition Framework
Christopher Brzuska, Marc Fischlin, Heike Schröder, Stefan Katzenbeisser 0001
CRYPTO1
2010 Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder
ACNS1