SAC logo
Selected Areas in Cryptography 2026
University of Ottawa
August 24–28, 2026
Ottawa, Ontario
August 24–28, 2026
Ottawa, Ontario
SAC logo
Selected Areas in Cryptography 2026

University of Ottawa
August 24–28, 2026
Ottawa, Ontario


Schedule


Mon Aug 24
9:00 AM – 10:15 AM

SAC Summer School - Lattice-based cryptography, Part 1

Lattice-Based Cryptography: Foundations

Huck Bennett, University of Colorado Boulder

In my first talk, I will give an introduction to lattices and lattice-based cryptography. I will present the foundational Learning With Errors (LWE) problem and will show how to use it to construct public-key cryptography. I will then discuss optimizations to this basic scheme, including those used in the recently standardized ML-KEM (a.k.a. Kyber) cryptosystem. I will conclude by briefly discussing constructions of advanced cryptographic primitives, like Fully Homomorphic Encryption (FHE).

Mon Aug 24
10:15 AM – 10:45 AM

Coffee Break


Mon Aug 24
10:45 AM – 12:00 PM

SAC Summer School - Lattice-based cryptography, Part 2

Lattice-Based Cryptography: New Directions

Huck Bennett, University of Colorado Boulder

In my second talk, I will discuss the Lattice Isomorphism Problem (LIP) and LIP-based cryptography. LIP-based cryptography was introduced in a pair of papers by Ducas and van Woerden and by Bennett, Ganju, Peetathawatchai, and Stephens-Davidowitz from 2022. It is much newer and less well-understood than LWE-based cryptography. Accordingly, there has been a flurry of work both on LIP-based cryptographic constructions and cryptanalysis in the last few years.

Mon Aug 24
12:00 PM – 2:00 PM

Lunch


Mon Aug 24
2:00 PM – 3:15 PM

SAC Summer School - Code-based cryptography, Part 1

Introduction to (Hamming) code-based cryptography

Philippe Gaborit, Université de Limoges

In the first talk we will give an introduction to (Hamming) code-based cryptography. The outline will be the following: basic of coding theory, theoretical an practical difficulty of code based problems, main encryption schemes (McEliece, BIKE, Aleknovich and HQC), and main signature scheme (full domain based scheme (CFS), Zero-knowledge based schemes). We will end by mentioning existing open problems and limitations.

Mon Aug 24
3:15 PM – 3:45 PM

Coffee Break


Mon Aug 24
3:45 PM – 5:00 PM

SAC Summer School - Code-based cryptography, Part 2

Introduction to Rank code-based crypto

Philippe Gaborit, Université de Limoges

In the second talk we will give an introduction to Rank code-based cryptography. Rank metric is an alternative metric used in code-based crypto. The promise of that metric is the fact that for a given size of parameters the attack complexity is higher than in Hamming metric, so that it is possible to get smaller public keys and ciphertext. In particular it is possible to get better parameters than for KYBER for instance. Rank-based crypto get to the second round of the NIST standardization process and is an active research area. In this talk we will review rank based coding theory and main encryption schemes (LRPC, RQC) and main signature schemes (Zero-knowledge and Miranda).





Tue Aug 25
9:00 AM – 10:15 AM

SAC Summer School - Provable Security for Symmetric-Key Cryptography, Part 1

Introduction to Provable Security for Symmetric-Key Cryptography — Case Study: The Sponge Construction

Charlotte Lefevre, Irisa, Rennes

In this talk, we will explore several techniques for proving the security of symmetric-key constructions. We begin with the PRP/PRF switching lemma to introduce game-playing techniques, and see how it applies to the security proof of the Even–Mansour construction. We then turn to indifferentiability, a security notion widely used to analyze hash function constructions, and study in detail the sponge construction and its proof of indifferentiability from a random oracle. Time permitting, we will see how the design principles of the sponge extend beyond hashing to authenticated encryption, using the scheme Ascon as an example.

Tue Aug 25
10:15 AM – 10:45 AM

Coffee Break


Tue Aug 25
10:45 AM – 12:00 PM

SAC Summer School - Provable Security for Symmetric-Key Cryptography, Part 2

Introduction to Provable Security for Symmetric-Key Cryptography — Case Study: The Sponge Construction

Charlotte Lefevre, Irisa, Rennes


Tue Aug 25
12:00 PM – 2:00 PM

Lunch


Tue Aug 25
2:00 PM – 3:15 PM

SAC Summer School - Symmetric Cryptanalysis, Part 1

Cryptanalysis of ChaCha: Past, Present and Future

Antonio Flórez-Gutiérrez, NTT Social Informatics Laboratories

ChaCha is an ARX-based stream cipher proposed by Bernstein in 2008, and has become one of the most widely deployed symmetric primitives due to its software performance. As a result, it has been the target of a lot of cryptanalysis over the last two decades, but, interestingly, most of it traces back to the same attack framework introduced by Aumasson et al. in 2008: a differential-linear distinguisher extended with key recovery using probabilistic neutral bits. In this presentation, we will revisit original paper, examine the attack's individual components, trace the evolution of these parts over the subsequent literature, speculate which gaps might still be improved in the future, and discuss what it all means to the security of ChaCha.

Tue Aug 25
3:15 PM – 3:45 PM

Coffee Break


Tue Aug 25
3:45 PM – 5:00 PM

SAC Summer School - Symmetric Cryptanalysis, Part 2

Cryptanalysis of ChaCha: Past, Present and Future

Antonio Flórez-Gutiérrez, NTT Social Informatics Laboratories






Wed Aug 26
9:00 AM - 9:10 AM

Opening remarks


Wed Aug 26
9:10 AM - 10:30 AM

Lattice-based cryptography

Snake-Eye Resistant and Robust PKE from (Ring-)LWE With Small Secrets
by Amit Deo, Benoit Libert

Provable decryption failure security for practical lattice-based PKE
by Christian Majenz, Fabrizio Sisinni

On the hull attacks against Construction A lattices
by Jean-Francois Biasse, Alexandra Hostetler, Anuvrat Jaindungarwal

Lattice-based Threshold Traitor Tracing with Public Traceability
by Sébastien Canard, Nathan Papon, Duong Hieu Phan


Wed Aug 26
10:30 AM – 11:00 AM

Coffee Break


Wed Aug 26
11:00 AM - 12:00 PM

Stafford Tavares Invited Lecture - New Directions in Fully Homomorphic Encryption

Chris Peikert, University of Michigan


Wed Aug 26
12:00 PM – 2:00 PM

Lunch break


Wed Aug 26
2:00 PM - 3:00 PM

Symmetric cryptography: modes of operation

Post-Quantum Security of Block Cipher Constructions
by Gorjan Alagic, Chen Bai, Christian Majenz, Kaiyan Shi

Extended Analysis of Key Committing Security of HCTR2
by Donghoon Chang, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito, Yu Sasaki, Rentaro Shiba, Takeshi Sugawara

Generic Attacks on Lai-Massey Structures
by Betul Askin Ozdemir, Tim Beyne, Vincent Rijmen


Wed Aug 26
3:00 PM – 3:30 PM

Coffee Break


Wed Aug 26
3:30 PM - 5:00 PM
Session chair: Daniel Panario

Algebraic cryptanalysis

Integral Resistance and Degree Bounds for Complex Linear Layers: Application to Prince and Lower-Latency Alternatives
by Simon Gerhalter, Maria Eichlseder

Revisiting Integral Distinguishers using Subspace Trails and Generalized Derivatives
by Noureddine El-Asri, Kirpa Garg, Valentin Suder

Concrete Bit-Operation Cost of XL
by Ruben Niederhagen, Hülya Evkan

Not Easy to Prepare a Pesto: Cryptanalysis of a Multivariate Public-Key Scheme from CCZ Equivalence
by Christof Beierle, Patrick Felke


Wed Aug 26
5:00 PM - 6:00 PM

Reception






Thu Aug 27
9:00 AM - 10:20 AM
Session chair: Eran Lambooij

Symmetric cryptanalysis

Refining Probabilistic-Linearization TIDA for 5-Round SHA3-384 Collision Attacks
by Luhan Yan, Zhenzhen Bao, Huina Li

Revisiting the Transferability of Chosen- to Known-plaintext Attacks and Applications to Round-reduced AES
by Xiaomeng Sun, Eik List, Wenying Zhang

Improved Related-Key Attacks on AES-192
by Florent Mazelet, María Naya-Plasencia

More Brisés in Ballet: Extending Differential and Linear Cryptanalysis
by Emanuele Bellini, Gabriele Bellini, Alessandro De Piccoli, Michela Gallone, David Gerault, Yunju Huang, Paul Huynh, Matteo Onger, SImone Pelizzola, Andrea Visconti


Thu Aug 27
10:20 AM – 10:50 AM

Coffee Break


Thu Aug 27
10:50 AM - 11:50 AM

Code-based cryptography

Performance Analysis of Parameterizable HQC Hardware Architecture
by Nishant Pandey, Sanjay Deshpande, Dixit Dutt Bohra, Debapriya Basu Roy, Dip Sankar Banerjee, Jakub Szefer

Bilinear Hulls for Support Splitting: Characterization, Optimization, and Applications
by Keita Ishizuka, Yusuke Aikawa, Tomoki Moriya

Syndrome Decoding with Hints
by Letizia D'Achille, Andre Esser, Nicolai Kraus


Thu Aug 27
11:50 AM – 1:50 PM

Lunch break


Thu Aug 27
1:50 PM - 2:50 PM
Session chair: Douglas Stebila

Other post-quantum constructions

Batched and Packed (Publicly) Verifiable Secret Sharing: A Unified Framework and Applications
by Shahla Atapoor, Karim Baghery, Georgio Nicolas, Robi Pedersen, Jannik Spiessens

Password-Based AKEM and HPKE
by Axel Durbet, Reihaneh Safavi-Naini, Jean-François Biasse

New Ring Signatures From Quaternions and Isogenies
by Kohei Nakagawa, Noboru Kunihiro


Thu Aug 27
3:00 PM - 4:00 PM

SAC and PST joint plenary talk - Three Use-Cases for Zero Knowledge Proofs

Jeremy Clark, Concordia University, Montreal

This talk will showcase three different use-cases of zero-knowledge proofs: governmental elections, the stock market, and cryptocurrency exchanges. For each application, we will also show a common mechanism for improving the efficiency of issuing a proof. We avoid using general-purpose zk-SNARK technology, which takes a description of a proof as a program or circuit, and compiles it into a proof. Instead we design the proof directly into an application-specific arithmetization of the voting/solvency/trading protocol, which cuts several steps out of the typical process for issuing proofs and improves prover time by one or two orders of magnitude over the zk-SNARK system Plonk.





Fri Aug 28
9:00 AM - 10:20 AM

Advanced constructions: IBE & FHE

Compact Partitioning from Truncation Collision-Resistant Hash: Application to the Lattice-based IBEs
by Parhat Abla

Simple and Efficient SKL-IBE with Classical Revocation from LWE
by Ho Nguyen Pham, Duong Hieu Phan, Quoc-Huy Vu, Weiqiang Wen

Stream-BSGS: Memory-Efficient Tree-BSGS with Optimized Relinearization Scheduling for FHE Polynomial Evaluation
by Zhongqi Wang, Shintaro Narisada, Takashi Nishide

Slicing Boolean Functions with Inner Products
by Pierrick Méaux, Tim Seuré


Fri Aug 28
10:20 AM – 10:50 AM

Coffee Break


Fri Aug 28
10:50 AM - 12:10 PM

Side-channel analysis and faults attacks

SDDT: An Operation Skip Attack Framework for Bitslice Ciphers---Validated on PIPO
by Dongwoo Kang, Hanbeom Shin, DongHyeon Kim, Seokhie Hong, HeeSeok Kim

Improving Skipping Fault Correction Attacks on Randomized Dilithium via MILP
by Haobo Ouyang, Chaoran Wang, Guowei Liu, Lixuan Wu, Meiqin Wang, Yanhong Fan

Power side-channel leakage distinguishers on LESSv2.0 - Exploiting sparse columns in Gaussian Elimination
by Maciej Czuprynko, Rishub Nagpal, Tobias Schneider, Sujoy Sinha Roy

Descent into Broken Trust: Uncovering ML-DSA Subkeys with Scarce Leakage and Local Optimization
by Carsten Schubert, Niklas Paskarbeit, Jean-Pierre Seifert, Marian Margraf


Fri Aug 28
12:10 PM – 2:10 PM

Lunch