EDBT 2026 Demo / reviewers in the wild / expert
Christian Rechberger
dblp:39/16
· DBLP profile ↗
70ranked-venue papers
1as first author
17since 2021 · last 2026
0000-0003-1280-6020ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 66 · 1 first-author · 17 since 2021Systems, architecture and hardware · 3Software engineering, systems software and programming languages · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Random Variable Commitments for Any Sampleable Distribution, and a Certified Laplace Mechanism
Fredrik Meisingseth, Christian Rechberger, Fabian Schmid |
CRYPTO (10) | 2 |
| 2025 | Cache Timing Leakages in Zero-Knowledge Protocols
Shibam Mukherjee, Christian Rechberger, Markus Schofnegger |
AFT | 2 |
| 2025 | webSPDZ: Versatile MPC on the Web
Thomas Buchsteiner, Karl W. Koch, Dragos Rotaru, Christian Rechberger |
CANS | 4 |
| 2025 | Shorter, Tighter, FAESTer: Optimizations and Improved (QROM) Analysis for VOLE-in-the-Head Signatures
Carsten Baum, Ward Beullens, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Christian Majenz, Shibam Mukherjee, Emmanuela Orsini, Sebastian Ramacher, Christian Rechberger, Lawrence Roy, Peter Scholl |
CRYPTO (6) | 10 |
| 2025 | Leap: A Fast, Lattice-Based OPRF with Application to Private Set Intersection
Lena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir, Sebastian Ramacher, Christian Rechberger |
EUROCRYPT (7) | 6 |
| 2025 | SoK: Computational and Distributed Differential Privacy for MPCabstractIn the last fifteen years, there has been a steady stream of works combining differential privacy with various other cryptographic disciplines, particularly that of multi-party computation, yielding both practical and theoretical unification. As a part of that unification, due to the rich definitional nature of both fields, there have been many proposed definitions of differential privacy adapted to the given use cases and cryptographic tools at hand, resulting in computational and/or distributed versions of differential privacy. In this work, we offer a systemisation of such definitions, with a focus on definitions that are both computational and tailored for a multi-party setting. We order the definitions according to the distribution model and computational perspective and propose a viewpoint on when given definitions should be seen as instantiations of the same generalised notion. The ordering highlights a clear, and sometimes strict, hierarchy between the definitions, where utility (accuracy) can be traded for stronger privacy guarantees or lesser trust assumptions. Further, we survey theoretical results relating the definitions and extend some of them. We also discuss the state of well-known open questions and suggest new open problems to study. Finally, we consider aspects of the practical use of the different notions, hopefully giving guidance also to future applied work. Fredrik Meisingseth, Christian Rechberger |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Practical Two-party Computational Differential Privacy with Active SecurityabstractIn this work we revisit the problem of using general-purpose MPC schemes to emulate the trusted dataholder in differential privacy (DP), to achieve the same accuracy but without the need to trust one single dataholder. In particular, we consider the two-party model where two computational parties (or dataholders), each with their own dataset, wish to compute a canonical DP mechanism on their combined data and to do so with active security. We start by remarking that available definitions of computational DP (CDP) for protocols are somewhat ill-suited for such a use-case, due to them either poorly capturing some strong security guarantees commonly given by general-purpose MPC protocols, or having too strict requirements in the sense that they need significant adjustment in order to be satisfiable by using common DP and MPC techniques. With this in mind, we propose a new version of simulation-based CDP, called SIM*-CDP, and prove it to be stronger than the IND-CDP and SIM-CDP and incomparable to SIM+-CDP. We demonstrate the usability of the SIM*-CDP definition by showing how to satisfy it by the use of an available distributed protocol for sampling truncated geometric noise. Further, we use the protocol to compute two-party inner-products with CDP and active security, and with accuracy equal to that of the central model, being the first to do so. Finally, we provide an open-sourced implementation and benchmark its practical performance. Our implementation generates a truncated geometric sample in between about 0.035 and 3.5 seconds (amortized), depending on network and parameter settings, comparing favourably to existing implementations. Fredrik Meisingseth, Christian Rechberger, Fabian Schmid |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | OPRFs from Isogenies: Designs and AnalysisabstractOblivious Pseudorandom Functions (OPRFs) are an elementary building block in cryptographic and privacy-preserving applications. While there are numerous pre-quantum secure OPRF constructions, it is unclear which of the proposed options for post-quantum secure constructions are practical for modern-day applications. In this work, we focus on isogeny group actions, as the associated low bandwidth leads to efficient constructions. We introduce OPUS, a novel Naor-Reingold-based OPRF from isogenies without oblivious transfer, and show efficient evaluations of the Naor-Reingold PRF using CSIDH and CSI-FiSh. Additionally, we analyze a previous proposal of a CSIDH-based OPRF and that the straightforward instantiation of the protocol leaks the server's private key. As a result, we propose mitigations to address those shortcomings, which require additional hardness assumptions. Our results report a very competitive protocol when combined with lattices for Oblivious Transfer. Lena Heimberger, Tobias Hennerbichler, Fredrik Meisingseth, Sebastian Ramacher, Christian Rechberger |
AsiaCCS | 5 |
| 2024 | One Tree to Rule Them All: Optimizing GGM Trees and OWFs for Post-Quantum Signatures
Carsten Baum, Ward Beullens, Shibam Mukherjee, Emmanuela Orsini, Sebastian Ramacher, Christian Rechberger, Lawrence Roy, Peter Scholl |
ASIACRYPT (1) | 6 |
| 2024 | Minimize the Randomness in Rasta-Like Designs: How Far Can We Go? - Application to Pasta
Lorenzo Grassi 0001, Fukang Liu, Christian Rechberger, Fabian Schmid, Roman Walch, Qingju Wang 0001 |
SAC (2) | 3 |
| 2024 | Hiding Your Awful Online Choices Made More Efficient and Secure: A New Privacy-Aware Recommender System
Shibam Mukherjee, Roman Walch, Fredrik Meisingseth, Elisabeth Lex, Christian Rechberger |
SEC | 5 |
| 2023 | Horst Meets Fluid-SPN: Griffin for Zero-Knowledge Applications
Lorenzo Grassi 0001, Yonglin Hao, Christian Rechberger, Markus Schofnegger, Roman Walch, Qingju Wang 0001 |
CRYPTO (3) | 3 |
| 2022 | Truncated Differential Properties of the Diagonal Set of Inputs for 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger |
ACISP | 2 |
| 2022 | Reinforced Concrete: A Fast Hash Function for Verifiable ComputationabstractWe propose a new hash function Reinforced Concrete, which is the first generic purpose hash that is fast both for a zero-knowledge prover and in native x86 computations. It is suitable for a various range of zero-knowledge proofs and protocols, from set membership to generic purpose verifiable computation. Being up to 15x faster than its predecessor Poseidon hash, Reinforced Concrete inherits security from traditional time-tested schemes such as AES, whereas taking the zero-knowledge performance from a novel and efficient decomposition of a prime field into compact buckets. Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger, Roman Walch |
CCS | 4 |
| 2022 | Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key CryptoabstractSignature schemes based on the MPC-in-the-head approach (MPCitH) have either been designed by taking a proof system and selecting a suitable symmetric-key primitive (Picnic, CCS16), or starting with an existing primitive such as AES and trying to find the most suitable proof system (BBQ, SAC19 or Banquet, PKC21). In this work we do both: we improve certain symmetric-key primitives to better fit existing signature schemes, and we also propose a new signature scheme that combines a new, minimalist one-way function with changes to a proof system to make their combination even more efficient. Our concrete results are as follows. Christoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger, Gregory M. Zaverucha |
CCS | 3 |
| 2022 | Privately Connecting Mobility to Infectious Diseases via Applied CryptographyabstractRecent work has shown that cell phone mobility data has the unique potential to create accurate models for human mobility and consequently the spread of infected diseases [74]. While prior studies have exclusively relied on a mobile network operator’s subscribers’ aggregated data in modelling disease dynamics, it may be preferable to contemplate aggregated mobility data of infected individuals only. Clearly, naively linking mobile phone data with health records would violate privacy by either allowing to track mobility patterns of infected individuals, leak information on who is infected, or both. This work aims to develop a solution that reports the aggregated mobile phone location data of infected individuals while still maintaining compliance with privacy expectations. To achieve privacy, we use homomorphic encryption, validation techniques derived from zero-knowledge proofs, and differential privacy. Our protocol’s open-source implementation can process eight million subscribers in 70 minutes. Alexandros Bampoulidis, Alessandro Bruni, Lukas Helminger, Daniel Kales, Christian Rechberger, Roman Walch |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Poseidon: A New Hash Function for Zero-Knowledge Proof Systems
Lorenzo Grassi 0001, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 0005, Markus Schofnegger |
USENIX Security Symposium | 3 |
| 2020 | An Algebraic Attack on Ciphers with Low-Degree Round Functions: Application to Full MiMC
Maria Eichlseder, Lorenzo Grassi 0001, Reinhard Lüftenegger, Morten Øygarden, Christian Rechberger, Markus Schofnegger, Qingju Wang 0001 |
ASIACRYPT (1) | 5 |
| 2020 | Efficient FPGA Implementations of LowMC and Picnic
Daniel Kales, Sebastian Ramacher, Christian Rechberger, Roman Walch, Mario Werner |
CT-RSA | 3 |
| 2020 | On a Generalization of Substitution-Permutation Networks: The HADES Design Strategy
Lorenzo Grassi 0001, Reinhard Lüftenegger, Christian Rechberger, Dragos Rotaru, Markus Schofnegger |
EUROCRYPT (2) | 3 |
| 2020 | Weak-Key Distinguishers for AES
Lorenzo Grassi 0001, Gregor Leander, Christian Rechberger, Cihangir Tezcan, Friedrich Wiemer |
SAC | 3 |
| 2020 | Revisiting Gilbert's known-key distinguisherabstractAbstract Known-key distinguishers have been introduced by Knudsen and Rijmen in 2007 to better understand the security of block ciphers in situations where the key can not be considered to be secret, i.e. the “thing between secret-key model and hash function use-cases”. Trying to find a rigorous model to fit this intuition is still ongoing. The most recent advance by Gilbert (Asiacrypt 2014) describes a new model that—even if it is well justified—seemingly does not match this intuition. AES is often considered as a target of such analyses, simply because AES or its building blocks are used in many settings that go beyond classical encryption. Consider AES-128. Results in the secret-key model cover up to 6 rounds, while results in the chosen-key model reach up to 9 rounds. Gilbert however showed a result in the known-key model that goes even further, covering 10 rounds. Does it mean that the use cases corresponding to the cryptanalysis of hash-function use-cases are inherently less efficient, or is it rather an artifact of the new model? In this paper we give strong evidence for the latter. In Gilbert’s work, two types of arguments or rather conjectures are put forward suggesting that the new model is meaningful. Firstly that the number of “extension rounds” due to the new model is limited to two. And secondly that only a distinguisher that exploits the uniform distribution property can be extended in such way. We disprove both conjectures and arrive at the following results: First, we are also able to show that more than two extension rounds are possible. As a result of this, we describe the first known-key distinguishers on 12 rounds of AES that fit into Gilbert’s model. The second conjecture is disproven by showing that the technique proposed by Gilbert can also be used to extend a known-key distinguisher based on another property: truncated differentials. A potential conclusion of this work would be that the counter-intuitive gap between Gilbert’s known-key model and the chosen-key model is wider than initially thought. We however conclude that results in Gilbert’s model are due to an artifact in the model. To remedy this situation, we propose a refinement of the known-key model which restores its original intent to fit the original intuition. Lorenzo Grassi 0001, Christian Rechberger |
Des. Codes Cryptogr. | 2 |
| 2020 | Framework for faster key search using related-key higher-order differential properties: applications to AgrastaabstractThe relevance of the related‐key model is usually controversial. However, in some cases, related‐key properties have already been used to reduce the effective key length of the cipher in the single‐key model. Hence, research into this direction can be helpful to bridge the gap between theory and practice aspects of the related‐key model. Motivated by this challenge, the authors develop a new framework to provide further evidence that deterministic related‐key characteristics can be utilised in the single‐key model. The authors describe a sound framework for utilising related‐key higher‐order differential distinguishers that can beat the boundaries given by exhaustive key search. The data required is only one known as plaintext–ciphertext pair if the number of ciphertext bits matches the key length. From a theoretical point of view, the connection between related‐key higher‐order differential properties and the security of cryptographic primitives in the single‐key model are precised. From a practical point of view, the proposed framework is used to evaluate the security of Agrasta cipher which is a variant of Rasta cipher presented at CRYPTO 2018. The proposed method is the first analysis of Agrasta reduced to three rounds that performs better than exhaustive key search and is independent of the used linear layers. Christoph Dobraunig, Farokhlagha Moazami, Christian Rechberger, Hadi Soleimany |
IET Inf. Secur. | 3 |
| 2019 | Algebraic Cryptanalysis of STARK-Friendly Designs: Application to MARVELlous and MiMC
Martin R. Albrecht, Carlos Cid, Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger |
ASIACRYPT (3) | 6 |
| 2019 | Feistel Structures for MPC, and More
Martin R. Albrecht, Lorenzo Grassi 0001, Léo Perrin, Sebastian Ramacher, Christian Rechberger, Dragos Rotaru, Arnab Roy 0005, Markus Schofnegger |
ESORICS (2) | 5 |
| 2019 | Linear Equivalence of Block Ciphers with Partial Non-Linear Layers: Application to LowMC
Itai Dinur, Daniel Kales, Angela Promitzer, Sebastian Ramacher, Christian Rechberger |
EUROCRYPT (1) | 5 |
| 2019 | Mobile Private Contact Discovery at Scale
Daniel Kales, Christian Rechberger, Thomas Schneider 0003, Matthias Senker, Christian Weinert |
USENIX Security Symposium | 2 |
| 2018 | Rasta: A Cipher with Low ANDdepth and Few ANDs per Bit
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi 0001, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger |
CRYPTO (1) | 8 |
| 2018 | Zero-Sum Partitions of PHOTON Permutations
Qingju Wang 0001, Lorenzo Grassi 0001, Christian Rechberger |
CT-RSA | 3 |
| 2017 | Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesabstractWe propose a new class of post-quantum digital signature schemes that: (a) derive their security entirely from the security of symmetric-key primitives, believed to be quantum-secure, and (b) have extremely small keypairs, and, (c) are highly parameterizable. Melissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi, Sebastian Ramacher, Christian Rechberger, Daniel Slamanig, Gregory M. Zaverucha |
CCS | 6 |
| 2017 | A New Structural-Differential Property of 5-Round AES
Lorenzo Grassi 0001, Christian Rechberger, Sondre Rønjom |
EUROCRYPT (2) | 2 |
| 2016 | MiMC: Efficient Encryption and Cryptographic Hashing with Minimal Multiplicative Complexity
Martin R. Albrecht, Lorenzo Grassi 0001, Christian Rechberger, Arnab Roy 0005, Tyge Tiessen |
ASIACRYPT (1) | 3 |
| 2016 | MPC-Friendly Symmetric Key PrimitivesabstractWe discuss the design of symmetric primitives, in particular Pseudo-Random Functions (PRFs) which are suitable for use in a secret-sharing based MPC system. We consider three different PRFs: the Naor-Reingold PRF, a PRF based on the Legendre symbol, and a specialized block cipher design called MiMC. We present protocols for implementing these PRFs within a secret-sharing based MPC system, and discuss possible applications. We then compare the performance of our protocols. Depending on the application, different PRFs may offer different optimizations and advantages over the classic AES benchmark. Thus, we cannot conclude that there is one optimal PRF to be used in all situations. Lorenzo Grassi 0001, Christian Rechberger, Dragos Rotaru, Peter Scholl, Nigel P. Smart |
CCS | 2 |
| 2015 | Analyzing Permutations for AES-like Ciphers: Understanding ShiftRows
Christof Beierle, Philipp Jovanovic, Martin M. Lauridsen, Gregor Leander, Christian Rechberger |
CT-RSA | 5 |
| 2015 | New ASIC/FPGA Cost Estimates for SHA-1 CollisionsabstractSHA-1 remains, till date, the most widely used hash function, in spite of several successful cryptanalytic attacks against it. These attacks, however, remain impractical due to high computation complexity and associated cost. We endeavor to do cost-time product estimation for an attack by the aid of application-specific hardware acceleration. This work proposes an Application-Specific Instruction-set Processor (ASIP), named Cracken. Cracken is aimed to efficiently realize near collision attack on SHA-1. The estimations of the physical attack complexity is done using 65nm standard CMOS technology and commercial FPGA devices. It is estimated, with post-layout simulations, that Stevens' differential attack with an estimated complexity of 2^57.5, can be executed in 46 days using 4096 Cracken cores at a cost of Euros 15m. Estimation for real collision with complexity 2^61 is also done. Our cost-time estimates reveal that an FPGA-based attack is more efficient compared to ASIC. Previously reported SHA-1 attacks based on ASIC and cloud computing platforms are also compiled and benchmarked for reference. Ayesha Khalid, Anupam Chattopadhyay, Christian Rechberger, Tim Güneysu, Christof Paar |
DSD | 4 |
| 2015 | Ciphers for MPC and FHE
Martin R. Albrecht, Christian Rechberger, Thomas Schneider 0003, Tyge Tiessen, Michael Zohner |
EUROCRYPT (1) | 2 |
| 2015 | Linear Distinguishers in the Key-less Setting: Application to PRESENT
Martin M. Lauridsen, Christian Rechberger |
FSE | 2 |
| 2015 | The Rebound Attack and Subspace Distinguishers: Application to Whirlpool
Mario Lamberger, Florian Mendel, Martin Schläffer, Christian Rechberger, Vincent Rijmen |
J. Cryptol. | 4 |
| 2014 | Rotational Rebound Attacks on Reduced Skein
Dmitry Khovratovich, Ivica Nikolic, Christian Rechberger |
J. Cryptol. | 3 |
| 2013 | The LOCAL Attack: Cryptanalysis of the Authenticated Encryption Scheme ALE
Dmitry Khovratovich, Christian Rechberger |
Selected Areas in Cryptography | 2 |
| 2012 | PRINCE - A Low-Latency Block Cipher for Pervasive Computing Applications - Extended Abstract
Julia Borghoff, Anne Canteaut, Tim Güneysu, Elif Bilge Kavun, Miroslav Knezevic, Lars R. Knudsen, Gregor Leander, Ventzislav Nikov, Christof Paar, Christian Rechberger, Peter Rombouts, Søren S. Thomsen, Tolga Yalçin |
ASIACRYPT | 10 |
| 2012 | Narrow-Bicliques: Cryptanalysis of Full IDEA
Dmitry Khovratovich, Gaëtan Leurent, Christian Rechberger |
EUROCRYPT | 3 |
| 2012 | Bicliques for Preimages: Attacks on Skein-512 and the SHA-2 Family
Dmitry Khovratovich, Christian Rechberger, Alexandra Savelieva |
FSE | 2 |
| 2012 | Improved Cryptanalysis of the Block Cipher KASUMI
Keting Jia, Leibo Li, Christian Rechberger, Jiazhe Chen, Xiaoyun Wang 0001 |
Selected Areas in Cryptography | 3 |
| 2011 | Improved Meet-in-the-Middle Cryptanalysis of KTANTAN (Poster)
Lei Wei 0001, Christian Rechberger, Jian Guo 0001, Hongjun Wu 0001, Huaxiong Wang, San Ling |
ACISP | 2 |
| 2011 | Biclique Cryptanalysis of the Full AES
Andrey Bogdanov, Dmitry Khovratovich, Christian Rechberger |
ASIACRYPT | 3 |
| 2010 | Second-Preimage Analysis of Reduced SHA-1
Christian Rechberger |
ACISP | 1 |
| 2010 | Advanced Meet-in-the-Middle Preimage Attacks: First Results on Full Tiger, and Improved Results on MD4 and SHA-2
Jian Guo 0001, San Ling, Christian Rechberger, Huaxiong Wang |
ASIACRYPT | 3 |
| 2010 | Rotational Rebound Attacks on Reduced Skein
Dmitry Khovratovich, Ivica Nikolic, Christian Rechberger |
ASIACRYPT | 3 |
| 2010 | Rebound Attacks on the Reduced Grøstl Hash Function
Florian Mendel, Christian Rechberger, Martin Schläffer, Søren S. Thomsen |
CT-RSA | 2 |
| 2009 | Cryptanalysis of Twister
Florian Mendel, Christian Rechberger, Martin Schläffer |
ACNS | 2 |
| 2009 | Rebound Distinguishers: Results on the Full Whirlpool Compression Function
Mario Lamberger, Florian Mendel, Christian Rechberger, Vincent Rijmen, Martin Schläffer |
ASIACRYPT | 3 |
| 2009 | MD5 Is Weaker Than Weak: Attacks on Concatenated Combiners
Florian Mendel, Christian Rechberger, Martin Schläffer |
ASIACRYPT | 2 |
| 2009 | Cryptanalysis of MDC-2
Lars R. Knudsen, Florian Mendel, Christian Rechberger, Søren S. Thomsen |
EUROCRYPT | 3 |
| 2009 | The Rebound Attack: Cryptanalysis of Reduced Whirlpool and Grøstl
Florian Mendel, Christian Rechberger, Martin Schläffer, Søren S. Thomsen |
FSE | 2 |
| 2008 | Preimages for Reduced SHA-0 and SHA-1
Christophe De Cannière, Christian Rechberger |
CRYPTO | 2 |
| 2008 | Cryptanalysis of the GOST Hash Function
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Marcin Kontak, Janusz Szmidt |
CRYPTO | 3 |
| 2008 | New Features of Latin Dances: Analysis of Salsa, ChaCha, and Rumba
Jean-Philippe Aumasson, Simon Fischer 0002, Shahram Khazaei, Willi Meier, Christian Rechberger |
FSE | 5 |
| 2008 | A (Second) Preimage Attack on the GOST Hash Function
Florian Mendel, Norbert Pramstaller, Christian Rechberger |
FSE | 3 |
| 2008 | Analysis of the Hash Function Design Strategy Called SMASHabstractThe hash function design strategy SMASH was recently proposed as an alternative to the MD4 family of hash functions. It can be shown that the strategy leads to designs that are vulnerable to efficient collision and (second) preimage attacks. The mathematical structure of the SMASH description facilitates the description of the weakness and the resulting attacks, but also functions with less mathematical elegance may show similar weaknesses. Mario Lamberger, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
IEEE Trans. Inf. Theory | 3 |
| 2007 | Second Preimages for SMASH
Mario Lamberger, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
CT-RSA | 3 |
| 2007 | Energy evaluation of software implementations of block ciphers under memory constraints
Johann Großschädl, Stefan Tillich, Christian Rechberger, Michael Hofmann 0007, Marcel Medwed |
DATE | 3 |
| 2007 | The Grindahl Hash Functions
Lars R. Knudsen, Christian Rechberger, Søren S. Thomsen |
FSE | 2 |
| 2006 | Finding SHA-1 Characteristics: General Results and Applications
Christophe De Cannière, Christian Rechberger |
ASIACRYPT | 2 |
| 2006 | A compact FPGA implementation of the hash function whirlpoolabstractRecent breakthroughs in cryptanalysis of standard hash functions like SHA-1 and MD5 raise the need for alternatives. A credible alternative to for instance SHA-1 or the SHA-2 family of hash functions is Whirlpool. Whirlpool is a hash function that has been evaluated and approved by NESSIE and is standardized by ISO/IEC. To the best of our knowledge only one FPGA implementation of Whirlpool has been published to date. This implementation is designed for high throughput rates requiring a considerable amount of hardware resources. In this article we present a compact hardware implementation of the hash function Whirlpool. The proposed architecture uses an innovative state representation that makes it possible to reduce the required hardware resources remarkably. The complete implementation requires 1456 CLB-slices and, most notably, no block RAMs. Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
FPGA | 2 |
| 2006 | Analysis of Step-Reduced SHA-256
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
FSE | 3 |
| 2006 | The Impact of Carries on the Complexity of Collision Attacks on SHA-1
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
FSE | 3 |
| 2006 | Threshold Implementations Against Side-Channel Attacks and Glitches
Svetla Nikova, Christian Rechberger, Vincent Rijmen |
ICICS | 2 |
| 2006 | On the Collision Resistance of RIPEMD-160
Florian Mendel, Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
ISC | 3 |
| 2005 | Exploiting Coding Theory for Collision Attacks on SHA-1
Norbert Pramstaller, Christian Rechberger, Vincent Rijmen |
IMACC | 2 |