Send email Copy Email Address
2026-07-28
Annabelle Theobald

Test-of-Time Award for CISPA-Faculty Cas Cremers and Colleagues from ETH Zurich

Fourteen years after publishing Automated Analysis of Diffie-Hellman Protocols and Advanced Security Properties, CISPA-Faculty Prof. Cas Cremers, Prof. David Basin, Dr. Benedikt Schmidt, and Dr. Simon Meier have received a Test-of-Time Award at the 2026 IEEE Computer Security Foundations Symposium (CSF). The award recognizes the lasting scientific impact of their paper, which laid the foundation for advances in automated tools for the formal verification of cryptographic protocols through its novel approach to automated security analysis.

Since 2023, the CSF Test-of-Time Award has recognized papers of “enduring significance and outstanding impact,” making it one of the conference’s highest honors. But what exactly is the scientific contribution of the award-winning work?

At the heart of the paper are modern key exchange protocols based on the Diffie-Hellman principle. Originally developed in the 1970s, the Diffie-Hellman method enables two parties to establish a shared secret key over an insecure network without transmitting the key itself. Over the following decades, increasingly sophisticated cryptographic protocols were built upon this principle to provide stronger security guarantees. However, the underlying algebraic properties of Diffie-Hellman made the automated security analysis of such protocols particularly challenging because existing analysis tools could not fully capture these properties.

This gap was addressed by current CISPA-Faculty Cas Cremers, who was a postdoc at the time, together with Prof. David Basin and their then doctoral students Dr. Benedikt Schmidt and Dr. Simon Meier. Together, they developed a general formal framework that enables both cryptographic protocols and their security properties to be described mathematically.  Building on this framework, they designed a novel analysis algorithm that systematically explores all possible protocol executions. The algorithm can automatically prove that a protocol satisfies the desired security properties or produce a proof that these properties can be violated, corresponding to a successful attack on the protocol. The researchers implemented their novel analysis algorithm in the Tamarin Prover. The paper describes the core algorithm that laid the foundation for much of the tool's subsequent development.

Why Is the Paper Still Relevant Today?

The researchers demonstrated the effectiveness of their approach through a series of demanding case studies, including the then state-of-the-art NAXOS protocol. Their work showed that even highly sophisticated cryptographic protocols could be analyzed automatically for security.

Since its publication, the methods introduced in the paper have influenced numerous subsequent research efforts in formal security analysis. The Tamarin Prover itself has also evolved considerably: over the years, its scope has been extended significantly beyond the original class of protocols considered in the paper. Today, it is regarded as one of the world’s leading tools for modeling and analyzing cryptographic protocols.

Most recently, David Basin, Cas Cremers, Dr. Ralf Sasse, and Dr. Jannik Dreier received the prestigious Levchin Prize at the Real-World Cryptography Conference in recognition of their contributions to the development of the Tamarin Prover.

The security protocols that Tamarin can analyze continue to form the foundation of applications such as online banking, secure web communication, messaging services, and many other security-critical systems.

About the Authors

Professor Cas Cremers has been CISPA-Faculty since 2018. He received his Ph.D. from Eindhoven University of Technology in 2006. From 2006 to 2013, he served as a postdoctoral researcher, senior researcher, and lecturer in David Basin’s group at ETH Zurich. He subsequently joined the University of Oxford as an Associate Professor before being appointed Professor of Information Security there in 2015. His research focuses on information security, the analysis of cryptographic protocols, and the development of formal verification tools with both theoretical and practical impact.

Professor David Basin has been a Full Professor at ETH Zurich since 2003, conducting research within the Institute of Information Security at D-INFK. He holds a PhD from Cornell University and worked at the University of Edinburgh, the Max Planck Institute for Informatics and the University of Freiburg before joining ETH Zurich. Professor Basin’s research focuses on methods and tools for building secure and reliable information systems. He is Editor-in-Chief of Springer-Verlag’s book series on Information Security and Cryptography and, from 2015 to 2020, of ACM Transactions on Privacy and Security. He was also the founding director of the Zurich Information Security Center (ZISC) and is a Fellow of both the ACM and IEEE.

Dr Benedikt Schmidt is a Software Engineer at Snowflake. He received his doctorate from ETH Zurich in 2012 under the supervision of Professor David Basin. After that, he was a postdoctoral researcher at the IMDEA Software Institute in Madrid before joining Google. Schmidt’s research focuses on the formal verification of cryptographic primitives and protocols, as well as the automated analysis of security protocols. He has contributed to verification tools including Tamarin and EasyCrypt and is a main developer of the Jasmin compiler, AutoG&P and the Generic Group Analyzer for high-assurance cryptographic software and proofs.

Dr Simon Meier is a Distinguished Software Engineer at Digital Asset, where he leads the development of a purely functional smart contract language and its associated tooling. He earned his doctorate in Computer Science at ETH Zurich in 2012, where he was part of the Information Security Group under David Basin. During his doctoral studies, he co-developed the Tamarin security protocol verifier and worked on machine-checked protocol verification in Isabelle/HOL. Meier’s research focuses on formal methods for security, in particular automated and machine-assisted verification of cryptographic protocols and systems, as well as functional programming for high-assurance software.