{"id":"https://openalex.org/W3037277476","doi":"https://doi.org/10.1007/s00145-021-09388-x","title":"On the Tight Security of TLS 1.3: Theoretically Sound Cryptographic Parameters for Real-World Deployments","display_name":"On the Tight Security of TLS 1.3: Theoretically Sound Cryptographic Parameters for Real-World Deployments","publication_year":2021,"publication_date":"2021-06-04","ids":{"openalex":"https://openalex.org/W3037277476","doi":"https://doi.org/10.1007/s00145-021-09388-x","mag":"3037277476"},"language":"en","primary_location":{"id":"doi:10.1007/s00145-021-09388-x","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00145-021-09388-x","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00145-021-09388-x.pdf","source":{"id":"https://openalex.org/S190936789","display_name":"Journal of Cryptology","issn_l":"0933-2790","issn":["0933-2790","1432-1378"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cryptology","raw_type":"journal-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/s00145-021-09388-x.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5004038755","display_name":"Denis Diemert","orcid":null},"institutions":[{"id":"https://openalex.org/I167360494","display_name":"University of Wuppertal","ror":"https://ror.org/00613ak93","country_code":"DE","type":"education","lineage":["https://openalex.org/I167360494"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Denis Diemert","raw_affiliation_strings":["University of Wuppertal, Wuppertal, Germany"],"affiliations":[{"raw_affiliation_string":"University of Wuppertal, Wuppertal, Germany","institution_ids":["https://openalex.org/I167360494"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5090157645","display_name":"Tibor Jager","orcid":"https://orcid.org/0000-0002-3205-7699"},"institutions":[{"id":"https://openalex.org/I167360494","display_name":"University of Wuppertal","ror":"https://ror.org/00613ak93","country_code":"DE","type":"education","lineage":["https://openalex.org/I167360494"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Tibor Jager","raw_affiliation_strings":["University of Wuppertal, Wuppertal, Germany"],"affiliations":[{"raw_affiliation_string":"University of Wuppertal, Wuppertal, Germany","institution_ids":["https://openalex.org/I167360494"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5004038755"],"corresponding_institution_ids":["https://openalex.org/I167360494"],"apc_list":{"value":2290,"currency":"EUR","value_usd":2890},"apc_paid":{"value":2290,"currency":"EUR","value_usd":2890},"fwci":0.42,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.67228612,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":95},"biblio":{"volume":"34","issue":"3","first_page":"726","last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.9861999750137329,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7854701280593872},{"id":"https://openalex.org/keywords/random-oracle","display_name":"Random oracle","score":0.759804368019104},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.6409802436828613},{"id":"https://openalex.org/keywords/cryptographic-primitive","display_name":"Cryptographic primitive","score":0.5571388006210327},{"id":"https://openalex.org/keywords/security-parameter","display_name":"Security parameter","score":0.5389543175697327},{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.515033483505249},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.51416015625},{"id":"https://openalex.org/keywords/oracle","display_name":"Oracle","score":0.49434328079223633},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.46101605892181396},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4576739966869354},{"id":"https://openalex.org/keywords/symmetric-key-algorithm","display_name":"Symmetric-key algorithm","score":0.4498625099658966},{"id":"https://openalex.org/keywords/digital-signature","display_name":"Digital signature","score":0.44630804657936096},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.4210147261619568},{"id":"https://openalex.org/keywords/transport-layer-security","display_name":"Transport Layer Security","score":0.4157019555568695},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.4101957380771637},{"id":"https://openalex.org/keywords/public-key-cryptography","display_name":"Public-key cryptography","score":0.22369703650474548},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.19654682278633118},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.0726872980594635}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7854701280593872},{"id":"https://openalex.org/C94284585","wikidata":"https://www.wikidata.org/wiki/Q228184","display_name":"Random oracle","level":4,"score":0.759804368019104},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.6409802436828613},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.5571388006210327},{"id":"https://openalex.org/C2776711565","wikidata":"https://www.wikidata.org/wiki/Q7445058","display_name":"Security parameter","level":3,"score":0.5389543175697327},{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.515033483505249},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.51416015625},{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.49434328079223633},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.46101605892181396},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4576739966869354},{"id":"https://openalex.org/C65302260","wikidata":"https://www.wikidata.org/wiki/Q327675","display_name":"Symmetric-key algorithm","level":4,"score":0.4498625099658966},{"id":"https://openalex.org/C118463975","wikidata":"https://www.wikidata.org/wiki/Q220849","display_name":"Digital signature","level":3,"score":0.44630804657936096},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4210147261619568},{"id":"https://openalex.org/C148176105","wikidata":"https://www.wikidata.org/wiki/Q206494","display_name":"Transport Layer Security","level":3,"score":0.4157019555568695},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.4101957380771637},{"id":"https://openalex.org/C203062551","wikidata":"https://www.wikidata.org/wiki/Q201339","display_name":"Public-key cryptography","level":3,"score":0.22369703650474548},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.19654682278633118},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.0726872980594635},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/s00145-021-09388-x","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00145-021-09388-x","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00145-021-09388-x.pdf","source":{"id":"https://openalex.org/S190936789","display_name":"Journal of Cryptology","issn_l":"0933-2790","issn":["0933-2790","1432-1378"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cryptology","raw_type":"journal-article"},{"id":"mag:3037277476","is_oa":false,"landing_page_url":"https://eprint.iacr.org/2020/726.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S2764847869","display_name":"IACR Cryptology ePrint Archive","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":["https://openalex.org/P4322614454"],"host_organization_lineage_names":["Cryptology ePrint Archive"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IACR Cryptology ePrint Archive","raw_type":null}],"best_oa_location":{"id":"doi:10.1007/s00145-021-09388-x","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00145-021-09388-x","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00145-021-09388-x.pdf","source":{"id":"https://openalex.org/S190936789","display_name":"Journal of Cryptology","issn_l":"0933-2790","issn":["0933-2790","1432-1378"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cryptology","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Partnerships for the goals","score":0.4099999964237213,"id":"https://metadata.un.org/sdg/17"}],"awards":[{"id":"https://openalex.org/G2406128221","display_name":"Theoretically-Sound Real-World Cryptography","funder_award_id":"802823","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G4956428346","display_name":null,"funder_award_id":"Horizon 2020 research and innovatio","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G5036817778","display_name":null,"funder_award_id":"European Union's Horizon 2020 research and innov","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8051717526","display_name":null,"funder_award_id":"Grant","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8318064016","display_name":null,"funder_award_id":"Horizon","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8633428685","display_name":null,"funder_award_id":"European Union's Horizon 2020 research and innovat","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"}],"funders":[{"id":"https://openalex.org/F4320313454","display_name":"Bergische Universit\u00e4t Wuppertal","ror":"https://ror.org/00613ak93"},{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3037277476.pdf","grobid_xml":"https://content.openalex.org/works/W3037277476.grobid-xml"},"referenced_works_count":57,"referenced_works":["https://openalex.org/W75729132","https://openalex.org/W1495444061","https://openalex.org/W1506423323","https://openalex.org/W1512498994","https://openalex.org/W1531296821","https://openalex.org/W1532961226","https://openalex.org/W1542059364","https://openalex.org/W1579363911","https://openalex.org/W1589586740","https://openalex.org/W1623551255","https://openalex.org/W1656678770","https://openalex.org/W1975344666","https://openalex.org/W1981449595","https://openalex.org/W1986686371","https://openalex.org/W2013613544","https://openalex.org/W2041428801","https://openalex.org/W2043711803","https://openalex.org/W2052267638","https://openalex.org/W2060474153","https://openalex.org/W2085179296","https://openalex.org/W2092279637","https://openalex.org/W2094250919","https://openalex.org/W2097834299","https://openalex.org/W2107506969","https://openalex.org/W2115148615","https://openalex.org/W2131300413","https://openalex.org/W2149093588","https://openalex.org/W2151413173","https://openalex.org/W2153041122","https://openalex.org/W2156186849","https://openalex.org/W2158276883","https://openalex.org/W2160950619","https://openalex.org/W2164090669","https://openalex.org/W2165549155","https://openalex.org/W2270478131","https://openalex.org/W2293388233","https://openalex.org/W2298971592","https://openalex.org/W2395368405","https://openalex.org/W2409148419","https://openalex.org/W2497610130","https://openalex.org/W2507130841","https://openalex.org/W2538826906","https://openalex.org/W2564949988","https://openalex.org/W2640092413","https://openalex.org/W2725913349","https://openalex.org/W2733667569","https://openalex.org/W2766348345","https://openalex.org/W2795300525","https://openalex.org/W2883305949","https://openalex.org/W2891162082","https://openalex.org/W2891609868","https://openalex.org/W2915352631","https://openalex.org/W2935452154","https://openalex.org/W2968515856","https://openalex.org/W2983439871","https://openalex.org/W3090969679","https://openalex.org/W3164655012"],"related_works":["https://openalex.org/W3168670086","https://openalex.org/W2611187102","https://openalex.org/W2999209598","https://openalex.org/W3202691700","https://openalex.org/W2906415869","https://openalex.org/W2768802245","https://openalex.org/W2568618753","https://openalex.org/W2519091223","https://openalex.org/W2185740852","https://openalex.org/W3152590224","https://openalex.org/W1794766316","https://openalex.org/W2998004243","https://openalex.org/W3006891966","https://openalex.org/W1747618102","https://openalex.org/W2933589166","https://openalex.org/W3118256525","https://openalex.org/W2906994158","https://openalex.org/W2797008633","https://openalex.org/W2167208487","https://openalex.org/W3084879446"],"abstract_inverted_index":{"Abstract":[0],"We":[1],"consider":[2],"the":[3,12,40,51,101,138,145,151,164,177,198,216,222,242,259],"theoretically":[4,67,270],"sound":[5,68,271],"selection":[6,272],"of":[7,14,43,54,103,141,153,167,218,221,224,273],"cryptographic":[8,139],"parameters,":[9],"such":[10,175,196],"as":[11,176,197],"size":[13],"algebraic":[15],"groups":[16],"or":[17],"RSA":[18],"keys,":[19],"for":[20,31,86,122,137,275],"TLS":[21,32,55,63,104,142,154,206,254,264,276],"1.3":[22,64,105,143,155],"in":[23,39,59,65,99,108,126,144,205,215,251,279],"practice.":[24,127],"While":[25],"prior":[26,188],"works":[27,96],"gave":[28],"security":[29,35,120,135,152,161,166],"proofs":[30],"1.3,":[33,207,277],"their":[34],"loss":[36,77,214],"is":[37,56,106,227],"quadratic":[38],"total":[41],"number":[42,217,223],"sessions":[44,286],"across":[45],"all":[46],"users,":[47,219],"which":[48,149,226],"due":[49],"to":[50,61,74,163,190,230],"pervasive":[52],"use":[53,88],"huge.":[57],"Therefore,":[58],"order":[60],"deploy":[62],"a":[66,133,212,246,252,269],"way,":[69],"it":[70],"would":[71,83],"be":[72,84],"necessary":[73],"compensate":[75,231],"this":[76,129],"with":[78,159,232,245,282],"unreasonably":[79],"large":[80,90],"parameters":[81,124,274],"that":[82,98,239],"infeasible":[85],"practical":[87],"at":[89,210],"scale.":[91],"Hence,":[92],"while":[93],"these":[94],"previous":[95],"show":[97],"principle":[100],"design":[102],"secure":[107,248,263],"an":[109],"asymptotic":[110],"sense,":[111],"they":[112],"do":[113],"not":[114],"yet":[115],"provide":[116,132],"any":[117],"useful":[118],"concrete":[119],"guarantees":[121],"real-world":[123],"used":[125,204],"In":[128],"work,":[130],"we":[131,183,208],"new":[134],"proof":[136],"core":[140],"random":[146],"oracle":[147],"model,":[148],"reduces":[150],"tightly":[156,247,262],"(that":[157],"is,":[158],"constant":[160],"loss)":[162],"(multi-user)":[165],"its":[168],"building":[169,173],"blocks.":[170],"For":[171,194],"some":[172],"blocks,":[174],"symmetric":[178],"record":[179],"layer":[180],"encryption":[181],"scheme,":[182],"can":[184,257],"then":[185],"rely":[186],"on":[187],"work":[189,236],"establish":[191],"tight":[192],"security.":[193],"others,":[195],"RSA-PSS":[199,243],"digital":[200],"signature":[201],"scheme":[202,244,249],"currently":[203],"obtain":[209,258],"least":[211],"linear":[213],"independent":[220],"sessions,":[225],"much":[228],"easier":[229],"reasonable":[233],"parameters.":[234],"Our":[235,266],"also":[237],"shows":[238],"by":[240],"replacing":[241],"(e.g.,":[250],"future":[253],"version),":[255],"one":[256],"first":[260],"fully":[261],"protocol.":[265],"results":[267],"enable":[268],"even":[278],"large-scale":[280],"settings":[281],"many":[283],"users":[284],"and":[285],"per":[287],"user.":[288]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1}],"updated_date":"2026-04-13T07:58:08.660418","created_date":"2025-10-10T00:00:00"}
