Unraveling end-to-end encryption: what, why, and how?
End-to-end encryption (E2EE) stands as the gold standard for digital privacy. But how does this
cryptographic shield truly work—and why does it matter for businesses and individuals alike? In
this session, we will unpack why E2EE isn’t just a buzzword but a necessity in a world full of
challenges such as AI-driven surveillance, sophisticated malware, and data breaches.
We will explore the meaning of E2EE in cryptography, presenting why simple mechanisms to
achieve authenticity and confidentiality do not suffice. We will borrow examples from cloud
storage
and secure messaging to understand how protocols can self-heal after breaches, ensuring past
and future data stays locked even if current keys are stolen.
Finally, we will walk through the architecture of the Signal Protocol -- the backbone of
WhatsApp,
Facebook Messenger, Signal, and others. We will build its "double ratchet" system from scratch,
understanding how its ephemeral keys and resilience against device compromise set the
benchmark for modern secure messaging.
Emerging Privacy Threats in Mobile Platforms
Seminario impartido por Narseo Vallina (IMDEA Networks) sobre amenazas emergentes a la privacidad en plataformas móviles.
Olingo: Efficient, Distributed, Non-Interactive, and Identifiable Threshold Lattice Signatures?
We propose a new and efficient threshold lattice signature framework called Olingo. Our
framework
is compatible with the most efficient rejection-free lattice signature scheme Raccoon (Crypto
2024)
and offers all the desired properties required for implementing threshold signatures from
standard
quantum safe assumptions in real-world systems: small keys and signatures, few rounds and
reasonable communication, non-interactive signing, distributed key generation, and identifiable
aborts. Olingo is the only scheme satisfying all of these requirements.
Identifiable aborts are particularly important; otherwise, a malicious party could misbehave in
the
signature computation so that the final signature does not verify and there is no mechanism to
identify the malicious party and remove it from the protocol. This can lead to a
denial-of-service
attack and prevent honest users from ever producing a signature. Our starting point is the
framework by Gur, Katz, and Silde (PQCrypto 2024). We change the underlying signature scheme,
go from two to three rounds of communication, and then apply numerous improvements and
optimizations for our state-of-the-art instantiation with all the above properties. We provide a
detailed proof of security for the new framework and its properties, and present concrete
parameters and benchmarks.
For 128 bits of security, up to 1024 users, and 260 signatures, we provide verification keys of
3.8 KB,
signatures of 12.9 KB, and communication of 432 KB total per party. An optimistic
non-interactive
version of our scheme requires only 82 KB in online communication per party when the message to
be signed is known.
This is joint work with Kamil Doruk Gur (UMD), Patrick Hough (Oxford), Jonathan Katz (Google /
UMD), and Caroline Sandsbråten (NTNU).
Sesión de Clausura
Entrega de premios y diplomas a las mejores soluciones para los retos propuestos y Conferencia de Clausura.
Vector Commitments: from theory to applications
Conferencia de clausura impartida por Dario Fiore (IMDEA Software).
Descargar Programa