A tale of two models: formal verification of KEMTLS in Tamarin
We prove the security of KEMTLS in two Tamarin models. One mode is based on the Cremers et al. model of TLS 1.3; the other closely resembles our pen-and-paper proofs. These models …
We prove the security of KEMTLS in two Tamarin models. One mode is based on the Cremers et al. model of TLS 1.3; the other closely resembles our pen-and-paper proofs. These models …
The recent KEMTLS protocol (Schwabe, Stebila and Wiggers,CCS’20) is a promising design for a quantum-safe TLS handshake protocol. Focused on the web setting, wherein clients learn …
Invited lecture about TLS, its history and making TLS post quantum. I also discuss KEMTLS.
We make KEMTLS more efficient in scenarios where the client already has the server's long-term public key, for example through caching or because it's pre-installed.
KEMTLS (CCS 2020) is a novel alternative to the Transport Layer Security (TLS) handshake that integrates post-quantum algorithms. It uses a key encapsulation mechanism (KEM) for …
Talk about KEMTLS on Cloudflare TV
Talk about Post-Quantum TLS without Handshake Signatures at RWC 2021 (virtual).
Conference talk about Post-Quantum TLS without Handshake Signatures at ACM CCS (virtual).
Talk about Post-Quantum TLS without Handshake Signatures at the Lorentz Workshop (virtual)
Department Lunch Talk about KEMTLS