EDBT 2026 Demo / reviewers in the wild / expert
Christoph Dobraunig
dblp:125/8630
· DBLP profile ↗
33ranked-venue papers
28as first author
10since 2021 · last 2025
0000-0002-3816-0187ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 27 first-author · 10 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Efficient Instances of Docked Double Decker with AES, and Application to Authenticated Encryption
Christoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander Tereschenko |
EUROCRYPT (1) | 1 |
| 2024 | Generalized Initialization of the Duplex Construction
Christoph Dobraunig, Bart Mennink |
ACNS (2) | 1 |
| 2024 | Ascon MAC, PRF, and Short-Input PRF - Lightweight, Fast, and Efficient Pseudorandom Functions
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer |
CT-RSA | 1 |
| 2022 | Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key CryptoabstractSignature schemes based on the MPC-in-the-head approach (MPCitH) have either been designed by taking a proof system and selecting a suitable symmetric-key primitive (Picnic, CCS16), or starting with an existing primitive such as AES and trying to find the most suitable proof system (BBQ, SAC19 or Banquet, PKC21). In this work we do both: we improve certain symmetric-key primitives to better fit existing signature schemes, and we also propose a new signature scheme that combines a new, minimalist one-way function with changes to a proof system to make their combination even more efficient. Our concrete results are as follows. Christoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger, Gregory M. Zaverucha |
CCS | 1 |
| 2022 | Leakage and Tamper Resilient Permutation-Based CryptographyabstractImplementation attacks such as power analysis and fault attacks have shown that, if potential attackers have physical access to a cryptographic device, achieving practical security requires more considerations apart from just cryptanalytic security. In recent years, and with the advent of micro-architectural or hardware-oriented attacks, it became more and more clear that similar attack vectors can also be exploited on larger computing platforms and without the requirement of physical proximity of an attacker. While newly discovered attacks typically come with implementation recommendations that help counteract a specific attack vector, the process of constantly patching cryptographic code is quite time consuming in some cases, and simply not possible in other cases. Christoph Dobraunig, Bart Mennink, Robert Primas |
CCS | 1 |
| 2022 | Information-Combining Differential Fault Attacks on DEFAULT
Marcel Nageler, Christoph Dobraunig, Maria Eichlseder |
EUROCRYPT (3) | 2 |
| 2021 | Ciminion: Symmetric Encryption Based on Toffoli-Gates over Large Finite Fields
Christoph Dobraunig, Lorenzo Grassi 0001, Anna Guinet, Daniël Kuijsters |
EUROCRYPT (2) | 1 |
| 2021 | Leakage Resilient Value Comparison with Application to Message Authentication
Christoph Dobraunig, Bart Mennink |
EUROCRYPT (2) | 1 |
| 2021 | Multi-user Security of the Elephant v2 Authenticated Encryption Mode
Tim Beyne, Yu Long Chen, Christoph Dobraunig, Bart Mennink |
SAC | 3 |
| 2021 | Ascon v1.2: Lightweight Authenticated Encryption and HashingabstractAbstract Authenticated encryption satisfies the basic need for authenticity and confidentiality in our information infrastructure. In this paper, we provide the specification of Ascon -128 and Ascon -128a. Both authenticated encryption algorithms provide efficient authenticated encryption on resource-constrained devices and on high-end CPUs. Furthermore, they have been selected as the “primary choice” for lightweight authenticated encryption in the final portfolio of the CAESAR competition. In addition, we specify the hash function Ascon-Hash , and the extendable output function Ascon-Xof . Moreover, we complement the specification by providing a detailed overview of existing cryptanalysis and implementation results. Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer |
J. Cryptol. | 1 |
| 2020 | Improved (semi-free-start/near-) collision and distinguishing attacks on round-reduced RIPEMD-160
Gaoli Wang, Fukang Liu, Binbin Cui, Florian Mendel, Christoph Dobraunig |
Des. Codes Cryptogr. | 5 |
| 2020 | Framework for faster key search using related-key higher-order differential properties: applications to AgrastaabstractThe relevance of the related‐key model is usually controversial. However, in some cases, related‐key properties have already been used to reduce the effective key length of the cipher in the single‐key model. Hence, research into this direction can be helpful to bridge the gap between theory and practice aspects of the related‐key model. Motivated by this challenge, the authors develop a new framework to provide further evidence that deterministic related‐key characteristics can be utilised in the single‐key model. The authors describe a sound framework for utilising related‐key higher‐order differential distinguishers that can beat the boundaries given by exhaustive key search. The data required is only one known as plaintext–ciphertext pair if the number of ciphertext bits matches the key length. From a theoretical point of view, the connection between related‐key higher‐order differential properties and the security of cryptographic primitives in the single‐key model are precised. From a practical point of view, the proposed framework is used to evaluate the security of Agrasta cipher which is a variant of Rasta cipher presented at CRYPTO 2018. The proposed method is the first analysis of Agrasta reduced to three rounds that performs better than exhaustive key search and is independent of the used linear layers. Christoph Dobraunig, Farokhlagha Moazami, Christian Rechberger, Hadi Soleimany |
IET Inf. Secur. | 1 |
| 2020 | Practical forgeries for ORANGEabstractWe analyze the authenticated encryption algorithm of ORANGE, a submission to the NIST lightweight cryptography standardization process. We show that it is practically possible to craft forgeries out of two observed transmitted messages that encrypt the same plaintext. The authors of ORANGE have confirmed the attack, and they discuss a fix for this attack in their second-round submission of ORANGE to the NIST lightweight cryptography competition. Christoph Dobraunig, Florian Mendel, Bart Mennink |
Inf. Process. Lett. | 1 |
| 2019 | Leakage Resilience of the Duplex Construction
Christoph Dobraunig, Bart Mennink |
ASIACRYPT (3) | 1 |
| 2019 | Efficient Collision Attack Frameworks for RIPEMD-160
Fukang Liu, Christoph Dobraunig, Florian Mendel, Takanori Isobe 0001, Gaoli Wang, Zhenfu Cao |
CRYPTO (2) | 2 |
| 2019 | Algebraic Cryptanalysis of Variants of Frit
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Markus Schofnegger |
SAC | 1 |
| 2018 | Statistical Ineffective Fault Attacks on Masked AES with Fault Countermeasures
Christoph Dobraunig, Maria Eichlseder, Hannes Groß, Stefan Mangard, Florian Mendel, Robert Primas |
ASIACRYPT (2) | 1 |
| 2018 | Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger |
CRYPTO (1) | 1 |
| 2018 | Fault Attacks on Nonce-Based Authenticated Encryption: Application to Keyak and Ketje
Christoph Dobraunig, Stefan Mangard, Florian Mendel, Robert Primas |
SAC | 1 |
| 2017 | Impossible-Differential and Boomerang Cryptanalysis of Round-Reduced Kiasu-BC
Christoph Dobraunig, Eik List |
CT-RSA | 1 |
| 2016 | Square Attack on 7-Round Kiasu-BC
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
ACNS | 1 |
| 2016 | Statistical Fault Attacks on Nonce-Based Authenticated Encryption Schemes
Christoph Dobraunig, Maria Eichlseder, Thomas Korak, Victor Lomné, Florian Mendel |
ASIACRYPT (1) | 1 |
| 2016 | Analysis of the Kupyna-256 Hash Function
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
FSE | 1 |
| 2016 | Cryptanalysis of Simpira v1
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
SAC | 1 |
| 2015 | Heuristic Tool for Linear Cryptanalysis with Applications to CAESAR Candidates
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
ASIACRYPT (2) | 1 |
| 2015 | Analysis of SHA-512/224 and SHA-512/256
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
ASIACRYPT (2) | 1 |
| 2015 | Towards Fresh and Hybrid Re-Keying Schemes with Beyond Birthday Security
Christoph Dobraunig, François Koeune, Stefan Mangard, Florian Mendel, François-Xavier Standaert |
CARDIS | 1 |
| 2015 | Cryptanalysis of Ascon
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer |
CT-RSA | 1 |
| 2015 | Suit up! - Made-to-Measure Hardware Implementations of ASCONabstractHaving ciphers that provide confidentiality and authenticity, that are fast in software and efficient in hardware, these are the goals of the CAESAR authenticated encryption competition. In this paper, the promising CAESAR candidate ASCON is implemented in hardware and optimized for different typical applications to fully explore ASCON's design space. Thus, we are able to present hardware implementations of Ascon suitable for RFID tags, Wireless Sensor Nodes, Embedded Systems, and applications that need maximum performance. For instance, we show that an ASCON implementation with a single unrolled round transformation is only 7 kGE large, but can process up to 5.5 Gbit/sec of data (0.75 cycles/byte), which is already enough to encrypt a Gigabit Ethernet connection. Besides, ASCON is not only fast and small, it can also be easily protected against DPA attacks. A threshold implementation of ASCON just requires about 8 kGE of chip area, which is only 3.1 times larger than the unprotected low-area optimized implementation. Hannes Groß, Erich Wenger, Christoph Dobraunig, Christoph Ehrenhöfer |
DSD | 3 |
| 2015 | Related-Key Forgeries for Prøst-OTR
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
FSE | 1 |
| 2015 | Forgery Attacks on Round-Reduced ICEPOLE-128
Christoph Dobraunig, Maria Eichlseder, Florian Mendel |
SAC | 1 |
| 2014 | On the Security of Fresh Re-keying to Counteract Side-Channel and Fault Attacks
Christoph Dobraunig, Maria Eichlseder, Stefan Mangard, Florian Mendel |
CARDIS | 1 |
| 2014 | Differential Cryptanalysis of SipHash
Christoph Dobraunig, Florian Mendel, Martin Schläffer |
Selected Areas in Cryptography | 1 |