Tobias Handirk

dblp:256/9210 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
3since 2021 · last 2024
0009-0002-5368-877XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 since 2021
YearPublicationVenuePosition
2024 Password-Protected Key Retrieval with(out) HSM Protection
abstract
Password-protected key retrieval (PPKR) enables users to store and retrieve high-entropy keys from a server securely. The process is bootstrapped from a human-memorizable password only, addressing the challenge of how end-users can manage cryptographic key material. The core security requirement is protection against a corrupt server, which should not be able to learn the key or offline- attack it through the password protection. PPKR is deployed at a large scale with the WhatsApp Backup Protocol (WBP), allowing users to access their encrypted messaging history when switching to a new device. Davies et al. (Crypto'23) formally analyzed the WBP, proving that it satisfies most of the desired security. The WBP uses the OPAQUE protocol for password-based key exchange as a building block and relies on the server using a hardware security module (HSM) for most of its protection. In fact, the security analysis assumes that the HSM is incorruptible - rendering most of the heavy cryptography in the WBP obsolete.
Sebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth, Anja Lehmann
CCS2
2023 Security Analysis of the WhatsApp End-to-End Encrypted Backup Protocol
Gareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk, Julia Hesse, Máté Horváth, Tibor Jager
CRYPTO (4)4
2021 A Formal Security Analysis of Session Resumption Across Hostnames
Kai Gellert, Tobias Handirk
ESORICS (1)2
2020 Forward-Secure 0-RTT Goes Live: Implementation and Performance Analysis in QUIC
Fynn Dallmeier, Jan Peter Drees, Kai Gellert, Tobias Handirk, Tibor Jager, Jonas Klauke, Simon Nachtigall, Timo Renzelmann, Rudi Wolf
CANS4
2020 T0RTT: Non-Interactive Immediate Forward-Secret Single-Pass Circuit Construction
abstract
Maintaining privacy on the Internet with the presence of powerful adversaries such as nation-state attackers is a challenging topic, and the Tor project is currently the most important tool to protect against this threat. The circuit construction protocol (CCP) negotiates cryptographic keys for Tor circuits, which overlay TCP/IP by routing Tor cells over n onion routers. The current circuit construction protocol provides strong security guarantees such as forward secrecy by exchanging 𝒪(n2) messages.
Sebastian Lauer, Kai Gellert, Robert Merget, Tobias Handirk, Jörg Schwenk
Proc. Priv. Enhancing Technol.4