EDBT 2026 Demo / reviewers in the wild / expert
Marjan Skrobot
dblp:115/7782
· DBLP profile ↗
13ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0002-7132-7591ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 1 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure authentication and traceability of physical objects
Mónica P. Arenas, Gabriele Lenzini, Mohammadamin Rakeei, Peter Y. A. Ryan, Marjan Skrobot, Maria Zhekova |
Comput. Secur. | 5 |
| 2024 | SweetPAKE: Key exchange with decoy passwordsabstractDecoy accounts are often used as an indicator of the compromise of sensitive data, such as password files. An attacker targeting only specific known-to-be-real accounts might, however, remain undetected. A more effective method proposed by Juels and Rivest at CCS'13 is to maintain additional fake passwords associated with each account. An attacker who gains access to the password file is unable to tell apart real passwords from fake passwords, and the attempted usage of a false password immediately sets off an alarm indicating a password file compromise. Password-Authenticated Key Exchange (PAKE) has long been recognised for its strong security guarantees when it comes to low-entropy password authentication and secure channel establishment, without having to rely on the setup of a PKI. In this paper, we introduce SweetPAKE, a new cryptographic primitive that offers the same security guarantees as PAKE for key exchange, while allowing clients with a single password to authenticate against servers with n candidate passwords for that account and establish a secure channel. Additional security properties are identified and formalized to ensure that (a) high-entropy session keys are indistinguishable from random, even if later on the long-term secret password becomes corrupted (forward secrecy); (b) upon password file leakage, an adversary cannot tell apart real from fake passwords; and (c) a malicious client cannot trigger a false alarm. We capture these properties by extending well-established game-based definitions of PAKE. Furthermore, we propose a new UC formulation that comprehensively unifies both SweetPAKE (session key indistinguishability and sugarword indistinguishability) and a related notion known as Oblivious-PAKE. Finally, we propose efficient SweetPAKE and Oblivious-PAKE protocols constructed from Password-Authenticated Public-Key Encryption (PAPKE) that satisfy all the proposed notions. Afonso Arriaga, Peter Y. A. Ryan, Marjan Skrobot |
AsiaCCS | 3 |
| 2024 | C'est Très CHIC: A Compact Password-Authenticated Key Exchange from Lattice-Based KEM
Afonso Arriaga, Manuel Barbosa, Stanislaw Jarecki, Marjan Skrobot |
ASIACRYPT (5) | 4 |
| 2024 | Verifying Artifact Authenticity with Unclonable Optical Tagsabstractpeer reviewed Mónica P. Arenas, Gabriele Lenzini, Mohammadamin Rakeei, Peter Y. A. Ryan, Marjan Skrobot, Maria Zhekova |
SECRYPT | 5 |
| 2023 | Wireless-Channel Key Exchange
Afonso Arriaga, Petra Sala, Marjan Skrobot |
CT-RSA | 3 |
| 2019 | An Offline Dictionary Attack Against zkPAKE Protocol
José Becerra, Peter Y. A. Ryan, Petra Sala, Marjan Skrobot |
SEC | 4 |
| 2018 | On Composability of Game-Based Password Authenticated Key ExchangeabstractIt is standard practice that the secret key derived from an execution of a Password Authenticated Key Exchange (PAKE) protocol is used to authenticate and encrypt some data payload using a Symmetric Key Protocol (SKP). Unfortunately, most PAKEs of practical interest are studied using so-called game-based models, which -- unlike simulation models -- do not guarantee secure composition per se. However, Brzuska et al. (CCS 2011) have shown that a middle ground is possible in the case of authenticated key exchange that relies on Public-Key Infrastructure (PKI): the game-based models do provide secure composition guarantees when the class of higher-level applications is restricted to SKPs. The question that we pose in this paper is whether or not a similar result can be exhibited for PAKE. Our work answers this question positively. More specifically, we show that PAKE protocols secure according to the game-based Real-or-Random (RoR) definition with the weak forward secrecy of Abdalla et al. (S&P 2015) allow for safe composition with arbitrary, higher-level SKPs. Since there is evidence that most PAKEs secure in the Find-then-Guess (FtG) model are in fact secure according to RoR definition, we can conclude that nearly all provably secure PAKEs enjoy a certain degree of composition, one that at least covers the case of implementing secure channels. Marjan Skrobot, Jean Lancrenon |
EuroS&P | 1 |
| 2018 | Forward Secrecy of SPAKE2
José Becerra, Dimiter Ostrev, Marjan Skrobot |
ProvSec | 3 |
| 2018 | An Offline Dictionary Attack against zkPAKE ProtocolabstractPassword Authenticated Key Exchange (PAKE) allows a user to establish a secure cryptographic key with a server, using only knowledge of a pre-shared password. One of the basic security requirements of PAKE is to prevent offline dictionary attacks. José Becerra, Peter Y. A. Ryan, Petra Sala, Marjan Skrobot |
WISEC | 4 |
| 2017 | Tightly-Secure PAK(E)
José Becerra, Vincenzo Iovino, Dimiter Ostrev, Petra Sala, Marjan Skrobot |
CANS | 5 |
| 2017 | On the Relation Between SIM and IND-RoR Security Models for PAKEsabstractSecurity models for PAKE protocols aim to capture the desired security properties that such protocols must satisfy when executed in the presence of an active adversary. They are usually classified into i) indistinguishability-based (IND-based) or ii) simulation-based (SIM-based). The relation between these two security notions is unclear and mentioned as a gap in the literature. In this work, we prove that the SIM-based model of Boyko, Mackenzie and Patel [EUROCRYPT00] and the IND-based model of Abdalla, Fouque and Pointcheval are equivalent, in the sense that a protocol proven secure in one model is also secure in the other model. José Becerra, Vincenzo Iovino, Dimiter Ostrev, Marjan Skrobot |
SECRYPT | 4 |
| 2016 | Two More Efficient Variants of the J-PAKE Protocol
Jean Lancrenon, Marjan Skrobot, Qiang Tang 0001 |
ACNS | 2 |
| 2015 | On the Provable Security of the Dragonfly Protocol
Jean Lancrenon, Marjan Skrobot |
ISC | 2 |