EDBT 2026 Demo / reviewers in the wild / expert
Bertram Poettering
dblp:48/8243
· DBLP profile ↗
40ranked-venue papers
6as first author
6since 2021 · last 2024
0000-0001-6525-5141ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 40 · 6 first-author · 6 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Digital Signatures with Outsourced Hashing
Bertram Poettering, Simon Rastikian |
ASIACRYPT (2) | 1 |
| 2023 | Attribute-based Single Sign-On: Secure, Private, and EfficientabstractA Single Sign-On (SSO) system allows users to access different remote services while authenticating only once. SSO can greatly improve the usability and security of online activities by dispensing with the need to securely remember or store tens or hundreds of authentication secrets. On the downside, today's SSO providers can track users' online behavior, and collect personal data that service providers want to see asserted before letting a user access their resources. In this work, we propose a new policy-based Single Sign-On service, i.e., a system that produces access tokens that are conditioned on the user's attributes fulfilling a specified policy. Our solution is based on multi-party computation and threshold cryptography, and generates access tokens of standardized format. The central idea is to distribute the role of the SSO provider among several entities, in order to shield user attributes and access patterns from each individual entity. We provide a formal security model and analysis in the Universal Composability framework, against proactive adversaries. Our implementation and benchmarking show the practicality of our system for many real-world use cases. Tore Kasper Frederiksen, Julia Hesse, Bertram Poettering, Patrick Towa |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | On Secure Ratcheting with Immediate Decryption
Jeroen Pijnenburg, Bertram Poettering |
ASIACRYPT (3) | 2 |
| 2022 | Sequential Digital Signatures for Cryptographic Software-Update Authentication
Bertram Poettering, Simon Rastikian |
ESORICS (2) | 1 |
| 2021 | On the (In)Security of ElGamal in OpenPGPabstractRoughly four decades ago, Taher ElGamal put forward what is today one of the most widely known and best understood public key encryption schemes. ElGamal encryption has been used in many different contexts, chiefly among them by the OpenPGP standard. Despite its simplicity, or perhaps because of it, in reality there is a large degree of ambiguity on several key aspects of the cipher. Each library in the OpenPGP ecosystem seems to have implemented a slightly different "flavour" of ElGamal encryption. While --taken in isolation-- each implementation may be secure, we reveal that in the interoperable world of OpenPGP, unforeseen cross-configuration attacks become possible. Concretely, we propose different such attacks and show their practical efficacy by recovering plaintexts and even secret keys. Luca De Feo, Bertram Poettering, Alessandro Sorniotti |
CCS | 2 |
| 2021 | SoK: Game-Based Security Models for Group Key Exchange
Bertram Poettering, Paul Rösler, Jörg Schwenk, Douglas Stebila |
CT-RSA | 1 |
| 2020 | Encrypt-to-Self: Securely Outsourcing Storage
Jeroen Pijnenburg, Bertram Poettering |
ESORICS (1) | 2 |
| 2020 | Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering |
J. Cryptol. | 4 |
| 2019 | Cryptanalysis of OCB2: Attacks on Authenticity and Confidentiality
Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Bertram Poettering |
CRYPTO (1) | 4 |
| 2019 | Lossy Trapdoor Permutations with Improved Lossiness
Benedikt Auerbach, Eike Kiltz, Bertram Poettering, Stefan Schoenen |
CT-RSA | 3 |
| 2019 | Subverting Decryption in AEAD
Marcel Armour, Bertram Poettering |
IMACC | 2 |
| 2018 | Towards Bidirectional Ratcheted Key Exchange
Bertram Poettering, Paul Rösler |
CRYPTO (1) | 1 |
| 2018 | A Cryptographic Look at Multi-party ChannelsabstractCryptographic channels aim to enable authenticated and confidential communication over the Internet. The general understanding seems to be that providing security in the sense of authenticated encryption for every (unidirectional) point-to-point link suffices to achieve this goal. As recently shown (in FSE17/ToSC17), however, the security properties of the unidirectional links do not extend, in general, to the bidirectional channel as a whole. Intuitively, the reason for this is that the increased interaction in bidirectional communication can be exploited by an adversary. The same applies, a fortiori, in a multi-party setting where several users operate concurrently and the communication develops in more directions. In the cryptographic literature, however, the targeted goals for group communication in terms of channel security are still unexplored. Applying the methodology of provable security, we fill this gap by defining exact (game-based) authenticity and confidentiality goals for broadcast communication, and showing how to achieve them. Importantly, our security notions also account for the causal dependencies between exchanged messages, thus naturally extending the bidirectional case where causal relationships are automatically captured by preserving the sending order. On the constructive side we propose a modular and yet efficient protocol that, assuming only point-to-point links between users, leverages (non-cryptographic) broadcast and standard cryptographic primitives to a full-fledged broadcast channel that provably meets the security notions we put forth. Patrick Eugster, Giorgia Azzurra Marson, Bertram Poettering |
CSF | 3 |
| 2017 | On the One-Per-Message Unforgeability of (EC)DSA and Its Variants
Manuel Fersch, Eike Kiltz, Bertram Poettering |
TCC (2) | 3 |
| 2017 | Cryptographic enforcement of information flow policies without public information via tree partitionsabstractWe may enforce an information flow policy by encrypting a protected resource and ensuring that only users authorized by the policy are able to decrypt the resource. In most schemes in the literature that use symmetric cryptographic primitives, each user is assigned a single secret and derives decry ption keys using this secret and publicly available information. Recent work has challenged this approach by developing schemes, based on a chain partition of the information flow policy, that do not require public information for key derivation, the trade-off being that a user may need to be assigned more than one secret. In general, many different chain partitions exist for the same policy and, until now, it was not known how to compute an appropriate one. In this paper, we introduce the notion of a tree partition, of which chain partitions are a special case. We show how a tree partition may be used to define a cryptographic enforcement scheme and prove that such schemes can be instantiated in such a way as to preserve the strongest security properties known for cryptographic enforcement schemes. We establish a number of results linking the amount of secret material that needs to be distributed to users with a weighted acyclic graph derived from the tree partition. These results enable us to develop efficient algorithms for deriving tree and chain partitions that minimize the total amount of secret material that needs to be distributed. Jason Crampton, Naomi Farley, Gregory Z. Gutin, Mark Jones 0001, Bertram Poettering |
J. Comput. Secur. | 5 |
| 2016 | From Identification to Signatures, Tightly: A Framework and Generic Transforms
Mihir Bellare, Bertram Poettering, Douglas Stebila |
ASIACRYPT (2) | 2 |
| 2016 | Selective Opening Security from Simulatable Data Encapsulation
Felix Heuer, Bertram Poettering |
ASIACRYPT (2) | 2 |
| 2016 | On the Provable Security of (EC)DSA SignaturesabstractAmong the signature schemes most widely deployed in practice are the DSA (Digital Signature Algorithm) and its elliptic curves variant ECDSA. They are represented in many international standards, including IEEE P1363, ANSI X9.62, and FIPS 186-4. Their popularity stands in stark contrast to the absence of rigorous security analyses: Previous works either study modified versions of (EC)DSA or provide a security analysis of unmodified ECDSA in the generic group model. Unfortunately, works following the latter approach assume abstractions of non-algebraic functions over generic groups for which it remains unclear how they translate to the security of ECDSA in practice. For instance, it has been pointed out that prior results in the generic group model actually establish strong unforgeability of ECDSA, a property that the scheme de facto does not possess. As, further, no formal results are known for DSA, understanding the security of both schemes remains an open problem. In this work we propose GenericDSA, a signature framework that subsumes both DSA and ECDSA in unmodified form. It carefully models the "modulo q" conversion function of (EC)DSA as a composition of three independent functions. The two outer functions mimic algebraic properties in the function's domain and range, the inner one is modeled as a bijective random oracle. We rigorously prove results on the security of GenericDSA that indicate that forging signatures in (EC)DSA is as hard as solving discrete logarithms. Importantly, our proofs do not assume generic group behavior. Manuel Fersch, Eike Kiltz, Bertram Poettering |
CCS | 3 |
| 2015 | Linkable Message Tagging: Solving the Key Distribution Problem of Signature Schemes
Felix Günther 0001, Bertram Poettering |
ACISP | 2 |
| 2015 | Cryptographic Enforcement of Information Flow Policies Without Public Information
Jason Crampton, Naomi Farley, Gregory Z. Gutin, Mark Jones 0001, Bertram Poettering |
ACNS | 5 |
| 2015 | Cold Boot Attacks in the Discrete Logarithm Setting
Bertram Poettering, Dale L. Sibborn |
CT-RSA | 1 |
| 2015 | A More Cautious Approach to Security Against Mass Surveillance
Jean Paul Degabriele, Pooya Farshim, Bertram Poettering |
FSE | 3 |
| 2014 | Big Bias Hunting in Amazonia: Large-Scale Computation and Exploitation of RC4 Biases (Invited Paper)
Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt |
ASIACRYPT (1) | 2 |
| 2014 | Multi-recipient encryption, revisitedabstractA variant of public key encryption that promises efficiency gains due to batch processing is multi-recipient public key encryption (MR-PKE). Precisely, in MR-PKE, a dedicated encryption routine takes a vector of messages and a vector of public keys and outputs a vector of ciphertexts, where the latter can be decrypted individually, as in regular PKE. In this paper we revisit the established security notions of MR-PKE and the related primitive MR-KEM. We identify a subtle flaw in a security model by Bellare, Boldyreva, and Staddon, that also appears in later publications by different authors. We further observe that these security models rely on the knowledge-of-secret-key (KOSK) assumption---a requirement that is rarely met in practice. We resolve this situation by proposing strengthened security notions for MR-PKE and MR-KEMs, together with correspondingly secure yet highly efficient schemes. Importantly, our models abstain from restricting the set of considered adversaries in the way prior models did, and in particular do not require the KOSK setting. We prove our constructions secure assuming hardness of the static Diffie-Hellman problem, in the random oracle model. Alexandre Miranda Pinto, Bertram Poettering, Jacob C. N. Schuldt |
AsiaCCS | 2 |
| 2014 | Even More Practical Secure Logging: Tree-Based Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering |
ESORICS (2) | 2 |
| 2014 | Double-Authentication-Preventing Signatures
Bertram Poettering, Douglas Stebila |
ESORICS (1) | 1 |
| 2014 | Plaintext Recovery Attacks Against WPA/TKIP
Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt |
FSE | 2 |
| 2013 | Pseudorandom signaturesabstractWe develop a three-level hierarchy of privacy notions for (unforgeable) digital signature schemes. We first prove mutual independence of existing notions of anonymity and confidentiality, and then show that these are implied by higher privacy goals. The top notion in our hierarchy is pseudorandomness: signatures with this property hide the entire information about the signing process and cannot be recognized as signatures when transmitted over a public network. This implies very strong unlinkability guarantees across different signers and even different signing algorithms, and gives rise to new forms of private public-key authentication. Nils Fleischhacker, Felix Günther 0001, Franziskus Kiefer, Mark Manulis, Bertram Poettering |
AsiaCCS | 5 |
| 2013 | Simple, Efficient and Strongly KI-Secure Hierarchical Key Assignment Schemes
Eduarda S. V. Freire 0001, Kenneth G. Paterson, Bertram Poettering |
CT-RSA | 3 |
| 2013 | ASICS: Authenticated Key Exchange Security Incorporating Certification Systems
Colin Boyd, Cas Cremers, Michèle Feltz, Kenneth G. Paterson, Bertram Poettering, Douglas Stebila |
ESORICS | 5 |
| 2013 | Practical Secure Logging: Seekable Sequential Key Generators
Giorgia Azzurra Marson, Bertram Poettering |
ESORICS | 2 |
| 2013 | On the Security of RC4 in TLS
Nadhem J. AlFardan, Daniel J. Bernstein, Kenneth G. Paterson, Bertram Poettering, Jacob C. N. Schuldt |
USENIX Security Symposium | 4 |
| 2013 | Publicly verifiable ciphertexts
Juan Manuel González Nieto, Mark Manulis, Bertram Poettering, Jothi Rangasamy, Douglas Stebila |
J. Comput. Secur. | 3 |
| 2011 | Private Discovery of Common Social Contacts
Emiliano De Cristofaro, Mark Manulis, Bertram Poettering |
ACNS | 3 |
| 2011 | Practical affiliation-hiding authentication from improved polynomial interpolationabstractAmong the plethora of privacy-friendly authentication techniques, affiliation-hiding (AH) protocols are valuable for their ability to hide not only identities of communicating users behind their affiliations (memberships to groups), but also these affiliations from non-members. These qualities become increasingly important in our highly computerized user-centric information society, where privacy is an elusive good. Mark Manulis, Bertram Poettering |
AsiaCCS | 2 |
| 2011 | Affiliation-Hiding Authentication with Minimal Bandwidth Consumption
Mark Manulis, Bertram Poettering |
WISTP | 2 |
| 2010 | Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder |
ACNS | 10 |
| 2010 | Privacy-Preserving Group Discovery with Linear Complexity
Mark Manulis, Benny Pinkas, Bertram Poettering |
ACNS | 3 |
| 2010 | Affiliation-Hiding Key Exchange with Untrusted Group Authorities
Mark Manulis, Bertram Poettering, Gene Tsudik |
ACNS | 2 |
| 2010 | Taming Big Brother Ambitions: More Privacy for Secret Handshakes
Mark Manulis, Bertram Poettering, Gene Tsudik |
Privacy Enhancing Technologies | 2 |