Sign in

Philipp Muens

@muens.io
154 followers 275 following 209 posts

Cryptography R&D @ primefactor.io • Nerd-snipe me with Lattices, Isogenies, Magmas, etc. • Instant Coffee Connoisseur • Webmaster @ muens.io

PostsRepliesMedia
Philipp Muens @muens.io · 11/08/2026
The Blockstream team just released their 192 page paper on Lattice-based Signature Schemes (for Bitcoin). It also includes an intro to Lattice-based cryptography. eprint.iacr.org/2026/1628
eprint.iacr.org
Lattice-based Signature Schemes for Bitcoin
Lattice-based cryptography offers a promising direction for transitioning Bitcoin toward post-quantum security, serving as a secure replacement for currently deployed discrete logarithm signatures. Th...
010
Philipp Muens @muens.io · 30/06/2026
Cedarcrypt is right around the corner and the program looks absolutely amazing! cedarcrypt.org Really sad that I can't attend this year 🥲 I hope that there'll be a second installment next year.
cedarcrypt.org
Cedarcrypt 2026 — Applied Cryptography Summer School & Conference
Join us for four days of applied cryptography in the Mediterranean. July 13–16, 2026 at AUB Mediterraneo Campus, Paphos, Cyprus.
010
Philipp Muens @muens.io · 02/06/2026
Totally agree on the influx of information around FHE for LLMs (and ML more broadly). Interestingly, I’ve noticed a slight uptick in new FHE papers over the past few months, especially with a focus on CKKS. What do you think the killer app is? Or is it the case that we still haven’t found one?
010
Philipp Muens @muens.io · 02/06/2026
The Duality Technologies team published a comprehensive SoK on private LLM inference via FHE (with a focus on the CKKS scheme). It’s still inefficient, but FHE has come a long way. I am very hopeful that we'll get there someday. eprint.iacr.org/2026/935
eprint.iacr.org
SoK: Private LLM Inference using Approximate Homomorphic Encryption
Although recent surveys on privacy-enhancing technologies concluded that FHE cannot feasibly evaluate non-linear activation functions in modern ML architectures, 20 CKKS-based frameworks have since de...
131
Philipp Muens @muens.io · 01/06/2026
Haha. I thought exactly the same thing this morning. I subscribe via RSS and wow, what a great list of amazing papers I woke up to. Still have to go through a bunch of them...
010
Philipp Muens @muens.io · 01/06/2026
Other good resources are (in no particular order): - eprint.iacr.org/2015/939 - eprint.iacr.org/2023/032 - eprint.iacr.org/2024/1287
eprint.iacr.org
A Decade of Lattice Cryptography
\emph{Lattice-based cryptography} is the use of conjectured hard problems on point lattices in~$\R^{n}$ as the foundation for secure cryptographic systems. Attractive features of lattice cryptography...
021
Philipp Muens @muens.io · 01/06/2026
Wow! Alfred Menezes just published this 182 page "A Gentle Introduction to Lattice-Based Cryptography" paper. I just skimmed through it, but it looks like an invaluable resource if you want to study lattices and how they're used in (PQ) Cryptography. eprint.iacr.org/2026/1098
eprint.iacr.org
A gentle introduction to lattice-based cryptography
We present the quantum-safe Kyber key encapsulation mechanism (ML-KEM) and the Dilithium signature scheme (ML-DSA). We also develop the mathematical background on lattices needed to understand why Kyb...
1147
Philipp Muens @muens.io · 15/05/2026
Good talk that shows techniques and tools to implement cryptographic algorithms in a more secure (as in fewer bugs) way. www.youtube.com/watch?v=Lbs8...
youtube.com
39C3 - How To Minimize Bugs in Cryptography Code
YouTube video by media.ccc.de
030
Philipp Muens @muens.io · 29/04/2026
Really nice writeup! Looking forward to part 2 (and the rest of the series). Also thanks a lot for publishing the code so one can study the actual implementation. Added it to my list of resources to work through once I dive deeper into CKKS.
010
Philipp Muens @muens.io · 27/04/2026
Dang. Now that you wrote it I can see it too 😮‍💨 The signs are all in there: Heavy use of em dashes, the overall structure of the post, the succinct writing, "Executive Summary" and "The Bottom Line" sections, etc. So it's very likely that "you're absolutely right"...
010
Philipp Muens @muens.io · 26/04/2026
Interesting take on why C should be used for Cryptography implementations. www.wolfssl.com/why-c-remain...
wolfssl.com
Why C Remains the Gold Standard for Cryptographic Software - wolfSSL
For production cryptographic software, memory safety alone does not define security. Real-world crypto must run on every platform, maintain stable assumptions
100
Philipp Muens @muens.io · 25/04/2026
This is a nice list with different resources on FHE attacks: github.com/Hexens/aweso... Pairs well with the Security Notions Zoo: securitynotionszoo.com
github.com
GitHub - Hexens/awesome-fhe-attacks: A curated list of research, articles, tools, and resources focused on attacks against Fully Homomorphic Encryption (FHE)
A curated list of research, articles, tools, and resources focused on attacks against Fully Homomorphic Encryption (FHE) - Hexens/awesome-fhe-attacks
010
Philipp Muens @muens.io · 19/04/2026
Another really good presentation that explains how iO can be constructed from LWE-with-hints in a very intuitive way. Lots of the schemes have been broken, unfortunately. However constructing iO from LWE with minor tweaks is still a promising direction. www.youtube.com/watch?v=NmxZ...
youtube.com
Circularity Based IO, Part 1
YouTube video by Simons Institute for the Theory of Computing
000
Philipp Muens @muens.io · 18/04/2026
This is a great talk that explains why constructing iO from pure LWE is still an open research question. It also dives into the LWE-with-hints line of work and proposes the new Circular Security with Random Opening assumption. www.youtube.com/watch?v=H3Qc... eprint.iacr.org/2025/390
youtube.com
Lattice-Based Post-Quantum iO from Circular Security with Random Opening Assumption
YouTube video by Simons Institute for the Theory of Computing
000
Philipp Muens @muens.io · 18/04/2026
This is a great review paper that explains the iO construction "Indistinguishability Obfuscation from Functional Encryption" by Bitansky and Vaikuntanathan in a very digestible manner. It's highly recommended to take some notes while reading along. piazza.com/class_profil...
piazza.com
000
Philipp Muens @muens.io · 11/04/2026
iO is still highly inefficient, unfortunately. I hope that we'll get there at some point as iO unlocks a lot of super interesting use cases: www.youtube.com/watch?v=SNnX... Hardware-based iO seems like a nice stepping stone towards practical iO. eprint.iacr.org/2025/1989.pdf
youtube.com
Indistinguishable obfuscation. The tech that will solve crypto! - Jordi Baylina
YouTube video by Duct Tape
010
Philipp Muens @muens.io · 10/04/2026
This is an amazing resource to learn how zkVMs work under the hood: ubermensch.blog/articles/mak...
ubermensch.blog
Making Sense of ZK Virtual Machines
A deep dive into how ZKVMs work — from ZK proofs and circuits through arithmetization to building a working STARK-based ZKVM in Rust.
000
Philipp Muens @muens.io · 26/03/2026
This is a very interesting paper that uses FHE to turn any signature scheme into a blind signature scheme. Verifiability is ensured using a zkp. It also introduces the concept of "committed verifiable FHE" where the verifier doesn't learn the circuit. eprint.iacr.org/2026/574
eprint.iacr.org
A Universal Blinder: One-round Blind Signatures from FHE
We construct compilers that convert any secure signature scheme into a single-round blind signature scheme. An important property of the construction is that the final blind signature has exactly the ...
000
Philipp Muens @muens.io · 21/03/2026
Really good paper that dives very deep into the intricacies of zkVMs. eprint.iacr.org/2026/525.pdf
eprint.iacr.org
011
Philipp Muens @muens.io · 20/03/2026
Interesting paper that shows why it's important to keep your cryptography up to date. eprint.iacr.org/2026/526
eprint.iacr.org
Broken By Design: A Longitudinal Analysis of Cryptographic Failures in Alipay Mobile Payment Infrastructure
We present a systematic security analysis of Alipay's APK signing certificate, issued in 2009 using md5WithRSAEncryption with RSA-1024 and still active in 2026, serving over one billion users. Through...
000
Philipp Muens @muens.io · 16/01/2026
I'm a huge fan of Adaptor Signatures and use them in a project I'm currently working on. A new paper was just released that studies Blind Adaptor Signatures which is an interesting combination of Blind Signatures and Adaptor Signatures: eprint.iacr.org/2026/060
eprint.iacr.org
Blind Adaptor Signatures, Revisited: Stronger Security Definitions and Their Construction toward Practical Applications
Although both blind signatures and adaptor signatures have individually attracted attention, there is little research on combining these primitives so far. To the best of our knowledge, although the ...
010
Philipp Muens @muens.io · 10/01/2026
Really excited for the new "Secret Mode" that will land in Go v1.26 and will make operations such as key generation more secure. antonz.org/accepted/run...
antonz.org
Go feature: Secret mode
Automatically erase memory to prevent secret leaks.
060
Philipp Muens @muens.io · 09/01/2026
Here's the GitHub repo: github.com/Threshold-ML...
github.com
GitHub - Threshold-ML-DSA/Threshold-ML-DSA
Contribute to Threshold-ML-DSA/Threshold-ML-DSA development by creating an account on GitHub.
010
Philipp Muens @muens.io · 09/01/2026
Really great to see more research on Threshold ML-DSA (fka Dilithium): eprint.iacr.org/2026/013 The code for the implementation can be found here: zenodo.org/records/1796...
eprint.iacr.org
Efficient Threshold ML-DSA
Threshold signature schemes allow a group of users to jointly generate a digital signature, providing resilience against faults and enhancing decentralization. With the advent of post-quantum cryptogr...
110
Philipp Muens @muens.io · 08/12/2025
Key recovery is a tricky problem. This new paper outlines an interesting approach based on natural language stories which utilizes embeddings behind the scenes. It's an interesting solution at the intersection of Cryptography and Machine Learning. eprint.iacr.org/2025/2206
eprint.iacr.org
LifeXP+: Secure, Usable and Reliable Key Recovery for Web3 Applications
In the Web2 world, users control their accounts using credentials such as usernames and passwords, which can be reset or recovered by centralized servers if the user loses them. In the decentralized W...
020
Philipp Muens @muens.io · 25/10/2025
Very interesting talk when it comes to the SotA of Quantum Computing: www.youtube.com/watch?v=OkVY...
youtube.com
DEF CON 33 - Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it? - K Karagiannis
YouTube video by DEFCONConference
030
Philipp Muens @muens.io · 22/09/2025
Here's the code for their implementation: github.com/TECDSA/ecdsa...
github.com
GitHub - TECDSA/ecdsa_two_round
Contribute to TECDSA/ecdsa_two_round development by creating an account on GitHub.
020
Philipp Muens @muens.io · 22/09/2025
Great to see some progress towards a Two-Round ECDSA Threshold Signature Scheme: eprint.iacr.org/2025/1696
eprint.iacr.org
Threshold ECDSA in Two Rounds
We propose the first two-round multi-party signing protocol for the Elliptic Curve Digital Signature Algorithm (ECDSA) in the threshold-optimal setting, reducing the number of rounds by one compared t...
110
Philipp Muens @muens.io · 11/09/2025
This is an interesting paper that allows for a context to be added to Threshold Decryptions: eprint.iacr.org/2025/279
eprint.iacr.org
Context-Dependent Threshold Decryption and its Applications
In a threshold decryption system a secret key is split across a number of parties so that any threshold of them can decrypt a given ciphertext. We introduce a new concept in threshold decryption call...
010
Philipp Muens @muens.io · 14/08/2025
Here's a link to the repository and its documentation: Repository: github.com/primefactor-... Documentation: pkg.go.dev/github.com/p...
github.com
GitHub - primefactor-io/vtc: Implementation of the Verifiable Timed Commitment scheme
Implementation of the Verifiable Timed Commitment scheme - primefactor-io/vtc
000
Philipp Muens @muens.io · 14/08/2025
To maximize learning I constrained myself to only depend on the standard library and zero 3rd party dependencies. The whole code is covered with various tests which you can use to see how the implementation can be used in practice.
100
Philipp Muens @muens.io · 14/08/2025
I also had to do a lot of pen-and-paper math to figure out how everything works. I'm super happy that it's finally out there! I also learned a ton while working on this which is valuable in and of itself.
100
Philipp Muens @muens.io · 14/08/2025
Implementing the Verifiable Timed Commitment scheme was definitely a hard nut to crack. I started working on this late last year, but there were a lot of missing pieces I had to put in place (e.g. implement the Linearly Homomorphic Time-Lock Puzzle first).
100
Philipp Muens @muens.io · 14/08/2025
One could use this in 2/2 multisigs (e.g. Payment Channels). Before funding the multisig, we could create a signed refund transaction which is timelocked via a VTC. The VTC can be opened after time t which allows one to refund themselves if the co-signer doesn't cooperate.
100
Philipp Muens @muens.io · 14/08/2025
Using this, timelock capabilities can be brought to Blockchains that don't have a scripting language. It furthermore increases privacy as no data regarding the timelock is stored on-chain (the VTC is shared off-chain).
100
Philipp Muens @muens.io · 14/08/2025
This construction has various applications, but the one I'm focusing on is refund transactions. Rather than using the Blockchain's scripting language you can share an encrypted signature over a refund transaction off-chain. This signature can then be recovered after time t.
100
Philipp Muens @muens.io · 14/08/2025
The VTC implementation described in the paper is really elegant as it uses Linearly Homomorphic Time-Lock Puzzles to implement the proof via a cut-and-choose mechanism. I highly recommend you read the paper or watch this presentation to learn more: www.youtube.com/watch?v=X4vO...
youtube.com
Verifiable timed signatures made practical | Cybersecurity Seminars
YouTube video by Monash Information Technology
100
Philipp Muens @muens.io · 14/08/2025
Verifiability is implemented via a proof which guarantees that the value that can be decrypted after time t is the one that was committed to. In our example we could provide the public key and the proof guarantees that the encrypted private key corresponds to the public key.
100
Philipp Muens @muens.io · 14/08/2025
A Verifiable Timed Commitment (VTC) allows one to commit to a value that's encrypted "into the future". For example, I can commit to and encrypt a private key in such a way that it can only be decrypted after time t.
100
Philipp Muens @muens.io · 14/08/2025
Paper: eprint.iacr.org/2020/1563.pdf Repository: github.com/primefactor-... Documentation: pkg.go.dev/github.com/p...
eprint.iacr.org
100
Philipp Muens @muens.io · 14/08/2025
Excited to share my implementation of the paper "Verifiable Timed Signatures Made Practical" by Thyagarajan et al. More specifically I implemented the Verifiable Timed Commitment scheme described in section E.
120
Philipp Muens @muens.io · 13/08/2025
This is a really interesting FHE paper in which BGV is used to build an ALU to do arithmetic as well as logical operations on messages in Z_2^n (e.g. 64 bit machine words). eprint.iacr.org/2025/1449
eprint.iacr.org
REFHE: Fully Homomorphic ALU
We present a fully homomorphic encryption scheme which natively supports arithmetic and logical operations over large "machine words", namely plaintexts of the form $\mathbb{Z}_{2^n}$ (e.g. $n=64$). O...
021
Philipp Muens @muens.io · 12/08/2025
Currently deep down the rabbit hole to finish my implementation of "Verifiable Timed Signatures Made Practical" eprint.iacr.org/2020/1563 While doing so I had to update my LHTLP implementation. It now features a range proof and new homomorphic operations: github.com/primefactor-...
eprint.iacr.org
Verifiable Timed Signatures Made Practical
A verifiable timed signature (VTS) scheme allows one to time-lock a signature on a known message for a given amount of time $T$ such that after performing a sequential computation for time $T$ anyone ...
000
Philipp Muens @muens.io · 06/08/2025
ZKSecurity just dropped this truly awesome PlonK tutorial: plonk.zksecurity.xyz
plonk.zksecurity.xyz
How to 𝒫𝔩𝔬𝔫𝒦
Interactive 𝒫𝔩𝔬𝔫𝒦 Zero-Knowledge Proof Tutorial
011
Philipp Muens @muens.io · 29/07/2025
This is an interesting read on how EdDSA's hash-based key derivation (RFC 8032) can be used to compute PQ-ZKPs for private key ownership proofs: eprint.iacr.org/2025/1368 This is good news as it allows for an easier transition towards Post Quantum secure cryptocurrencies.
eprint.iacr.org
Post-Quantum Readiness in EdDSA Chains
The impending threat posed by large-scale quantum computers necessitates a reevaluation of signature schemes deployed in blockchain protocols. In particular, blockchains relying on ECDSA, such as Bitc...
010
Philipp Muens @muens.io · 23/07/2025
Ingonyama just published the first three lessons of their "Foundations of High-Speed Cryptography" course 👀 www.ingonyama.com/foundations-...
ingonyama.com
Foundations of High-Speed Cryptography Course
Start with a gentle introduction to core cryptographic primitives, explore the basics of hardware acceleration, and then apply them to build optimized systems with ICICLE.
010
Philipp Muens @muens.io · 18/07/2025
That would be awesome! For me first thing in the morning is checking the new publications on eprint.iacr.org (also followed arxiv.org/list/cs.CR/recent but there’s too much noise IMHO).
arxiv.org
Cryptography and Security
100
Philipp Muens @muens.io · 18/07/2025
This paper looks really interesting: eprint.iacr.org/2025/770 ZKPs for (F)HE Schemes based on Ring-LWE. FHE + ZKPs are a dream combo.
eprint.iacr.org
ZHE: Efficient Zero-Knowledge Proofs for HE Evaluations
Homomorphic Encryption (HE) allows computations on encrypted data without decryption. It can be used where the users’ information are to be processed by an untrustful server, and has been a popular ch...
020
Philipp Muens @muens.io · 09/07/2025
The recording of the Diamond iO talk by the Machina iO team that was held during the Simon Institute's "Obfuscation" workshop was just uploaded: www.youtube.com/watch?v=1RcK...
youtube.com
Diamond iO: Lattice-Based Obfuscation without Bootstrapping from Functional Encryption, toward...
YouTube video by Simons Institute
020
Philipp Muens @muens.io · 04/07/2025
This is a great paper that explains how to obtain indistinguishability obfuscation (iO) via recursive Functional Encryption: piazza.com/class_profil... It's basically a simplified version of the [BV15] paper: eprint.iacr.org/2015/163
piazza.com
010