EDBT 2026 Demo / reviewers in the wild / expert
Christopher Brzuska
dblp:88/5874 · also Chris Brzuska, Christina Brzuska
· DBLP profile ↗
36ranked-venue papers
21as first author
15since 2021 · last 2026
0009-0001-7485-1217ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 21 first-author · 14 since 2021Theory of computation · 5 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Simple Attacks Against (Extended) Fiat-Shamir
Christopher Brzuska, Pavel Hubácek, Aleksi Kalsta |
PKC (1) | 1 |
| 2026 | Threshold Public-Key Encryption: Definitions, Relations, and CPA-to-CCA Transforms
Christopher Brzuska, Michael Klooß, Ivy K. Y. Woo |
PKC (4) | 1 |
| 2026 | Project Everest: Perspectives from Developing Industrial-Grade High-Assurance SoftwareabstractProject Everest began at Microsoft Research in 2016, aiming to spur research in program verification to produce industrial-grade software. In collaboration with INRIA and Carnegie Mellon University, Project Everest’s goal was to produce drop-in verified replacements of secure communications software used in the HTTPS ecosystem, including TLS, the underlying cryptography, and related subprotocols. Now, almost a decade later, we reflect on the project, sharing both its successes and failures, and look ahead to the next decade of program verification research. Danel Ahman, Karthikeyan Bhargavan, Barry Bond, Jay Bosamiya, Christopher Brzuska, Antoine Delignat-Lavaud, Cédric Fournet, Aymeric Fromherz, Sydney Gibson, Chris Hawblitzel, Catalin Hritcu, Markulf Kohlweiss, Guido Martínez, Haobin Ni, Bryan Parno, Jonathan Protzenko, Tahina Ramananandro, Aseem Rastogi, Exequiel Rivas, Nikhil Swamy, Santiago Zanella-Béguelin |
ACM Trans. Program. Lang. Syst. | 5 |
| 2025 | Succinct PPRFs via Memory-Tight Reductions
Joël Alwen, Christopher Brzuska, Jérôme Govinden, Patrick Harasser, Stefano Tessaro |
CRYPTO (5) | 2 |
| 2025 | On Building Fine-Grained One-Way Functions from Strong Average-Case HardnessabstractAbstract Constructing one-way functions from average-case hardness is a long-standing open problem. A positive result would exclude Pessiland (Impagliazzo ’95) and establish a highly desirable win–win situation: either (symmetric) cryptography exists unconditionally, or all $$\textsf{NP} $$ NP problems can be solved efficiently on the average. Motivated by the lack of progress on this seemingly very hard question, we initiate the investigation of weaker yet meaningful candidate win–win results of the following type: either there are fine-grained one-way functions (FGOWF), or non-trivial speedups can be obtained for all $$\textsf{NP} $$ NP problems on the average. FGOWFs only require a fixed polynomial gap (as opposed to superpolynomial) between the running time of the function and the running time of an inverter. We obtain three main results: Construction. We show that if there is an $$\textsf{NP} $$ NP language having a very strong form of average-case hardness, which we call block finding hardness, then FGOWF exist. We provide heuristic support for this very strong average-case hardness notion by showing that it holds for a random language. Then, we study whether weaker (and more natural) forms of average-case hardness could already suffice to obtain FGOWF and obtain two negative results: Separation I. We provide a strong oracle separation for the implication ( $$\exists $$ ∃ exponentially average-case hard $$\textsf{NP} $$ NP language $$\implies $$ ⇒ $$\exists $$ ∃ FGOWF). Separation II. We provide a second strong negative result for an even weaker candidate win–win result. Namely, we rule out a relativizing proof for the implication ( $$\exists $$ ∃ exponentially average-case $$\textsf{NP} $$ NP hard language whose hardness amplifies optimally through parallel repetitions $$\implies $$ ⇒ $$\exists $$ ∃ FGOWF). This separation forms the core technical contribution of our work. Christopher Brzuska, Geoffroy Couteau |
J. Cryptol. | 1 |
| 2024 | Breaking DPA-Protected Kyber via the Pair-Pointwise Multiplication
Estuardo Alpirez Bock, Gustavo Banegas, Christopher Brzuska, Lukasz Chmielewski, Kirthivaasan Puniamurthy, Milan Sorf |
ACNS (2) | 3 |
| 2024 | CryptoZoo: A Viewer for Reduction Proofs
Christopher Brzuska, Christoph Egger 0001, Kirthivaasan Puniamurthy |
ACNS (1) | 1 |
| 2024 | Evasive LWE Assumptions: Definitions, Classes, and Counterexamples
Christopher Brzuska, Akin Ünal, Ivy K. Y. Woo |
ASIACRYPT (4) | 1 |
| 2024 | On Bounded Storage Key Agreement and One-Way Functions
Christopher Brzuska, Geoffroy Couteau, Christoph Egger 0001, Willy Quach |
TCC (1) | 1 |
| 2023 | Adaptive Distributional Security for Garbling Schemes with 𝒪(|x|) Online Complexity
Estuardo Alpirez Bock, Christopher Brzuska, Pihla Karanko, Sabine Oechsner, Kirthivaasan Puniamurthy |
ASIACRYPT (1) | 2 |
| 2023 | A State-Separating Proof for Yao's Garbling SchemeabstractSecure multiparty computation enables mutually distrusting parties to compute a public function of their secret inputs. One of the main approaches for designing MPC protocols are garbled circuits whose core component is usually referred to as a garbling scheme. In this work, we revisit the security of Yao's garbling scheme and provide a modular security proof which composes the security of multiple layer garblings to prove security of the full circuit garbling. We perform our security proof in the style of state-separating proofs (ASIACRYPT 2018). Christopher Brzuska, Sabine Oechsner |
CSF | 1 |
| 2022 | Key-Schedule Security for the TLS 1.3 Standard
Christopher Brzuska, Antoine Delignat-Lavaud, Christoph Egger 0001, Cédric Fournet, Konrad Kohbrok, Markulf Kohlweiss |
ASIACRYPT (1) | 1 |
| 2022 | On Building Fine-Grained One-Way Functions from Strong Average-Case Hardness
Christopher Brzuska, Geoffroy Couteau |
EUROCRYPT (2) | 1 |
| 2022 | Security Analysis of the MLS Key DerivationabstractCryptographic communication protocols provide confidentiality, integrity and authentication properties for end-to-end communication under strong corruption attacks, including, notably, post-compromise security (PCS). Most protocols are designed for one-to-one communication. Protocols for group communication are less common, less efficient, and tend to provide weaker security guarantees. This is because group communication poses unique challenges, such as coordinated key updates, changes to group membership and complex post-compromise recovery procedures. We need to tackle this complex challenge as a community. Thus, the Internet Engineering Task Force (IETF) has created a working group with the goal of developing a sound standard for a continuous asynchronous key-exchange protocol for dynamic groups that is secure and remains efficient for large group sizes. The current version of the Messaging Layer Security (MLS) security protocol is in a feature freeze, i.e., no changes are made in order to provide a stable basis for cryptographic analysis. The key schedule and TreeKEM design are of particular concern since they are crucial to distribute and combine several keys to achieve PCS. In this work, we study the MLS continuous group key derivation (CGKD) which comprises the MLS key schedule, TreeKEM and their composition, as specified in Draft 11 of the MLS RFC, while abstracting away signatures, message flow and authentication guarantees. We establish the uniqueness and key indistinguishability properties of the MLS CGKD as computational security properties. Christopher Brzuska, Eric Cornelissen, Konrad Kohbrok |
SP | 1 |
| 2021 | On Derandomizing Yao's Weak-to-Strong OWF Construction
Christopher Brzuska, Geoffroy Couteau, Pihla Karanko, Felix Rohrbach |
TCC (2) | 1 |
| 2020 | Security Reductions for White-Box Key-Storage in Mobile Payments
Estuardo Alpirez Bock, Christopher Brzuska, Marc Fischlin, Christian Janson, Wil Michiels |
ASIACRYPT (1) | 2 |
| 2019 | Doubly Half-Injective PRGs for Incompressible White-Box Cryptography
Estuardo Alpirez Bock, Alessandro Amadori, Joppe W. Bos, Christopher Brzuska, Wil Michiels |
CT-RSA | 4 |
| 2019 | White-Box Cryptography: Don't Forget About Grey-Box Attacks
Estuardo Alpirez Bock, Joppe W. Bos, Christopher Brzuska, Charles Hubain, Wil Michiels, Cristofaro Mune, Eloi Sanfelix Gonzalez, Philippe Teuwen, Alexander Treff |
J. Cryptol. | 3 |
| 2018 | On the Ineffectiveness of Internal Encodings - Revisiting the DCA Attack on White-Box Cryptography
Estuardo Alpirez Bock, Christopher Brzuska, Wil Michiels, Alexander Treff |
ACNS | 2 |
| 2018 | State Separation for Code-Based Game-Playing Proofs
Christopher Brzuska, Antoine Delignat-Lavaud, Cédric Fournet, Konrad Kohbrok, Markulf Kohlweiss |
ASIACRYPT (3) | 1 |
| 2017 | Arithmetic CryptographyabstractWe study the possibility of computing cryptographic primitives in a fully black-box arithmetic model over a finite field F . In this model, the input to a cryptographic primitive (e.g., encryption scheme) is given as a sequence of field elements, the honest parties are implemented by arithmetic circuits that make only a black-box use of the underlying field, and the adversary has a full (non-black-box) access to the field. This model captures many standard information-theoretic constructions. We prove several positive and negative results in this model for various cryptographic tasks. On the positive side, we show that, under coding-related intractability assumptions, computational primitives like commitment schemes, public-key encryption, oblivious transfer, and general secure two-party computation can be implemented in this model. On the negative side, we prove that garbled circuits, additively homomorphic encryption, and secure computation with low online complexity cannot be achieved in this model. Our results reveal a qualitative difference between the standard Boolean model and the arithmetic model, and explain, in retrospect, some of the limitations of previous constructions. Benny Applebaum, Jonathan Avron, Christopher Brzuska |
J. ACM | 3 |
| 2016 | On Statistically Secure Obfuscation with Approximate Correctness
Zvika Brakerski, Christopher Brzuska, Nils Fleischhacker |
CRYPTO (2) | 2 |
| 2016 | Safely Exporting Keys from Secure Channels - On the Security of EAP-TLS and TLS Key Exporters
Christopher Brzuska, Håkon Jacobsen, Douglas Stebila |
EUROCRYPT (1) | 1 |
| 2016 | Downgrade Resilience in Key-Exchange ProtocolsabstractKey-exchange protocols such as TLS, SSH, IPsec, and ZRTP are highly configurable, with typical deployments supporting multiple protocol versions, cryptographic algorithms and parameters. In the first messages of the protocol, the peers negotiate one specific combination: the protocol mode, based on their local configurations. With few notable exceptions, most cryptographic analyses of configurable protocols consider a single mode at a time. In contrast, downgrade attacks, where a network adversary forces peers to use a mode weaker than the one they would normally negotiate, are a recurrent problem in practice. How to support configurability while at the same time guaranteeing the preferred mode is negotiated? We set to answer this question by designing a formal framework to study downgrade resilience and its relation to other security properties of key-exchange protocols. First, we study the causes of downgrade attacks by dissecting and classifying known and novel attacks against widely used protocols. Second, we survey what is known about the downgrade resilience of existing standards. Third, we combine these findings to define downgrade security, and analyze the conditions under which several protocols achieve it. Finally, we discuss patterns that guarantee downgrade security by design, and explain how to use them to strengthen the security of existing protocols, including a newly proposed draft of TLS 1.3. Karthikeyan Bhargavan, Christopher Brzuska, Cédric Fournet, Matthew Green 0001, Markulf Kohlweiss, Santiago Zanella-Béguelin |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | Arithmetic Cryptography: Extended AbstractabstractWe study the possibility of computing cryptographic primitives in a fully-black-box arithmetic model over a finite field $\F$. In this model, the input to a cryptographic primitive (e.g., encryption scheme) is given as a sequence of field elements, the honest parties are implemented by arithmetic circuits which make only a black-box use of the underlying field, and the adversary has a full (non-black-box) access to the field. This model captures many standard information-theoretic constructions. Benny Applebaum, Jonathan Avron, Christopher Brzuska |
ITCS | 3 |
| 2015 | On Basing Size-Verifiable One-Way Functions on NP-Hardness
Andrej Bogdanov, Christopher Brzuska |
TCC (1) | 2 |
| 2015 | Random-Oracle Uninstantiability from Indistinguishability Obfuscation
Christopher Brzuska, Pooya Farshim, Arno Mittelbach |
TCC (2) | 1 |
| 2014 | Using Indistinguishability Obfuscation via UCEs
Christopher Brzuska, Arno Mittelbach |
ASIACRYPT (2) | 1 |
| 2014 | Indistinguishability Obfuscation versus Multi-bit Point Obfuscation with Auxiliary Input
Christopher Brzuska, Arno Mittelbach |
ASIACRYPT (2) | 1 |
| 2014 | Indistinguishability Obfuscation and UCEs: The Case of Computationally Unpredictable Sources
Christopher Brzuska, Pooya Farshim, Arno Mittelbach |
CRYPTO (1) | 1 |
| 2013 | Notions of Black-Box Reductions, Revisited
Paul Baecher, Christopher Brzuska, Marc Fischlin |
ASIACRYPT (1) | 2 |
| 2013 | Reset Indifferentiability and Its Consequences
Paul Baecher, Christopher Brzuska, Arno Mittelbach |
ASIACRYPT (1) | 2 |
| 2013 | An analysis of the EMV channel establishment protocolabstractWith over 1.6 billion debit and credit cards in use worldwide, the EMV system (a.k.a. "Chip-and-PIN") has become one of the most important deployed cryptographic protocol suites. Recently, the EMV consortium has decided to upgrade the existing RSA based system with a new system relying on Elliptic Curve Cryptography (ECC). One of the central components of the new system is a protocol that enables a card to establish a secure channel with a card reader. In this paper we provide a security analysis of the proposed protocol, we propose minor changes/clarifications to the "Request for Comments" issued in Nov 2012, and demonstrate that the resulting protocol meets the intended security goals. Christopher Brzuska, Nigel P. Smart, Bogdan Warinschi, Gaven J. Watson |
CCS | 1 |
| 2011 | Composability of bellare-rogaway key exchange protocolsabstractIn this paper we examine composability properties for the fundamental task of key exchange. Roughly speaking, we show that key exchange protocols secure in the prevalent model of Bellare and Rogaway can be composed with arbitrary protocols that require symmetrically distributed keys. This composition theorem holds if the key exchange protocol satisfies an additional technical requirement that our analysis brings to light: it should be possible to determine which sessions derive equal keys given only the publicly available information. What distinguishes our results from virtually all existing work is that we do not rely, neither directly nor indirectly, on the simulation paradigm. Instead, our security notions and composition theorems exclusively use a game-based formalism.We thus avoid several undesirable consequences of simulation-based security notions and support applicability to a broader class of protocols. In particular, we offer an abstract formalization of game-based security that should be of independent interest in other investigations using game-based formalisms. Christopher Brzuska, Marc Fischlin, Bogdan Warinschi, Stephen C. Williams |
CCS | 1 |
| 2011 | Physically Uncloneable Functions in the Universal Composition Framework
Christopher Brzuska, Marc Fischlin, Heike Schröder, Stefan Katzenbeisser 0001 |
CRYPTO | 1 |
| 2010 | Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder |
ACNS | 1 |