Sign in

COSIC

@cosic.bsky.social
354 followers 45 following 1.1K posts

COSIC provides a broad expertise in digital security and strives for innovative security solutions. COSIC is headed by Bart Preneel. www.esat.kuleuven.be/cosic

PostsRepliesMedia
COSIC @cosic.bsky.social · 15h
Tomorrow Roozbeh Sarenche (COSIC) will be giving a COSIC Seminar on "Towards Decentralized Searcher Competition in MEV Markets". Free to attend live! www.esat.kuleuven.be/cosic/?post_...
esat.kuleuven.be
Events Archive - COSIC
000
COSIC @cosic.bsky.social · 25/09/2026
Curious about real-world post-quantum migration experiences? Frank Morgner (BDR) will share lessons learned from building a PQ-ready ID card, including roadmap considerations and crypto-agility aspects, at the #PQCSA Workshop "Post-Quantum Cryptography: State of the Art" in Bonn.
100
COSIC @cosic.bsky.social · 24/09/2026
The COSIC Seminar on "Provable Security and Privacy Analysis of WPA3’s SAE and SAE-PK Protocols" by Olga Sanina (TU Darmstadt) is now available on our YouTube channel: www.youtube.com/watch?v=A6YT...
youtube.com
COSIC Seminar "Provable Security and Privacy Analysis of WPA3’s SAE..." (Olga Sanina, TU Darmstadt)
YouTube video by COSIC - Computer Security and Industrial Cryptography
010
COSIC @cosic.bsky.social · 24/09/2026
Hundreds of Belgian military personnel can be identified via Strava activity at NATO and military sites, reports De Morgen. "This is simply not wise," says Bart Preneel. Shared location data can create real security risks. #CyberSecurity www.demorgen.be/nieuws/loopj... (paywall)
demorgen.be
Loopje rond de F-35’s? Onderzoek van De Morgen legt groot veiligheidslek bloot op gevoelige legerbasissen
Vriend of vijand: wie wil weten welke Belgische militairen op gevoelige locaties zoals het NAVO-hoofdkwartier in Brussel of de luchtmachtbasis van Kleine-Brogel werken, hoeft niet ver te zoeken. Op de...
000
COSIC @cosic.bsky.social · 23/09/2026
"Algorithms for solving the isogeny problem with oriented elliptic curves" is accepted to IACR Communications in Cryptology. Paper: eprint.iacr.org/2026/1219
eprint.iacr.org
Algorithms for solving the isogeny problem with oriented elliptic curves
We introduce WayFinder, a framework for generalizing the Delfs-Galbraith and SuperSolver algorithms for the supersingular isogeny problem. Our framework extends the search for elliptic curves with an ...
021
COSIC @cosic.bsky.social · 23/09/2026
Paper "0-RTT Integrated in SPDM for Large-Scale AI Super-Clusters" presented at #ESORICS 2026 in Rome. sites.google.com/di.uniroma1....
sites.google.com
31st European Symposium on Research in Computer Security - Accepted Papers
Winter Cycle
000
COSIC @cosic.bsky.social · 22/09/2026
A few more pics of the KU Leuven Security & Privacy showcase at BE-CYBER 2026. Master of Cybersecurity: onderwijsaanbod.kuleuven.be/opleidingen/... BE-CYBER event website: cybersecuritycoalition.be/becyber/ #becyber
onderwijsaanbod.kuleuven.be
Master of Cybersecurity (Leuven)
Discover the Master of Cybersecurity at KU Leuven in Belgium. Focus on cryptography, privacy, hardware security, secure software, and systems security.
000
COSIC @cosic.bsky.social · 22/09/2026
[1/3] BE-CYBER has become the annual gathering point for Belgium's cybersecurity community, bringing together policymakers, industry, technology experts and researchers. cybersecuritycoalition.be/becyber/ #BECYBER #CyberSecurity #KULeuven
100
COSIC @cosic.bsky.social · 22/09/2026
We have a new PhD student: Milan Boutros! Milan will be working on post-quantum cryptography, focusing on isogeny-based, code-based and multivariate cryptography.
120
COSIC @cosic.bsky.social · 21/09/2026
🔐 Interested in Post-Quantum Cryptography? You can still register until 27 September for our one-day training on NIST standards, cryptographic libraries and migration strategies in Bonn. 📅 Register now: www.esat.kuleuven.be/cosic/events... #PQC #PostQuantumCryptography #PostQuantum #PQCSA
010
COSIC @cosic.bsky.social · 21/09/2026
Join us this week at COSIC for two seminars at the forefront of cybersecurity and cryptography: 🔐 Wi-Fi security in WPA3 with Olga Sanina (TU Darmstadt) and FlipFields and the future of finite fields & rings with Christopher Wolf. Don't miss out! 👇 www.esat.kuleuven.be/cosic/?post_...
esat.kuleuven.be
Events Archive - COSIC
000
COSIC @cosic.bsky.social · 18/09/2026
We were delighted to celebrate the remarkable contributions of Nigel Smart with "Secrets Shared, Privacy Preserved", bringing together colleagues, collaborators, students, and friends from across the cryptography community.
120
COSIC @cosic.bsky.social · 18/09/2026
📢 Join Leonard Schild (COSIC, KU Leuven) at the #PQCSA Workshop in Bonn on 6 October 2026, where he will introduce the mathematical foundations of post-quantum cryptography, covering lattices, hash-based signatures, and Classic McEliece. Register now: www.esat.kuleuven.be/cosic/events...
000
COSIC @cosic.bsky.social · 17/09/2026
Interested in post-quantum cryptography implementations? Quinten Norga (COSIC, KU Leuven) will speak on "Performance, Side Channels & Implementation Pitfalls" at the #PQCSA Workshop in Bonn on 6 October 2026. Register now: www.esat.kuleuven.be/cosic/events... #PostQuantum #PQC #Quantum
020
COSIC @cosic.bsky.social · 16/09/2026
📹The COSIC Seminar on "Crypto-Agility in Hardware Security: Building Systems That Can Evolve" by Michael Hutter (Universität der Bundeswehr München) is now available on our YouTube channel: www.youtube.com/watch?v=BiOh...
youtube.com
COSIC Seminar "Crypto-Agility in Hardware Security: Building Systems That Can..." (Michael Hutter)
YouTube video by COSIC - Computer Security and Industrial Cryptography
010
COSIC @cosic.bsky.social · 16/09/2026
📹The COSIC Seminar on "LeOPaRd: Towards Practical Post-Quantum Oblivious PRFs via 2HashDH Paradigm" by Muhammed Esgin (Monash University) is now available on our YouTube channel: www.youtube.com/watch?v=ahgP...
youtube.com
COSIC Seminar "LeOPaRd: Towards Practical Post-Quantum..." (Muhammed Esgin, Monash University)
YouTube video by COSIC - Computer Security and Industrial Cryptography
000
COSIC @cosic.bsky.social · 16/09/2026
👏"Multi-Verifier Keyed-Verification Anonymous Credentials" accepted at #asiacrypt 2026. Preprint: eprint.iacr.org/2025/2156
eprint.iacr.org
Multi-Verifier Keyed-Verification Anonymous Credentials
Keyed-Verification anonymous credentials (KVAC) enable privacy-preserving authentication and can be seen as the symmetric primitive of conventional anonymous credentials: issuance and verification of ...
021
COSIC @cosic.bsky.social · 16/09/2026
Welcome to new PhD student Ema Šujster, who will work on the intersection of cryptography, privacy, cybersecurity, and law enforcement, focusing on how law enforcement can lawfully access digital evidence without undermining the security and privacy provided by modern encryption.
100
COSIC @cosic.bsky.social · 16/09/2026
👏"A Simple and Unified Approach for Proving Knowledge of Isogenies between Abelian Varieties" is accepted at #asiacrypt 2026. Preprint: eprint.iacr.org/2026/1157
eprint.iacr.org
A Simple and Unified Approach for Proving Knowledge of Isogenies between Abelian Varieties
In this paper we introduce a simple and unified approach, based on generic proof systems, to prove knowledge of any isogeny between two principally polarized abelian varieties in any dimension, assum...
000
COSIC @cosic.bsky.social · 16/09/2026
👏We are proud to announce that two COSIC papers have been accepted at the IEEE Symposium on Security and Privacy (S&P 2027)! Congratulations to all authors on this outstanding achievement. We are very proud of this success! #sp2027 #IEEE
100
COSIC @cosic.bsky.social · 15/09/2026
The paper #DDRop is accepted at #ACMCCS 2026. We show how silently dropping DDR5 writes can undermine modern confidential computing protections, enabling attacks against Intel TDX, Intel Scalable SGX, and AMD SEV-SNP. Website & paper: ddropattack.eu
ddropattack.eu
DDRop
100
COSIC @cosic.bsky.social · 15/09/2026
The quantum threat is approaching. How should we prepare? Join Bart Preneel at the #PQCSA Workshop in Bonn on 6 Oct 2026 for his talk: "The Quantum Threat: Why Act Now?" Registration is open: www.esat.kuleuven.be/cosic/events... #PostQuantum #PQC #Quantum
030
COSIC @cosic.bsky.social · 14/09/2026
This week at COSIC: we're hosting the 7th Leuven Isogeny Days and look forward to welcoming everyone back! Also on Wednesday, Leila Taghizadeh will give a COSIC seminar. Check out the full calendar: www.esat.kuleuven.be/cosic/?post_...
esat.kuleuven.be
Events Archive - COSIC
000
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 03/09/2026
A Quasidifferential Analysis of the Wrong-Key Randomization Hypothesis (Tim Beyne, Gregor Leander, Mariia Mutkovina, Ricardo Rodriguez Reveco) ia.cr/2026/1848
Abstract. The Wrong-Key Randomization (WKR) hypothesis governs data-complexity estimates in differential cryptanalysis: wrong-key guesses are assumed to behave as a random permutation would. Exact computation of fixed-key differential probabilities was, until recently, infeasible.

We use quasidifferential trails to compute the exact wrong-key distribution for the key-recovery map G_(k, k′) = F_(k′)⁻¹  ∘ F_(k) in PRESENT-like SPNs. A mask-first reformulation exposes a Walsh–Hadamard structure; restricting the transform to the low-dimensional support, together with SMT-guided trail enumeration, reduces the cost: for a 16-bit toy cipher, from~2⁸⁰ to~2¹³; for , from~2¹⁹² to~2³⁰; and for GIFT, from~2¹⁹² to~2³².

For the toy cipher, PRESENT and GIFT, the computed distribution is a structured mixture: a large zero-probability class coexists with bottleneck classes orders of magnitude above the random-permutation mean, and nothing lies between them. Such a distribution is not unimodal, so no Poisson or binomial law fits it for any parameter and the hypothesis is formally false for all three targets. For PRESENT, however, we show that this deviation does not affect the security of Wang’s 14-round differential attack. We cast the computed distribution as a structured composite hypothesis—the differential counterpart of the random-permutation/composite-hypothesis model used for wrong keys in linear cryptanalysis–and show that the shape of the wrong-key distribution, not merely its mean, governs how many wrong keys survive the key-recovery filter. For PRESENT with Wang’s distinguisher, the structural signal is carried only by the right pairs, whose weight is too small for the deviation to surface; the hypothesis remains a safe heuristic in this case despite being formally false. Our SMT-based enumeration tool is publicly available.
Image showing part 2 of abstract.
021
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 10/09/2026
What to Guess in Key-Recovery Attacks? (Tim Beyne, Gregor Leander, Patrick Neumann, Yevhen Perehuda, Michiel Verbauwhede) ia.cr/2026/1897
Abstract. Determining the precise parts of the key that need to be guessed in a key-recovery attack is fundamental for judging its cost: if the same attack can be executed by guessing less key material, then the cipher’s resistance against this attack is overestimated. Although a multitude of prior works provide upper bounds on the key material required, and although these bounds might be tight in some special cases, a precise evaluation of the required key material and the tightness of these bounds is still missing. We remedy this by enumerating linear trails to iteratively compute the affine hull of the support of the Fourier transform of the key-recovery map. This leads to a generic and practical algorithm that identifies the smallest subspace of key material to be guessed. This algorithm is ready to be used in many different attacks and for a large variety of cipher structures. We demonstrate its impact by showcasing improvements on several published integral, linear, differential-linear, and zero-correlation attacks on the block ciphers PRESENT, SIMON, SKINNY, and GIFT.
011
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 06/09/2026
OptiMix: Scalable and Distributed Approaches for Latency Optimization in Modern Mixnets (Mahdi Rahimi) ia.cr/2026/1863
Abstract. Mixnets provide network-level anonymity, traded off with increased communication latency, which consequently limits their applicability to only latency-tolerant applications, shrinking the anonymity set to clients engaged in such use cases. Addressing this issue requires optimizing latency, as recently explored in (NDSS’24) and (NDSS’25) through node arrangement and strategic routing. However, these approaches are tailored to specific mixnet designs, rely on simplified models and trust assumptions, or suffer from limited practical efficiency.

In contrast, bridges these gaps by introducing a general low-latency mixnet model adaptable to all well-established designs. To this end, %we first propose an efficient distributed protocol for arranging nodes in mixnets that achieves low-latency properties while maintaining unpredictability against adversaries. we first propose an efficient distributed protocol for arranging nodes in mixnets that achieves low-latency properties while maintaining unbiasability against adversaries. Second, we introduce novel strategic routing schemes that optimize communication latency. Third, we design a load-balancing algorithm that evenly distributes traffic without undermining the latency-optimized characteristics of the routing strategies. Fourth, we conduct extensive evaluations using data from the deployed Nym mixnet, demonstrating substantial latency reductions with minimal anonymity loss across various mixnet designs—achieving up to 4× performance gains over state-of-the-art solutions. %Finally, we propose a cover-routing mechanism that enables clients to benefit from low-latency mixnets without sacrificing anonymity, at the modest cost of generating additional traffic. Finally, considering that latency reduction incurs either anonymity degradation or increased bandwidth overhead—as stated by the anonymity trilemma—we propose a cover-routing mechanism that enables clients to benefit from low-latency mixnets without compromising anonymity, at the modest cost of generating additional cover traffic.
Image showing part 2 of abstract.
011
COSIC @cosic.bsky.social · 10/09/2026
🔐 Preparing for the post-quantum transition? Join our one-day training on "Post-Quantum Cryptography: State of the Art" in Bonn on 6 October 2026. Learn about NIST standards, cryptographic libraries, and practical migration strategies. Register now: www.esat.kuleuven.be/cosic/events...
000
COSIC @cosic.bsky.social · 10/09/2026
Welcome to our newest PhD student Luca Biscaldi! Luca will work on securing PQC implementations in HW applying and adapting the Threshold Implementations framework. "I chose COSIC because of the strong sense of family. I immediately felt part of the group!" #choosecosic
000
COSIC @cosic.bsky.social · 10/09/2026
The IEEE Benelux LMAG has published its review of the celebration honoring Joan Daemen and Vincent Rijmen, recipients of the BBVA Foundation Frontiers of Knowledge Award for the creation of AES. Read more: region8today.ieeer8.org/category/eve... #AES #Cryptography #IEEE #COSIC
region8today.ieeer8.org
IEEE Region 8 Today -
IEEE Region 8 Today -
000
COSIC @cosic.bsky.social · 10/09/2026
On 2nd September, Songqiao Cui successfully defended his PhD thesis in COSIC, congrats! 🥳🎉🪩🎓
010
COSIC @cosic.bsky.social · 10/09/2026
At #IJCB 2026 in Rome, Enrique Argones Rúa presented a joint work on biometric template protection, exploring how reliable and unreliable biometric features can be combined in hybrid strengthened fuzzy extractors. ijcb2026.ieee-biometrics.org/accepted-pap...
000
COSIC @cosic.bsky.social · 10/09/2026
🎉 #ERC Starting Grant 2026 for COSIC's Tim Beyne! His project #RECRYPT aims to reshape the security analysis of symmetric #cryptography and strengthen digital security. 🔐 research.kuleuven.be/EU/p/erc/new...
000
COSIC @cosic.bsky.social · 10/09/2026
📶 How secure is “secure” Wi‑Fi ranging? Our latest research on IEEE 802.11az/802.11bk shows that stronger ranging signals alone are not enough.
100
COSIC @cosic.bsky.social · 28/08/2026
Powerful AI can strengthen cybersecurity, but open access also raises new risks. “GLM-5.3 has already found more than 2,000 vulnerabilities in different applications,” says Bart Preneel. #AI #Cybersecurity #ZAI www.standaard.be/economie/chi...
standaard.be
000
COSIC @cosic.bsky.social · 28/08/2026
Nikola Antonijević's COSIC seminar on "Secure Wi-Fi Ranging Today: Security and Adoption of IEEE 802.11az/bk" is now available on our YouTube channel: www.youtube.com/watch?v=U6Rk...
youtube.com
COSIC Seminar "Secure Wi-Fi Ranging Today: Security and Adoption..." (Nikola Antonijević, COSIC)
YouTube video by COSIC - Computer Security and Industrial Cryptography
010
COSIC @cosic.bsky.social · 27/08/2026
Good news: the COSIC Seminar on "Threshold Encryption for Mempool Privacy on Public Blockchains" by Sebastian Faust (TU Darmstadt) is now online on our YouTube channel: www.youtube.com/watch?v=rqQu...
youtube.com
COSIC Seminar "Threshold Encryption for Mempool Privacy on Public.." (Sebastian Faust, TU Darmstadt)
YouTube video by COSIC - Computer Security and Industrial Cryptography
000
COSIC @cosic.bsky.social · 25/08/2026
Attending CRA Standards Unlocked in Bonn in October? Consider also registering for our one-day training on NIST standards, cryptographic libraries and migration strategies: www.esat.kuleuven.be/cosic/events... #cra #pqcsa #postquantum #quantum
esat.kuleuven.be
Post-Quantum Cryptography: State of the Art
010
COSIC @cosic.bsky.social · 24/08/2026
This week in COSIC... Looking for an interesting seminar this week? We have three free-to-attend COSIC seminars coming up. Find all the details on our events calendar: www.esat.kuleuven.be/cosic/?post_...
esat.kuleuven.be
Events Archive - COSIC
000
COSIC @cosic.bsky.social · 21/08/2026
The program for "Secrets Shared, Privacy Preserved", the celebration of the work of Nigel Smart, is now available! Join us in Amalfi on 17 September 2026, co-located with #SCN 2026. 🔗 www.esat.kuleuven.be/cosic/events... Registration is open. We look forward to seeing you there!
030
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 18/08/2026
From Round Skipping to S-Box Skipping: Attacking Poseidon’s Partial Layer via Subspace Restriction (Amit Singh Bhati, Sundas Tariq, Tomer Ashur) ia.cr/2026/1692
Abstract. Poseidon [Grassi, Khovratovich, Rechberger, Roy, and Schofnegger; USENIX’21] is an arithmetization-oriented (AO) hash function designed to be efficient in real-world zero-knowledge (ZK) applications. We present GSR, a generalized S-box skipping gadget that absorbs a single initial full round and t − 2k partial rounds without increasing the polynomial degree of the Poseidon polynomial system with state size t and input-output constraints 2k. By restricting the subspace of the total constraints satisfying solutions, independent of the rounds constants and MDS matrix selection, the distinguisher expends input degrees of freedom to linearize the internal state transitions where the dense algebraic mixing usually occurs. This maps a computationally infeasible polynomial system into a bounded, low-degree ideal parameterized by k free variables.

We show how to use the gadget to construct a probability 1 distinguisher over t − 2k + 1 rounds of Poseidon. We then show how this distinguisher can be used as a basis for interpolation-based attacks. We go on to present experimental solutions to the CICO-1 problem over 28 out of 31 rounds and CICO-2 problem over 25 out of 31 rounds in the setting set by the Ethereum Poseidon initiative (i.e., using the KoalaBear field with t = 24 and α = 3). Crucially, since the subspace restriction approach is tuned only by t and k, our results apply to the Poseidon structure regardless of the choice of round constants, MDS matrix, S-box exponent α, or field size p.
Image showing part 2 of abstract.
011
COSIC @cosic.bsky.social · 20/08/2026
Registration is now open for the Post-Quantum Cryptography: State of the Art workshop, taking place in Bonn on 6 October 2026. www.esat.kuleuven.be/cosic/events...
100
COSIC @cosic.bsky.social · 18/08/2026
BlackBerry is back, but not through smartphones. Its #QNX software powers hundreds of millions of vehicles. Bart Preneel highlights its microkernel design: secure, resilient and built for critical systems. www.demorgen.be/nieuws/black... (paywall)
demorgen.be
BlackBerry maakte smartphones die niemand meer wou. Vandaag is het bedrijf terug, op ‘een markt die gaat exploderen’
Tien jaar geleden gooide BlackBerry de handdoek als smartphonebedrijf, voorbijgestreefd door de concurrentie. Maar kijk, nu maakt de telefoonreus van toen een opmerkelijke comeback in de autosector.
011
COSIC @cosic.bsky.social · 17/08/2026
We’re excited to announce the 7th edition of the Leuven Isogeny Days (Sept 16–18, 2026)! Registration is open until 22 August, join us! More info & signup: www.esat.kuleuven.be/cosic/projec... #LID #Isogeny #IsogenyDays
033
COSIC @cosic.bsky.social · 17/08/2026
📢 Today marks the start of the official registration period for KU Leuven programmes! Why choose for the Advanced Master of Cybersecurity at KU Leuven Faculty of Engineering Science? Read below 👇
100
COSIC @cosic.bsky.social · 17/08/2026
This week in COSIC... On Thursday there is a COSIC Seminar on "Secure Wi-Fi Ranging Today: Security and Adoption of IEEE 802.11az/bk" by Nikola Antonijević: www.esat.kuleuven.be/cosic/?post_...
esat.kuleuven.be
Events Archive - COSIC
000
COSIC @cosic.bsky.social · 14/08/2026
🏆 Congratulations to COSIC researcher Tim Vlummens and co-authors! Their paper, "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", received the Internet Defense Prize 2026 at #USENIX Security Symposium and was also selected as a Distinguished Paper.
100
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 12/02/2024
Subfield attack: leveraging composite-degree extensions in the Quotient Ring transform (Pierre Pébereau) ia.cr/2024/196
Abstract. In this note, we show that some of the parameters of the Quotient-Ring transform proposed for VOX are vulnerable. More precisely, they were chosen to defeat an attack in the field extension 𝔽_(q^(l)) obtained by quotienting 𝔽_(q)[X] by an irreducible polynomial of degree l. We observe that we may use a smaller extension 𝔽_(q^(l′)) for any l′|l, in which case the attacks apply again. We also introduce a simple algebraic attack without the use of the MinRank problem to attack the scheme. These attacks concern a subset of the parameter sets proposed for VOX: I, Ic, III, IIIa, V, Vb. We estimate the cost of our attack on these parameter sets and find costs of at most 2⁶⁷ gates, and significantly lower in most cases. In practice, our attack requires 0.3s, 1.35s, 0.56s for parameter sets I,III,V for the initial VOX parameters, and 56.7s, 6.11s for parameter sets IIIa, Vb proposed after the rectangular MinRank attack.
022
Reposted by COSIC
ePrint Updates @eprint.ing.bot · 23/07/2026
MQ on my Hardware: Performance Analysis of MQOM on FPGA (Stelios Manasidis, Quinten Norga, Suparna Kundu, Ingrid Verbauwhede) ia.cr/2026/1483
Abstract. Recent algorithmic advancements in the Multi-Party Computation-in-the-Head (MPCitH) paradigm have resulted in more efficient post-quantum digital signature schemes. MQOM is a MPCitH-based digital signature scheme and candidate in the ongoing NIST Post-Quantum Cryptography (PQC) standardization effort, offering performance competitive with lattice- and multivariate-based schemes in software. In this work, we develop a dedicated hardware accelerator for MQOM and analyze the impact of recent algorithmic modifications on hardware performance. This is achieved through the careful co-design of high-throughput symmetric primitive engines and highly-optimized polynomial arithmetic cores, minimizing stalling and supporting entirely on-the-fly computations of all polynomial arithmetic. As a result, no intermediate buffers are required and re-computation or sampling is avoided. Secondly, we analyze MQOM’s use of correlated GGM trees for generating MPC party shares, which reduce computational cost at the cost of increased signature size. We observe that this choice leads to increased design flexibility and significantly reduces on-chip memory requirements for hardware designs. Furthermore, MQOM proposes several parameter sets per security level. We analyze the impact of different MQOM parameter sets on hardware cost and performance. Our design with NIST L1 parameters only requires 15 812/9 384 LUTs/FFs and 4.5 BRAMs on FPGA, while performing the signature generation in 0.46 ms and signature verification in 0.38 ms. Compared to state-of-the-art hardware implementations of other MPCitH-based DSAs, we improve the area-time-product (ATP) by a factor 3.5× up to 66.4×. Compared to the lattice-based ML-DSA scheme, our MQOM hardware design is only outperformed by a factor 1.5×. Our results show that MQOM and the correlated GGM tree structure are hardware-friendly designs, leading to one of the highest HW-vs-SW speedup ratios among similar PQC DSAs, while also attaining the smallest on-chip memory footprint among high-performance hardware implementations.
Image showing part 2 of abstract.
011
COSIC @cosic.bsky.social · 13/08/2026
Yasmine Guidoum is visiting COSIC to conduct research on extending multidimensional linear cryptanalysis to a wider range of generalized Feistel constructions, with the goal of deriving attack bounds and analyzing the impact of diffusion mechanisms on security. #choosecosic
110
COSIC @cosic.bsky.social · 13/08/2026
Welcome to Birce Bilginur Fındık, who is visiting us to investigate how much of an FPGA's gate-level design can be reconstructed directly from its bitstream, assessing the feasibility and limits of netlist recovery without access to source files or encryption keys. #choosecosic
100