EDBT 2026 Demo / reviewers in the wild / expert
Benedikt Wagner
dblp:244/9639
· DBLP profile ↗
25ranked-venue papers
0as first author
25since 2021 · last 2026
0000-0002-4620-7264ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 23 since 2021Systems, architecture and hardware · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tight Lattice-Based Signatures Without Trapdoors from Search LWE
Rutchathon Chairattana-Apirom, Nico Döttling, Julian Loss, Stefano Tessaro, Benedikt Wagner |
CRYPTO (3) | 5 |
| 2026 | Aborting Random Oracles: How to Build Them, How to Use Them
Gottfried Herold, Dmitry Khovratovich, Mikhail A. Kudinov, Stefano Tessaro, Benedikt Wagner |
CRYPTO (6) | 5 |
| 2026 | Byzantine Consensus in the Partially Authenticated SettingabstractByzantine Agreement and Broadcast are traditionally studied in one of two extremes: the authenticated setting, where a public key infrastructure (PKI) enables universally verifiable signatures and yields higher fault tolerance, and the unauthenticated setting, where no PKI is available and resilience necessarily drops. Motivated by Proof-of-Stake blockchains, where only a stable subset of participants (e.g., validators) have registered long-term keys while others do not, we initiate a systematic study of consensus in the partially authenticated setting, where a subset of parties are registered in a PKI and the remaining parties are unregistered. Christoph Lenzen 0001, Julian Loss, Kecheng Shi 0001, Benedikt Wagner |
PODC | 4 |
| 2026 | Generic Constructions of Compact and Tightly Selective-Opening Secure Public-Key Encryption Schemes
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng |
J. Cryptol. | 2 |
| 2025 | T-Spoon: Tightly Secure Two-Round Multi-signatures with Key Aggregation
Renas Bacho, Benedikt Wagner |
CRYPTO (6) | 2 |
| 2025 | At the Top of the Hypercube - Better Size-Time Tradeoffs for Hash-Based Signatures
Dmitry Khovratovich, Mikhail A. Kudinov, Benedikt Wagner |
CRYPTO (6) | 3 |
| 2025 | Kleptographic Attacks Against Implicit Rejection
Antoine Joux, Julian Loss, Benedikt Wagner |
PKC (4) | 3 |
| 2025 | Sublinear-Round Broadcast without Trusted SetupabstractByzantine broadcast is one of the fundamental problems in distributed computing. Many of its practical applications, from multiparty computation to consensus mechanisms for blockchains, require increasingly weaker trust assumptions, as well as scalability for an ever-growing number of users n. This rules out existing solutions which run in a linear number of rounds in n or rely on trusted setup requirements. In this paper, we propose the first sublinear-round and trustless Byzantine broadcast protocol for the dishonest majority setting. Unlike previous sublinear-round protocols, our protocol assumes neither the existence of a trusted dealer who honestly issues keys and correlated random strings to the parties nor random oracles. Instead, we present a solution whose setup is limited to an unstructured uniform reference string and a plain public key infrastructure (a.k.a. bulletin-board PKI). Andreea B. Alexandru, Julian Loss, Charalampos Papamanthou, Giorgos Tsimos, Benedikt Wagner |
SODA | 5 |
| 2024 | HARTS: High-Threshold, Adaptively Secure, and Robust Threshold Schnorr Signatures
Renas Bacho, Julian Loss, Gilad Stern, Benedikt Wagner |
ASIACRYPT (3) | 4 |
| 2024 | Tightly Secure Non-interactive BLS Multi-signatures
Renas Bacho, Benedikt Wagner |
ASIACRYPT (2) | 2 |
| 2024 | Jackpot: Non-interactive Aggregatable Lotteries
Nils Fleischhacker, Mathias Hall-Andersen, Mark Simkin 0001, Benedikt Wagner |
ASIACRYPT (6) | 4 |
| 2024 | Practical Blind Signatures in Pairing-Free Groups
Michael Klooß, Michael Reichle, Benedikt Wagner |
ASIACRYPT (1) | 3 |
| 2024 | FRIDA: Data Availability Sampling from FRI
Mathias Hall-Andersen, Mark Simkin 0001, Benedikt Wagner |
CRYPTO (6) | 3 |
| 2024 | Twinkle: Threshold Signatures from DDH with Full Adaptive Security
Renas Bacho, Julian Loss, Stefano Tessaro, Benedikt Wagner, Chenzhi Zhu |
EUROCRYPT (1) | 4 |
| 2024 | A Holistic Security Analysis of Monero Transactions
Cas Cremers, Julian Loss, Benedikt Wagner |
EUROCRYPT (3) | 3 |
| 2024 | Toothpicks: More Efficient Fork-Free Two-Round Multi-signatures
Jiaxin Pan 0001, Benedikt Wagner |
EUROCRYPT (1) | 2 |
| 2024 | Sweep-UC: Swapping Coins PrivatelyabstractFair exchange (also referred to as atomic swap) is a fundamental operation in any cryptocurrency that allows users to atomically exchange coins. While a large body of work has been devoted to this problem, most solutions lack on-chain privacy. Thus, coins retain a public transaction history which is known to degrade the fungibility of a currency. This has led to a flourishing line of related research on fair exchange with privacy guarantees. Existing protocols either rely on heavy scripting (which also degrades fungibility and leads to high transaction fees), do not support atomic swaps across a wide range of currencies, or come with incomplete security proofs.To overcome these limitations, we introduce Sweep-UC1, the first fair exchange protocol that simultaneously is efficient, minimizes scripting, and is compatible with a wide range of currencies (more than the state of the art). We build SweepUC from modular sub-protocols and give a rigorous security analysis in the UC framework. Many of our tools and security definitions can be used in standalone fashion and may serve as useful components for future constructions of fair exchange. Lucjan Hanzlik, Julian Loss, Sri Aravinda Krishnan Thyagarajan, Benedikt Wagner |
SP | 4 |
| 2024 | Generic constructions of master-key KDM secure attribute-based encryption
Jiaxin Pan 0001, Chen Qian 0002, Benedikt Wagner |
Des. Codes Cryptogr. | 3 |
| 2023 | Tighter Security for Generic Authenticated Key Exchange in the QROM
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng |
ASIACRYPT (4) | 2 |
| 2023 | Lattice-Based Authenticated Key Exchange with Tight Security
Jiaxin Pan 0001, Benedikt Wagner, Runzhi Zeng |
CRYPTO (5) | 2 |
| 2023 | Rai-Choo! Evolving Blind Signatures to the Next Level
Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
EUROCRYPT (5) | 3 |
| 2023 | Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive Assumptions
Jiaxin Pan 0001, Benedikt Wagner |
EUROCRYPT (5) | 2 |
| 2023 | Token meets Wallet: Formalizing Privacy and Revocation for FIDO2abstractThe FIDO2 standard is a widely-used class of challenge-response type protocols that allows to authenticate to an online service using a hardware token. Barbosa et al. (CRYPTO ‘21) provided the first formal security model and analysis for the FIDO2 standard. However, their model has two shortcomings: (1) It does not include privacy, one of the key features claimed by FIDO2. (2) It only covers tokens that store all secret keys locally. In contrast, due to limited memory, most existing FIDO2 tokens either derive all secret keys from a common seed or store keys on the server (the latter approach is also known as key wrapping).In this paper, we revisit the security of the WebAuthn component of FIDO2 as implemented in practice. Our contributions are as follows. (1) We adapt the model of Barbosa et al. so as to capture authentication tokens using key derivation or key wrapping. (2) We provide the first formal definition of privacy for the WebAuthn component of FIDO2. We then prove the privacy of this component in common FIDO2 token implementations if the underlying building blocks are chosen appropriately. (3) We address the unsolved problem of global key revocation in FIDO2. To this end, we introduce and analyze a simple revocation procedure that builds on the popular BIP32 standard used in cryptocurrency wallets and can efficiently be implemented with existing FIDO2 servers. Lucjan Hanzlik, Julian Loss, Benedikt Wagner |
SP | 3 |
| 2022 | PI-Cut-Choo and Friends: Compact Blind Signatures via Parallel Instance Cut-and-Choose and More
Rutchathon Chairattana-Apirom, Lucjan Hanzlik, Julian Loss, Anna Lysyanskaya, Benedikt Wagner |
CRYPTO (3) | 5 |
| 2021 | Short Identity-Based Signatures with Tight Security from Lattices
Jiaxin Pan 0001, Benedikt Wagner |
PQCrypto | 2 |