
BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Laboratoire de Mathématiques de Versailles - ECPv6.17.3//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Laboratoire de Mathématiques de Versailles
X-ORIGINAL-URL:https://lmv.math.cnrs.fr
X-WR-CALDESC:Évènements pour Laboratoire de Mathématiques de Versailles
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:Europe/Paris
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20240331T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20241027T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20250330T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20251026T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20260329T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20261025T010000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20250304T110000
DTEND;TZID=Europe/Paris:20250304T120000
DTSTAMP:20250307T094139Z
CREATED:20250127T215014Z
LAST-MODIFIED:20250307T094139Z
UID:13619-1741086000-1741089600@lmv.math.cnrs.fr
SUMMARY:CRYPTO : Kévin Carrier - Combinatorial Attacks on Code-based and Lattice-based Cryptosystems
DESCRIPTION:The decoding problem is fundamental in post-quantum cryptography. It can be broadly described as essentially solving a linear system with a non-linear constraint on the solution. Phrased this way\, the problem applies to both code-based and lattice-based cryptography. For example\, the linear system may be defined over FF_q\, with the non-linear constraint being a condition on the Hamming weight of the solution (McEliece\, BIKE\, HQC\, Wave\, SDitH…) or even a condition on the subfield in which the solution resides (CROSS). The system may also be defined over FF_q^m\, with the non-linear constraint being a condition on the rank of the vector space spanned by the solution vectors (Mirath\, Ryde). In lattice-based cryptography\, the system is generally defined over ZZ_q\, with the non-linear constraint being a condition on the Euclidean length of the solution (Kyber\, Falcon\, Dilithium\, Hawk…). The list above is far from exhaustive and can extend to other areas such as Fully Homomorphic Encryption (FHE) or the blind code recognition problem (reverse of telecomunication). \nFor a long time in cryptography\, codes and lattices evolved in parallel without much interaction. A unified approach allows for a better understanding of new cryptosystems and their fundamental limits. Whether designing or attacking\, it is interesting for each field to draw inspiration from the other. \nCombinatorial techniques for solving the decoding problem (in both codes and lattices) can be classified into two categories: primal attacks and dual attacks. Primal attacks aim to recover a set of information about the solution\, essentially a compressed description of the solution. Exhaustive search can then be accelerated using techniques like the Birthday Paradox (collision search). More recently\, techniques based on nearest-neighbor searches have emerged and significantly sped up primal attacks. The nearest-neighbor problem involves finding close pairs in a list. The notion of closeness can be extended to adapt to the non-linear constraint of the original decoding problem. However\, this requires adapting known techniques to these different variants of the nearest-neighbor problem. \nIt turns out that primal decoding techniques are often more effective when there are few equations in the system relative to the number of unknowns. Therefore\, when the number of equations is close to the number of unknowns\, is it possible to reduce the problem to another decoding problem where the number of equations is smaller? One approach to this is to dualize the decoding problem: instead of searching for a solution in a specific subspace\, could we reduce the problem to finding a solution in the orthogonal/dual subspace? Some recent attacks\, known as dual attacks\, offer an initial attempt at such a reduction. However\, dual attacks are a topic of controversy. In particular\, the recent dual attack by Matzov\, which claims to significantly lower the security level of Kyber\, a lattice-based cryptosystem currently being standardized by NIST\, has not been widely accepted. The analysis behind this attack relies on a set of assumptions that\, in certain scenarios\, have been shown to contradict established theorems or well-tested heuristics. Nonetheless\, we present new techniques for analyzing dual attacks. Specifically\, we avoid the same independence assumption made in Matzov’s work\, allowing us to reassess the complexity of dual attacks on Kyber and demonstrate that its security levels fall below the NIST requirements.
URL:https://lmv.math.cnrs.fr/evenenement/tba-kevin-carrier/
LOCATION:Bâtiment Fermat\, salle 4205
CATEGORIES:Séminaire CRYPTO
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20250305T110000
DTEND;TZID=Europe/Paris:20250305T120000
DTSTAMP:20250307T094122Z
CREATED:20250227T105220Z
LAST-MODIFIED:20250307T094122Z
UID:13794-1741172400-1741176000@lmv.math.cnrs.fr
SUMMARY:CRYPTO : Sofia Zebboudj : Authentification Quantique
DESCRIPTION:Bien que certains cryptosystèmes classiques soient considérés comme sûrs avec la technologie actuelle\, les avancées en informatique quantique pourraient bientôt remettre en cause la robustesse de certains mécanismes cryptographiques. À titre d’exemple\, les algorithmes quantiques de factorisation des nombres premiers et de résolution des problèmes de logarithme discret fragilisent les bases sur lesquelles reposent la plupart des cryptosystèmes classiques. La cryptographie quantique offre une alternative prometteuse en exploitant certains principes de la mécanique quantique (principes d’incertitude de Heisenberg et de non-clonage) pour garantir la sécurité des communications. \nCette présentation se focalise plus particulièrement sur l’authentification quantique. Un nouveau protocole de génération de codes d’authentification de message (MAC) combinant traitements quantiques et classiques y sera présenté. Cette solution représente une avancée vers des protocoles d’authentification résistants aux menaces quantiques et classiques et ouvre la voie à des applications sécurisées et plus réalisables pour les réseaux de communication de demain.
URL:https://lmv.math.cnrs.fr/evenenement/crypto-sofia-zebboudj-authentification-quantique/
LOCATION:Bâtiment Fermat\, salle 4205
CATEGORIES:Séminaire CRYPTO
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20250310T110000
DTEND;TZID=Europe/Paris:20250310T120000
DTSTAMP:20250314T122653Z
CREATED:20250224T101845Z
LAST-MODIFIED:20250314T122653Z
UID:13785-1741604400-1741608000@lmv.math.cnrs.fr
SUMMARY:CRYPTO : Ky Nuguyen - Multi-Client Functional Encryption with Public Inputs and Strong Security
DESCRIPTION:Recent years have witnessed a significant development for functional encryption (FE) in the multi-user setting\, particularly with multi-client functional encryption (MCFE). The challenge becomes more important when combined with access control\, such as attribute-based encryption (ABE)\, which was actually not covered syntactically by the public-key FE nor semantically by the secret-key MCFE frameworks. On the other hand\, as for complex primitives\, many works have studied the admissibility of adversaries to ensure that the security model encompasses all real threats of attacks.\n\n  1. At a conceptual level\, by adding a public input to FE/MCFE\, we cover many previous primitives\, notably attribute-based function classes. Furthermore\, with the strongest admissibility for inner-product functionality\, our framework is quite versatile\, as it encrypts multiple sub-vectors\, allows repetitions and corruptions\, and eventually also encompasses public-key FE and classical ABE\, bridging the private setting of MCFE with the public setting of FE and ABE.\n\n  2. Finally\, we propose an MCFE with public inputs with the class of functions that combines inner-products (on private inputs) and attribute-based access-control (on public inputs) for LSSS policies. We achieve the first AB-MCFE for inner products with strong admissibility (from Nguyen et al.\, ACNS’23) and with adaptive security.\nIn the end\, our concrete MCFE leads to MIFE for inner products\, public-key single-input inner-product FE with LSSS key-policy\, and KP-ABE for LSSS\, with adaptive security. Previous AB-MCFE constructions are either restricted in terms of weaker admissibility (Nguyen et al.\, ASIACRYPT’22) or considers a slightly larger functionality of attribute-weighted sum but with only selective security (Agrawal et al.\, CRYPTO’23).\n\nThis is a joint work with Duong Hieu Phan (Télécom Paris) and David Pointcheval (ENS-PSL\, Cosmian)\, available at https://eprint.iacr.org/2024/740
URL:https://lmv.math.cnrs.fr/evenenement/crypto-ky-nuguyen-multi-client-functional-encryption-with-public-inputs-and-strong-security/
LOCATION:Bâtiment Fermat\, salle 4205
CATEGORIES:Séminaire CRYPTO
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20250311T110000
DTEND;TZID=Europe/Paris:20250311T120000
DTSTAMP:20250314T122801Z
CREATED:20250127T215121Z
LAST-MODIFIED:20250314T122801Z
UID:13621-1741690800-1741694400@lmv.math.cnrs.fr
SUMMARY:CRYPTO : Christophe Levrat - A new algorithm solving the matrix code equivalence problem
DESCRIPTION:The matrix code equivalence problem consists\, given two k-dimensional vector spaces C\,D of m x n matrices over a finite field\, in finding invertible matrices P and Q such that D=PCQ. Recent signature schemes such as MEDS and ALTEQ relate their security to the hardness of this problem. Naranayan et al. recently published an algorithm solving this problem in the case k = n =m in O(q^{k/2}) operations. In this talk\, we present a different algorithm which solves the general matrix equivalence problem. Our approach consists in reducing the problem to the matrix code conjugacy problem\, i.e. the case P=Q. For the latter problem\, a natural invariant based on the hull of the code can be used. Next\, the equivalence of codes can be deduced using a usual list collision argument. For k=m=n\, our algorithm achieves a similar complexity to the aforementioned reference. However\, it extends to a much broader range of parameters. This is joint work with Alain Couvreur.
URL:https://lmv.math.cnrs.fr/evenenement/tba-christophe-levrat/
LOCATION:Bâtiment Fermat\, salle 4205
CATEGORIES:Séminaire CRYPTO
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20250314T110000
DTEND;TZID=Europe/Paris:20250314T120000
DTSTAMP:20250314T122745Z
CREATED:20250224T100043Z
LAST-MODIFIED:20250314T122745Z
UID:13782-1741950000-1741953600@lmv.math.cnrs.fr
SUMMARY:CRYPTO: Rocco Mora - The Regular Multivariate Quadratic Problem
DESCRIPTION:In this talk\, we introduce a new NP-complete variant of the multivariate quadratic problem. The computational challenge involves finding a solution to an algebraic system that meets the « regular » constraint\, meaning that each block of the solution vector contains only one nonzero entry. Following this\, we adapt and compare various techniques of cryptanalysis to study the asymptotic complexity of the average instance.
URL:https://lmv.math.cnrs.fr/evenenement/crypto-rocco-mora-tba/
LOCATION:Bâtiment Fermat\, salle 4205
CATEGORIES:Séminaire CRYPTO
END:VEVENT
END:VCALENDAR