EDBT 2026 Demo / reviewers in the wild / expert
Martin R. Albrecht
dblp:92/7397 · also Martin Albrecht 0001
· DBLP profile ↗
62ranked-venue papers
59as first author
27since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 59 · 56 first-author · 27 since 2021Theory of computation · 3 · 3 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hardness of Hinted ISIS from the Space-Time Hardness of Lattice Problems
Martin R. Albrecht, Russell W. F. Lai, Eamonn W. Postlethwaite |
CRYPTO (3) | 1 |
| 2026 | A Real-World Law-Enforcement Hack: The Case of Encrochat
Martin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas Stebila |
CRYPTO (10) | 1 |
| 2026 | At-Compromise Security - The Case for Alert Blindness
Martin R. Albrecht, Simone Colombo 0002, Benjamin Dowling, Rikke Bjerg Jensen |
EUROCRYPT (2) | 1 |
| 2026 | A Gaussian Leftover Hash Lemma for Modules over Number Fields
Martin R. Albrecht, Joël Felderhoff, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo |
EUROCRYPT (4) | 1 |
| 2026 | Four Attacks and a Proof for TelegramabstractAbstract We study the use of symmetric cryptography in the MTProto 2.0 protocol, Telegram’s equivalent of the TLS protocol. We give positive and negative results. On the one hand, we formally and in detail specify a slight variant of Telegram’s “record protocol” and prove that it achieves security in a suitable bidirectional secure channel model, albeit under unstudied assumptions; this model itself advances the state of the art for secure channels. On the other hand, we first motivate our slight deviation from MTProto as deployed by giving two attacks on the original protocol specification: one of practical, one of theoretical interest. Then, we give two attacks on the implementation, which are outside of our formal model: one targeting the client, one targeting the server. The client-side attack enables plaintext recovery by exploiting timing side channels, of varying strength, in three official Telegram clients. On its own this attack is thwarted by the secrecy of header fields that are established by Telegram’s key exchange protocol. We thus chain this attack with an attack against the implementation of the key exchange protocol on Telegram’s servers. This final attack breaks the authentication properties of Telegram’s key exchange, allowing a MitM attack. More mundanely, it also reduces the cost of the client-side plaintext-recovery attack. In totality, our results provide the first comprehensive study of MTProto’s use of symmetric cryptography, as well as highlight weaknesses in its key exchange. Martin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors Stepanovs |
J. Cryptol. | 1 |
| 2025 | Partial Lattice Trapdoors: How to Split Lattice Trapdoors, Literally
Martin R. Albrecht, Russell W. F. Lai, Oleksandra Lapiha, Ivy K. Y. Woo |
ASIACRYPT (3) | 1 |
| 2025 | Post-quantum Online/Offline Signatures
Martin R. Albrecht, Nicolas Gama, James Howe, Anand Kumar Narayanan |
CT-RSA | 1 |
| 2025 | Hollow LWE: A New Spin - Unbounded Updatable Encryption from LWE and PCE
Martin R. Albrecht, Benjamin Bencina, Russell W. F. Lai |
EUROCRYPT (8) | 1 |
| 2025 | Formal Analysis of Multi-device Group Messaging in WhatsApp
Martin R. Albrecht, Benjamin Dowling |
EUROCRYPT (8) | 1 |
| 2025 | Analysis of the Telegram Key Exchange
Martin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Eyal Ronen, Igors Stepanovs |
EUROCRYPT (8) | 1 |
| 2025 | On the Virtues of Information Security in the UK Climate Movement
Mikaela Brough, Rikke Bjerg Jensen, Martin R. Albrecht |
USENIX Security Symposium | 3 |
| 2024 | Verifiable Oblivious Pseudorandom Functions from Lattices: Practical-Ish and Thresholdisable
Martin R. Albrecht, Kamil Doruk Gür |
ASIACRYPT (4) | 1 |
| 2024 | Batch Signatures, Revisited
Carlos Aguilar Melchor, Martin R. Albrecht, Thomas Bailleux, Nina Bindel, James Howe, Andreas Hülsing, David Joseph, Marc Manzano |
CT-RSA | 2 |
| 2024 | Crypto Dark Matter on the Torus - Oblivious PRFs from Shallow PRFs and TFHE
Martin R. Albrecht, Alex Davidson, Amit Deo, Daniel Gardham |
EUROCRYPT (6) | 1 |
| 2024 | SLAP: Succinct Lattice-Based Polynomial Commitments from Standard Assumptions
Martin R. Albrecht, Giacomo Fenzi, Oleksandra Lapiha, Ngoc Khanh Nguyen 0001 |
EUROCRYPT (6) | 1 |
| 2024 | Share with Care: Breaking E2EE in NextcloudabstractNextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users. We provide the first detailed documentation and security analysis of Nextcloud's E2EE feature. Nextcloud's strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users' data. We have responsibly disclosed the three vulnerabilities to N extcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems. Martin R. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson |
EuroS&P | 1 |
| 2024 | Device-Oriented Group Messaging: A Formal Cryptographic Analysis of Matrix' CoreabstractFocusing on its cryptographic core, we provide the first formal description of the Matrix secure group messaging protocol. Observing that no existing secure messaging model in the literature captures the relationships (and shared state) between users, their devices and the groups they are a part of, we introduce the Device-Oriented Group Messaging model to capture these key characteristics of the Matrix protocol. Utilising our new formalism, we determine that Matrix achieves the basic security notions of confidentiality and authentication, provided it introduces authenticated group membership. On the other hand, while the state sharing functionality in Matrix conflicts with advanced security notions in the literature – forward and post-compromise security – it enables features such as history sharing and account recovery, provoking broader questions about how such security notions should be conceptualised. Martin R. Albrecht, Benjamin Dowling |
SP | 1 |
| 2023 | Caveat Implementor! Key Recovery Attacks on MEGA
Martin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. Paterson |
EUROCRYPT (5) | 1 |
| 2023 | Practically-exploitable Cryptographic Vulnerabilities in MatrixabstractWe report several practically-exploitable cryptographic vulnerabilities in the Matrix standard for federated real-time communication and its flagship client and prototype implementation, Element. These, together, invalidate the confidentiality and authentication guarantees claimed by Matrix against a malicious server. This is despite Matrix’ cryptographic routines being constructed from well-known and -studied cryptographic building blocks. The vulnerabilities we exploit differ in their nature (insecure by design, protocol confusion, lack of domain separation, implementation bugs) and are distributed broadly across the different subprotocols and libraries that make up the cryptographic core of Matrix and Element. Together, these vulnerabilities highlight the need for a systematic and formal analysis of the cryptography in the Matrix standard. Martin R. Albrecht, Sofía Celi, Benjamin Dowling |
SP | 1 |
| 2022 | Lattice-Based SNARKs: Publicly Verifiable, Preprocessing, and Recursively Composable - (Extended Abstract)
Martin R. Albrecht, Valerio Cini, Russell W. F. Lai, Giulio Malavolta, Sri Aravinda Krishnan Thyagarajan |
CRYPTO (2) | 1 |
| 2022 | Four Attacks and a Proof for TelegramabstractWe study the use of symmetric cryptography in the MTProto 2.0 protocol, Telegram’s equivalent of the TLS record protocol. We give positive and negative results. On the one hand, we formally and in detail model a slight variant of Telegram’s “record protocol” and prove that it achieves security in a suitable bidirectional secure channel model, albeit under unstudied assumptions; this model itself advances the state-of-the-art for secure channels. On the other hand, we first motivate our modelling deviation from MTProto as deployed by giving two attacks – one of practical, one of theoretical interest – against MTProto without our modifications. We then also give a third attack exploiting timing side channels, of varying strength, in three official Telegram clients. On its own this attack is thwarted by the secrecy of salt and id fields that are established by Telegram’s key exchange protocol. To recover these, we chain the third attack with a fourth one against the implementation of the key exchange protocol on Telegram’s servers. In totality, our results provide the first comprehensive study of MTProto’s use of symmetric cryptography. Martin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors Stepanovs |
SP | 1 |
| 2022 | Breaking Bridgefy, again: Adopting libsignal is not enough
Martin R. Albrecht, Raphael Eikenberg, Kenneth G. Paterson |
USENIX Security Symposium | 1 |
| 2021 | Lattice Reduction with Approximate Enumeration Oracles - Practical Algorithms and Concrete Performance
Martin R. Albrecht, Shi Bai 0001, Joe Rowell |
CRYPTO (2) | 1 |
| 2021 | Subtractive Sets over Cyclotomic Rings - Limits of Schnorr-Like Arguments over Lattices
Martin R. Albrecht, Russell W. F. Lai |
CRYPTO (2) | 1 |
| 2021 | Mesh Messaging in Large-Scale Protests: Breaking Bridgefy
Martin R. Albrecht, Jorge Blasco Alís, Rikke Bjerg Jensen, Lenka Mareková |
CT-RSA | 1 |
| 2021 | On Bounded Distance Decoding with Predicate: Breaking the "Lattice Barrier" for the Hidden Number Problem
Martin R. Albrecht, Nadia Heninger |
EUROCRYPT (1) | 1 |
| 2021 | Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong
Martin R. Albrecht, Jorge Blasco Alís, Rikke Bjerg Jensen, Lenka Mareková |
USENIX Security Symposium | 1 |
| 2020 | Estimating Quantum Speedups for Lattice Sieves
Martin R. Albrecht, Vlad Gheorghiu, Eamonn W. Postlethwaite, John M. Schanck |
ASIACRYPT (2) | 1 |
| 2020 | Faster Enumeration-Based Lattice Reduction: Root Hermite Factor k1/(2k) Time kk/8+o(k)
Martin R. Albrecht, Shi Bai 0001, Pierre-Alain Fouque, Paul Kirchner, Damien Stehlé, Weiqiang Wen |
CRYPTO (2) | 1 |
| 2020 | Multilinear Maps from ObfuscationabstractAbstract We provide constructions of multilinear groups equipped with natural hard problems from indistinguishability obfuscation, homomorphic encryption, and NIZKs. This complements known results on the constructions of indistinguishability obfuscators from multilinear maps in the reverse direction. We provide two distinct, but closely related constructions and show that multilinear analogues of the $${\text {DDH}} $$ DDH assumption hold for them. Our first construction is symmetric and comes with a $$\kappa $$ κ -linear map $$\mathbf{e }: {{\mathbb {G}}}^\kappa \longrightarrow {\mathbb {G}}_T$$ e:Gκ⟶GT for prime-order groups $${\mathbb {G}}$$ G and $${\mathbb {G}}_T$$ GT . To establish the hardness of the $$\kappa $$ κ -linear $${\text {DDH}} $$ DDH problem, we rely on the existence of a base group for which the $$\kappa $$ κ -strong $${\text {DDH}} $$ DDH assumption holds. Our second construction is for the asymmetric setting, where $$\mathbf{e }: {\mathbb {G}}_1 \times \cdots \times {\mathbb {G}}_{\kappa } \longrightarrow {\mathbb {G}}_T$$ e:G1×⋯×Gκ⟶GT for a collection of $$\kappa +1$$ κ+1 prime-order groups $${\mathbb {G}}_i$$ Gi and $${\mathbb {G}}_T$$ GT , and relies only on the 1-strong $${\text {DDH}} $$ DDH assumption in its base group. In both constructions, the linearity $$\kappa $$ κ can be set to any arbitrary but a priori fixed polynomial value in the security parameter. We rely on a number of powerful tools in our constructions: probabilistic indistinguishability obfuscation, dual-mode NIZK proof systems (with perfect soundness, witness-indistinguishability, and zero knowledge), and additively homomorphic encryption for the group $$\mathbb {Z}_N^{+}$$ ZN+ . At a high level, we enable “bootstrapping” multilinear assumptions from their simpler counterparts in standard cryptographic groups and show the equivalence of PIO and multilinear maps under the existence of the aforementioned primitives. Martin R. Albrecht, Pooya Farshim, Shuai Han 0001, Dennis Hofheinz, Enrique Larraia, Kenneth G. Paterson |
J. Cryptol. | 1 |
| 2019 | Algebraic Cryptanalysis of STARK-Friendly Designs: Application to MARVELlous and MiMC
Martin R. Albrecht, Carlos Cid, Lorenzo Grassi 0001, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger, Markus Schofnegger |
ASIACRYPT (3) | 1 |
| 2019 | Feistel Structures for MPC, and More
Martin R. Albrecht, Lorenzo Grassi 0001, Léo Perrin, Sebastian Ramacher, Christian Rechberger, Dragos Rotaru, Arnab Roy 0005, Markus Schofnegger |
ESORICS (2) | 1 |
| 2019 | The General Sieve Kernel and New Records in Lattice Reduction
Martin R. Albrecht, Léo Ducas, Gottfried Herold, Elena Kirshanova, Eamonn W. Postlethwaite, Marc Stevens 0001 |
EUROCRYPT (2) | 1 |
| 2019 | Exploring Trade-offs in Batch Bounded Distance Decoding
Martin R. Albrecht, Benjamin R. Curtis, Thomas Wunderer |
SAC | 1 |
| 2018 | Prime and Prejudice: Primality Testing Under Adversarial ConditionsabstractThis work provides a systematic analysis of primality testing under adversarial conditions, where the numbers being tested for primality are not generated randomly, but instead provided by a possibly malicious party. Such a situation can arise in secure messaging protocols where a server supplies Diffie-Hellman parameters to the peers, or in a secure communications protocol like TLS where a developer can insert such a number to be able to later passively spy on client-server data. We study a broad range of cryptographic libraries and assess their performance in this adversarial setting. As examples of our findings, we are able to construct 2048-bit composites that are declared prime with probability (1/16) by OpenSSL's primality testing in its default configuration; the advertised performance is (2-80). We can also construct 1024-bit composites that always pass the primality testing routine in GNU GMP when configured with the recommended minimum number of rounds. And, for a number of libraries (Cryptlib, LibTomCrypt, JavaScript Big Number, WolfSSL), we can construct composites that always pass the supplied primality tests. We explore the implications of these security failures in applications, focusing on the construction of malicious Diffie-Hellman parameters. We show that, unless careful primality testing is performed, an adversary can supply parameters (p,q,g) which on the surface look secure, but where the discrete logarithm problem in the subgroup of order q generated by g is easy. We close by making recommendations for users and developers. In particular, we promote the Baillie-PSW primality test which is both efficient and conjectured to be robust even in the adversarial setting for numbers up to a few thousand bits. Martin R. Albrecht, Jake Massimo, Kenneth G. Paterson, Juraj Somorovsky |
CCS | 1 |
| 2017 | Sampling from Arbitrary Centered Discrete Gaussians for Lattice-Based Cryptography
Carlos Aguilar Melchor, Martin R. Albrecht, Thomas Ricosset |
ACNS | 2 |
| 2017 | Large Modulus Ring-LWE ≥ Module-LWE
Martin R. Albrecht, Amit Deo |
ASIACRYPT (1) | 1 |
| 2017 | Revisiting the Expected Cost of Solving uSVP and Applications to LWE
Martin R. Albrecht, Florian Göpfert, Fernando Virdia, Thomas Wunderer |
ASIACRYPT (1) | 1 |
| 2017 | Tightly Secure Ring-LWE Based Key Encapsulation with Short Ciphertexts
Martin R. Albrecht, Emmanuela Orsini, Kenneth G. Paterson, Guy Peer, Nigel P. Smart |
ESORICS (1) | 1 |
| 2017 | On Dual Lattice Attacks Against Small-Secret LWE and Parameter Choices in HElib and SEAL
Martin R. Albrecht |
EUROCRYPT (2) | 1 |
| 2017 | Notes on GGH13 Without the Presence of Ideals
Martin R. Albrecht, Alex Davidson, Enrique Larraia |
IMACC | 1 |
| 2016 | MiMC: Efficient Encryption and Cryptographic Hashing with Minimal Multiplicative Complexity
Martin R. Albrecht, Lorenzo Grassi 0001, Christian Rechberger, Arnab Roy 0005, Tyge Tiessen |
ASIACRYPT (1) | 1 |
| 2016 | A Surfeit of SSH Cipher SuitesabstractThis work presents a systematic analysis of symmetric encryption modes for SSH that are in use on the Internet, providing deployment statistics, new attacks, and security proofs for widely used modes. We report deployment statistics based on two Internet-wide scans of SSH servers conducted in late 2015 and early 2016. Dropbear and OpenSSH implementations dominate in our scans. From our first scan, we found 130,980 OpenSSH servers that are still vulnerable to the CBC-mode-specific attack of Albrecht et al. (IEEE S&P 2009), while we found a further 20,000 OpenSSH servers that are vulnerable to a new attack on CBC-mode that bypasses the counter-measures introduced in OpenSSH 5.2 to defeat the attack of Albrecht et al. At the same time, 886,449 Dropbear servers in our first scan are vulnerable to a variant of the original CBC-mode attack. On the positive side, we provide formal security analyses for other popular SSH encryption modes, namely ChaCha20-Poly1305, generic Encrypt-then-MAC, and AES-GCM. Our proofs hold for detailed pseudo-code descriptions of these algorithms as implemented in OpenSSH. Our proofs use a corrected and extended version of the "fragmented decryption" security model that was specifically developed for the SSH setting by Boldyreva et al. (Eurocrypt 2012). These proofs provide strong confidentiality and integrity guarantees for these alternatives to CBC-mode encryption in SSH. However, we also show that these alternatives do not meet additional, desirable notions of security (boundary-hiding under passive and active attacks, and denial-of-service resistance) that were formalised by Boldyreva et al. Martin R. Albrecht, Jean Paul Degabriele, Torben Brandt Hansen, Kenneth G. Paterson |
CCS | 1 |
| 2016 | A Subfield Lattice Attack on Overstretched NTRU Assumptions - Cryptanalysis of Some FHE and Graded Encoding Schemes
Martin R. Albrecht, Shi Bai 0001, Léo Ducas |
CRYPTO (1) | 1 |
| 2016 | Lucky Microseconds: A Timing Attack on Amazon's s2n Implementation of TLSabstracts2n is an implementation of the TLS protocol that was released in late June 2015 by Amazon. It is implemented in around 6,000 lines of C99 code. By comparison, OpenSSL needs around 70,000 lines of code to implement the protocol. At the time of its release, Amazon announced that s2n had undergone three external security evaluations and penetration tests. We show that, despite this, s2n — as initially released — was vulnerable to a timing attack in the case of CBC-mode ciphersuites, which could be extended to complete plaintext recovery in some settings. Our attack has two components. The first part is a novel variant of the Lucky 13 attack that works even though protections against Lucky 13 were implemented in s2n. The second part deals with the randomised delays that were put in place in s2n as an additional countermeasure to Lucky 13. Our work highlights the challenges of protecting implementations against sophisticated timing attacks. It also illustrates that standard code audits are insufficient to uncover all cryptographic attack vectors. Martin R. Albrecht, Kenneth G. Paterson |
EUROCRYPT (1) | 1 |
| 2016 | Polly Cracker, revisited
Martin R. Albrecht, Jean-Charles Faugère, Pooya Farshim, Gottfried Herold, Ludovic Perret |
Des. Codes Cryptogr. | 1 |
| 2015 | Implementing Candidate Graded Encoding Schemes from Ideal Lattices
Martin R. Albrecht, Catalin Cocis, Fabien Laguillaumie, Adeline Roux-Langlois |
ASIACRYPT (2) | 1 |
| 2015 | Ciphers for MPC and FHE
Martin R. Albrecht, Christian Rechberger, Thomas Schneider 0003, Tyge Tiessen, Michael Zohner |
EUROCRYPT (1) | 1 |
| 2015 | On the complexity of the BKW algorithm on LWE
Martin R. Albrecht, Carlos Cid, Jean-Charles Faugère, Robert Fitzpatrick, Ludovic Perret |
Des. Codes Cryptogr. | 1 |
| 2014 | Block Ciphers - Focus on the Linear Layer (feat. PRIDE)
Martin R. Albrecht, Benedikt Driessen, Elif Bilge Kavun, Gregor Leander, Christof Paar, Tolga Yalçin |
CRYPTO (1) | 1 |
| 2012 | The M4RIE library for dense linear algebra over small fields with even characteristicabstractWe describe algorithms and implementations for linear algebra with dense matrices over F2e for 2 ≤ e ≤ 10. Our main contributions are: (1) a specialisation of precomputation tables to F2e, called Newton-John tables in this work, to avoid scalar multiplications in Gaussian elimination and matrix multiplication, (2) an efficient implementation of Karatsuba-style multiplication for matrices over extension fields of F2 and (3) a description of an open-source library -- called M4RIE -- providing the fastest known implementation of dense linear algebra over F2e with 2 ≤ e ≤ 10. Martin R. Albrecht |
ISSAC | 1 |
| 2012 | An All-In-One Approach to Differential Cryptanalysis for Small Block Ciphers
Martin R. Albrecht, Gregor Leander |
Selected Areas in Cryptography | 1 |
| 2012 | On the relation between the MXL family of algorithms and Gröbner basis algorithms
Martin R. Albrecht, Carlos Cid, Jean-Charles Faugère, Ludovic Perret |
J. Symb. Comput. | 1 |
| 2011 | Cold Boot Key Recovery by Solving Polynomial Systems with Noise
Martin R. Albrecht, Carlos Cid |
ACNS | 1 |
| 2011 | Polly Cracker, Revisited
Martin R. Albrecht, Pooya Farshim, Jean-Charles Faugère, Ludovic Perret |
ASIACRYPT | 1 |
| 2011 | On Cipher-Dependent Related-Key Attacks in the Ideal-Cipher Model
Martin R. Albrecht, Pooya Farshim, Kenneth G. Paterson, Gaven J. Watson |
FSE | 1 |
| 2011 | Breaking an Identity-Based Encryption Scheme Based on DHIES
Martin R. Albrecht, Kenneth G. Paterson |
IMACC | 1 |
| 2010 | Algebraic Precomputations in Differential and Integral Cryptanalysis
Martin R. Albrecht, Carlos Cid, Thomas Dullien, Jean-Charles Faugère, Ludovic Perret |
Inscrypt | 1 |
| 2010 | Algorithm 898: Efficient multiplication of dense matrices over GF(2)abstractWe describe an efficient implementation of a hierarchy of algorithms for multiplication of dense matrices over the field with two elements (F 2 ). In particular we present our implementation—in the M4RI library—of Strassen-Winograd matrix multiplication and the “Method of the Four Russians for Multiplication” (M4RM) and compare it against other available implementations. Good performance is demonstrated on AMD's Opteron processor and particulary good performance on Intel's Core 2 uo processor. The open-source M4RI library is available as a stand-alone package as well as part of the Sage mathematics system. In machine terms, addition in F 2 is logical-XOR, and multiplication is logical-AND, thus a machine word of 64 bits allows one to operate on 64 elements of F 2 in parallel: at most one CPU cycle for 64 parallel additions or multiplications. As such, element-wise operations over F 2 are relatively cheap. In fact, in this paper, we conclude that the actual bottlenecks are memory reads and writes and issues of data locality. We present our empirical findings in relation to minimizing these and give an analysis thereof. Martin R. Albrecht, Gregory V. Bard, William Hart |
ACM Trans. Math. Softw. | 1 |
| 2009 | Attacking cryptographic schemes based on "perturbation polynomials"abstractWe show attacks on several cryptographic schemes that have recently been proposed for achieving various security goals in sensor networks. Roughly speaking, these schemes all use "perturbation polynomials" to add "noise" to polynomialbased systems that offer information-theoretic security, in an attempt to increase the resilience threshold while maintaining efficiency. We show that the heuristic security arguments given for these modified schemes do not hold, and that they can be completely broken once we allow even a slight extension of the parameters beyond those achieved by the underlying information-theoretic schemes. Martin R. Albrecht, Craig Gentry, Shai Halevi, Jonathan Katz |
CCS | 1 |
| 2009 | Algebraic Techniques in Differential Cryptanalysis
Martin R. Albrecht, Carlos Cid |
FSE | 1 |
| 2009 | Plaintext Recovery Attacks against SSHabstractThis paper presents a variety of plaintext-recovering attacks against SSH. We implemented a proof of concept of our attacks against OpenSSH, where we can verifiably recover 14 bits of plaintext from an arbitrary block of ciphertext with probability $2^{-14}$ and 32 bits of plaintext from an arbitrary block of ciphertext with probability $2^{-18}$. These attacks assume the default configuration of a 128-bit block cipher operating in CBC mode. The paper explains why a combination of flaws in the basic design of SSH leads implementations such as OpenSSH to be open to our attacks, why current provable security results for SSH do not cover our attacks, and how the attacks can be prevented in practice. Martin R. Albrecht, Kenneth G. Paterson, Gaven J. Watson |
SP | 1 |