[crypto] Fwd: CWG: June 19th Programme

R. Hirschfeld ray at unipay.nl
Wed Jun 10 18:10:07 CEST 2026



-------- Original Message --------
Subject: CWG: June 19th  Programme
Date: 2026-06-10 15:19
 From: "Hermus, Patricia" <p.b.hermus at tue.nl>
To: Secretariaat DM <secdm at tue.nl>

Dear Crypto Working Group participant,

Find below the schedule for our next meeting.
We will see you next Friday,  June 19th from 10:45 to 15:45, at the 
Kargadoor, in Utrecht.

Best regards,



10:45

Security Analysis of the Family of DME Schemes
  Pilar Coscojuela Escanilla

We propose a systematic approach to analyzing the security of the family 
of DME cryptosystems, which belong to the area of multivariate 
cryptography. We focus on the DME scheme proposed to the NIST in 2023 
and a minus variation of the scheme, called DME$^-$. As in many attacks 
on other multivariate cryptosystems, the bottleneck of the attack 
reduces to solving an instance of the MinRank problem of low rank, 
arising from the structure of the scheme. We prove that the expected 
number of solutions of such a MinRank instance is finite. All complexity 
estimates are derived using existing results about complexity 
generalized determinantal ideals and therefore rely on the assumption of 
genericity. Once the set of private keys is simplified -- by 
specializing some of the variables -- so that, for a given public key, 
there exists essentially a unique private key, the genericity assumption 
appears reasonable in light of the experimental results. The results 
presented in this talk are part of the speaker’s PhD thesis.

11:30 – Coffee Break

11:45

Fast Codes for Fast Cryptography
Nicolas Resch

Motivated by the goal of designing highly efficient cryptographic 
schemes (particularly in the area of secure multiparty computation), we 
consider the task of
designing linear error-correcting codes (or, more precisely, 
distributions over codes) that are both fast — that is, encoding can be 
completed in linear time — and additionally achieve the 
Gilbert-Varshamov (GV) bound with high probability. Furthermore, these 
cryptographic tasks require us to guarantee that the dual code achieves 
the same properties of fast encodability and distance at the GV bound.

In this talk, I will introduce two such constructions. The first is 
inspired by repeat- multiple-accumulate (RMA) codes, a class of binary 
turbo codes which admit very
fast encoding. Subsequently I will describe another construction based 
on codes of Druk & Ishai, that allows for generalizing the arbitrary 
alphabets and rates (the first construction is limited to rate 1/2), 
among other benefits, albeit at the cost of poorer concrete efficiency.



12:30 – Lunch : (Lunch not included)


14:00

On the Plaintext Awareness of AEAD Schemes
Mario Marhuenda Beltran

Plaintext-awareness of AEAD schemes is one of the more obscure and 
easily misunderstood notions, at a high level, it aims to capture 
security against leakage of the plaintext during a MAC operation.
First, we show that a recent result is flawed, voiding it, yet we show 
that a weaker version can be re-established.
Then we study the plaintext-awareness of more general constructions, 
like Encrypt-then-MAC and Encode-then-Encipher, showing that the achieve 
the highest possible degree of security in terms of plaintext-awareness.
Finally, we study the interplay of plaintext-awareness with more 
well-known notions, and we identify and close gap in the literature.


14:45 – Coffee Break

15:00

Verified hotpatching for real-time embedded systems
Roberto Blanco Martinez

The security of long-running systems depends, essentially, on the 
ability to obtain, verify and install updates (to software, to firmware) 
as new vulnerabilities are discovered and patched. In embedded systems, 
in particular those in charge of safety-critical systems and with hard 
real-time constraints, this task is significantly more complex: in 
general, these systems must continue operating as patches are applied 
and all task deadlines must be met. In this talk we will discuss novel 
architectures that take advantage of existing hardware features to meet 
all these constraints, consider how to specify and verify the security 
of our design, and touch on the role cryptographic code plays in these 
processes.



15:45 – End of activities

--------


Kind regards, Met vriendelijke groet
Patricia Hermus
Management Assistant

[cid:image001.png at 01DCF8DD.708A6090]
Discrete Mathematics/ Domain Mathematics
Program Management Mathematics
Department of Mathematics and Computer Science
Eindhoven University of Technology

E : p.b.hermus at tue.nl

Not in the office on Tuesdays and Fridays


More information about the crypto mailing list