<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1 plus MathML 2.0 plus SVG 1.1//EN" "http://www.w3.org/2002/04/xhtml-math-svg/xhtml-math-svg.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
  <head>
    <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=utf-8"/>
    <title>Team:CRYPT</title>
    <link rel="stylesheet" href="../static/css/raweb.css" type="text/css"/>
    <meta name="description" content="Research Program - Public-Key Cryptanalysis"/>
    <meta name="dc.title" content="Research Program - Public-Key Cryptanalysis"/>
    <meta name="dc.subject" content=""/>
    <meta name="dc.publisher" content="INRIA"/>
    <meta name="dc.date" content="(SCHEME=ISO8601) 2015-01"/>
    <meta name="dc.type" content="Report"/>
    <meta name="dc.language" content="(SCHEME=ISO639-1) en"/>
    <meta name="projet" content="CRYPT"/>
    <!-- Piwik -->
    <script type="text/javascript" src="/rapportsactivite/piwik.js"></script>
    <noscript><p><img src="//piwik.inria.fr/piwik.php?idsite=49" style="border:0;" alt="" /></p></noscript>
    <!-- End Piwik Code -->
  </head>
  <body>
    <div class="tdmdiv">
      <div class="logo">
        <a href="http://www.inria.fr">
          <img style="align:bottom; border:none" src="../static/img/icons/logo_INRIA-coul.jpg" alt="Inria"/>
        </a>
      </div>
      <div class="TdmEntry">
        <div class="tdmentete">
          <a href="uid0.html">Team Crypt</a>
        </div>
        <span>
          <a href="uid1.html">Members</a>
        </span>
      </div>
      <div class="TdmEntry">Overall Objectives<ul><li><a href="./uid3.html">Presentation</a></li><li><a href="./uid7.html">State of the Art</a></li></ul></div>
      <div class="TdmEntry">Research Program<ul><li class="tdmActPage"><a href="uid11.html&#10;&#9;&#9;  ">Public-Key Cryptanalysis</a></li><li><a href="uid15.html&#10;&#9;&#9;  ">Secret-Key Cryptanalysis</a></li></ul></div>
      <div class="TdmEntry">
        <a href="./uid19.html">Highlights of the Year</a>
      </div>
      <div class="TdmEntry">Partnerships and Cooperations<ul><li><a href="uid21.html&#10;&#9;&#9;  ">National Initiatives</a></li><li><a href="uid30.html&#10;&#9;&#9;  ">European Initiatives</a></li><li><a href="uid33.html&#10;&#9;&#9;  ">International Initiatives</a></li><li><a href="uid41.html&#10;&#9;&#9;  ">International Research Visitors</a></li></ul></div>
      <div class="TdmEntry">Dissemination<ul><li><a href="uid48.html&#10;&#9;&#9;  ">Promoting Scientific Activities</a></li><li><a href="uid62.html&#10;&#9;&#9;  ">Teaching - Supervision - Juries</a></li></ul></div>
      <div class="TdmEntry">
        <div>Bibliography</div>
      </div>
      <div class="TdmEntry">
        <ul>
          <li>
            <a id="tdmbibentmajor" href="bibliography.html">Major publications</a>
          </li>
          <li>
            <a id="tdmbibentyear" href="bibliography.html#year">Publications of the year</a>
          </li>
          <li>
            <a id="tdmbibentfoot" href="bibliography.html#References">References in notes</a>
          </li>
        </ul>
      </div>
    </div>
    <div id="main">
      <div class="mainentete">
        <div id="head_agauche">
          <small><a href="http://www.inria.fr">
	    
	    Inria
	  </a> | <a href="../index.html">
	    
	    Raweb 
	    2015</a> | <a href="http://www.inria.fr/en/teams/crypt">Presentation of the Team CRYPT</a></small>
        </div>
        <div id="head_adroite">
          <table class="qrcode">
            <tr>
              <td>
                <a href="crypt.xml">
                  <img style="align:bottom; border:none" alt="XML" src="../static/img/icons/xml_motif.png"/>
                </a>
              </td>
              <td>
                <a href="crypt.pdf">
                  <img style="align:bottom; border:none" alt="PDF" src="IMG/qrcode-crypt-pdf.png"/>
                </a>
              </td>
              <td>
                <a href="../crypt/crypt.epub">
                  <img style="align:bottom; border:none" alt="e-pub" src="IMG/qrcode-crypt-epub.png"/>
                </a>
              </td>
            </tr>
            <tr>
              <td/>
              <td>PDF
</td>
              <td>e-Pub
</td>
            </tr>
          </table>
        </div>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid7.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid15.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
      <div id="textepage">
        <!--DEBUT2 du corps du module-->
        <h2>Section: 
      Research Program</h2>
        <h3 class="titre3">Public-Key Cryptanalysis</h3>
        <p>This project is interested in any public-key cryptanalysis, in the broad sense.</p>
        <a name="uid12"/>
        <h4 class="titre4">Mathematical Foundations</h4>
        <p>Historically, one useful side-effect of public-key cryptanalysis
has been the introduction of advanced mathematical objects
in cryptology, which were later used for cryptographic design.
The most famous examples are elliptic curves (first introduced in cryptology
to factor integer numbers), lattices (first introduced in cryptology
to attack knapsack cryptosystems) and pairings over elliptic curves
(first introduced in cryptology to attack the discrete logarithm problem
over special elliptic curves).
It is therefore interesting to develop the mathematics of public-key cryptanalysis.
In particular, we would like to deepen our understanding of lattices
by studying well-known mathematical aspects such as packing problems, transference theorems or random lattices.
As an example, the team recently determined in <a href="./bibliography.html#crypt-2015-bid3">[19]</a>  the natural density
of co-cyclic lattices: these are integer lattices whose factor group is cyclic.</p>
        <a name="uid13"/>
        <h4 class="titre4">Lattice Algorithms</h4>
        <p>Due to the strong interest surrounding lattice-based cryptography at the moment,
our main focus is to attack lattice-based cryptosystems,
particularly the most efficient ones (such as NTRU), and the ones providing new functionalities
such as fully-homomorphic encryption or noisy multi-linear maps:
recent cryptanalysis examples include <a href="./bibliography.html#crypt-2015-bid4">[4]</a> , <a href="./bibliography.html#crypt-2015-bid5">[5]</a>  for the latter,
and <a href="./bibliography.html#crypt-2015-bid6">[6]</a>  for the former.
We want to assess the concrete security level of lattice-based cryptosystems,
as has been done for cryptosystems based on integer factoring or discrete logarithms:
this has been explored in  <a href="./bibliography.html#crypt-2015-bid7">[22]</a> , but needs to be developed.
This requires to analyze and design the best algorithms for solving lattice problems,
either exactly or approximately.
In this area, much progress has been obtained the past few years (such as  <a href="./bibliography.html#crypt-2015-bid8">[23]</a> ),
but we believe there is still more to come.
We are working on new lattice computational records.
In <a href="./bibliography.html#crypt-2015-bid9">[14]</a> ,
the team developed a new enumeration algorithm based on genetic strategies.</p>
        <p>We are also interested in lattice-based cryptanalysis of non-lattice cryptosystems,
by designing new attacks or improving old attacks.
A well-known example is RSA for which the best attacks in certain settings are based on lattice techniques,
following a seminal work by Coppersmith in 1996:
recently <a href="./bibliography.html#crypt-2015-bid10">[3]</a> , we improved the efficiency of some of these attacks on RSA,
and we would like to extend this kind of results.</p>
        <a name="uid14"/>
        <h4 class="titre4">New Assumptions</h4>
        <p>In the past few years,
new cryptographic functionalities (such as fully-homomorphic encryption, noisy multilinear maps, indistinguishability obfuscation, etc.)
have appeared, many of which being based on lattices.
They usually introduce new algorithmic problems whose hardness is not well-understood.
It is extremely important to study the hardness of these new assumptions,
in order to evaluate the feasibility of these new functionalities.
Sometimes, the problem itself is not new, but the (aggressive) choices of parameters are:
for instance, several implementations of fully-homomorphic encryption
used well-known lattice problems like LWE or BDD
but with very large parameters which have not been studied much.</p>
        <p>Currently, there are very few articles studying the concrete hardness of these new assumptions,
especially compared to the articles using these new assumptions.</p>
      </div>
      <!--FIN du corps du module-->
      <br/>
      <div class="bottomNavigation">
        <div class="tail_aucentre">
          <a href="./uid7.html" accesskey="P"><img style="align:bottom; border:none" alt="previous" src="../static/img/icons/previous_motif.jpg"/> Previous | </a>
          <a href="./uid0.html" accesskey="U"><img style="align:bottom; border:none" alt="up" src="../static/img/icons/up_motif.jpg"/>  Home</a>
          <a href="./uid15.html" accesskey="N"> | Next <img style="align:bottom; border:none" alt="next" src="../static/img/icons/next_motif.jpg"/></a>
        </div>
        <br/>
      </div>
    </div>
  </body>
</html>
