From ray at unipay.nl Wed Jun 10 18:10:07 2026 From: ray at unipay.nl (R. Hirschfeld) Date: Wed, 10 Jun 2026 18:10:07 +0200 Subject: [crypto] Fwd: CWG: June 19th Programme In-Reply-To: References: Message-ID: <42e76e21dbb11d5509331d713b1f5df5@unipay.nl> -------- Original Message -------- Subject: CWG: June 19th Programme Date: 2026-06-10 15:19 From: "Hermus, Patricia" To: Secretariaat DM Dear Crypto Working Group participant, Find below the schedule for our next meeting. We will see you next Friday, June 19th from 10:45 to 15:45, at the Kargadoor, in Utrecht. Best regards, 10:45 Security Analysis of the Family of DME Schemes Pilar Coscojuela Escanilla We propose a systematic approach to analyzing the security of the family of DME cryptosystems, which belong to the area of multivariate cryptography. We focus on the DME scheme proposed to the NIST in 2023 and a minus variation of the scheme, called DME$^-$. As in many attacks on other multivariate cryptosystems, the bottleneck of the attack reduces to solving an instance of the MinRank problem of low rank, arising from the structure of the scheme. We prove that the expected number of solutions of such a MinRank instance is finite. All complexity estimates are derived using existing results about complexity generalized determinantal ideals and therefore rely on the assumption of genericity. Once the set of private keys is simplified -- by specializing some of the variables -- so that, for a given public key, there exists essentially a unique private key, the genericity assumption appears reasonable in light of the experimental results. The results presented in this talk are part of the speaker?s PhD thesis. 11:30 ? Coffee Break 11:45 Fast Codes for Fast Cryptography Nicolas Resch Motivated by the goal of designing highly efficient cryptographic schemes (particularly in the area of secure multiparty computation), we consider the task of designing linear error-correcting codes (or, more precisely, distributions over codes) that are both fast ? that is, encoding can be completed in linear time ? and additionally achieve the Gilbert-Varshamov (GV) bound with high probability. Furthermore, these cryptographic tasks require us to guarantee that the dual code achieves the same properties of fast encodability and distance at the GV bound. In this talk, I will introduce two such constructions. The first is inspired by repeat- multiple-accumulate (RMA) codes, a class of binary turbo codes which admit very fast encoding. Subsequently I will describe another construction based on codes of Druk & Ishai, that allows for generalizing the arbitrary alphabets and rates (the first construction is limited to rate 1/2), among other benefits, albeit at the cost of poorer concrete efficiency. 12:30 ? Lunch : (Lunch not included) 14:00 On the Plaintext Awareness of AEAD Schemes Mario Marhuenda Beltran Plaintext-awareness of AEAD schemes is one of the more obscure and easily misunderstood notions, at a high level, it aims to capture security against leakage of the plaintext during a MAC operation. First, we show that a recent result is flawed, voiding it, yet we show that a weaker version can be re-established. Then we study the plaintext-awareness of more general constructions, like Encrypt-then-MAC and Encode-then-Encipher, showing that the achieve the highest possible degree of security in terms of plaintext-awareness. Finally, we study the interplay of plaintext-awareness with more well-known notions, and we identify and close gap in the literature. 14:45 ? Coffee Break 15:00 Verified hotpatching for real-time embedded systems Roberto Blanco Martinez The security of long-running systems depends, essentially, on the ability to obtain, verify and install updates (to software, to firmware) as new vulnerabilities are discovered and patched. In embedded systems, in particular those in charge of safety-critical systems and with hard real-time constraints, this task is significantly more complex: in general, these systems must continue operating as patches are applied and all task deadlines must be met. In this talk we will discuss novel architectures that take advantage of existing hardware features to meet all these constraints, consider how to specify and verify the security of our design, and touch on the role cryptographic code plays in these processes. 15:45 ? End of activities -------- Kind regards, Met vriendelijke groet Patricia Hermus Management Assistant [cid:image001.png at 01DCF8DD.708A6090] Discrete Mathematics/ Domain Mathematics Program Management Mathematics Department of Mathematics and Computer Science Eindhoven University of Technology E : p.b.hermus at tue.nl Not in the office on Tuesdays and Fridays