CryptoDB
Bogdan Warinschi
Publications
Year
Venue
Title
2022
PKC
Lifting Standard Model Reductions to Common Setup Assumptions
📺
Abstract
In this paper we show that standard model black-box reductions naturally lift to various setup assumptions, such as the random oracle (ROM) or ideal cipher model.
Concretely, we prove that a black-box reduction from a security notion $P$ to security notion $Q$ in the standard model can be turned into a non-programmable black-box reduction from $P_\oracle$ to $Q_\oracle$ in a model with a setup assumption $\oracle$, where $P_\oracle$ and $Q_\oracle$ are the natural extensions of $P$ and $Q$ to a model with a setup assumption $\oracle$.
Our results rely on a generalization of the recent framework by Hofheinz and Nguyen (PKC 2019) to support primitives which make use of a trusted setup. Our framework encompasses standard idealized settings like the random oracle and the ideal cipher model.
At the core of our main result lie novel properties of negligible functions that can be of independent interest.
2021
CRYPTO
Provable Security Analysis of FIDO2
📺
Abstract
We carry out the first provable security analysis of the new FIDO2 protocols, the promising FIDO Alliance’s proposal for a standard for passwordless user authentication. Our analysis covers the core components of FIDO2: the W3C’s Web Authentication (WebAuthn) specification and the new Client-to-Authenticator Protocol (CTAP2).
Our analysis is modular. For WebAuthn and CTAP2, in turn, we propose appropriate security models that aim to capture their intended security goals and use the models to analyze their security. First, our proof confirms the authentication security of WebAuthn. Then, we show CTAP2 can only be proved secure in a weak sense; meanwhile, we identify a series of its design flaws and provide suggestions for improvement. To withstand stronger yet realistic adversaries, we propose a generic protocol called sPACA and prove its strong security; with proper instantiations, sPACA is also more efficient than CTAP2. Finally, we analyze the overall security guarantees provided by FIDO2 and WebAuthn+sPACA based on the security of their components.
We expect that our models and provable security results will help clarify the security guarantees of the FIDO2 protocols. In addition, we advocate the adoption of our sPACA protocol as a substitute for CTAP2 for both stronger security and better performance.
2021
RWC
SWiSSSE: System-Wide Security for Searchable Symmetric Encryption
Abstract
This talk introduces a new direction of research for searchable symmetric encryption (SSE). In contrast to previous research in SSE which focussed only on leakage from the encrypted index component of SSE, we consider the system-wide security of SSE schemes, encompassing both encrypted indices and encrypted documents. The SWiSSSE scheme that we present provably meets a strong, system-side security definition; our proof is complemented by cryptanalysis showing that the residual leakage does not render SWiSSSE vulnerable to known attacks. We believe that by taking a system-wide view of security for SSE, we can provide greater confidence to practitioners considering deployment of SSE schemes.
2012
ASIACRYPT
2007
CRYPTO
2003
EUROCRYPT
Service
- Crypto 2019 Program committee
- PKC 2018 Program committee
- Eurocrypt 2015 Program committee
- Crypto 2014 Program committee
- Eurocrypt 2014 Program committee
- Crypto 2011 Program committee
- PKC 2010 Program committee
- TCC 2010 Program committee
- TCC 2007 Program committee
Coauthors
- Manuel Barbosa (1)
- Mihir Bellare (1)
- David Bernhard (3)
- Alexandra Boldyreva (3)
- Emmanuel Bresson (1)
- David Cash (1)
- Dario Catalano (3)
- Shan Chen (1)
- Liqun Chen (1)
- Dario Fiore (3)
- Marc Fischlin (4)
- Essam Ghadafi (1)
- Zichen Gui (1)
- Carmit Hazay (1)
- Tibor Jager (1)
- Yassine Lakhnech (1)
- Laurent Mazaré (1)
- Daniele Micciancio (2)
- Paul Morrissey (3)
- Ngoc Khanh Nguyen (1)
- Adriana Palacio (1)
- Kenneth Paterson (1)
- Arpita Patra (1)
- Sikhar Patranabis (1)
- Olivier Pereira (1)
- Thomas Shrimpton (1)
- Nigel P. Smart (4)
- Martijn Stam (2)
- Ryan Stanley-Oakes (1)
- Eftychios Theodorakis (1)
- Bogdan Warinschi (21)