EDBT 2026 Demo / reviewers in the wild / expert
Elena Andreeva 0001
dblp:50/4172-1
· DBLP profile ↗
31ranked-venue papers
22as first author
12since 2021 · last 2026
0000-0003-0964-8711ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 22 first-author · 12 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PUE Schemes: Efficient Updatable Encryption With Robust Security From Symmetric PrimitivesabstractSecuring sensitive data for long-term storage in the cloud is a challenging problem. Updatable encryption (UE) enables changing the encryption key of encrypted data in the cloud while the plaintext and all versions of the key remain secret from the cloud storage provider, making it an efficient alternative for companies that seek to outsource their data storage. Andreas Weninger, Elena Andreeva 0001 |
AsiaCCS | 2 |
| 2025 | Sonikku: Gotta Speed, Keed! A Family of Fast and Secure MACs
Amit Singh Bhati, Elena Andreeva 0001, Damian Vizár |
CANS | 2 |
| 2025 | Breaking the IEEE Encryption Standard XCB-AES in Two Queries
Amit Singh Bhati, Elena Andreeva 0001 |
CRYPTO (5) | 2 |
| 2025 | Multiforked Iterated Even-Mansour and a Note on the Tightness of IEM Proofs
Elena Andreeva 0001, Amit Singh Bhati, Andreas Weninger |
SAC | 1 |
| 2024 | Masked Iterate-Fork-Iterate: A New Design Paradigm for Tweakable Expanding Pseudorandom Function
Elena Andreeva 0001, Benoit Cogliati, Virginie Lallemand, Marine Minier, Antoon Purnal, Arnab Roy 0005 |
ACNS (2) | 1 |
| 2024 | Skye: An Expanding PRF based Fast KDF and its ApplicationsabstractA Key Derivation Function (KDF) generates a uniform and highly random key-stream from weakly random key material. KDFs are broadly used in various security protocols such as digital signatures and key exchange protocols. HKDF, the most deployed KDF in practice, is based on the extract-then-expand paradigm. It is presently used, among others, in the Signal Protocol for end-to-end encrypted messaging. Amit Singh Bhati, Antonin Dufka, Elena Andreeva 0001, Arnab Roy 0005, Bart Preneel |
AsiaCCS | 3 |
| 2024 | On Efficient and Secure Compression Functions for Arithmetization-Oriented HashingabstractZK-SNARKs, a fundamental component of privacyoriented payment systems, identity protocols, or anonymous voting systems, are advanced cryptographic protocols for verifiable computation: modern SNARKs allow to encode the invariants of a program, expressed as an arithmetic circuit, in an appropriate constraint language from which short, zero-knowledge proofs for correct computations can be constructed. One of the most important computations that is run through SNARK systems is the verification of Merkle tree (MT) opening proofs, which relies on the evaluation of a fixed-input-length (FIL) cryptographic compression function over binary MTs. As classical, bit-oriented hash functions like SHA-2 are not compactly representable in SNARK frameworks, Arithmetization-Oriented (AO) cryptographic designs have emerged as an alternative, efficient solution. Today, the majority of AO compression functions are built from permutation-based hashing modes, such as Sponge. While this approach allows cost savings, compared to blockcipher-based modes, as it does not require key-scheduling, AO blockcipher schedulers are often cheap to compute. Furthermore, classical bitoriented cryptography has long studied how to construct provably secure compression functions from blockciphers, following the Preneel-Govaerts-Vandewalle (PGV) framework. The potential efficiency gains together with the strong provable security foundations in the classic setting, motivate the study of AO blockcipher-based compression functions. In this work, we propose AO PGV-LC and PGV-ELC, two AO blockcipher-based FIL compression modes inspired by and extending the classical PGV approach, offering flexible input and output sizes and coming with provable security guarantees in the AO setting. We prove the collision and preimage resistance in the ideal cipher model, and give bounds for collision and opening resistance over MTs of arbitrary arity. We compare experimentally the AO PGV-ELC mode over the HADES blockcipher with its popular and widely adopted Sponge instantiation, POSEIDON, and its improved variant POSEIDON2. Our resulting constructions are up to 3× faster than POSEIDONAND 2× faster than POSEIDON2 in native x86 execution, and up to 50% faster in the Groth16 SNARK framework. Finally, we study the benefits of using MTs of arity wider than two, proposing a new strategy to obtain a compact R1CS constraint system in such case. In fact, by combining an efficient parametrization of the HADES blockcipher over the PGV-ELC mode, together with an optimal choice of the MT arity, we measured an improvement of up to 9× in native MT construction time, and up to 2.5× in proof generation time, compared to POSEIDON over binary MTs. Elena Andreeva 0001, Rishiraj Bhattacharyya, Arnab Roy 0005, Stefano Trevisani |
CSF | 1 |
| 2024 | Quantum cryptanalysis of Farfalle and (generalised) key-alternating Feistel networks
Samir Hodzic, Arnab Roy 0005, Elena Andreeva 0001 |
Des. Codes Cryptogr. | 3 |
| 2024 | The COLM Authenticated Encryption Scheme
Elena Andreeva 0001, Andrey Bogdanov, Nilanjan Datta, Atul Luykx, Bart Mennink, Mridul Nandi, Elmar Tischhauser, Kan Yasuda |
J. Cryptol. | 1 |
| 2023 | A Forkcipher-Based Pseudo-Random Number Generator
Elena Andreeva 0001, Andreas Weninger |
ACNS | 1 |
| 2023 | Let's Go Eevee! A Friendly and Suitable Family of AEAD Modes for IoT-to-Cloud Secure ComputationabstractIoT devices collect privacy-sensitive data, e.g., in smart grids or in medical devices, and send this data to cloud servers for further processing. In order to ensure confidentiality as well as authenticity of the sensor data in the untrusted cloud environment, we consider a transciphering scenario between embedded IoT devices and multiple cloud servers that perform secure multi-party computation (MPC). Concretely, the IoT devices encrypt their data with a lightweight symmetric cipher and send the ciphertext to the cloud servers. To obtain the secret shares of the cleartext message for further processing, the cloud servers engage in an MPC protocol to decrypt the ciphertext in a distributed manner. This way, the plaintext is never exposed to the individual servers. Amit Singh Bhati, Erik Pohle, Aysajan Abidin, Elena Andreeva 0001, Bart Preneel |
CCS | 4 |
| 2021 | Compactness of Hashing Modes and Efficiency Beyond Merkle Tree
Elena Andreeva 0001, Rishiraj Bhattacharyya, Arnab Roy 0005 |
EUROCRYPT (2) | 1 |
| 2020 | Optimized Software Implementations for the Lightweight Encryption Scheme ForkAE
Arne Deprez, Elena Andreeva 0001, Jose Maria Bermudo Mera, Angshuman Karmakar, Antoon Purnal |
CARDIS | 2 |
| 2020 | Nonce-Misuse Security of the SAEF Authenticated Encryption Mode
Elena Andreeva 0001, Amit Singh Bhati, Damian Vizár |
SAC | 1 |
| 2020 | Interpolation Cryptanalysis of Unbalanced Feistel Networks with Low Degree Round Functions
Arnab Roy 0005, Elena Andreeva 0001, Jan Ferdinand Sauer |
SAC | 2 |
| 2019 | Forkcipher: A New Primitive for Authenticated Encryption of Very Short Messages
Elena Andreeva 0001, Virginie Lallemand, Antoon Purnal, Reza Reyhanitabar, Arnab Roy 0005, Damian Vizár |
ASIACRYPT (2) | 1 |
| 2016 | New Second-Preimage Attacks on Hash Functions
Elena Andreeva 0001, Charles Bouillaguet, Orr Dunkelman, Pierre-Alain Fouque, Jonathan J. Hoch, John Kelsey, Adi Shamir, Sébastien Zimmer |
J. Cryptol. | 1 |
| 2015 | Security of Keyed Sponge Constructions Using a Modular Proof Approach
Elena Andreeva 0001, Joan Daemen, Bart Mennink, Gilles Van Assche |
FSE | 1 |
| 2015 | Forgery and Subkey Recovery on CAESAR Candidate iFeed
Willem Schroé, Bart Mennink, Elena Andreeva 0001, Bart Preneel |
SAC | 3 |
| 2015 | Open problems in hash function security
Elena Andreeva 0001, Bart Mennink, Bart Preneel |
Des. Codes Cryptogr. | 1 |
| 2014 | How to Securely Release Unverified Plaintext in Authenticated Encryption
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda |
ASIACRYPT (1) | 1 |
| 2014 | APE: Authenticated Permutation-Based Encryption for Lightweight Cryptography
Elena Andreeva 0001, Begül Bilgin, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda |
FSE | 1 |
| 2014 | COBRA: A Parallelizable Authenticated Online Cipher Without Block Cipher Inverse
Elena Andreeva 0001, Atul Luykx, Bart Mennink, Kan Yasuda |
FSE | 1 |
| 2013 | Parallelizable and Authenticated Online Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan Yasuda |
ASIACRYPT (1) | 1 |
| 2013 | On the Indifferentiability of Key-Alternating Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Yevgeniy Dodis, Bart Mennink, John P. Steinberger |
CRYPTO (1) | 1 |
| 2013 | Towards Understanding the Known-Key Security of Block Ciphers
Elena Andreeva 0001, Andrey Bogdanov, Bart Mennink |
FSE | 1 |
| 2012 | Provable Security of BLAKE with Non-ideal Compression Function
Elena Andreeva 0001, Atul Luykx, Bart Mennink |
Selected Areas in Cryptography | 1 |
| 2011 | The Symbiosis between Collision and Preimage Resistance
Elena Andreeva 0001, Martijn Stam |
IMACC | 1 |
| 2010 | Security Reductions of the Second Round SHA-3 Candidates
Elena Andreeva 0001, Bart Mennink, Bart Preneel |
ISC | 1 |
| 2008 | Second Preimage Attacks on Dithered Hash Functions
Elena Andreeva 0001, Charles Bouillaguet, Pierre-Alain Fouque, Jonathan J. Hoch, John Kelsey, Adi Shamir, Sébastien Zimmer |
EUROCRYPT | 1 |
| 2007 | Seven-Property-Preserving Iterated Hashing: ROX
Elena Andreeva 0001, Gregory Neven, Bart Preneel, Thomas Shrimpton |
ASIACRYPT | 1 |