Doreen Riepel

Doreen Riepel

I am a tenure-track faculty member at CISPA Helmholtz Center for Information Security, where I am part of the research area Algorithmic Foundations and Cryptography. My group focuses mainly on provable security. Previously, I was a postdoctoral researcher at UC San Diego working with Mihir Bellare. I received my PhD from Ruhr University Bochum under the supervision of Eike Kiltz.

My research lies at the intersection of cryptography and provable security. I study the theoretical foundations of cryptographic schemes and protocols used in practice, with the goal of obtaining strong and concrete security guarantees. My work combines the analysis of existing cryptographic constructions with the design of new protocols and security models. I am particularly interested in authenticated key exchange, secure messaging, advanced encryption schemes, post-quantum cryptography, and tight security reductions. Recent work includes contributions to group and ratcheted key exchange, updatable and attribute-based encryption, cryptographic group actions and isogeny-based cryptography, and formal models for modern cryptographic protocols.

More broadly, I aim to increase the rigor and reliability of cryptographic research. For example, I am interested in computer-assisted proofs and the formal verification of security arguments, with the goal of bringing provable security closer to techniques from formal methods. I am also interested in strengthening the foundations of isogeny-based cryptography by better aligning provable security techniques with the underlying mathematics..

CV

Publications

Preprints
Snake Mackerel: An Isogeny-Based AKEM Leveraging Randomness Reuse

Jonas Janneck, Jonas Meers, Massimo Ostuzzi, Doreen Riepel

IACR Cryptology ePrint Archive, 2025

2026
Lattice-Based Updatable KEM for Group Messaging

Joël Alwen, Georg Fuchsbauer, Marta Mularczyk, Doreen Riepel

Annual International Cryptology Conference (CRYPTO)

Secure Cloud Storage: Modularization, Network Adversaries and Adaptive Corruptions

Jonas Janneck, Doreen Riepel

Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT)

The Algebraic Isogeny Model: A General Model with Applications to SQIsign and Key Exchanges

Marius A. Aardal, Andrea Basso, Doreen Riepel

Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT)

2025
ABE Cubed: Advanced Benchmarking Extensions for ABE Squared

Sven Argo, Marloes Venema, Doreen Riepel, Tim Güneysu, Diego F. Aranha

IACR Transactions on Cryptographic Hardware and Embedded Systems (CHES)

Intermundium-DL: Assessing the Resilience of Current Schemes to Discrete-Log-Computation Attacks on Public Parameters

Mihir Bellare, Doreen Riepel, Laura Shea

IACR International Conference on Practice and Theory of Public-Key Cryptography (PKC)

Public-Algorithm Substitution Attacks: Subverting Hashing and Verification

Mihir Bellare, Doreen Riepel, Laura Shea

IACR International Conference on Practice and Theory of Public-Key Cryptography (PKC)

Verifiable and Provably Secure Machine Unlearning

Thorsten Eisenhofer, Doreen Riepel, Varun Chandrasekaran, Esha Ghosh, Olga Ohrimenko, Nicolas Papernot

IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)

2024
The Concrete Security of Two-Party Computation: Simple Definitions, and Tight Proofs for PSI and OPRFs

Mihir Bellare, Doreen Riepel, Rishabh Ranjan, Ali Aldakheel

International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT)

Count Corruptions, Not Users: Improved Tightness for Signatures, Encryption and Authenticated Key Exchange

Mihir Bellare, Doreen Riepel, Stefano Tessaro, Yizhao Zhang

International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT)

Tightly-Secure Group Key Exchange with Perfect Forward Secrecy

Emanuele Di Giandomenico, Doreen Riepel, Sven Schäge

International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT)

On the Tight Security of the Double Ratchet

Daniel Collins, Doreen Riepel, Si An Oliver Tran

ACM Conference on Computer and Communications Security (CCS)

ISABELLA: Improving Structures of Attribute-Based Encryption Leveraging Linear Algebra

Doreen Riepel, Marloes Venema, Tanya Verma

ACM Conference on Computer and Communications Security (CCS)

Key Exchange with Tight (Full) Forward Secrecy via Key Confirmation

Jiaxin Pan, Doreen Riepel, Runzhi Zeng

Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT)

CCA Secure Updatable Encryption from Non-Mappable Group Actions

Jonas Meers, Doreen Riepel

Post-Quantum Cryptography (PQCrypto)

2023
Tightly-Secure Authenticated Key Exchange

Doreen Riepel

PhD Thesis, Ruhr University Bochum

Multi-User CDH Problems and the Concrete Security of NAXOS and HMQV

Eike Kiltz, Jiaxin Pan, Magnus Ringerud, Doreen Riepel

Topics in Cryptology – CT-RSA

Generic Models for Group Actions

Julien Duman, Dominik Hartmann, Eike Kiltz, Sabrina Kunzweiler, Jonas Lehmann, Doreen Riepel

IACR International Conference on Practice and Theory of Public-Key Cryptography (PKC)

No More Reviewer #2: Subverting Automatic Paper-Reviewer Assignment using Adversarial Learning

Thorsten Eisenhofer, Erwin Quiring, Jonas Möller, Doreen Riepel, Thorsten Holz, Konrad Rieck

USENIX Security Symposium

2022
Strongly Anonymous Ratcheted Key Exchange

Benjamin Dowling, Eduard Hauck, Doreen Riepel, Paul Rösler

International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT)

Group Action Key Encapsulation and Non-Interactive Key Exchange in the QROM

Julien Duman, Dominik Hartmann, Eike Kiltz, Sabrina Kunzweiler, Jonas Lehmann, Doreen Riepel

International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT)

FABEO: Fast Attribute-Based Encryption with Optimal Security

Doreen Riepel, Hoeteck Wee

ACM Conference on Computer and Communications Security (CCS)

Password-Authenticated Key Exchange from Group Actions

Michel Abdalla, Thorsten Eisenhofer, Eike Kiltz, Sabrina Kunzweiler, Doreen Riepel

Annual International Cryptology Conference (CRYPTO)

2021
Authenticated Key Exchange and Signatures with Tight Security in the Standard Model

Shuai Han, Tibor Jager, Eike Kiltz, Shengli Liu, Jiaxin Pan, Doreen Riepel, Sven Schäge

Annual International Cryptology Conference (CRYPTO)

Analysing the HPKE Standard

Joël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz, Benjamin Lipp, Doreen Riepel

Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT)

Tightly-Secure Authenticated Key Exchange, Revisited

Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge

Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT)

Projects

Crypto Proof Ladders

The Crypto Proof Ladders project aims to provide a gentle introduction to formal methods for cryptography. The main idea is to present a collection of cryptographic problems with increasing levels of difficulty, formalized both as traditional pen-and-paper proofs and within different proof tools. The project is an initiative that originated from the HACS workshop and brings together cryptographers, cryptography engineers, and formal methods researchers. In this context, Paul Rösler and I contributed game-based definitions and proofs for unilateral authenticated key exchange protocols, available here. An EasyCrypt translation of the proof, mainly driven by François Dupressoir, is currently a work in progress.
Additional tools and resources are listed below.

PELICAN

The PELICAN project is an Équipe Associée with Inria, led by Sabrina Kunzweiler and myself. Funded by Inria, PELICAN focuses on the foundations of provable security for isogeny-based cryptographic protocols, and supports visits between our groups to foster closer collaboration.

PQarrots

I am part of the PQarrots submission to the NIST Threshold Cryptography Call. We propose post-quantum threshold primitives based on isogeny-based group actions, including threshold signatures, public-key encryption, and distributed key generation. A preview is available here. A more detailed version with full specifications, implementation details, and security proofs will follow.

Service

Program Committees

2026
CRYPTO, S&P
2025
PKC, ACNS
2024
EUROCRYPT
2023
TCC

Reviewing

2026
EUROCRYPT, PKC
2025
CRYPTO, JoC
2024
CRYPTO, ASIACRYPT, TCC, ACM TOPS, JoC
2023
EUROCRYPT, PKC
2022
CRYPTO, ACM TOPS
2021
EUROCRYPT
2020
CRYPTO

Other

2026 · PC · Marche Workshop on Group Actions in Cryptography
CAST/GI Promotionspreis
2025, 2026 · Award committee

Organization

Co-organizer · EUROCRYPT 2026 affiliated event
Co-organizer · Women in Security and Cryptography

Resources

Tools for Cryptographers

I am generally interested in tools that support rigorous cryptographic proofs. While I am currently not involved in the development of such tools myself, I am actively supporting this area and am always happy to discuss ideas in this direction. Below are a few tools and resources developed by members of the community that I find particularly interesting:

  • ProofFrog is a light-weight and easy-to-learn tool that checks game-hopping proof transitions in reduction-based security proofs.
  • Domino is a tool to write and verify cryptographic proofs in the State-Separation Proofs framework. It can manage more tedious aspects, as they often come up in proofs for key exchange protocols.
  • EasyCrypt is an interactive framework for machine-checked proofs of cryptographic schemes and protocols in the computational model. It is a very powerful tool, therefore not so easy to learn.

A direction that I find particularly interesting is how cryptographic proofs can be made more readable and interactive. Beyond traditional static LaTeX documents (who does ever read appendices), I believe that future proof presentations could allow structured navigation through games, reductions, and assumptions, making complex arguments easier to follow and verify. Related resources include:

  • TeXFrog supports writing game-hopping proofs in LaTeX by automatically generating per-game renderings with highlighted differences.
  • The Joy of Cryptography is a free undergraduate-level textbook by Mike Rosulek that introduces the fundamentals of provable security. The new web version is a nice example of presenting cryptographic content in a more structured and interactive way.

Talks

Invited Talks
Modeling and Proving Security: From Foundations of Key Exchange to Real-World Cryptography
Jun 2025 · Women in Security and Cryptography Workshop (WISC) · Bochum, Germany
Conference Talks
Count Corruptions, Not Users: Improved Tightness for Signatures, Encryption and Authenticated Key Exchange
Dec 2024 · Asiacrypt 2024 · Kolkata, India
On the Tight Security of the Double Ratchet
Oct 2024 · ACM CCS 2024 · Salt Lake City, UT, USA
CCA Secure Updatable Encryption from Non-Mappable Group Actions
Jun 2024 · PQCrypto 2024 · Oxford, UK
Key Exchange with Tight (Full) Forward Secrecy via Key Confirmation
May 2024 · Eurocrypt 2024 · Zürich, Switzerland
Multi-User CDH Problems and the Concrete Security of NAXOS and HMQV
Apr 2023 · RSA Conference 2023 · San Francisco, CA, USA
FABEO: Fast Attribute-Based Encryption with Optimal Security
Nov 2022 · ACM CCS 2022 · Los Angeles, CA, USA
Password-Authenticated Key Exchange from Group Actions
Aug 2022 · Crypto 2022 · Santa Barbara, CA, USA
Tightly-Secure Authenticated Key Exchange, Revisited
Oct 2021 · Eurocrypt 2021 · Zagreb, Croatia
Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Aug 2021 · Crypto 2021 · Virtual
Seminar & Workshop Talks
From Pen-and-Paper to EasyCrypt: An Ongoing Story of Signed Diffie-Hellman
May 2026 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy
Lattice-Based Updatable KEM for Group Messaging
Jan 2026 · IBM Research · Zürich, Switzerland
Jan 2026 · ETH Zürich · Zürich, Switzerland
Count Corruptions, Not Users: Improved Tightness for Signatures, Encryption and Authenticated Key Exchange
Jun 2025 · Ruhr University Bochum · Bochum, Germany
Jun 2025 · University of Wuppertal · Wuppertal, Germany
Key Exchange Security – Pen&Paper Model and Proof of Signed Diffie-Hellman
May 2025 · Workshop on Computer-Aided Proofs of Security (CAPS) · Madrid, Spain
Password-Authenticated Key Exchange from Group Actions
Feb 2025 · Workshop on PAKE and Password Security & Usability · Luxembourg
Nov 2022 · UC San Diego · La Jolla, CA, USA
Mar 2022 · UC Berkeley · Berkeley, CA, USA
Jan 2022 · Max-Planck Institute for Security and Privacy · Bochum, Germany
Jan 2022 · New York University · Virtual
On the Tight Security of the Double Ratchet
Jun 2024 · NTNU Trondheim · Trondheim, Norway
Tightly-Secure AKE: Overview, Challenges and New Directions
Jun 2024 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy
Advanced Key Exchange Protocols from CSIDH
Jul 2023 · Microsoft Research and University of Washington · Redmond, WA, USA
Generic Models for Group Actions
Mar 2023 · Young Researcher Crypto Seminar (YRCS) · Regensburg, Germany
Analysis of Key Exchange Protocols based on Group Actions
Mar 2023 · NTNU Trondheim · Trondheim, Norway
FABEO: Fast Attribute-Based Encryption with Optimal Security
Aug 2022 · NTT Research CIS Update 2022 · Santa Barbara, CA, USA
On Key Exchange from Group Actions
Jul 2022 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy

BibTeX