Eike Kiltz

dblp:k/EikeKiltz · DBLP profile ↗
← Back
94ranked-venue papers
29as first author
14since 2021 · last 2026
0000-0003-1178-048XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 85 · 22 first-author · 14 since 2021Theory of computation · 20 · 10 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 A Closer Look at Falcon
Pierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck, Eike Kiltz
EUROCRYPT (4)5
2024 Ring Signatures for Deniable AKEM: Gandalf's Fellowship
Phillip Gajland, Jonas Janneck, Eike Kiltz
CRYPTO (1)3
2023 The Pre-Shared Key Modes of HPKE
Joël Alwen, Jonas Janneck, Eike Kiltz, Benjamin Lipp 0001
ASIACRYPT (6)3
2023 Post-Quantum Multi-Recipient Public Key Encryption
abstract
A multi-message multi-recipient PKE (mmPKE) encrypts a batch of messages, in one go, to a corresponding set of independently chosen receiver public keys. The resulting ''multi-recipient ciphertext'' can be then be reduced (by any 3rd party) to a shorter, receiver specific, ''invidual ciphertext.'' Finally, to recover the i-th message in the batch from their indvidual ciphertext the i-th receiver only needs their own decryption key. A special case of mmPKE is multi-recipient PKE (mPKE) where all receivers are sent the same message. By treating (m)mPKE and their KEM counterparts as a stand-alone primitives we allow for more efficient constructions than trivially composing individual PKE/KEM instances. This is especially valuable in the post-quantum setting, where PKE/KEM ciphertexts and public keys tend to be far larger than their classic counterparts.
Joël Alwen, Dominik Hartmann, Eike Kiltz, Marta Mularczyk, Peter Schwabe
CCS3
2023 Multi-user CDH Problems and the Concrete Security of NAXOS and HMQV
Eike Kiltz, Jiaxin Pan 0001, Doreen Riepel, Magnus Ringerud
CT-RSA1
2023 Limits in the Provable Security of ECDSA Signatures
Dominik Hartmann, Eike Kiltz
TCC (4)2
2022 Group Action Key Encapsulation and Non-Interactive Key Exchange in the QROM
Julien Duman, Dominik Hartmann, Eike Kiltz, Sabrina Kunzweiler, Jonas Meers, Doreen Riepel
ASIACRYPT (2)3
2022 Server-Aided Continuous Group Key Agreement
abstract
Continuous Group Key Agreement (CGKA) -- or Group Ratcheting -- lies at the heart of a new generation of scalable End-to-End secure (E2E) cryptographic multi-party applications. One of the most important (and first deployed) CGKAs is ITK which underpins the IETF's upcoming Messaging Layer Security E2E secure group messaging standard. To scale beyond the group sizes possible with earlier E2E protocols, a central focus of CGKA protocol design is to minimize bandwidth requirements (i.e. communication complexity).
Joël Alwen, Dominik Hartmann, Eike Kiltz, Marta Mularczyk
CCS3
2022 Password-Authenticated Key Exchange from Group Actions
Michel Abdalla, Thorsten Eisenhofer, Eike Kiltz, Sabrina Kunzweiler, Doreen Riepel
CRYPTO (2)3
2021 Faster Lattice-Based KEMs via a Generic Fujisaki-Okamoto Transform Using Prefix Hashing
abstract
Constructing an efficient CCA-secure KEM is generally done by first constructing a passively-secure PKE scheme, and then applying the Fujisaki-Okamoto (FO) transformation. The original FO transformation was designed to offer security in a single user setting. A stronger notion, known as multi-user security, considers the attacker's advantage in breaking one of many user's ciphertexts. Bellare et al. (EUROCRYPT 2000) showed that standard single user security implies multi-user security with a multiplicative tightness gap equivalent to the number of users.
Julien Duman, Kathrin Hövelmanns, Eike Kiltz, Vadim Lyubashevsky, Gregor Seiler
CCS3
2021 Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Shuai Han 0001, Tibor Jager, Eike Kiltz, Shengli Liu 0001, Jiaxin Pan 0001, Doreen Riepel, Sven Schäge
CRYPTO (4)3
2021 Analysing the HPKE Standard
Joël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz, Benjamin Lipp 0001, Doreen Riepel
EUROCRYPT (1)4
2021 Tightly-Secure Authenticated Key Exchange, Revisited
Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge
EUROCRYPT (1)2
2021 On the Impossibility of Purely Algebraic Signatures
Nico Döttling, Dominik Hartmann, Dennis Hofheinz, Eike Kiltz, Sven Schäge, Bogdan Ursu
TCC (3)4
2020 Lattice-Based Blind Signatures, Revisited
Eduard Hauck, Eike Kiltz, Julian Loss, Ngoc Khanh Nguyen 0001
CRYPTO (2)2
2020 Everybody's a Target: Scalability in Public-Key Encryption
Benedikt Auerbach, Federico Giacon, Eike Kiltz
EUROCRYPT (3)3
2019 Lossy Trapdoor Permutations with Improved Lossiness
Benedikt Auerbach, Eike Kiltz, Bertram Poettering, Stefan Schoenen
CT-RSA2
2019 A Modular Treatment of Blind Signatures from Identification Schemes
Eduard Hauck, Eike Kiltz, Julian Loss
EUROCRYPT (3)2
2019 On the Security of Two-Round Multi-Signatures
abstract
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a single signature that convinces a verifier that every individual signer approved the message. The increased interest in technologies to decentralize trust has triggered the proposal of highly efficient two-round Schnorr-based multi-signature schemes designed to scale up to thousands of signers, namely BCJ by Bagherzandi et al. (CCS 2008), MWLD by Ma et al. (DCC 2010), CoSi by Syta et al. (S&P 2016), and MuSig by Maxwell et al. (ePrint 2018). In this work, we point out serious security issues in all currently known two-round multi-signature schemes (without pairings). First, we prove that none of the schemes can be proved secure without radically departing from currently known techniques. Namely, we show that if the one-more discrete-logarithm problem is hard, then no algebraic reduction exists that proves any of these schemes secure under the discrete-logarithm or one-more discrete-logarithm problem. We point out subtle flaws in the published security proofs of the above schemes (except CoSi, which was not proved secure) to clarify the contradiction between our result and the existing proofs. Next, we describe practical sub-exponential attacks on all schemes, providing further evidence to their insecurity. Being left without two-round multi-signature schemes, we present mBCJ, a variant of the BCJ scheme that we prove secure under the discrete-logarithm assumption in the random-oracle model. Our experiments show that mBCJ barely affects scalability compared to CoSi, allowing 16384 signers to collaboratively sign a message in about 2 seconds, making it a highly practical and provably secure alternative for large-scale deployments.
Manu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz, Julian Loss, Gregory Neven, Igors Stepanovs
IEEE Symposium on Security and Privacy4
2018 The Algebraic Group Model and its Applications
Georg Fuchsbauer, Eike Kiltz, Julian Loss
CRYPTO (2)2
2018 A Concrete Treatment of Fiat-Shamir Signatures in the Quantum Random-Oracle Model
Eike Kiltz, Vadim Lyubashevsky, Christian Schaffner
EUROCRYPT (3)1
2018 CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM
abstract
Rapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security.
Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé
EuroS&P3
2018 Optimal Security Proofs for Full Domain Hash, Revisited
Saqib A. Kakvi, Eike Kiltz
J. Cryptol.2
2017 Tightly-Secure Signatures from Five-Move Identification Protocols
Eike Kiltz, Julian Loss, Jiaxin Pan 0001
ASIACRYPT (3)1
2017 Memory-Tight Reductions
Benedikt Auerbach, David Cash, Manuel Fersch, Eike Kiltz
CRYPTO (1)4
2017 On the One-Per-Message Unforgeability of (EC)DSA and Its Variants
Manuel Fersch, Eike Kiltz, Bertram Poettering
TCC (2)2
2017 A Modular Analysis of the Fujisaki-Okamoto Transformation
Dennis Hofheinz, Kathrin Hövelmanns, Eike Kiltz
TCC (1)3
2017 An Algebraic Framework for Diffie-Hellman Assumptions
Alex Escala, Gottfried Herold, Eike Kiltz, Carla Ràfols, Jorge Luis Villar
J. Cryptol.3
2017 Instantiability of RSA-OAEP Under Chosen-Plaintext Attack
Eike Kiltz, Adam O'Neill, Adam D. Smith 0001
J. Cryptol.1
2017 Efficient Authentication from Hard Learning Problems
Eike Kiltz, Krzysztof Pietrzak, Daniele Venturi 0001, David Cash, Abhishek Jain 0002
J. Cryptol.1
2016 On the Provable Security of (EC)DSA Signatures
abstract
Among the signature schemes most widely deployed in practice are the DSA (Digital Signature Algorithm) and its elliptic curves variant ECDSA. They are represented in many international standards, including IEEE P1363, ANSI X9.62, and FIPS 186-4. Their popularity stands in stark contrast to the absence of rigorous security analyses: Previous works either study modified versions of (EC)DSA or provide a security analysis of unmodified ECDSA in the generic group model. Unfortunately, works following the latter approach assume abstractions of non-algebraic functions over generic groups for which it remains unclear how they translate to the security of ECDSA in practice. For instance, it has been pointed out that prior results in the generic group model actually establish strong unforgeability of ECDSA, a property that the scheme de facto does not possess. As, further, no formal results are known for DSA, understanding the security of both schemes remains an open problem. In this work we propose GenericDSA, a signature framework that subsumes both DSA and ECDSA in unmodified form. It carefully models the "modulo q" conversion function of (EC)DSA as a composition of three independent functions. The two outer functions mimic algebraic properties in the function's domain and range, the inner one is modeled as a bijective random oracle. We rigorously prove results on the security of GenericDSA that indicate that forging signatures in (EC)DSA is as hard as solving discrete logarithms. Importantly, our proofs do not assume generic group behavior.
Manuel Fersch, Eike Kiltz, Bertram Poettering
CCS2
2016 Optimal Security Proofs for Signatures from Identification Schemes
Eike Kiltz, Daniel Masny, Jiaxin Pan 0001
CRYPTO (2)1
2016 Tightly CCA-Secure Encryption Without Pairings
Romain Gay, Dennis Hofheinz, Eike Kiltz, Hoeteck Wee
EUROCRYPT (1)3
2016 Selective opening security of practical public-key encryption schemes
abstract
The authors show that two well‐known and widely employed public‐key encryption schemes – RSA optimal asymmetric encryption padding (RSA‐OAEP) and Diffie–Hellman integrated encryption scheme (DHIES), instantiated with a one‐time pad, – are secure under (the strong, simulation‐based security notion of) selective opening security against chosen‐ciphertext attacks in the random oracle model. Both schemes are obtained via known generic transformations that transform relatively weak primitives (with security in the sense of one‐wayness) to indistinguishability (IND)‐CCA secure encryption schemes. The authors also show a similar result for the well‐known Fujisaki–Okamoto transformation that can generically turn a one‐way secure public key encryption system and a one‐time pad into a IND‐CCA‐secure public‐key encryption system. The authors prove that selective opening security comes for free in these transformations. Both DHIES and RSA‐OAEP are important building blocks in several standards for public key encryption and key exchange protocols. The Fujisaki–Okamoto transformation is very versatile and has successfully been utilised to build efficient lattice‐based cryptosystems. The considered schemes are the first practical cryptosystems that meet the strong notion of simulation‐based selective opening ( SIM‐SO‐CCA ) security.
Felix Heuer, Tibor Jager, Sven Schäge, Eike Kiltz
IET Inf. Secur.4
2015 Structure-Preserving Signatures from Standard Assumptions, Revisited
Eike Kiltz, Jiaxin Pan 0001, Hoeteck Wee
CRYPTO (2)1
2015 Quasi-Adaptive NIZK for Linear Subspaces Revisited
Eike Kiltz, Hoeteck Wee
EUROCRYPT (2)1
2015 Tightly-Secure Authenticated Key Exchange
Christoph Bader, Dennis Hofheinz, Tibor Jager, Eike Kiltz, Yong Li 0021
TCC (1)4
2015 Subtleties in the Definition of IND-CCA: When and How Should Challenge Decryption Be Disallowed?
Mihir Bellare, Dennis Hofheinz, Eike Kiltz
J. Cryptol.3
2014 (Hierarchical) Identity-Based Encryption from Affine Message Authentication
Olivier Blazy, Eike Kiltz, Jiaxin Pan 0001
CRYPTO (1)2
2013 An Algebraic Framework for Diffie-Hellman Assumptions
Alex Escala, Gottfried Herold, Eike Kiltz, Carla Ràfols, Jorge Luis Villar
CRYPTO (2)3
2013 Digital Signatures with Minimal Overhead from Indifferentiable Random Invertible Functions
Eike Kiltz, Krzysztof Pietrzak, Mario Szegedy
CRYPTO (1)1
2013 More Constructions of Lossy and Correlation-Secure Trapdoor Functions
David Mandell Freeman, Oded Goldreich 0001, Eike Kiltz, Alon Rosen, Gil Segev 0001
J. Cryptol.3
2013 Practical Chosen Ciphertext Secure Encryption from Factoring
Dennis Hofheinz, Eike Kiltz, Victor Shoup
J. Cryptol.2
2012 Certifying RSA
Saqib A. Kakvi, Eike Kiltz, Alexander May 0001
ASIACRYPT2
2012 Identity-Based (Lossy) Trapdoor Functions and Applications
Mihir Bellare, Eike Kiltz, Chris Peikert, Brent Waters
EUROCRYPT2
2012 Message Authentication, Revisited
Yevgeniy Dodis, Eike Kiltz, Krzysztof Pietrzak, Daniel Wichs
EUROCRYPT2
2012 Optimal Security Proofs for Full Domain Hash, Revisited
Saqib A. Kakvi, Eike Kiltz
EUROCRYPT2
2012 Lapin: An Efficient Authentication Protocol Based on Ring-LPN
Stefan Heyse, Eike Kiltz, Vadim Lyubashevsky, Christof Paar, Krzysztof Pietrzak
FSE2
2012 Bonsai Trees, or How to Delegate a Lattice Basis
David Cash, Dennis Hofheinz, Eike Kiltz, Chris Peikert
J. Cryptol.3
2012 Programmable Hash Functions and Their Applications
Dennis Hofheinz, Eike Kiltz
J. Cryptol.2
2011 Short Signatures from Weaker Assumptions
Dennis Hofheinz, Tibor Jager, Eike Kiltz
ASIACRYPT3
2011 Efficient Authentication from Hard Learning Problems
Eike Kiltz, Krzysztof Pietrzak, David Cash, Abhishek Jain 0002, Daniele Venturi 0001
EUROCRYPT1
2010 Leakage Resilient ElGamal Encryption
Eike Kiltz, Krzysztof Pietrzak
ASIACRYPT1
2010 Instantiability of RSA-OAEP under Chosen-Plaintext Attack
Eike Kiltz, Adam O'Neill, Adam D. Smith 0001
CRYPTO1
2010 Bonsai Trees, or How to Delegate a Lattice Basis
David Cash, Dennis Hofheinz, Eike Kiltz, Chris Peikert
EUROCRYPT3
2010 Encryption Schemes Secure against Chosen-Ciphertext Selective Opening Attacks
Serge Fehr, Dennis Hofheinz, Eike Kiltz, Hoeteck Wee
EUROCRYPT3
2010 Adaptive Trapdoor Functions and Chosen-Ciphertext Security
Eike Kiltz, Payman Mohassel, Adam O'Neill
EUROCRYPT1
2010 Cryptographic Protocols from Lattices
Eike Kiltz
ProvSec1
2010 A Twist on the Naor-Yung Paradigm and Its Application to Efficient CCA-Secure Encryption from Hard Search Problems
Ronald Cramer, Dennis Hofheinz, Eike Kiltz
TCC3
2010 Leakage-Resilient Signatures
Sebastian Faust, Eike Kiltz, Krzysztof Pietrzak, Guy N. Rothblum
TCC2
2010 Efficient hybrid encryption from ID-based encryption
Masayuki Abe, Yang Cui 0001, Hideki Imai, Eike Kiltz
Des. Codes Cryptogr.4
2010 Some (in)sufficient conditions for secure hybrid encryption
Javier Herranz, Dennis Hofheinz, Eike Kiltz
Inf. Comput.3
2009 The Group of Signed Quadratic Residues and Applications
Dennis Hofheinz, Eike Kiltz
CRYPTO2
2009 Practical Chosen Ciphertext Secure Encryption from Factoring
Dennis Hofheinz, Eike Kiltz
EUROCRYPT2
2009 On the Security of Padding-Based Encryption Schemes - or - Why We Cannot Prove OAEP Secure in the Standard Model
Eike Kiltz, Krzysztof Pietrzak
EUROCRYPT1
2009 A New Randomness Extraction Paradigm for Hybrid Encryption
Eike Kiltz, Krzysztof Pietrzak, Martijn Stam, Moti Yung
EUROCRYPT1
2009 The Kurosawa-Desmedt key encapsulation is not chosen-ciphertext secure
Seung Geol Choi, Javier Herranz, Dennis Hofheinz, Jung Yeon Hwang, Eike Kiltz, Dong Hoon Lee 0001, Moti Yung
Inf. Process. Lett.5
2009 The Twin Diffie-Hellman Problem and Applications
David Cash, Eike Kiltz, Victor Shoup
J. Cryptol.2
2009 Direct chosen-ciphertext secure identity-based key encapsulation without random oracles
Eike Kiltz, David Galindo
Theor. Comput. Sci.1
2008 Chosen Ciphertext Security with Optimal Ciphertext Overhead
Masayuki Abe, Eike Kiltz, Tatsuaki Okamoto
ASIACRYPT2
2008 Programmable Hash Functions and Their Applications
Dennis Hofheinz, Eike Kiltz
CRYPTO2
2008 Public-Key Encryption with Non-interactive Opening
Ivan Damgård, Dennis Hofheinz, Eike Kiltz, Rune Thorbek
CT-RSA3
2008 CCA2 Secure IBE: Standard Model Efficiency through Authenticated Symmetric Encryption
Eike Kiltz, Yevgeniy Vahlis
CT-RSA1
2008 The Twin Diffie-Hellman Problem and Applications
David Cash, Eike Kiltz, Victor Shoup
EUROCRYPT2
2008 Generalised key delegation for hierarchical identity-based encryption
abstract
The authors introduce a new primitive called identity-based encryption with wildcard key derivation (WKD-IBE or ‘wicked IBE’) that enhances the concept of hierarchical identity-based encryption by allowing more general key delegation patterns. A secret key is derived for a vector of identity strings, where entries can be left blank using a wildcard. This key can then be used to derive keys for any pattern that replaces wildcards with concrete identity strings. For example, one may want to allow the university's head system administrator to derive secret keys (and hence the ability to decrypt) for all departmental sysadmin email addresses sysadmin@*.univ.edu, where * is a wildcard that can be replaced with any string. The authors provide appropriate security notions and provably secure instantiations with different tradeoffs in terms of ciphertext size and efficiency. The authors also present a generic construction of identity-based broadcast encryption (IBBE) from any WKD-IBE scheme. One of their instantiations yields an IBBE scheme with constant ciphertext size.
Michel Abdalla, Eike Kiltz, Gregory Neven
IET Inf. Secur.2
2008 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
J. Cryptol.4
2007 Bounded CCA2-Secure Encryption
Ronald Cramer, Goichiro Hanaoka, Dennis Hofheinz, Hideki Imai, Eike Kiltz, Rafael Pass, Abhi Shelat, Vinod Vaikuntanathan
ASIACRYPT5
2007 A Note on Secure Computation of the Moore-Penrose Pseudoinverse and Its Application to Secure Linear Algebra
Ronald Cramer, Eike Kiltz, Carles Padró
CRYPTO2
2007 Secure Hybrid Encryption from Weakened Key Encapsulation
Dennis Hofheinz, Eike Kiltz
CRYPTO2
2007 Generalized Key Delegation for Hierarchical Identity-Based Encryption
Michel Abdalla, Eike Kiltz, Gregory Neven
ESORICS2
2007 Secure Linear Algebra Using Linearly Recurrent Sequences
Eike Kiltz, Payman Mohassel, Enav Weinreb, Matthew K. Franklin
TCC1
2006 Direct Chosen-Ciphertext Secure Identity-Based Key Encapsulation Without Random Oracles
Eike Kiltz, David Galindo
ACISP1
2006 On the Generic Construction of Identity-Based Signatures with Additional Properties
David Galindo, Javier Herranz, Eike Kiltz
ASIACRYPT3
2006 Unconditionally Secure Constant-Rounds Multi-party Computation for Equality, Comparison, Bits and Exponentiation
Ivan Damgård, Matthias Fitzi, Eike Kiltz, Jesper Buus Nielsen, Tomas Toft
TCC3
2006 Chosen-Ciphertext Security from Tag-Based Encryption
Eike Kiltz
TCC1
2006 Polynomial interpolation of cryptographic functions related to Diffie-Hellman and discrete logarithm problem
Eike Kiltz, Arne Winterhof
Discret. Appl. Math.1
2005 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
CRYPTO4
2005 Append-Only Signatures
Eike Kiltz, Anton Mityagin, Saurabh Panjwani, Barath Raghavan
ICALP1
2005 Secure Computation of the Mean and Related Statistics
Eike Kiltz, Gregor Leander, John Malone-Lee
TCC1
2005 Threshold circuit lower bounds on cryptographic functions
Eike Kiltz, Hans Simon 0001
J. Comput. Syst. Sci.1
2003 Complexity Theoretic Aspects of Some Cryptographic Functions
Eike Kiltz, Hans Simon 0001
COCOON1
2003 A General Construction of IND-CCA2 Secure Public Key Encryption
Eike Kiltz, John Malone-Lee
IMACC1
2003 On the Representation of Boolean Predicates of the Diffie-Hellman Function
Eike Kiltz
STACS1
2001 A Primitive for Proving the Security of Every Bit and About Universal Hash Functions & Hard Core Bits
Eike Kiltz
FCT1