REWOCRYPT - Theoretically-Sound Real-World Cryptography

This project has received funding from the European Research Council (ERC) under the European Union's Horizon 2020 research and innovation programme (grant agreement No 802823).
What is the problem/issue being addressed?
Modern cryptographic techniques enable us to construct cryptosystems in a theoretically sound way, underpinned by precise mathematical arguments and based on a (relatively) small number of computational hardness assumptions that can thoroughly be analyzed, independently of particular cryptographic constructions.
Today we have a large number of different accepted security definitions for many cryptographic primitives. A very important insight provided by theoretical cryptography is that we have understood that there may be many useful security notions for the same cryptographic primitive. Different applications may have different security requirements, therefore the "right" security notion depends on the given application. A proof of security holds only for the definition considered in the proof (and by trivial implication also for any weaker security definition, of course). Even a provably-secure cryptosystem can be completely insecure in practice, if the security model considered in the proof does not reflect the security requirements of the application properly.
In the recent past, we have seen a very large number of practical attacks on cryptosystems, which can be seen as a consequence of the fact that the security properties provided by a cryptosystem do not match the concrete security requirements of an application.
Why is it important for society?
Cryptography is a cornerstone of secure communication in a modern, increasingly interconnected and increasingly digitized society.
What are the overall objectives?
The main objective of the REWOCRYPT project is to close the gap between theoretical and real- world cryptography, by tackling the most important research challenge at the intersection of these areas: We want to achieve the same strong security guarantees for real-world cryptography that we are able to achieve in theoretical cryptography.
The theoretically-sound design and security analysis of real-world cryptography will improve our understanding of the security properties required from real-world cryptosystems, whether and how these can be achieved with efficient cryptographic constructions, and ultimately contribute to the prevention of practical attacks. This will be a significant improvement of the current state-of-the-art. Providing solid technical and methodological foundations for the theoretically-sound, practice-driven formal analysis of real-world cryptosystems is a ground-breaking contribution, which will significantly deepen our understanding of "secure" real-world cryptography in both theory and practice. By identifying new security notions and understanding if and how they can be achieved, or why they can not be achieved, one can also expect valuable further contributions to cryptographic theory.
Project-Related Publications
This sections detaild all project related publications sorted by work packages.
Pillar 1: Securely Combining Cryptography with the Application Layer
Work Package 1.1: How to use TLS 0-RTT Securely in Applications
- Fynn Dallmeier, Jan P. Drees, Kai Gellert, Tobias Handirk, Tibor Jager, Jonas Klauke, Simon Nachtigall, Timo Renzelmann, Rudi Wolf
Forward-Secure 0-RTT Goes Live: Implementation and Performance Analysis in QUIC
19th International Conference on Cryptology and Network Security 2020 - David Derler, Kai Gellert, Tibor Jager, Daniel Slamanig, Christoph Striecks
Bloom Filter Encryption and Applications to Efficient Forward-Secret 0-RTT Key Exchange
Journal of Cryptology, 2021 - Nimrod Aviram, Kai Gellert, Tibor Jager
Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTT
Journal of Cryptology - Special Issue on TLS 1.3, 2021
Work Package 1.2: Secure Compress-then-Encrypt and How to Use Length-Hiding Encryption
- Kai Gellert, Tibor Jager, Lin Lyu, Tom Neuschulten
On Fingerprinting Attacks and Length-Hiding Encryption
RSA Conference, Cryptographers’ Track - CT-RSA 2022
Pillar 2: Possibility and Impossibility of Cryptographic Primitives for Real-World Applications
Work Package 2.1: Provably Secure Cryptographic Primitives for Modern Applications
- Cas Cremers, Katriel Cohn-Gordon, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager
Highly Efficient Key Exchange Protocols with Optimal Tightness
39th International Cryptology Conference - CRYPTO 2019 - Tibor Jager, David Niehues
On the Real-World Instantiability of Admissible Hash Functions and Efficient Verifiable Random Functions
Selected Areas in Cryptography - SAC 2019 - 26th International Conference - Gareth T. Davies, Christian Janson, Daniel P. Martin
Client-oblivious OPRAM
International Conference on Information and Communications Security - ICICS 2020 - Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao Jiang
Fast and Secure Updatable Encryption
40th Annual International Cryptology Conference - CRYPTO 2020 - Gareth T. Davies, Herman Galteland, Kristian Gjøsteen, Yao Jiang
Cloud-assisted Asynchronous Key Transport with Post-Quantum Security
25th Australasian Conference on Information Security and Privacy - ACISP 2020 - Colin Boyd, Gareth T. Davies, Bor de Kock, Kai Gellert, Tibor Jager, Lise Millerjord
Symmetric Key Exchange with Full Forward Security and Robust Synchronization
27th Annual International Conference on the Theory and Applications of Cryptology and Information Security - ASIACRYPT 2021 - Gareth T. Davies, Sebastian Faller, Kai Gellert, Tobias Handirk, Julia Hesse, Máté Horvath, Tibor Jager
Security Analysis of the WhatsApp End-to-End Encrypted Backup Protocol
43th Annual International Cryptology Conference - CRYPTO 2023
Work Package 2.2: Overcoming Impossibility Results on Tight Real-World Security
- Hannah E. Davis, Denis Diemert, Felix Günther, Tibor Jager
On the Concrete Security of TLS 1.3 PSK Mode
41th Annual International Conference on the Theory and Applications of Cryptographic Techniques - EUROCRYPT 2022 - Denis Diemert, Tibor Jager
On the Tight Security of TLS 1.3: Theoretically-Sound Cryptographic Parameters for Real-World Deployments
Journal of Cryptology - Special Issue on TLS 1.3, 2021 - Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge
Tightly-Secure Authenticated Key Exchange, Revisited
40th Annual International Conference on the Theory and Applications of Cryptographic Techniques - EUROCRYPT 2021 - Denis Diemert, Kai Gellert, Tibor Jager, Lin Lyu
More Efficient Digital Signatures with Tight Multi-User Security
24th International Conference on Practice and Theory of Public-Key Cryptography - PKC 2021 - Shuai Han, Tibor Jager, Eike Kiltz, Shengli Liu, Jiaxin Pan, Doreen Riepel, Sven Schäge
Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
41th Annual International Cryptology Conference - CRYPTO 2021 - Denis Diemert, Kai Gellert, Tibor Jager, Lin Lyu
Digital Signatures with Memory-Tight Security in the Multi-Challenge Setting
27th Annual International Conference on the Theory and Applications of Cryptology and Information Security - ASIACRYPT 2021 - Kai Gellert, Kristian Gjøsteen, Håkon Jacobsen, Tibor Jager
On Optimal Tightness for Key Exchange with Full Forward Secrecy via Key Confirmation
43th Annual International Cryptology Conference - CRYPTO 2023
Work Package 2.3: Systematic Study of the Secure Use of Legacy Cryptography
- No research results have been published yet.