Christoph Dobraunig

dblp:125/8630 · DBLP profile ↗
← Back
33ranked-venue papers
28as first author
10since 2021 · last 2025
0000-0002-3816-0187ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 27 first-author · 10 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2025 Efficient Instances of Docked Double Decker with AES, and Application to Authenticated Encryption
Christoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander Tereschenko
EUROCRYPT (1)1
2024 Generalized Initialization of the Duplex Construction
Christoph Dobraunig, Bart Mennink
ACNS (2)1
2024 Ascon MAC, PRF, and Short-Input PRF - Lightweight, Fast, and Efficient Pseudorandom Functions
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer
CT-RSA1
2022 Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key Crypto
abstract
Signature schemes based on the MPC-in-the-head approach (MPCitH) have either been designed by taking a proof system and selecting a suitable symmetric-key primitive (Picnic, CCS16), or starting with an existing primitive such as AES and trying to find the most suitable proof system (BBQ, SAC19 or Banquet, PKC21). In this work we do both: we improve certain symmetric-key primitives to better fit existing signature schemes, and we also propose a new signature scheme that combines a new, minimalist one-way function with changes to a proof system to make their combination even more efficient. Our concrete results are as follows.
Christoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger, Gregory M. Zaverucha
CCS1
2022 Leakage and Tamper Resilient Permutation-Based Cryptography
abstract
Implementation attacks such as power analysis and fault attacks have shown that, if potential attackers have physical access to a cryptographic device, achieving practical security requires more considerations apart from just cryptanalytic security. In recent years, and with the advent of micro-architectural or hardware-oriented attacks, it became more and more clear that similar attack vectors can also be exploited on larger computing platforms and without the requirement of physical proximity of an attacker. While newly discovered attacks typically come with implementation recommendations that help counteract a specific attack vector, the process of constantly patching cryptographic code is quite time consuming in some cases, and simply not possible in other cases.
Christoph Dobraunig, Bart Mennink, Robert Primas
CCS1
2022 Information-Combining Differential Fault Attacks on DEFAULT
Marcel Nageler, Christoph Dobraunig, Maria Eichlseder
EUROCRYPT (3)2
2021 Ciminion: Symmetric Encryption Based on Toffoli-Gates over Large Finite Fields
Christoph Dobraunig, Lorenzo Grassi 0001, Anna Guinet, Daniël Kuijsters
EUROCRYPT (2)1
2021 Leakage Resilient Value Comparison with Application to Message Authentication
Christoph Dobraunig, Bart Mennink
EUROCRYPT (2)1
2021 Multi-user Security of the Elephant v2 Authenticated Encryption Mode
Tim Beyne, Yu Long Chen, Christoph Dobraunig, Bart Mennink
SAC3
2021 Ascon v1.2: Lightweight Authenticated Encryption and Hashing
abstract
Abstract Authenticated encryption satisfies the basic need for authenticity and confidentiality in our information infrastructure. In this paper, we provide the specification of Ascon -128 and Ascon -128a. Both authenticated encryption algorithms provide efficient authenticated encryption on resource-constrained devices and on high-end CPUs. Furthermore, they have been selected as the “primary choice” for lightweight authenticated encryption in the final portfolio of the CAESAR competition. In addition, we specify the hash function Ascon-Hash , and the extendable output function Ascon-Xof . Moreover, we complement the specification by providing a detailed overview of existing cryptanalysis and implementation results.
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer
J. Cryptol.1
2020 Improved (semi-free-start/near-) collision and distinguishing attacks on round-reduced RIPEMD-160
Gaoli Wang, Fukang Liu, Binbin Cui, Florian Mendel, Christoph Dobraunig
Des. Codes Cryptogr.5
2020 Framework for faster key search using related-key higher-order differential properties: applications to Agrasta
abstract
The relevance of the related‐key model is usually controversial. However, in some cases, related‐key properties have already been used to reduce the effective key length of the cipher in the single‐key model. Hence, research into this direction can be helpful to bridge the gap between theory and practice aspects of the related‐key model. Motivated by this challenge, the authors develop a new framework to provide further evidence that deterministic related‐key characteristics can be utilised in the single‐key model. The authors describe a sound framework for utilising related‐key higher‐order differential distinguishers that can beat the boundaries given by exhaustive key search. The data required is only one known as plaintext–ciphertext pair if the number of ciphertext bits matches the key length. From a theoretical point of view, the connection between related‐key higher‐order differential properties and the security of cryptographic primitives in the single‐key model are precised. From a practical point of view, the proposed framework is used to evaluate the security of Agrasta cipher which is a variant of Rasta cipher presented at CRYPTO 2018. The proposed method is the first analysis of Agrasta reduced to three rounds that performs better than exhaustive key search and is independent of the used linear layers.
Christoph Dobraunig, Farokhlagha Moazami, Christian Rechberger, Hadi Soleimany
IET Inf. Secur.1
2020 Practical forgeries for ORANGE
abstract
We analyze the authenticated encryption algorithm of ORANGE, a submission to the NIST lightweight cryptography standardization process. We show that it is practically possible to craft forgeries out of two observed transmitted messages that encrypt the same plaintext. The authors of ORANGE have confirmed the attack, and they discuss a fix for this attack in their second-round submission of ORANGE to the NIST lightweight cryptography competition.
Christoph Dobraunig, Florian Mendel, Bart Mennink
Inf. Process. Lett.1
2019 Leakage Resilience of the Duplex Construction
Christoph Dobraunig, Bart Mennink
ASIACRYPT (3)1
2019 Efficient Collision Attack Frameworks for RIPEMD-160
Fukang Liu, Christoph Dobraunig, Florian Mendel, Takanori Isobe 0001, Gaoli Wang, Zhenfu Cao
CRYPTO (2)2
2019 Algebraic Cryptanalysis of Variants of Frit
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Markus Schofnegger
SAC1
2018 Statistical Ineffective Fault Attacks on Masked AES with Fault Countermeasures
Christoph Dobraunig, Maria Eichlseder, Hannes Groß, Stefan Mangard, Florian Mendel, Robert Primas
ASIACRYPT (2)1
2018 Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger
CRYPTO (1)1
2018 Fault Attacks on Nonce-Based Authenticated Encryption: Application to Keyak and Ketje
Christoph Dobraunig, Stefan Mangard, Florian Mendel, Robert Primas
SAC1
2017 Impossible-Differential and Boomerang Cryptanalysis of Round-Reduced Kiasu-BC
Christoph Dobraunig, Eik List
CT-RSA1
2016 Square Attack on 7-Round Kiasu-BC
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
ACNS1
2016 Statistical Fault Attacks on Nonce-Based Authenticated Encryption Schemes
Christoph Dobraunig, Maria Eichlseder, Thomas Korak, Victor Lomné, Florian Mendel
ASIACRYPT (1)1
2016 Analysis of the Kupyna-256 Hash Function
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
FSE1
2016 Cryptanalysis of Simpira v1
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
SAC1
2015 Heuristic Tool for Linear Cryptanalysis with Applications to CAESAR Candidates
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
ASIACRYPT (2)1
2015 Analysis of SHA-512/224 and SHA-512/256
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
ASIACRYPT (2)1
2015 Towards Fresh and Hybrid Re-Keying Schemes with Beyond Birthday Security
Christoph Dobraunig, François Koeune, Stefan Mangard, Florian Mendel, François-Xavier Standaert
CARDIS1
2015 Cryptanalysis of Ascon
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer
CT-RSA1
2015 Suit up! - Made-to-Measure Hardware Implementations of ASCON
abstract
Having ciphers that provide confidentiality and authenticity, that are fast in software and efficient in hardware, these are the goals of the CAESAR authenticated encryption competition. In this paper, the promising CAESAR candidate ASCON is implemented in hardware and optimized for different typical applications to fully explore ASCON's design space. Thus, we are able to present hardware implementations of Ascon suitable for RFID tags, Wireless Sensor Nodes, Embedded Systems, and applications that need maximum performance. For instance, we show that an ASCON implementation with a single unrolled round transformation is only 7 kGE large, but can process up to 5.5 Gbit/sec of data (0.75 cycles/byte), which is already enough to encrypt a Gigabit Ethernet connection. Besides, ASCON is not only fast and small, it can also be easily protected against DPA attacks. A threshold implementation of ASCON just requires about 8 kGE of chip area, which is only 3.1 times larger than the unprotected low-area optimized implementation.
Hannes Groß, Erich Wenger, Christoph Dobraunig, Christoph Ehrenhöfer
DSD3
2015 Related-Key Forgeries for Prøst-OTR
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
FSE1
2015 Forgery Attacks on Round-Reduced ICEPOLE-128
Christoph Dobraunig, Maria Eichlseder, Florian Mendel
SAC1
2014 On the Security of Fresh Re-keying to Counteract Side-Channel and Fault Attacks
Christoph Dobraunig, Maria Eichlseder, Stefan Mangard, Florian Mendel
CARDIS1
2014 Differential Cryptanalysis of SipHash
Christoph Dobraunig, Florian Mendel, Martin Schläffer
Selected Areas in Cryptography1