RSSAmplifier

Blog

Douglas Stebila

Douglas Stebila's website

douglas.stebila.caRSS feed ↗107 posts

Latest posts

Research paper: A real-world law-enforcement hack: the case of Encrochat

Abstract: In 2020, a coordinated law-enforcement effort infiltrated Encrochat, an end-to-end encrypted service provider, exfiltrating historical and real-time data and metadata over months. Encrochat was used extensively by organised crime, and the data from the operation was used as supporting evidence in over 6,000 arrests and related prosecutions across Europe. Encrochat's architecture was…

Research paper: Post-quantum traditional (PQ/T) hybrid key agreement mechanisms for TLS 1.3

Abstract: This document defines three hybrid key agreement mechanisms for TLS 1.3 — X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 — that combine the post-quantum ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) with an ECDHE (Ephemeral Elliptic Curve Diffie-Hellman) exchange.

Research paper: Kemeleon encodings

Abstract: This document specifies Kemeleon encoding algorithms for encoding ML-KEM encapsulation keys and ciphertexts as random bytestrings. Kemeleon encodings provide obfuscation of encapsulation keys and ciphertexts, relying on module LWE assumptions.

Research paper: Hybrid key exchange in TLS 1.3

Abstract: Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum cryptography. This document provides a construction for hybrid key exchange in the Transport Layer…

Research paper: Security Considerations for FrodoKEM

Abstract: ISO standardized FrodoKEM in June 2026. This document provides security guidance for FrodoKEM for use in protocols. It explains what security claims protocol designers may rely on, what assumptions and conditions are required, what parameter sets are in scope, and what implementors need to do to use FrodoKEM safely. The scope follows the current FrodoKEM Internet-Draft.

Research paper: FrodoKEM: key encapsulation from learning with errors

Abstract: This internet draft specifies FrodoKEM, an IND-CCA2 secure Key Encapsulation Mechanism (KEM).

Research paper: On the multi-target security of post-quantum key encapsulation mechanisms

Abstract: Practical deployments of key encapsulation mechanisms (KEMs) may entail large servers each using their public keys to communicate with potentially millions of clients simultaneously. While the standard IND-CCA security definition for KEMs considers only a single challenge public key and single challenge ciphertext, it can be relevant to consider multi-target scenarios where the adversary…

Research paper: StarHunters: secure hybrid post-quantum KEMs from IND-CCA2 PKEs

Abstract: This paper formally specifies and analyzes the CK hybrid key encapsulation mechanism (KEM) construction from the IRTF CFRG's recent draft on hybrid (post-quantum/traditional) KEMs CK combines two KEMs using a PRF to produce a hybrid KEM. Unlike the QSF framework of Barbosa et al., which combines an IND-CCA KEM with a nominal group (Diffie-Hellman-style), CK combines a C2PRI-secure…

Research paper: Split-key PRFs and extended hybrid security for KEM combiners

Abstract: Key encapsulation mechanism (KEM) combiners allow for the construction of hybrid KEMs that are secure as long as at least one of several underlying ingredient KEMs remains secure. In PKC 2018, Giacon, Heuer, and Poettering showed that parallel KEM combiners whose core function is a split-key pseudorandom function (PRF) satisfy IND-CCA security if at least one of the ingredient KEMs…

Research paper: KEM-based authentication for TLS 1.3

Abstract: This document gives a construction for a Key Encapsulation Mechanism (KEM)-based authentication mechanism in TLS 1.3. This proposal authenticates peers via a key exchange protocol, using their long-term (KEM) public keys.

Research paper: FrodoKEM: A CCA-secure learning with errors key encapsulation mechanism

Abstract: Large-scale quantum computers capable of implementing Shor's algorithm pose a significant threat to the security of the most widely used public-key cryptographic schemes. This risk has motivated substantial efforts by standards bodies and government agencies to identify and standardize quantum-safe cryptographic systems. Among the proposed solutions, lattice-based cryptography has…

Research paper: Verifiable decapsulation: recognizing faulty implementations of post-quantum KEMs

Abstract: Cryptographic schemes often contain verification steps that are essential for security. Yet, faulty implementations missing these steps can easily go unnoticed, as the schemes might still function correctly. A prominent instance of such a verification step is the re-encryption check in the Fujisaki-Okamoto (FO) transform that plays a prominent role in the post-quantum key encapsulation…

Research paper: Hybrid obfuscated key exchange and KEMs

Abstract: Hiding the metadata in Internet protocols serves to protect user privacy, dissuade traffic analysis, and prevent network ossification. Fully encrypted protocols require even the initial key exchange to be obfuscated: a passive observer should be unable to distinguish a protocol execution from an exchange of random bitstrings. Deployed obfuscated key exchanges such as Tor's pluggable…

Photo gallery: UK • 2025

Photo gallery: UK • 2025

Photo gallery: Spain • 2025

Photo gallery: Spain • 2025

Photo gallery: Bulgaria • 2025

Photo gallery: Bulgaria • 2025

Research paper: Falsifiability, composability, and comparability of game-based security models for key exchange protocols

Abstract: A security proof for a key exchange protocol requires writing down a security definition. Authors typically have a clear idea of the level of security they aim to achieve. Defining the model formally additionally requires making choices on games vs. simulation-based models, partnering, on having one or more Test queries and on adopting a style of avoiding trivial attacks: exclusion,…

Research paper: ProofFrog: a tool for verifying game-hopping proofs

Abstract: Cryptographic proofs allow researchers to provide theoretical guarantees on the security that their constructions provide. A proof of security can completely eliminate a class of attacks by potential adversaries. Human fallibility, however, means that even a proof reviewed by experts may still hide flaws or outright errors. Proof assistants are software tools built for the purpose of…

Research paper: TurboTLS: TLS connection establishment with 1 less round trip

Abstract: We show how to establish TLS connections using one less round trip. In our approach, which we call TurboTLS, the initial client-to-server and server-to-client flows of the TLS handshake are sent over UDP rather than TCP. At the same time, in the same flights, the three-way TCP handshake is carried out. Once the TCP connection is established, the client and server can complete the final…

Research paper: Advances in Cryptology – CRYPTO 2024, Part X

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part IX

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part VIII

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part VII

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part VI

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part V

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part IV

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part III

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part II

Abstract:

Research paper: Advances in Cryptology – CRYPTO 2024, Part I

Abstract:

Presentation: A Real-World Law-Enforcement Breach of End-to-End Encrypted Messaging: The Case of Encrochat

A Real-World Law-Enforcement Breach of End-to-End Encrypted Messaging: The Case of Encrochat, presented at Workshop on Attacks in Cryptography 7 (WAC7)

Photo gallery: Copenhagen • 2024

Photo gallery: Copenhagen • 2024

Photo gallery: Norway • 2024

Photo gallery: Norway • 2024

Research paper: Quantum-safe account recovery for WebAuthn

Abstract: WebAuthn is a passwordless authentication protocol which allows users to authenticate to online services using public-key cryptography. Users prove their identity by signing a challenge with a private key, which is stored on a device such as a cell phone or a USB security token. This approach avoids many of the common security problems with password-based authentication. WebAuthn's…

Photo gallery: Switzerland • 2024

Photo gallery: Switzerland • 2024

Photo gallery: Italy • 2024

Photo gallery: Italy • 2024

Photo gallery: Taiwan • 2024

Photo gallery: Taiwan • 2024

Photo gallery: Barcelona • 2024

Photo gallery: Barcelona • 2024

Blog post: Security analysis of Apple's iMessage PQ3 protocol

Today Apple announced its new iMessage PQ3 protocol, which is an update to the cryptographic protocol used in iMessage that adds post-quantum cryptography. I worked with Apple over the past few months to analyze the protocol and show that it meets the security goals, and have written a paper describing my findings. I’m glad to see the adoption of post-quantum cryptography protocols continuing.

Research paper: Security analysis of the iMessage PQ3 protocol

Abstract: The iMessage PQ3 protocol is an end-to-end encrypted messaging protocol designed for exchanging data in long-lived sessions between two devices. It aims to provide classical and post-quantum confidentiality for forward secrecy and post-compromise secrecy, as well as classical authentication. Its initial authenticated key exchange is constructed from digital signatures plus elliptic curve…

Blog post: Launch of the Linux Foundation's Post-Quantum Cryptography Alliance

Today is the launch of the Post-Quantum Cryptography Alliance, a new open-source software foundation within the Linux Foundation, which will be the new home of the Open Quantum Safe project.

Blog post: New York Times article on post-quantum cryptography

The New York Times has an article today about the need to transition to post-quantum cryptography, and the governemnt and academic efforts over the past few years.

Research paper: Making an asymmetric PAKE quantum-annoying by hiding group elements

Abstract: The KHAPE-HMQV protocol is a state-of-the-art highly efficient asymmetric password-authenticated key exchange protocol that provides several desirable security properties, but has the drawback of being vulnerable to quantum adversaries due to its reliance on discrete logarithm-based building blocks: solving a single discrete logarithm allows the attacker to perform an offline dictionary…

Presentation: New Initiatives in Open-Source Post-Quantum Software

New Initiatives in Open-Source Post-Quantum Software, presented at International Cryptographic Module Conference 2023

Photo gallery: Japan • 2023

Photo gallery: Japan • 2023

Research paper: X25519Kyber768Draft00 hybrid post-quantum key agreement

Abstract: This memo defines X25519Kyber768Draft00, a hybrid post-quantum key exchange for TLS 1.3.

Presentation: Standardizing post-quantum cryptography at the IETF

Standardizing post-quantum cryptography at the IETF, presented at Real World PQC

Research paper: A formal treatment of distributed key generation, and new constructions

Abstract: In this work, we present a novel generic construction for a Distributed Key Generation (DKG) scheme. Our generic construction relies on three modular cryptographic building blocks. The first is an aggregatable Verifiable Secret Sharing (AgVSS) scheme, the second is a Non-Interactive Key Exchange (NIKE) scheme, and the third is a secure hash function. We give formal definitions for the…

Presentation: Rethinking Internet protocols for post-quantum cryptography

Rethinking Internet protocols for post-quantum cryptography, presented at Virginia Tech

Research paper: Proof-of-possession for KEM certificates using verifiable generation

Abstract: Certificate authorities in public key infrastructures typically require entities to prove possession of the secret key corresponding to the public key they want certified. While this is straightforward for digital signature schemes, the most efficient solution for public key encryption and key encapsulation mechanisms (KEMs) requires an interactive challenge-response protocol, requiring…

Research paper: A tale of two models: formal verification of KEMTLS via Tamarin

Abstract: KEMTLS is a proposal for changing the TLS handshake to authenticate the handshake using long-term key encapsulation mechanism keys instead of signatures, motivated by trade-offs in the characteristics of post-quantum algorithms. Prior proofs of security of KEMTLS and its variant KEMTLS-PDK have been hand-written proofs in the reductionist model under computational assumptions. In this…