Description
Les propriétés d'équivalence permettent d'exprimer un nombre important de propriétés de sécurité (secret fort, intraçabilité, anonymat...), soit comme propriété de symétrie, soit en comparant un protocole réél à une situation idéale.<br/> En principe, ces propriétés doivent valoir y compris lorsqu'un nombre arbitraire d'agents différents utilisent le protocole. Nous démontrerons que dans de nombreux cas, la vérification pour un petit nombre d'agents suffit à donner des garanties pour un nombre arbitraire. Finalement, nous montrerons que le relâchement de chacune de nos hypothèses mène à des contre-exemples (aucune borne n'est calculable dans ces cas).
Next sessions
-
Key Attack on the ACDGV Matrix Encryption Scheme
Speaker : Anmoal Porwal - Technical University of Munich
I will present our key-recovery attack on the ACDGV public-key encryption scheme proposed at ASIACRYPT 2024 by Aragon, Couvreur, Dyseryn, Gaborit, and Vinçotte. The secret key is a Gabidulin code hidden by appending random rows and columns and by left- and right-multiplication with invertible matrices. Our attack exploits the resulting algebraic structure to recover an equivalent secret key. It[…]-
Cryptography
-
Asymmetric primitive
-
-
Module Learning With Errors and Structured Extrapolated Dihedral Cosets
Speaker : Jinwei Zheng - Télécom Paris
The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes. Inspired by the equivalence between LWE and[…]-
Cryptography
-