Doreen Riepel

Doreen Riepel
CV

I am a tenure-track faculty member at CISPA Helmholtz Center for Information Security, where I am part of the research area Algorithmic Foundations and Cryptography. My group focuses mainly on provable security. Previously, I was a postdoctoral researcher at UC San Diego working with Mihir Bellare. I received my PhD from Ruhr University Bochum under the supervision of Eike Kiltz.

My research lies at the intersection of cryptography and provable security. I study the theoretical foundations of cryptographic schemes and protocols used in practice, with the goal of obtaining strong and concrete security guarantees. My work combines the analysis of existing cryptographic constructions with the design of new protocols and security models. I am particularly interested in authenticated key exchange, secure messaging, advanced encryption schemes, post-quantum cryptography, and tight security reductions. Recent work includes contributions to group and ratcheted key exchange, updatable and attribute-based encryption, cryptographic group actions and isogeny-based cryptography, and formal models for modern cryptographic protocols.

More broadly, I aim to increase the rigor and reliability of cryptographic research. For example, I am interested in computer-assisted proofs and the formal verification of security arguments, with the goal of bringing provable security closer to techniques from formal methods. I am also interested in strengthening the foundations of isogeny-based cryptography by better aligning provable security techniques with the underlying mathematics.

Publications

Projects

Crypto Proof Ladders

The Crypto Proof Ladders project aims to provide a gentle introduction to formal methods for cryptography. The main idea is to present a collection of cryptographic problems with increasing levels of difficulty, formalized both as traditional pen-and-paper proofs and within different proof tools. The project is an initiative that originated from the HACS workshop and brings together cryptographers, cryptography engineers, and formal methods researchers. In this context, Paul Rösler and I contributed game-based definitions and proofs for unilateral authenticated key exchange protocols, available here. An EasyCrypt translation of the proof, mainly driven by François Dupressoir, is currently a work in progress.
Additional tools and resources are listed below.

PELICAN

The PELICAN project is an Équipe Associée with Inria, led by Sabrina Kunzweiler and myself. Funded by Inria, PELICAN focuses on the foundations of provable security for isogeny-based cryptographic protocols, and supports visits between our groups to foster closer collaboration.

PQarrots

I am part of the PQarrots submission to the NIST Threshold Cryptography Call. We propose post-quantum threshold primitives based on isogeny-based group actions, including threshold signatures, public-key encryption, and distributed key generation. A preview is available here. A more detailed version with full specifications, implementation details, and security proofs will follow.

Service

Program Committees

2026
CRYPTO, S&P, ACM PQQS
2025
PKC, ACNS
2024
EUROCRYPT
2023
TCC

Reviewing

2026
EUROCRYPT, PKC
2025
CRYPTO, JoC
2024
CRYPTO, ASIACRYPT, TCC, ACM TOPS, JoC
2023
EUROCRYPT, PKC
2022
CRYPTO, ACM TOPS
2021
EUROCRYPT
2020
CRYPTO

Other

2026 · PC · Marche Workshop on Group Actions in Cryptography
CAST/GI Promotionspreis
2025, 2026 · Award committee

Organization

Co-organizer · EUROCRYPT 2026 affiliated event
Co-organizer · Women in Security and Cryptography

Resources

Tools for Cryptographers

I am generally interested in tools that support rigorous cryptographic proofs. While I am currently not involved in the development of such tools myself, I am actively supporting this area and am always happy to discuss ideas in this direction. Below are a few tools and resources developed by members of the community that I find particularly interesting:

  • ProofFrog is a light-weight and easy-to-learn tool that checks game-hopping proof transitions in reduction-based security proofs.
  • Domino is a tool to write and verify cryptographic proofs in the State-Separation Proofs framework. It can manage more tedious aspects, as they often come up in proofs for key exchange protocols.
  • EasyCrypt is an interactive framework for machine-checked proofs of cryptographic schemes and protocols in the computational model. It is a very powerful tool, therefore not so easy to learn.

A direction that I find particularly interesting is how cryptographic proofs can be made more readable and interactive. Beyond traditional static LaTeX documents (who does ever read appendices), I believe that future proof presentations could allow structured navigation through games, reductions, and assumptions, making complex arguments easier to follow and verify. Related resources include:

  • TeXFrog supports writing game-hopping proofs in LaTeX by automatically generating per-game renderings with highlighted differences.
  • The Joy of Cryptography is a free undergraduate-level textbook by Mike Rosulek that introduces the fundamentals of provable security. The new web version is a nice example of presenting cryptographic content in a more structured and interactive way.
Implementations

Lincoln Cryptools is a GitHub organization that hosts implementations of cryptographic schemes and tools, in particular for attribute-based encryption. The project includes code accompanying papers such as ABE Cubed and ISABELLA, to which I contributed on the theoretical aspects. Since then, my coauthors have continued to expand the project with new functionality and capabilities, which can be found on the organization's website.

Talks

Invited Talks
Modeling and Proving Security: From Foundations of Key Exchange to Real-World Cryptography
Jun 2025 · Women in Security and Cryptography Workshop (WISC) · Bochum, Germany
Conference Talks
Count Corruptions, Not Users: Improved Tightness for Signatures, Encryption and Authenticated Key Exchange
Dec 2024 · Asiacrypt 2024 · Kolkata, India
On the Tight Security of the Double Ratchet
Oct 2024 · ACM CCS 2024 · Salt Lake City, UT, USA
CCA Secure Updatable Encryption from Non-Mappable Group Actions
Jun 2024 · PQCrypto 2024 · Oxford, UK
Key Exchange with Tight (Full) Forward Secrecy via Key Confirmation
May 2024 · Eurocrypt 2024 · Zürich, Switzerland
Multi-User CDH Problems and the Concrete Security of NAXOS and HMQV
Apr 2023 · RSA Conference 2023 · San Francisco, CA, USA
FABEO: Fast Attribute-Based Encryption with Optimal Security
Nov 2022 · ACM CCS 2022 · Los Angeles, CA, USA
Password-Authenticated Key Exchange from Group Actions
Aug 2022 · Crypto 2022 · Santa Barbara, CA, USA
Tightly-Secure Authenticated Key Exchange, Revisited
Oct 2021 · Eurocrypt 2021 · Zagreb, Croatia
Authenticated Key Exchange and Signatures with Tight Security in the Standard Model
Aug 2021 · Crypto 2021 · Virtual
Seminar & Workshop Talks
From Pen-and-Paper to EasyCrypt: An Ongoing Story of Signed Diffie-Hellman
May 2026 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy
Lattice-Based Updatable KEM for Group Messaging
Jan 2026 · IBM Research · Zürich, Switzerland
Jan 2026 · ETH Zürich · Zürich, Switzerland
Count Corruptions, Not Users: Improved Tightness for Signatures, Encryption and Authenticated Key Exchange
Jun 2025 · Ruhr University Bochum · Bochum, Germany
Jun 2025 · University of Wuppertal · Wuppertal, Germany
Key Exchange Security – Pen&Paper Model and Proof of Signed Diffie-Hellman
May 2025 · Workshop on Computer-Aided Proofs of Security (CAPS) · Madrid, Spain
Password-Authenticated Key Exchange from Group Actions
Feb 2025 · Workshop on PAKE and Password Security & Usability · Luxembourg
Nov 2022 · UC San Diego · La Jolla, CA, USA
Mar 2022 · UC Berkeley · Berkeley, CA, USA
Jan 2022 · Max-Planck Institute for Security and Privacy · Bochum, Germany
Jan 2022 · New York University · Virtual
On the Tight Security of the Double Ratchet
Jun 2024 · NTNU Trondheim · Trondheim, Norway
Tightly-Secure AKE: Overview, Challenges and New Directions
Jun 2024 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy
Advanced Key Exchange Protocols from CSIDH
Jul 2023 · Microsoft Research and University of Washington · Redmond, WA, USA
Generic Models for Group Actions
Mar 2023 · Young Researcher Crypto Seminar (YRCS) · Regensburg, Germany
Analysis of Key Exchange Protocols based on Group Actions
Mar 2023 · NTNU Trondheim · Trondheim, Norway
FABEO: Fast Attribute-Based Encryption with Optimal Security
Aug 2022 · NTT Research CIS Update 2022 · Santa Barbara, CA, USA
On Key Exchange from Group Actions
Jul 2022 · Secure Key Exchange and Channel Protocols (SKECH) · Bertinoro, Italy

BibTeX