EDBT 2026 Demo / reviewers in the wild / expert
Kai Gellert
dblp:237/1554
· DBLP profile ↗
13ranked-venue papers
3as first author
10since 2021 · last 2024
0000-0003-0985-7265ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Bare PAKE: Universally Composable Key Exchange from Just Passwords
Manuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw Jarecki |
CRYPTO (2) | 2 |
| 2023 | Security Analysis of the WhatsApp End-to-End Encrypted Backup Protocol
Gareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk, Julia Hesse, Máté Horváth, Tibor Jager |
CRYPTO (4) | 3 |
| 2023 | On Optimal Tightness for Key Exchange with Full Forward Secrecy via Key Confirmation
Kai Gellert, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager |
CRYPTO (4) | 1 |
| 2022 | On Fingerprinting Attacks and Length-Hiding Encryption
Kai Gellert, Tibor Jager, Lin Lyu 0001, Tom Neuschulten |
CT-RSA | 1 |
| 2021 | Symmetric Key Exchange with Full Forward Security and Robust Synchronization
Colin Boyd, Gareth T. Davies, Bor de Kock, Kai Gellert, Tibor Jager, Lise Millerjord |
ASIACRYPT (4) | 4 |
| 2021 | Digital Signatures with Memory-Tight Security in the Multi-challenge Setting
Denis Diemert, Kai Gellert, Tibor Jager, Lin Lyu 0001 |
ASIACRYPT (4) | 2 |
| 2021 | A Formal Security Analysis of Session Resumption Across Hostnames
Kai Gellert, Tobias Handirk |
ESORICS (1) | 1 |
| 2021 | A Modern View on Forward SecurityabstractAbstract Forward security ensures that compromise of entities today does not impact the security of cryptographic primitives employed in the past. Such a form of security is regarded as increasingly important in the modern world due to the existence of adversaries with mass storage capabilities and powerful infiltration abilities. Although the idea of forward security has been known for over 30 years, current understanding of what it really should mean is limited due to the prevalence of new techniques and inconsistent terminology. We survey existing methods for achieving forward security for different cryptographic primitives and propose new definitions and terminology aimed at a unified treatment of the notion. Colin Boyd, Kai Gellert |
Comput. J. | 2 |
| 2021 | Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTTabstractAbstract The TLS 1.3 0-RTT mode enables a client reconnecting to a server to send encrypted application-layer data in “0-RTT” (“zero round-trip time”), without the need for a prior interactive handshake. This fundamentally requires the server to reconstruct the previous session’s encryption secrets upon receipt of the client’s first message. The standard techniques to achieve this are session caches or, alternatively, session tickets. The former provides forward security and resistance against replay attacks, but requires a large amount of server-side storage. The latter requires negligible storage, but provides no forward security and is known to be vulnerable to replay attacks. In this paper, we first formally define session resumption protocols as an abstract perspective on mechanisms like session caches and session tickets. We give a new generic construction that provably provides forward security and replay resilience, based on puncturable pseudorandom functions (PPRFs). We show that our construction can immediately be used in TLS 1.3 0-RTT and deployed unilaterally by servers, without requiring any changes to clients or the protocol. To this end, we present a generic composition of our new construction with TLS 1.3 and prove its security. This yields the first construction that achieves forward security for all messages, including the 0-RTT data. We then describe two new constructions of PPRFs, which are particularly suitable for use for forward-secure and replay-resilient session resumption in TLS 1.3. The first construction is based on the strong RSA assumption. Compared to standard session caches, for “128-bit security” it reduces the required server storage by a factor of almost 20, when instantiated in a way such that key derivation and puncturing together are cheaper on average than one full exponentiation in an RSA group. Hence, a 1 GB session cache can be replaced with only about 51 MBs of storage, which significantly reduces the amount of secure memory required. For larger security parameters or in exchange for more expensive computations, even larger storage reductions are achieved. The second construction combines a standard binary tree PPRF with a new “domain extension” technique. For a reasonable choice of parameters, this reduces the required storage by a factor of up to 5 compared to a standard session cache. It employs only symmetric cryptography, is suitable for high-traffic scenarios, and can serve thousands of tickets per second. Nimrod Aviram, Kai Gellert, Tibor Jager |
J. Cryptol. | 2 |
| 2021 | Bloom Filter Encryption and Applications to Efficient Forward-Secret 0-RTT Key ExchangeabstractAbstract Forward secrecy is considered an essential design goal of modern key establishment (KE) protocols, such as TLS 1.3, for example. Furthermore, efficiency considerations such as zero round-trip time (0-RTT), where a client is able to send cryptographically protected payload data along with the very first KE message, are motivated by the practical demand for secure low-latency communication. For a long time, it was unclear whether protocols that simultaneously achieve 0-RTT and full forward secrecy exist. Only recently, the first forward-secret 0-RTT protocol was described by Günther et al. (Eurocrypt, 2017). It is based on puncturable encryption. Forward secrecy is achieved by “puncturing” the secret key after each decryption operation, such that a given ciphertext can only be decrypted once (cf. also Green and Miers, S&P 2015). Unfortunately, their scheme is completely impractical, since one puncturing operation takes between 30 s and several minutes for reasonable security and deployment parameters, such that this solution is only a first feasibility result, but not efficient enough to be deployed in practice. In this paper, we introduce a new primitive that we term Bloom filter encryption (BFE), which is derived from the probabilistic Bloom filter data structure. We describe different constructions of BFE schemes and show how these yield new puncturable encryption mechanisms with extremely efficient puncturing. Most importantly, a puncturing operation only involves a small number of very efficient computations, plus the deletion of certain parts of the secret key, which outperforms previous constructions by orders of magnitude. This gives rise to the first forward-secret 0-RTT protocols that are efficient enough to be deployed in practice. We believe that BFE will find applications beyond forward-secret 0-RTT protocols. David Derler, Kai Gellert, Tibor Jager, Daniel Slamanig, Christoph Striecks |
J. Cryptol. | 2 |
| 2020 | Forward-Secure 0-RTT Goes Live: Implementation and Performance Analysis in QUIC
Fynn Dallmeier, Jan Peter Drees, Kai Gellert, Tobias Handirk, Tibor Jager, Jonas Klauke, Simon Nachtigall, Timo Renzelmann, Rudi Wolf |
CANS | 3 |
| 2020 | T0RTT: Non-Interactive Immediate Forward-Secret Single-Pass Circuit ConstructionabstractMaintaining privacy on the Internet with the presence of powerful adversaries such as nation-state attackers is a challenging topic, and the Tor project is currently the most important tool to protect against this threat. The circuit construction protocol (CCP) negotiates cryptographic keys for Tor circuits, which overlay TCP/IP by routing Tor cells over n onion routers. The current circuit construction protocol provides strong security guarantees such as forward secrecy by exchanging 𝒪(n2) messages. Sebastian Lauer, Kai Gellert, Robert Merget, Tobias Handirk, Jörg Schwenk |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTT
Nimrod Aviram, Kai Gellert, Tibor Jager |
EUROCRYPT (2) | 2 |