Post-Quantum

Post-Quantum TLS without handshake signatures at RWC 2021 featured image

Post-Quantum TLS without handshake signatures at RWC 2021

Talk about Post-Quantum TLS without Handshake Signatures at RWC 2021 (virtual).

avatar
Thom Wiggers
Post-Quantum TLS without handshake signatures featured image

Post-Quantum TLS without handshake signatures

Conference talk about Post-Quantum TLS without Handshake Signatures at ACM CCS (virtual).

avatar
Thom Wiggers
Post-Quantum TLS without handshake signatures featured image

Post-Quantum TLS without handshake signatures

Talk about Post-Quantum TLS without Handshake Signatures at the Lorentz Workshop (virtual)

avatar
Thom Wiggers
Lunch talk: Post-Quantum TLS without handshake signatures featured image

Lunch talk: Post-Quantum TLS without handshake signatures

Department Lunch Talk about KEMTLS

avatar
Thom Wiggers

Post-Quantum TLS without handshake signatures

We present an alternative to TLS 1.3, by authenticating using only Key-Encapsulation Mechanisms. This allows us to get rid of handshake signatures, as post-quantum signature …

Peter Schwabe

Post-Quantum TLS with KEMs

We investigate getting rid of signatures in TLS

avatar
Thom Wiggers

Rephrasing TLS key exchange in terms of KEMs

In the RFC for TLS 1.3 (RFC8446) especially, the key exchange is defined in terms of (EC)DH key shares being exchanged. This limits us to algorithms which support non-interactive …

avatar
Thom Wiggers

Using (post-quantum) KEMs in TLS 1.3

The new TLS 1.3 standard \[1\] does not yet provide any support for post-quantum algorithms. In this blog post we’ll be talking about how we could negotiate a post-quantum key …

avatar
Thom Wiggers