SAC logo
Selected Areas in Cryptography 2026
University of Ottawa
August 24–28, 2026
Ottawa, Ontario
August 24–28, 2026
Ottawa, Ontario
SAC logo
Selected Areas in Cryptography 2026

University of Ottawa
August 24–28, 2026
Ottawa, Ontario


Invited Speakers

Jeremy Clark

Joint SAC-PST plenary speaker

Jeremy Clark

Associate Professor, Concordia University, Montreal (Canada)

Chris Peikert

Stafford Tavares lecturer

Chris Peikert

Professor, University of Michigan (USA)

Huck Bennett

Summer School speaker

Huck Bennett

Assistant Professor, University of Colorado Boulder (USA)

Antonio Flórez-Gutiérrez

Summer School speaker

Antonio Flórez-Gutiérrez

Permanent Researcher, NTT Social Informatics Laboratories (Japan)

Philippe Gaborit

Summer School speaker

Philippe Gaborit

Professor, Université de Limoges (France)

Charlotte Lefevre

Summer School speaker

Charlotte Lefevre

Postdoctoral researcher, Irisa, Rennes (France)


Jeremy Clark

Three Use-Cases for Zero Knowledge Proofs

This talk will showcase three different use-cases of zero-knowledge proofs: governmental elections, the stock market, and cryptocurrency exchanges. For each application, we will also show a common mechanism for improving the efficiency of issuing a proof. We avoid using general-purpose zk-SNARK technology, which takes a description of a proof as a program or circuit, and compiles it into a proof. Instead we design the proof directly into an application-specific arithmetization of the voting/solvency/trading protocol, which cuts several steps out of the typical process for issuing proofs and improves prover time by one or two orders of magnitude over the zk-SNARK system Plonk.

Jeremy Clark is an associate professor at the Concordia Institute for Information Systems Engineering. At Concordia, he holds the NSERC/Raymond Chabot Grant Thornton/Catallaxy Industrial Research Chair in Blockchain Technologies. He obtained his PhD from the University of Waterloo, where his gold medal dissertation was on designing and deploying secure voting systems including Scantegrity—the first cryptographically verifiable system used in a public sector election. He wrote one of the earliest academic papers on Bitcoin, completed several research projects in the area, and contributed to the first textbook. Beyond research, he has worked with several municipalities on voting technology and testified to both the Canadian Senate and House finance committees on Bitcoin.


Chris Peikert

New Directions in Fully Homomorphic Encryption

Chris Peikert is the Arthur W. Burks Collegiate Professor in Computer Science and Engineering at the University of Michigan. He received his B.S. in mathematics, M.Eng., and Ph.D. in electrical engineering and computer science from MIT. His research interests include cryptography, lattices, coding theory, algorithms, and computational complexity. Prof. Peikert is a pioneer in the study of quantum-secure and lattice-based cryptography. His work has been instrumental in advancing cryptographic techniques that are both efficient and resistant to various attacks, including those from future quantum computers. His contributions have led to the establishment of post-quantum cryptography standards that are in widespread use today. Before joining the University of Michigan, he served on the faculty at Georgia Tech. Prof. Peikert is the recipient of Sloan Foundation Fellowship, the Bergmann Memorial Research Award, and multiple Best Paper and Test-of-Time awards at top conferences. He is a Fellow of the International Association for Cryptologic Research (IACR).


Huck Bennett

Lattice-Based Cryptography: Foundations and New Directions

In my first talk, I will give an introduction to lattices and lattice-based cryptography. I will present the foundational Learning With Errors (LWE) problem and will show how to use it to construct public-key cryptography. I will then discuss optimizations to this basic scheme, including those used in the recently standardized ML-KEM (a.k.a. Kyber) cryptosystem. I will conclude by briefly discussing constructions of advanced cryptographic primitives, like Fully Homomorphic Encryption (FHE).

In my second talk, I will discuss the Lattice Isomorphism Problem (LIP) and LIP-based cryptography. LIP-based cryptography was introduced in a pair of papers by Ducas and van Woerden and by Bennett, Ganju, Peetathawatchai, and Stephens-Davidowitz from 2022. It is much newer and less well-understood than LWE-based cryptography. Accordingly, there has been a flurry of work both on LIP-based cryptographic constructions and cryptanalysis in the last few years.

Huck Bennett is an assistant professor in the computer science department at the University of Colorado Boulder. His research area is theoretical computer science, with a focus on lattices and error-correcting codes. Before coming to Colorado, Bennett was an assistant professor at Oregon State University from 2021 to 2023. Before that, Bennett was a postdoctoral scholar at the University of Michigan and at Northwestern University. He earned his Ph.D. from the Courant Institute of Mathematical Sciences at New York University advised by Daniel Dadush and Chee Yap.


Antonio Flórez-Gutiérrez

Cryptanalysis of ChaCha: Past, Present and Future

ChaCha is an ARX-based stream cipher proposed by Bernstein in 2008, and has become one of the most widely deployed symmetric primitives due to its software performance. As a result, it has been the target of a lot of cryptanalysis over the last two decades, but, interestingly, most of it traces back to the same attack framework introduced by Aumasson et al. in 2008: a differential-linear distinguisher extended with key recovery using probabilistic neutral bits. In this presentation, we will revisit original paper, examine the attack's individual components, trace the evolution of these parts over the subsequent literature, speculate which gaps might still be improved in the future, and discuss what it all means to the security of ChaCha.

Antonio Flórez-Gutiérrez is a researcher at NTT's Social Informatics Laboratories in Japan. He obtained hs PhD in Inria in France under the supervision of María Naya-Plasencia. He mainly works in the cryptanalysis of symmetric cryptographic primitives, with contributions to linear cryptanalysis and key recovery attacks among other topics.


Philippe Gaborit

Introduction to Code-based Cryptography

In the first talk we will give an introduction to (Hamming) code-based cryptography. The outline will be the following: basic of coding theory, theoretical an practical difficulty of code based problems, main encryption schemes (McEliece, BIKE, Aleknovich and HQC), and main signature scheme (full domain based scheme (CFS), Zero-knowledge based schemes). We will end by mentioning existing open problems and limitations.

In the second talk we will give an introduction to Rank code-based cryptography. Rank metric is an alternative metric used in code-based crypto. The promise of that metric is the fact that for a given size of parameters the attack complexity is higher than in Hamming metric, so that it is possible to get smaller public keys and ciphertext. In particular it is possible to get better parameters than for KYBER for instance. Rank-based crypto get to the second round of the NIST standardization process and is an active research area. In this talk we will review rank based coding theory and main encryption schemes (LRPC, RQC) and main signature schemes (Zero-knowledge and Miranda).

Philippe Gaborit was born in Bordeaux, France in 1969. He got a Master Degree at the French engineering school, École des Mines de Saint-Etienne in 1993. He received a Ph.D. degree in Mathematics at Bordeaux University in 1997 and the Habilitation à Diriger des Recherches in Mathematics at Limoges University in 2004. After a post-doc at University of Illinois at Chicago from 1997 to 1999, he became Associate Professor at the Mathematics Department of Limoges University from 1999 to 2008. Since 2008 he is Professor at the Computer Science Department of Limoges University. His research interests include Coding theory, Code-based Cryptography, Security, DNA codes and Quantum codes. He is one of the co-inventors of the HQC code-based encryption algorithm, standardized by NIST in 2025.


Charlotte Lefevre

Introduction to Provable Security for Symmetric-Key Cryptography. Case Study: The Sponge Construction

In this talk, we will explore several techniques for proving the security of symmetric-key constructions. We begin with the PRP/PRF switching lemma to introduce game-playing techniques, and see how it applies to the security proof of the Even–Mansour construction. We then turn to indifferentiability, a security notion widely used to analyze hash function constructions, and study in detail the sponge construction and its proof of indifferentiability from a random oracle. Time permitting, we will see how the design principles of the sponge extend beyond hashing to authenticated encryption, using the scheme Ascon as an example.

Charlotte Lefevre is a postdoctoral researcher with the INRIA team CAPSULE at the University of Rennes, France. She obtained her PhD from Radboud University, the Netherlands, in February 2026. Her research interests lie in the design and provable security analysis of symmetric cryptographic schemes, particularly those based on permutations.