[crypto] Fwd: Next CWG: September 25th Programme

R. Hirschfeld ray at unipay.nl
Mon Sep 21 21:32:27 CEST 2026



-------- Original Message --------
Subject: Next CWG: September  25th  Programme
Date: 2026-09-21 18:22
 From: Secretariaat DM <secdm at tue.nl>
To: "Hermus, Patricia" <p.b.hermus at tue.nl>

Dear Crypto Working Group participant,

Please find below the agenda for our next meeting.
We look forward to seeing you on Friday, September 25th, from 10:45 to 
15:45 at Kargadoor, Utrecht.
Our apologies for the delay in sending this invitation and agenda.

Best regards,



10:45

“The ABC of Symmetric Primitives over Integer Rings”
    Berenika Richterová

Designing a secure symmetric-key cipher over a vector space over a field 
F_{p^n} is well known and understood by the cryptographic community. 
Even if the attacks are continuously improving, our current 
understanding regarding the design and security of the majority of the 
symmetric-key primitives has not fundamentally changed in the last 20 
years.

How does this picture change when we move to an integer ring Z_{p^n}? 
Although easy to state, the question is considerably harder to answer. 
In this talk, we show how existing statistical and algebraic attacks 
behave for these ciphers and present new attacks that take into account 
that not all functions over integer rings admit a polynomial 
representation. Based on this, we discuss possible design strategies, 
focusing on the security of the ciphers


11:30 – Coffee Break

11:45

“MIKE, an isogney-based NIKE”
   Krijn Reijnders

We present MIKE, a post-quantum non-interactive key exchange (NIKE) with 
public keys of 80 bytes and a key agreement in 7.5 milliseconds in 
constant time. MIKE is therefore significantly faster and more practical 
than any other post-quantum NIKE, but also significantly more complex: 
at its core, it relies on a monoidal action of Hermition modules on 
superspecial principally polarized abelian varieties. However, stripping 
away layers of (beautiful) mathematics, we find at its core a somewhat 
digestible and comprehensible scheme. In this talk, we present MIKE in 
the reverse order, starting from the very simple core idea, and building 
up the necessary complexity that we need to understand MIKE at different 
levels.


12:30 – Lunch : (Lunch not included)


14:00

“On the Common Bias of Majorities: Poly-Time Attacks on Low-Weight PRGs”
   Akin Ünal


Pseudorandom Generators (PRGs) based on Threshold-XOR predicates with 
large locality and high stretches have recently gained traction,
since they lend themselves as shallow weak Pseudorandom Functions (PRFs) 
to fast multiparty computation protocols.
In this talk, I will present fast attacks on such PRGs that achieve 
substantial advantages over the previous attacks of Fu, Li, Lyu and Liu 
(EC'26).
Concretely, they break the security levels of most parameters collected 
by Boura, Couteau, Perrin and Rotella (ToSC'25),
as well as those proposed by Fu, Li, Lyu and Liu (EC'26).
On the asymptotic side, we get poly-time attacks with noticeable 
advantage for Threshold predicates of linear sizes.

14:45 – Coffee Break

15:00

“Formal Verification of Assembly Implementations of Cryptographic 
Functions via Decompilation.”
Tom Béné

Implementations of cryptographic primitives need to be both 
unquestionably secure and highly performant. The second requirement 
often leads library writers to craft hand-optimized assembly code, which 
significantly complicates the use of formal methods to satisfy the first 
requirement.
We propose that decompilation techniques can be used to lift 
cryptographic code written in assembly to Jasmin, a language designed 
for high-assurance cryptography, and machine-checked for conformance 
against verified reference implementations, potentially offering 
comparable guarantees, and evaluate the viability of our approach with 
case studies drawn from mainstream cryptographic libraries.


15:45 – End of activities



You're receiving this email because some time ago you requested to 
receive information about the CWG. We are now moving to a TU/e hosted 
mailing list, and you will receive a notice that you're added to the CWG 
mailing list. You can then manage your subscription yourself. Note that 
the membership list is not available to list members and that posting to 
this mailing list will be restricted to the mailing list operators, 
Andreas, Tanja, and me.



Kind regards, Met vriendelijke groet
Patricia Hermus
Management Assistant

[cid:image001.png at 01DD442E.58017DA0]
Discrete Mathematics/ Domain Mathematics
Program Management Mathematics
Department of Mathematics and Computer Science
Eindhoven University of Technology

Metaforum, Groene Loper Building 5, Room MF 5.120
E : p.b.hermus at tue.nl<mailto:p.b.hermus at tue.nl>
T : + 31- (0)40 247 2549

Not in the office on Tuesdays and Fridays


More information about the crypto mailing list