EDBT 2026 Demo / reviewers in the wild / expert
Tibor Jager
dblp:53/1548
· DBLP profile ↗
57ranked-venue papers
20as first author
15since 2021 · last 2025
0000-0002-3205-7699ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 55 · 20 first-author · 14 since 2021Theory of computation · 4 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Rerandomizable Garbling, Revisited
Raphael Heitjohann, Jonas von der Heyden, Tibor Jager |
CRYPTO (4) | 3 |
| 2023 | Subversion-Resilient Authenticated Encryption Without Random Oracles
Pascal Bemmann, Sebastian Berndt 0001, Denis Diemert, Thomas Eisenbarth 0001, Tibor Jager |
ACNS | 5 |
| 2023 | Security Analysis of the WhatsApp End-to-End Encrypted Backup Protocol
Gareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk, Julia Hesse, Máté Horváth, Tibor Jager |
CRYPTO (4) | 7 |
| 2023 | On Optimal Tightness for Key Exchange with Full Forward Secrecy via Key Confirmation
Kai Gellert, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager |
CRYPTO (4) | 4 |
| 2022 | On Fingerprinting Attacks and Length-Hiding Encryption
Kai Gellert, Tibor Jager, Lin Lyu 0001, Tom Neuschulten |
CT-RSA | 2 |
| 2022 | On the Concrete Security of TLS 1.3 PSK Mode
Hannah Davis, Denis Diemert, Felix Günther 0001, Tibor Jager |
EUROCRYPT (2) | 4 |
| 2022 | Automated Information Leakage Detection: A New Method Combining Machine Learning and Hypothesis Testing with an Application to Side-channel Detection in Cryptographic ProtocolsabstractDue to the proliferation of a large amount of publicly available data, information leakage (IL) has become a major problem. IL occurs when secret (sensitive) information of a system is inadvertently disclosed to unauthorized parties through externally observable information. Standard statistical approaches estimate the mutual information between observable (input) and secret information (output), which tends to be a difficult problem for high-dimensional input. Current approaches based on (supervised) machine learning using the accuracy of predictive models on extracted system input and output have proven to be more effective in detecting these leakages. However, these approaches are domain-specific and fail to account for imbalance in the dataset. In this paper, we present a robust autonomous approach to detecting IL, which blends machine learning and statistical techniques, to overcome these shortcomings. We propose to use Fisher’s Exact Test (FET) on the evaluated confusion matrix , which inherently takes the imbalances in the dataset into account. As a use case, we consider the problem of detecting padding side-channels or ILs in systems implementing cryptographic protocols. In an extensive experimental study on detecting ILs in synthetic and real-world scenarios, our approach outperforms the state of the art. Pritha Gupta, Arunselvan Ramaswamy, Jan Peter Drees, Eyke Hüllermeier, Claudia Priesterjahn, Tibor Jager |
ICAART (2) | 6 |
| 2021 | Symmetric Key Exchange with Full Forward Security and Robust Synchronization
Colin Boyd, Gareth T. Davies, Bor de Kock, Kai Gellert, Tibor Jager, Lise Millerjord |
ASIACRYPT (4) | 5 |
| 2021 | Digital Signatures with Memory-Tight Security in the Multi-challenge Setting
Denis Diemert, Kai Gellert, Tibor Jager, Lin Lyu 0001 |
ASIACRYPT (4) | 3 |
| 2021 | Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Shuai Han 0001, Tibor Jager, Eike Kiltz, Shengli Liu 0001, Jiaxin Pan 0001, Doreen Riepel, Sven Schäge |
CRYPTO (4) | 2 |
| 2021 | Versatile and Sustainable Timed-Release Encryption and Sequential Time-Lock Puzzles (Extended Abstract)
Peter Chvojka, Tibor Jager, Daniel Slamanig, Christoph Striecks |
ESORICS (2) | 2 |
| 2021 | Tightly-Secure Authenticated Key Exchange, Revisited
Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge |
EUROCRYPT (1) | 1 |
| 2021 | Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTTabstractAbstract The TLS 1.3 0-RTT mode enables a client reconnecting to a server to send encrypted application-layer data in “0-RTT” (“zero round-trip time”), without the need for a prior interactive handshake. This fundamentally requires the server to reconstruct the previous session’s encryption secrets upon receipt of the client’s first message. The standard techniques to achieve this are session caches or, alternatively, session tickets. The former provides forward security and resistance against replay attacks, but requires a large amount of server-side storage. The latter requires negligible storage, but provides no forward security and is known to be vulnerable to replay attacks. In this paper, we first formally define session resumption protocols as an abstract perspective on mechanisms like session caches and session tickets. We give a new generic construction that provably provides forward security and replay resilience, based on puncturable pseudorandom functions (PPRFs). We show that our construction can immediately be used in TLS 1.3 0-RTT and deployed unilaterally by servers, without requiring any changes to clients or the protocol. To this end, we present a generic composition of our new construction with TLS 1.3 and prove its security. This yields the first construction that achieves forward security for all messages, including the 0-RTT data. We then describe two new constructions of PPRFs, which are particularly suitable for use for forward-secure and replay-resilient session resumption in TLS 1.3. The first construction is based on the strong RSA assumption. Compared to standard session caches, for “128-bit security” it reduces the required server storage by a factor of almost 20, when instantiated in a way such that key derivation and puncturing together are cheaper on average than one full exponentiation in an RSA group. Hence, a 1 GB session cache can be replaced with only about 51 MBs of storage, which significantly reduces the amount of secure memory required. For larger security parameters or in exchange for more expensive computations, even larger storage reductions are achieved. The second construction combines a standard binary tree PPRF with a new “domain extension” technique. For a reasonable choice of parameters, this reduces the required storage by a factor of up to 5 compared to a standard session cache. It employs only symmetric cryptography, is suitable for high-traffic scenarios, and can serve thousands of tickets per second. Nimrod Aviram, Kai Gellert, Tibor Jager |
J. Cryptol. | 3 |
| 2021 | Bloom Filter Encryption and Applications to Efficient Forward-Secret 0-RTT Key ExchangeabstractAbstract Forward secrecy is considered an essential design goal of modern key establishment (KE) protocols, such as TLS 1.3, for example. Furthermore, efficiency considerations such as zero round-trip time (0-RTT), where a client is able to send cryptographically protected payload data along with the very first KE message, are motivated by the practical demand for secure low-latency communication. For a long time, it was unclear whether protocols that simultaneously achieve 0-RTT and full forward secrecy exist. Only recently, the first forward-secret 0-RTT protocol was described by Günther et al. (Eurocrypt, 2017). It is based on puncturable encryption. Forward secrecy is achieved by “puncturing” the secret key after each decryption operation, such that a given ciphertext can only be decrypted once (cf. also Green and Miers, S&P 2015). Unfortunately, their scheme is completely impractical, since one puncturing operation takes between 30 s and several minutes for reasonable security and deployment parameters, such that this solution is only a first feasibility result, but not efficient enough to be deployed in practice. In this paper, we introduce a new primitive that we term Bloom filter encryption (BFE), which is derived from the probabilistic Bloom filter data structure. We describe different constructions of BFE schemes and show how these yield new puncturable encryption mechanisms with extremely efficient puncturing. Most importantly, a puncturing operation only involves a small number of very efficient computations, plus the deletion of certain parts of the secret key, which outperforms previous constructions by orders of magnitude. This gives rise to the first forward-secret 0-RTT protocols that are efficient enough to be deployed in practice. We believe that BFE will find applications beyond forward-secret 0-RTT protocols. David Derler, Kai Gellert, Tibor Jager, Daniel Slamanig, Christoph Striecks |
J. Cryptol. | 3 |
| 2021 | On the Tight Security of TLS 1.3: Theoretically Sound Cryptographic Parameters for Real-World DeploymentsabstractAbstract We consider thetheoretically soundselection of cryptographic parameters, such as the size of algebraic groups or RSA keys, for TLS 1.3 in practice. While prior works gave security proofs for TLS 1.3, their security loss isquadraticin the total number of sessions across all users, which due to the pervasive use of TLS is huge. Therefore, in order to deploy TLS 1.3 in a theoretically sound way, it would be necessary to compensate this loss with unreasonably large parameters that would be infeasible for practical use at large scale. Hence, while these previous works show that in principle the design of TLS 1.3 is secure in an asymptotic sense, they do not yet provide any usefulconcretesecurity guarantees for real-world parameters used in practice. In this work, we provide a new security proof for the cryptographic core of TLS 1.3 in the random oracle model, which reduces the security of TLS 1.3tightly(that is, with constant security loss) to the (multi-user) security of its building blocks. For some building blocks, such as the symmetric record layer encryption scheme, we can then rely on prior work to establish tight security. For others, such as the RSA-PSS digital signature scheme currently used in TLS 1.3, we obtain at least alinearloss in the number of users, independent of the number of sessions, which is much easier to compensate with reasonable parameters. Our work also shows that by replacing the RSA-PSS scheme with a tightly secure scheme (e.g., in a future TLS version), one can obtain the first fully tightly secure TLS protocol. Our results enable a theoretically sound selection of parameters for TLS 1.3, even in large-scale settings with many users and sessions per user. Denis Diemert, Tibor Jager |
J. Cryptol. | 2 |
| 2020 | Offline Witness Encryption with Semi-adaptive Security
Peter Chvojka, Tibor Jager, Saqib A. Kakvi |
ACNS (1) | 2 |
| 2020 | Forward-Secure 0-RTT Goes Live: Implementation and Performance Analysis in QUIC
Fynn Dallmeier, Jan Peter Drees, Kai Gellert, Tobias Handirk, Tibor Jager, Jonas Klauke, Simon Nachtigall, Timo Renzelmann, Rudi Wolf |
CANS | 5 |
| 2019 | Highly Efficient Key Exchange Protocols with Optimal Tightness
Katriel Cohn-Gordon, Cas Cremers, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager |
CRYPTO (3) | 5 |
| 2019 | Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTT
Nimrod Aviram, Kai Gellert, Tibor Jager |
EUROCRYPT (2) | 3 |
| 2019 | On the Real-World Instantiability of Admissible Hash Functions and Efficient Verifiable Random Functions
Tibor Jager, David Niehues |
SAC | 1 |
| 2019 | On Tight Security Proofs for Schnorr Signatures
Nils Fleischhacker, Tibor Jager, Dominique Schröder |
J. Cryptol. | 2 |
| 2018 | Short Digital Signatures and ID-KEMs via Truncation Collision Resistance
Tibor Jager, Rafael Kurek |
ASIACRYPT (2) | 1 |
| 2018 | Simple and More Efficient PRFs with Tight Security from LWE and Matrix-DDH
Tibor Jager, Rafael Kurek, Jiaxin Pan 0001 |
ASIACRYPT (3) | 1 |
| 2018 | On the Security of the PKCS#1 v1.5 Signature SchemeabstractThe RSA PKCS#1 v1.5 signature algorithm is the most widely used digital signature scheme in practice. Its two main strengths are its extreme simplicity, which makes it very easy to implement, and that verification of signatures is significantly faster than for DSA or ECDSA. Despite the huge practical importance of RSA PKCS#1 v1.5 signatures, providing formal evidence for their security based on plausible cryptographic hardness assumptions has turned out to be very difficult. Therefore the most recent version of PKCS#1 (RFC 8017) even recommends a replacement the more complex and less efficient scheme RSA-PSS, as it is provably secure and therefore considered more robust. The main obstacle is that RSA PKCS#1 v1.5 signatures use a deterministic padding scheme, which makes standard proof techniques not applicable. We introduce a new technique that enables the first security proof for RSA-PKCS#1 v1.5 signatures. We prove full existential unforgeability against adaptive chosen-message attacks (EUF-CMA) under the standard RSA assumption. Furthermore, we give a tight proof under the Phi-Hiding assumption. These proofs are in the random oracle model and the parameters deviate slightly from the standard use, because we require a larger output length of the hash function. However, we also show how RSA-PKCS#1 v1.5 signatures can be instantiated in practice such that our security proofs apply. In order to draw a more complete picture of the precise security of RSA PKCS#1 v1.5 signatures, we also give security proofs in the standard model, but with respect to weaker attacker models (key-only attacks) and based on known complexity assumptions. The main conclusion of our work is that from a provable security perspective RSA PKCS#1 v1.5 can be safely used, if the output length of the hash function is chosen appropriately. Tibor Jager, Saqib A. Kakvi, Alexander May 0001 |
CCS | 1 |
| 2018 | Practical and Tightly-Secure Digital Signatures and Authenticated Key Exchange
Kristian Gjøsteen, Tibor Jager |
CRYPTO (2) | 2 |
| 2018 | Bloom Filter Encryption and Applications to Efficient Forward-Secret 0-RTT Key Exchange
David Derler, Tibor Jager, Daniel Slamanig, Christoph Striecks |
EUROCRYPT (3) | 2 |
| 2018 | How to build time-lock encryptionabstractTime-lock encryption is a method to encrypt a message such that it can only be decrypted after a certain deadline has passed. We propose a novel time-lock encryption scheme, whose main advantage over prior constructions is that even receivers with relatively weak computational resources should immediately be able to decrypt after the deadline, without any interaction with the sender, other receivers, or a trusted third party. We build our time-lock encryption on top of the new concept of computational reference clocks and an extractable witness encryption scheme. We explain how to construct a computational reference clock based on Bitcoin. We show how to achieve constant level of multilinearity for witness encryption by using SNARKs. We propose a new construction of a witness encryption scheme which is of independent interest: our scheme, based on Subset-Sum , achieves extractable security without relying on obfuscation. The scheme employs multilinear maps of arbitrary order and is independent of the implementations of multilinear maps. Jia Liu 0003, Tibor Jager, Saqib A. Kakvi, Bogdan Warinschi |
Des. Codes Cryptogr. | 2 |
| 2017 | Simple Security Definitions for and Constructions of 0-RTT Key Exchange
Britta Hale, Tibor Jager, Sebastian Lauer, Jörg Schwenk |
ACNS | 2 |
| 2017 | 0-RTT Key Exchange with Full Forward Secrecy
Felix Günther 0001, Britta Hale, Tibor Jager, Sebastian Lauer |
EUROCRYPT (3) | 3 |
| 2017 | Multi-key Authenticated Encryption with Corruptions: Reductions Are Lossy
Tibor Jager, Martijn Stam, Ryan Stanley-Oakes, Bogdan Warinschi |
TCC (1) | 1 |
| 2017 | Authenticated Confidential Channel Establishment and the Security of TLS-DHE
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk |
J. Cryptol. | 1 |
| 2016 | How to Generate and Use Universal Samplers
Dennis Hofheinz, Tibor Jager, Dakshita Khurana, Amit Sahai, Brent Waters, Mark Zhandry |
ASIACRYPT (2) | 2 |
| 2016 | Breaking PPTP VPNs via RADIUS Encryption
Matthias Horst, Martin Grothe, Tibor Jager, Jörg Schwenk |
CANS | 3 |
| 2016 | On the Impossibility of Tight Cryptographic Reductions
Christoph Bader, Tibor Jager, Yong Li 0021, Sven Schäge |
EUROCRYPT (2) | 2 |
| 2016 | Tightly secure signatures and public-key encryption
Dennis Hofheinz, Tibor Jager |
Des. Codes Cryptogr. | 2 |
| 2016 | Selective opening security of practical public-key encryption schemesabstractThe authors show that two well‐known and widely employed public‐key encryption schemes – RSA optimal asymmetric encryption padding (RSA‐OAEP) and Diffie–Hellman integrated encryption scheme (DHIES), instantiated with a one‐time pad, – are secure under (the strong, simulation‐based security notion of) selective opening security against chosen‐ciphertext attacks in the random oracle model. Both schemes are obtained via known generic transformations that transform relatively weak primitives (with security in the sense of one‐wayness) to indistinguishability (IND)‐CCA secure encryption schemes. The authors also show a similar result for the well‐known Fujisaki–Okamoto transformation that can generically turn a one‐way secure public key encryption system and a one‐time pad into a IND‐CCA‐secure public‐key encryption system. The authors prove that selective opening security comes for free in these transformations. Both DHIES and RSA‐OAEP are important building blocks in several standards for public key encryption and key exchange protocols. The Fujisaki–Okamoto transformation is very versatile and has successfully been utilised to build efficient lattice‐based cryptosystems. The considered schemes are the first practical cryptosystems that meet the strong notion of simulation‐based selective opening ( SIM‐SO‐CCA ) security. Felix Heuer, Tibor Jager, Sven Schäge, Eike Kiltz |
IET Inf. Secur. | 2 |
| 2016 | Black-Box Accumulation: Collecting Incentives in a Privacy-Preserving WayabstractAbstract We formalize and construct black-box accumulation (BBA), a useful building block for numerous important user-centric protocols including loyalty systems, refund systems, and incentive systems (as, e.g., employed in participatory sensing and vehicle-to-grid scenarios). A core requirement all these systems share is a mechanism to let users collect and sum up values (call it incentives, bonus points, reputation points, etc.) issued by some other parties in a privacy-preserving way such that curious operators may not be able to link the different transactions of a user. At the same time, a group of malicious users may not be able to cheat the system by pretending to have collected a higher amount than what was actually issued to them. As a first contribution, we fully formalize the core functionality and properties of this important building block. Furthermore, we present a generic and non-interactive construction of a BBA system based on homomorphic commitments, digital signatures, and non-interactive zero-knowledge proofs of knowledge. For our construction, we formally prove security and privacy properties. Finally, we propose a concrete instantiation of our construction using Groth-Sahai commitments and proofs as well as the optimal structure-preserving signature scheme of Abe et al. and analyze its efficiency. Tibor Jager, Andy Rupp |
Proc. Priv. Enhancing Technol. | 1 |
| 2015 | On the Security of TLS 1.3 and QUIC Against Weaknesses in PKCS#1 v1.5 EncryptionabstractEncrypted key transport with RSA-PKCS#1 v1.5 is the most commonly deployed key exchange method in all current versions of the Transport Layer Security (TLS) protocol, including the most recent version 1.2. However, it has several well-known issues, most importantly that it does not provide forward secrecy, and that it is prone to side channel attacks that may enable an attacker to learn the session key used for a TLS session. A long history of attacks shows that RSA-PKCS#1 v1.5 is extremely difficult to implement securely. The current draft of TLS version 1.3 dispenses with this encrypted key transport method. But is this sufficient to protect against weaknesses in RSA-PKCS#1 v1.5? Tibor Jager, Jörg Schwenk, Juraj Somorovsky |
CCS | 1 |
| 2015 | Practical Invalid Curve Attacks on TLS-ECDHabstractElliptic Curve Cryptography (ECC) is based on cyclic groups, where group elements are represented as points in a finite plane. All ECC cryptosystems implicitly assume that only valid group elements will be processed by the different cryptographic algorithms. It is well-known that a check for group membership of given points in the plane should be performed before processing. However, in several widely used cryptographic libraries we analyzed, this check was missing, in particular in the popular ECC implementations of Oracle and Bouncy Castle. We analyze the effect of this missing check on Oracle’s default Java TLS implementation (JSSE with a SunEC provider) and TLS servers using the Bouncy Castle library. It turns out that the effect on the security of TLS-ECDH is devastating. We describe an attack that allows to extract the long-term private key from a TLS server that uses such a vulnerable library. This allows an attacker to impersonate the legitimate server to any communication partner, after performing the attack only once. Tibor Jager, Jörg Schwenk, Juraj Somorovsky |
ESORICS (1) | 1 |
| 2015 | Tightly-Secure Authenticated Key Exchange
Christoph Bader, Dennis Hofheinz, Tibor Jager, Eike Kiltz, Yong Li 0021 |
TCC (1) | 3 |
| 2015 | Verifiable Random Functions from Weaker Assumptions
Tibor Jager |
TCC (2) | 1 |
| 2015 | Confined Guessing: New Signatures From Standard Assumptions
Florian Böhl, Dennis Hofheinz, Tibor Jager, Jessica Koch, Christoph Striecks |
J. Cryptol. | 3 |
| 2014 | On Tight Security Proofs for Schnorr Signatures
Nils Fleischhacker, Tibor Jager, Dominique Schröder |
ASIACRYPT (1) | 2 |
| 2013 | Practical Signatures from Standard Assumptions
Florian Böhl, Dennis Hofheinz, Tibor Jager, Jessica Koch, Jae Hong Seo, Christoph Striecks |
EUROCRYPT | 3 |
| 2013 | One Bad Apple: Backwards Compatibility Attacks on State-of-the-Art Cryptography
Tibor Jager, Kenneth G. Paterson, Juraj Somorovsky |
NDSS | 1 |
| 2013 | On the Analysis of Cryptographic Assumptions in the Generic Ring Model
Tibor Jager, Jörg Schwenk |
J. Cryptol. | 1 |
| 2012 | Tightly Secure Signatures and Public-Key Encryption
Dennis Hofheinz, Tibor Jager |
CRYPTO | 2 |
| 2012 | On the Security of TLS-DHE in the Standard Model
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk |
CRYPTO | 1 |
| 2012 | Bleichenbacher's Attack Strikes again: Breaking PKCS#1 v1.5 in XML Encryption
Tibor Jager, Sebastian Schinzel, Juraj Somorovsky |
ESORICS | 1 |
| 2011 | Short Signatures from Weaker Assumptions
Dennis Hofheinz, Tibor Jager, Eike Kiltz |
ASIACRYPT | 2 |
| 2011 | How to break XML encryptionabstractXML Encryption was standardized by W3C in 2002, and is implemented in XML frameworks of major commercial and open-source organizations like Apache, redhat, IBM, and Microsoft. It is employed in a large number of major web-based applications, ranging from business communications, e-commerce, and financial services over healthcare applications to governmental and military infrastructures. In this work we describe a practical attack on XML Encryption, which allows to decrypt a ciphertext by sending related ciphertexts to a Web Service and evaluating the server response. We show that an adversary can decrypt a ciphertext by performing only 14 requests per plaintext byte on average. This poses a serious and truly practical security threat on all currently used implementations of XML Encryption. Tibor Jager, Juraj Somorovsky |
CCS | 1 |
| 2010 | Generic Compilers for Authenticated Key Exchange
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk |
ASIACRYPT | 1 |
| 2010 | The Semi-Generic Group Model and Applications to Pairing-Based Cryptography
Tibor Jager, Andy Rupp |
ASIACRYPT | 1 |
| 2009 | On the Analysis of Cryptographic Assumptions in the Generic Ring Model
Tibor Jager, Jörg Schwenk |
ASIACRYPT | 1 |
| 2008 | A Browser-Based Kerberos Authentication Scheme
Sebastian Gajek, Tibor Jager, Mark Manulis, Jörg Schwenk |
ESORICS | 2 |
| 2008 | On Black-Box Ring Extraction and Integer Factorization
Kristina Altmann, Tibor Jager, Andy Rupp |
ICALP (2) | 2 |
| 2008 | On the Equivalence of Generic Group Models
Tibor Jager, Jörg Schwenk |
ProvSec | 1 |