Migrating protocols to PQ: the good, the bad, and the ugly
Migrating TLS to PQ seems easy. Just write in “PQ” and “KEM”, and we’re done, right? In this talk, I will show that things are unfortunately not that easy. Just using ML-DSA may …
Migrating TLS to PQ seems easy. Just write in “PQ” and “KEM”, and we’re done, right? In this talk, I will show that things are unfortunately not that easy. Just using ML-DSA may …
I presented a Formal Analysis Triage Team report on Extended Key Usage (EKU) in the TLS working group session.
Key exchange in TLS is now mostly PQ! But what about authentication? In this talk, I discussed some of the ongoing work to make the costs of PQ certificates acceptable so that …
Conference talk presenting a unified framework for deniability analysis of Signal handshake protocols, including a deniable ring signature from Falcon/MAYO.
Conference talk presenting the BAKE framework for Signal's handshake protocols, covering X3DH, PQXDH, and the fully post-quantum RingXKEM.
I presented a status update on our IETF draft on stateful HBS state management, now adopted as a PQUIP working group document.
Invited talk for Comcast Research's Monthly Research Presentation Series on the costs and challenges of post-quantum authentication.
I presented a status update on our IETF draft on stateful HBS state management.
In this talk, I explain that although the focus on and progress with post-quantum key exchange is great, that does not mean that we should relax about post-quantum authentication. …
I presented an update on the IETF draft regarding state management for stateful hash-based signature schemes.