Tanja Lange 0001

dblp:56/2224 · DBLP profile ↗
← Back
41ranked-venue papers
4as first author
6since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 1 first-author · 6 since 2021Theory of computation · 4 · 3 first-author
YearPublicationVenuePosition
2025 Higher-Genus McEliece
Daniel J. Bernstein, Tanja Lange 0001, Alex Pellegrini
ASIACRYPT (4)2
2025 A Key-Update Mechanism for the Space Data Link Security Protocol
Andreas Hülsing, Tanja Lange 0001, Fiona Johanna Weber
CANS2
2025 PQConnect: Automated Post-Quantum End-to-End Tunnels
Daniel J. Bernstein, Tanja Lange 0001, Jonathan Levin 0002, Bo-Yin Yang
NDSS2
2023 Concrete Analysis of Quantum Lattice Enumeration
Shi Bai 0001, Maya-Iggy van Hoof, Floyd Johnson, Tanja Lange 0001, Tran Ngo
ASIACRYPT (3)4
2023 Disorientation Faults in CSIDH
Gustavo Banegas, Juliane Krämer, Tanja Lange 0001, Michael Meyer 0001, Lorenz Panny, Krijn Reijnders, Jana Sotáková, Monika Trimoska
EUROCRYPT (5)3
2021 Verifying Post-Quantum Signatures in 8 kB of RAM
Andreas Hülsing, Matthias J. Kannwischer, Juliane Krämer, Tanja Lange 0001, Marc Stöttinger, Elisabeth Waitz, Thom Wiggers, Bo-Yin Yang
PQCrypto5
2020 McTiny: Fast High-Confidence Post-Quantum Key Erasure for Tiny Network Servers
Daniel J. Bernstein, Tanja Lange 0001
USENIX Security Symposium2
2019 Quantum Circuits for the CSIDH: Optimizing Quantum Evaluation of Isogenies
Daniel J. Bernstein, Tanja Lange 0001, Chloe Martindale, Lorenz Panny
EUROCRYPT (2)2
2018 CSIDH: An Efficient Post-Quantum Commutative Group Action
abstract
We propose an efficient commutative group action suitable for non-interactive key exchange in a post-quantum setting. Our construction follows the layout of the Couveignes–Rostovtsev–Stolbunov cryptosystem, but we apply it to supersingular elliptic curves defined over a large prime field $$\mathbb F_p$$ , rather than to ordinary elliptic curves. The Diffie–Hellman scheme resulting from the group action allows for public-key validation at very little cost, runs reasonably fast in practice, and has public keys of only 64 bytes at a conjectured AES-128 security level, matching NIST’s post-quantum security category I.
Wouter Castryck, Tanja Lange 0001, Chloe Martindale, Lorenz Panny, Joost Renes
ASIACRYPT (3)2
2017 Sliding Right into Disaster: Left-to-Right Sliding Windows Leak
Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange 0001, Christine van Vredendaal, Yuval Yarom
CHES6
2017 Short Generators Without Quantum Computers: The Case of Multiquadratics
Jens Bauch, Daniel J. Bernstein, Henry de Valence, Tanja Lange 0001, Christine van Vredendaal
EUROCRYPT (1)4
2017 NTRU Prime: Reducing Attack Surface at Low Cost
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001, Christine van Vredendaal
SAC3
2017 Lattice Klepto - Turning Post-Quantum Crypto Against Itself
abstract
This paper studies ways to backdoor lattice-based systems following Young and Yung’s work on backdooring RSA and discrete-log based systems. For the NTRU encryption scheme we show how to build a backdoor and to change the system so that each ciphertext leaks information about the plaintext to the owner of the backdoor. For signature schemes the backdoor leaks information about the signing key to the backdoor owner. As in Young and Yung’s work the backdoor uses the freedom that random selections offer in the protocol to hide a secret message encrypted to the backdoor owner. The most interesting and very different part though is how to hide and retrieve the hidden messages.
Robin Kwant, Tanja Lange 0001, Kimberley Thissen
SAC2
2016 Flush, Gauss, and Reload - A Cache Attack on the BLISS Lattice-Based Signature Scheme
Leon Groot Bruinderink, Andreas Hülsing, Tanja Lange 0001, Yuval Yarom
CHES3
2015 Bad Directions in Cryptographic Hash Functions
Daniel J. Bernstein, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen
ACISP3
2015 SPHINCS: Practical Stateless Hash-Based Signatures
abstract
This paper introduces a high-security post-quantum stateless hash-based signature scheme that signs hundreds of messages per second on a modern 4-core 3.5GHz Intel CPU. Signatures are 41 KB, public keys are 1 KB, and private keys are 1 KB. The signature scheme is designed to provide long-term $$2^{128}$$ security even against attackers equipped with quantum computers. Unlike most hash-based designs, this signature scheme is stateless, allowing it to be a drop-in replacement for current signature schemes.
Daniel J. Bernstein, Daira Hopwood, Andreas Hülsing, Tanja Lange 0001, Ruben Niederhagen, Louiza Papachristodoulou, Michael Schneider 0002, Peter Schwabe, Zooko Wilcox-O'Hearn
EUROCRYPT (1)4
2014 Kummer Strikes Back: New DH Speed Records
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001, Peter Schwabe
ASIACRYPT (1)3
2014 Kangaroos in Side-Channel Attacks
Tanja Lange 0001, Christine van Vredendaal, Marnix Wakker
CARDIS1
2014 Curve41417: Karatsuba Revisited
Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange 0001
CHES3
2014 Batch NFS
Daniel J. Bernstein, Tanja Lange 0001
Selected Areas in Cryptography2
2014 On the Practical Exploitability of Dual EC in TLS Implementations
Stephen Checkoway, Ruben Niederhagen, Adam Everspaugh, Matthew Green 0001, Tanja Lange 0001, Thomas Ristenpart, Daniel J. Bernstein, Jake Maskiewicz, Hovav Shacham, Matt Fredrikson
USENIX Security Symposium5
2013 Factoring RSA Keys from Certified Smart Cards: Coppersmith in the Wild
Daniel J. Bernstein, Yun-An Chang, Chen-Mou Cheng, Li-Ping Chou, Nadia Heninger, Tanja Lange 0001, Nicko van Someren
ASIACRYPT (2)6
2013 Non-uniform Cracks in the Concrete: The Power of Free Precomputation
Daniel J. Bernstein, Tanja Lange 0001
ASIACRYPT (2)2
2013 Elligator: elliptic-curve points indistinguishable from uniform random strings
abstract
Censorship-circumvention tools are in an arms race against censors. The censors study all traffic passing into and out of their controlled sphere, and try to disable censorship-circumvention tools without completely shutting down the Internet. Tools aim to shape their traffic patterns to match unblocked programs, so that simple traffic profiling cannot identify the tools within a reasonable number of traces; the censors respond by deploying firewalls with increasingly sophisticated deep-packet inspection. Cryptography hides patterns in user data but does not evade censorship if the censor can recognize patterns in the cryptography itself. In particular, elliptic-curve cryptography often transmits points on known elliptic curves, and those points are easily distinguishable from uniform random strings of bits.
Daniel J. Bernstein, Michael Hamburg, Anna Krasnova, Tanja Lange 0001
CCS4
2013 MinimaLT: minimal-latency networking through better security
abstract
MinimaLT is a new network protocol that provides ubiquitous encryption for maximal confidentiality, including protecting packet headers. MinimaLT provides server and user authentication, extensive Denial-of-Service protections, privacy-preserving IP mobility, and fast key erasure. We describe the protocol, demonstrate its performance relative to TLS and unencrypted TCP/IP, and analyze its protections, including its resilience against DoS attacks. By exploiting the properties of its cryptographic protections, MinimaLT is able to eliminate three way handshakes and thus create connections faster than unencrypted TCP/IP.
W. Michael Petullo, Jon A. Solworth, Daniel J. Bernstein, Tanja Lange 0001
CCS5
2013 Quantum Algorithms for the Subset-Sum Problem
Daniel J. Bernstein, Stacey Jeffery, Tanja Lange 0001, Alexander Meurer
PQCrypto3
2011 High-Speed High-Security Signatures
Daniel J. Bernstein, Niels Duif, Tanja Lange 0001, Peter Schwabe, Bo-Yin Yang
CHES3
2011 Smaller Decoding Exponents: Ball-Collision Decoding
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
CRYPTO2
2011 Wild McEliece Incognito
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
PQCrypto2
2010 Type-II Optimal Polynomial Bases
Daniel J. Bernstein, Tanja Lange 0001
WAIFI2
2009 ECM on Graphics Cards
Daniel J. Bernstein, Tien-Ren Chen, Chen-Mou Cheng, Tanja Lange 0001, Bo-Yin Yang
EUROCRYPT4
2008 Binary Edwards Curves
Daniel J. Bernstein, Tanja Lange 0001, Reza Rezaeian Farashahi
CHES2
2008 Attacking and Defending the McEliece Cryptosystem
Daniel J. Bernstein, Tanja Lange 0001, Christiane Peters
PQCrypto2
2008 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
J. Cryptol.6
2007 Faster Addition and Doubling on Elliptic Curves
Daniel J. Bernstein, Tanja Lange 0001
ASIACRYPT2
2005 Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi
CRYPTO6
2003 Improved Algorithms for Efficient Arithmetic on Elliptic Curves Using Fast Endomorphisms
Mathieu Ciet, Tanja Lange 0001, Francesco Sica 0001, Jean-Jacques Quisquater
EUROCRYPT2
2003 Interpolation of the Discrete Logarithm in Fq by Boolean Functions and by Polynomials in Several Variables Modulo a Divisor of Q-1
Tanja Lange 0001, Arne Winterhof
Discret. Appl. Math.1
2003 Linear Complexity of the Discrete Logarithm
Sergei Konyagin, Tanja Lange 0001, Igor E. Shparlinski
Des. Codes Cryptogr.2
2002 Polynomial Interpolation of the Elliptic Curve and XTR Discrete Logarithm
Tanja Lange 0001, Arne Winterhof
COCOON1
2000 Factoring polynomials over arbitrary finite fields
Tanja Lange 0001, Arne Winterhof
Theor. Comput. Sci.1