EDBT 2026 Demo / reviewers in the wild / expert
Dennis Hofheinz
dblp:74/3914
· DBLP profile ↗
75ranked-venue papers
36as first author
13since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 73 · 36 first-author · 13 since 2021Theory of computation · 12 · 5 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tight Security for BBS Signatures
Rutchathon Chairattana-Apirom, Dennis Hofheinz, Stefano Tessaro |
EUROCRYPT (1) | 2 |
| 2025 | Tightly-Secure Blind Signatures in Pairing-Free GroupsabstractWe construct the first blind signature scheme that achieves all of the following properties simultaneously: The third property enables a reasonably efficient solution, and in fact signatures in our scheme comprise 10 group elements and 29 $$\mathbb {Z} _p$$ -elements. Our scheme starts from a pairing-based non-blind signature scheme (Abe et al., JoC 2023), and uses recent techniques of Chairattana-Apirom, Tessaro, and Zhu (CRYPTO 2024) to replace the pairings used in this scheme with non-interactive zero-knowledge proofs in the random oracle model. This conversion is not generic or straightforward (also because prior works have converted only significantly simpler signature schemes), and we are required to improve upon and innovate existing techniques in several places. As an interesting side note, and unlike previous works, our techniques only require a non-programmable random oracle, and our signature scheme achieves predicate blindness (which means that the user can prove statements about the signed message during the signing process). Nicholas Brandt, Dennis Hofheinz, Michael Klooß, Michael Reichle |
ASIACRYPT (6) | 2 |
| 2025 | Malleable SNARKs and Their Applications
Suvradip Chakraborty, Dennis Hofheinz, Roman Langrehr, Jesper Buus Nielsen, Christoph Striecks, Daniele Venturi 0001 |
EUROCRYPT (4) | 2 |
| 2025 | Securely Instantiating 'Half Gates' Garbling in the Standard Model
Anasuya Acharya, Karen Azari, Mirza Ahad Baig, Dennis Hofheinz, Chethan Kamath |
PKC (4) | 4 |
| 2025 | Non-interactive Key Exchange: New Notions, New Constructions, and Forward Security
Suvradip Chakraborty, Dennis Hofheinz, Roman Langrehr |
PKC (2) | 2 |
| 2024 | Identity-Based Encryption with (Almost) Tight Security in the Multi-instance, Multi-ciphertext SettingabstractAbstract We construct an identity-based encryption (IBE) scheme that is tightly secure in a very strong sense. Specifically, we consider a setting with many instances of the scheme and many encryptions per instance. In this setting, we reduce the security of our scheme to a variant of a simple assumption used for a similar purpose by Chen and Wee (CRYPTO 2013, Springer, 2013). The security loss of our reduction is $$\textbf{O} (k)$$ O(k) (where $$k $$ k is the security parameter). Our scheme is the first IBE scheme to achieve this strong flavor of tightness under a simple assumption. Technically, our scheme is a variation of the IBE scheme by Chen and Wee. However, in order to “lift” their results to the multi-instance, multi-ciphertext case, we need to develop new ideas. In particular, while we build on (and extend) their high-level proof strategy, we deviate significantly in the low-level proof steps. Dennis Hofheinz, Jessica Koch, Christoph Striecks |
J. Cryptol. | 1 |
| 2023 | The Power of Undirected Rewindings for Adaptive Security
Dennis Hofheinz, Julia Kastner 0001, Karen Azari |
CRYPTO (2) | 1 |
| 2023 | Deniable Authentication When Signing Keys Leak
Suvradip Chakraborty, Dennis Hofheinz, Ueli Maurer, Guilherme Rito |
EUROCRYPT (3) | 2 |
| 2023 | Compact Structure-Preserving Signatures with Almost Tight SecurityabstractAbstract In structure-preserving cryptography, every building block shares the same bilinear groups. These groups must be generated for a specific, a priori fixed security level, and thus, it is vital that the security reduction in all involved building blocks is as tight as possible. In this work, we present the first generic construction of structure-preserving signature schemes whose reduction cost is independent of the number of signing queries. Its chosen-message security is almost tightly reduced to the chosen-plaintext security of a structure-preserving public-key encryption scheme and the security of Groth–Sahai proof system. Technically, we adapt the adaptive partitioning technique by Hofheinz (Eurocrypt 2017) to the setting of structure-preserving signature schemes. To achieve a structure-preserving scheme, our new variant of the adaptive partitioning technique relies only on generic group operations in the scheme itself. Interestingly, however, we will use non-generic operations during our security analysis. Instantiated over asymmetric bilinear groups, the security of our concrete scheme is reduced to the external Diffie–Hellman assumption with linear reduction cost in the security parameter, independently of the number of signing queries. The signatures in our schemes consist of a larger number of group elements than those in other non-tight schemes, but can be verified faster, assuming their security reduction loss is compensated by increasing the security parameter to the next standard level. Masayuki Abe, Dennis Hofheinz, Ryo Nishimaki, Miyako Ohkubo, Jiaxin Pan 0001 |
J. Cryptol. | 2 |
| 2022 | The Price of Verifiability: Lower Bounds for Verifiable Random Functions
Nicholas Brandt, Dennis Hofheinz, Julia Kastner 0001, Akin Ünal |
TCC (2) | 2 |
| 2021 | Onion Routing with Replies
Christiane Weis, Dennis Hofheinz, Andy Rupp, Thorsten Strufe |
ASIACRYPT (2) | 2 |
| 2021 | On the Impossibility of Purely Algebraic Signatures
Nico Döttling, Dominik Hartmann, Dennis Hofheinz, Eike Kiltz, Sven Schäge, Bogdan Ursu |
TCC (3) | 3 |
| 2021 | Towards Tight Adaptive Security of Non-interactive Key Exchange
Julia Hesse, Dennis Hofheinz, Lisa Kohl, Roman Langrehr |
TCC (3) | 2 |
| 2020 | On Instantiating the Algebraic Group Model from Falsifiable Assumptions
Thomas Agrikola, Dennis Hofheinz, Julia Kastner 0001 |
EUROCRYPT (2) | 2 |
| 2020 | Multilinear Maps from ObfuscationabstractAbstract We provide constructions of multilinear groups equipped with natural hard problems from indistinguishability obfuscation, homomorphic encryption, and NIZKs. This complements known results on the constructions of indistinguishability obfuscators from multilinear maps in the reverse direction. We provide two distinct, but closely related constructions and show that multilinear analogues of the $${\text {DDH}} $$ DDH assumption hold for them. Our first construction is symmetric and comes with a $$\kappa $$ κ -linear map $$\mathbf{e }: {{\mathbb {G}}}^\kappa \longrightarrow {\mathbb {G}}_T$$ e:Gκ⟶GT for prime-order groups $${\mathbb {G}}$$ G and $${\mathbb {G}}_T$$ GT . To establish the hardness of the $$\kappa $$ κ -linear $${\text {DDH}} $$ DDH problem, we rely on the existence of a base group for which the $$\kappa $$ κ -strong $${\text {DDH}} $$ DDH assumption holds. Our second construction is for the asymmetric setting, where $$\mathbf{e }: {\mathbb {G}}_1 \times \cdots \times {\mathbb {G}}_{\kappa } \longrightarrow {\mathbb {G}}_T$$ e:G1×⋯×Gκ⟶GT for a collection of $$\kappa +1$$ κ+1 prime-order groups $${\mathbb {G}}_i$$ Gi and $${\mathbb {G}}_T$$ GT , and relies only on the 1-strong $${\text {DDH}} $$ DDH assumption in its base group. In both constructions, the linearity $$\kappa $$ κ can be set to any arbitrary but a priori fixed polynomial value in the security parameter. We rely on a number of powerful tools in our constructions: probabilistic indistinguishability obfuscation, dual-mode NIZK proof systems (with perfect soundness, witness-indistinguishability, and zero knowledge), and additively homomorphic encryption for the group $$\mathbb {Z}_N^{+}$$ ZN+ . At a high level, we enable “bootstrapping” multilinear assumptions from their simpler counterparts in standard cryptographic groups and show the equivalence of PIO and multilinear maps under the existence of the aforementioned primitives. Martin R. Albrecht, Pooya Farshim, Shuai Han 0001, Dennis Hofheinz, Enrique Larraia, Kenneth G. Paterson |
J. Cryptol. | 4 |
| 2019 | Dual-Mode NIZKs from Obfuscation
Dennis Hofheinz, Bogdan Ursu |
ASIACRYPT (1) | 1 |
| 2019 | Designated-Verifier Pseudorandom Generators, and Their Applications
Geoffroy Couteau, Dennis Hofheinz |
EUROCRYPT (2) | 2 |
| 2018 | Identity-Based Encryption Tightly Secure Under Chosen-Ciphertext Attacks
Dennis Hofheinz, Dingding Jia, Jiaxin Pan 0001 |
ASIACRYPT (2) | 1 |
| 2018 | On Tightly Secure Non-Interactive Key Exchange
Julia Hesse, Dennis Hofheinz, Lisa Kohl |
CRYPTO (2) | 2 |
| 2018 | More Efficient (Almost) Tightly Secure Structure-Preserving Signatures
Romain Gay, Dennis Hofheinz, Lisa Kohl, Jiaxin Pan 0001 |
EUROCRYPT (2) | 2 |
| 2018 | On the (Im-)Possibility of Extending Coin TossabstractWe consider the task of extending a given coin toss. By this, we mean the two-party task of using a single instance of a given coin toss protocol in order to interactively generate more random coins. A bit more formally, our goal is to generate n common random coins from a single use of an ideal functionality that gives $$m Dennis Hofheinz, Jörn Müller-Quade, Dominique Unruh |
J. Cryptol. | 1 |
| 2017 | Compact Structure-Preserving Signatures with Almost Tight Security
Masayuki Abe, Dennis Hofheinz, Ryo Nishimaki, Miyako Ohkubo, Jiaxin Pan 0001 |
CRYPTO (2) | 2 |
| 2017 | Kurosawa-Desmedt Meets Tight Security
Romain Gay, Dennis Hofheinz, Lisa Kohl |
CRYPTO (3) | 2 |
| 2017 | Adaptive Partitioning
Dennis Hofheinz |
EUROCRYPT (3) | 1 |
| 2017 | A Modular Analysis of the Fujisaki-Okamoto Transformation
Dennis Hofheinz, Kathrin Hövelmanns, Eike Kiltz |
TCC (1) | 1 |
| 2016 | How to Generate and Use Universal Samplers
Dennis Hofheinz, Tibor Jager, Dakshita Khurana, Amit Sahai, Brent Waters, Mark Zhandry |
ASIACRYPT (2) | 1 |
| 2016 | Tightly CCA-Secure Encryption Without Pairings
Romain Gay, Dennis Hofheinz, Eike Kiltz, Hoeteck Wee |
EUROCRYPT (1) | 2 |
| 2016 | Tightly secure signatures and public-key encryption
Dennis Hofheinz, Tibor Jager |
Des. Codes Cryptogr. | 1 |
| 2015 | Idealizing Identity-Based Encryption
Dennis Hofheinz, Christian Matt 0002, Ueli Maurer |
ASIACRYPT (1) | 1 |
| 2015 | Tightly-Secure Authenticated Key Exchange
Christoph Bader, Dennis Hofheinz, Tibor Jager, Eike Kiltz, Yong Li 0021 |
TCC (1) | 2 |
| 2015 | Subtleties in the Definition of IND-CCA: When and How Should Challenge Decryption Be Disallowed?
Mihir Bellare, Dennis Hofheinz, Eike Kiltz |
J. Cryptol. | 2 |
| 2015 | Confined Guessing: New Signatures From Standard Assumptions
Florian Böhl, Dennis Hofheinz, Tibor Jager, Jessica Koch, Christoph Striecks |
J. Cryptol. | 2 |
| 2015 | GNUC: A New Universal Composability Framework
Dennis Hofheinz, Victor Shoup |
J. Cryptol. | 1 |
| 2014 | Polynomial Spaces: A New Framework for Composite-to-Prime-Order Transformations
Gottfried Herold, Julia Hesse, Dennis Hofheinz, Carla Ràfols, Andy Rupp |
CRYPTO (1) | 3 |
| 2014 | A Generic View on Trace-and-Revoke Broadcast Encryption Schemes
Dennis Hofheinz, Christoph Striecks |
CT-RSA | 1 |
| 2014 | Standard versus Selective Opening Security: Separation and Equivalence Results
Dennis Hofheinz, Andy Rupp |
TCC | 1 |
| 2013 | Programmable Hash Functions in the Multilinear Setting
Eduarda S. V. Freire 0001, Dennis Hofheinz, Kenneth G. Paterson, Christoph Striecks |
CRYPTO (1) | 2 |
| 2013 | Practical Signatures from Standard Assumptions
Florian Böhl, Dennis Hofheinz, Tibor Jager, Jessica Koch, Jae Hong Seo, Christoph Striecks |
EUROCRYPT | 2 |
| 2013 | Circular Chosen-Ciphertext Security with Compact Ciphertexts
Dennis Hofheinz |
EUROCRYPT | 1 |
| 2013 | Practical Chosen Ciphertext Secure Encryption from Factoring
Dennis Hofheinz, Eike Kiltz, Victor Shoup |
J. Cryptol. | 1 |
| 2013 | Polynomial Runtime and Composability
Dennis Hofheinz, Dominique Unruh, Jörn Müller-Quade |
J. Cryptol. | 1 |
| 2012 | Tightly Secure Signatures and Public-Key Encryption
Dennis Hofheinz, Tibor Jager |
CRYPTO | 1 |
| 2012 | All-But-Many Lossy Trapdoor Functions
Dennis Hofheinz |
EUROCRYPT | 1 |
| 2012 | Bonsai Trees, or How to Delegate a Lattice Basis
David Cash, Dennis Hofheinz, Eike Kiltz, Chris Peikert |
J. Cryptol. | 2 |
| 2012 | Programmable Hash Functions and Their Applications
Dennis Hofheinz, Eike Kiltz |
J. Cryptol. | 1 |
| 2011 | Short Signatures from Weaker Assumptions
Dennis Hofheinz, Tibor Jager, Eike Kiltz |
ASIACRYPT | 1 |
| 2011 | Possibility and Impossibility Results for Selective Decommitments
Dennis Hofheinz |
J. Cryptol. | 1 |
| 2010 | Bounded Key-Dependent Message Security
Boaz Barak, Iftach Haitner, Dennis Hofheinz, Yuval Ishai |
EUROCRYPT | 3 |
| 2010 | Bonsai Trees, or How to Delegate a Lattice Basis
David Cash, Dennis Hofheinz, Eike Kiltz, Chris Peikert |
EUROCRYPT | 2 |
| 2010 | Encryption Schemes Secure against Chosen-Ciphertext Selective Opening Attacks
Serge Fehr, Dennis Hofheinz, Eike Kiltz, Hoeteck Wee |
EUROCRYPT | 2 |
| 2010 | A Twist on the Naor-Yung Paradigm and Its Application to Efficient CCA-Secure Encryption from Hard Search Problems
Ronald Cramer, Dennis Hofheinz, Eike Kiltz |
TCC | 2 |
| 2010 | Some (in)sufficient conditions for secure hybrid encryption
Javier Herranz, Dennis Hofheinz, Eike Kiltz |
Inf. Comput. | 2 |
| 2010 | Obfuscation for Cryptographic Purposes
Dennis Hofheinz, John Malone-Lee, Martijn Stam |
J. Cryptol. | 1 |
| 2009 | CoSP: a general framework for computational soundness proofsabstractWe describe CoSP, a general framework for conducting computational soundness proofs of symbolic models and for embedding these proofs into formal calculi. CoSP considers arbitrary equational theories and computational implementations, and it abstracts away many details that are not crucial for proving computational soundness, such as message scheduling, corruption models, and even the internal structure of a protocol. CoSP enables soundness results, in the sense of preservation of trace properties, to be proven in a conceptually modular and generic way: proving x cryptographic primitives sound for y calculi only requires x + y proofs (instead of x • y proofs without this framework), and the process of embedding calculi is conceptually decoupled from computational soundness proofs of cryptographic primitives. We exemplify the usefulness of CoSP by proving the first computational soundness result for the full-fledged applied π-calculus under active attacks. Concretely, we embed the applied π-calculus into CoSP and give a sound implementation of public-key encryption and digital signatures. Michael Backes 0001, Dennis Hofheinz, Dominique Unruh |
CCS | 2 |
| 2009 | The Group of Signed Quadratic Residues and Applications
Dennis Hofheinz, Eike Kiltz |
CRYPTO | 1 |
| 2009 | Possibility and Impossibility Results for Encryption and Commitment Secure under Selective Opening
Mihir Bellare, Dennis Hofheinz, Scott Yilek |
EUROCRYPT | 2 |
| 2009 | Practical Chosen Ciphertext Secure Encryption from Factoring
Dennis Hofheinz, Eike Kiltz |
EUROCRYPT | 1 |
| 2009 | The Kurosawa-Desmedt key encapsulation is not chosen-ciphertext secure
Seung Geol Choi, Javier Herranz, Dennis Hofheinz, Jung Yeon Hwang, Eike Kiltz, Dong Hoon Lee 0001, Moti Yung |
Inf. Process. Lett. | 3 |
| 2009 | Polynomial runtime in simulatability definitionsabstractWe elaborate on the problem of polynomial runtime in simulatability definitions for multi-party computation. First, the need for a new definition is demonstrated by showing which problems occur with common definitions of polynomial runtime. Then, we give a definition which captures in an intuitive manner what it means for a protocol or an adversary to have polynomial runtime. We show that this notion is suitable for simulatability definitions for multi-party computation. In particular, a composition theorem is shown for this notion. Dennis Hofheinz, Jörn Müller-Quade, Dominique Unruh |
J. Comput. Secur. | 1 |
| 2008 | Programmable Hash Functions and Their Applications
Dennis Hofheinz, Eike Kiltz |
CRYPTO | 1 |
| 2008 | Public-Key Encryption with Non-interactive Opening
Ivan Damgård, Dennis Hofheinz, Eike Kiltz, Rune Thorbek |
CT-RSA | 2 |
| 2008 | Towards Key-Dependent Message Security in the Standard Model
Dennis Hofheinz, Dominique Unruh |
EUROCRYPT | 1 |
| 2007 | Bounded CCA2-Secure Encryption
Ronald Cramer, Goichiro Hanaoka, Dennis Hofheinz, Hideki Imai, Eike Kiltz, Rafael Pass, Abhi Shelat, Vinod Vaikuntanathan |
ASIACRYPT | 3 |
| 2007 | Secure Hybrid Encryption from Weakened Key Encapsulation
Dennis Hofheinz, Eike Kiltz |
CRYPTO | 1 |
| 2007 | Obfuscation for Cryptographic Purposes
Dennis Hofheinz, John Malone-Lee, Martijn Stam |
TCC | 1 |
| 2006 | Conditional Reactive Simulatability
Michael Backes 0001, Markus Dürmuth, Dennis Hofheinz, Ralf Küsters |
ESORICS | 3 |
| 2006 | On the (Im-)Possibility of Extending Coin Toss
Dennis Hofheinz, Jörn Müller-Quade, Dominique Unruh |
EUROCRYPT | 1 |
| 2006 | Simulatable Security and Polynomially Bounded Concurrent ComposabilityabstractSimulatable security is a security notion for multi-party protocols that implies strong composability features. The main definitional flavours of simulatable security are standard simulatability, universal simulatability, and black-box simulatability. All three come in "computational," "statistical" and "perfect" subflavours indicating the considered adversarial power. Universal and black-box simulatability, in all of their subflavours, are already known to guarantee that the concurrent composition even of a polynomial number of secure protocols stays secure. We show that computational standard simulatability does not allow for secure concurrent composition of polynomially many protocols, but we also show that statistical standard simulatability does. The first result assumes the existence of an interesting cryptographic tool (namely time-lock puzzles), and its proof employs a cryptographic multi-party computation in an interesting and unconventional way Dennis Hofheinz, Dominique Unruh |
S&P | 1 |
| 2005 | Polynomial Runtime in Simulatability DefinitionsabstractWe elaborate on the problem of polynomial runtime in simulatability definitions for multiparty computation. First, the need for a new definition is demonstrated by showing which problems occur with common definitions of polynomial runtime. Then, we give a definition which captures in an intuitive manner what it means for a protocol or an adversary to have polynomial runtime. We show that this notion is suitable for simulatability definitions for multiparty computation. In particular, a composition theorem is shown for this notion. Dennis Hofheinz, Jörn Müller-Quade, Dominique Unruh |
CSFW | 1 |
| 2005 | On the Notion of Statistical Security in Simulatability Definitions
Dennis Hofheinz, Dominique Unruh |
ISC | 1 |
| 2005 | Comparing Two Notions of Simulatability
Dennis Hofheinz, Dominique Unruh |
TCC | 1 |
| 2004 | How to Break and Repair a Universally Composable Signature Functionality
Michael Backes 0001, Dennis Hofheinz |
ISC | 2 |
| 2004 | Universally Composable Commitments Using Random Oracles
Dennis Hofheinz, Jörn Müller-Quade |
TCC | 1 |
| 2004 | On the Security of Two Public Key Cryptosystems Using Non-Abelian Groups
María Isabel González Vasco, Dennis Hofheinz, Consuelo Martínez, Rainer Steinwandt |
Des. Codes Cryptogr. | 2 |
| 2003 | Initiator-Resilient Universally Composable Key Exchange
Dennis Hofheinz, Jörn Müller-Quade, Rainer Steinwandt |
ESORICS | 1 |