[crypto] Fwd: Next CWG: September 25th Programme
R. Hirschfeld
ray at unipay.nl
Mon Sep 21 21:32:27 CEST 2026
-------- Original Message --------
Subject: Next CWG: September 25th Programme
Date: 2026-09-21 18:22
From: Secretariaat DM <secdm at tue.nl>
To: "Hermus, Patricia" <p.b.hermus at tue.nl>
Dear Crypto Working Group participant,
Please find below the agenda for our next meeting.
We look forward to seeing you on Friday, September 25th, from 10:45 to
15:45 at Kargadoor, Utrecht.
Our apologies for the delay in sending this invitation and agenda.
Best regards,
10:45
“The ABC of Symmetric Primitives over Integer Rings”
Berenika Richterová
Designing a secure symmetric-key cipher over a vector space over a field
F_{p^n} is well known and understood by the cryptographic community.
Even if the attacks are continuously improving, our current
understanding regarding the design and security of the majority of the
symmetric-key primitives has not fundamentally changed in the last 20
years.
How does this picture change when we move to an integer ring Z_{p^n}?
Although easy to state, the question is considerably harder to answer.
In this talk, we show how existing statistical and algebraic attacks
behave for these ciphers and present new attacks that take into account
that not all functions over integer rings admit a polynomial
representation. Based on this, we discuss possible design strategies,
focusing on the security of the ciphers
11:30 – Coffee Break
11:45
“MIKE, an isogney-based NIKE”
Krijn Reijnders
We present MIKE, a post-quantum non-interactive key exchange (NIKE) with
public keys of 80 bytes and a key agreement in 7.5 milliseconds in
constant time. MIKE is therefore significantly faster and more practical
than any other post-quantum NIKE, but also significantly more complex:
at its core, it relies on a monoidal action of Hermition modules on
superspecial principally polarized abelian varieties. However, stripping
away layers of (beautiful) mathematics, we find at its core a somewhat
digestible and comprehensible scheme. In this talk, we present MIKE in
the reverse order, starting from the very simple core idea, and building
up the necessary complexity that we need to understand MIKE at different
levels.
12:30 – Lunch : (Lunch not included)
14:00
“On the Common Bias of Majorities: Poly-Time Attacks on Low-Weight PRGs”
Akin Ünal
Pseudorandom Generators (PRGs) based on Threshold-XOR predicates with
large locality and high stretches have recently gained traction,
since they lend themselves as shallow weak Pseudorandom Functions (PRFs)
to fast multiparty computation protocols.
In this talk, I will present fast attacks on such PRGs that achieve
substantial advantages over the previous attacks of Fu, Li, Lyu and Liu
(EC'26).
Concretely, they break the security levels of most parameters collected
by Boura, Couteau, Perrin and Rotella (ToSC'25),
as well as those proposed by Fu, Li, Lyu and Liu (EC'26).
On the asymptotic side, we get poly-time attacks with noticeable
advantage for Threshold predicates of linear sizes.
14:45 – Coffee Break
15:00
“Formal Verification of Assembly Implementations of Cryptographic
Functions via Decompilation.”
Tom Béné
Implementations of cryptographic primitives need to be both
unquestionably secure and highly performant. The second requirement
often leads library writers to craft hand-optimized assembly code, which
significantly complicates the use of formal methods to satisfy the first
requirement.
We propose that decompilation techniques can be used to lift
cryptographic code written in assembly to Jasmin, a language designed
for high-assurance cryptography, and machine-checked for conformance
against verified reference implementations, potentially offering
comparable guarantees, and evaluate the viability of our approach with
case studies drawn from mainstream cryptographic libraries.
15:45 – End of activities
You're receiving this email because some time ago you requested to
receive information about the CWG. We are now moving to a TU/e hosted
mailing list, and you will receive a notice that you're added to the CWG
mailing list. You can then manage your subscription yourself. Note that
the membership list is not available to list members and that posting to
this mailing list will be restricted to the mailing list operators,
Andreas, Tanja, and me.
Kind regards, Met vriendelijke groet
Patricia Hermus
Management Assistant
[cid:image001.png at 01DD442E.58017DA0]
Discrete Mathematics/ Domain Mathematics
Program Management Mathematics
Department of Mathematics and Computer Science
Eindhoven University of Technology
Metaforum, Groene Loper Building 5, Room MF 5.120
E : p.b.hermus at tue.nl<mailto:p.b.hermus at tue.nl>
T : + 31- (0)40 247 2549
Not in the office on Tuesdays and Fridays
More information about the crypto
mailing list