Sven Schäge

dblp:04/2350 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
8since 2021 · last 2025
0000-0002-8698-4244ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 7 first-author · 8 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 New Limits for Homomorphic Encryption
Sven Schäge, Marc Vorstermans
ASIACRYPT (8)1
2024 Tightly-Secure Group Key Exchange with Perfect Forward Secrecy
Emanuele Di Giandomenico, Doreen Riepel, Sven Schäge
ASIACRYPT (5)3
2024 Protoss: Protocol for Tight Optimal Symmetric Security
Emanuele Di Giandomenico, Yong Li 0021, Sven Schäge
CCS3
2024 New Limits of Provable Security and Applications to ElGamal Encryption
Sven Schäge
EUROCRYPT (4)1
2024 TOPAS 2-pass key exchange with full perfect forward secrecy and optimal communication complexity
abstract
Abstract We present Transmission optimal protocol with active security ( $$\textsf {TOPAS}$$ TOPAS ), the first key agreement protocol with optimal communication complexity (message size and number of rounds) that provides security against fully active adversaries. The size of the protocol messages and the computational costs to generate them are comparable to the basic Diffie-Hellman protocol over elliptic curves (which is well-known to only provide security against passive adversaries). Session keys are indistinguishable from random keys—even under reflection and key compromise impersonation attacks. What makes $$\textsf {TOPAS}$$ TOPAS stand out is that it also features a security proof of full perfect forward secrecy (PFS), where the attacker can actively modify messages sent to or from the test-session. The proof of full PFS relies on two new extraction-based security assumptions. It is well-known that existing implicitly-authenticated 2-message protocols like $$\textsf {HMQV}$$ HMQV cannot achieve this strong form of (full) security against active attackers (Krawczyk, Crypto’05). This makes $$\textsf {TOPAS}$$ TOPAS the first key agreement protocol with full security against active attackers that works in prime-order groups while having optimal message size. We also present a variant of our protocol, $$\textsf {TOPAS+}$$ TOPAS + , which, under the Strong Diffie-Hellman assumption, provides better computational efficiency in the key derivation phase. Finally, we present a third protocol termed $$\textsf {FACTAS}$$ FACTAS (for factoring-based protocol with active security) which has the same strong security properties as $$\textsf {TOPAS}$$ TOPAS and $$\textsf {TOPAS+}$$ TOPAS + but whose security is solely based on the factoring assumption in groups of composite order (except for the proof of full PFS).
Sven Schäge
Des. Codes Cryptogr.1
2021 Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Shuai Han 0001, Tibor Jager, Eike Kiltz, Shengli Liu 0001, Jiaxin Pan 0001, Doreen Riepel, Sven Schäge
CRYPTO (4)7
2021 Tightly-Secure Authenticated Key Exchange, Revisited
Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge
EUROCRYPT (1)4
2021 On the Impossibility of Purely Algebraic Signatures
Nico Döttling, Dominik Hartmann, Dennis Hofheinz, Eike Kiltz, Sven Schäge, Bogdan Ursu
TCC (3)5
2017 No-Match Attacks and Robust Partnering Definitions: Defining Trivial Attacks for Security Protocols is Not Trivial
abstract
An essential cornerstone of the definition of security for key exchange protocols is the notion of partnering. The de-facto standard definition of partnering is that of (partial) matching conversations (MC), which essentially states that two processes are partnered if every message sent by the first is actually received by the second and vice versa. We show that proving security under MC-based definitions is error-prone. To this end, we introduce no-match attacks, a new class of attacks that renders many existing security proofs invalid. We show that no-match attacks are often hard to avoid in MC-based security definitions without a) modifications of the original protocol or b) resorting to the use of cryptographic primitives with special properties. Finally, we show several ways to thwart no-match attacks. Most notably and as one of our major contributions, we provide a conceptually new definition of partnering that circumvents the problems of a MC-based partnering notion while preserving all its advantages. Our new notion of partnering not only makes security definitions for key exchange model practice much more closely. In contrast to many other security notions of key exchange it also adheres to the high standards of good cryptographic definitions: it is general, supports cryptographic intuition, allows for efficient falsification, and provides a fundamental composition property that MC-based notions lack.
Yong Li 0021, Sven Schäge
CCS2
2017 Authenticated Confidential Channel Establishment and the Security of TLS-DHE
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
J. Cryptol.3
2016 On the Impossibility of Tight Cryptographic Reductions
Christoph Bader, Tibor Jager, Yong Li 0021, Sven Schäge
EUROCRYPT (2)4
2016 Selective opening security of practical public-key encryption schemes
abstract
The authors show that two well‐known and widely employed public‐key encryption schemes – RSA optimal asymmetric encryption padding (RSA‐OAEP) and Diffie–Hellman integrated encryption scheme (DHIES), instantiated with a one‐time pad, – are secure under (the strong, simulation‐based security notion of) selective opening security against chosen‐ciphertext attacks in the random oracle model. Both schemes are obtained via known generic transformations that transform relatively weak primitives (with security in the sense of one‐wayness) to indistinguishability (IND)‐CCA secure encryption schemes. The authors also show a similar result for the well‐known Fujisaki–Okamoto transformation that can generically turn a one‐way secure public key encryption system and a one‐time pad into a IND‐CCA‐secure public‐key encryption system. The authors prove that selective opening security comes for free in these transformations. Both DHIES and RSA‐OAEP are important building blocks in several standards for public key encryption and key exchange protocols. The Fujisaki–Okamoto transformation is very versatile and has successfully been utilised to build efficient lattice‐based cryptosystems. The considered schemes are the first practical cryptosystems that meet the strong notion of simulation‐based selective opening ( SIM‐SO‐CCA ) security.
Felix Heuer, Tibor Jager, Sven Schäge, Eike Kiltz
IET Inf. Secur.3
2015 TOPAS: 2-Pass Key Exchange with Full Perfect Forward Secrecy and Optimal Communication Complexity
abstract
We present TOPAS (Transmission Optimal Protocol with Active Security), the first key agreement protocol with optimal communication complexity that provides security against fully active adversaries. This solves a longstanding open problem. The size of the protocol messages (approx. 160 bits for 80-bit security) and the computational costs to generate them are comparable to the basic Diffie-Hellman protocol over elliptic curves (which is well-known to only provide security against passive adversaries). Session keys are indistinguishable from random keys - even under reflection and key compromise impersonation attacks - under generalizations of TOPAS stand out is that it also features a security proof of full perfect forward secrecy (PFS), where the attacker can actively modify messages sent to or from the test-session. The proof of full PFS relies on two new extraction-based security assumptions. It is well-known that existing implicitly-authenticated 2-message protocols like HMQV cannot achieve this strong form of (full) security against active attackers (Krawczyk, Crypto'05). We also present a variant of our protocol, TOPAS+, which, under the Strong Diffie-Hellman assumption, provides better computational efficiency in the key derivation phase.
Sven Schäge
CCS1
2015 Tight Security for Signature Schemes Without Random Oracles
Sven Schäge
J. Cryptol.1
2014 New Modular Compilers for Authenticated Key Exchange
Yong Li 0021, Sven Schäge, Zheng Yang 0005, Christoph Bader, Jörg Schwenk
ACNS2
2012 On the Security of TLS-DHE in the Standard Model
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
CRYPTO3
2011 Tight Proofs for Signature Schemes without Random Oracles
Sven Schäge
EUROCRYPT1
2010 Towards an Anonymous Access Control and Accountability Scheme for Cloud Computing
abstract
An important aspect of trust in cloud computing consists in preventing the cloud provider from misusing the user's data. In this work-in-progress paper, we propose the approach of data anonymization to solve this problem. As this directly leads to problems of cloud usage accounting, we also propose a solution for anonymous yet reliable access control and accountability based on ring and group signatures.
Meiko Jensen, Sven Schäge, Jörg Schwenk
IEEE CLOUD2
2010 Generic Compilers for Authenticated Key Exchange
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
ASIACRYPT3
2009 Twin Signature Schemes, Revisited
Sven Schäge
ProvSec1