Sign in

Peter Schwabe

@cryptojedi.bsky.social
550 followers 211 following 7 posts

Researcher in cryptographic engineering at MPI-SP.

PostsRepliesMedia
Reposted by Peter Schwabe
Deirdre Connolly¹ ² @durumcrustulum.com · 14/10/2025
Another @nadiaheninger.bsky.social W
182
Reposted by Peter Schwabe
Konstantin Macher @pneutig.eupolicy.social.ap.brid.gy · 05/10/2025
NEU: Erklärvideo des Max Planck Institute for Security and Privacy zu #Chatkontrolle und #ClientSideScanning. Das Client-Side-Scanning ist ein Angriff auf Verschlüsselung und untergräbt jegliches Vertrauen in private Kommunikation. Die Bundesregierung muss […] [Original post on eupolicy.social]
0429
Reposted by Peter Schwabe
Karola Marky @yon-juni.bsky.social · 05/10/2025
Die #Chatkontrolle soll angeblich Kinder schützen, doch sogar der Kinderschutzbund ist entschieden gegen diese Maßnahme, weil sie unsere Grundrechte einschränkt ohne dabei effektiv zu sein kinderschutzbund.de/stellungnahm...
kinderschutzbund.de
Stellungnahme zur öffentlichen Anhörung des Ausschusses für Digitales zur “Chatkontrolle” am Mittwoch, 1. März 2023 - Der Kinderschutzbund
Der Ausschuss für Digitales befasst sich am Mittwoch, 1. März 2023, mit dem Thema Chatkontrolle. Die öffentliche Anhörung findet ab 14 Uhr statt. Unsere Stellungnahme finden Sie hier als PDF zum Downl...
112
Reposted by Peter Schwabe
François Dupressoir @francois.dupressoir.eu · 05/10/2025
SUBMIT
111
Reposted by Peter Schwabe
Nigel Smart @smartcryptology.bsky.social · 04/10/2025
FHE.org 2026 Taipei Registrations are open! Registrations are open for the 5th Annual FHE.org Conference on Fully Homomorphic Encryption, colocated with Real World Crypto 2026 in Taipei, Taiwan, on March 8, 2026. Get your tickets now! luma.com/fhe-org-conf...
fhe.org
Fully Homomorphic Encryption
We are a community of researchers and developers interested in advancing homomorphic encryption and other secure computation techniques.
131
Reposted by Peter Schwabe
Signal @signal.org · 03/10/2025
We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EU’s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. signal.org/blog/pdfs/ge...
signal.org
4039252365
Reposted by Peter Schwabe
µASC Conference @uasc.cc · 04/10/2025
uASC 2026 will take place on February 3, 2026, in Leuven, Belgium, hosted by KU Leuven. Have you submitted your paper yet? 🤔 Cycle 2 Paper Submission Deadline is November 4, 2025! 👉 uasc.cc #uasc26
013
Reposted by Peter Schwabe
mccurley.bsky.social @mccurley.bsky.social · 15/09/2025
Whoa. 100 responses from speakers at CHES, and only one is presenting by video. Maybe their conference is actually worth going to?
062
Reposted by Peter Schwabe
Sofia Celi @claucece.bsky.social · 25/06/2025
Come to the ASCrypto school, affiliated with Latincrypt2025! 🗓️ Sept 29–30 | Medellín, Colombia 👨‍🏫 Learn 𝐦𝐨𝐝𝐞𝐫𝐧 𝐩𝐫𝐨𝐯𝐢𝐧𝐠 𝐬𝐲𝐬𝐭𝐞𝐦𝐬 from top experts 💥 2 days, 3 modules: IVC, STARKs, MPC 👥 With Benedikt Bünz, Sophia Yakoubov, Alan Szepieniec Organised by the amazing Arantxa Zapico and Javier Verbel.
064
Reposted by Peter Schwabe
µASC Conference @uasc.cc · 19/05/2025
uASC 2026 will take place on February 3, 2026, in Leuven, Belgium, hosted by KU Leuven. We can't wait to see you next year! Cycle 1 Paper Submission Deadline is July 15, 2025! 👉 uasc.cc #uasc26
0109
Reposted by Peter Schwabe
Mathy Vanhoef @vanhoefm.bsky.social · 25/05/2025
All papers should publish their code. Help realize this by becoming an artifact reviewer at NDSS'26, apply here: docs.google.com/forms/d/e/1F... You'll review artifacts of accepted papers. We especially encourage junior/senior PhD students & PostDocs to help. Distinguished reviews will get awards!
docs.google.com
Self-nomination for the Artifact Evaluation Committee of NDSS 2026
We are looking for members of the Artifact Evaluation Committee (AEC) of NDSS 2026. The Network and Distributed System Security symposium adopts an Artifact Evaluation (AE) process allowing authors t...
01210
Reposted by Peter Schwabe
Ruhr-Universität Bochum @ruhr-uni-bochum.de · 20/05/2025
Kinderschutz im Netz bleibt oft Theorie: Informatikerin Veelasha Moonsamy untersuchte mit Kolleg*innen aus Belgien und den Niederlanden rund 70.000 Werbeanzeigen auf Webseiten für Kinder – mit alarmierenden Ergebnissen. 👉 news.rub.de/wissenschaft... (Foto: Roberto Schirdewahn)
Blaue Fläche, auf der in weißer Schrift ein Zitat steht von Veelasha Moonsamy: "Die Werbeanzeigen auf Webseiten für Kinder waren eine bunte Mischung mit einigen alamierenden Inhalten." Daneben in einem Kreis ein Portraitfoto der Forscherin.
083
Reposted by Peter Schwabe
Michael Hutter @michutte.bsky.social · 19/05/2025
The CHES 2025 Challenge is coming back with two tracks! 🔬 GE Wars: Test your DL-SCA skills on real-world AES EM traces. 🔧 HACK@CHES'25: Dive into hardware security on a custom OpenTitan SoC. 🔗 ches.iacr.org/2025/challen... #CHES2025 #SideChannel #HardwareSecurity
ches.iacr.org
CHES 2025
Cryptographic Hardware and Embedded Systems
021
Reposted by Peter Schwabe
Sabine Oechsner @proofnerd.bsky.social · 05/05/2025
Our paper on attacking concurrent MPC implementations is finally on eprint 🎉 (And @schollster.bsky.social will present it at S&P 2025!) A summary 🧵
2125
Reposted by Peter Schwabe
Kenny Paterson @kennyog.bsky.social · 04/05/2025
Just about ready to set off to Madrid for #eurocrypt 2025, where I’ll have the great honour of giving the 2025 IACR Distinguished Lecture on Tuesday afternoon. #iacr #cryptography
2303
Peter Schwabe @cryptojedi.bsky.social · 03/05/2025
For those who enjoyed reading "Constant-Time Code: The Pessimist Case" by Thomas Pornin (2025/435), here's what I would consider "The Optimist Case": eprint.iacr.org/2025/759 Joint work with Santiago Arranz-Olmos, Gilles Barthe, Benjamin Grégoire, Jan Jancar, Vincent Laporte, and Tiago Oliveira.
eprint.iacr.org
Let's DOIT: Using Intel's Extended HW/SW Contract for Secure Compilation of Crypto Code
It is a widely accepted standard practice to implement cryptographic software so that secret inputs do not influence the cycle count. Software following this paradigm is often referred to as "constant...
0153
Reposted by Peter Schwabe
cascremers.bsky.social @cascremers.bsky.social · 02/05/2025
Updated version v0.9.5 of our book now available at tamarin-prover.com/book/ , with a range of improvements and exercises at the end.
tamarin-prover.com
Modeling and Analyzing Security Protocols with Tamarin: A Comprehensive Guide
The Tamarin prover is a security protocol verification tool that supports both falsification and unbounded verification in the symbolic model.
175
Reposted by Peter Schwabe
Real World Crypto Symposium @rwc.iacr.org · 28/03/2025
Big announcement: RWC 2027 in Seattle! April 5-7 subject to board approval.
5115
Reposted by Peter Schwabe
Real World Crypto Symposium @rwc.iacr.org · 28/03/2025
RWC 2026 in Taipei!
0147
Reposted by Peter Schwabe
Christopher Patton @cjpatton.bsky.social · 21/03/2025
An intro to lattice crypto and the published NIST standards for non-cryptographers who find themselves involved in the PQ transition. Thanks to @cryptojedi.bsky.social for the assist :) blog.cloudflare.com/lattice-cryp...
blog.cloudflare.com
Prepping for post-quantum: a beginner’s guide to lattice cryptography
This post is a beginner's guide to lattices, the math at the heart of the transition to post-quantum (PQ) cryptography. It explains how to do lattice-based encryption and authentication from scratch.
1114
Reposted by Peter Schwabe
Real World Crypto Symposium @rwc.iacr.org · 21/03/2025
Ready for a cryptic adventure? Next week’s #realworldcrypto 2025 Day 2 promises anonymous credentials & signatures, post-quantum breakthroughs, open-source PKI insights, and side-channel showdowns—all in one jam-packed program!
144
Reposted by Peter Schwabe
µASC Conference @uasc.cc · 16/03/2025
uASC 2025 was a huge success - we were sold out! Thanks to everyone who joined and see you in 2026!
051
Reposted by Peter Schwabe
Martin R. Albrecht @malb.bsky.social · 11/03/2025
Together with @kennyog.bsky.social we're organising a meeting at Eurocrypt to discuss how the, let's say, "dramatically changing political landscape" affects cryptography and our community, both domestically in some countries but also internationally eurocrypt.iacr.org/2025/communi...
 Wednesday, May 7, 14:30-16:00 (Room TBD): Cryptography in a Changing World: Navigating Geopolitical Uncertainty and Security Risks

Join us to discuss what we as a community can and should do in light of a dramatically changing political landscape, both domestically for some of us and internationally for all of us. We don't have ideas to pitch to you, but we think it will be useful to meet and to start a discussion.
For more information: Martin Albrecht and Kenny Paterson.
33714
Peter Schwabe @cryptojedi.bsky.social · 07/03/2025
The 3rd edition of WISC – Women in Security and Cryptography Workshop will take place in Bochum from June 16 to 18. Already confirmed are talks by Lejla Batina, Zinaida Benenson, Shafi Goldwasser, Martina Lindorfer, and Doreen Riepel. Registration is open now! casa.rub.de/en/events/wi...
casa.rub.de
WISC | Cluster of Excellence CASA | RUB
The Women in Security and Cryptography Workshop promotes international female PhD students and outstanding female students in the field of IT security.
01511
Reposted by Peter Schwabe
Paul Rösler @roeslpa.bsky.social · 05/03/2025
Join our Applied Crypto group at FAU in Nürnberg as a PhD student or spread the word: we're hiring. Our work covers many topics in real-world crypto, especially provable security and privacy of modern messaging protocols 🔐✉️ www.jobs.fau.de/jobs/7-phd-p...
jobs.fau.de
7 PhD positions (m/f/d) (salary level 13 TV-L) in Computer Science (full time) and 3 PhD position (m/f/d) (salary level 13 TV-L) in Law (part time, 75%)
0711
Reposted by Peter Schwabe
Real World Crypto Symposium @rwc.iacr.org · 19/02/2025
One more week left before the end of early registration for #realworldcrypto 2025. The last day to save $100 on your registration is February 26. rwc.iacr.org/2025/registr...
rwc.iacr.org
RWC 2025 registration
Real World Crypto Symposium
012
Reposted by Peter Schwabe
Nick Sullivan @nicksullivan.org · 19/02/2025
The tentative program for Real World Crypto 2025 is live! rwc.iacr.org/2025/program... A huge thanks to my co-chair @malb.bsky.social and all the amazing program committee members for helping put this together. I'm looking forward to seeing everyone in Sofia! #realworldcrypto
rwc.iacr.org
RWC 2025 program
Real World Crypto Symposium
0149
Reposted by Peter Schwabe
Annika Goedde @annikacg.bsky.social · 17/02/2025
🎥 Finden wir den perfekten Geheimcode? Für "42 – Die Antwort auf fast alles" durfte ich Dreharbeiten an der @ruhr-uni-bochum.de begleiten. Die Folge mit Eike Kiltz & Peter Schwabe ist nun in der Mediathek verfügbar: www.arte.tv/de/videos/11... @cryptojedi.bsky.social #Bochum #Kryptographie
arte.tv
Finden wir den perfekten Geheimcode? - 42 - Die Antwort auf fast alles - Die ganze Doku | ARTE
Wir suchen seit jeher nach ihm – dem perfekten Geheimcode: Eine sichere Verschlüsselung unserer vertraulichen Informationen. Besonders heute, in der digitalen Welt. Doch die sicherste Verschlüsselung ...
072
Reposted by Peter Schwabe
Krijn Reijnders @krijn.isogeni.es · 23/01/2025
Finally, a state-of-the-art version of CTIDH! That is, deterministic and a prime of 2048 bits. We introduce a new batching strategy we call "wombats", making dCTIDH five times faster than deterministic CSIDH. Surprisingly, it even beats "non-deterministic" CTIDH. See eprint.iacr.org/2025/107
eprint.iacr.org
dCTIDH: Fast & Deterministic CTIDH
This paper presents dCTIDH, a CSIDH implementation that combines two recent developments into a novel state-of-the-art deterministic implementation. We combine the approach of deterministic variants o...
2127
Reposted by Peter Schwabe
Deirdre Connolly¹ ² @durumcrustulum.com · 18/01/2025
New in EasyCrypt: KEM and PKE modelling libraries! github.com/EasyCrypt/ea... github.com/EasyCrypt/ea...
github.com
KEM libraries (non-ROM and ROM) by MM45 · Pull Request #672 · EasyCrypt/easycrypt
Initial attempt at libraries for KEM (both in standard model and ROM). There are several points of interest/discussion listed below which I think should be agreed upon before merging. The resulting...
092
Reposted by Peter Schwabe
Daniel Gruss @gruss.cc · 05/01/2025
We look for contributions from academia and industry and accept papers, posters, and talks. Or just attend uASC 25 on **February 19** in Bochum and meet fellow microarchitecture security researchers.
033
Reposted by Peter Schwabe
Martin R. Albrecht @malb.bsky.social · 03/01/2025
Khanh and Eamonn are organising UK Crypto Day on 20 February at King's College London. Registration is free (and open) but required: uk-crypto-day.github.io/2025/02/20/u... Help us spread the word and see you there.
uk-crypto-day.github.io
UK Crypto Day: 20 February 2025
Schedule
01513
Reposted by Peter Schwabe
Kevin McCurley @tragiccommons.infosec.exchange.ap.brid.gy · 10/12/2024
Sofía Celi joins as new co-editor of eprint.iacr.org. The core of IACR is volunteer effort, and it's always good to welcome someone new. @claucece
0325
Reposted by Peter Schwabe
Nicola Tuveri @romen.dev · 22/11/2024
🚨 Join the OpenSSL Academic Community! 🚨 Help shape the future of OpenSSL by joining the Academic Community hub. Participate in discussions, the BAC election process, and more. Voting starts Dec 2—join now! 📖 Learn more: openssl-library.org/post/2024-10...
openssl-library.org
OpenSSL Forms Business Advisory Committees - Shape the Future - Join Now!
The OpenSSL Foundation (primarily focused on non-commercial communities) and the OpenSSL Corporation (primarily focused on commercial communities) are pleased to announce the formation of Business Adv...
143
Reposted by Peter Schwabe
Deirdre Connolly¹ ² @durumcrustulum.com · 30/10/2024
The EasyCrypt proofs for X-Wing are now on GitHub: github.com/formosa-cryp...
github.com
GitHub - formosa-crypto/formosa-x-wing
Contribute to formosa-crypto/formosa-x-wing development by creating an account on GitHub.
0103
Reposted by Peter Schwabe
Real World Crypto Symposium @rwc.iacr.org · 06/09/2024
RWC 2025 is now officially open for submissions for contributed talks! rwc.iacr.org/2025/contrib...
rwc.iacr.org
RWC 2025 paper submission
Real World Crypto Symposium
2179
Reposted by Peter Schwabe
Nick Sullivan @nicksullivan.org · 06/09/2024
RWC 2025 in Sofia is going to be 🔥 I'm excited to be the co-chair (along with @martinralbrecht) of the program committee this year. We have an amazing group of reviewers this year, and we're looking forward to reading the strongest batch of talk submissions yet. #realworldcrypto
033
Reposted by Peter Schwabe
ePrint Updates @eprint.ing.bot · 16/08/2024
Basic Lattice Cryptography: The concepts behind Kyber (ML-KEM) and Dilithium (ML-DSA) (Vadim Lyubashevsky) ia.cr/2024/1287
Abstract. This tutorial focuses on describing the fundamental mathematical concepts and design decisions used in the two “main” lattice schemes standardized by NIST and included in the CNSA 2.0 algorithmic suite. They are the KEM / encryption scheme CRYSTALS-Kyber (ML-KEM) and the signature scheme CRYSTALS-Dilithium (ML-DSA) . In addition, we will also give the main ideas behind other lattice-based KEMs like Frodo and NTRU.
072
Reposted by Peter Schwabe
ePrint Updates @eprint.ing.bot · 29/07/2024
A Generic Framework for Side-Channel Attacks against LWE-based Cryptosystems (Julius Hermelink, Silvan Streit, Erik Mårtensson, Richard Petri) ia.cr/2024/1211
Abstract. Lattice-based cryptography is in the process of being standardized. Several proposals to deal with side-channel information using lattice reduction exist. However, it has been shown that algorithms based on Bayesian updating are often more favorable in practice.

In this work, we define distribution hints; a type of hint that allows modelling probabilistic information. These hints generalize most previously defined hints and the information obtained in several attacks.

We define two solvers for our hints; one is based on belief propagation and the other one uses a greedy approach. We prove that the latter is a computationally less expensive approximation of the former and that previous algorithms used for specific attacks may be seen as special cases of our solvers. Thereby, we provide a systematization of previously obtained information and used algorithms in real-world side-channel attacks.

In contrast to lattice-based approaches, our framework is not limited to value leakage. For example, it can deal with noisy Hamming weight leakage or partially incorrect information. Moreover, it improves upon the recovery of the secret key from approximate hints in the form they arise in real-world attacks.

Our framework has several practical applications: We exemplarily show that a recent attack can be improved; we reduce the number of traces and corresponding ciphertexts and increase the noise resistance. Further, we explain how distribution hints could be applied in the context of previous attacks and outline a potential new attack.
Image showing part 2 of abstract.
001
Reposted by Peter Schwabe
ePrint Updates @eprint.ing.bot · 25/07/2024
Towards ML-KEM & ML-DSA on OpenTitan (Amin Abdulrahman, Felix Oberhansl, Hoang Nguyen Hien Pham, Jade Philipoom, Peter Schwabe, Tobias Stelzer, Andreas Zankl) ia.cr/2024/1192
Abstract. This paper presents extensions to the OpenTitan hardware root of trust that aim at enabling high-performance lattice-based cryptography. We start by carefully optimizing ML-KEM and ML-DSA - the two primary algorithms selected by NIST for standardization - in software targeting the OTBN accelerator. Based on profiling results of these implementations, we propose tightly integrated extensions to OTBN, specifically an interface from OTBN to OpenTitan’s Keccak accelerator (KMAC core) and extensions to the OTBN ISA to support operations on 256-bit vectors. We implement these extensions in hardware and show that we achieve a speedup by a factor between 6 and 9 for different operations and parameter sets of ML-KEM and ML-DSA compared to our baseline implementation on unmodified OTBN. This speedup is achieved with an increase in cell count of less than 12% in OTBN, which corresponds to an increase of less than 2% for the full Earlgrey OpenTitan core.
001
Reposted by Peter Schwabe
Tancrède Lepoint @tancre.de · 08/07/2024
The program of Crypto 2024 is online, with an invited talk by Karthik Bhargavan on formal verification in crypto! #crypto2024 crypto.iacr.org/2024/program...
crypto.iacr.org
Crypto 2024 program
44th Annual International Cryptology Conference
143
Reposted by Peter Schwabe
ePrint Updates @eprint.ing.bot · 08/06/2024
A Tight Security Proof for SPHINCS⁺, Formally Verified (Manuel Barbosa, François Dupressoir, Andreas Hülsing, Matthias Meijers, Pierre-Yves Strub) ia.cr/2024/910
Abstract. SPHINCS⁺ is a post-quantum signature scheme that, at the time of writing, is being standardized as SLH-DSA. It is the most conservative option for post-quantum signatures, but the original tight proofs of security were flawed—as reported by Kudinov, Kiktenko and Fedorov in 2020. In this work, we formally prove a tight security bound for SPHINCS⁺ using the EasyCrypt proof assistant, establishing greater confidence in the general security of the scheme and that of the parameter sets considered for standardization. To this end, we reconstruct the tight security proof presented by Hülsing and Kudinov (in 2022) in a modular way. A small but important part of this effort involves a complex argument relating four different games at once, of a form not yet formalized in EasyCrypt (to the best of our knowledge). We describe our approach to overcoming this major challenge, and develop a general formal verification technique aimed at this type of reasoning. Enhancing the set of reusable EasyCrypt artifacts previously produced in the formal verification of stateful hash-based cryptographic constructions, we (1) improve and extend the existing libraries for hash functions and (2) develop new libraries for fundamental concepts related to hash-based cryptographic constructions, including Merkle trees. These enhancements, along with the formal verification technique we develop, further ease future formal verification endeavors in EasyCrypt, especially those concerning hash-based cryptographic constructions.
Image showing part 2 of abstract.
034
Peter Schwabe @cryptojedi.bsky.social · 01/06/2024
On my way to the summerschool on real-world crypto and privacy. Who else is coming?
2210
Reposted by Peter Schwabe
ePrint Updates @eprint.ing.bot · 31/05/2024
Formally verifying Kyber Episode V: Machine-checked IND-CCA security and correctness of ML-KEM in EasyCrypt (José Bacelar Almeida et al.) ia.cr/2024/843
Abstract. We present a formally verified proof of the correctness and IND-CCA security of ML-KEM, the Kyber-based Key Encapsulation Mechanism (KEM) undergoing standardization by NIST. The proof is machine-checked in EasyCrypt and it includes: 1) A formalization of the correctness (decryption failure probability) and IND-CPA security of the Kyber base public-key encryption scheme, following Bos et al. at Euro S&P 2018; 2) A formalization of the relevant variant of the Fujisaki-Okamoto transform in the Random Oracle Model (ROM), which follows closely (but not exactly) Hofheinz, Hovelmanns and Kiltz at TCC 2017; 3) A proof that the IND-CCA security of the ML-KEM specification and its correctness as a KEM follows from the previous results; 4) Two formally verified implementations of ML-KEM written in Jasmin that are provably constant-time, functionally equivalent to the ML-KEM specification and, for this reason, inherit the provable security guarantees established in the previous points. The top-level theorems give self-contained concrete bounds for the correctness and security of MLKEM down to (a variant of) Module-LWE. We discuss how they are built modularly by leveraging various EasyCrypt features.
Image showing part 2 of abstract.
023
Reposted by Peter Schwabe
Martin R. Albrecht @malb.bsky.social · 28/05/2024
We are looking for a postdoc to work with us on lattice-based cryptography: www.kcl.ac.uk/jobs/090126-... Stuff like e.g. this malb.io/sis-with-hin... Funded by this grant: martinralbrecht.wordpress.com/2023/01/31/e...
kcl.ac.uk
Research Fellow/Research Associate in Cryptography
047
Reposted by Peter Schwabe
Frederic Jacobs @fredericjacobs.com · 26/03/2024
As always, great coverage of #RealWorldCrypto by @durumcrustulum.com. This year, only for the lucky users of BlueSky! Below is the thread covering the conference, including my PQ3 talk :)
1205
Reposted by Peter Schwabe
Martin R. Albrecht @malb.bsky.social · 25/03/2024
Slides for my talk "An Update on Lattice Cryptanalysis Vol. 1" at the Real World Post Quantum Cryptography workshop yesterday: github.com/malb/talks/b... Yes, there was a Vol 2, it was given by John Schanck and his talk was way better.
076
Reposted by Peter Schwabe
John Schanck @susurrusus.bsky.social · 25/03/2024
slides from my talk at rwpqc: jmschanck.info/talks/202403...
084
Reposted by Peter Schwabe
Yawning Angel @yawning.bsky.social · 08/03/2024
As promised: gitlab.com/yawning/bs255 This still is a work in progress and probably has stupid bugs, and needs: - More test cases. - A specification document. But, it was relaxing to write, and I think illustrates "it is possible to do better".
321