RISC Seminars (Research on Information Security and Cryptology)
Archives: [2026] [2025] [2024] [2023] [2022] [2021] [2020] [2019] [2018] [2017] [2016] [2015] [2014] [2013] [2012] [2011] [2010] [2009] [2008] [2007] [2006] [2005] [2004] [List of Speakers](To receive information about upcoming seminars, register for the RISC mailing list.)
Upcoming Event(s)
[print]
Lattice Cryptanalysis
Organised on the occasion of the upcoming PhD defense of Ludo Pulles and as a belated celebration of the recent PhD defense of Lynn Engelberts.
| Date: | Tuesday, September 22nd, 2026, 14:00h |
| Location: | CWI Amsterdam, Room L016 |
| Schedule: | |
| 14:00 | Ludo Pulles (University of Bordeaux): HAWK: Having Automorphisms Weakens Key Abstract: This summer, the signature scheme HAWK, which is based on the Lattice Isomorphism Problem (LIP), suffered from multiple new attacks.
One attack by Anthropic reduced HAWK's security by almost 50% [SW26], and HAWK withdrew from NIST's on-ramp standardization process.
In this presentation, I will explain the last part of this attack, which is a specific case of a general theorem around lattice automorphisms [vGP25].
Namely, we show if an adversary has any nontrivial automorphism of the underlying integer lattice, that they can reduce search rank-2 module-LIP, over a cyclotomic ring of degree a power of two to a LIP instance of at most half the rank.
Hence, knowledge of such a nontrivial automorphism speeds up the key recovery attack on HAWK at least quadratically.
Additionally, we also show which specific automorphism is constructed in Anthropic's attack.
[SW26] Z. Straznickas and S.A. Weis. HAWK-n Key Recovery Reduces to SVP in Dimension n/2+1. https://eprint.iacr.org/2026/1593
[vGP25] D.M.H. van Gent and L.N. Pulles. HAWK: Having Automorphisms Weakens Key. https://doi.org/10.62056/a3qjp2w9p
|
| 14:30 | Lynn Engelberts (CWI): A subexponential-time algorithm for solving the Short Integer Solution problem Abstract: Lattice-based cryptography plays a central role in the migration to post-quantum cryptography, highlighting the importance of understanding the hardness of the underlying lattice problems. In this talk, I will present joint work from my PhD research that focuses on the Short Integer Solution problem (SIS), which is a foundational lattice problem underlying the NIST standard ML-DSA. I will describe a classical algorithm for solving nontrivial instances of SIS in subexponential time, using a strategy inspired by Wagner’s algorithm combined with discrete-Gaussian techniques. Time permitting, I will discuss ongoing work extending this approach to LWE.
|
| 15:00 | Coffee break |
| 15:30 | Cong Ling (Imperial College London): Spinor genus and the lattice isomorphism problem Abstract: We study the spinor genus, a classification of quadratic forms in the context of cryptography based on the lattice isomorphism problem (LIP). The spinor genus lies between the genus and the equivalence class, thereby refining the concept of genus. For the special case of binary forms over certain number fields, we offer an efficient quantum algorithm to test if two forms lie in the same spinor genus. Finally, we present a quantum polynomial-time attack on a digital signature scheme DEFI based on indefinite quadratic forms.
|
| 16:00 | Phong Nguyen (Inria and DI ENS/PSL): Adelic reduction of module lattices (TBC) |
| 16:30 | Thomas Debris (Inria and École Polytechnique): Worst-to-average Case Hardness of Sparse--LPN via Biased Fourier Analysis |
Ludo will defend his PhD thesis, Lattice Cryptography: Isomorphisms & Dual Attacks, on Wednesday, September 23rd, 2026, at 16:00h in the Academy Building, Rapenburg 73, 2311 GJ Leiden. More info at: https://www.universiteitleiden.nl/en/events/2026/09/lattice-cryptography-isomorphisms--dual-attacks
Past 2026 Event(s)
| 23 April 2026 | Random Module Lattices
|
0.01563s c
