Daniel J. Bernstein

dblp:b/DanielJBernstein · DBLP profile ↗
← Back
52ranked-venue papers
44as first author
7since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 50 · 42 first-author · 7 since 2021Theory of computation · 2 · 2 first-author
YearPublicationVenuePosition
2026 Accelerating and verifying constant-time modular inversion
Daniel J. Bernstein, Han-Ting Chen, John Harrison 0001, Cesare Huang, Gregory Maxwell, Bow-Yaw Wang, Pieter Wuille, Bo-Yin Yang
EUROCRYPT (7)1
2025 Higher-Genus McEliece
Daniel J. Bernstein, Tanja Lange 0001, Alex Pellegrini
ASIACRYPT (4)1
2025 PQConnect: Automated Post-Quantum End-to-End Tunnels
Daniel J. Bernstein, Tanja Lange 0001, Jonathan Levin 0002, Bo-Yin Yang
NDSS1
2024 CryptAttackTester: high-assurance attack analysis
Daniel J. Bernstein, Tung Chou
CRYPTO (6)1
2024 Cryptographic Competitions
abstract
Abstract Competitions are widely viewed as the safest way to select cryptographic algorithms. This paper surveys procedures that have been used in cryptographic competitions, and analyzes the extent to which those procedures reduce security risks.
Daniel J. Bernstein
J. Cryptol.1
2022 OpenSSLNTRU: Faster post-quantum TLS key exchange
Daniel J. Bernstein, Billy Bob Brumley, Ming-Shing Chen, Nicola Tuveri
USENIX Security Symposium1
2021 BasicBlocker: ISA Redesign to Make Spectre-Immune CPUs Faster
abstract
Recent research has revealed an ever-growing class of microarchitectural attacks that exploit speculative execution, a standard feature in modern processors. Proposed and deployed countermeasures involve a variety of compiler updates, firmware updates, and hardware updates. None of the deployed countermeasures have convincing security arguments, and many of them have already been broken.
Jan Philipp Thoma, Jakob Feldtkeller, Markus Krausz, Tim Güneysu, Daniel J. Bernstein
RAID5
2020 McTiny: Fast High-Confidence Post-Quantum Key Erasure for Tiny Network Servers
Daniel J. Bernstein, Tanja Lange 0001
USENIX Security Symposium1
2019 Decisional Second-Preimage Resistance: When Does SPR Imply PRE?
Daniel J. Bernstein, Andreas Hülsing
ASIACRYPT (3)1
2019 The SPHINCS+ Signature Framework
abstract
We introduce SPHINCS+, a stateless hash-based signature framework. SPHINCS+ has significant advantages over the state of the art in terms of speed, signature size, and security, and is among the nine remaining signature schemes in the second round of the NIST PQC standardization project. One of our main contributions in this context is a new few-time signature scheme that we call FORS. Our second main contribution is the introduction of tweakable hash functions and a demonstration how they allow for a unified security analysis of hash-based signature schemes. We give a security reduction for SPHINCS+ using this abstraction and derive secure parameters in accordance with the resulting bound. Finally, we present speed results for our optimized implementation of SPHINCS+ and compare to SPHINCS-256, Gravity-SPHINCS, and Picnic.
Daniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, Peter Schwabe
CCS1
2019 Quantum Circuits for the CSIDH: Optimizing Quantum Evaluation of Isogenies
Daniel J. Bernstein, Tanja Lange 0001, Chloe Martindale, Lorenz Panny
EUROCRYPT (2)1
2018 Asymptotically Faster Quantum Algorithms to Solve Multivariate Quadratic Equations
Daniel J. Bernstein, Bo-Yin Yang
PQCrypto1
2017 Sliding Right into Disaster: Left-to-Right Sliding Windows Leak
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange 0001, Christine van Vredendaal, Yuval Yarom
CHES1
2017 Gimli : A Cross-Platform Permutation
Daniel J. Bernstein, Stefan Kölbl, Stefan Lucks, Pedro Maat Costa Massolino, Florian Mendel, Kashif Nawaz, Tobias Schneider 0002, Peter Schwabe, François-Xavier Standaert, Yosuke Todo, Benoît Viguier
CHES1
2017 Short Generators Without Quantum Computers: The Case of Multiquadratics
Jens Bauch, Daniel J. Bernstein, Henry de Valence, Tanja Lange 0001, Christine van Vredendaal
EUROCRYPT (1)2
2017 A Low-Resource Quantum Factoring Algorithm
Daniel J. Bernstein, Jean-François Biasse, Michele Mosca
PQCrypto1
2017 Post-quantum RSA
Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta
PQCrypto1
2017 Low-Communication Parallel Quantum Multi-Target Preimage Search
Gustavo Banegas, Daniel J. Bernstein
SAC2
2017 NTRU Prime: Reducing Attack Surface at Low Cost
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001, Christine van Vredendaal
SAC1
2016 Hash-Function Based PRFs: AMAC and Its Multi-User Security
Mihir Bellare, Daniel J. Bernstein, Stefano Tessaro
EUROCRYPT (1)2
2015 Bad Directions in Cryptographic Hash Functions
Daniel J. Bernstein, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen
ACISP1
2015 SPHINCS: Practical Stateless Hash-Based Signatures
abstract
This paper introduces a high-security post-quantum stateless hash-based signature scheme that signs hundreds of messages per second on a modern 4-core 3.5GHz Intel CPU. Signatures are 41 KB, public keys are 1 KB, and private keys are 1 KB. The signature scheme is designed to provide long-term $$2^{128}$$ security even against attackers equipped with quantum computers. Unlike most hash-based designs, this signature scheme is stateless, allowing it to be a drop-in replacement for current signature schemes.
Daniel J. Bernstein, Daira Hopwood, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen, Louiza Papachristodoulou, Michael Schneider 0002, Peter Schwabe, Zooko Wilcox-O'Hearn
EUROCRYPT (1)1
2014 Kummer Strikes Back: New DH Speed Records
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001, Peter Schwabe
ASIACRYPT (1)1
2014 Curve41417: Karatsuba Revisited
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001
CHES1
2014 Faster Binary-Field Multiplication and Faster Binary-Field MACs
abstract
This paper shows how to securely authenticate messages using just $$29$$ bit operations per authenticated bit, plus a constant overhead per message. The authenticator is a standard type of “universal” hash function providing information-theoretic security; what is new is computing this type of hash function at very high speed. At a lower level, this paper shows how to multiply two elements of a field of size $$2^{128}$$ using just $$9062 \approx 71\,\cdot \, 128$$ bit operations, and how to multiply two elements of a field of size $$2^{256}$$ using just $$22164 \approx 87\,\cdot \, 256$$ bit operations. This performance relies on a new representation of field elements and new FFT-based multiplication techniques. This paper’s constant-time software uses just 1.89 Core 2 cycles per byte to authenticate very long messages. On a Sandy Bridge it takes 1.43 cycles per byte, without using Intel’s PCLMULQDQ polynomial-multiplication hardware. This is much faster than the speed records for constant-time implementations of GHASH without PCLMULQDQ (over 10 cycles/byte), even faster than Intel’s best Sandy Bridge implementation of GHASH with PCLMULQDQ (1.79 cycles/byte), and almost as fast as state-of-the-art 128-bit prime-field MACs using Intel’s integer-multiplication hardware (around 1 cycle/byte).
Daniel J. Bernstein, Tung Chou
Selected Areas in Cryptography1
2014 Batch NFS
Daniel J. Bernstein, Tanja Lange 0001
Selected Areas in Cryptography1
2014 On the Practical Exploitability of Dual EC in TLS Implementations
Stephen Checkoway, Ruben Niederhagen, Adam Everspaugh, Matthew Green 0001, Tanja Lange 0001, Thomas Ristenpart, Daniel J. Bernstein, Jake Maskiewicz, Hovav Shacham, Matt Fredrikson
USENIX Security Symposium7
2013 Factoring RSA Keys from Certified Smart Cards: Coppersmith in the Wild
Daniel J. Bernstein, Yun-An Chang, Chen-Mou Cheng, Li-Ping Chou, Nadia Heninger, Tanja Lange 0001, Nicko van Someren
ASIACRYPT (2)1
2013 Non-uniform Cracks in the Concrete: The Power of Free Precomputation
Daniel J. Bernstein, Tanja Lange 0001
ASIACRYPT (2)1
2013 Elligator: elliptic-curve points indistinguishable from uniform random strings
abstract
Censorship-circumvention tools are in an arms race against censors. The censors study all traffic passing into and out of their controlled sphere, and try to disable censorship-circumvention tools without completely shutting down the Internet. Tools aim to shape their traffic patterns to match unblocked programs, so that simple traffic profiling cannot identify the tools within a reasonable number of traces; the censors respond by deploying firewalls with increasingly sophisticated deep-packet inspection. Cryptography hides patterns in user data but does not evade censorship if the censor can recognize patterns in the cryptography itself. In particular, elliptic-curve cryptography often transmits points on known elliptic curves, and those points are easily distinguishable from uniform random strings of bits.
Daniel J. Bernstein, Michael Hamburg, Anna Krasnova, Tanja Lange 0001
CCS1
2013 MinimaLT: minimal-latency networking through better security
abstract
MinimaLT is a new network protocol that provides ubiquitous encryption for maximal confidentiality, including protecting packet headers. MinimaLT provides server and user authentication, extensive Denial-of-Service protections, privacy-preserving IP mobility, and fast key erasure. We describe the protocol, demonstrate its performance relative to TLS and unencrypted TCP/IP, and analyze its protections, including its resilience against DoS attacks. By exploiting the properties of its cryptographic protections, MinimaLT is able to eliminate three way handshakes and thus create connections faster than unencrypted TCP/IP.
W. Michael Petullo, Jon A. Solworth, Daniel J. Bernstein, Tanja Lange 0001
CCS4
2013 McBits: Fast Constant-Time Code-Based Cryptography
abstract
This paper presents extremely fast algorithms for code-based public-key cryptography, including full protection against timing attacks. For example, at a 2 128 security level, this paper achieves a reciprocal decryption throughput of just 60493 cycles (plus cipher cost etc.) on a single Ivy Bridge core. These algorithms rely on an additive FFT for fast root computation, a transposed additive FFT for fast syndrome computation, and a sorting network to avoid cache-timing attacks.
Daniel J. Bernstein, Tung Chou, Peter Schwabe
CHES1
2013 Quantum Algorithms for the Subset-Sum Problem
Daniel J. Bernstein, Stacey Jeffery, Tanja Lange 0001, Alexander Meurer
PQCrypto1
2013 On the Security of RC4 in TLS
Nadhem J. AlFardan, Daniel J. Bernstein, Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt
USENIX Security Symposium2
2012 NEON Crypto
abstract
NEON is a vector instruction set included in a large fraction of new ARM-based tablets and smartphones. This paper shows that NEON supports high-security cryptography at surprisingly high speeds; normally data arrives at lower speeds, giving the CPU time to handle tasks other than cryptography. In particular, this paper explains how to use a single 800MHz Cortex A8 core to compute the existing NaCl suite of high-security cryptographic primitives at the following speeds: 5.60 cycles per byte (1.14 Gbps) to encrypt using a shared secret key, 2.30 cycles per byte (2.78 Gbps) to authenticate using a shared secret key, 527102 cycles (1517/second) to compute a shared secret key for a new public key, 624846 cycles (1280/second) to verify a signature, and 244655 cycles (3269/second) to sign a message. These speeds make no use of secret branches and no use of secret memory addresses.
Daniel J. Bernstein, Peter Schwabe
CHES1
2011 High-Speed High-Security Signatures
Daniel J. Bernstein, Niels Duif, Tanja Lange 0001, Peter Schwabe, Bo-Yin Yang
CHES1
2011 Smaller Decoding Exponents: Ball-Collision Decoding
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
CRYPTO1
2011 Simplified High-Speed High-Distance List Decoding for Alternant Codes
Daniel J. Bernstein
PQCrypto1
2011 Wild McEliece Incognito
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
PQCrypto1
2010 Grover vs. McEliece
Daniel J. Bernstein
PQCrypto1
2010 Type-II Optimal Polynomial Bases
Daniel J. Bernstein, Tanja Lange 0001
WAIFI1
2009 Batch Binary Edwards
Daniel J. Bernstein
CRYPTO1
2009 ECM on Graphics Cards
Daniel J. Bernstein, Tien-Ren Chen, Chen-Mou Cheng, Tanja Lange 0001, Bo-Yin Yang
EUROCRYPT1
2008 Binary Edwards Curves
Daniel J. Bernstein, Tanja Lange 0001, Reza Rezaeian Farashahi
CHES1
2008 Proving Tight Security for Rabin-Williams Signatures
Daniel J. Bernstein
EUROCRYPT1
2008 Attacking and Defending the McEliece Cryptosystem
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
PQCrypto1
2007 Faster Addition and Doubling on Elliptic Curves
Daniel J. Bernstein, Tanja Lange 0001
ASIACRYPT1
2007 Analysis of QUAD
Bo-Yin Yang, Chia-Hsin Owen Chen, Daniel J. Bernstein, Jiun-Ming Chen
FSE3
2005 Stronger Security Bounds for Wegman-Carter-Shoup Authenticators
Daniel J. Bernstein
EUROCRYPT1
2005 The Poly1305-AES Message-Authentication Code
Daniel J. Bernstein
FSE1
1999 How to Stretch Random Functions: The Security of Protected Counter Sums
Daniel J. Bernstein
J. Cryptol.1
1998 Composing Power Series Over a Finite Ring in Essentially Linear Time
Daniel J. Bernstein
J. Symb. Comput.1