Table of contents

  • This session has been presented November 10, 2017.

Description

  • Speaker

    Damien Stehlé - ENS de Lyon

Kyber -- a Key Exchange Mechanism -- and Dilithium -- a digital signature -- are the two components of the Cryptographic Suite for Algebraic Lattices (CRYSTALS). I will present the intractable problems underlying their security, overview their design and comment their practical performance. The talk is based on the following articles:<br/> https://eprint.iacr.org/2017/633.pdf<br/&gt; https://eprint.iacr.org/2017/634.pdfv which are joint works with are joint works with Joppe Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, John Schanck, Peter Schwabe, Gregor Seiler and Vadim Lyubashevsky.

Next sessions

  • Key Attack on the ACDGV Matrix Encryption Scheme

    • September 25, 2026 (13:45 - 14:45)

    • IRMAR - Université de Rennes - Campus Beaulieu Bat. 22, RDC, Rennes - Amphi Lebesgue

    Speaker : Anmoal Porwal - Technical University of Munich

    I will present our key-recovery attack on the ACDGV public-key encryption scheme proposed at ASIACRYPT 2024 by Aragon, Couvreur, Dyseryn, Gaborit, and Vinçotte. The secret key is a Gabidulin code hidden by appending random rows and columns and by left- and right-multiplication with invertible matrices. Our attack exploits the resulting algebraic structure to recover an equivalent secret key. It[…]
    • Cryptography

    • Asymmetric primitive

  • Module Learning With Errors and Structured Extrapolated Dihedral Cosets

    • October 02, 2026 (13:45 - 14:45)

    • IRMAR - Université de Rennes - Campus Beaulieu Bat. 22, RDC, Rennes - Amphi Lebesgue

    Speaker : Jinwei Zheng - Télécom Paris

    The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes.   Inspired by the equivalence between LWE and[…]
    • Cryptography

Show previous sessions