Douglas Stebila

dblp:67/675 · DBLP profile ↗
← Back
58ranked-venue papers
5as first author
14since 2021 · last 2026
0000-0001-9443-3170ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 55 · 5 first-author · 14 since 2021Databases, data management, data science and information retrieval · 2Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 A Real-World Law-Enforcement Hack: The Case of Encrochat
Martin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas Stebila
CRYPTO (10)4
2025 Verifiable Decapsulation: Recognizing Faulty Implementations of Post-quantum KEMs
Lewis Glabush, Felix Günther 0001, Kathrin Hövelmanns, Douglas Stebila
CRYPTO (3)4
2025 Hybrid Obfuscated Key Exchange and KEMs
Felix Günther 0001, Michael Rosenberg, Douglas Stebila, Shannon Veitch
CRYPTO (3)3
2024 Quantum-Safe Account Recovery for WebAuthn
abstract
WebAuthn is a passwordless authentication protocol which allows users to authenticate to online services using public-key cryptography. Users prove their identity by signing a challenge with a private key, which is stored on a device such as a cell phone or a USB security token. This approach avoids many of the common security problems with password-based authentication.
Douglas Stebila, Spencer Wilson
AsiaCCS1
2024 Obfuscated Key Exchange
abstract
Censorship circumvention tools enable clients to access endpoints in a network despite the presence of a censor. Censors use a variety of techniques to identify content they wish to block, including filtering traffic patterns that are characteristic of proxy or circumvention protocols and actively probing potential proxy servers. Circumvention practitioners have developed fully encrypted protocols (FEPs), intended to have traffic that appears indistinguishable from random. A FEP is typically composed of a key exchange protocol to establish shared secret keys, and then a secure channel protocol to encrypt application data; both must avoid revealing to observers that an obfuscated protocol is in use.
Felix Günther 0001, Douglas Stebila, Shannon Veitch
CCS2
2024 TurboTLS: TLS Connection Establishment with 1 Less Round Trip
Carlos Aguilar Melchor, Thomas Bailleux, Jason Goertzen, Adrien Guinet, David Joseph, Douglas Stebila
ESORICS (2)6
2023 Making an Asymmetric PAKE Quantum-Annoying by Hiding Group Elements
Marcel Tiepelt, Edward Eaton, Douglas Stebila
ESORICS (1)3
2023 Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation
Jason Goertzen, Douglas Stebila
PQCrypto2
2022 Proof-of-Possession for KEM Certificates using Verifiable Generation
abstract
Certificate authorities in public key infrastructures typically require entities to prove possession of the secret key corresponding to the public key they want certified. While this is straightforward for digital signature schemes, the most efficient solution for public key encryption and key encapsulation mechanisms (KEMs) requires an interactive challenge-response protocol, requiring a departure from current issuance processes. In this work we investigate how to non-interactively prove possession of a KEM secret key, specifically for lattice-based KEMs, motivated by the recently proposed KEMTLS protocol which replaces signature-based authentication in TLS 1.3 with KEM-based authentication. Although there are various zero-knowledge (ZK) techniques that can be used to prove possession of a lattice key, they yield large proofs or are inefficient to generate. We propose a technique called verifiable generation, in which a proof of possession is generated at the same time as the key itself is generated. Our technique is inspired by the Picnic signature scheme and uses the multi-party-computation-in-the-head (MPCitH) paradigm; this similarity to a signature scheme allows us to bind attribute data to the proof of possession, as required by certificate issuance protocols. We show how to instantiate this approach for two lattice-based KEMs in Round 3 of the NIST post-quantum cryptography standardization project, Kyber and FrodoKEM, and achieve reasonable proof sizes and performance. Our proofs of possession are faster and an order of magnitude smaller than the previous best MPCitH technique for knowledge of a lattice key, and in size-optimized cases can be comparable to even state-of-the-art direct lattice-based ZK proofs for Kyber. Our approach relies on a new result showing the uniqueness of Kyber and FrodoKEM secret keys, even if the requirement that all secret key components are small is partially relaxed, which may be of independent interest for improving efficiency of zero-knowledge proofs for other lattice-based statements.
Tim Güneysu, Philip W. Hodges, Georg Land, Mike Ounsworth, Douglas Stebila, Gregory M. Zaverucha
CCS5
2022 A Tale of Two Models: Formal Verification of KEMTLS via Tamarin
Sofía Celi, Jonathan Hoyland, Douglas Stebila, Thom Wiggers
ESORICS (3)3
2021 SoK: Game-Based Security Models for Group Key Exchange
Bertram Poettering, Paul Rösler, Jörg Schwenk, Douglas Stebila
CT-RSA4
2021 More Efficient Post-quantum KEMTLS with Pre-distributed Public Keys
Peter Schwabe, Douglas Stebila, Thom Wiggers
ESORICS (1)2
2021 The "Quantum Annoying" Property of Password-Authenticated Key Exchange Protocols
Edward Eaton, Douglas Stebila
PQCrypto2
2021 A Cryptographic Analysis of the TLS 1.3 Handshake Protocol
abstract
Abstract We analyze the handshake protocol of the Transport Layer Security (TLS) protocol, version 1.3. We address both the full TLS 1.3 handshake (the one round-trip time mode, with signatures for authentication and (elliptic curve) Diffie–Hellman ephemeral ((EC)DHE) key exchange), and the abbreviated resumption/“PSK” mode which uses a pre-shared key for authentication (with optional (EC)DHE key exchange and zero round-trip time key establishment). Our analysis in the reductionist security framework uses a multi-stage key exchange security model, where each of the many session keys derived in a single TLS 1.3 handshake is tagged with various properties (such as unauthenticated versus unilaterally authenticated versus mutually authenticated, whether it is intended to provide forward security, how it is used in the protocol, and whether the key is protected against replay attacks). We show that these TLS 1.3 handshake protocol modes establish session keys with their desired security properties under standard cryptographic assumptions.
Benjamin Dowling, Marc Fischlin, Felix Günther 0001, Douglas Stebila
J. Cryptol.4
2020 Post-Quantum TLS Without Handshake Signatures
abstract
We present KEMTLS, an alternative to the TLS 1.3 handshake that uses key-encapsulation mechanisms (KEMs) instead of signatures for server authentication. Among existing post-quantum candidates, signature schemes generally have larger public key/signature sizes compared to the public key/ciphertext sizes of KEMs: by using an IND-CCA-secure KEM for server authentication in post-quantum TLS, we obtain multiple benefits. A size-optimized post-quantum instantiation of KEMTLS requires less than half the bandwidth of a size-optimized post-quantum instantiation of TLS 1.3. In a speed-optimized instantiation, KEMTLS reduces the amount of server CPU cycles by almost 90% compared to TLS 1.3, while at the same time reducing communication size, reducing the time until the client can start sending encrypted application data, and eliminating code for signatures from the server's trusted code base.
Peter Schwabe, Douglas Stebila, Thom Wiggers
CCS2
2020 Benchmarking Post-quantum Cryptography in TLS
Christian Paquin, Douglas Stebila, Goutam Tamvada
PQCrypto2
2020 Towards Post-Quantum Security for Signal's X3DH Handshake
Jacqueline Brendel, Marc Fischlin, Felix Günther 0001, Christian Janson, Douglas Stebila
SAC5
2020 A Formal Security Analysis of the Signal Messaging Protocol
Katriel Cohn-Gordon, Cas Cremers, Benjamin Dowling, Luke Garratt, Douglas Stebila
J. Cryptol.5
2020 Efficient Oblivious Database Joins
Simeon Krastnikov, Florian Kerschbaum, Douglas Stebila
Proc. VLDB Endow.3
2019 Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange
Nina Bindel, Jacqueline Brendel, Marc Fischlin, Brian Goncalves, Douglas Stebila
PQCrypto5
2017 A Formal Security Analysis of the Signal Messaging Protocol
abstract
Signal is a new security protocol and accompanying app that provides end-to-end encryption for instant messaging. The core protocol has recently been adopted by WhatsApp, Facebook Messenger, and Google Allo among many others, the first two of these have at least 1 billion active users. Signal includes several uncommon security properties (such as "future secrecy" or "post-compromise security"), enabled by a novel technique called ratcheting in which session keys are updated with every message sent. Despite its importance and novelty, there has been little to no academic analysis of the Signal protocol. We conduct the first security analysis of Signal's key agreement and double ratchet as a multi-stage key exchange protocol. We extract from the implementation a formal description of the abstract protocol, and define a security model which can capture the "ratcheting" key update structure. We then prove the security of Signal's core in our model, demonstrating several standard security properties. We have found no major flaws in the design, and hope that our presentation and results can serve as a starting point for other analyses of this widely adopted protocol.
Katriel Cohn-Gordon, Cas Cremers, Benjamin Dowling, Luke Garratt, Douglas Stebila
EuroS&P5
2017 Transitioning to a Quantum-Resistant Public Key Infrastructure
Nina Bindel, Udyani Herath, Matthew McKague, Douglas Stebila
PQCrypto4
2016 From Identification to Signatures, Tightly: A Framework and Generic Transforms
Mihir Bellare, Bertram Poettering, Douglas Stebila
ASIACRYPT (2)3
2016 Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWE
abstract
Lattice-based cryptography offers some of the most attractive primitives believed to be resistant to quantum computers. Following increasing interest from both companies and government agencies in building quantum computers, a number of works have proposed instantiations of practical post-quantum key exchange protocols based on hard problems in ideal lattices, mainly based on the Ring Learning With Errors (R-LWE) problem. While ideal lattices facilitate major efficiency and storage benefits over their non-ideal counterparts, the additional ring structure that enables these advantages also raises concerns about the assumed difficulty of the underlying problems. Thus, a question of significant interest to cryptographers, and especially to those currently placing bets on primitives that will withstand quantum adversaries, is how much of an advantage the additional ring structure actually gives in practice. Despite conventional wisdom that generic lattices might be too slow and unwieldy, we demonstrate that LWE-based key exchange is quite practical: our constant time implementation requires around 1.3ms computation time for each party; compared to the recent NewHope R-LWE scheme, communication sizes increase by a factor of 4.7x, but remain under 12 KiB in each direction. Our protocol is competitive when used for serving web pages over TLS; when partnered with ECDSA signatures, latencies increase by less than a factor of 1.6x, and (even under heavy load) server throughput only decreases by factors of 1.5x and 1.2x when serving typical 1 KiB and 100 KiB pages, respectively. To achieve these practical results, our protocol takes advantage of several innovations. These include techniques to optimize communication bandwidth, dynamic generation of public parameters (which also offers additional security against backdoors), carefully chosen error distributions, and tight security parameters.
Joppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov, Michael Naehrig, Valeria Nikolaenko, Ananth Raghunathan, Douglas Stebila
CCS8
2016 From Stateless to Stateful: Generic Authentication and Authenticated Encryption Constructions with Application to TLS
Colin Boyd, Britta Hale, Stig Fr. Mjølsnes, Douglas Stebila
CT-RSA4
2016 Secure Logging Schemes and Certificate Transparency
Benjamin Dowling, Felix Günther 0001, Udyani Herath, Douglas Stebila
ESORICS (2)4
2016 Safely Exporting Keys from Secure Channels - On the Security of EAP-TLS and TLS Key Exporters
Christopher Brzuska, Håkon Jacobsen, Douglas Stebila
EUROCRYPT (1)3
2016 Post-quantum Key Exchange for the Internet and the Open Quantum Safe Project
Douglas Stebila, Michele Mosca
SAC1
2016 Authenticated Network Time Synchronization
Benjamin Dowling, Douglas Stebila, Gregory M. Zaverucha
USENIX Security Symposium2
2015 Modelling Ciphersuite and Version Negotiation in the TLS Protocol
Benjamin Dowling, Douglas Stebila
ACISP2
2015 A Cryptographic Analysis of the TLS 1.3 Handshake Protocol Candidates
abstract
The Internet Engineering Task Force (IETF) is currently developing the next version of the Transport Layer Security (TLS) protocol, version 1.3. The transparency of this standardization process allows comprehensive cryptographic analysis of the protocols prior to adoption, whereas previous TLS versions have been scrutinized in the cryptographic literature only after standardization. This is even more important as there are two related, yet slightly different, candidates in discussion for TLS 1.3, called draft-ietf-tls-tls13-05 and draft-ietf-tls-tls13-dh-based. We give a cryptographic analysis of the primary ephemeral Diffie-Hellman-based handshake protocol, which authenticates parties and establishes encryption keys, of both TLS 1.3 candidates. We show that both candidate handshakes achieve the main goal of providing secure authenticated key exchange according to an augmented multi-stage version of the Bellare-Rogaway model. Such a multi-stage approach is convenient for analyzing the design of the candidates, as they establish multiple session keys during the exchange.
Benjamin Dowling, Marc Fischlin, Felix Günther 0001, Douglas Stebila
CCS4
2015 Continuous After-the-Fact Leakage-Resilient eCK-Secure Key Exchange
Janaka Alawatugoda 0001, Douglas Stebila, Colin Boyd
IMACC2
2015 Post-Quantum Key Exchange for the TLS Protocol from the Ring Learning with Errors Problem
abstract
Lattice-based cryptographic primitives are believed to offer resilience against attacks by quantum computers. We demonstrate the practicality of post-quantum key exchange by constructing cipher suites for the Transport Layer Security (TLS) protocol that provide key exchange based on the ring learning with errors (R-LWE) problem, we accompany these cipher suites with a rigorous proof of security. Our approach ties lattice-based key exchange together with traditional authentication using RSA or elliptic curve digital signatures: the post-quantum key exchange provides forward secrecy against future quantum attackers, while authentication can be provided using RSA keys that are issued by today's commercial certificate authorities, smoothing the path to adoption. Our cryptographically secure implementation, aimed at the 128-bit security level, reveals that the performance price when switching from non-quantum-safe key exchange is not too high. With our R-LWE cipher suites integrated into the Open SSL library and using the Apache web server on a 2-core desktop computer, we could serve 506 RLWE-ECDSA-AES128-GCM-SHA256 HTTPS connections per second for a 10 KiB payload. Compared to elliptic curve Diffie-Hellman, this means an 8 KiB increased handshake size and a reduction in throughput of only 21%. This demonstrates that provably secure post-quantum key-exchange can already be considered practical.
Joppe W. Bos, Craig Costello, Michael Naehrig, Douglas Stebila
IEEE Symposium on Security and Privacy4
2014 Continuous After-the-Fact Leakage-Resilient Key Exchange
Janaka Alawatugoda 0001, Colin Boyd, Douglas Stebila
ACISP3
2014 Modelling after-the-fact leakage for key exchange
abstract
Security models for two-party authenticated key exchange (AKE) protocols have developed over time to prove the security of AKE protocols even when the adversary learns certain secret values. In this work, we address more granular leakage: partial leakage of long-term secrets of protocol principals, even after the session key is established. We introduce a generic key exchange security model, which can be instantiated allowing bounded or continuous leakage, even when the adversary learns certain ephemeral secrets or session keys. Our model is the strongest known partial-leakage-based security model for key exchange protocols. We propose a generic construction of a two-pass leakage-resilient key exchange protocol that is secure in the proposed model, by introducing a new concept: the leakage-resilient NAXOS trick. We identify a special property for public-key cryptosystems: pair generation indistinguishability, and show how to obtain the leakage-resilient NAXOS trick from a pair generation indistinguishable leakage-resilient public-key cryptosystem.
Janaka Alawatugoda 0001, Douglas Stebila, Colin Boyd
AsiaCCS2
2014 Multi-Ciphersuite Security of the Secure Shell (SSH) Protocol
abstract
The Secure Shell (SSH) protocol is widely used to provide secure remote access to servers, making it among the most important security protocols on the Internet. We show that the signed-Diffie--Hellman SSH ciphersuites of the SSH protocol are secure: each is a secure authenticated and confidential channel establishment (ACCE) protocol, the same security definition now used to describe the security of Transport Layer Security (TLS) ciphersuites. While the ACCE definition suffices to describe the security of individual ciphersuites, it does not cover the case where parties use the same long-term key with many different ciphersuites: it is common in practice for the server to use the same signing key with both finite field and elliptic curve Diffie--Hellman, for example. While TLS is vulnerable to attack in this case, we show that SSH is secure even when the same signing key is used across multiple ciphersuites. We introduce a new generic multi-ciphersuite composition framework to achieve this result in a black-box way.
Florian Bergsma, Benjamin Dowling, Florian Kohlar, Jörg Schwenk, Douglas Stebila
CCS5
2014 Double-Authentication-Preventing Signatures
Bertram Poettering, Douglas Stebila
ESORICS (1)2
2013 Count-Min Sketches for Estimating Password Frequency within Hamming Distance Two
Leah F. South, Douglas Stebila
ACISP2
2013 On the security of TLS renegotiation
abstract
The Transport Layer Security (TLS) protocol is the most widely used security protocol on the Internet. It supports negotiation of a wide variety of cryptographic primitives through different cipher suites, various modes of client authentication, and additional features such as renegotiation. Despite its widespread use, only recently has the full TLS protocol been proven secure, and only the core cryptographic protocol with no additional features. These additional features have been the cause of several practical attacks on TLS. In 2009, Ray and Dispensa demonstrated how TLS renegotiation allows an attacker to splice together its own session with that of a victim, resulting in a man-in-the-middle attack on TLS-reliant applications such as HTTP. TLS was subsequently patched with two defence mechanisms for protection against this attack.
Florian Giesen, Florian Kohlar, Douglas Stebila
CCS3
2013 Comparative eye tracking of experts and novices in web single sign-on
abstract
Security indicators in web browsers alert users to the presence of a secure connection between their computer and a web server; many studies have shown that such indicators are largely ignored by users in general. In other areas of computer security, research has shown that technical expertise can decrease user susceptibility to attacks.
Majid Arianezhad, L. Jean Camp, Timothy Kelley, Douglas Stebila
CODASPY4
2013 Quantum One-Time Programs - (Extended Abstract)
Anne Broadbent, Gus Gutoski, Douglas Stebila
CRYPTO (2)3
2013 ASICS: Authenticated Key Exchange Security Incorporating Certification Systems
Colin Boyd, Cas Cremers, Michèle Feltz, Kenneth G. Paterson, Bertram Poettering, Douglas Stebila
ESORICS6
2013 Quantum Key Distribution in the Classical Authenticated Key Exchange Framework
Michele Mosca, Douglas Stebila, Berkant Ustaoglu
PQCrypto2
2013 Anonymity and one-way authentication in key exchange protocols
Ian Goldberg 0001, Douglas Stebila, Berkant Ustaoglu
Des. Codes Cryptogr.2
2013 Publicly verifiable ciphertexts
Juan Manuel González Nieto, Mark Manulis, Bertram Poettering, Jothi Rangasamy, Douglas Stebila
J. Comput. Secur.5
2012 Effort-Release Public-Key Encryption from Cryptographic Puzzles
Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto, Lakshmi Kuppusamy
ACISP2
2012 Practical client puzzles in the standard model
abstract
Client puzzles are cryptographic problems that are neither easy nor hard to solve. In this paper, we solve the problem of constructing cryptographic puzzles that are secure in the standard model and are very efficient. To prove the security of our puzzle, we introduce a new variant of the interval discrete logarithm assumption which may be of independent interest, and show this new problem to be hard under reasonable assumptions. Our experimental results show that, for 512-bit modulus, the solution verification time of our proposed puzzle can be up to 50x and 89x faster than that of the existing puzzles.
Lakshmi Kuppusamy, Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto
AsiaCCS3
2012 Analyzing the Effectiveness of Graph Metrics for Anomaly Detection in Online Social Networks
Reza Hassanzadeh, Richi Nayak, Douglas Stebila
WISE3
2011 An integrated approach to cryptographic mitigation of denial-of-service attacks
abstract
Gradual authentication is a principle proposed by Meadows as a way to tackle denial-of-service attacks on network protocols by gradually increasing the confidence in clients before the server commits resources. In this paper, we propose an efficient method that allows a defending server to authenticate its clients gradually with the help of some fast-to-verify measures. Our method integrates hash-based client puzzles along with a special class of digital signatures supporting fast verification. Our hash-based client puzzle provides finer granularity of difficulty and is proven secure in the puzzle difficulty model of Chen et al. (2009). We integrate this with the fast-verification digital signature scheme proposed by Bernstein (2000, 2008). These schemes can be up to 20 times faster for client authentication compared to RSA-based schemes. Our experimental results show that, in the Secure Sockets Layer (SSL) protocol, fast verification digital signatures can provide a 7% increase in connections per second compared to RSA signatures, and our integration of client puzzles with client authentication imposes no performance penalty on the server since puzzle verification is a part of signature verification.
Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto
AsiaCCS2
2011 Stronger Difficulty Notions for Client Puzzles and Denial-of-Service-Resistant Protocols
Douglas Stebila, Lakshmi Kuppusamy, Jothi Rangasamy, Colin Boyd, Juan Manuel González Nieto
CT-RSA1
2011 Defending Web Services against Denial of Service Attacks Using Client Puzzles
abstract
The interoperable and loosely-coupled web services architecture, while beneficial, can be resource-intensive, and is thus susceptible to denial of service (DoS) attacks in which an attacker can use a relatively insignificant amount of resources to exhaust the computational resources of a web service. We investigate the effectiveness of defending web services from DoS attacks using client puzzles, a cryptographic countermeasure which provides a form of gradual authentication by requiring the client to solve some computationally difficult problems before access is granted. In particular, we describe a mechanism for integrating a hash-based puzzle into existing web services frameworks and analyze the effectiveness of the countermeasure using a variety of scenarios on a network test bed. Client puzzles are an effective defence against flooding attacks. They can also mitigate certain types of semantic-based attacks, although they may not be the optimal solution.
Suriadi Suriadi, Douglas Stebila, Andrew J. Clark
ICWS2
2010 Predicate-Based Key Exchange
James Birkett, Douglas Stebila
ACISP2
2010 One-Time-Password-Authenticated Key Exchange
Kenneth G. Paterson, Douglas Stebila
ACISP2
2009 Towards Denial-of-Service-Resilient Key Agreement Protocols
Douglas Stebila, Berkant Ustaoglu
ACISP1
2006 Unified Point Addition Formulæ and Side-Channel Attacks
Douglas Stebila, Nicolas Thériault
CHES1
2004 Speeding up Secure Web Transactions Using Elliptic Curve Cryptography
Douglas Stebila, Stephen Fung, Sheueling Chang Shantz, Nils Gura, Hans Eberle
NDSS2
2003 Generic GF(2) Arithmetic in Software and Its Application to ECC
André Weimerskirch, Douglas Stebila, Sheueling Chang Shantz
ACISP2
2002 An End-to-End Systems Approach to Elliptic Curve Cryptography
Nils Gura, Sheueling Chang Shantz, Hans Eberle, Daniel F. Finchelstein, Edouard Goupy, Douglas Stebila
CHES8