I completed my PhD at Technische Universität Darmstadt about the security of cordless phones (DECT Phones) in 2011. This included parts from different research areas like radio protocols, reverse engineering, FPGA and micro controller programming, as well as cryptanalysis and designing attacks and countermeasures against cryptographic primitives like stream- and block ciphers, as well as the analysis of the DECT radio protocol.

Previously, I completed my Diploma at Technische Universität Darmstadt. My final thesis was about the security of WEP protected Wireless LAN networks. This included designing an advanced attack against the RC4 stream cipher and implementing it. I also obtained a Bachelor from Technische Universität Darmstadt. My Bachelor Thesis was about implementing a TLS Client Stack for mobile phones.

My main research interests are wireless protocols like DECT, GSM, 3G, WiFi, DVB and many more. I am also very interested in internet infrastructure and in network protocols like SSL/TLS, IPSEC, OTR and everything else, that helps to improve internet security. Besides theoretical research, I also have a strong interest in the applied side of IT security.


  • Henning Bär, Max Mühlhäuser, Erik Tews, Guido Rößling:
    Interaction During Lectures Using Mobile Phones. In: Proceedings of ED-MEDIA 2005. pp. 3767-3772, Association for the Advancement of Computers in Education (AACE), Charlottesville, VA, 2005.

  • Henning Bär, Erik Tews, Guido Rößling:
    Improving Feedback and Classroom Interaction Using Mobile Phones. In: Proceedings of Mobile Learning 2005. pp. 55-62, IADIS Press, 2005.
  • Henning Bär, Guido Rößling, Erik Tews, Elmar Lecher:
    Bluetooth Interaction Support in Lectures. Proceedings of Mobile Learning 2006. pp. 360-364, IADIS Press, 2006. ISBN 972-8924-15-1.
  • Erik Tews:
    Entwicklung von MicroTLS als sichere Ende-zu-Ende-Verbindung über Bluetooth und TCP/IP, Bachelor Thesis, RBG.
  • Erik Tews, Ralf-Philipp Weinmann, Andrei Pyshkin:
    Breaking 104 bit WEP in less than 60 seconds, WISA 2007, LNCS 4867, pp. 188-202, Springer-Verlag (alternative version on the IACR ePrint Archive: Report 2007/120)
  • Michael Hartle, Daniel Schumann, Arsene Botchak, Erik Tews, Max Mühlhäuser:
    Describing Data Format Exploits Using Bitstream Segment Graphs. Proceedings of the Third International Multi-Conference on Computing in the Global Information Technology, Athens, Greece. 2008. (best paper award)
  • Erik Tews:
    Attacks on the WEP protocol, Diplomarbeit. IACR ePrint Archive: Report 2007/471. (Cast Förderpreis Award)
  • Ulrich Kühn, Andrei Pyshkin, Erik Tews, Ralf-Philipp Weinmann:
    Variants of Bleichenbacher’s Low-Exponent Attack on PKCS#1 RSA Signatures, SICHERHEIT 2008, LNI, pp. 97-109, GI-Verlag. (best paper award)
  • Falko Strenzke, Erik Tews, H. Gregor Molter, Raphael Overbeck and Abdulhadi Shoufan:
    Side Channels in the McEliece PKC, PQCrypto 2008LNCS 5299, pp. 216-229, Springer, 2008.
  • Martin Beck, Erik Tews:
    Practical attacks against WEP and WPA, Conference On Wireless Network Security (WISEC) 2009, Proceedings of the second ACM conference on Wireless network security, Pages: 79-86.
  • Stefan Lucks and Andreas Schuler and Erik Tews and Ralf-Philipp Weinmann and Matthias Wenzel: 
    Attacks on the DECT authentication mechanisms
    , CT-RSA 2009.
  • H. Gregor Molter, Kei Ogata, Erik Tews, Ralf-Philipp Weinmann:
    An Efficient FPGA Implementation for an DECT Brute-Force Attacking Scenario, Proceedings of the 2009 Fifth International Conference on Wireless and Mobile Communications, Pages: 82-86, ISBN:978-0-7695-3750-4.
  • Karsten Nohl, Erik Tews, Ralf-Philipp Weinmann: 
    Cryptanalysis of the DECT Standard Cipher
    , Fast Software Encryption 2010 (FSE2010), February 2010.
  • Michael Weiner, Erik Tews, Benedikt Heinz, Johann Heyszl: 
    FPGA Implementation of an Improved Attack Against the DECT Standard Cipher
    , ICISC 2010.
  • Karsten Nohl, Erik Tews:
    Kann man mit DECT noch vertraulich telefonieren? Datenschutz und Datensicherheit (DuD) Heft 11, 2010
  • Patrick McHardy, Andreas Schuler, Erik Tews:
    Interactive decryption of DECT phone calls, WISEC 2011
  • Erik Tews, Julian Wälde, Michael Weiner: Breaking DVB-CSA, WEWORC 2011 (to appear)
  • Erik Tews: DECT Security Analysis (to appear)


Dr. Erik Tews
Security Engineering Group
Computer Science Department
Technische Universität Darmstadt

Visitors: CASED building, Mornewegstrasse 32, 4th floor, room 4.2.21
Postal address: Hochschulstrasse 10, D-64289 Darmstadt
Phone: +49 6151 16 25628 or

