Based on joint work with Dan Boneh, Hart Montgomery, and David J. Wu: eprint 2017/100 and eprint 2017/380.

The talk will focus on GGH15. It will be composed of 3 parts: (1) The description of GGHRSW obfuscator; (2) The description of the GGH 15 maps; (3) The analysis of the GGH15 based obfuscator.

Based on joint work with Craig Gentry and Shai Halevi: eprint 2016/998.

– Our construction for reusable garbled circuits achieves the optimal “full” simulation based security.

– When generalised to handle Q queries for any fixed polynomial Q , our ciphertext size grows additively with Q^2 . Such query dependence on ciphertext size has only been achieved in a weaker security game before [Agr17].

– The ciphertext of our scheme can be divided into a succinct data dependent component and a non-succinct data independent component. This makes it well suited for optimization in an online- offline model that allows a majority of the computation to be performed in an offline phase, before the data becomes available.

Security of our scheme may be based on the Learning With Errors assumption (LWE) or its ring variant (Ring-LWE). To achieve our result, we provide new public key and ciphertext evaluation algorithms in the context of functional encryption. These algorithms are general, and may find application elsewhere.

Based on joint work with Alon Rosen: eprint 2016/361.

Consequently, the heuristic security of SPRING is evaluated using known attacks and the complexity of the best known algorithms for breaking the underlying hard problem. We revisit the efficiency and security of SPRING when used as a pseudo-random generator. We propose a new variant which is competitive with the AES in counter mode without hardware AES acceleration, and about four times slower than AES with hardware acceleration. In terms of security, we improve some previous analysis of SPRING and we estimate the security of our variant against classical algorithms and attacks. Finally, we implement our variant using AVX2 instructions, resulting in high performances on high-end desktop computers.

This is joint work with Charles Bouillaguet, Pierre-Alain Fouque and Paul Kirchner.

This is joint work with Carlos Aguilar-Melchor, Pierre-Alain Fouque, Vadim Lyubashevsky, Thomas Pornin and Thomas Ricosset.

We now turn to more traditional power analysis and EMA, and propose several attacks that can yield a full key recovery in that setting, the most striking of which exploits an easy SPA leakage in the rejection sampling algorithm used during signature generation. Existing implementations of that rejection sampling step, which is essential for security, actually leak the relative norm of the secret key in the totally real subfield of the cyclotomic field used in BLISS. We show how an extension to power-of-two cyclotomic fields of an algorithm due to Howgrave-Graham and Szydlo (ANTS 2004) can be used to recover the secret key from that relative norm, at least when the absolute norm is easy to factor (which happens for a significant fraction of secret keys). The entire attack is validated in practice using EMA experiments against an 8-bit AVR microcontroller, and an implementation of our generalized Howgrave-Graham–Szydlo algorithm in PARI/GP.

The talk will be based on this article.

This is joint work with Pierre-Alain Fouque, Benoît Gérard and Mehdi Tibouchi.

The talk will be based on this article.

This is joint work with Fabrice Benhamouda and Helger Lipmaa.

This is joint work with Benoît Libert, San Ling, Khoa Nguyen and Huaxiong Wang.

This is joint work with Shweta Agrawal, Sanjay Bhattacherjee, Duong Hieu Phan and Shota Yamada.

This is joint work with Fabrice Benhamouda, Léo Ducas and Willy Quach.

The talk will be based on this article.

This is joint work with Ilia Iliashenko and Frederik Vercauteren.

* The Gentry-Szydlo algorithm to perform a halving of dimension by working in the totally real subfield of the cyclotomic field.

* A q-descent procedure using lattice reduction and ideal arithmetic to reduce the problem to PIP for L(1/2)-smooth ideals.

* A linear algebra phase to solve the L(1/2)-smooth instances.

All along the presentation we will emphasize on the relations between the commutative algebra side (ideals arithmetic, manipulations of number field elements,...) and the geometric side (norms related issues, lattice reduction,...).

The talk will be based on this article.

Joint work with Pierre-Alain Fouque, Alexandre Gélin and Paul Kirchner.

The talk will be based on this article.

Joint work with Ronald Cramer and Benjamin Wesolowski.

Joint work with Elena Kirshanova.

The talk will be based on this article.

Joint work with Wessel P.J. van Woerden.

The talk will be based on this article.

Joint work with Vinod Vaikuntanathan, Hoeteck Wee and Daniel Wichs.

The talk will be based on this article.

Joint work with Nicolas Gama and Mariya Georgieva and Malika Izabachène.

The talk will be based on this article.

Joint work with Rafael Del Pino, Michele Minelli and Hoeteck Wee.

The talk will be based on this article.

Joint work with Yehuda Lindell and Nigel P. Smart.

The talk will be based on this article.

Joint work with Martin R. Albrecht, Dennis Hofheinz, Enrique Larraia and Kenneth G. Paterson.

The talk will be based on this article.

The talk will be based on this article.

Joint work with Sebastian Faust and Daniele Venturi.

The talk will be based on this article.

Joint work with Joris Barrier, Serge Guelton, Adrien Guinet, Marc-Olivier Killijian and Tancrède Lepoint .

This is work in progress with Alex van Poppelen and Wessel van Woerden

The talk will be based on this article.

Joint work with Erdem Alkim, Léo Ducas and Thomas Pöppelmann.

Joint work with Catalin Cocis, Fabien Laguillaumlie and Adeline Langlois.

Joint work with Arnold Neumaier.

The talk will be based on this article and this article.

Joint work with Baojian Zhou, Wai Ho Mow and Xiao-Wen Chang.

The talk will be based on this article.

Joint work with Céline Chevalier, Adrian Thillard, and Damien Vergnaud.

The talk will be based on this article.

Joint work with Sergey Gorbunov and Vinod Vaikuntanathan.

The talk will be based on this article.

Joint work with Shweta Agrawal.

The talk will be based on this article.

Joint work with Léo Ducas.

Joint work with Anja Becker and Antoine Joux.

The talk will be based on this article.

Joint work with Alexander May.

Joint work with Martin R. Albrecht, Carlos Cid and Jean-Charles Faugère.

The talk will be based on this article. Joint work with San Ling and Huaxiong Wang.

The talk will be based on this article. Joint work with Martianus Frederic Ezerman, Hyung Tae Lee, San Ling and Huaxiong Wang.

Joint work with Carlos Aguilar Melchor, Olivier Blazy and Jean-Christophe Deneuville.

