Ruben Baecker
Ruben Baecker

Hey, I'm Ruben!Ruben Baecker

I'm a PhD student in applied cryptography at Friedrich-Alexander-Universität Erlangen-Nürnberg, in Germany, supervised by Dominique Schröder. You can reach me at mail [at] ruben-baecker.de, find me on Google Scholar and DBLP, or download my CV as a PDF.

If you're reviewing an application of mine, feel free to switch to "formal" mode in the top right corner ;)

PhD student
Chair of Applied Cryptography
Friedrich-Alexander-Universität Erlangen-Nürnberg
Germany
mail [at] ruben-baecker.de
Google Scholar · DBLP · CV (PDF)

Research

I build cryptographic protocols that distribute trust. No single party holds the key, and no single corruption breaks the system. A second line of work builds cryptography from secrets as weak as a password.

Threshold cryptography

In threshold cryptography, a key is protected by requiring t parties to collaborate, but securing protocols against adaptive corruptions, where the attacker picks targets while watching the protocol run, often demands heavy assumptions. My research builds adaptively secure protocols under reduced assumptions, including Threshold Schnorr Signatures [BGLRSY26], Distributed Key Generation [BGJNRS26], and Oblivious PRFs [BGRS25].

Password-based cryptography

In password-based cryptography, systems are secured despite predictable, human-generated secrets. The core challenge is preventing offline cracking by forcing attackers into rate-limited online guessing. My papers identify gaps in prior works and propose stronger security models and protocols to close them [BGS25][ABGGKRS25].

Three of my papers are proved within the Universal Composability framework [ABGGKRS25][BGRS25][BGJNRS26], and three are proved using Game-based definitions [BGS25][BGLRSY26][BGKS26].

How I came to crypto Back to the short version

How I came to crypto

I've been fascinated by cryptography since I was a kid, drawing up my own ciphers in elementary school and hiding secret alphabets in empty pen cartridges. My first real Java program was an encryption scheme built on multi-alphabet substitution. As a high school student, I attended two seminars at Fraunhofer, one on cryptography and one on embedded hardware. After the second, we started to design a custom encryption machine in hardware, but unfortunately never finished.

Then I read a book on cryptography and concluded the field was finished. We had symmetric encryption, public key encryption and signatures, so what else could there be? Turns out: a lot. Once I started studying computer science I took every crypto lecture I could find, and I haven't really stopped since.

Research

I design cryptographic protocols that distribute trust. No single party holds the key, and no single corruption breaks the system. A second line of work builds cryptography from low-entropy secrets, in practice passwords.

Threshold cryptography

In threshold cryptography, a key is protected by requiring t parties to collaborate, but securing protocols against adaptive corruptions, where the attacker picks targets while watching the protocol run, often demands heavy assumptions. My research constructs adaptively secure protocols under reduced assumptions, including Threshold Schnorr Signatures [BGLRSY26], Distributed Key Generation [BGJNRS26], and Oblivious PRFs [BGRS25].

Password-based cryptography

In password-based cryptography, systems remain secure despite low-entropy, human-chosen secrets. The central challenge is preventing offline cracking by forcing an adversary into rate-limited online guessing. My papers identify gaps in prior works and propose stronger security models and protocols to close them [BGS25][ABGGKRS25].

Three of my papers are proved within the Universal Composability framework [ABGGKRS25][BGRS25][BGJNRS26], and three are proved using Game-based definitions [BGS25][BGLRSY26][BGKS26].

Recent Publications

Ruben Baecker, Paul Gerhart, Davide Li Calsi, Luigi Russo, Dominique Schröder, and Arkady Yerukhimovich
ASIACRYPT 2026
Abstract
We present FaFROST+, the first two-round Schnorr threshold signature scheme achieving full adaptive security under the Algebraic One-More Discrete Logarithm (AOMDL) assumption with identifiable aborts. Building on the FROST framework, FaFROST+ preserves its communication efficiency while dispensing with the LDVR assumption introduced at CRYPTO'25. Our result demonstrates that round-optimal adaptive security, practical efficiency, and identifiable aborts are simultaneously achievable under the well-studied AOMDL assumption.
Threshold Schnorr signatures are a hot topic right now, especially since NIST is working on standardizing them. FaFROST+ is the first two-round scheme with identifiable aborts that is adaptivly secure under the Algebraic One-More Discrete Log assumption alone. We keep FROST’s communication efficiency and don’t need the LDVR assumption introduced at CRYPTO’25.
Ruben Baecker, Paul Gerhart, Jonathan Katz, and Dominique Schröder
ASIACRYPT 2026
Abstract

Adaptor signatures enable scriptless protocols on blockchains such as Bitcoin by allowing a buyer to lock a coin based on an NP statement and release payment to any party that reveals the corresponding witness. They underlie a broad class of layer-2 protocols, including payment channels, cross-chain swaps, and coin-mixing services, which today secure billions of dollars in locked value. Fairness for existing adaptor-signature constructions, however, is inherently two-party, so does not apply to deployments in which the buyer or witness holder is operated by a committee.

In this work, we formalize and solve the fair exchange problem in that setting. We consider a buyer group holding shares of a signing key controlling a coin, and a seller group holding shares of a secret witness. The goal is to guarantee fairness both between groups (ensuring that each group obtains its asset if and only if the other does), as well as within groups (ensuring that all honest buyers learn the witness and all honest sellers receive payment), even in the presence of malicious insiders and/or partial information leakage.

We present efficient protocols achieving these guarantees under standard cryptographic assumptions on scriptless blockchains with timelocks. Our construction introduces two new primitives of independent interest, threshold adaptor signatures and certified witness encryption, which we define, analyze, and instantiate efficiently.

We study how two groups can trade fairly without smart contracts, using just cryptography and minimal blockchain assumptions. Our protocol ensures fairness both between the groups and among members within each group. Along the way, we introduce two new cryptographic primitives: certified witness encryption and threshold adaptor signatures.
Ruben Baecker, Paul Gerhart, and Dominique Schröder
ASIACRYPT 2025
Abstract

Passwords remain the dominant form of authentication on the Internet. The rise of single sign-on (SSO) services has centralized password storage, increasing the devastating impact of potential attacks and underscoring the need for secure storage mechanisms. A decade ago, Facebook introduced a novel approach to password security, later formalized in Pythia by Everspaugh et al. (USENIX'15), which proposed the concept of password hardening. The primary motivation behind these advances is to achieve provable security against offline brute-force attacks. This work initiated significant follow-on research (CCS'16, USENIX'17), including Password-Hardened Encryption (PHE) (USENIX'18, CCS'20), which was introduced shortly thereafter. Virgil Security commercializes PHE as a software-as-a-service solution and integrates it into its messenger platform to enhance security.

In this paper, we revisit PHE and provide both negative and positive contributions. First, we identify a critical weakness in the original design and present a practical cryptographic attack that enables offline brute-force attacks – the very threat PHE was designed to mitigate. This weakness stems from a flawed security model that fails to account for real-world attack scenarios and the interaction of security properties with key rotation, a mechanism designed to enhance security by periodically updating keys. Our analysis shows how the independent treatment of security properties in the original model leaves PHE vulnerable. We demonstrate the feasibility of the attack by extracting passwords in seconds that were secured by the commercialized but open-source PHE provided by Virgil Security.

On the positive side, we propose a novel, highly efficient construction that addresses these shortcomings, resulting in the first practical PHE scheme that achieves security in a realistic setting. We introduce a refined security model that accurately captures the challenges of practical deployments, and prove that our construction meets these requirements. Finally, we provide a comprehensive evaluation of the proposed scheme, demonstrating its robustness and performance.

Password-Hardened Encryption (PHE) was designed to protect passwords even if servers are compromised, and its SimplePHE variant is used in a commercial product. We show a critical flaw in its original security definition and demonstrate a resulting attack using alternating corruption patterns. To address this, we present a new, efficient PHE scheme with a stronger security model, prove its security, and show it even outperforms existing schemes.
Show all papers Show fewer
Behzad Abdolmaleki, Ruben Baecker, Paul Gerhart, Mike Graf, Mojtaba Khalili, Daniel Rausch, and Dominique Schröder
ASIACRYPT 2025
Abstract

Password-Hardened Encryption (PHE) protects against offline brute-force attacks by involving an external ratelimiter that enforces rate-limited decryption without learning passwords or keys. Threshold Password-Hardened Encryption (TPHE), introduced by Brost et al. (CCS’20), distributes this trust among multiple ratelimiters. Despite its promise, the security foundations of TPHE remain unclear. We make three contributions:

  1. We uncover a flaw in the proof of Brost et al.’s TPHE scheme, which invalidates its claimed security and leaves the guarantees of existing constructions uncertain;
  2. We provide the first universal composability (UC) formalization of PHE and TPHE, unifying previous fragmented models and supporting key rotation, an essential feature for long-term security and related primitives such as updatable encryption;
  3. We present the first provably secure TPHE scheme, which is both round-optimal and UC-secure, thus composable in real-world settings; and we implement and evaluate our protocol, demonstrating practical efficiency that outperforms prior work in realistic WAN scenarios.
We propose the first UC model for Threshold Password-Hardened Encryption (TPHE), unifying and strengthening its security definitions. Along the way, we found a flaw in the security proof of the original TPHE scheme. Finally, we design the first provably secure, round-optimal TPHE scheme. The proof was a pain, and I’m happy it’s finally done.
Ruben Baecker, Paul Gerhart, Daniel Rausch, and Dominique Schröder
CRYPTO 2025
Abstract

Oblivious Pseudorandom Functions (OPRFs) are fundamental cryptographic primitives essential for privacy-enhancing technologies such as private set intersection, oblivious keyword search, and password-based authentication protocols. We present the first fully adaptive, partially oblivious threshold pseudorandom function that supports proactive key refresh and provides composable security under the One-More Gap Diffie-Hellman assumption in the random oracle model.

Our construction is secure with respect to a new ideal functionality for OPRFs that addresses three critical shortcomings of previous models–specifically, key refresh and non-verifiability issues that rendered them unrealizable. In addition, we identify a gap in a prior work’s proof of partial obliviousness and develop a novel proof technique to salvage their scheme.

We introduce the first threshold partially-oblivious pseudorandom function with proactive key refresh, fully-adaptive security, and a proof in the UC framework. Our new model closes gaps in earlier definitions, and we develop a proof technique that repairs a gap in prior work.

Preprints

Ruben Baecker, Paul Gerhart, Stanislaw Jarecki, Phillip Nazarian, Daniel Rausch, and Dominique Schröder
eprint.iacr.org
Abstract

Threshold signatures are widely deployed in decentralized asset custody and blockchain infrastructure to eliminate single points of failure. In these systems, an attacker can adaptively corrupt committee members based on public membership and protocol transcripts. Recent cryptanalysis shows this threat is concrete: schemes exposing per-party key commitments enable practical forgeries for committees of roughly 200 signers at the cost of just one minute of the global Bitcoin hashrate.

While a new generation of signing schemes defeats this attack by hiding individual key shares, every distributed key generation (DKG) protocol used in practice exposes this information, voiding the adaptive security of any scheme built on top. Trusted dealers avoid the leakage but reintroduce the single point of failure that threshold cryptography exists to eliminate. True adaptive security must therefore span both key generation and signing.

We present Janus, the first DKG suite to achieve this end-to-end guarantee. Janus serves as a drop-in replacement for a trusted dealer in threshold schemes, hiding all key shares while outputting a standard DLog public key compatible with existing verifiers, wallets, and smart contracts. Assuming secure erasures, we prove security against an adaptive adversary that corrupts members mid-protocol and controls a dishonest majority. We also show that Janus directly supports a variety of DLog-based primitives, including threshold Schnorr signatures and oblivious pseudorandom functions. Our suite includes Janus2R, which achieves an unbiased key in two rounds, and Janus1R, which completes within a single round by tolerating an additive key shift. When a node misbehaves, both variants generate a 259-byte universally verifiable proof for automated on-chain slashing, and both naturally allow committees to proactively refresh their shares without changing the public key. Our open-source Rust implementation completes key generation for a 16-node intercontinental committee in 310 ms and scales to 512 nodes.

Crites and Stewart recently discovered an attack against Threshold Schnorr Signature schemes that commit to key shares as pk_i = g^sk_i. While there are Threshold Schnorr Signature schemes that prevents this attack, they all rely on a trusted setup. We propose a family of DKGs that explicitly never leak these kind of commitments to allow for a decentralized setup of these threshold signature schemes. Our DKGs are practically efficient, provide identifiable aborts, and achieve security under the standard CDH assumption against a dishonest majority. One variant terminates in just a single round in the optimistic case.