Andreas Hülsing

dblp:27/1744 · DBLP profile ↗
← Back
39ranked-venue papers
10as first author
22since 2021 · last 2026
0000-0003-2215-4134ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 39 · 10 first-author · 22 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Starfighters-On the General Applicability of X-Wing
Deirdre Connolly, Kathrin Hövelmanns, Andreas Hülsing, Stavros Kousidis, Matthias Meijers
SP3
2025 How Hard can it be to Formalize a Proof? - Lessons from Formalizing CryptoBox Three Times in EasyCrypt
François Dupressoir, Andreas Hülsing, Cameron Low, Matthias Meijers, Charlotte Mylog, Sabine Oechsner
ASIACRYPT (2)2
2025 Hybrid-Query Bounds with Partial Input Control Framework and Application to Tight M-eTCR
Andreas Hülsing, Mikhail A. Kudinov, Christian Majenz
ASIACRYPT (8)1
2025 A Key-Update Mechanism for the Space Data Link Security Protocol
Andreas Hülsing, Tanja Lange 0001, Fiona Johanna Weber
CANS1
2025 (Un)breakable Curses - Re-encryption in the Fujisaki-Okamoto Transform
Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz, Fabrizio Sisinni
EUROCRYPT (2)2
2024 A Tight Security Proof for SPHINCS+, Formally Verified
Manuel Barbosa, François Dupressoir, Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub
ASIACRYPT (4)3
2024 Towards Post-quantum Secure PAKE - A Tight Security Proof for OCAKE in the BPR Model
Nouri Alnahawi, Kathrin Hövelmanns, Andreas Hülsing, Silvia Ritsch
CANS (2)3
2024 On Round Elimination for Special-Sound Multi-round Identification and the Generality of the Hypercube for MPCitH
Andreas Hülsing, David Joseph, Christian Majenz, Anand Kumar Narayanan
CRYPTO (1)1
2024 Batch Signatures, Revisited
Carlos Aguilar Melchor, Martin R. Albrecht, Thomas Bailleux, Nina Bindel, James Howe, Andreas Hülsing, David Joseph, Marc Manzano
CT-RSA6
2023 SDitH in the QROM
Carlos Aguilar Melchor, Andreas Hülsing, David Joseph, Christian Majenz, Eyal Ronen, Dongze Yue
ASIACRYPT (7)2
2023 Fixing and Mechanizing the Security Proof of Fiat-Shamir with Aborts and Dilithium
Manuel Barbosa, Gilles Barthe, Christian Doczkal, Jelle Don, Serge Fehr, Benjamin Grégoire, Yu-Hsuan Huang 0003, Andreas Hülsing, Yi Lee, Xiaodi Wu 0001
CRYPTO (5)8
2023 Machine-Checked Security for rmXMSS as in RFC 8391 and $\mathrm {SPHINCS^{+}} $
Manuel Barbosa, François Dupressoir, Benjamin Grégoire, Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub
CRYPTO (5)4
2023 The Return of the SDitH
Carlos Aguilar Melchor, Nicolas Gama, James Howe, Andreas Hülsing, David Joseph, Dongze Yue
EUROCRYPT (5)4
2023 SPHINCS+C: Compressing SPHINCS+ With (Almost) No Cost
abstract
SPHINCS+ [CCS ’19] is one of the selected post-quantum digital signature schemes of NIST’s post-quantum standardization process. The scheme is a hash-based signature and is considered one of the most secure and robust proposals. The proposal includes a fast (but larger) variant and a small (but slower) variant for each security level. The main problem that might hinder its adoption is its large signature size. Although SPHINCS+ supports a trade-off between signature size and the computational cost of signing, further reducing the signature size (below the small variants) results in a prohibitively high computational cost for the signer.This paper presents several novel methods for further compressing the signature size while requiring negligible added computational costs for the signer and further reducing verification time. Moreover, our approach enables a much more efficient trade-off curve between signature size and the computational costs of the signer. In many parameter settings, we achieve small signatures and faster running times simultaneously. For example, for 128-bit (classical) security, the small signature variant of SPHINCS+ is 7856 bytes long, while our variant is only 6304 bytes long: a compression of approximately 20% while still reducing the signer’s running time. However, other trade-offs that focus, e.g., on verification speed, are possible.The main insight behind our scheme is that there are predefined specific subsets of messages for which the WOTS+ and FORS signatures (that SPHINCS+ uses) can be compressed, and generation can be made faster while maintaining the same security guarantees. Although most messages will not come from these subsets, we can search for suitable hashed values to sign. We sign a hash of the message concatenated with a counter that was chosen such that the hashed value is in the subset. The resulting signature is both smaller and faster to sign and verify.Our schemes are simple to describe and implement. We provide an implementation, a theoretical analysis of speed and security, as well as benchmark results.
Andreas Hülsing, Mikhail A. Kudinov, Eyal Ronen, Eylon Yogev
SP1
2022 Failing Gracefully: Decryption Failures and the Fujisaki-Okamoto Transform
Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz
ASIACRYPT (4)2
2022 Recovering the Tight Security Proof of SPHINCS+
Andreas Hülsing, Mikhail A. Kudinov
ASIACRYPT (4)1
2022 Post Quantum Noise
abstract
We introduce PQNoise, a post-quantum variant of the Noise framework. We demonstrate that it is possible to replace the Diffie-Hellman key-exchanges in Noise with KEMs in a secure way. A challenge is the inability to combine key pairs of KEMs, which can be resolved by certain forms of randomness-hardening for which we introduce a formal abstraction. We provide a generic recipe to turn classical Noise patterns into PQNoise patterns. We prove that the resulting PQNoise patterns achieve confidentiality and authenticity in the fACCE model. Moreover we show that for those classical Noise-patterns that have been conjectured or proven secure in the fACCE model our matching PQNoise patterns eventually achieve the same security. Our security proof is generic and applies to any valid PQNoise pattern. This is made possible by another abstraction, called a hash-object, which hides the exact workings of how keying material is processed in an abstract stateful object that outputs pseudorandom keys under different corruption patterns. We also show that the hash chains used in Noise are a secure hash-object. Finally, we demonstrate the practicality of PQNoise delivering benchmarks for several base patterns.
Yawning Angel, Benjamin Dowling, Andreas Hülsing, Peter Schwabe, Florian Weber
CCS3
2022 Formal Verification of Saber's Public-Key Encryption Scheme in EasyCrypt
Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub
CRYPTO (1)1
2021 Tight Adaptive Reprogramming in the QROM
Alex Bredariol Grilo, Kathrin Hövelmanns, Andreas Hülsing, Christian Majenz
ASIACRYPT (1)3
2021 Verifying Post-Quantum Signatures in 8 kB of RAM
Andreas Hülsing, Matthias J. Kannwischer, Juliane Krämer, Tanja Lange 0001, Marc Stöttinger, Elisabeth Waitz, Thom Wiggers, Bo-Yin Yang
PQCrypto2
2021 Post-quantum WireGuard
abstract
In this paper we present PQ-WireGuard, a post-quantum variant of the handshake in the WireGuard VPN protocol (NDSS 2017). Unlike most previous work on post-quantum security for real-world protocols, this variant does not only consider post-quantum confidentiality (or forward secrecy) but also post-quantum authentication. To achieve this, we replace the Diffie-Hellman-based handshake by a more generic approach only using key-encapsulation mechanisms (KEMs). We establish security of PQ-WireGuard, adapting the security proofs for WireGuard in the symbolic model and in the standard model to our construction. We then instantiate this generic construction with concrete post-quantum secure KEMs, which we carefully select to achieve high security and speed. We demonstrate competitiveness of PQ-WireGuard presenting extensive bench-marking results comparing to widely deployed VPN solutions.
Andreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber, Philip R. Zimmermann
SP1
2021 Epochal Signatures for Deniable Group Chats
abstract
In this work we take a formal look at deniability in group chat applications and introduce the concept of "epochal signatures" that allows to turn many secure group chat protocols into deniable ones. Intuitively, the transform works for protocols that use signatures for authentication and that become deniable if the signatures are removed. In contrast to previous proposals that use signatures for entity authentication, like mpOTR (CCS’09), our construction does not require pairwise key establishment of participants and allows to add and remove participants without requiring to re-initialize the chat. These properties allow the deployment in protocols that are also designed to scale to very large groups. Finally, we construct a practical epochal signature scheme from generic primitives and prove it secure.
Andreas Hülsing, Florian Weber
SP1
2019 Decisional Second-Preimage Resistance: When Does SPR Imply PRE?
Daniel J. Bernstein, Andreas Hülsing
ASIACRYPT (3)2
2019 The SPHINCS+ Signature Framework
abstract
We introduce SPHINCS+, a stateless hash-based signature framework. SPHINCS+ has significant advantages over the state of the art in terms of speed, signature size, and security, and is among the nine remaining signature schemes in the second round of the NIST PQC standardization project. One of our main contributions in this context is a new few-time signature scheme that we call FORS. Our second main contribution is the introduction of tweakable hash functions and a demonstration how they allow for a unified security analysis of hash-based signature schemes. We give a security reduction for SPHINCS+ using this abstraction and derive secure parameters in accordance with the resulting bound. Finally, we present speed results for our optimized implementation of SPHINCS+ and compare to SPHINCS-256, Gravity-SPHINCS, and Picnic.
Daniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, Peter Schwabe
CCS2
2019 Quantum Indistinguishability of Random Sponges
Jan Czajkowski, Andreas Hülsing, Christian Schaffner
CRYPTO (2)2
2019 Tighter Proofs of CCA Security in the Quantum Random Oracle Model
Nina Bindel, Michael Hamburg, Kathrin Hövelmanns, Andreas Hülsing, Edoardo Persichetti
TCC (2)4
2018 Post-quantum Security of the Sponge Construction
Jan Czajkowski, Leon Groot Bruinderink, Andreas Hülsing, Christian Schaffner, Dominique Unruh
PQCrypto3
2017 High-Speed Key Encapsulation from NTRU
Andreas Hülsing, Joost Rijneveld, John M. Schanck, Peter Schwabe
CHES1
2017 "Oops, I Did It Again" - Security of One-Time Signatures Under Two-Message Attacks
Leon Groot Bruinderink, Andreas Hülsing
SAC2
2016 From 5-Pass MQ -Based Identification to MQ -Based Signatures
abstract
This paper presents MQDSS, the first signature scheme with a security reduction based on the problem of solving a multivariate system of quadratic equations ( $$\mathcal {MQ}$$ problem). In order to construct this scheme we give a new security reduction for the Fiat-Shamir transform from a large class of 5-pass identification schemes and show that a previous attempt from the literature to obtain such a proof does not achieve the desired goal. We give concrete parameters for MQDSS and provide a detailed security analysis showing that the resulting instantiation MQDSS-31-64 achieves 128 bits of post-quantum security. Finally, we describe an optimized implementation of MQDSS-31-64 for recent Intel processors with full protection against timing attacks and report benchmarks of this implementation.
Ming-Shing Chen, Andreas Hülsing, Joost Rijneveld, Simona Samardjiska, Peter Schwabe
ASIACRYPT (2)2
2016 Flush, Gauss, and Reload - A Cache Attack on the BLISS Lattice-Based Signature Scheme
Leon Groot Bruinderink, Andreas Hülsing, Tanja Lange 0001, Yuval Yarom
CHES2
2016 Semantic Security and Indistinguishability in the Quantum World
Tommaso Gagliardoni, Andreas Hülsing, Christian Schaffner
CRYPTO (3)2
2015 PALPAS - PAssword Less PAssword Synchronization
abstract
Tools that synchronize passwords over several user devices typically store the encrypted passwords in a central online database. For encryption, a low-entropy, password-based key is used. Such a database may be subject to unauthorized access which can lead to the disclosure of all passwords by an offline brute-force attack. In this paper, we present PALPAS, a secure and user-friendly tool that synchronizes passwords between user devices without storing information about them centrally. The idea of PALPAS is to generate a password from a high entropy secret shared by all devices and a random salt value for each service. Only the salt values are stored on a server but not the secret. The salt enables the user devices to generate the same password but is statistically independent of the password. In order for PALPAS to generate passwords according to different password policies, we also present a mechanism that automatically retrieves and processes the password requirements of services. PALPAS users need to only memorize a single password and the setup of PALPAS on a further device demands only a one-time transfer of few static data.
Moritz Horsch, Andreas Hülsing, Johannes Buchmann 0001
ARES2
2015 Bad Directions in Cryptographic Hash Functions
Daniel J. Bernstein, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen
ACISP2
2015 SPHINCS: Practical Stateless Hash-Based Signatures
abstract
This paper introduces a high-security post-quantum stateless hash-based signature scheme that signs hundreds of messages per second on a modern 4-core 3.5GHz Intel CPU. Signatures are 41 KB, public keys are 1 KB, and private keys are 1 KB. The signature scheme is designed to provide long-term $$2^{128}$$ security even against attackers equipped with quantum computers. Unlike most hash-based designs, this signature scheme is stateless, allowing it to be a drop-in replacement for current signature schemes.
Daniel J. Bernstein, Daira Hopwood, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen, Louiza Papachristodoulou, Michael Schneider 0002, Peter Schwabe, Zooko Wilcox-O'Hearn
EUROCRYPT (1)3
2014 Developing and testing SCoP - a visual hash scheme
abstract
Purpose – The purpose of this study was to develop and test SCoP. Users find comparing long meaningless strings of alphanumeric characters difficult. While visual hashes – where users compare images rather than strings – have been proposed as an alternative, people are unable to sufficiently distinguish more than 30 bits, which does not provide adequate security against collision attacks. Our goal is to improve the situation. Design/methodology/approach – A visual hash scheme was developed using shapes, colours, patterns and position parameters. It was evaluated in a series of pilot user studies and improved iteratively, leading to SCoP, which encodes 60 distinguishable bits. We tested SCoP further in two follow-up studies, simulating verifying in remote electronic voting and https certificate validation. Findings – Participants attained an average accuracy rate of 97 per cent with SCoP when comparing two visual hash images, one placed above the other. From the follow-up studies, SCoP was seen to be more promising for the https certificate validation use case, with direct image comparison, while a low average accuracy rate in simulating verifiability in remote electronic voting limits its applicability in an image-recall use case. Research limitations/implications – Participants achieved high accuracy rates in unrealistic situations, where the images appeared on the screen at the same time and in the same size. Studies in more realistic situations are therefore necessary. Originality/value – We identify a visual hash scheme encoding a higher number of distinguishable bits than previously reported in literature, and extend the testing to realistic scenarios.
Maina M. Olembo, Timo Kilian, Simon Stockhardt, Andreas Hülsing, Melanie Volkamer
Inf. Manag. Comput. Secur.4
2013 Discrete Ziggurat: A Time-Memory Trade-Off for Sampling from a Gaussian Distribution over the Integers
Johannes Buchmann 0001, Daniel Cabarcas, Florian Göpfert, Andreas Hülsing, Patrick Weiden
Selected Areas in Cryptography4
2012 Forward Secure Signatures on Smart Cards
Andreas Hülsing, Christoph Busold, Johannes Buchmann 0001
Selected Areas in Cryptography1
2011 XMSS - A Practical Forward Secure Signature Scheme Based on Minimal Security Assumptions
Johannes Buchmann 0001, Erik Dahmen, Andreas Hülsing
PQCrypto3