Phillip Rogaway

dblp:r/PhillipRogaway · DBLP profile ↗
← Back
78ranked-venue papers
19as first author
2since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 73 · 19 first-author · 2 since 2021Theory of computation · 5Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2022 On Committing Authenticated-Encryption
John Chan, Phillip Rogaway
ESORICS (2)2
2021 The Design and Evolution of OCB
abstract
Abstract We describe OCB3, the final version of OCB, a blockcipher mode for authenticated encryption (AE). We prove the construction secure, up to the birthday bound, assuming its underlying blockcipher is secure as a strong-PRP. We study the scheme’s software performance, comparing its speed, on multiple platforms, to a variety of other AE schemes. We reflect on the history and development of the mode.
Ted Krovetz, Phillip Rogaway
J. Cryptol.2
2020 Reimagining Secret Sharing: Creating a Safer and More Versatile Primitive by Adding Authenticity, Correcting Errors, and Reducing Randomness Requirements
abstract
Aiming to strengthen classical secret-sharing to make it a more directly useful primitive for human endusers, we develop definitions, theorems, and efficient constructions for what we call adept secret-sharing. Our primary concerns are the properties we call privacy, authenticity, and error correction. Privacy strengthens the classical requirement by ensuring maximal confidentiality even if the dealer does not employ fresh, uniformly random coins with each sharing. That might happen either intentionally—to enable reproducible secretsharing— or unintentionally, when an entropy source fails. Authenticity is a shareholder’s guarantee that a secret recovered using his or her share will coincide with the value the dealer committed to at the time the secret was shared. Error correction is the guarantee that recovery of a secret will succeed, also identifying the valid shares, exactly when there is a unique explanation as to which shares implicate what secret. These concerns arise organically from a desire to create general-purpose libraries and apps for secret sharing that can withstand both strong adversaries and routine operational errors.
Mihir Bellare, Wei Dai 0011, Phillip Rogaway
Proc. Priv. Enhancing Technol.3
2019 Anonymous AE
John Chan, Phillip Rogaway
ASIACRYPT (2)2
2018 Simplifying Game-Based Definitions - Indistinguishability up to Correctness and Its Application to Stateful AE
Phillip Rogaway
CRYPTO (2)1
2018 Deterministic Encryption with the Thorp Shuffle
Ben Morris 0001, Phillip Rogaway, Till Stegers
J. Cryptol.2
2018 Onion-AE: Foundations of Nested Encryption
abstract
Abstract Nested symmetric encryption is a well-known technique for low-latency communication privacy. But just what problem does this technique aim to solve? In answer, we provide a provable-security treatment foronion authenticated-encryption(onion-AE). Extending the conventional notion for authenticated-encryption, we demand indistinguishability from random bits and time-of-exit authenticity verification. We show that the encryption technique presently used in Tor does not satisfy our definition of onion-AE security, but that a construction by Mathewson (2012), based on a strong, tweakable, wideblock PRP, does do the job. We go on to discuss three extensions of onion-AE, giving definitions to handle inbound flows, immediate detection of authenticity errors, and corrupt ORs.
Phillip Rogaway
Proc. Priv. Enhancing Technol.1
2016 Big-Key Symmetric Encryption: Resisting Key Exfiltration
Mihir Bellare, Daniel M. Kane, Phillip Rogaway
CRYPTO (1)3
2015 Online Authenticated-Encryption and its Nonce-Reuse Misuse-Resistance
Viet Tung Hoang, Reza Reyhanitabar, Phillip Rogaway, Damian Vizár
CRYPTO (1)3
2015 Robust Authenticated-Encryption AEZ and the Problem That It Solves
Viet Tung Hoang, Ted Krovetz, Phillip Rogaway
EUROCRYPT (1)3
2015 Robust Authenticated Encryption and the Limits of Symmetric Cryptography
Christian Badertscher, Christian Matt 0002, Ueli Maurer, Phillip Rogaway, Björn Tackmann
IMACC4
2015 Augmented Secure Channels and the Goal of the TLS 1.3 Record Layer
Christian Badertscher, Christian Matt 0002, Ueli Maurer, Phillip Rogaway, Björn Tackmann
ProvSec4
2014 Security of Symmetric Encryption against Mass Surveillance
Mihir Bellare, Kenneth G. Paterson, Phillip Rogaway
CRYPTO (1)3
2014 Sometimes-Recurse Shuffle - Almost-Random Permutations in Logarithmic Expected Time
Ben Morris 0001, Phillip Rogaway
EUROCRYPT2
2014 Reconsidering Generic Composition
Chanathip Namprempre, Phillip Rogaway, Thomas Shrimpton
EUROCRYPT2
2013 Efficient Garbling from a Fixed-Key Blockcipher
abstract
We advocate schemes based on fixed-key AES as the best route to highly efficient circuit-garbling. We provide such schemes making only one AES call per garbled-gate evaluation. On the theoretical side, we justify the security of these methods in the random-permutation model, where parties have access to a public random permutation. On the practical side, we provide the Just Garble system, which implements our schemes. Just Garble evaluates moderate-sized garbled-circuits at an amortized cost of 23.2 cycles per gate (7.25 nsec), far faster than any prior reported results.
Mihir Bellare, Viet Tung Hoang, Sriram Keelveedhi, Phillip Rogaway
IEEE Symposium on Security and Privacy4
2012 Adaptively Secure Garbling with Applications to One-Time Programs and Secure Outsourcing
Mihir Bellare, Viet Tung Hoang, Phillip Rogaway
ASIACRYPT3
2012 Foundations of garbled circuits
abstract
Garbled circuits, a classical idea rooted in the work of Yao, have long been understood as a cryptographic technique, not a cryptographic goal. Here we cull out a primitive corresponding to this technique. We call it a garbling scheme. We provide a provable-security treatment for garbling schemes, endowing them with a versatile syntax and multiple security definitions. The most basic of these, privacy, suffices for two-party secure function evaluation (SFE) and private function evaluation (PFE). Starting from a PRF, we provide an efficient garbling scheme achieving privacy and we analyze its concrete security. We next consider obliviousness and authenticity, properties needed for private and verifiable outsourcing of computation. We extend our scheme to achieve these ends. We provide highly efficient blockcipher-based instantiations of both schemes. Our treatment of garbling schemes presages more efficient garbling, more rigorous analyses, and more modularly designed higher-level protocols.
Mihir Bellare, Viet Tung Hoang, Phillip Rogaway
CCS3
2012 An Enciphering Scheme Based on a Card Shuffle
Viet Tung Hoang, Ben Morris 0001, Phillip Rogaway
CRYPTO3
2012 The Security of Ciphertext Stealing
Phillip Rogaway, Mark Wooding
FSE1
2011 Online Ciphers from Tweakable Blockciphers
Phillip Rogaway
CT-RSA1
2011 The Software Performance of Authenticated-Encryption Modes
Ted Krovetz, Phillip Rogaway
FSE2
2010 On Generalized Feistel Networks
Viet Tung Hoang, Phillip Rogaway
CRYPTO2
2010 An Analysis of the Blockcipher-Based Hash Functions from PGV
John Black, Phillip Rogaway, Thomas Shrimpton, Martijn Stam
J. Cryptol.2
2009 How to Encipher Messages on a Small Domain
Ben Morris 0001, Phillip Rogaway, Till Stegers
CRYPTO2
2009 Authentication without Elision: Partially Specified Protocols, Associated Data, and Cryptographic Models Described by Code
abstract
Specification documents for real-world authentication protocols typically mandate some aspects of a protocol's behavior but leave other features optional or undefined. In addition, real-world schemes often include parameter negotiations, authenticate associated data, and support a multiplicity of options. The cryptographic community has routinely elided such matters from our definitions, schemes, and proofs. We propose encompassing them by explicitly modeling the presence of unspecified protocol functionality. To demonstrate, we provide a new treatment for mutual authentication in the public-key setting, doing this in the computational cryptographic tradition. In our model, compactly described in pseudocode, a protocol core (PC) will call out to protocol details (PD), but, for defining security, such calls will be serviced by the adversary. Parties accepting an authentication exchange will output a string of associated data, the value of which may be determined by the PD calls. We illustrate the approach by re-proving security for the Needham-Schroeder-Lowe public-key protocol, but extended in a manner that would be typical were the mechanism embedded in a real-world standard.
Phillip Rogaway, Till Stegers
CSF1
2008 Constructing Cryptographic Hash Functions from Fixed-Key Blockciphers
Phillip Rogaway, John P. Steinberger
CRYPTO1
2008 Security/Efficiency Tradeoffs for Permutation-Based Hashing
Phillip Rogaway, John P. Steinberger
EUROCRYPT1
2007 Robust computational secret sharing and a unified account of classical secret-sharing goals
abstract
We give a unified account of classical secret-sharing goals from a modern cryptographic vantage. Our treatment encompasses perfect, statistical, and computational secret sharing; static and dynamic adversaries; schemes with or without robustness; schemes where a participant recovers the secret and those where an external party does so. We then show that Krawczyk's 1993 protocol for robust computational secret sharing (RCSS) need not be secure, even in the random-oracle model and for threshold schemes, if the encryption primitive it uses satisfies only one-query indistinguishability (ind1), the only notion Krawczyk defines. Nonetheless, we show that the protocol is secure (in the random-oracle model, for threshold schemes) if the encryption scheme also satisfies one-query key-unrecoverability (key1). Since practical encryption schemes are ind1+key1 secure, our result effectively shows that Krawczyk's RCSS protocol is sound (in the random-oracle model, for threshold schemes). Finally, we prove the security for a variant of Krawczyk's protocol, in the standard model and for arbitrary access structures, assuming ind1 encryption and a statistically-hiding, weakly-binding commitment scheme.
Phillip Rogaway, Mihir Bellare
CCS1
2007 How to Enrich the Message Space of a Cipher
Thomas Ristenpart, Phillip Rogaway
FSE2
2007 Reconciling Two Views of Cryptography (The Computational Soundness of Formal Encryption)
Martín Abadi, Phillip Rogaway
J. Cryptol.2
2006 The Security of Triple Encryption and a Framework for Code-Based Game-Playing Proofs
Mihir Bellare, Phillip Rogaway
EUROCRYPT2
2006 A Provable-Security Treatment of the Key-Wrap Problem
Phillip Rogaway, Thomas Shrimpton
EUROCRYPT1
2006 Variationally universal hashing
Ted Krovetz, Phillip Rogaway
Inf. Process. Lett.2
2005 Improved Security Analyses for CBC MACs
Mihir Bellare, Krzysztof Pietrzak, Phillip Rogaway
CRYPTO3
2005 CBC MACs for Arbitrary-Length Messages: The Three-Key Constructions
John Black, Phillip Rogaway
J. Cryptol.2
2004 Efficient Instantiations of Tweakable Blockciphers and Refinements to Modes OCB and PMAC
Phillip Rogaway
ASIACRYPT1
2004 A Parallelizable Enciphering Mode
Shai Halevi, Phillip Rogaway
CT-RSA2
2004 The EAX Mode of Operation
Mihir Bellare, Phillip Rogaway, David A. Wagner 0001
FSE2
2004 Nonce-Based Symmetric Encryption
Phillip Rogaway
FSE1
2004 Cryptographic Hash-Function Basics: Definitions, Implications, and Separations for Preimage Resistance, Second-Preimage Resistance, and Collision Resistance
Phillip Rogaway, Thomas Shrimpton
FSE1
2003 A Tweakable Enciphering Mode
Shai Halevi, Phillip Rogaway
CRYPTO2
2003 OCB: A block-cipher mode of operation for efficient authenticated encryption
abstract
We describe a parallelizable block-cipher mode of operation that simultaneously provides privacy and authenticity. OCB encrypts-and-authenticates a nonempty string M ∈ {0, 1}* using ⌈| M |/ n ⌉ + 2 block-cipher invocations, where n is the block length of the underlying block cipher. Additional overhead is small. OCB refines a scheme, IAPM, suggested by Charanjit Jutla. Desirable properties of OCB include the ability to encrypt a bit string of arbitrary length into a ciphertext of minimal length, cheap offset calculations, cheap key setup, a single underlying cryptographic key, no extended-precision addition, a nearly optimal number of block-cipher calls, and no requirement for a random IV. We prove OCB secure, quantifying the adversary's ability to violate the mode's privacy or authenticity in terms of the quality of its block cipher as a pseudorandom permutation (PRP) or as a strong PRP, respectively.
Phillip Rogaway, Mihir Bellare, John Black
ACM Trans. Inf. Syst. Secur.1
2002 Authenticated-encryption with associated-data
abstract
When a message is transformed into a ciphertext in a way designed to protect both its privacy and authenticity, there may be additional information, such as a packet header, that travels alongside the ciphertext (at least conceptually) and must get authenticated with it. We formalize and investigate this authenticated-encryption with associated-data (AEAD) problem. Though the problem has long been addressed in cryptographic practice, it was never provided a definition or even a name. We do this, and go on to look at efficient solutions for AEAD, both in general and for the authenticated-encryption scheme OCB. For the general setting we study two simple ways to turn an authenticated-encryption scheme that does not support associated-data into one that does: nonce stealing and ciphertext translation. For the case of OCB we construct an AEAD-scheme by combining OCB and the pseudorandom function PMAC, using the same key for both algorithms. We prove that, despite "interaction" between the two schemes when using a common key, the combination is sound. We also consider achieving AEAD by the generic composition of a nonce-based, privacy-only encryption scheme and a pseudorandom function.
Phillip Rogaway
CCS1
2002 Black-Box Analysis of the Block-Cipher-Based Hash-Function Constructions from PGV
John Black, Phillip Rogaway, Thomas Shrimpton
CRYPTO2
2002 Ciphers with Arbitrary Finite Domains
John Black, Phillip Rogaway
CT-RSA2
2002 A Block-Cipher Mode of Operation for Parallelizable Message Authentication
John Black, Phillip Rogaway
EUROCRYPT2
2002 Reconciling Two Views of Cryptography (The Computational Soundness of Formal Encryption)
Martín Abadi, Phillip Rogaway
J. Cryptol.2
2001 OCB: a block-cipher mode of operation for efficient authenticated encryption
abstract
We describe a parallelizable block-cipher mode of operation that simultaneously provides privacy and authenticity. OCB encrypts-and-authenticates a nonempty string M ε {0,1}• using \lceil |M|/n\rceil + 2 block-cipher invocations, where n is the block length of the underlying block cipher. Additional overhead is small. OCB refines a scheme, IAPM, suggested by Charanjit Jutla. Desirable properties of OCB include: the ability to encrypt a bit string of arbitrary length into a ciphertext of minimal length; cheap offset calculations; cheap session setup; a single underlying cryptographic key; no extended-precision addition; a nearly optimal number of block-cipher calls; and no requirement for a random IV. We prove OCB secure, quantifying the adversary's ability to violate the mode's privacy or authenticity in terms of the quality of its block cipher as a pseudorandom permutation (PRP) or as a strong PRP, respectively.
Phillip Rogaway, Mihir Bellare, John Black, Ted Krovetz
CCS1
2001 The Oracle Diffie-Hellman Assumptions and an Analysis of DHIES
Michel Abdalla, Mihir Bellare, Phillip Rogaway
CT-RSA3
2001 How to Protect DES Against Exhaustive Key Search (an Analysis of DESX)
Joe Kilian, Phillip Rogaway
J. Cryptol.2
2000 Encode-Then-Encipher Encryption: How to Exploit Nonces or Redundancy in Plaintexts for Efficient Cryptography
Mihir Bellare, Phillip Rogaway
ASIACRYPT2
2000 CBC MACs for Arbitrary-Length Messages: The Three-Key Constructions
John Black, Phillip Rogaway
CRYPTO2
2000 Authenticated Key Exchange Secure against Dictionary Attacks
Mihir Bellare, David Pointcheval, Phillip Rogaway
EUROCRYPT3
2000 The Security of the Cipher Block Chaining Message Authentication Code
Mihir Bellare, Joe Kilian, Phillip Rogaway
J. Comput. Syst. Sci.3
1999 UMAC: Fast and Secure Message Authentication
John Black, Shai Halevi, Hugo Krawczyk, Ted Krovetz, Phillip Rogaway
CRYPTO5
1999 On the Construction of Variable-Input-Length Ciphers
Mihir Bellare, Phillip Rogaway
FSE2
1999 Bucket Hashing and Its Application to Fast Message Authentication
Phillip Rogaway
J. Cryptol.1
1998 Relations Among Notions of Security for Public-Key Encryption Schemes
Mihir Bellare, Anand Desai, David Pointcheval, Phillip Rogaway
CRYPTO4
1998 Luby-Rackoff Backwards: Increasing Security by Making Block Ciphers Non-invertible
Mihir Bellare, Ted Krovetz, Phillip Rogaway
EUROCRYPT3
1998 A Software-Optimized Encryption Algorithm
Phillip Rogaway, Don Coppersmith
J. Cryptol.1
1997 Collision-Resistant Hashing: Towards Making UOWHFs Practical
Mihir Bellare, Phillip Rogaway
CRYPTO2
1997 A Concrete Security Treatment of Symmetric Encryption
abstract
We study notions and schemes for symmetric (ie. private key) encryption in a concrete security framework. We give four different notions of security against chosen plaintext attack and analyze the concrete complexity of reductions among them, providing both upper and lower bounds, and obtaining tight relations. In this way we classify notions (even though polynomially reducible to each other) as stronger or weaker in terms of concrete security. Next we provide concrete security analyses of methods to encrypt using a block cipher, including the most popular encryption method, CBC. We establish tight bounds (meaning matching upper bounds and attacks) on the success of adversaries as a function of their resources.
Mihir Bellare, Anand Desai, E. Jokipii, Phillip Rogaway
FOCS4
1997 Minimizing the use of random oracles in authenticated encryption schemes
Mihir Bellare, Phillip Rogaway
ICICS2
1997 Locally Random Reductions: Improvements and Applications
Donald Beaver, Joan Feigenbaum, Joe Kilian, Phillip Rogaway
J. Cryptol.4
1996 How to Protect DES Against Exhaustive Key Search
Joe Kilian, Phillip Rogaway
CRYPTO2
1996 The Exact Security of Digital Signatures - HOw to Sign with RSA and Rabin
Mihir Bellare, Phillip Rogaway
EUROCRYPT2
1995 XOR MACs: New Methods for Message Authentication Using Finite Pseudorandom Functions
Mihir Bellare, Roch Guérin, Phillip Rogaway
CRYPTO3
1995 Bucket Hashing and its Application to Fast Message Authentication
Phillip Rogaway
CRYPTO1
1995 Provably secure session key distribution: the three party case
abstract
We study session key distribution in the ting of Needham and Schroeder.(This is three-party setthe trust model assumed by the popular Kerberos "authentication system. ) Such protocols are basic building blocks for contemporary distributed systems-yet the underlying problem has, up until now, lacked a definition or provably-good solution, One consequence is that incorrect protocols have proliferated.This paper provides the first treatment of this problem in the complexity-theoretic framework of modern cryptography.We present a definition, protocol, and a proof that the protocol satisfies the definition, assuming the (minimal) assumption of a pseudorandom function.When this assumption is appropriately instantiated, our protocols are simple and efficient.
Mihir Bellare, Phillip Rogaway
STOC2
1994 The Security of Cipher Block Chaining
Mihir Bellare, Joe Kilian, Phillip Rogaway
CRYPTO3
1993 Random Oracles are Practical: A Paradigm for Designing Efficient Protocols
abstract
We argue that the random oracle model—where all parties have access to a public random oracle—provides a bridge between cryptographic theory and cryptographic practice. In the paradigm we suggest, a practical protocol P is produced by first devising and proving correct a protocol PR for the random oracle model, and then replacing oracle accesses by the computation of an “appropriately chosen” function h. This paradigm yields protocols much more efficient than standard ones while retaining many of the advantages of provable security. We illustrate these gains for problems including encryption, signatures, and zero-knowledge proofs.
Mihir Bellare, Phillip Rogaway
CCS2
1993 Entity Authentication and Key Distribution
Mihir Bellare, Phillip Rogaway
CRYPTO2
1993 A Software-Optimised Encryption Algorithm
Phillip Rogaway, Don Coppersmith
FSE1
1991 Secure Computation (Abstract)
Silvio Micali, Phillip Rogaway
CRYPTO2
1990 Security with Low Communication Overhead
Donald Beaver, Joan Feigenbaum, Joe Kilian, Phillip Rogaway
CRYPTO4
1990 The Round Complexity of Secure Protocols (Extended Abstract)
abstract
In a network of n players, each player i having private input zi, we show how the players can collaboratively evaluate a function f(zl, ..., zn) in a way that does not compromise the privacy of the players' inputs, and yet requires only a constant number of rounds of interaction.The underlying model of computation is a complete network of private channels, with broadcast, and a majority of the players must behave honestly.Our solution assumes the existence of a one-way function.share bi to player i.For some parameter t, t < n/2, we require that no t players get information about b from their pieces; and yet, b is recoverable, and is known to be recoverable, given the cooperation of the n -t good players--even if the t bad players try to obstruct b's recovery, or try to alter the recovered value.The value b which a player has effectively "committed to" is independent of the values that honest players may concurrently be committing to.After the sharing stage, a computation stage follows, in which each player, given his own shares of xl, ..., x,~, computes his own share of f(zt,..., z,~).To accomplish this, the function f to be evaluated is represented by a
Donald Beaver, Silvio Micali, Phillip Rogaway
STOC3
1988 Everything Provable is Provable in Zero-Knowledge
Michael Ben-Or, Oded Goldreich 0001, Shafi Goldwasser, Johan Håstad, Joe Kilian, Silvio Micali, Phillip Rogaway
CRYPTO7