Sign in

Doreen Riepel

@doreenriepel.bsky.social
127 followers 137 following 12 posts

Tenure-Track Faculty at CISPA • Cryptography & Provable Security

PostsRepliesMedia
Reposted by Doreen Riepel
ePrint Updates @eprint.ing.bot · 13/09/2026
Symmetric and Asymmetric Anonymous Authenticated KEM (Benedikt Auerbach, Doreen Riepel, Paul Rösler, Lea Thiemt, Julian Thomas) ia.cr/2026/1926
Abstract. The terms Signcryption, Split KEM, and Authenticated Key-Encapsulation Mechanism (AKEM) are often used synonymously to capture the amalgamation of a KEM and a Digital Signature Scheme in a single primitive. This means that a sender Alice can encapsulate a symmetric secret to the public key of receiver Bob, and Bob can use Alice’s public key to verify that Alice was indeed the sender. Some constructions of AKEM additionally use symmetric pre-shared key material between Alice and Bob to redundantly protect the confidentiality and authenticity of the encapsulated symmetric secret. So far, only special variants of such redundancy have been studied in the literature. Furthermore, beyond confidentiality and authenticity, anonymity of senders and receivers is a desirable property of AKEM that has received little attention yet.

In this work, we begin with formally defining strong compatible notions of confidentiality, authenticity, and anonymity for AKEM. In these notions, Alice and Bob can redundantly protect the encapsulated secret using all possible combinations of asymmetric sender key, asymmetric receiver key, and symmetric pre-shared key material. For every such combination, we develop an efficient construction from standard primitives.

Our consideration of anonymity and the use of symmetric pre-shared key material provokes the study of a tagging and detection mechanism: When Bob receives a ciphertext that is anonymously protected with a pre-shared key, he needs to detect which out of multiple candidate pre-shared keys to use for decryption. We prove that this detection cannot be substantially more efficient than preforming trial decryptions, even when permitting pre-computation. This result is of independent interest and may have broader applications as we prove its equivalence to 1-out-of-n multi-key decryption, resp. verification, in Symmetric Encryption and Message Authentication Codes.
Image showing part 2 of abstract.
011
Reposted by Doreen Riepel
ePrint Updates @eprint.ing.bot · 30/07/2026
Just-in-Time-OPRFs and a Modular Framework for Fast Private Set Intersection (Mihir Bellare, Rishabh Ranjan, Doreen Riepel) ia.cr/2026/1532
Abstract. This paper gives a modular and unified framework within which to derive fast protocols for Private Set Intersection (PSI). At the core of this is a new primitive, that we define, and that we call a Just-In-Time OPRF (JIT-OPRF). We show how to obtain PSI generically from any JIT-OPRF, and then how to obtain JIT-OPRFs from Oblivious Transfer (OT) and Vector Oblivious Linear Evaluation (VOLE). We recover as special cases PSI protocols in the literature based on these two assumptions. Our results and proofs throughout are concrete rather than asymptotic, with explicit bounds that allow one to determine security parameters to achieve a desired level (e.g.~128 bits) of proven security in practice. Our results show interesting differences in the concrete security of OT and VOLE based PSI. Beyond the practical contribution of concrete-security, our work adds conceptual simplicity to this area, and opens the door to new PSI protocols via the construction of new JIT-OPRFs.
083
Reposted by Doreen Riepel
Damien Robert @damienrobert.bsky.social · 05/07/2026
It's been a while since I last posted about MIKE, but a lot of exciting stuff happened meanwhile. MIKE is described in more details in this 4 part thread: - CSIDH bsky.app/profile/dami... - SIDH bsky.app/profile/dami... - MIKE bsky.app/profile/dami... - Speculations: bsky.app/profile/dami...
1104
Doreen Riepel @doreenriepel.bsky.social · 08/05/2026
Join us tomorrow for ProTeCS, one of Eurocrypt’s affiliated events! We are thankful to have two amazing invited speakers, Bart Mennink and Mike Rosulek! We are also happy to have seven contributed talks from the community. Check out our full program here: protecs-workshop.gitlab.io/program
protecs-workshop.gitlab.io
Program
Workshop on Proofs and Proof Techniques for Cryptographic Security. Affiliated with Eurocrypt 2026.
163
Reposted by Doreen Riepel
Miro Haller @mirohaller.bsky.social · 04/05/2026
The Cryptographic Applications Workshop (CAW) happens this Sunday in Rome! Just a reminder that if you're not coming to Rome you can still attend remotely. Just register here: forms.gle/2JZ7hLs8diQM... before May 8. See caw.cryptanalysis.fun for more infos and our program.
Program of CAW, also on our website: https://caw.cryptanalysis.fun/
086
Reposted by Doreen Riepel
Sabine Oechsner @proofnerd.bsky.social · 17/04/2026
I'm looking for a PhD student to work with me on formal verification for cryptographic protocols. This is a 4-year position at VU Amsterdam, co-supervised with Kristina Sojakova. Send me an email if you want to know more!
11013
Doreen Riepel @doreenriepel.bsky.social · 05/03/2026
I am very excited that our work on secure cloud storage is now online. A big shoutout also to my co-author @jonasjanneck.bsky.social who will present the results at Eurocrypt’26!
192
Reposted by Doreen Riepel
Paolo Santini @palli-santini.bsky.social · 16/02/2026
📢📢📢 𝐌𝐚𝐆𝐈𝐂 𝟐𝟎𝟐𝟔 𝐌𝐚𝐫𝐜𝐡𝐞 𝐖𝐨𝐫𝐤𝐬𝐡𝐨𝐩 𝐨𝐧 𝐆𝐫𝐨𝐮𝐩 𝐀𝐜𝐭𝐢𝐨𝐧𝐬 𝐢𝐧 𝐂𝐫𝐲𝐩𝐭𝐨𝐠𝐫𝐚𝐩𝐡𝐲 In May 5-8, let's all gather together to speak about Group Actions! Early registration until March 8! Organized with Marco Baldi, @bsky.defeo.lu, @giacomoborin.bsky.social, @andreavbasso.bsky.social magic-workshop.github.io
magic-workshop.github.io
MaGIC 2026 - Marche Workshop on Group Actions in Cryptography
047
Reposted by Doreen Riepel
Jonas Janneck @jonasjanneck.bsky.social · 27/02/2026
Happy to announce that Bird of Prey is accepted at EC’26 🛸✍️🎉 eprint.iacr.org/2025/1844 The paper presents three signature combiners for PQC migration preserving strong unforgeability. They capture all broadly used classical schemes and can be used with *any* PQ signature in a black-box way!
eprint.iacr.org
Bird of Prey: Practical Signature Combiners Preserving Strong Unforgeability
Following the announcement of the first winners of the NIST post-quantum cryptography standardization process in 2022, cryptographic protocols are now undergoing migration to the newly standardized sc...
141
Reposted by Doreen Riepel
Damien Robert @damienrobert.bsky.social · 20/02/2026
I am very happy to announce that thanks to the hard work of many people (The "MIKE Team"), we now have a working implementation in SageMath of MIKE (Module Isogeny Key Exchange).
198
Doreen Riepel @doreenriepel.bsky.social · 18/02/2026
📢 We have extended the deadline for our EC workshop to *Monday AoE*! Submit your talk proposal on any topic related to cryptographic proofs and proof techniques 🤓 Take the opportunity to advertise your ongoing, submitted or published work, or to share other insights related to security proofs
194
Reposted by Doreen Riepel
Sabine Oechsner @proofnerd.bsky.social · 14/02/2026
Remember to submit your ProTeCS talk. The deadline is on Thursday!
011
Doreen Riepel @doreenriepel.bsky.social · 30/01/2026
Planning your trip to Eurocrypt or looking for an excuse to still go? The reviewers did not appreciate your too involved or too elegant proofs? Consider submitting a talk to ProTeCS (protecs-workshop.gitlab.io), an affiliated event of EC, where we celebrate proofs as independent objects of study!
protecs-workshop.gitlab.io
Call for Presentations
Workshop on Proofs and Proof Techniques for Cryptographic Security. Affiliated with Eurocrypt 2026.
1114
Reposted by Doreen Riepel
Andrea Basso @andreavbasso.bsky.social · 09/01/2026
New paper out! 🎉 We translate the algebraic group model to the (generic) isogeny setting, generalising previous results that were limited to oriented isogenies (we show that any result that holds in the AGAM also holds in the AIM). Using this model, we obtain two important results:
1123
Reposted by Doreen Riepel
ePrint Updates @eprint.ing.bot · 09/01/2026
The Algebraic Isogeny Model: A General Model with Applications to SQIsign and Key Exchanges (Marius A. Aardal, Andrea Basso, Doreen Riepel) ia.cr/2026/032
Abstract. We introduce the Algebraic Isogeny Model (AIM): an algebraic model, akin to the Algebraic Group Model in the group setting, for isogenies and supersingular elliptic curves. This model is significantly more general than previous ones, such as the Algebraic Group Action Model: the AIM works with arbitrary isogenies over 𝔽_(p²), rather than being limited to oriented ones, which gives considerably more power to the adversary.

Within this model, we obtain three results. First, we show that any result in the AGAM can be lifted to the AIM, strengthening previous results against more powerful adversaries. Then, we prove that the SQIsign identification protocol is ID-sound: in turn, this implies that SQIsign is EUF-CMA secure in the Quantum Random Oracle Model, resolving (in the AIM) a long-standing open problem. Lastly, we establish the equivalence of the DLOG and CDH problems for all SIDH-derived key exchanges, such as M-SIDH, binSIDH, and terSIDH.
052
Reposted by Doreen Riepel
ePrint Updates @eprint.ing.bot · 09/07/2025
ABE Cubed: Advanced Benchmarking Extensions for ABE Squared (Sven Argo, Marloes Venema, Doreen Riepel, Tim Güneysu, Diego F. Aranha) ia.cr/2025/1230
Abstract. Since attribute-based encryption (ABE) was proposed in 2005, it has established itself as a valuable tool in the enforcement of access control. For practice, it is important that ABE satisfies many desirable properties such as multi-authority and negations support. Nowadays, we can attain these properties simultaneously, but none of these schemes have been implemented. Furthermore, although simpler schemes have been optimized extensively on a structural level, there is still much room for improvement for these more advanced schemes. However, even if we had schemes with such structural improvements, we would not have a way to benchmark and compare them fairly to measure the effect of such improvements. The only framework that aims to achieve this goal, ABE Squared (TCHES ’22), was designed with simpler schemes in mind.

In this work, we propose the ABE Cubed framework, which provides advanced benchmarking extensions for ABE Squared. To motivate our framework, we first apply structural improvements to the decentralized ciphertext-policy ABE scheme supporting negations presented by Riepel, Venema and Verma (ACM CCS ‘24), which results in five new schemes with the same properties. We use these schemes to uncover and bridge the gaps in the ABE Squared framework. In particular, we observe that advanced schemes depend on more “variables” that affect the schemes’ efficiency in different dimensions. Whereas ABE Squared only considered one dimension (as was sufficient for the schemes considered there), we devise a benchmarking strategy that allows us to analyze the schemes in multiple dimensions. As a result, we obtain a more complete overview on the computational efficiency of the schemes, and ultimately, this allows us to make better-founded choices about which schemes provide the best efficiency trade-offs for practice.
Image showing part 2 of abstract.
052
Reposted by Doreen Riepel
Luca De Feo @bsky.defeo.lu · 25/04/2025
The SQIparty starts on Monday, but it's still time to register! We prepared an exciting program for you with a balanced mix of talks, coding sprints, skillshares and other activities! www.cig.udl.cat/SQIparty2025... See you in Lleida!
299
Reposted by Doreen Riepel
Maria Corte-Real Santos @maria.isogeny.club · 03/04/2025
Really excited to share the Decrypting Diversity Summit happening in Montpellier, France from 17-20 June! The goal of the summit is to promote diversity, inclusivity, and gender equality within the cryptography community. For more info: decryptingdiversity.com
decryptingdiversity.com
Decrypting Diversity Summit
Decrypting Diversity Summit
196
Reposted by Doreen Riepel
Sabine Oechsner @proofnerd.bsky.social · 03/04/2025
Interested in formal verification for cryptography? But not sure where to start? If you are coming to Eurocrypt, consider joining us for CAPS, the workshop on Computer-Aided Proofs of Security! caps-workshop.com
caps-workshop.com
CAPS Workshop
2116
Reposted by Doreen Riepel
Daniel Slamanig @drl3c7er.bsky.social · 20/03/2025
We have extended the submission deadline for the International Workshop on Foundations and Applications of Privacy-Enhancing Cryptography (PrivCrypt) by two weeks to April 4, 2025, AoE. Please help spread the word and consider submitting your work to join us in Munich in Summer 😎
035
Reposted by Doreen Riepel
Paul Rösler @roeslpa.bsky.social · 05/03/2025
Join our Applied Crypto group at FAU in Nürnberg as a PhD student or spread the word: we're hiring. Our work covers many topics in real-world crypto, especially provable security and privacy of modern messaging protocols 🔐✉️ www.jobs.fau.de/jobs/7-phd-p...
jobs.fau.de
7 PhD positions (m/f/d) (salary level 13 TV-L) in Computer Science (full time) and 3 PhD position (m/f/d) (salary level 13 TV-L) in Law (part time, 75%)
0711
Reposted by Doreen Riepel
ePrint Updates @eprint.ing.bot · 04/03/2025
Lattice-Based Updatable Public-Key Encryption for Group Messaging (Joël Alwen, Georg Fuchsbauer, Marta Mularczyk, Doreen Riepel) ia.cr/2025/365
Abstract. Updatable Public-Key Encryption (UPKE) augments the security of PKE with Forward Secrecy properties. While requiring more coordination between parties, UPKE enables much more efficient constructions than full-fledged Forward-Secret PKE. Alwen, Fuchsbauer and Mularczyk (AFM, Eurocrypt’24) presented the strongest security notion to date. It is the first to meet the needs of UPKE’s most important applications: Secure Group Messaging and Continuous Group Key Agreement. The authors provide a very efficient construction meeting their notion with classic security based on the Computational Diffie-Hellman (CDH) assumption in the Random Oracle Model (ROM).

In this work we present the first post-quantum secure UPKE construction meeting (a slight relaxation of) the AFM security notion. Based on the Module LWE assumption, our construction is practically efficient. Moreover, public key sizes are about 1/2 and ciphertext sizes around 2/3 of those of the state-of-the-art lattice-based UPKE scheme in the ROM by Abou Haidar, Passelègue and Stehlé – despite only being shown to satisfy a significantly weaker security notion. As the AFM proofs relies on random self-reducibility of CDH, which has no analogue for lattices, we develop a new proof technique for strong UPKE, identifying the core properties required from the underlying (lattice-based) encryption scheme.
Image showing part 2 of abstract.
031
Reposted by Doreen Riepel
Tibor Jager @tiborj.bsky.social · 02/03/2025
The list of accepted papers and the (preliminary) program for PKC 2025 are now available online: pkc.iacr.org/2025/program... We are also delighted to announce that Jesper Buus Nielsen has accepted our invitation to give an invited talk at PKC 2025! See you at PKC 2025!
pkc.iacr.org
196
Reposted by Doreen Riepel
Kenny Paterson @kennyog.bsky.social · 28/02/2025
Come join us at the SPIQE workshop in Munich in June! spiqe-workshop.github.io - we are now open for paper submissions and talk proposals on all aspects of secure protocol implementation for the post-quantum era.
spiqe-workshop.github.io
Secure Protocol Implementations in the Quantum Era (SPIQE)
Secure Protocol Implementations in the Quantum Era (SPIQE)
065