Description
At the dawn of the quantum computing era, the security of digital communications is entering a new phase.Post-quantum cryptography is now essential to protect our data and ensure its authenticity through electronic
signatures, the foundation of digital trust.
For this 4th edition, institutional, industrial and academic experts will come together to share insights, feedback and the latest advances in the deployment of post-quantum solutions, particularly for large-scale communication infrastructures and
electronic signature systems.
Agenda includes :
- Institutional talks addressing strategic, regulatory and digital sovereignty challenges.
- Industry feedback on the integration of post-quantum cryptography and electronic signature solutions.
- Presentations of ongoing research and development, especially on new signature schemes, their performance and their large-scale deployment.
Steering committee
- Marie-Thérèse André, DGA MI
- Philippe Chartier, Inria - IRMAR
- Karine Chatel, Université de Rennes - CREACH LABS
- Pierre-Alain Fouque, Université de Rennes - IRISA
- Gabriel Gallin, DGA MI
- Benoît Gérard, ANSSI
- Aurore Guillevic, INRIA - IRISA
- Reynald Lercier, DGA MI - IRMAR (chair)
- Antonin Leroux, DGA MI - IRMAR
- Guénaël Renault, ANSSI
Practical infos
Program for Wednesday, November 18
-
09:00 - 09:15
Introduction
Speaker : Pantxoa Amorena, Head of the Cyber Division, DGA
-
09:15 - 10:00
ANSSI PQC transition roadmap and product certification strategy
Speaker : Samih Souissi and Nicolas Gurel, ANSSI
Abstract : In the second part, Nicolas Gurel will present feedback and advances in ANSSI's post-quantum cryptography product certification. Following up on the presentation delivered in 2024 regarding ANSSI policies on the certification of products using post-quantum cryptography and the ITSEF licensing process, he will cover:
- the required capabilities of ITSEFs;
- ITSEFs licensed or in the licensing process;
- the products certified to date;
- initial technical feedback from these evaluations, with a focus on key considerations identified in the Common Criteria (CC) and First-Level Security Certification (CSPN) schemes. -
10:00 - 10:30
PQC developments at DGA
Speaker : Clément Gomez, DGA
Abstract to be announced.
-
10:30 - 11:00
Coffe break
-
11:00 - 12:00
Status report on the additional signature schemes initiative
Speaker : Pierre Ciadoux, Former NIST associate
Abstract to be announced.
-
12:00 - 13:30
Lunch
-
13:30 - 14:10
Title to be confirmed
Speaker : Antonin Leroux, DGA MI - IRMAR
Abstract to be announced.
-
14:10 - 14:50
Technical elements on signature hybridization
Speaker : Maxime Roméas, cryptography laboratory, ANSSI
Abstract to be announced.
-
14:50 - 15:30
Verification Mythology: Why High-Assurance Cryptography Is Just Engineering
Speaker : Nadim Kobeissi, Symbolic Software
Abstract : High-assurance cryptography has a mythology problem. The field presents itself as an arcane discipline where wizard-scholars produce machine-checked proofs that place code beyond reproach. The reality is more prosaic: it is software engineering with a proof step, and the proof step has the same failure modes as every other step — copy-paste errors, dead code, untested configurations, and documentation that drifts from reality. This talk presents concrete evidence from two systematic studies of verified cryptographic libraries including post-quantum cryptographic libraries, extending to structural observations across the broader high-assurance ecosystem, to argue that demystifying formal verification is a prerequisite for making it actually work.
-
15:30 - 16:00
Coffee break
-
16:00 - 16:30
Cryptanalysis of the signature scheme Hawk
Speaker : Alice Pellet-Mary, CNRS, Univ. Bordeaux
Abstract : In this talk, I will present the recent attacks on the signature scheme Hawk, that have led to its withdrawal from the NIST competition. We will first review the main ideas of the attacks. We will then mention their impact on Hawk, and discuss the most promising way to avoid them in future constructions based on module-LIP. We will conclude the talk with a discussion about what these attacks say about the hardness of other module lattice problems (spoiler: they have no impact on "short vector"-type problems such as NTRU or module-LWE).
-
16:30 - 17:00
Integration issues of post-quantum algorithms in communication protocols
Speaker : Thomas Pornin, NCC Group
Abstract : Post-quantum key exchange and signature schemes are meant to replace pre-quantum schemes such as RSA and ECDSA in existing communication protocols and data formats. However, they have somewhat different characteristics, in terms of size (larger keys, ciphertexts and signatures), speed, RAM usage, code size, protection from side-channel attacks, and API requirements such as data streaming and multi-signatures. In this talk, we discuss these issues especially in the case of the Falcon (FN-DSA) and Dilithium (ML-DSA) signature schemes, both for large systems (laptops, servers) and small embedded systems (microcontrollers). We will also investigate how implementers in the industry are starting to tackle these issues.
-
17:00 - 17:30
Presentation of the NYMPHEAS upstream study
Speaker : Kirsten Wilke, Secure-IC
Abstract : NYMPHEAS is an upstream study conducted jointly by DGA MI, Secure-IC, and SERMA. It focuses on post-quantum digital signature algorithms, that is algorithms resistant to cryptanalysis by a quantum computer. Specifically, it aims to provide a comparative overview of the strengths and weaknesses of so-called "alternative" algorithms, which rely on security foundations radically different from those of already standardized, lattice-based algorithms.
In this first part, Secure-IC will present the state of the art for the Dilithium, SDitH, UOV, FAEST, and HuFu algorithms. In particular, a software implementation was developed independently of the reference implementation, and its characteristics will be presented.
-
17:30 - 18:00
Evaluation of NYMPHEAS signature scheme implementations
Speaker : Stéphane Horte, SERMA
Abstract : The second part of the presentation on the NYMPHEAS project will focus on the two most promising digital signature algorithms, namely Dilithium and FAEST. Secure-IC will explain how they were ported to a FPGA prototyping board, a task that required an algorithm-architecture co-design analysis. To protect these implementations against attacks exploiting information leakage (timing, power consumption, or electromagnetic emissions), Secure-IC integrated countermeasures while optimizing performance.
Side-channel attacks carried out by SERMA make it possible to measure leakages from implementations without countermeasures, in order to quantify the gain in protection provided by enabling them.
Program for Thursday, November 19
-
09:00 - 09:30
Poster session part 1 : Early-Career Researchers in Post-Quantum Cryptography
Poster introductions by the presenters
-
09:30 - 10:30
Poster session part 2 : Discussions around the posters
A time dedicated to discussions around the posters.
-
10:30 - 11:00
Coffee break
-
11:00 - 11:40
Practical Experiences in PQC Migration
Speaker : Bor de Kock, TNO
Abstract : As awareness of the quantum threat to cryptography continues to grow, many organizations are seeking practical guidance on how to begin their migration to post-quantum cryptography (PQC). In our PQC working group, seven organizations from different sectors collaborate to gain hands-on experience and learn from one another's challenges and successes.
In this talk, we share the lessons learned from a series of real-world experiments and proof-of-concepts aimed at understanding the cryptographic landscape of organizations. We discuss different approaches to building a cryptographic inventory, including engaging with vendors, leveraging certificate issuance logs, and evaluating the effectiveness of existing scanning tools.
Beyond the technical aspects, we reflect on the trade-offs between the effort required and the value gained from different inventory objectives, such as identifying vulnerable cryptography, assessing migration risks, and prioritizing remediation activities. Finally, we discuss the benefits of tackling these challenges collaboratively. While reinventing the wheel can be wasteful, practical experimentation remains essential and sharing those experiences can accelerate PQC migration for everyone.
-
11:45 - 12:00
Best poster award
-
12:00 - 13:30
LUNCH
-
13:30 - 14:10
Securing Tomorrow with Post-Quantum Cryptography
Speaker : Melissa Azouaoui, NXP
Abstract : Quantum computing is becoming an engineering reality that must be considered in today's embedded system designs. As governments and standardization bodies define post-quantum cryptography (PQC) migration roadmaps, manufacturers face the challenge of securing devices that may remain deployed for decades.
This talk explores the integration of PQC into embedded security architectures and the practical challenges of deploying quantum-safe security in resource-constrained environments. Drawing on NXP's experience in PQC standardization and product development, it highlights how PQC can be incorporated as a foundational security capability and what organizations can do today to prepare for the post-quantum transition.
-
14:10 - 14:50
Protecting Post-Quantum Cryptography in Hostile Environments (white-box)
Speaker : Agathe Houzelot, IDEMIA
Abstract : Post-quantum cryptography is progressively being integrated into consumer devices, mobile applications and digital identity infrastructures. However, this transition raises a new security challenge: how can quantum-resistant cryptographic algorithms remain protected when deployed in hostile software environments that attackers can inspect, modify and reverse engineer?
White-box cryptography aims to protect cryptographic secrets even when an attacker has full visibility and control over the software implementation, but its application to post-quantum cryptography remains largely unexplored. In this talk, we investigate white-box implementations of post-quantum cryptography, using the FrodoKEM key encapsulation mechanism as a case study.
We explore how existing protection techniques can be adapted to a lattice-based cryptosystem, introduce new mechanisms when existing approaches are not applicable or insufficient, and evaluate the resulting trade-offs between security and performance. Our work highlights that the transition to post-quantum cryptography is not simply a matter of replacing classical algorithms. It also requires rethinking how cryptographic secrets are protected once deployed in software.
By addressing this challenge, we open a new research direction at the intersection of post-quantum cryptography and software protection techniques, contributing to the development of the next generation of secure digital services for the post-quantum era.
-
14:50 - 15:30
Secure and Embedded Implementations of ML-KEM and ML-DSA
Speaker : Ryad Benadjila and Gabriel Zaid, CryptoExperts
Abstract : The optimized and portable implementation of the post-quantum standards FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA) on highly constrained microcontrollers raises significant challenges, particularly regarding memory footprint.
Drawing on our experience integrating these standards into CryptoExperts' PQLib library (portable across Cortex-M4, RISC-V, etc.), this presentation will detail the implemented software architecture and the memory/speed trade-offs. We will analyze the specific pitfalls associated with these algorithms' primitives when developing a portable and constant-time implementation. Finally, after identifying the main performance bottlenecks and evaluating the potential benefits of hardware acceleration, we will outline a few concrete directions for integrating physical protections against Side-Channel Attacks (SCA) and Fault Injection Attacks (FIA).
-
15:30 - 16:00
COFFEE BREAK
-
16:00 - 16:30
Triple Ratchet: a bandwidth-efficient hybrid secure Signal protocol
Speaker :Thomas Prest, PQShield
Abstract :Secure messaging apps are used by billions of people daily. Faced with the imminent threat of “Harvest Now, Decrypt Later” attacks, their providers must act now to make their protocols hybrid-secure: at least as secure as before, but now also post-quantum secure. Since most of these apps build on Signal's Double Ratchet, securing Signal matters a great deal.
Signal and Apple have already deployed hybrid variants: PQXDH on the initial handshake, and PQ3 on the whole protocol, by adding a PQ-ratchet. But the communication overhead of Kyber forces real-world PQ3 to run that ratchet only about every 50 messages, and this amortization degrades quickly in realistic scenarios, causing many consecutive retransmissions of 2272 bytes of public key and ciphertext.
We present Triple Ratchet, which improves on PQ3 in two ways. Erasure codes make communication inside the PQ-ratchet provably balanced, giving far better worst-case guarantees. And Katana, a new Kyber variant, cuts the combined ciphertext and public key size by over 37% at the 192-bit security level, from 2272 to 1416 bytes; along the way we identify and fix a security flaw in earlier optimization proposals.
Developed with the Signal team, who have brought some of these ideas into production. This talk is aimed at security practitioners rather than cryptographers alone.
-
16:30 - 17:00
The Zama Protocol in a Post-Quantum World
Speaker : Morten Dahl, Zama
Abstract :Blockchains are cryptographic systems in an unusually pure form: there are no trusted servers, account ownership rests entirely on digital signatures, and every transaction is published to a permanent, globally replicated ledger. This makes them uniquely exposed on both sides of the quantum threat: harvest-now-decrypt-later applies to a public ledger by construction, and a signature forgery is not fraud to be reversed but ownership itself.
The Zama Protocol adds confidentiality to blockchains using fully homomorphic encryption (TFHE): smart contracts operate on encrypted values, with decryption controlled by a threshold key management system built on secure multiparty computation. In this talk we give a component-by-component assessment of what the quantum threat means for this protocol, organized by a simple deadline distinction: confidentiality must be post-quantum today, while integrity must migrate before Q-day. The confidential layer, built on lattice assumptions from the same family as ML-KEM and ML-DSA, is already post-quantum; the threshold KMS is secure on paper but its deployment relies on classical primitives; the underlying blockchain's signatures remain classical. We present our phased roadmap for closing the gaps on our side, and along the way illustrate how the protocol works and the use cases being built on top of it.
-
17:00 - 17:30
DAKE: Bandwidth-Efficient AKE from Double-KEM
Speaker : Éric Sageloli, Thales
Abstract : Bandwidth remains a major bottleneck in post-quantum cryptography, especially for authenticated key exchange protocols, which are at the core of numerous applications.
In this presentation, we introduce DAKE (Double AKE), a generic family of secure, two- and three-message, bandwidth-efficient AKE protocols contributing to this line of research. To improve the communication size of ML-KEM-based AKEs, these protocols rely on double-KEMs: primitives that encapsulate a single shared key under two public keys at once. We also introduce Maul, a size-efficient ML-KEM-inspired double-KEM designed to be compatible with our protocols.
When instantiated with Maul, our protocols reduce overall communication by about 16% in the mutually authenticated setting, and about 20% in the unilateral setting, improving over both the double-KEM AKE of Xue et al. (ASIACRYPT 2018) and standard ML-KEM-based AKEs.
-
17:30 - 18:00
Anonymous Credentials in a Post-Quantum World
Speaker : Olivier Sanders, Orange Labs
Abstract : Anonymous Credentials, long confined to the area of secure computing, are in the limelight today thanks to the European Digital Identity Wallet (EUDI wallet) initiative that aims at providing both secure and private solutions for authenticating European citizens. This requires new cryptographic mechanisms that significantly depart from the classical digital signature standards. This momentum for privacy-preserving solutions however coincides with the post-quantum migration urged by many cybersecurity agencies worldwide, which is quite complex to manage in this specific context.
In this talk, we will present these cryptographic mechanisms and the associated issues, both technical and practical, along with the peculiar challenges of migrating them to quantum-resistant solutions.
Call for posters
A Call for Posters is open to PhD students and postdoctoral researchers. The poster session is an opportunity to present ongoing work and to engage in discussion with specialists from a range of disciplines. Topics may include, but are not limited to:
- New post-quantum cryptographic schemes (design, security, cryptanalysis).
- Performance and optimization of post-quantum primitives.
- Software, hardware or embedded implementation, resistance to physical attacks.
- Integration, large-scale deployment and post-quantum cryptographic transition.
Early-career researchers are warmly encouraged to submit a proposal.
Each accepted poster will be the subject of a short 3-minute talk. The best poster will be awarded a prize during the event.
How to submit
- Submission : One-page abstract in English, with name, affiliation and contact details
- Send to conference@creachlabs.fr
- Deadline : 11 October 2026
- Notification : 18 October 2026
- Selection criteria : Relevance, scientific quality and clarity
- Poster format: A0, portrait, written in English
- Printing : Can be handled by the organizers (send your file ahead of time)
- Download the call for poster proposals
PQC 2026 : Part of the European Cyber Week 2026
The 4th edition of the Post-Quantum Cryptography Conference is featured on the program of the European Cyber Week 2026.