CWI Cryptology Group Internal Seminar

     Archives: [2026] [2025] [2024] [2023] [2022] [2021] [2020] [2019] [List of Speakers]

Upcoming Event(s)


[print]
CWI Cryptology Group Internal Seminar
Date:2026-11-04
Location:M290/online
Schedule: 
14:00Eamonn Postlethwaite (Kings College London):
Hardness of hinted ISIS from the space-time hardness of lattice problems
Abstract: We initiate the study of basing the hardness of hinted ISIS problems (i.e. with trapdoor information, or ‘hints’) on the previously conjectured space-time hardness of lattice problems without hints. We present two main results. 1. If there exists an efficient algorithm for hinted ISIS that outputs solutions a constant factor longer than the hints, then there exists a single-exponential time and polynomial memory zero-centred spherical Gaussian sampler solving hinted SIS with norm a constant factor shorter than the hints. 2. Assume the existence of a chain of algorithms for hinted ISIS each taking as input Gaussian hints whose norms decrease by a constant factor at each step in the chain, then there exists a single-exponential time and polynomial memory algorithm for SIS with norm a quasilinear factor from optimal. The existence of such hinted ISIS solvers implies single-exponential time and polynomial memory algorithms for worst-case lattice problems, contradicting a conjecture by Lombardi and Vaikuntanathan (CRYPTO’20) and all known algorithms. This suggests that hinted ISIS is hard. Apart from advancing our understanding of hinted lattice problems, an immediate consequence is that signing the same message twice in GPV-style [Gentry–Peikert–Vaikuntanathan, STOC’08] schemes (without salting or derandomisation) likely does not compromise unforgeability. Also, cryptanalytic attempts on the One-More-ISIS problem [Agrawal–Kirshanova–Stehlé-Yadav, CCS’22] likely will need to overcome the conjectured space-time hardness of lattices.

[print]
CWI Cryptology Group Internal Seminar
Date:2026-09-30
Location:M290/online
Schedule: 
14:00Marian Dietz (ETH Zurich):
Bulletproofs are Optimal: Lower Bounds for Vector Commitments from Fiat-Shamir in Pairing-Free Groups
Abstract: Vector Commitments allow parties to commit to an (ordered) vector and to later succinctly open it at any desired position. In plain (i.e., known order and pairing-free) prime-order groups, all state-of-the-art constructions rely on the combination of a generalized Pedersen commitment and an inner product argument. This includes the celebrated constructions of Bootle et al. (EUROCRYPT 2016) and Bünz et al. (S\&P 2018) and subsequent improvements. All of these achieve proofs consisting of $\Theta(\log n)$ group elements, and further provide useful properties including malleability, subvector opening and transparent setup. However, breaking the $O(\log n)$ barrier in the plain discrete logarithm setting has proven to be a hard problem. This is in stark contrast with other settings, e.g. from pairing-friendly groups or groups of unknown order, where constructions with constant-size commitment and openings have been known for over a decade. In this work we investigate whether this limitation is inherent to constructions based on prime-order groups. Specifically we prove new lower bounds for any accumulator (a weaker object than vector commitments, thus making our result more general), with interactive public-coin membership proof in Maurer's Generic Group Model. An implication of our result is that in such setting at least one of the following must occur: (i) the commitment has super-constant size; (ii) the opening proof contains $\Omega(\log n)$ group elements; (iii) the opening proof has length $n^{1-o(1)}$. Our bound further extends to primitives that directly imply accumulators/VC including polynomial/functional commitments and inner product arguments.

Past 2026 Event(s)


2026-08-12CWI Cryptology Group Internal Seminar
  • Daan van Gent (Leiden University): HAWK: a post-mortem
2026-06-24CWI Cryptology Group Internal Seminar
  • Joost van der Laan (CWI): Tightly Unique Signature Schemes in the Random Oracle Model via Hash-and-Subset-Sign
2026-06-17CWI Cryptology Group Internal Seminar
  • Chris van Noorden (CWI): Post-Quantum Anonymous Signatures from the Lattice Isomorphism Group Action
2026-06-10CWI Cryptology Group Internal Seminar
  • Stijn Maatje (CWI): Forensic Cryptanalysis of the Backdoored UA-8295 Message Terminal
19.05.2026CWI Cryptology Group Internal Seminar
  • David Wu (University of Texas at Austin): The Structured Generic Group Model
29.04.2026CWI Cryptology Group Internal Seminar
  • Tim Beyne (KU Leuven): Observations on TETRA Encryption Algorithm TEA-3
15.04.2026CWI Cryptology Group Internal Seminar
  • Barbara Jiabao Benedikt (TU Darmstadt): The Order of Hashing in Fiat-Shamir Schemes
08.04.2026CWI Cryptology Group Internal Seminar
  • Tabitha Ogilvie (Royal Holloway University of London): On the Concrete Hardness Gap Between MLWE and LWE
2026-03-04CWI Cryptology Group Internal Seminar
  • Deep Inder Mohan (Georgia Tech): Generic and Algebraic Computation Models: When AGM Proofs Transfer to the GGM
2026-02-18CWI Cryptology Group Internal Seminar
  • Eugenio Paracucchi (CISPA Helmholtz Center for Information Security): Tanuki: New Frameworks for (Concurrently Secure) Blind Signatures from Post-Quantum Groups Actions
2026-02-04CWI Cryptology Group Internal Seminar
  • Valentina Frasca (University of Catania): On the (Un)biasability of Existing Verifiable Random Functions
2026-01-28CWI Cryptology Group Internal Seminar
  • Pierre Briaud (CNRS, University of Limoges): The Algebraic CheapLunch: Extending FreeLunch Attacks on Arithmetization-Oriented Primitives Beyond CICO-1
2026-01-21CWI Cryptology Group Internal Seminar
  • Yuxi Zheng (EPFL): How to Prove Post-Quantum Security for Succinct Non-Interactive Reductions
2026-01-14CWI Cryptology Group Internal Seminar
  • Jesko Dujmnovic (Northeastern University and Boston University): When Simple Permutations Mix Poorly
2026-01-07CWI Cryptology Group Internal Seminar
  • Kewen Wu (School of Mathematics at the Institute for Advanced Study): No exponential quantum speedup for SIS∞ anymore
0.0122s c