EDBT 2026 Demo / reviewers in the wild / expert
Dominique Schröder
dblp:52/6199
· DBLP profile ↗
62ranked-venue papers
3as first author
17since 2021 · last 2026
0000-0001-6943-8914ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 61 · 3 first-author · 17 since 2021Theory of computation · 3Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDH
Paul Gerhart, Davide Li Calsi, Luigi Russo 0001, Dominique Schröder |
EUROCRYPT (2) | 4 |
| 2025 | Universally Composable Password-Hardened Encryption
Behzad Abdolmaleki, Ruben Baecker, Paul Gerhart, Mike Graf 0001, Mojtaba Khalili, Daniel Rausch 0001, Dominique Schröder |
ASIACRYPT (6) | 7 |
| 2025 | Password-Hardened Encryption Revisited
Ruben Baecker, Paul Gerhart, Dominique Schröder |
ASIACRYPT (6) | 3 |
| 2025 | A Fully-Adaptive Threshold Partially-Oblivious PRF
Ruben Baecker, Paul Gerhart, Daniel Rausch 0001, Dominique Schröder |
CRYPTO (5) | 4 |
| 2025 | Automated Analysis and Synthesis of Message Authentication CodesabstractMessage Authentication Codes (MACs) represent a fundamental symmetric key primitive, serving to ensure the authenticity and integrity of transmitted data. As a building block in authenticated encryption and in numerous deployed standards, including TLS, IPsec, and SSH, MACs play a central role in practice. Due to their importance for practice, MACs have been subject to extensive research, leading to prominent schemes such as HMAC, CBCMAC, or LightMAC. Despite the existence of various MACs, there is still considerable interest in creating schemes that are more efficient, potentially parallelizable, or have specific non-cryptographic attributes, such as being patent-free. In this context, we introduce an automated method for analyzing and synthesizing MAC schemes. In order to achieve this goal, we have constructed a framework that restricts the class of MACs in such a way that it is sufficiently expressive to cover known constructions, yet also admits automated reasoning about the security guarantees of both known and new schemes. Our automated analysis has identified a novel category of MACs, termed “hybrid” MACs. These MACs operate by processing multiple blocks concurrently, with each block managed by a different, specified MAC scheme. A key finding is that in certain scenarios, the hybrid MAC marginally outperforms the simultaneous operation of the individual MACs. This improvement is attributed to the hybrid approach exploiting the strengths and compensating for the weaknesses of each distinct MAC scheme involved. Our implementation confirms that we have successfully identified new schemes that have comparable performance with state-of-the-art schemes and in some settings seem to be slightly more efficient. Stefan Milius, Dominik Paulus, Dominique Schröder, Lutz Schröder, Julian Thomas |
CSF | 3 |
| 2025 | SoK: Descriptive Statistics Under Local Differential PrivacyabstractLocal Differential Privacy (LDP) provides a formal guarantee of privacy that enables the collection and analysis of sensitive data without revealing any individual's data. While LDP methods have been extensively studied, there is a lack of a systematic and empirical comparison of LDP methods for descriptive statistics. In this paper, we first provide a systematization of LDP methods for descriptive statistics, comparing their properties and requirements. We demonstrate that several mean estimation methods based on sampling from a Bernoulli distribution are equivalent in the one-dimensional case and introduce methods for variance estimation. We then empirically compare methods for mean, variance, and frequency estimation. Finally, we provide recommendations for the use of LDP methods for descriptive statistics and discuss their limitations and open questions. René Raab, Pascal Berrang, Paul Gerhart, Dominique Schröder |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Increasing the Resilience of Secure Multiparty Computation Using Security ModulesabstractWe investigate the problem of Secure Multiparty Computation (SMC) in a synchronous system with Byzantine failures where processes have access to trusted hardware. While previous solutions needed a majority of well-behaving processes to solve SMC, we construct an algorithm that solves SMC for an arbitrary number of Byzantine processes. We do this by refining and combining multiple established concepts from the literature: (1) We introduce a dynamic association between processes and trusted hardware modules in the hybrid system model of Fort et al. (TrustedPals model), (2) we utilize the primitive of Uniform Reliable Broadcast for information dissemination between trusted hardware modules, and (3) we use (and slightly adapt) the concept of Sealed Computation as an abstraction of trusted hardware modules. Lamya Abdullah, Felix C. Freiling, Dominique Schröder |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Foundations of Adaptor Signatures
Paul Gerhart, Dominique Schröder, Pratik Soni, Sri Aravinda Krishnan Thyagarajan |
EUROCRYPT (2) | 2 |
| 2024 | Measuring Conditional Anonymity - A Global StudyabstractThe realm of digital health is experiencing a global surge, with mobile applications extending their reach into various facets of daily life. From tracking daily eating habits and vital functions to monitoring sleep patterns and even the menstrual cycle, these apps have become ubiquitous in their pursuit of comprehensive health insights. Many of these apps collect sensitive data and promise users to protect their privacy - often through pseudonymization. We analyze the real anonymity that users can expect by this approach and report on our findings. More concretely: We introduce the notion of conditional anonymity sets derived from statistical properties of the population; We measure anonymity sets for two real-world applications and present overarching findings from 39 countries; We develop a graphical tool for people to explore their own anonymity set. One of our case studies is a popular app for tracking the menstruation cycle. Our findings for this app show that, despite their promise to protect privacy, the collected data can be used to identify users up to groups of 5 people in 97% of all the US counties, allowing the de-anonymization of the individuals. Given that the US Supreme Court recently overturned abortion rights, the possibility of determining individuals is a calamity. Pascal Berrang, Paul Gerhart, Dominique Schröder |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Practical Schnorr Threshold Signatures Without the Algebraic Group Model
Hien Chu, Paul Gerhart, Tim Ruffing, Dominique Schröder |
CRYPTO (1) | 4 |
| 2022 | ROAST: Robust Asynchronous Schnorr Threshold SignaturesabstractBitcoin and other cryptocurrencies have recently introduced support for Schnorr signatures whose cleaner algebraic structure, as compared to ECDSA, allows for simpler and more practical constructions of highly demanded ''t-of-n'' threshold signatures. However, existing Schnorr threshold signature schemes still fall short of the needs of real-world applications due to their assumption that the network is synchronous and due to their lack of robustness, i.e., the guarantee that t honest signers are able to obtain a valid signature even in the presence of other malicious signers who try to disrupt the protocol. This hinders the adoption of threshold signatures in the cryptocurrency ecosystem, e.g., in second-layer protocols built on top of cryptocurrencies. Tim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch, Dominique Schröder |
CCS | 5 |
| 2022 | Verifiable Timed Linkable Ring Signatures for Scalable Payments for Monero
Sri Aravinda Krishnan Thyagarajan, Giulio Malavolta, Fritz Schmid, Dominique Schröder |
ESORICS (2) | 4 |
| 2022 | Everlasting UC Commitments from Fully Malicious PUFsabstractAbstract Everlasting security models the setting where hardness assumptions hold during the execution of a protocol but may get broken in the future. Due to the strength of this adversarial model, achieving any meaningful security guarantees for composable protocols is impossible without relying on hardware assumptions (Müller-Quade and Unruh, JoC’10). For this reason, a rich line of research has tried to leverage physical assumptions to construct well-known everlasting cryptographic primitives, such as commitment schemes. The only known everlastingly UC secure commitment scheme, due to Müller-Quade and Unruh (JoC’10), assumes honestly generated hardware tokens. The authors leave the possibility of constructing everlastingly UC secure commitments from malicious hardware tokens as an open problem. Goyal et al. (Crypto’10) constructs unconditionally UC-secure commitments and secure computation from malicious hardware tokens, with the caveat that the honest tokens must encapsulate other tokens. This extra restriction rules out interesting classes of hardware tokens, such as physically uncloneable functions (PUFs). In this work, we present the first construction of an everlastingly UC-secure commitment scheme in the fully malicious token modelwithout requiringhonest token encapsulation. Our scheme assumes the existence of PUFs and is secure in the common reference string model. We also show that our results are tight by giving an impossibility proof for everlasting UC-securecomputationfrom non-erasable tokens (such as PUFs), even with trusted setup. Bernardo Magri, Giulio Malavolta, Dominique Schröder, Dominique Unruh |
J. Cryptol. | 3 |
| 2021 | A Security Framework for Distributed LedgersabstractIn the past few years blockchains have been a major focus for security research, resulting in significant progress in the design, formalization, and analysis of blockchain protocols. However, the more general class of distributed ledgers, which includes not just blockchains but also prominent non-blockchain protocols, such as Corda and OmniLedger, cannot be covered by the state-of-the-art in the security literature yet. These distributed ledgers often break with traditional blockchain paradigms, such as block structures to store data, system-wide consensus, or global consistency. In this paper, we close this gap by proposing the first framework for defining and analyzing the security of general distributed ledgers, with an ideal distributed ledger functionality, called Fledger, at the core of our contribution. This functionality covers not only classical blockchains but also non-blockchain distributed ledgers in a unified way. To illustrate Fledger, we first show that the prominent ideal block-chain functionalities Gledger and GPL realize (suitable instantiations of) Fledger, which captures their security properties. This implies that their respective implementations, including Bitcoin, Ouroboros Genesis, and Ouroboros Crypsinous, realize Fledger as well. Secondly, we demonstrate that Fledger is capable of precisely modeling also non-blockchain distributed ledgers by performing the first formal security analysis of such a distributed ledger, namely the prominent Corda protocol. Due to the wide spread use of Corda in industry, in particular the financial sector, this analysis is of independent interest. These results also illustrate that Fledger not just generalizes the modular treatment of blockchains to distributed ledgers, but moreover helps to unify existing results. Mike Graf 0001, Daniel Rausch 0001, Viktoria Ronge, Christoph Egger 0001, Ralf Küsters, Dominique Schröder |
CCS | 6 |
| 2021 | OpenSquare: Decentralized Repeated Modular Squaring ServiceabstractRepeated Modular Squaring is a versatile computational operation that has led to practical constructions of timed-cryptographic primitives like time-lock puzzles (TLP) and verifiable delay functions (VDF) that have a fast growing list of applications. While there is a huge interest for timed-cryptographic primitives in the blockchains area, we find two real-world concerns that need immediate attention towards their large-scale practical adoption: Firstly, the requirement to constantly perform computations seems unrealistic for most of the users. Secondly, choosing the parameters for the bound (T) seems complicated due to the lack of heuristics and experience. We present OpenSquare, a decentralized repeated modular squaring service, that overcomes the above concerns. OpenSquare lets clients outsource their repeated modular squaring computation via smart contracts to any computationally powerful servers that offer computational services for rewards in an unlinkable manner. Sri Aravinda Krishnan Thyagarajan, Tiantian Gong, Adithya Bhat, Aniket Kate, Dominique Schröder |
CCS | 5 |
| 2021 | CoinJoin in the Wild - An Empirical Analysis in Dash
Dominic Deuber, Dominique Schröder |
ESORICS (2) | 2 |
| 2021 | Foundations of Ring SamplingabstractA ring signature scheme allows the signer to sign on behalf of an ad hoc set of users, called a ring. The verifier can be convinced that a ring member signs, but cannot point to the exact signer. Ring signatures have become increasingly important today with their deployment in anonymous cryptocurrencies. Conventionally, it is implicitly assumed that all ring members are equally likely to be the signer. This assumption is generally false in reality, leading to various practical and devastating deanonymizing attacks in Monero, one of the largest anonymous cryptocurrencies. These attacks highlight the unsatisfactory situation that how a ring should be chosen is poorly understood. Viktoria Ronge, Christoph Egger 0001, Russell W. F. Lai, Dominique Schröder, Hoover H. F. Yin |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | Threshold Password-Hardened Encryption ServicesabstractPassword-hardened encryption (PHE) was introduced by Lai et al. at USENIX 2018 and immediately productized by VirgilSecurity. PHE is a password-based key derivation protocol that involves an oblivious external crypto service for key derivation. The security of PHE protects against offline brute-force attacks, even when the attacker is given the entire database. Furthermore, the crypto service neither learns the derived key nor the password. PHE supports key-rotation meaning that both the server and crypto service can update their keys without involving the user. While PHE significantly strengthens data security, it introduces a single point of failure because key-derivation always requires access to the crypto service. In this work, we address this issue and simultaneously increase security by introducing threshold password-hardened encryption. Our formalization of this primitive revealed shortcomings of the original PHE definition that we also address in this work. Following the spirit of prior works, we give a simple and efficient construction using lightweight tools only. We also implement our construction and evaluate its efficiency. Our experiments confirm the practical efficiency of our scheme and show that it is more efficient than common memory-hard functions, such as scrypt. From a practical perspective this means that threshold PHE can be used as an alternative to scrypt for password protection and key-derivation, offering better security in terms of offline brute force attacks. Julian Brost, Christoph Egger 0001, Russell W. F. Lai, Fritz Schmid, Dominique Schröder, Markus Zoppelt |
CCS | 5 |
| 2020 | Verifiable Timed Signatures Made PracticalabstractA verifiable timed signature (VTS) scheme allows one to time-lock a signature on a known message for a given amount of time T such that after performing a sequential computation for time T anyone can extract the signature from the time-lock. Verifiability ensures that anyone can publicly check if a time-lock contains a valid signature on the message without solving it first, and that the signature can be obtained by solving the same for time T. Sri Aravinda Krishnan Thyagarajan, Adithya Bhat, Giulio Malavolta, Nico Döttling, Aniket Kate, Dominique Schröder |
CCS | 6 |
| 2020 | Feasibility and Infeasibility of Secure Computation with Malicious PUFs
Dana Dachman-Soled, Nils Fleischhacker, Jonathan Katz, Anna Lysyanskaya, Dominique Schröder |
J. Cryptol. | 5 |
| 2019 | Omniring: Scaling Private Payments Without Trusted SetupabstractMonero is the largest cryptocurrency with built-in cryptographic privacy features. The transactions are authenticated using zero-knowledge spend proofs, which provide a certain level of anonymity by hiding the source accounts from which the funds are sent among a set of other accounts. Due to its similarities to ring signatures, this core cryptographic component is called Ring Confidential Transactions (RingCT). Because of its practical relevance, several works attempt to analyze the security of RingCT. Since RingCT is rather complex, most of them are either informal, miss fundamental functionalities, or introduce undesirable trusted setup assumptions. Regarding efficiency, Monero currently deploys a scheme in which the size of the spend proof is linear in the ring size. This limits the ring size to only a few accounts, which in turn limits the acquired anonymity significantly and facilitates de-anonymization attacks. As a solution to these problems, we present the first rigorous formalization of RingCT as a cryptographic primitive. We then propose a generic construction of RingCT and prove it secure in our formal security model. By instantiating our generic construction with new efficient zero-knowledge proofs, we obtain Omniring, a fully-fledged RingCT scheme in the discrete logarithm setting that provides the highest concrete and asymptotic efficiency as of today. Omniring is the first RingCT scheme which 1) does not require a trusted setup or pairing-friendly elliptic curves, 2) has a proof size logarithmic in the size of the ring, and 3) allows to share the same ring between all source accounts in a transaction, thereby enabling significantly improved privacy level without sacrificing performance. Our zero-knowledge proofs rely on novel enhancements to the Bulletproofs framework (S&P 2018), which we believe are of independent interest. Russell W. F. Lai, Viktoria Ronge, Tim Ruffing, Dominique Schröder, Sri Aravinda Krishnan Thyagarajan, Jiafan Wang 0001 |
CCS | 4 |
| 2019 | Arithmetic Garbling from Bilinear Maps
Nils Fleischhacker, Giulio Malavolta, Dominique Schröder |
ESORICS (2) | 3 |
| 2019 | Group ORAM for privacy and access control in outsourced personal recordsabstractCloud storage has rapidly become a cornerstone of many IT infrastructures, constituting a seamless solution for the backup, synchronization, and sharing of large amounts of data. Putting user data in the direct control of cloud service providers, however, raises security and privacy concerns related to the integrity of outsourced data, the accidental or intentional leakage of sensitive information, the profiling of user activities and so on. Furthermore, even if the cloud provider is trusted, users having access to outsourced files might be malicious and misbehave. These concerns are particularly serious in sensitive applications like personal health records and credit score systems. To tackle this problem, we present [Formula: see text], a definitional framework for Group Oblivious RAM, in which we formalize several security and privacy properties such as secrecy, integrity, anonymity, and obliviousness. [Formula: see text] allows per entry access control, as selected by the data owner. [Formula: see text] is the first framework to define such a wide range of security and privacy properties for outsourced storage. Regarding obliviousness, we tackle two different attacker models: our first definition protects against an honest-but-curious server while our second definition protects against such a server colluding with malicious clients. In the latter model, we prove a server-side computational lower bound of [Formula: see text] where n is the number of entries in the database, i.e., every operations requires to process a constant fraction of the database. Furthermore, we present two constructions: a pure cryptographic instantiation, which achieves an [Formula: see text] amortized communication and computation complexity and a construction based on a trusted proxy with logarithmic communication and server-side computational complexity. The second construction bypasses the previously established lower bound leveraging a trusted party. Both schemes achieve secrecy, integrity, and obliviousness with respect to a server colluding with malicious clients, but not anonymity due to the deployed access control mechanism. In the former model, we present a cryptographic system that achieves secrecy, integrity, obliviousness, and anonymity. In the process of designing an efficient construction, we developed three new, generally applicable cryptographic schemes, namely, batched zero-knowledge proof of shuffle correctness, the hash-and-proof paradigm, which even improves upon the former, and an accountability technique based on chameleon signatures, which we consider of independent interest. We implemented our constructions in Amazon Elastic Compute Cloud (EC2) and ran a performance evaluation demonstrating the scalability and efficiency of our construction. Matteo Maffei, Giulio Malavolta, Manuel Reinert, Dominique Schröder |
J. Comput. Secur. | 4 |
| 2019 | (Efficient) Universally Composable Oblivious Transfer Using a Minimal Number of Stateless Tokens
Seung Geol Choi, Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich, Hong-Sheng Zhou |
J. Cryptol. | 3 |
| 2019 | On Tight Security Proofs for Schnorr Signatures
Nils Fleischhacker, Tibor Jager, Dominique Schröder |
J. Cryptol. | 3 |
| 2019 | My Genome Belongs to Me: Controlling Third Party Computation on Genomic DataabstractAbstract An individual’s genetic information is possibly the most valuable personal information. While knowledge of a person’s DNA sequence can facilitate the diagnosis of several heritable diseases and allow personalized treatment, its exposure comes with significant threats to the patient’s privacy. Currently known solutions for privacy-respecting computation require the owner of the DNA to either be heavily involved in the execution of a cryptographic protocol or to completely outsource the access control to a third party. This motivates the demand for cryptographic protocols which enable computation over encrypted genomic data while keeping the owner of the genome in full control. We envision a scenario where data owners can exercise arbitrary and dynamic access policies, depending on the intended use of the analysis results and on the credentials of who is conducting the analysis. At the same time, data owners are not required to maintain a local copy of their entire genetic data and do not need to exhaust their computational resources in an expensive cryptographic protocol. In this work, we present METIS, a system that assists the computation over encrypted data stored in the cloud while leaving the decision on admissible computations to the data owner. It is based on garbled circuits and supports any polynomially-computable function. A critical feature of our system is that the data owner is free from computational overload and her communication complexity is independent of the size of the input data and only linear in the size of the circuit’s output. We demonstrate the practicality of our approach with an implementation and an evaluation of several functions over real datasets. Dominic Deuber, Christoph Egger 0001, Katharina Fech, Giulio Malavolta, Dominique Schröder, Sri Aravinda Krishnan Thyagarajan, Florian Battke, Claudia Durand |
Proc. Priv. Enhancing Technol. | 5 |
| 2018 | Homomorphic Secret Sharing for Low Degree Polynomials
Russell W. F. Lai, Giulio Malavolta, Dominique Schröder |
ASIACRYPT (3) | 3 |
| 2018 | Simple Password-Hardened Encryption Services
Russell W. F. Lai, Christoph Egger 0001, Manuel Reinert, Sherman S. M. Chow, Matteo Maffei, Dominique Schröder |
USENIX Security Symposium | 6 |
| 2018 | Efficient unlinkable sanitizable signatures from signatures with re-randomizable keysabstractA sanitizable signature scheme is a malleable signature scheme where a designated third party has the permission to modify certain parts of the message and adapt the signature accordingly. This primitive was introduced by Ateniese et al . (ESORICS 2005) and Brzuska et al . (PKC 2009) formalized the initially suggested five security properties. In the subsequent year, Brzuska et al . (PKC 2010) introduced a notion called unlinkability where the basic idea is that linking message‐signature pairs of the same document should be infeasible. Brzuska et al . formalized this notion and suggested a generic instantiation based on group signatures with a special structure. Unfortunately, the most efficient instantiations of group signatures do not have this property. In this work, we present the first efficient construction of unlinkable sanitizable signatures based on a novel type of signature schemes with re‐randomizable keys. This property allows one to re‐randomize both the signing and the verification key separately but consistently. Given a signature scheme with re‐randomizable keys, we obtain a sanitizable signature scheme by signing the message with a re‐randomized key and proving in zero‐knowledge that the derived key originates from either the signer or the sanitizer. To obtain an efficient instantiation, we instantiate this generic idea with Schnorr signatures and efficient ‐protocols that we turn into a non‐interactive zero‐knowledge proof via the Fiat‐Shamir transformation. In this work, we present an optimized version that is more efficient than the construction we suggested in the extended abstract of this work at PKC 2016. Nils Fleischhacker, Johannes Krupp, Giulio Malavolta, Jonas Schneider-Bensch, Dominique Schröder, Mark Simkin 0001 |
IET Inf. Secur. | 5 |
| 2018 | Delegatable functional signaturesabstractThe authors introduce delegatable functional signatures (DFS) which support the delegation of signing capabilities to another party, called the evaluator , with respect to a functionality . In a DFS, the signer of a message can choose an evaluator, specify how the evaluator can modify the signature without voiding its validity, allow additional input, and decide how the evaluator can further delegate its capabilities. Technically, DFS unify several seemingly different signature primitives, including functional signatures and policy‐based signatures, sanitisable signatures, identity‐based signatures, and blind signatures. The authors characterise the instantiability of DFS with respect to the corresponding security notions of unforgeability and privacy. On the positive side, they show that privacy‐free DFS can be constructed from one‐way functions. Furthermore, they show that unforgeable and private DFS can be constructed from doubly‐enhanced trapdoor permutations. On the negative side, they show that the previous result is optimal regarding its underlying assumptions. Their impossibility result shows that unforgeable private DFS cannot be constructed from one‐way permutations. Sebastian Meiser 0001, Dominique Schröder |
IET Inf. Secur. | 2 |
| 2018 | Functional CredentialsabstractAbstract A functional credential allows a user to anonymously prove possession of a set of attributes that fulfills a certain policy. The policies are arbitrary polynomially computable predicates that are evaluated over arbitrary attributes. The key feature of this primitive is the delegation of verification to third parties, called designated verifiers. The delegation protects theprivacy of the policy: A designated verifier can verify that a user satisfies a certain policy without learning anything about the policy itself. We illustrate the usefulness of this property in different applications, including outsourced databases with access control. We present a new framework to construct functional credentials that does not require (non-interactive) zero-knowledge proofs. This is important in settings where the statements are complex and thus the resulting zero-knowledge proofs are not efficient. Our construction is based on any predicate encryption scheme and the security relies on standard assumptions. A complexity analysis and an experimental evaluation confirm the practicality of our approach. Dominic Deuber, Matteo Maffei, Giulio Malavolta, Max Rabkin, Dominique Schröder, Mark Simkin 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2017 | Maliciously Secure Multi-Client ORAM
Matteo Maffei, Giulio Malavolta, Manuel Reinert, Dominique Schröder |
ACNS | 4 |
| 2017 | Efficient Ring Signatures in the Standard Model
Giulio Malavolta, Dominique Schröder |
ASIACRYPT (2) | 2 |
| 2017 | Subset Predicate Encryption and Its Applications
Jonathan Katz, Matteo Maffei, Giulio Malavolta, Dominique Schröder |
CANS | 4 |
| 2017 | On the Security of Frequency-Hiding Order-Preserving Encryption
Matteo Maffei, Manuel Reinert, Dominique Schröder |
CANS | 3 |
| 2017 | Phoenix: Rebirth of a Cryptographic Password-Hardening Service
Russell W. F. Lai, Christoph Egger 0001, Dominique Schröder, Sherman S. M. Chow |
USENIX Security Symposium | 3 |
| 2017 | Security of Blind Signatures Revisited
Dominique Schröder, Dominique Unruh |
J. Cryptol. | 1 |
| 2016 | Efficient Cryptographic Password Hardening Services from Partially Oblivious CommitmentsabstractPassword authentication still constitutes the most widespread authentication concept on the Internet today, but the human incapability to memorize safe passwords has left this concept vulnerable to various attacks ever since. Affected enterprises such as Facebook now strive to mitigate such attacks by involving external cryptographic services that harden passwords. Everspaugh et al.~provided the first comprehensive formal treatment of such a service, and proposed the Pythia PRF-Service as a cryptographically secure solution (Usenix Security'15). Pythia relies on a novel cryptographic primitive called partially oblivious pseudorandom functions and its security is proven under a strong new interactive assumption in the random oracle model. Jonas Schneider-Bensch, Nils Fleischhacker, Dominique Schröder, Michael Backes 0001 |
CCS | 3 |
| 2016 | Two-Message, Oblivious Evaluation of Cryptographic Functionalities
Nico Döttling, Nils Fleischhacker, Johannes Krupp, Dominique Schröder |
CRYPTO (3) | 4 |
| 2016 | Efficient Sanitizable Signatures Without Random Oracles
Russell W. F. Lai, Tao Zhang 0014, Sherman S. M. Chow, Dominique Schröder |
ESORICS (1) | 4 |
| 2015 | Foundations of Reconfigurable PUFs
Jonas Schneider-Bensch, Dominique Schröder |
ACNS | 2 |
| 2015 | Liar, Liar, Coins on Fire!: Penalizing Equivocation By Loss of BitcoinsabstractWe show that equivocation, i.e., making conflicting statements to others in a distributed protocol, can be monetarily disincentivized by the use of crypto-currencies such as Bitcoin. To this end, we design completely decentralized non-equivocation contracts, which make it possible to penalize an equivocating party by the loss of its money. At the core of these contracts, there is a novel cryptographic primitive called accountable assertions, which reveals the party's Bitcoin credentials if it equivocates. Non-equivocation contracts are particularly useful for distributed systems that employ public append-only logs to protect data integrity, e.g., in cloud storage and social networks. Moreover, as double-spending in Bitcoin is a special case of equivocation, the contracts enable us to design a payment protocol that allows a payee to receive funds at several unsynchronized points of sale, while being able to penalize a double-spending payer after the fact. Tim Ruffing, Aniket Kate, Dominique Schröder |
CCS | 3 |
| 2015 | Efficient Pseudorandom Functions via On-the-Fly Adaptation
Nico Döttling, Dominique Schröder |
CRYPTO (1) | 2 |
| 2015 | Verifiably Encrypted Signatures: Security Revisited and a New ConstructionabstractIn structure-preserving signatures on equivalence classes (SPS-EQ- $$\mathcal {R}$$ ), introduced at $$\textsc {Asiacrypt}$$ 2014, each message M in $$(\mathbb {G}^*)^\ell $$ is associated to its projective equivalence class, and a signature commits to the equivalence class: anybody can transfer the signature to a new, scaled, representative. In this work, we give the first black-box construction of a public-key encryption scheme from any SPS-EQ- $$\mathcal {R}$$ satisfying a simple new property which we call perfect composition. The construction does notinvolve any non-black-box technique and the implication is that such SPS-EQ- $$\mathcal {R}$$ cannot be constructed from one-way functions in a black-box way. The main idea of our scheme is to build a verifiable encrypted signature (VES) first and then apply the general transformation suggested by Calderon et al. (CT-RSA 2014). The original definition of VES requires that the underlying signature scheme be correct and secure in addition to other security properties. The latter have been extended in subsequent literature, but the former requirements have sometimes been neglected, leaving a hole in the security notion. We show that Calderon et al.’s notion of resolution independence fills this gap. Christian Hanser, Max Rabkin, Dominique Schröder |
ESORICS (1) | 3 |
| 2015 | Privacy and Access Control for Outsourced Personal RecordsabstractCloud storage has rapidly become a cornerstone of many IT infrastructures, constituting a seamless solution for the backup, synchronization, and sharing of large amounts of data. Putting user data in the direct control of cloud service providers, however, raises security and privacy concerns related to the integrity of outsourced data, the accidental or intentional leakage of sensitive information, the profiling of user activities and so on. Furthermore, even if the cloud provider is trusted, users having access to outsourced files might be malicious and misbehave. These concerns are particularly serious in sensitive applications like personal health records and credit score systems. To tackle this problem, we present GORAM, a cryptographic system that protects the secrecy and integrity of outsourced data with respect to both an untrusted server and malicious clients, guarantees the anonymity and unlink ability of accesses to such data, and allows the data owner to share outsourced data with other clients, selectively granting them read and write permissions. GORAM is the first system to achieve such a wide range of security and privacy properties for outsourced storage. In the process of designing an efficient construction, we developed two new, generally applicable cryptographic schemes, namely, batched zero-knowledge proofs of shuffle and an accountability technique based on chameleon signatures, which we consider of independent interest. We implemented GORAM in Amazon Elastic Compute Cloud (EC2) and ran a performance evaluation demonstrating the scalability and efficiency of our construction. Matteo Maffei, Giulio Malavolta, Manuel Reinert, Dominique Schröder |
IEEE Symposium on Security and Privacy | 4 |
| 2014 | WebTrust - A Comprehensive Authenticity and Integrity Framework for HTTP
Michael Backes 0001, Rainer W. Gerling, Sebastian Gerling, Stefan Nürnberger, Dominique Schröder, Mark Simkin 0001 |
ACNS | 5 |
| 2014 | On Tight Security Proofs for Schnorr Signatures
Nils Fleischhacker, Tibor Jager, Dominique Schröder |
ASIACRYPT (1) | 3 |
| 2014 | POSTER: Enhancing Security and Privacy with Google GlassabstractIn the past years wearable computing devices, such as head-mounted displays, and ubiquitous computing increasingly gained importance. Head-mounted displays are comprised of a front-facing camera and a little screen in front of the user's eye. They provide their users with a seamless extension of their perceptual abilities in an unobtrusive and user-friendly manner. The Ubic-framework combines these new devices with mathematically sound digital cryptographic primitives and resource-friendly computer vision techniques to provide users with novel security and privacy guarantees in their everyday life. In our hands-on demo we show how Ubic allows users to read encrypted and verify digitally signed physical documents. In addition, we present an identification scheme, which is secure against real-world attacks, such as skimming and shoulder-surfing, but remains user friendly and easily deployable in current infrastructures. The Ubic-framework first appeared at ESORICS 2014. Johannes Krupp, Dominique Schröder, Mark Simkin 0001 |
CCS | 2 |
| 2014 | Feasibility and Infeasibility of Secure Computation with Malicious PUFs
Dana Dachman-Soled, Nils Fleischhacker, Jonathan Katz, Anna Lysyanskaya, Dominique Schröder |
CRYPTO (2) | 5 |
| 2014 | Ubic: Bridging the Gap between Digital Cryptography and the Physical World
Mark Simkin 0001, Dominique Schröder, Andreas Bulling, Mario Fritz |
ESORICS (1) | 2 |
| 2014 | Brief announcement: towards security and privacy for outsourced data in the multi-party settingabstractCloud storage has rapidly acquired popularity among users, constituting a seamless solution for the backup, synchronization, and sharing of large amounts of data. This technology, however, puts user data in the direct control of cloud service providers, which raises increasing security and privacy concerns related to the integrity of outsourced data, the accidental or intentional leakage of sensitive information, the profiling of user activities and so on. We present GORAM, a cryptographic system that protects the secrecy and integrity of the data outsourced to an untrusted server and guarantees the anonymity and unlinkability of consecutive accesses to such data. GORAM allows the database owner to share outsourced data with other clients, selectively granting them read and write permissions. GORAM is the first system to achieve such a wide range of security and privacy properties for outsourced storage. Technically, GORAM builds on a combination of ORAM to conceal data accesses, attribute-based encryption to rule the access to outsourced data, and zero-knowledge proofs to prove read and write permissions in a privacy-preserving manner. We implemented GORAM and conducted an experimental evaluation to demonstrate its feasibility. Matteo Maffei, Giulio Malavolta, Manuel Reinert, Dominique Schröder |
PODC | 4 |
| 2014 | (Efficient) Universally Composable Oblivious Transfer Using a Minimal Number of Stateless Tokens
Seung Geol Choi, Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich, Hong-Sheng Zhou |
TCC | 3 |
| 2012 | Verifiable data streamingabstractIn a verifiable data streaming protocol, the client streams a long string to the server who stores it in its database. The stream is verifiable in the sense that the server can neither change the order of the elements nor manipulate them. The client may also retrieve data from the database and update them. The content of the database is publicly verifiable such that any party in possession of some value $s$ and a proof Ö can check that s is indeed in the database. Dominique Schröder, Heike Schröder |
CCS | 1 |
| 2012 | Uniqueness Is a Different Story: Impossibility of Verifiable Random Functions from Trapdoor Permutations
Dario Fiore 0001, Dominique Schröder |
TCC | 2 |
| 2011 | Round Optimal Blind Signatures
Sanjam Garg, Vanishree Rao, Amit Sahai, Dominique Schröder, Dominique Unruh |
CRYPTO | 4 |
| 2011 | Expedient Non-malleability Notions for Hash Functions
Paul Baecher, Marc Fischlin, Dominique Schröder |
CT-RSA | 3 |
| 2011 | How to Aggregate the CL Signature Scheme
Dominique Schröder |
ESORICS | 1 |
| 2011 | Impossibility of Blind Signatures from One-Way Permutations
Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich |
TCC | 2 |
| 2010 | Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder |
ACNS | 11 |
| 2010 | Generic Constructions for Verifiably Encrypted Signatures without Random Oracles or NIZKs
Markus Rückert, Michael Schneider 0002, Dominique Schröder |
ACNS | 3 |
| 2010 | On the Impossibility of Three-Move Blind Signature Schemes
Marc Fischlin, Dominique Schröder |
EUROCRYPT | 2 |
| 2009 | Security of Verifiably Encrypted Signatures and a Construction without Random Oracles
Markus Rückert, Dominique Schröder |
Pairing | 2 |