<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2018">
  <identification id="secret" isproject="true">
    <shortname>SECRET</shortname>
    <projectName>Security, Cryptology and Transmissions</projectName>
    <theme-de-recherche>Algorithmics, Computer Algebra and Cryptology</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>http://www.paris.inria.fr/secret/index.php?lg=en</urlTeam>
    <header_dates_team>Creation of the Project-Team: 2008 July 01</header_dates_team>
    <LeTypeProjet>Project-Team</LeTypeProjet>
    <keywordsSdN>
      <term>A3.1.5. - Control access, privacy</term>
      <term>A4. - Security and privacy</term>
      <term>A4.2. - Correcting codes</term>
      <term>A4.3. - Cryptography</term>
      <term>A4.3.1. - Public key cryptography</term>
      <term>A4.3.2. - Secret key cryptography</term>
      <term>A4.3.3. - Cryptographic protocols</term>
      <term>A4.3.4. - Quantum Cryptography</term>
      <term>A7.1. - Algorithms</term>
      <term>A7.1.4. - Quantum algorithms</term>
      <term>A8.1. - Discrete mathematics, combinatorics</term>
      <term>A8.6. - Information theory</term>
    </keywordsSdN>
    <keywordsSecteurs>
      <term>B6.4. - Internet of things</term>
      <term>B6.5. - Information systems</term>
      <term>B9.5.1. - Computer science</term>
      <term>B9.5.2. - Mathematics</term>
      <term>B9.10. - Privacy</term>
    </keywordsSecteurs>
    <UR name="Paris"/>
  </identification>
  <team id="uid1">
    <person key="secret-2018-idp112224">
      <firstname>Anne</firstname>
      <lastname>Canteaut</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Team leader, Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp115136">
      <firstname>André</firstname>
      <lastname>Chailloux</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
    </person>
    <person key="secret-2018-idp117600">
      <firstname>Pascale</firstname>
      <lastname>Charpin</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Emeritus</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp120448">
      <firstname>Gaëtan</firstname>
      <lastname>Leurent</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Starting Research Position until Feb. 2018, Researcher from March 2018</moreinfo>
    </person>
    <person key="secret-2018-idp122880">
      <firstname>Anthony</firstname>
      <lastname>Leverrier</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp125728">
      <firstname>María</firstname>
      <lastname>Naya Plasencia</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp128592">
      <firstname>Nicolas</firstname>
      <lastname>Sendrier</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp131456">
      <firstname>Jean-Pierre</firstname>
      <lastname>Tillich</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secret-2018-idp134320">
      <firstname>Christina</firstname>
      <lastname>Boura</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Univ de Versailles Saint-Quentin-en-Yvelines, Associate Professor, en délégation until Oct. 2018</moreinfo>
    </person>
    <person key="secret-2018-idp136960">
      <firstname>Léo</firstname>
      <lastname>Perrin</lastname>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria from Sept 2018, Fondation Sciences Mathématiques de Paris until Aug 2018</moreinfo>
    </person>
    <person key="secret-2018-idp139568">
      <firstname>Xavier</firstname>
      <lastname>Bonnetain</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp142032">
      <firstname>Rémi</firstname>
      <lastname>Bricout</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp144496">
      <firstname>Rodolfo</firstname>
      <lastname>Canto Torres</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Oct 2018</moreinfo>
    </person>
    <person key="secret-2018-idp146928">
      <firstname>Kevin</firstname>
      <lastname>Carrier</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ministère de la Défense</moreinfo>
    </person>
    <person key="secret-2018-idp149392">
      <firstname>Daniel</firstname>
      <lastname>Coggia</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>DGA, from Sep 2018</moreinfo>
    </person>
    <person key="secret-2018-idp151824">
      <firstname>Thomas</firstname>
      <lastname>Debris</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp154288">
      <firstname>Sébastien</firstname>
      <lastname>Duval</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université, until Sep 2018</moreinfo>
    </person>
    <person key="secret-2018-idp156784">
      <firstname>Shouvik</firstname>
      <lastname>Ghorai</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp159248">
      <firstname>Antoine</firstname>
      <lastname>Grospellier</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp161712">
      <firstname>Matthieu</firstname>
      <lastname>Lequesne</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Sorbonne Université</moreinfo>
    </person>
    <person key="secret-2018-idp164176">
      <firstname>Vivien</firstname>
      <lastname>Londe</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Univ de Bordeaux</moreinfo>
    </person>
    <person key="secret-2018-idp166608">
      <firstname>Andrea</firstname>
      <lastname>Olivo</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="secret-2018-idp169040">
      <firstname>Yann</firstname>
      <lastname>Rotella</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Sep 2018</moreinfo>
    </person>
    <person key="secret-2018-idp171472">
      <firstname>André</firstname>
      <lastname>Schrottenloher</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Feb 2018</moreinfo>
    </person>
    <person key="secret-2018-idp173904">
      <firstname>Ferdinand</firstname>
      <lastname>Sibleyras</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="secret-2018-idp176336">
      <firstname>Valentin</firstname>
      <lastname>Vasseur</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Univ René Descartes</moreinfo>
    </person>
    <person key="secret-2018-idp149392">
      <firstname>Daniel</firstname>
      <lastname>Coggia</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>DGA, from Mar 2018 until Aug 2018</moreinfo>
    </person>
    <person key="secret-2018-idp181280">
      <firstname>Mariem</firstname>
      <lastname>Hammami</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Jul 2018 until Oct 2018</moreinfo>
    </person>
    <person key="secret-2018-idp183760">
      <firstname>Anirudh</firstname>
      <lastname>Krishna</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Univ. Sherbroke, Canada, until Mar 2018, MITACS</moreinfo>
    </person>
    <person key="secret-2018-idp186256">
      <firstname>Anais</firstname>
      <lastname>Querol Cruz</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Mar 2018 until Aug 2018</moreinfo>
    </person>
    <person key="secret-2018-idp188736">
      <firstname>Florian</firstname>
      <lastname>Wartelle</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Mar 2018 until Sep 2018</moreinfo>
    </person>
    <person key="polsys-2018-idp204448">
      <firstname>Christelle</firstname>
      <lastname>Guiziou</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="secret-2018-idp193680">
      <firstname>Thomas</firstname>
      <lastname>Peyrin</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>NTU, Singapore, January and July 2018</moreinfo>
    </person>
    <person key="secret-2018-idp196160">
      <firstname>Shizhu</firstname>
      <lastname>Tian</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Univ. Chinese Academy of Sciences, from Sep 2018</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Presentation and scientific foundations</bodyTitle>
      <p>The research work within the project-team is mostly devoted to the
design and analysis of cryptographic algorithms, in the classical or
in the quantum setting. This work is essential since the current situation of
cryptography is rather fragile. Many
cryptographic protocols are now known whose security can be formally
proved assuming that the involved cryptographic primitives are ideal
(random oracle model, ideal cipher model...). However, the
security of the available primitives has been either threatened by recent progress
in cryptanalysis or by the possible invention of a large quantum
computer. In other
words, there is usually no concrete algorithm available to instantiate
in practice the ideal “black boxes” used in these protocols!</p>
      <p>In this context, our research work focuses on both families of
cryptographic primitives, <i>symmetric</i> and <i>asymmetric</i>
primitives.</p>
    </subsection>
    <subsection id="uid4" level="1">
      <bodyTitle>Main topics</bodyTitle>
      <p>Our domain in cryptology includes the
analysis and the design of</p>
      <simplelist>
        <li id="uid5">
          <p noindent="true">symmetric primitives (a.k.a. secret-key
algorithms),</p>
        </li>
        <li id="uid6">
          <p noindent="true">public-key primitives based on
hard problems coming from coding theory which are likely to be resistant
against a quantum computer,</p>
        </li>
        <li id="uid7">
          <p noindent="true">quantum cryptographic protocols whose security does not rely on
computational assumptions but on the laws of quantum physics.</p>
        </li>
      </simplelist>
    </subsection>
  </presentation>
  <fondements id="uid8">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid9" level="1">
      <bodyTitle>Scientific foundations</bodyTitle>
      <p>Our approach relies on a
competence whose impact is much wider than cryptology. Our tools
come from information theory, discrete mathematics, probabilities,
algorithmics, quantum physics... Most of our work mixes fundamental
aspects (study of mathematical objects) and practical aspects
(cryptanalysis, design of algorithms, implementations). Our
research is mainly driven by the belief that discrete mathematics
and algorithmics of finite structures form the scientific core of
(algorithmic) data protection.
</p>
    </subsection>
    <subsection id="uid10" level="1">
      <bodyTitle>Symmetric cryptology</bodyTitle>
      <p>Symmetric techniques are widely used because they are the only ones that can achieve some major features such as high-speed or low-cost encryption, fast authentication, and efficient hashing. It is a very active research area which is stimulated by a pressing industrial demand.
The process which has led to the new block cipher standard AES in 2001 was the outcome of a decade of research in symmetric cryptography, where new attacks have been proposed, analyzed and then thwarted by some appropriate designs. However, even if its security has not been challenged so far, it clearly appears that the AES cannot serve as a Swiss knife in all environments. In particular an important challenge raised by several new applications is the design of symmetric encryption schemes with some additional properties compared to the AES, either in terms of implementation performance (low-cost hardware implementation, low latency, resistance against side-channel attacks...) or in terms of functionalities (like authenticated encryption). The past decade has then been characterized by a multiplicity of new proposals. This proliferation of symmetric primitives has been amplified by several public competitions (eSTREAM, SHA-3, CAESAR...) which have encouraged innovative constructions and promising but unconventional designs. We are then facing up to a very new situation where implementers need to make informed choices among more than 40 lightweight block ciphers <footnote id="uid11" id-text="1">35 are described on <ref xlink:href="https://www.cryptolux.org/index.php/Lightweight_Block_Ciphers" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>cryptolux.<allowbreak/>org/<allowbreak/>index.<allowbreak/>php/<allowbreak/>Lightweight_Block_Ciphers</ref>.</footnote> or 57 new authenticated-encryption schemes <footnote id="uid12" id-text="2">see <ref xlink:href="http://competitions.cr.yp.to/caesar-submissions.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>competitions.<allowbreak/>cr.<allowbreak/>yp.<allowbreak/>to/<allowbreak/>caesar-submissions.<allowbreak/>html</ref></footnote>. Evaluating the security of all these proposals has then become a primordial task which requires the attention of the community.</p>
      <p>In this context we believe that the cryptanalysis effort cannot scale up without an in-depth study of the involved algorithms.
Indeed most attacks are described as ad-hoc techniques dedicated to a particular cipher. To determine whether they apply to some other primitives, it is then crucial to formalize them in a general setting. Our approach relies on the idea that a unified description of generic attacks (in the sense that they apply to a large class of primitives) is the only methodology for a precise evaluation of the resistance of all these new proposals, and of their security margins. In particular, such a work prevents misleading analyses based on wrong estimations of the complexity or on non-optimized algorithms. It also provides security criteria which enable designers to guarantee that their primitive resists some families of attacks. The main challenge is to provide a generic description which captures most possible optimizations of the attack.</p>
    </subsection>
    <subsection id="uid13" level="1">
      <bodyTitle>Code-based cryptography</bodyTitle>
      <p>Public-key cryptography is one of the key tools for providing network
security (SSL, e-commerce, e-banking...). The security of nearly
all public-key schemes used today relies on the presumed difficulty of
two problems, namely factorization of large integers or computing the
discrete logarithm over various groups. The hardness of those
problems was questioned in 1994 <footnote id="uid14" id-text="3">P. Shor, <i>Algorithms for
quantum computation: Discrete logarithms and factoring</i>, FOCS
1994.</footnote> when Shor showed that a quantum computer could solve them
efficiently. Though large enough quantum computers that would be able
to threaten the existing cryptosystems do not exist yet, the
cryptographic research community has to get ready and has to prepare
alternatives. This line of work is usually referred to as <i>post-quantum cryptography</i>. This has become a prominent research field. Most notably, an international call for post-quantum primitives <footnote id="uid15" id-text="4"><ref xlink:href="http://csrc.nist.gov/groups/ST/post-quantum-crypto/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>csrc.<allowbreak/>nist.<allowbreak/>gov/<allowbreak/>groups/<allowbreak/>ST/<allowbreak/>post-quantum-crypto/</ref></footnote> has been launched by the NIST, with a submission deadline in November 2017.</p>
      <p>The research of the project-team in this field is
focused on the design and cryptanalysis of cryptosystems making use of
coding theory. Code-based cryptography is one the main techniques for post-quantum
cryptography (together with lattice-based, multivariate, or hash-based
cryptography).
</p>
    </subsection>
    <subsection id="uid16" level="1">
      <bodyTitle>Quantum information</bodyTitle>
      <p>The field of quantum information and computation aims at exploiting the laws of quantum physics to manipulate information in radically novel ways. There are two main applications:</p>
      <simplelist>
        <li id="uid17">
          <p noindent="true">quantum computing, that offers the promise of solving some problems that seem to be intractable for
classical computers such as for instance factorization or solving the discrete
logarithm problem;</p>
        </li>
        <li id="uid18">
          <p noindent="true">quantum cryptography, which provides new ways to exchange data in a provably secure fashion.
For instance it allows key distribution by using an authenticated channel and quantum communication over an
unreliable channel with unconditional security, in the sense that its security can be proven rigorously by using
only
the laws of quantum physics, even with all-powerful adversaries.</p>
        </li>
      </simplelist>
      <p>Our team deals with quantum coding theoretic issues related to building a large quantum
computer and with quantum cryptography. The first part builds upon our expertise
in classical coding theory whereas the second axis focuses on
obtaining security proofs for quantum protocols or on devising quantum cryptographic protocols
(and more generally quantum protocols related to cryptography).
A close relationship with partners working in the whole area of quantum information processing
in the Parisian region has also been developed through our participation
to the Fédération de Recherche “PCQC” (Paris Centre for Quantum Computing).
</p>
    </subsection>
  </fondements>
  <domaine id="uid19">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid20" level="1">
      <bodyTitle>Cryptographic primitives</bodyTitle>
      <p>Our major application domain is the design of cryptographic primitives, especially for platforms with restricting implementation requirements. For instance, we aim at recommending (or designing) low-cost (or extremely fast) encryption schemes, or primitives which remain secure against quantum computers. </p>
    </subsection>
    <subsection id="uid21" level="1">
      <bodyTitle>Code Reconstruction</bodyTitle>
      <p>To evaluate the quality of a cryptographic algorithm, it is usually
assumed that its specifications are public, as, in accordance with
Kerckhoffs principle, it would be dangerous to rely, even partially,
on the fact that the adversary does not know those specifications.
However, this fundamental rule does not mean that the specifications
are known to the attacker. In practice, before mounting a
cryptanalysis, it is necessary to strip off the data. This
reverse-engineering process is often subtle, even when the data
formatting is not concealed on purpose. A typical case is
interception: some raw data, not necessarily encrypted, is observed
out of a noisy channel. To access the information, the whole
communication system has first to be disassembled and every
constituent reconstructed. A transmission system actually corresponds
to a succession of elements (symbol mapping, scrambler, channel
encoder, interleaver... ), and there exist many possibilities
for each of them.
In addition to the “preliminary to cryptanalysis” aspect, there are
other links between those problems and cryptology. They share
some scientific tools (algorithmics, discrete mathematics,
probability...), but beyond that, there are some very strong
similarities in the techniques.</p>
    </subsection>
  </domaine>
  <highlights id="uid22">
    <bodyTitle>Highlights of the Year</bodyTitle>
    <subsection id="uid23" level="1">
      <bodyTitle>Highlights of the Year</bodyTitle>
      <simplelist>
        <li id="uid24">
          <p noindent="true"><b>Keynote at Eurocrypt:</b> A. Canteaut bas been an invited keynote speaker at Eurocrypt 2018 in Tel-Aviv.</p>
        </li>
        <li id="uid25">
          <p noindent="true"><b>Cryptanalysis of candidates to the NIST post-quantum competition:</b> The members of the project-team are involved in the design of several attacks against submissions to the NIST standardization effort for post-quantum cryptography. This work has led to the break of <tt>EDON-K</tt> key encapsulation mechanism, of <tt>RLCE</tt> encryption scheme, of <tt>RankSign</tt>, and of a recently proposed IBE scheme.</p>
        </li>
        <li id="uid26">
          <p noindent="true"><b>Quantum fault-tolerance with constant overhead:</b> In a couple of papers published at STOC 2018 and FOCS 2018, A. Grospellier and A. Leverrier together with O. Fawzi (from ENS Lyon) proved that quantum expander codes can be combined with quantum fault-tolerance techniques to achieve constant overhead: the ratio between the total number of physical qubits required for a quantum computation with faulty hardware and the number of logical qubits involved in the ideal computation is asymptotically constant, and can even be taken arbitrarily close to 1 in the limit of small physical error rate. This improves on the polylogarithmic overhead promised by the celebrated threshold theorem.</p>
        </li>
      </simplelist>
    </subsection>
  </highlights>
  <logiciels id="uid27">
    <bodyTitle>New Software and Platforms</bodyTitle>
    <subsection id="uid28" level="1">
      <bodyTitle>CFS</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Reference implementation of parallel CFS (reinforced version of the digital signature scheme CFS). Two variants are proposed, one with a « bit-packing » finite field arithmetic and an evolution with a « bit-slicing » finite-field arithmetic (collaboration with Peter Schwabe). For 80 bits of security the running time for producing one signature with the « bit-packing » variant is slightly above one second. This is high but was still the fastest so far. The evolution with the « bit-slicing » arithmetic produces the same signature in about 100 milliseconds.</p>
      <simplelist>
        <li id="uid29">
          <p noindent="true">Participants: Grégory Landais and Nicolas Sendrier</p>
        </li>
        <li id="uid30">
          <p noindent="true">Contact: Nicolas Sendrier</p>
        </li>
        <li id="uid31">
          <p noindent="true">URL: <ref xlink:href="https://gforge.inria.fr/projects/cfs-signature/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>gforge.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>projects/<allowbreak/>cfs-signature/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid32" level="1">
      <bodyTitle>Collision Decoding</bodyTitle>
      <p><span class="smallcap" align="left">Keywords:</span> Algorithm - Binary linear code</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> Collision Decoding implements two variants of information set decoding : Stern-Dumer, and MMT. To our knowledge it is the best full-fledged open-source implementation of generic decoding of binary linear codes. It is the best generic attack against code-based cryptography.</p>
      <simplelist>
        <li id="uid33">
          <p noindent="true">Participants: Grégory Landais and Nicolas Sendrier</p>
        </li>
        <li id="uid34">
          <p noindent="true">Contact: Nicolas Sendrier</p>
        </li>
        <li id="uid35">
          <p noindent="true">URL: <ref xlink:href="https://gforge.inria.fr/projects/collision-dec/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>gforge.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>projects/<allowbreak/>collision-dec/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid36" level="1">
      <bodyTitle>ISDF</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Implementation of the Stern-Dumer decoding algorithm, and of a varaint of the algorithm due to May, Meurer and Thomae.</p>
      <simplelist>
        <li id="uid37">
          <p noindent="true">Participants: Grégory Landais and Nicolas Sendrier</p>
        </li>
        <li id="uid38">
          <p noindent="true">Contact: Anne Canteaut</p>
        </li>
        <li id="uid39">
          <p noindent="true">URL: <ref xlink:href="https://gforge.inria.fr/projects/collision-dec/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>gforge.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>projects/<allowbreak/>collision-dec/</ref></p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid40">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid41" level="1">
      <bodyTitle>Symmetric
cryptology</bodyTitle>
      <participants>
        <person key="secret-2018-idp139568">
          <firstname>Xavier</firstname>
          <lastname>Bonnetain</lastname>
        </person>
        <person key="secret-2018-idp134320">
          <firstname>Christina</firstname>
          <lastname>Boura</lastname>
        </person>
        <person key="secret-2018-idp112224">
          <firstname>Anne</firstname>
          <lastname>Canteaut</lastname>
        </person>
        <person key="secret-2018-idp117600">
          <firstname>Pascale</firstname>
          <lastname>Charpin</lastname>
        </person>
        <person key="secret-2018-idp149392">
          <firstname>Daniel</firstname>
          <lastname>Coggia</lastname>
        </person>
        <person key="secret-2018-idp154288">
          <firstname>Sébastien</firstname>
          <lastname>Duval</lastname>
        </person>
        <person key="secret-2018-idp120448">
          <firstname>Gaëtan</firstname>
          <lastname>Leurent</lastname>
        </person>
        <person key="secret-2018-idp125728">
          <firstname>María</firstname>
          <lastname>Naya Plasencia</lastname>
        </person>
        <person key="secret-2018-idp136960">
          <firstname>Léo</firstname>
          <lastname>Perrin</lastname>
        </person>
        <person key="secret-2018-idp169040">
          <firstname>Yann</firstname>
          <lastname>Rotella</lastname>
        </person>
        <person key="secret-2018-idp171472">
          <firstname>André</firstname>
          <lastname>Schrottenloher</lastname>
        </person>
        <person key="secret-2018-idp173904">
          <firstname>Ferdinand</firstname>
          <lastname>Sibleyras</lastname>
        </person>
      </participants>
      <subsection id="uid42" level="2">
        <bodyTitle>Block ciphers</bodyTitle>
        <p>Our recent results mainly concern either the analysis or the design of lightweight block ciphers.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid43">
            <p noindent="true">Nonlinear approximations of block ciphers: A. Canteaut, together with C. Beierle and G. Leander have exhibited the relationship between nonlinear invariants for block ciphers and nonlinear approximations. They have shown that, in some cases, the linear hull effect may be formalized in terms of nonlinear invariants. They have also introduced a new framework to study the probability of nonlinear approximations over iterated block ciphers <ref xlink:href="#secret-2018-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
          <li id="uid44">
            <p noindent="true">Impossible differential cryptanalysis: C. Boura, V. Lallemand and M. Naya-Plasencia have introduced new techniques and complexity analyses for impossible differential cryptanalysis. They also showed that the technique of multiple differentials can be applied to impossible differential attacks <ref xlink:href="#secret-2018-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
          <li id="uid45">
            <p noindent="true">Construction of lightweight MDS matrices: S. Duval and G. Leurent have exhibited MDS matrices with the lowest known implementation cost. They have been constructed by a search through a space of circuits yielding MDS matrices <ref xlink:href="#secret-2018-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid46" level="2">
        <bodyTitle>Stream ciphers</bodyTitle>
        <p>Stream ciphers provide an alternative to block-cipher-based encryption schemes. They are especially well-suited in applications which require either extremely fast encryption or a very low-cost hardware implementation.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid47">
            <p noindent="true">Design of encryption schemes for efficient homomorphic-ciphertext compression: A. Canteaut, M. Naya-Plasencia together with their coauthors have investigated the constraints on the symmetric cipher imposed by this application and they have proposed some solutions based on additive IV-based stream ciphers <ref xlink:href="#secret-2018-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid48">
            <p noindent="true">Cryptanalysis of Goldreich pseudo-random generator: Goldreich's PRG is a theoretical construction which expands a short random string into a long pseudo-random string by applying a simple <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>d</mi></math></formula>-ary predicate to public random sized subsets of the bits of the seed. While the security of Goldreich's PRG has been thoroughly investigated, with a variety of results deriving provable security guarantees against classes of attacks in some parameter regimes and necessary criteria to be satisfied by the underlying predicate, little was known about its concrete security and efficiency. Motivated by the hope of getting practical instantiations of this construction, Y. Rotella and his co-authors initiated a study of the concrete security of Goldreich's PRG, and evaluated its resistance to cryptanalytic attacks. They developped a new guess-and-determine-style attack, and identified new criteria which captured the security guarantees <ref xlink:href="#secret-2018-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid49" level="2">
        <bodyTitle>Authenticated encryption</bodyTitle>
        <p>A limitation of all classical block ciphers is that they aim at protecting confidentiality only, while most applications need both encryption and authentication. These two functionalities are provided by using a block cipher like the AES together with an appropriate mode of operation. However, it appears that the most widely-used mode of operation for authenticated encryption, AES-GCM, is not very efficient for high-speed networks. Also, the security of the GCM mode completely collapses when an IV is reused. These severe drawbacks have then motivated an international competition named CAESAR, partly supported by the NIST, which has been launched in order to define some new authenticated encryption schemes <footnote id="uid50" id-text="5"><ref xlink:href="http://competitions.cr.yp.to/caesar.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>competitions.<allowbreak/>cr.<allowbreak/>yp.<allowbreak/>to/<allowbreak/>caesar.<allowbreak/>html</ref></footnote>.
The project-team is involved in a national cryptanalytic effort in this area led by the BRUTUS project funded by the ANR. In this context, the members of the project-team have obtained some cryptanalytic results on several candidates to the CAESAR competition.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid51">
            <p noindent="true">State-recovery attack on a simplified version of Ketje Jr. <ref xlink:href="#secret-2018-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
          <li id="uid52">
            <p noindent="true">Cryptanalysis of Morus, one of the finalists of the CAESAR competition <ref xlink:href="#secret-2018-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid53" level="2">
        <bodyTitle>Cryptographic properties and construction of appropriate
building blocks</bodyTitle>
        <p>The construction of building blocks which guarantee
a high resistance against the known attacks is a major topic within
our project-team, for stream ciphers, block ciphers and hash
functions. The use of such optimal objects actually leads to some
mathematical structures which may be at the origin of new attacks. This
work involves fundamental aspects related to discrete mathematics,
cryptanalysis and implementation aspects. Actually, characterizing
the structures of the building blocks which are optimal regarding to
some attacks is very important for finding appropriate constructions
and also for determining whether the underlying structure induces some
weaknesses or not.
For these reasons, we have investigated several families of filtering
functions and of S-boxes which are well-suited for their cryptographic
properties or for their implementation characteristics.</p>
        <p>
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid54">
            <p noindent="true">Differential Equivalence of Sboxes: C. Boura, A. Canteaut and their co-authors have studied two notions of differential equivalence of Sboxes corresponding to the case when the functions have the same difference table, or when their difference tables have the same support <ref xlink:href="#secret-2018-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. They proved that these two notions do not coincide, and that they are invariant under some classical equivalence relations like EA and CCZ equivalence. They also proposed an algorithm for determining the whole equivalence class of a given function.</p>
          </li>
          <li id="uid55">
            <p noindent="true">Boomerang Uniformity of Sboxes: The boomerang attack is a cryptanalysis technique against block ciphers which combines two differentials for the upper part and the lower part of the cipher. The Boomerang Connectivity Table (BCT) is a tool introduced by Cid <i>et al.</i> at Eurocrypt 2018 for analysing the dependency between these two differentials. C. Boura and A. Canteaut <ref xlink:href="#secret-2018-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> have provided an in-depth analysis of BCT, by studying more closely differentially 4-uniform Sboxes. They have completely characterized the BCT of all differentially 4-uniform permutations of 4 bits and then study these objects for some cryptographically relevant families of Sboxes, as the inverse function and quadratic permutations. These two families are the first examples of differentially 4-uniform Sboxes optimal against boomerang attacks for an even number of variables, answering an open question raised by Cid <i>et al.</i>.</p>
          </li>
          <li id="uid56">
            <p noindent="true">CCZ equivalence of Sboxes: A. Canteaut and L. Perrin have characterized CCZ-equivalence as a property of the zeroes in the Walsh spectrum of an Sbox (or equivalently in their DDT). They used this framework to show how to efficiently upper bound the number of distinct EA-equivalence classes in a given CCZ-equivalence class. More importantly, they proved that CCZ-equivalence can be reduced to the association of EA-equivalence and an operation called twisting. They then revisited several results from the literature on CCZ-equivalence and showed how they can be interpreted in light of this new framework <ref xlink:href="#secret-2018-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
          <li id="uid57">
            <p noindent="true">Links between linear and differential properties of Sboxes: P. Charpin together with J. Peng has established new links between the differential uniformity and the nonlinearity of some Sboxes in the case of two-valued functions and quadratic functions. More precisely, they have exhibited a lower bound on the nonlinearity of monomial permutations depending on their differential uniformity, as well as an upper bound in the case of differentially two-valued functions <ref xlink:href="#secret-2018-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/></p>
          </li>
          <li id="uid58">
            <p noindent="true">Construction of building-blocks with resistance against fault-attacks at a low implementation overhead <ref xlink:href="#secret-2018-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid59" level="2">
        <bodyTitle>Modes of operation and generic attacks</bodyTitle>
        <p>In order to use a block cipher in practice, and to achieve a given
security notion, a mode of operation must be used on top of the block
cipher. Modes of operation are usually studied through provable security, and we
know that their use is secure as long as the underlying primitive is
secure, and we respect some limits on the amount of data processed. The
analysis of generic attack helps us understand what happens when the
hypotheses of the security proofs do not hold, or the corresponding
limits are not respected. Comparing proofs and attacks also shows gaps
where our analysis is incomplete, and when improved proof or attacks are
required.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid60">
            <p noindent="true">Use of block ciphers operating on small blocks with the CTR
mode <ref xlink:href="#secret-2018-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: the security proof of the CTR mode
requires that no more than <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mrow><mi>n</mi><mo>/</mo><mn>2</mn></mrow></msup></math></formula> blocks are encrypted with
the same key, but the known attacks reveal very little information and
are considered less problematic than on CBC. However, G. Leurent and F. Sibleyras have exhibited concrete attacks
against the CTR mode when processing close to <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mrow><mi>n</mi><mo>/</mo><mn>2</mn></mrow></msup></math></formula> blocks of
data, and have shown that an attacker can actually extract as much
information as in the case of CBC encryption.</p>
          </li>
          <li id="uid61">
            <p noindent="true">Generic attacks against some MAC constructions based on block ciphers <ref xlink:href="#secret-2018-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: G. Leurent and F. Sibleyras, together with M. Nandi, have studied the security of several recent MAC
constructions with provable security beyond the birthday bound, namely <tt>SUM-ECBC</tt>, <tt>PMAC+</tt>, <tt>3kf9</tt>, <tt>GCM-SIV2</tt>, and some variants.
They described a new cryptanalysis technique for double-block MACs and they showed how to
build a forgery attack with query complexity <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>𝒪</mi><mo>(</mo><msup><mn>2</mn><mrow><mn>3</mn><mi>n</mi><mo>/</mo><mn>4</mn></mrow></msup><mo>)</mo></mrow></math></formula>, proving that these schemes do not
reach full security in the information-theoretic model. Surprisingly, their
attack on <tt>LightMAC+</tt> invalidates a recent security proof by Naito.
Moreover, they gave the first attack against <tt>SUM-ECBC</tt> and <tt>GCM-SIV2</tt>, with complexity below <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mi>n</mi></msup></math></formula>.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid62" level="1">
      <bodyTitle>Code-based cryptography</bodyTitle>
      <participants>
        <person key="secret-2018-idp144496">
          <firstname>Rodolfo</firstname>
          <lastname>Canto Torres</lastname>
        </person>
        <person key="secret-2018-idp151824">
          <firstname>Thomas</firstname>
          <lastname>Debris</lastname>
        </person>
        <person key="secret-2018-idp161712">
          <firstname>Matthieu</firstname>
          <lastname>Lequesne</lastname>
        </person>
        <person key="secret-2018-idp128592">
          <firstname>Nicolas</firstname>
          <lastname>Sendrier</lastname>
        </person>
        <person key="secret-2018-idp131456">
          <firstname>Jean-Pierre</firstname>
          <lastname>Tillich</lastname>
        </person>
        <person key="secret-2018-idp176336">
          <firstname>Valentin</firstname>
          <lastname>Vasseur</lastname>
        </person>
      </participants>
      <p>The first cryptosystem based on error-correcting codes
was a public-key encryption scheme proposed by McEliece in 1978; a
dual variant was proposed in 1986 by Niederreiter. We proposed
the first (and only) digital signature scheme in 2001. Those systems
enjoy very interesting features (fast encryption/decryption, short
signature, good security reduction) but also have their drawbacks
(large public key, encryption overhead, expensive signature
generation). Some of the main issues in this field are</p>
      <simplelist>
        <li id="uid63">
          <p noindent="true">security analysis, including against a quantum adversary, implementation and practicality of existing solutions,</p>
        </li>
        <li id="uid64">
          <p noindent="true">reducing the key size, <i>e.g.</i>, by using rank metric instead of Hamming metric, or by using structured codes,</p>
        </li>
        <li id="uid65">
          <p noindent="true">addressing new functionalities, like identity-based encryption, hashing or symmetric encryption.</p>
        </li>
      </simplelist>
      <p>Our recent work on code-based cryptography has to be seen in the context of the recently launched NIST competition whose purpose is to standardize
quantum-safe public-key primitives. This call concerns all three major cryptographic primitives, namely public-key cryptosytems, key-exchange protocols and digital signature schemes.
The most promising
techniques today for addressing this issue are code-based cryptography, lattice-based cryptography, mutivariate cryptography, and hash-based cryptography.</p>
      <p>Our contributions in this area are two-fold and consist in:</p>
      <simplelist>
        <li id="uid66">
          <p noindent="true">designing and analysis new code-based solutions;</p>
        </li>
        <li id="uid67">
          <p noindent="true">cryptanalyzing code-based schemes, especially candidates to the NIST competition.</p>
        </li>
      </simplelist>
      <subsection id="uid68" level="2">
        <bodyTitle>Design of new code-based solutions</bodyTitle>
        <p>The members of the project-team have submitted several candidates to the NIST competition, including a key-exchange protocol based on quasi-cyclic MDPC codes <ref xlink:href="#secret-2018-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Their recent work on MDPC codes is important in this context in order to carefully analyze the properties of this candidate.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid69">
            <p noindent="true">Thwarting the GJS attack: the decryption algorithm of the QC-MDPC cryptosystem is based on an iterative bit-flipping algorithm, which fails with a small probability. These failures have been exploited in 2016 by Guo, Johansson and Stankovski to perform a key-recovery attack. JP Tillich recently analyzed how this attack can be avoided by increasing the key size of the scheme. Most notably, he proved that, under a very reasonable assumption, the
error probability after decoding decays almost exponentially with the code-length with just
two iterations of bit-flipping. With an additional assumption,
it even decays exponentially with an unbounded number of iterations, implying that in this case
the increase of the key size equired for resisting to the GJS attack is only moderate <ref xlink:href="#secret-2018-bid21" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid70">
            <p noindent="true">Design of a new KEM with IND-CCA2 security in a model considering decoding failures <ref xlink:href="#secret-2018-bid22" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>:
M. Lequesne, N. Sendrier and their co-authors explored the underlying causes of the GJS attack, how it can be improved and how it can be mitigated. They derived a new timing attack performing well even in cases which were more challenging to the GJS attack. They also showed how to construct a new KEM, called ParQ that can reduce the decryption failure rate to a level negligible in the security parameter. They formally proved the IND-CCA2 security of ParQ, in a model that considers decoding failures.</p>
          </li>
          <li id="uid71">
            <p noindent="true">Design of a new code-based signature scheme <ref xlink:href="#secret-2018-bid23" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: T. Debris, N. Sendrier and JP Tillich recently proposed a "hash-and-sign" code-based signature scheme called <tt>Wave</tt>, which uses a family of ternary generalized (U, U + V) codes.
<tt>Wave</tt> achieves existential unforgeability under adaptive-chosen-message attacks in the random oracle model with a tight reduction to two assumptions from coding theory: one is a distinguishing problem that is related to the trapdoor inserted in the scheme, the other one is a multiple-target version of syndrome decoding. This scheme enjoys efficient signature and verification algorithms. For 128-bit security, signature are 8000-bit long and the public-key size is slightly smaller than one megabyte.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid72" level="2">
        <bodyTitle>Cryptanalysis of code-based schemes</bodyTitle>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid73">
            <p noindent="true">Cryptanalysis of two public-key cryptosystems based on the rank syndrome decoding problem <ref xlink:href="#secret-2018-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: JP Tillich and his co-authors proposed an attack on the Rank Syndrome Decoding problem which improves the previously best known algorithm for solving this problem.
This attack breaks for some parameters some recently proposed
cryptosystems based on LRPC codes or Gabidulin codes, including Loidreau's cryptosystem and the LRPC cryptosystem.</p>
          </li>
          <li id="uid74">
            <p noindent="true">Cryptanalysis of the NIST submission <tt>RankSign</tt> and of a recently proposed IBE scheme: T. Debris and JP Tillich have presented an algebraic attack against <tt>RankSign</tt> that exploits the fact that the augmented LRPC codes used in this scheme have codewords with a very low weight. This attack shows that all the parameters proposed for this candidate can be broken. They also proved that, for the IBE scheme based on <tt>RankSign</tt>, the problem is deeper than finding a new signature in rank-based cryptography, since they found an attack on the generic problem upon which the security reduction relies <ref xlink:href="#secret-2018-bid24" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid75">
            <p noindent="true">Cryptanalysis of the <tt>EDON-K</tt> key encapsulation mechanism submitted to the NIST competition: <tt>EDON-K</tt> is a candidate to the NIST competition which is inspired by the McEliece scheme but uses another family of codes defined over <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>𝔽</mi><msup><mn>2</mn><mn>128</mn></msup></msub></math></formula> instead of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>𝔽</mi><mn>2</mn></msub></math></formula> and is not based on the Hamming metric. M. Lequesne and JP Tillich presented an attack making the scheme insecure for the intended use. Indeed, recovering the error in the McEliece scheme corresponding to <tt>EDON-K</tt> can be viewed as a decoding problem for the rank-metric with a super-code of an LRPC code of very small rank A suitable parity-check matrix for this super-code can then be easily derived from the public key and used to recover the error <ref xlink:href="#secret-2018-bid25" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <li id="uid76">
            <p noindent="true">Attack against <tt>RLCE</tt> <ref xlink:href="#secret-2018-bid26" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: M. Lequesne and JP Tillich, together with A. Couvreur, recently presented a key-recovery attack against the Random Linear Code Encryption
(RLCE) scheme recently submitted by Y. Wang to the NIST competition. This
attack recovers the secret-key for all the short key-parameters proposed by the author.
It uses a polynomial-time algorithm based on a square code distinguisher.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid77" level="1">
      <bodyTitle>Quantum Information</bodyTitle>
      <participants>
        <person key="secret-2018-idp139568">
          <firstname>Xavier</firstname>
          <lastname>Bonnetain</lastname>
        </person>
        <person key="secret-2018-idp142032">
          <firstname>Rémi</firstname>
          <lastname>Bricout</lastname>
        </person>
        <person key="secret-2018-idp115136">
          <firstname>André</firstname>
          <lastname>Chailloux</lastname>
        </person>
        <person key="secret-2018-idp156784">
          <firstname>Shouvik</firstname>
          <lastname>Ghorai</lastname>
        </person>
        <person key="secret-2018-idp159248">
          <firstname>Antoine</firstname>
          <lastname>Grospellier</lastname>
        </person>
        <person key="secret-2018-idp183760">
          <firstname>Anirudh</firstname>
          <lastname>Krishna</lastname>
        </person>
        <person key="secret-2018-idp122880">
          <firstname>Anthony</firstname>
          <lastname>Leverrier</lastname>
        </person>
        <person key="secret-2018-idp164176">
          <firstname>Vivien</firstname>
          <lastname>Londe</lastname>
        </person>
        <person key="secret-2018-idp125728">
          <firstname>María</firstname>
          <lastname>Naya Plasencia</lastname>
        </person>
        <person key="secret-2018-idp166608">
          <firstname>Andrea</firstname>
          <lastname>Olivo</lastname>
        </person>
        <person key="secret-2018-idp131456">
          <firstname>Jean-Pierre</firstname>
          <lastname>Tillich</lastname>
        </person>
        <person key="secret-2018-idp171472">
          <firstname>André</firstname>
          <lastname>Schrottenloher</lastname>
        </person>
      </participants>
      <p>Our research in quantum information focusses on several axes: quantum codes with the goal of developing better error correction strategies to build large quantum computers, quantum cryptography which exploits the laws of quantum mechanics to derive security guarantees, relativistic cryptography which exploits in addition the fact that no information can travel faster than the speed of light and finally quantum cryptanalysis which investigates how quantum computers could be harnessed to attack classical cryptosystems.</p>
      <subsection id="uid78" level="2">
        <bodyTitle>Quantum codes</bodyTitle>
        <p>Protecting quantum information from external noise is an issue of paramount
importance for building a quantum computer. It also worthwhile to
notice that all quantum error-correcting code schemes proposed up to
now suffer from the very same problem that the first (classical)
error-correcting codes had: there are constructions of good quantum
codes, but for the best of them it is not known how to decode them in
polynomial time.</p>
        <p>Two PhD students within the project-team work on this topic. First, Antoine Grospellier, co-advised by A. Leverrier and O. Fawzi (Ens Lyon), studies efficient decoding algorithms for quantum LDPC codes. Beyond their intrinsic interest for channel-coding problems, such algorithms would be particularly relevant in the context of quantum fault-tolerance, since they would allow to considerably reduce the required overhead to obtain fault-tolerance in quantum computation.
Vivien Londe is co-advised by A. Leverrier and G. Zémor (IMB) and his thesis is devoted to the design of better quantum LDPC codes: the main idea is to generalize the celebrated toric code of Kitaev by considering cellulations of manifolds in higher dimensions. A recent surprising result was that this approach leads to a much better behaviour than naively expected and a major challenge is to explore the mathematics behind this phenomenon in order to find even better constructions, or to uncover potential obstructions.</p>
        <p>
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid79">
            <p noindent="true">Decoding algorithm for quantum expander codes <ref xlink:href="#secret-2018-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid28" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, <ref xlink:href="#secret-2018-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
In this work, A. Grospellier, A. Leverrier and O. Fawzi analyze an efficient decoding algorithm for quantum expander codes and prove that it can correct a linear number of random errors with a negligible failure probability. As an application, this shows that this family of codes can be used to obtain quantum fault-tolerance with only a constant overhead in terms of qubits, compared to a polylogarithmic overhead as in previous schemes. This is a crucial step in order to eventually build large universal quantum computers.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid80" level="2">
        <bodyTitle>Quantum cryptography</bodyTitle>
        <p>Quantum cryptography exploits the laws of quantum physics to establish the security of certain cryptographic primitives.
The most studied one is certainly quantum key distribution, which allows two distant parties to establish a secret using an untrusted quantum channel.
Our activity in this field is particularly focussed on protocols with continuous variables, which are well-suited to implementations. The interest of continuous variables for quantum cryptography was recently recognized by being awarded a 10 M€ funding from the Quantum Flagship and SECRET will contribute to this project by studying the security of new key distribution protocols <ref xlink:href="#secret-2018-bid30" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid81">
            <p noindent="true">Security proof for two-way continuous-variable quantum key distribution <ref xlink:href="#secret-2018-bid31" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: while many quantum key distribution protocols are one-way in the sense that quantum information is sent from one party to the other, it can be beneficial in terms of performance to consider two-way protocols where the quantum states perform a round-trip between the two parties. In this paper (to appear in <i>Physical Review A</i>), we show how to exploit the symmetries of the protocols in phase-space to establish their security against the most general attacks allowed by quantum theory.</p>
          </li>
          <li id="uid82">
            <p noindent="true">Investigating the optimality of ancilla-assisted linear optical Bell measurements <ref xlink:href="#secret-2018-bid32" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: Due to its experimental and theoretical simplicity, linear
quantum optics has proved to be a promising route for the
early implementation of important quantum communication protocols. A. Olivo and F. Grosshans study the efficiency of non ambiguous Bell measurements in this model and show both theoretical and numerical bounds depending on the number of ancilla qubits. This is important for understanding what resources are needed for building quantum repeaters, the last missing building block for secure long distance quantum key distribution networks.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid83" level="2">
        <bodyTitle>Relativistic cryptography</bodyTitle>
        <p>Two-party cryptographic tasks are well-known to be impossible without complexity assumptions, either in the classical or the quantum world. Remarkably, such no-go theorems become invalid when adding the physical assumption that no information can travel faster than the speed of light. This additional assumption gives rise to the emerging field of relativistic cryptography. We worked on this topic for several years and Andrea Olivo was recruited as a PhD student to continue working on both theoretical and practical aspects of relativistic cryptography.</p>
        <p>
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid84">
            <p noindent="true">Relativistic commitment and zero-knowledge proofs <ref xlink:href="#secret-2018-bid33" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: A. Chailloux and A. Leverrier constructed a relativistic zero-knowledge protocol for any NP-complete problem. The main technical tool is the analysis of quantum consecutive measurements, which allows us to prove security against quantum adversaries. R. Bricout and A. Chailloux also studied relativistic multi-round bit commitment schemes. They showed optimal classical cheating strategies for the canonical <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msub><mi>F</mi><mi>Q</mi></msub></math></formula> commitment scheme.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid85" level="2">
        <bodyTitle>Quantum cryptanalysis of symmetric primitives</bodyTitle>
        <p>Symmetric cryptography seems at first sight much less affected in the post-quantum world than asymmetric cryptography: its main known threat seemed for a long time Grover's algorithm, which allows for an exhaustive key search in the square root of the normal complexity. For this reason, it was usually believed that doubling key lengths suffices to maintain an equivalent security in the post-quantum world.
However, a lot of work is certainly required in the field of symmetric cryptography in order to “quantize” the classical families of attacks in an
optimized way, as well as to find new dedicated quantum attacks. M. Naya Plasencia has recently been awarded an ERC Starting grant for her project named QUASYModo on this topic.</p>
        <p noindent="true">
          <b>Recent results:</b>
        </p>
        <simplelist>
          <li id="uid86">
            <p noindent="true">Hidden-shift quantum cryptanalysis <ref xlink:href="#secret-2018-bid34" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: X. Bonnetain and M. Naya-Plasencia have obtained new results that consider the tweak proposed at Eurocrypt 2017 of using modular additions to counter Simon's attacks. They have developed new algorithms that improve and generalize Kuperberg's algorithm for the hidden shift problem. Thanks to their improved algorithm, they have been able to build a quantum attack in the superposition model on Poly1305, proposed at FSE 2005, largely used and claimed to be quantumly secure. They also analyzed the security of some classical symmetric constructions with concrete parameters, to evaluate the impact and practicality of the proposed tweak, concluding that it does not seem to be efficient</p>
          </li>
          <li id="uid87">
            <p noindent="true">Quantum algorithm for the <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>k</mi></math></formula>-XOR problem <ref xlink:href="#secret-2018-bid35" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: The <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>k</mi></math></formula>-XOR (or generalized birthday) problem aims at finding <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>k</mi></math></formula> elements of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>n</mi></math></formula>-bits, drawn at random, such that the XOR of all of them is 0. The algorithms proposed by Wagner more than 15 years ago remain the best known classical algorithms for solving it, when disregarding logarithmic factors. M. Naya-Plasencia and A. Schrottenloher, together with L. Grassi, studied this problem in the quantum setting and provided algorithms with the best known quantum time-complexities. In particular, they were able to considerably improve the 3-XOR algorithm.</p>
          </li>
          <li id="uid88">
            <p noindent="true">Quantum cryptanalysis of CSIDH and Ordinary Isogeny-based Schemes <ref xlink:href="#secret-2018-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>: CSIDH is a recent proposal by Castryck et al. for post-quantum non-interactive key-exchange. It is similar in design to a scheme by Couveignes, Rostovtsev and Stolbunov, but it replaces ordinary elliptic curves by supersingular elliptic curves. Although CSIDH uses supersingular curves, it can attacked by a quantum subexponential hidden shift algorithm due to Childs et al. While the designers of CSIDH claimed that the parameters they suggested ensures security against this algorithm, X. Bonnetain and A. Schrottenloher showed that these security parameters were too optimistic: they improved the hidden shift algorithm and gave a precise complexity analysis in this context, which greatly reduced the complexity. For example, they showed that only <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mn>35</mn></msup></math></formula> quantum equivalents of a key-exchange are sufficient to break the 128-bit classical, 64-bit quantum security parameters proposed, instead of <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mn>62</mn></msup></math></formula>. They also extended their analysis to ordinary isogeny computations, and showed that an instance proposed by De Feo, Kieffer and Smith and expected to offer 56 bits of quantum security can be broken in <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mn>38</mn></msup></math></formula> quantum evaluations of a key exchange.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
  </resultats>
  <partenariat id="uid89">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid90" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="uid91" level="2">
        <bodyTitle>ANR</bodyTitle>
        <simplelist>
          <li id="uid92">
            <p noindent="true">
              <b>ANR BRUTUS (<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>10</mn><mo>/</mo><mn>14</mn><mo>→</mo><mn>09</mn><mo>/</mo><mn>18</mn></mrow></math></formula>)</b>
            </p>
            <p noindent="true">
              <i>Authenticated Ciphers and Resistance against
Side-Channel Attacks</i>
            </p>
            <p noindent="true">ANR program: Défi Société de l'information et de la communication</p>
            <p noindent="true">Partners: ANSSI, Inria (project-team SECRET and project-team MARELLE), Orange, University of Lille, University of Rennes, University Versailles-Saint Quentin</p>
            <p noindent="true">160 kEuros</p>
            <p noindent="true">The Brutus project aims at investigating the security of authenticated encryption systems.
We plan to evaluate carefully the security of the most promising candidates to the CAESAR competition, by trying to attack the
underlying primitives or to build security proofs of modes of operation. We target the traditional
black-box setting, but also more "hostile" environments, including the hardware platforms where some side-channel information is available.</p>
          </li>
          <li id="uid93">
            <p noindent="true">
              <b>ANR DEREC (<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>10</mn><mo>/</mo><mn>16</mn><mo>→</mo><mn>09</mn><mo>/</mo><mn>21</mn></mrow></math></formula>)</b>
            </p>
            <p noindent="true">
              <i>Relativistic cryptography</i>
            </p>
            <p noindent="true">ANR Program: jeunes chercheurs</p>
            <p noindent="true">244 kEuros</p>
            <p noindent="true">The goal of project DEREC is to demonstrate the feasibility of guaranteeing the security of some cryptographic protocols using the relativistic paradigm, which states that information propagation is limited by the speed of light. We plan to study some two party primitives such as bit commitment and their security against classical and quantum adversaries in this model. We then plan to the integration of those primitives into larger cryptosystems. Finally, we plan on performing a demonstration of those systems in real life conditions.</p>
          </li>
          <li id="uid94">
            <p noindent="true">
              <b>ANR CBCRYPT (<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>10</mn><mo>/</mo><mn>17</mn><mo>→</mo><mn>09</mn><mo>/</mo><mn>21</mn></mrow></math></formula>)</b>
            </p>
            <p noindent="true">
              <i>Code-based cryptography</i>
            </p>
            <p noindent="true">ANR Program: AAP Générique 2017</p>
            <p noindent="true">Partners: Inria SECRET (coordinator), XLIM, Univ. Rouen, Univ. Bordeaux.</p>
            <p noindent="true">197 kEuros</p>
            <p noindent="true">The goal of CBCRYPT is to propose code-based candidates to the NIST call
aiming at standardizing public-key primitives which resist to quantum attacks. These proposals are based
either on code-based schemes relying on the
usual Hamming metric or on the rank metric.
The project does not deal solely with the NIST call. We also develop
some other code-based solutions: these are either primitives that are not mature enough to be proposed in
the first NIST call or whose functionalities are not covered by the NIST call, such as identity-based
encryption, broadcast encryption, attribute based encryption or functional encryption. A third goal of
this project is of a more fundamental nature: namely to lay firm foundations for code-based cryptography by
developing thorough and rigorous security proofs together with a set of algorithmic tools for assessing
the security of code-based cryptography.</p>
          </li>
          <li id="uid95">
            <p noindent="true">
              <b>ANR quBIC (<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mn>10</mn><mo>/</mo><mn>17</mn><mo>→</mo><mn>09</mn><mo>/</mo><mn>21</mn></mrow></math></formula>)</b>
            </p>
            <p noindent="true">
              <i>Quantum
Banknotes and Information-Theoretic Credit Cards</i>
            </p>
            <p noindent="true">ANR Program: AAP Générique 2017</p>
            <p noindent="true">Partners: Univ. Paris-Diderot (coordinator), Inria SECRET, UPMC (LIP6), CNRS (Laboratoire Kastler Brossel)</p>
            <p noindent="true">87 kEuros</p>
            <p noindent="true">For a quantum-safe future, classical security systems as well as
quantum protocols that guarantee security against all adversaries must
be deployed. Here, we will study and implement one of the most
promising quantum applications, namely unforgeable quantum money. A
money scheme enables a secure transaction between a client, a vendor
and a bank via the use of a credit card or via the use of banknotes,
with maximal security guarantees. Our objectives are to perform a
theoretical analysis of quantum money schemes, in realistic conditions
and for encodings in both discrete and continuous variables, and to
demonstrate experimentally these protocols using state-of-the-art
quantum memories and integrated detection devices.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid96" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid97" level="2">
        <bodyTitle>FP7 &amp; H2020 Projects</bodyTitle>
        <subsection id="uid98" level="3">
          <bodyTitle>PQCRYPTO</bodyTitle>
          <sanspuceslist>
            <li id="uid99">
              <p noindent="true">Title: Post-quantum cryptography for long-term security</p>
            </li>
            <li id="uid100">
              <p noindent="true">Programm: H2020</p>
            </li>
            <li id="uid101">
              <p noindent="true">Duration: March 2015 - March 2018</p>
            </li>
            <li id="uid102">
              <p noindent="true">Coordinator: TECHNISCHE UNIVERSITEIT EINDHOVEN</p>
            </li>
            <li id="uid103">
              <p noindent="true">Partners:</p>
              <sanspuceslist>
                <li id="uid104">
                  <p noindent="true">Academia Sinica (Taiwan)</p>
                </li>
                <li id="uid105">
                  <p noindent="true">Bundesdruckerei (Germany)</p>
                </li>
                <li id="uid106">
                  <p noindent="true">Danmarks Tekniske Universitet (Denmark)</p>
                </li>
                <li id="uid107">
                  <p noindent="true">Katholieke Universiteit Leuven (Belgium)</p>
                </li>
                <li id="uid108">
                  <p noindent="true">Nxp Semiconductors Belgium Nv (Belgium)</p>
                </li>
                <li id="uid109">
                  <p noindent="true">Ruhr-Universitaet Bochum (Germany)</p>
                </li>
                <li id="uid110">
                  <p noindent="true">Stichting Katholieke Universiteit (Netherlands)</p>
                </li>
                <li id="uid111">
                  <p noindent="true">Technische Universiteit Eindhoven (Netherlands)</p>
                </li>
                <li id="uid112">
                  <p noindent="true">Technische Universitaet Darmstadt (Germany)</p>
                </li>
                <li id="uid113">
                  <p noindent="true">University of Haifa (Israel)</p>
                </li>
              </sanspuceslist>
            </li>
            <li id="uid114">
              <p noindent="true">Inria contact: Nicolas Sendrier</p>
            </li>
            <li id="uid115">
              <p noindent="true">Online banking, e-commerce, telemedicine, mobile communication, and cloud computing depend fundamentally on the security of the underlying cryptographic algorithms. Public-key algorithms are particularly crucial since they provide digital signatures and establish secure communication without requiring in-person meetings. Essentially all applications today are based on RSA or on the discrete-logarithm problem in finite fields or on elliptic curves. Cryptographers optimize parameter choices and implementation details for these systems and build protocols on top of these systems; cryptanalysts fine-tune attacks and establish exact security levels for these systems. Alternative systems are far less visible in research and unheard of in practice. It might seem that having three systems offers enough variation, but these systems are all broken as soon as large quantum computers are built. The EU and governments around the world are investing heavily in building quantum computers; society needs to be prepared for the consequences, including cryptanalytic attacks accelerated by these computers. Long-term confidential documents such as patient health-care records and state secrets have to guarantee security for many years, but information encrypted today using RSA or elliptic curves and stored until quantum computers are available will then be as easy to decipher as Enigma-encrypted messages are today. PQCRYPTO will allow users to switch to post-quantum cryptography: cryptographic systems that are not merely secure for today but that will also remain secure long-term against attacks by quantum computers. PQCRYPTO will design a portfolio of high-security post-quantum public-key systems, and will improve the speed of these systems, adapting to the different performance challenges of mobile devices, the cloud, and the Internet of Things. PQCRYPTO will provide efficient implementations of high-security post-quantum cryptography for a broad spectrum of real-world applications.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid116" level="3">
          <bodyTitle>QCALL</bodyTitle>
          <sanspuceslist>
            <li id="uid117">
              <p noindent="true">Title: Quantum Communications for ALL</p>
            </li>
            <li id="uid118">
              <p noindent="true">Programm: H2020-MSCA-ITN-2015</p>
            </li>
            <li id="uid119">
              <p noindent="true">Duration: December 2016 - November 2020</p>
            </li>
            <li id="uid120">
              <p noindent="true">Coordinator: University of Leeds (UK)</p>
            </li>
            <li id="uid121">
              <p noindent="true">Other partners: see <ref xlink:href="http://www.qcall-itn.eu/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>qcall-itn.<allowbreak/>eu/</ref></p>
            </li>
            <li id="uid122">
              <p noindent="true">Inria contact: Anthony Leverrier</p>
            </li>
            <li id="uid123">
              <p noindent="true">QCALL is a European Innovative Training Network that endeavors to take the next necessary steps to bring the developing quantum technologies closer to the doorsteps of end users. QCALL will empower a nucleus of 15 doctoral researchers in this area to provide secure communications in the European continent and, in the long run, to its connections worldwide.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid124" level="3">
          <bodyTitle>ERC QUASYModo</bodyTitle>
          <sanspuceslist>
            <li id="uid125">
              <p noindent="true">Title: QUASYModo <i>Symmetric Cryptography in the Post-Quantum World</i></p>
            </li>
            <li id="uid126">
              <p noindent="true">Program: ERC starting grant</p>
            </li>
            <li id="uid127">
              <p noindent="true">Duration: September 2017 - August 2022</p>
            </li>
            <li id="uid128">
              <p noindent="true">PI: María Naya Plasencia</p>
            </li>
            <li id="uid129">
              <p noindent="true">As years go by, the existence of quantum computers becomes more tangible and the scientific community
is already anticipating the enormous consequences of the induced breakthrough in computational power.
Cryptology is one of the affected disciplines. Indeed, the current state-of-the-art asymmetric cryptography
would become insecure, and we are actively searching for alternatives. Symmetric cryptography, essential
for enabling secure communications, seems much less affected at first sight: its biggest known threat is
Grover’s algorithm, which allows exhaustive key searches in the square root of the normal complexity.
Thus, so far, it is believed that doubling key lengths suffices to maintain an equivalent security in the post-
quantum world.
The security of symmetric cryptography is completely based on cryptanalysis: we only gain confidence in
the security of a symmetric primitive through extensive and continuous scrutiny. It is therefore not possible
to determine whether a symmetric primitive might be secure or not in a post-quantum world without first
understanding how a quantum adversary could attack it. Correctly evaluating the security of symmetric
primitives in the post-quantum world cannot be done without a corresponding cryptanalysis toolbox, which
neither exists nor has ever been studied. This is the big gap I have identified and that I plan to fill with this
project.
Next, doubling the key length is not a trivial task and needs to be carefully studied. My ultimate aim is
to propose efficient solutions secure in the post-quantum world with the help of our previously obtained
quantum symmetric cryptanalysis toolbox. This will help prevent the chaos that big quantum computers
would generate: being ready in advance will definitely save a great amount of time and money, while
protecting our current and future communications.
The main challenge of QUASYModo is to redesign symmetric cryptography for the post-quantum
world.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid130" level="2">
        <bodyTitle>Collaborations in European Programs, Except FP7 &amp; H2020</bodyTitle>
        <subsection id="uid131" level="3">
          <bodyTitle>QCDA</bodyTitle>
          <sanspuceslist>
            <li id="uid132">
              <p noindent="true">Program: QuantERA ERA-NET Cofund in Quantum Technologies</p>
            </li>
            <li id="uid133">
              <p noindent="true">Project acronym: QCDA</p>
            </li>
            <li id="uid134">
              <p noindent="true">Project title: Quantum Code Design and Architecture</p>
            </li>
            <li id="uid135">
              <p noindent="true">Duration: February 2018 - January 2021</p>
            </li>
            <li id="uid136">
              <p noindent="true">Coordinator: Earl Campbell, University of Sheffield, UK</p>
            </li>
            <li id="uid137">
              <p noindent="true">Other partners: University of Sheffield (UK), TU Delft
(Netherlands), TU Munich (Germany), University College London (UK)</p>
            </li>
            <li id="uid138">
              <p noindent="true">Inria contact: Anthony Leverrier</p>
            </li>
            <li id="uid139">
              <p noindent="true">General purpose quantum computers must follow a fault-tolerant design
to prevent ubiquitous decoherence processes from corrupting
computations. All approaches to fault-tolerance demand extra physical
hardware to perform a quantum computation. Kitaev's surface, or toric,
code is a popular idea that has captured the hearts and minds of many
hardware developers, and has given many people hope that
fault-tolerant quantum computation is a realistic prospect. Major
industrial hardware developers include Google, IBM, and Intel. They
are all currently working toward a fault-tolerant architecture based
on the surface code. Unfortunately, however, detailed resource
analysis points towards substantial hardware requirements using this
approach, possibly millions of qubits for commercial applications.
Therefore, improvements to fault-tolerant designs are a pressing
near-future issue. This is particularly crucial since sufficient time
is required for hardware developers to react and adjust course
accordingly.</p>
              <p>This consortium will initiate a European co-ordinated approach to
designing a new generation of codes and protocols for fault-tolerant
quantum computation. The ultimate goal is the development of
high-performance architectures for quantum computers that offer
significant reductions in hardware requirements; hence accelerating
the transition of quantum computing from academia to industry. Key
directions developed to achieve these improvements include: the
economies of scale offered by large blocks of logical qubits in
high-rate codes; and the exploitation of continuous-variable degrees
of freedom.</p>
              <p>The project further aims to build a European community addressing
these architectural issues, so that a productive feedback cycle
between theory and experiment can continue beyond the lifetime of the
project itself. Practical protocols and recipes resulting from this
project are anticipated to become part of the standard arsenal for
building scalable quantum information processors.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid140" level="1">
      <bodyTitle>International Initiatives</bodyTitle>
      <subsection id="uid141" level="2">
        <bodyTitle>Inria Associate Teams Not Involved in an Inria International Labs</bodyTitle>
        <subsection id="uid142" level="3">
          <bodyTitle>
            <ref xlink:href="https://team.inria.fr/chocolat/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">CHOCOLAT </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid143">
              <p noindent="true">Title: Chosen-prefix Collision Attack on SHA-1 with ASICs Cluster</p>
            </li>
            <li id="uid144">
              <p noindent="true">International Partner (Institution - Laboratory - Researcher):</p>
              <sanspuceslist>
                <li id="uid145">
                  <p noindent="true">NTU (Singapore)
- SYLLAB - Peyrin Thomas</p>
                </li>
              </sanspuceslist>
            </li>
            <li id="uid146">
              <p noindent="true">Start year: 2017</p>
            </li>
            <li id="uid147">
              <p noindent="true">See also: <ref xlink:href="https://team.inria.fr/chocolat/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>team.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>chocolat/</ref></p>
            </li>
            <li id="uid148">
              <p noindent="true">The hash function SHA-1 is one of the most widely used hash functions in
the industry, but it has been shown to not be collision-resistant by a
team of Chinese researchers led by Prof. Wang in 2005. However, nobody
has publicly produced a real pair of colliding messages so far, because
the estimated attack complexity is around <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mn>63</mn></msup></math></formula> SHA-1 computations
(this represents about 70000 years of computation on a normal PC).</p>
              <p>While a collision of SHA-1 would clearly demonstrate the weakness of the
algorithm, a much more powerful attack would be to find a collision such
that the prefix of the colliding messages is chosen by some challenger
beforehand. In particular, this would allow creating a rogue certificate
authority certificate that would be accepted by browsers. Such an attack
has already been deployed for certificates using the MD5 hash function,
but MD5 is much weaker than SHA-1 and it has already been removed
from most security applications. SHA-1 is still widely used and
performing such an attack for certificates using SHA-1 would have a very
big impact.</p>
              <p>The objective of the project is to design a chosen-prefix collision
attack against the SHA-1 hash function, and to implement the attack in
practice. We estimate this will require <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><msup><mn>2</mn><mn>70</mn></msup></math></formula> computations, and we
will use an ASIC cluster to perform such a computation.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid149" level="2">
        <bodyTitle>Inria International Partners</bodyTitle>
        <subsection id="uid150" level="3">
          <bodyTitle>Declared Inria International Partners</bodyTitle>
          <sanspuceslist>
            <li id="uid151">
              <p noindent="true">Title: Discrete Mathematics, Codes and Cryptography</p>
            </li>
            <li id="uid152">
              <p noindent="true">International Partner (Institution - Laboratory - Researcher):</p>
              <sanspuceslist>
                <li id="uid153">
                  <p noindent="true">Indian Statistical Institute (India)
- Cryptology Research Group - Bimal Roy</p>
                </li>
              </sanspuceslist>
            </li>
            <li id="uid154">
              <p noindent="true">Duration: 2014 - 2018</p>
            </li>
            <li id="uid155">
              <p noindent="true">Start year: 2014</p>
            </li>
            <li id="uid156">
              <p noindent="true">Today's cryptology offers important challenges. Some are well-known: Can we understand existing cryptanalysis techniques well enough to devise criterion for the design of efficient and secure symmetric cryptographic primitives? Can we propose cryptographic protocols which offer provable security features under some reasonable algorithmic assumptions? Some are newer: How could we overcome the possible apparition of a quantum computer with its devastating consequences on public key cryptography as it is used today? Those challenges must be addressed, and some of the answers will involve tools borrowed to discrete mathematics, combinatorics, algebraic coding theory, algorithmic. The guideline of this proposal is to explore further and enrich the already well established connections between those scientific domains and their applications to cryptography and its challenges.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid157" level="3">
          <bodyTitle>Informal International Partners</bodyTitle>
          <simplelist>
            <li id="uid158">
              <p noindent="true">Nanyang Technological University (Singapore): cryptanalysis of symmetric primitives.</p>
            </li>
            <li id="uid159">
              <p noindent="true">Ruhr-Universität Bochum (Germany): design and cryptanalysis of symmetric primitives.</p>
            </li>
            <li id="uid160">
              <p noindent="true">University of Sherbrooke (Canada): quantum codes.</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid161" level="1">
      <bodyTitle>International Research Visitors</bodyTitle>
      <subsection id="uid162" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <simplelist>
          <li id="uid163">
            <p noindent="true">Thomas Peyrin, NTU Singapore, January 2018 and July 2018.</p>
          </li>
          <li id="uid164">
            <p noindent="true">Sristy Agrawal, Indian Institute of Science Education and Research, Kolkata, India, January 2018.</p>
          </li>
          <li id="uid165">
            <p noindent="true">Anastasiya Gorodilova, Sobolev Institute of Mathematics, Novosibirsk, Russia, September 2018.</p>
          </li>
          <li id="uid166">
            <p noindent="true">Lorenzo Grassi, IAIK, Graz University of Technology, Austria, September 2018.</p>
          </li>
        </simplelist>
        <subsection id="uid167" level="3">
          <bodyTitle>Internships</bodyTitle>
          <simplelist>
            <li id="uid168">
              <p noindent="true">Daniel Coggia, MPRI, March-Aug. 2018</p>
            </li>
            <li id="uid169">
              <p noindent="true">Anaïs Querol Cruz, MPRI, March-Aug. 2018</p>
            </li>
            <li id="uid170">
              <p noindent="true">Florian Wartelle, UVSQ, March-Sept. 2018</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid171" level="2">
        <bodyTitle>Visits to International Teams</bodyTitle>
        <subsection id="uid172" level="3">
          <bodyTitle>Research Stays Abroad</bodyTitle>
          <simplelist>
            <li id="uid173">
              <p noindent="true">NTU, Singapore, joint work within the
CHOCOLAT Associate Team: S. Duval (April 8-19), G. Leurent (October 29 - November 10).</p>
            </li>
            <li id="uid174">
              <p noindent="true">University of Sherbrooke, Sherbrooke, Canada, June 11-15, 2018 (J.P. Tillich)</p>
            </li>
            <li id="uid175">
              <p noindent="true">Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, Clear Water
Bay, Kowloon, Hong Kong, September 30-October 9, 2018 (P. Charpin).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid176">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid177" level="1">
      <bodyTitle>Promoting Scientific Activities</bodyTitle>
      <subsection id="uid178" level="2">
        <bodyTitle>Scientific Events Organisation</bodyTitle>
        <subsection id="uid179" level="3">
          <bodyTitle>General Chair, Scientific Chair</bodyTitle>
          <simplelist>
            <li id="uid180">
              <p noindent="true">WCC 2019, March 31 - April 5, 2019, St Jacut-de-la-Mer, France: A. Canteaut, program co-chair</p>
            </li>
            <li id="uid181">
              <p noindent="true">Eurocrypt 2020, Zagreb, Croatia: A. Canteaut, program co-chair</p>
            </li>
            <li id="uid182">
              <p noindent="true">Workshop on quantum code design and architectures (kick-off meeting of the European project QCDA), November 5-6, 2018, Paris (France): A. Leverrier.</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid183" level="3">
          <bodyTitle>Member of the Organizing Committees</bodyTitle>
          <simplelist>
            <li id="uid184">
              <p noindent="true">Training School on Symmetric Cryptography and Blockchain: February 19-23, 2018, Torremolinos (Spain): A. Canteaut.</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid185" level="2">
        <bodyTitle>Scientific Events Selection</bodyTitle>
        <subsection id="uid186" level="3">
          <bodyTitle>Chair of Conference Program Committees</bodyTitle>
          <p>As a co-editor-in-chief of the journal <i>IACR Transactions on Symmetric Cryptology</i>, María Naya-Plasencia served as a program chair of the conference <i>Fast Software Encryption (FSE)</i>, held in Bruges March 2018.
Gaëtan Leurent will serve as a co-editor-in-chief of <i>IACR
Transactions on Symmetric Cryptology</i> starting from 2019.</p>
        </subsection>
        <subsection id="uid187" level="3">
          <bodyTitle>Member of the Conference Program Committees</bodyTitle>
          <simplelist>
            <li id="uid188">
              <p noindent="true">FSE 2018: March 5-7, 2018, Bruges, Belgium (C. Boura, A. Canteaut, G. Leurent, M. Naya-Plasencia, L. Perrin);</p>
            </li>
            <li id="uid189">
              <p noindent="true">CryptoAction Symposium 2018: April 4-5, Sutomore, Montenegro (A. Canteaut);</p>
            </li>
            <li id="uid190">
              <p noindent="true">PQCrypto 2018: April 9-11, 2018, Fort Lauderdale, USA, (M. Naya-Plasencia, N. Sendrier, J.P. Tillich);</p>
            </li>
            <li id="uid191">
              <p noindent="true">CT-RSA 2018: April 16-20, 2018, San Francisco, USA (M. Naya-Plasencia);</p>
            </li>
            <li id="uid192">
              <p noindent="true">Eurocrypt 2018: April 29- May 3, 2018, Tel Aviv, Israel (M. Naya-Plasencia);</p>
            </li>
            <li id="uid193">
              <p noindent="true">WAIFI 2018: June 14-16, 2018, Bergen, Norway, (L. Perrin)</p>
            </li>
            <li id="uid194">
              <p noindent="true">SAC 2018: August 13-14, 2018, Calgary, Canada, (G. Leurent);</p>
            </li>
            <li id="uid195">
              <p noindent="true">Crypto 2018: August 17-19, 2018, Santa Barbara, USA, (M. Naya-Plasencia);</p>
            </li>
            <li id="uid196">
              <p noindent="true">QCrypt 2018: August 27-31, 2018, Shanghai, China, (A. Leverrier);</p>
            </li>
            <li id="uid197">
              <p noindent="true">TQC 2018: July 16-18, 2018, Sydney, Australia, (A. Leverrier);</p>
            </li>
            <li id="uid198">
              <p noindent="true">QTech 2018: September 5-7, 2018, Paris, France, (A. Leverrier);</p>
            </li>
            <li id="uid199">
              <p noindent="true">SCN 2018: September 5-7, 2018, Amalfi, Italy, (G. Leurent);</p>
            </li>
            <li id="uid200">
              <p noindent="true">AQIS 2018: September 8-12, 2018, Nagoya, Japan, (A. Leverrier);</p>
            </li>
            <li id="uid201">
              <p noindent="true">SETA 2018: October 1-6, 2018, Hong-Kong, China, (P. Charpin);</p>
            </li>
            <li id="uid202">
              <p noindent="true">Asiacrypt 2018: December 02-06, 2018, Brisbane, Australia, (G. Leurent);</p>
            </li>
            <li id="uid203">
              <p noindent="true">CT-RSA 2019: March 4-8, 2019, San Francisco, USA, (L. Perrin)</p>
            </li>
            <li id="uid204">
              <p noindent="true">FSE 2019: March 25-28, 2019, Paris, France (C. Boura, A. Canteaut, G. Leurent, M. Naya-Plasencia)</p>
            </li>
            <li id="uid205">
              <p noindent="true">WCC 2019: March 31 - April 5, 2019, St Jacut-de-la-Mer, France, (A. Canteaut chair, P. Charpin, N. Sendrier, J.P. Tillich);</p>
            </li>
            <li id="uid206">
              <p noindent="true">PQCrypto 2019: May 8-10, 2019, Chongqing, China, (J.P. Tillich);</p>
            </li>
            <li id="uid207">
              <p noindent="true">CBC 2019: May 18-19, Darmstadt, Germany, (J.P. Tillich);</p>
            </li>
            <li id="uid208">
              <p noindent="true">Eurocrypt 2019: May 19-23, 2019, Darmstadt, Germany (C. Boura)</p>
            </li>
            <li id="uid209">
              <p noindent="true">ISIT 2019: July 7-12, 2019, Paris, France, (J.P. Tillich);</p>
            </li>
            <li id="uid210">
              <p noindent="true">CHES 2019: August 25-28, 2019, Atlanta, USA, (G. Leurent);</p>
            </li>
            <li id="uid211">
              <p noindent="true">Eurocrypt 2020: Zagreb, Croatia (A. Canteaut, PC co-chair).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid212" level="2">
        <bodyTitle>Journal</bodyTitle>
        <subsection id="uid213" level="3">
          <bodyTitle>Member of the Editorial Boards</bodyTitle>
          <simplelist>
            <li id="uid214">
              <p noindent="true"><i>Designs, Codes and Cryptography</i>, associate editor: P. Charpin.</p>
            </li>
            <li id="uid215">
              <p noindent="true"><i>Finite Fields and Applications</i>, associate editor:
A. Canteaut, P. Charpin.</p>
            </li>
            <li id="uid216">
              <p noindent="true"><i>Applicable Algebra in Engineering, Communication and Computing</i>, associate editor: A. Canteaut.</p>
            </li>
            <li id="uid217">
              <p noindent="true"><i>IACR Transactions on Symmetric Cryptology</i>, associate editors: C. Boura, A. Canteaut, G. Leurent, M. Naya-Plasencia.</p>
            </li>
            <li id="uid218">
              <p noindent="true"><i>IACR Transactions on Cryptographic Hardware and Embedded Systems</i>, associate editors: G. Leurent.</p>
            </li>
            <li id="uid219">
              <p noindent="true"><i>Advances in Mathematics of Communications</i>, associate editors: N. Sendrier and J.P. Tillich</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid220" level="3">
          <bodyTitle>Reviewer - Reviewing Activities</bodyTitle>
          <simplelist>
            <li id="uid221">
              <p noindent="true">Remote Referee - step 2- ERC-2018-CoG (A. Canteaut)</p>
            </li>
            <li id="uid222">
              <p noindent="true">Remote Referee - step 2- ERC-2018-STG (M. Naya-Plasencia)</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid223" level="2">
        <bodyTitle>Invited Talks</bodyTitle>
        <simplelist>
          <li id="uid224">
            <p noindent="true">A. Canteaut, <i>Desperately Seeking Sboxes</i>, Eurocrypt 2018, Tel Aviv, Israel, April 29 - May 3 2018.</p>
          </li>
          <li id="uid225">
            <p noindent="true">M. Naya-Plasencia, <i>New Results on Quantum Symmetric Cryptanalysis</i>, QUANTALGO Quantum Algorithms and Applications Workshop, 2018, Paris, France, September 25 - 28, 2018.</p>
          </li>
          <li id="uid226">
            <p noindent="true">M. Naya-Plasencia, <i>New Results on Quantum Symmetric Cryptanalysis</i>, CrossFYRE Workshop, 2018, Surrey, UK, September 13 - 14, 2018.</p>
          </li>
          <li id="uid227">
            <p noindent="true">M. Naya-Plasencia, <i>New Results on Quantum Symmetric Cryptanalysis</i>,
Journées Nationales 2018 du GDR Informatique Mathématique, Apr 2018, Palaiseau, France</p>
          </li>
          <li id="uid228">
            <p noindent="true">J.P. Tillich <i>Schémas cryptographiques à clé publique à base de codes correcteurs proposés à la compétition du NIST</i>, Journées
Nationales 2018 du Pré-GDR Sécurité Informatique, June 1, 2018.</p>
          </li>
        </simplelist>
        <p>The members of the project-team have also been invited to give talks to some workshops or international seminars, including:</p>
        <descriptionlist>
          <li id="uid229">
            <p noindent="true">C. Boura, A. Canteaut, J. Jean and V. Suder, <i>On Sboxes sharing the same DDT</i>,
Dagstuhl Seminar 18021 Symmetric Cryptography, Jan 2018, Dagstuhl, Germany</p>
          </li>
          <li id="uid230">
            <p noindent="true">A. Canteaut <i>L'insoutenable légèreté du chiffrement</i>, Journées Scientifiques Inria 2018, June 2018, Bordeaux, France</p>
          </li>
          <li id="uid231">
            <p noindent="true">A. Canteaut and L. Perrin <i>On CCZ-Equivalence, Extended-Affine Equivalence and Function Twisting</i>, BFA 2018 - 3rd International Workshop on Boolean Functions and their Applications, Jun 2018, Loen, Norway</p>
          </li>
          <li id="uid232">
            <p noindent="true">A. Chailloux, <i>Relativistic commitment and zero-knowledge proofs</i>,
17th Bellairs Crypto-Workshop 2018, Mar 2018, Holetown, Barbados.</p>
          </li>
          <li id="uid233">
            <p noindent="true">T. Fuhr, M. Naya-Plasencia and Y. Rotella, <i>New Results on Modified Versions of Ketje Jr</i>, Dagstuhl Seminar 18021 Symmetric Cryptography, Jan 2018, Dagstuhl, Germany</p>
          </li>
          <li id="uid234">
            <p noindent="true">G. Leurent, <i>MDS Matrices with Lightweight Circuits</i>, The Challenges of Lightweight Cryptanalysis, April 2018, Tel Aviv, Israel.</p>
          </li>
          <li id="uid235">
            <p noindent="true">G. Leurent, <i>Security Issues with Small Block Sizes</i>, Lightweight Crypto Day, April 2018, Tel Aviv, Israel.</p>
          </li>
          <li id="uid236">
            <p noindent="true">G. Leurent <i>The Missing Difference Problem</i>, Flexible Symmetric Cryptography, March 2018, Leiden, Netherlands.</p>
          </li>
          <li id="uid237">
            <p noindent="true">M. Naya-Plasencia, <i>Quantum Safe Symmetric Cryptography</i>, Flexible Symmetric Cryptography Lorentz Center Workshop, 2018, Leiden, Netherlands, March 19 - 23, 2018.</p>
          </li>
          <li id="uid238">
            <p noindent="true">M. Naya-Plasencia, <i>Symmetric lightweight primitives: (Design and) Cryptanalysis</i>, Lightweight Crypto Day, April 2018, Tel Aviv, Israel.</p>
          </li>
          <li id="uid239">
            <p noindent="true">L. Perrin, <i>Generalized Feistel Networks with Optimal Diffusion</i>, Dagstuhl Seminar 18021 Symmetric Cryptography, Jan 2018, Dagstuhl, Germany</p>
          </li>
          <li id="uid240">
            <p noindent="true">L. Perrin, <i>S-Box Reverse-Engineering: Boolean Functions, American/Russian Standards, and Butterflies</i>, CECC 2018 - Central European Conference on Cryptology, Jun 2018, Smolenice, Slovakia.</p>
          </li>
        </descriptionlist>
      </subsection>
      <subsection id="uid241" level="2">
        <bodyTitle>Leadership within the Scientific Community</bodyTitle>
        <simplelist>
          <li id="uid242">
            <p noindent="true">A. Canteaut serves as a chair of the steering committee of <i>Fast Software Encryption (FSE)</i>.</p>
          </li>
          <li id="uid243">
            <p noindent="true">A. Canteaut serves on the steering committee of the international competition CAESAR for authenticated encryption <footnote id="uid244" id-text="6"><ref xlink:href="https://competitions.cr.yp.to/caesar.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>competitions.<allowbreak/>cr.<allowbreak/>yp.<allowbreak/>to/<allowbreak/>caesar.<allowbreak/>html</ref></footnote></p>
          </li>
          <li id="uid245">
            <p noindent="true">N. Sendrier serves on the steering committee of <i>Post-quantum cryptography (PQCrypto)</i>.</p>
          </li>
          <li id="uid246">
            <p noindent="true">P. Charpin, N. Sendrier and JP Tillich serve on the steering committee of the WCC conference series.</p>
          </li>
          <li id="uid247">
            <p noindent="true">A. Leverrier serves on the steering committee of <i>DIM SIRTEQ</i> (réseau francilien pour les technologies quantiques).</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid248" level="2">
        <bodyTitle>Research Administration</bodyTitle>
        <simplelist>
          <li id="uid249">
            <p noindent="true">A. Canteaut serves as Head of Science of the Inria Paris research center since September 2017.</p>
          </li>
          <li id="uid250">
            <p noindent="true">A. Canteaut serves on the <i>Inria Evaluation Committee</i> since September 2017.</p>
          </li>
          <li id="uid251">
            <p noindent="true">M. Naya-Plasencia and G. Leurent are members of <i>Inria Paris CSD Committee</i> (Comité de suivi doctoral).</p>
          </li>
          <li id="uid252">
            <p noindent="true">M. Naya-Plasencia is a member of <i>Inria Paris Scientific Hiring Committee</i> (Assignement of PhD, post-doctoral and delegation Inria fundings).</p>
          </li>
          <li id="uid253">
            <p noindent="true">M. Naya-Plasencia serves as head of the jury for PhD scholarships from EDITE.</p>
          </li>
          <li id="uid254">
            <p noindent="true">M. Naya-Plasencia serves on the <i>Comité des usagers du projet "rue Barrault"</i>.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid255" level="2">
        <bodyTitle>Committees for the selection of professors, assistant professors and researchers</bodyTitle>
        <simplelist>
          <li id="uid256">
            <p noindent="true">Inria Paris Chargés de recherche: A. Canteaut (vice-chair)</p>
          </li>
          <li id="uid257">
            <p noindent="true">Inria Chargés de recherche (national selection): A. Canteaut</p>
          </li>
          <li id="uid258">
            <p noindent="true">ISTIC, Rennes, maître de conférence: M. Naya-Plasencia</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid259" level="1">
      <bodyTitle>Teaching - Supervision - Juries</bodyTitle>
      <subsection id="uid260" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <sanspuceslist>
          <li id="uid261">
            <p noindent="true">Master: A. Canteaut, <i>Error-correcting codes and applications to cryptology</i>, 12 hours, M2, University Paris-Diderot (MPRI), France;</p>
          </li>
          <li id="uid262">
            <p noindent="true">Master: A. Chailloux, <i>Quantum Information</i>, 18 hours, M2, University Paris-Diderot (MPRI), France;</p>
          </li>
          <li id="uid263">
            <p noindent="true">Master: A. Leverrier, <i>Quantum information and cryptography</i>, 18 hours, M2, University Paris-Diderot (MPRI), France;</p>
          </li>
          <li id="uid264">
            <p noindent="true">Master: N. Sendrier, Information theory, 40 hours, M1, UVSQ, MINT, France;</p>
          </li>
          <li id="uid265">
            <p noindent="true">Master: J.-P. Tillich, <i>Introduction to Information Theory</i>, 32 hours, M2, Ecole Polytechnique, France;</p>
          </li>
          <li id="uid266">
            <p noindent="true">Corps des Mines: G. Leurent <i>Cryptographie symétrique</i>, 7
hours, Telecom ParisTech, France;</p>
          </li>
        </sanspuceslist>
        <p>The members of the project-team were also invited to give courses at training schools for PhD students and young researchers:</p>
        <simplelist>
          <li id="uid267">
            <p noindent="true">A. Canteaut, <i>Secure building-blocks against differential and linear attacks</i>, Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain, February 2018. 3 hours.</p>
          </li>
          <li id="uid268">
            <p noindent="true">A. Canteaut, <i>Exploiting algebraic properties of block ciphers</i>, Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain, February 2018. 1.5 hours.</p>
          </li>
          <li id="uid269">
            <p noindent="true">G. Leurent <i>How Not to Use a Blockcipher</i>, Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain, February 2018. 2.5 hours.</p>
          </li>
          <li id="uid270">
            <p noindent="true">A. Leverrier, <i>Security of continuous-variable quantum key distribution</i>,
Secure Quantum Communications School, Baiona, Spain, May 2018.</p>
          </li>
          <li id="uid271">
            <p noindent="true">M. Naya-Plasencia, <i>Introduction to Symmetric Cryptography</i>,
Summer School on real-world crypto and privacy, Sibenik, Croatia, June 2018.</p>
          </li>
          <li id="uid272">
            <p noindent="true">M. Naya-Plasencia, <i>Lightweight Cryptography</i>, Summer School on real-world crypto and privacy, Sibenik, Croatia, June 2018.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid273" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <sanspuceslist>
          <li id="uid274">
            <p noindent="true">PhD: Sébastien Duval, <i>Constructions for lightweight cryptography</i>, Sorbonne Université, October 3, 2018.</p>
          </li>
          <li id="uid275">
            <p noindent="true">PhDs: Yann Rotella, <i>Finite fields and symmetric cryptography</i>, Sorbonne Université, September 19, 2018.</p>
          </li>
          <li id="uid276">
            <p noindent="true">PhD in progress: Rodolfo Canto Torres, <i>Analysis of generic decoding algorithms for the Hamming metric and study of cryptosystems based on the rank metric</i>, since September 2015, supervisor: N. Sendrier</p>
          </li>
          <li id="uid277">
            <p noindent="true">PhD in progress: Xavier Bonnetain, <i>Cryptanalysis of symmetric primitives in the post-quantum world</i>, since September 2016, supervisor: M. Naya Plasencia</p>
          </li>
          <li id="uid278">
            <p noindent="true">PhD in progress: Thomas Debris, <i>Quantum algorithms for decoding linear codes</i>, since September 2016, supervisor: J.-P. Tillich</p>
          </li>
          <li id="uid279">
            <p noindent="true">PhD in progress: Antoine Grospellier, <i>LDPC codes: constructions and decoding</i>, since October 2016, supervisor: J.-P. Tillich</p>
          </li>
          <li id="uid280">
            <p noindent="true">PhD in progress: Vivien Londe, <i>Study of quantum LDPC codes</i>, since September 2016, supervisors: G. Zémor and A. Leverrier</p>
          </li>
          <li id="uid281">
            <p noindent="true">PhD in progress: Kevin Carrier, <i>Reconstruction of error-correcting codes</i>, since October 2016, supervisor: N. Sendrier</p>
          </li>
          <li id="uid282">
            <p noindent="true">PhD in progress: Matthieu Lequesne, <i>Attaques par canaux cachés sur les cryptosystèmes à base de codes MDPC quasi-cycliques</i>, since September 2017, supervisor: N. Sendrier</p>
          </li>
          <li id="uid283">
            <p noindent="true">PhD in progress: Ferdinand Sibleyras, <i>Security of modes of operation</i>, since October 2017, supervisor: G. Leurent and A. Canteaut</p>
          </li>
          <li id="uid284">
            <p noindent="true">PhD in progress: Valentin Vasseur, <i>Etude du décodage des codes QC-MDPC</i>, since October 2017, supervisor: N. Sendrier</p>
          </li>
          <li id="uid285">
            <p noindent="true">PhD in progress: Rémi Bricout, <i>Etude de scénarios
non-locaux quantiques à l'aide d'outils de la théorie de l'information
quantique</i>, since September 2017, supervisor: A. Chailloux and A.
Leverrier</p>
          </li>
          <li id="uid286">
            <p noindent="true">PhD in progress: Shouvik Ghorai, <i>Beyond-QKD
continuous-variable quantum cryptographic protocols</i>, since October
2017, supervisors: E. Diamanti (UPMC), A. Leverrier</p>
          </li>
          <li id="uid287">
            <p noindent="true">PhD in progress: Andrea Olivo, <i>Partir de contraintes relativistes pour faire de la cryptographie quantique</i>, since November 2017, supervisors: A. Chailloux and F. Grosshans (laboratoire Aimé Cotton).</p>
          </li>
          <li id="uid288">
            <p noindent="true">PhD in progress: Daniel Coggia, <i>Cryptanalysis techniques for lightweight ciphers</i>, since September 2018, supervisors: A. Canteaut and C. Boura.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid289" level="2">
        <bodyTitle>Juries</bodyTitle>
        <simplelist>
          <li id="uid290">
            <p noindent="true">Alex Bredariol Grilo, <i>Quantum proofs, the Local Hamiltonian problem and applications</i>; Université Sorbonne Paris Cité, Paris, April 27, 2018, committee: A. Leverrier.</p>
          </li>
          <li id="uid291">
            <p noindent="true">Vincent Zucca, <i>Towards efficient arithmetic for Ring-LWE based homomorphic encryption</i>, Sorbonne Université, June 25, 2018, committee: A. Canteaut (chair);</p>
          </li>
          <li id="uid292">
            <p noindent="true">Yann Rotella, <i>Mathématiques discrètes appliquées à la cryptographie symétrique</i>, Sorbonne Université, September 19, 2018, committee: A. Canteaut (supervisor), M. Naya-Plasencia</p>
          </li>
          <li id="uid293">
            <p noindent="true">Dahmun Goudarzi, <i>Secure implementation of block ciphers against physical attacks</i>, PSL, September 21, 2018, committee: A. Canteaut</p>
          </li>
          <li id="uid294">
            <p noindent="true">Sébastien Duval, <i>Constructions pour la cryptographie à bas coût</i>, Sorbonne Université, October 3, committee: C. Boura, A. Canteaut (supervisor), G. Leurent (supervisor)</p>
          </li>
          <li id="uid295">
            <p noindent="true">Benjamin Lac, <i>Cryptographie légère intrinsèquement résistante aux attaques physiques pour l'Internet des objets</i>, Ecole des Mines de St-Etienne, October 18, 2018, committee: A. Canteaut</p>
          </li>
          <li id="uid296">
            <p noindent="true">Michele Minelli, <i>Chiffrement Totalement Homomorphe pour l'Apprentissage Automatique</i>, Université Paris Sciences et Lettres, October 26, 2018, committee: M. Naya-Plasencia (chair)</p>
          </li>
          <li id="uid297">
            <p noindent="true">Claire Delaplace, <i>Algorithmes d’algèbre linéaire pour la cryptographie</i>, Université de Rennes, November 21, 2018, committee: M. Naya-Plasencia.</p>
          </li>
          <li id="uid298">
            <p noindent="true">David Gérault, <i>Security Analysis of Contactless Communication Protocols</i>, Université Clermont Auvergne, November 27, 2018, committee: M. Naya-Plasencia (reviewer).</p>
          </li>
          <li id="uid299">
            <p noindent="true">Colin Chaigneau, <i>Cryptanalyse des Algorithmes de Chiffrement Symétrique</i>, Université de Versailles, November 28, 2018, committee: M. Naya-Plasencia (reviewer).</p>
          </li>
          <li id="uid300">
            <p noindent="true">Victor Cauchois, <i>Couches de Diffusion Lineaires à Partir de Matrices MDS</i>, Université de Rennes, December 13, 2018, committee: M. Naya-Plasencia.</p>
          </li>
          <li id="uid301">
            <p noindent="true">Eloi de Chérisey, <i>Towards a better formalisation of the side-channel threat</i>, Telecom Paris, December 18, 2018, committee: A. Canteaut (chair).</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid302" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <subsection id="uid303" level="2">
        <bodyTitle>Internal or external Inria responsibilities</bodyTitle>
        <simplelist>
          <li id="uid304">
            <p noindent="true"><b>Association Animath</b>: M. Lequesne serves on the board of Animath.</p>
          </li>
          <li id="uid305">
            <p noindent="true">M. Lequesne is also member of the scientific committee of the French Tournament of Young Mathematicians: redaction of the problems for the competition, jury member (chair of a jury) ;
member of the scientific committee of the International Tournament of Young Mathematicians: redaction of the problems for the competition, jury member (chair of a jury) ; Member of the scientific committee of the Correspondances des Jeunes Mathématicien.ne.s: redaction of the problems for the competition.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid306" level="2">
        <bodyTitle>Articles and contents</bodyTitle>
        <simplelist>
          <li id="uid307">
            <p noindent="true">A.Chailloux, <i>L'algorithme de Shor</i>, Interstices, Inria, March 2018.</p>
          </li>
          <li id="uid308">
            <p noindent="true">G. Leurent and M. Naya-Plasencia, <i>La fragilité inattendue du chiffrement symétrique</i>, “La Recherche”, November 2018.</p>
          </li>
          <li id="uid309">
            <p noindent="true">JP Tillich, <i>Les codes correcteurs</i>, “La Recherche”, November 2018, p. 45-46.</p>
          </li>
          <li id="uid310">
            <p noindent="true">A. Canteaut, <i>La meilleure garantie de sécurité est l'épreuve du temps</i>, interview to the journal “La Recherche”, November 2018.</p>
          </li>
          <li id="uid311">
            <p noindent="true">M. Naya-Plasencia, <i>Symmetric Cryptanalysis: The Foundation of Trust</i>, Lorentz Center Highlights, 2018, Leiden, Netherlands, Mars 20, 2018.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid312" level="2">
        <bodyTitle>Education</bodyTitle>
        <simplelist>
          <li id="uid313">
            <p noindent="true"><b>Alkindi cipher challenge:</b> Several members of the project-team are involved in the cipher challenge for high-school students "concours Alkindi" <ref xlink:href="http://www.concours-alkindi.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>concours-alkindi.<allowbreak/>fr/</ref>. Mathieu Lequesne serves as a co-organizer of the challenge, preparing the three rounds and the final. Together with C. Boura and A. Canteaut, he was also involved in the redaction of the exercises, and in videos for Inria channel on different aspects of cryptography and how to solve problems from the Alkindi challenge: <ref xlink:href="https://www.youtube.com/watch?v=Y-VQBzwEaqQ&amp;t=17s" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>youtube.<allowbreak/>com/<allowbreak/>watch?v=Y-VQBzwEaqQ&amp;t=17s</ref>, <ref xlink:href="https://www.youtube.com/watch?v=Mv415zfUFNs&amp;t=3s" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>youtube.<allowbreak/>com/<allowbreak/>watch?v=Mv415zfUFNs&amp;t=3s</ref> and <ref xlink:href="https://www.youtube.com/watch?v=8ohEeTPKBwA&amp;t=21s" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>youtube.<allowbreak/>com/<allowbreak/>watch?v=8ohEeTPKBwA&amp;t=21s</ref>.
The best teams from Académie de Paris have been visiting the SECRET project-team in June 2018 <ref xlink:href="https://www.youtube.com/watch?v=EVLHEOWAORc" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>www.<allowbreak/>youtube.<allowbreak/>com/<allowbreak/>watch?v=EVLHEOWAORc</ref>.</p>
          </li>
          <li id="uid314">
            <p noindent="true">Organization of the event “Rendez-vous des Jeunes Mathématiciennes et Informaticiennes” at Inria Paris (October 22-23) by M. Lequesne, a 2-days camp for 20 high-school girls interested in mathematics and computer science.</p>
          </li>
          <li id="uid315">
            <p noindent="true">Organization of the International Tournament of Young Mathematicians in Paris, a one-week competition (July 5-12) for 120 high-school students. M. Lequesne served as vice-president of the local organizing committee.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid316" level="2">
        <bodyTitle>Interventions</bodyTitle>
        <simplelist>
          <li id="uid317">
            <p noindent="true">A. Canteaut gave a talk to high-school students at Palais de la Découverte, during the “Semaine des maths” (March 2018) <ref xlink:href="#secret-2018-bid37" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>;</p>
          </li>
          <li id="uid318">
            <p noindent="true">A. Canteaut gave the talk during the closing ceremony of “Olympiades nationales de mathématiques” (June 2018) <ref xlink:href="#secret-2018-bid38" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>;</p>
          </li>
          <li id="uid319">
            <p noindent="true">A. Canteaut gave a presentation on research in computer science to 10-year children in a school in Paris (Jan. 2018);</p>
          </li>
          <li id="uid320">
            <p noindent="true">M. Lequesne gave a presentation on code-based cryptography to high-school interns (stagiaires de 3e) (Dec. 2018).</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="secret-2018-bid88" type="inproceedings" rend="refer" n="refercite:beierle:hal-01631130">
      <identifiant type="doi" value="10.1007/978-3-319-63715-0_22"/>
      <identifiant type="hal" value="hal-01631130"/>
      <analytic>
        <title level="a">Proving Resistance Against Invariant Attacks: How to Choose the Round Constants</title>
        <author>
          <persName>
            <foreName>Christof</foreName>
            <surname>Beierle</surname>
            <initial>C.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Leander</surname>
            <initial>G.</initial>
          </persName>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Jonathan</foreName>
            <surname>Katz</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Hovav</foreName>
            <surname>Shacham</surname>
            <initial>H.</initial>
          </persName>
        </editor>
        <title level="m">Crypto 2017 - Advances in Cryptology</title>
        <loc>Santa Barbara, United States</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10402</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <publisher>
            <orgName type="organisation">Steven Myers</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">647–678</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01631130" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01631130</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid85" type="inproceedings" rend="refer" n="refercite:bhargavan:hal-01404208">
      <identifiant type="doi" value="10.1145/2976749.2978423"/>
      <identifiant type="hal" value="hal-01404208"/>
      <analytic>
        <title level="a">On the Practical (In-)Security of 64-bit Block Ciphers</title>
        <author>
          <persName key="prosecco-2018-idp162000">
            <foreName>Karthikeyan</foreName>
            <surname>Bhargavan</surname>
            <initial>K.</initial>
          </persName>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">ACM CCS 2016 - 23rd ACM Conference on Computer and Communications Security</title>
        <loc>Vienna, Austria</loc>
        <imprint>
          <publisher>
            <orgName>ACM</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2016</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01404208" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01404208</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid91" type="inproceedings" rend="refer" n="refercite:canteaut:hal-01104051">
      <identifiant type="hal" value="hal-01104051"/>
      <analytic>
        <title level="a">On the behaviors of affine equivalent Sboxes regarding differential and linear attacks</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Joëlle</foreName>
            <surname>Roué</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Advances in Cryptology - Eurocrypt 2015</title>
        <loc>Sofia, Bulgaria</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>April</month>
            <year>2015</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01104051" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01104051</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid90" type="inproceedings" rend="refer" n="refercite:chailloux:hal-01651007">
      <identifiant type="doi" value="10.1007/978-3-319-70697-9_8"/>
      <identifiant type="hal" value="hal-01651007"/>
      <analytic>
        <title level="a">An Efficient Quantum Collision Search Algorithm and Implications on Symmetric Cryptography</title>
        <author>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Tsuyoshi</foreName>
            <surname>Takagi</surname>
            <initial>T.</initial>
          </persName>
          <persName key="secret-2018-idp193680">
            <foreName>Thomas</foreName>
            <surname>Peyrin</surname>
            <initial>T.</initial>
          </persName>
        </editor>
        <title level="m">Asiacrypt 2017 - Advances in Cryptology</title>
        <loc>Hong Kong, China</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10625</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">211–240</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01651007" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01651007</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid93" type="article" rend="refer" n="refercite:chakraborty:hal-01237241">
      <identifiant type="doi" value="10.1103/PhysRevLett.115.250501"/>
      <identifiant type="hal" value="hal-01237241"/>
      <analytic>
        <title level="a">Arbitrarily long relativistic bit commitment </title>
        <author>
          <persName>
            <foreName>Kaushik</foreName>
            <surname>Chakraborty</surname>
            <initial>K.</initial>
          </persName>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Physical Review Letters</title>
        <imprint>
          <dateStruct>
            <year>2015</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01237241" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01237241</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid89" type="article" rend="refer" n="refercite:charpin:hal-01068860">
      <identifiant type="doi" value="10.1016/j.ffa.2014.02.003"/>
      <identifiant type="hal" value="hal-01068860"/>
      <analytic>
        <title level="a">Sparse Permutations with Low Differential Uniformity</title>
        <author>
          <persName key="secret-2018-idp117600">
            <foreName>Pascale</foreName>
            <surname>Charpin</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Gohar M.</foreName>
            <surname>Kyureghyan</surname>
            <initial>G. M.</initial>
          </persName>
          <persName>
            <foreName>Valentin</foreName>
            <surname>Suder</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Finite Fields and Their Applications</title>
        <imprint>
          <biblScope type="volume">28</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2014</year>
          </dateStruct>
          <biblScope type="pages">214-243</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01068860" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01068860</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid94" type="inproceedings" rend="refer" n="refercite:Courtois_Finiasz_Sendrier01a">
      <analytic>
        <title level="a">How to achieve a McEliece-based Digital Signature Scheme</title>
        <author>
          <persName>
            <foreName>Nicolas</foreName>
            <surname>Courtois</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Matthieu</foreName>
            <surname>Finiasz</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp128592">
            <foreName>Nicolas</foreName>
            <surname>Sendrier</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Advances in Cryptology - Asiacrypt 2001</title>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="number">2248</biblScope>
          <publisher>
            <orgName>Springer-Verlag</orgName>
          </publisher>
          <dateStruct>
            <year>2001</year>
          </dateStruct>
          <biblScope type="pages">157–174</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid87" type="article" rend="refer" n="refercite:couvreur:hal-01661935">
      <identifiant type="doi" value="10.1109/TIT.2016.2574841"/>
      <identifiant type="hal" value="hal-01661935"/>
      <analytic>
        <title level="a">Polynomial Time Attack on Wild McEliece Over Quadratic Extensions</title>
        <author>
          <persName key="grace-2018-idp118848">
            <foreName>Alain</foreName>
            <surname>Couvreur</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Ayoub</foreName>
            <surname>Otmani</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes">
        <title level="j">IEEE Transactions on Information Theory</title>
        <imprint>
          <biblScope type="volume">63</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">404–427</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01661935" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01661935</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid86" type="inproceedings" rend="refer" n="refercite:kaplan:hal-01404196">
      <identifiant type="doi" value="10.1007/978-3-662-53008-5_8"/>
      <identifiant type="hal" value="hal-01404196"/>
      <analytic>
        <title level="a">Breaking Symmetric Cryptosystems Using Quantum Period Finding</title>
        <author>
          <persName>
            <foreName>Marc</foreName>
            <surname>Kaplan</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Matthew</foreName>
            <surname>Robshaw</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Jonathan</foreName>
            <surname>Katz</surname>
            <initial>J.</initial>
          </persName>
        </editor>
        <title level="m">Crypto 2016 - 36th Annual International Cryptology Conference</title>
        <loc>Santa Barbara, United States</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">9815</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">207 - 237</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01404196" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01404196</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid92" type="inproceedings" rend="refer" n="refercite:misoczki:hal-00870929">
      <identifiant type="hal" value="hal-00870929"/>
      <analytic>
        <title level="a">MDPC-McEliece: New McEliece Variants from Moderate Density Parity-Check Codes</title>
        <author>
          <persName>
            <foreName>Rafael</foreName>
            <surname>Misoczki</surname>
            <initial>R.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
          <persName key="secret-2018-idp128592">
            <foreName>Nicolas</foreName>
            <surname>Sendrier</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Paulo S. L. M.</foreName>
            <surname>Barreto</surname>
            <initial>P. S. L. M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">IEEE International Symposium on Information Theory - ISIT 2013</title>
        <loc>Istanbul, Turkey</loc>
        <imprint>
          <dateStruct>
            <month>July</month>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">2069-2073</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-00870929" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00870929</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid4" type="phdthesis" rend="year" n="cite:duval:tel-01900290">
      <identifiant type="hal" value="tel-01900290"/>
      <monogr>
        <title level="m">Constructions for Lightweight Cryptography</title>
        <author>
          <persName key="secret-2018-idp154288">
            <foreName>Sébastien</foreName>
            <surname>Duval</surname>
            <initial>S.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Sorbonne Université , UPMC</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/tel-01900290" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>tel-01900290</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Theses</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid42" type="phdthesis" rend="year" n="cite:rotella:tel-01944827">
      <identifiant type="hal" value="tel-01944827"/>
      <monogr>
        <title level="m">Discrete Mathematics for symmetric cryptography</title>
        <author>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Sorbonne Université</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/tel-01944827" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>tel-01944827</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Theses</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid0" type="article" rend="year" n="cite:beierle:hal-01944995">
      <identifiant type="doi" value="10.13154/tosc.v2018.i4.80-101"/>
      <identifiant type="hal" value="hal-01944995"/>
      <analytic>
        <title level="a">Nonlinear Approximations in Cryptanalysis Revisited</title>
        <author>
          <persName>
            <foreName>Christof</foreName>
            <surname>Beierle</surname>
            <initial>C.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Leander</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03115">
        <idno type="issn">I-NtFnd</idno>
        <title level="j">IACR Transactions on Symmetric Cryptology</title>
        <imprint>
          <biblScope type="volume">2018</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">80-101</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944995" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944995</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid12" type="article" rend="year" n="cite:boura:hal-01944598">
      <identifiant type="doi" value="10.13154/tosc.v2018.i3.290-310"/>
      <identifiant type="hal" value="hal-01944598"/>
      <analytic>
        <title level="a">On the Boomerang Uniformity of Cryptographic Sboxes</title>
        <author>
          <persName key="secret-2018-idp134320">
            <foreName>Christina</foreName>
            <surname>Boura</surname>
            <initial>C.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03115">
        <idno type="issn">I-NtFnd</idno>
        <title level="j">IACR Transactions on Symmetric Cryptology</title>
        <imprint>
          <biblScope type="volume">2018</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">290-310</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944598" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944598</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid10" type="article" rend="year" n="cite:boura:hal-01944565">
      <identifiant type="doi" value="10.1007/s10623-018-0496-z"/>
      <identifiant type="hal" value="hal-01944565"/>
      <analytic>
        <title level="a">Two Notions of Differential Equivalence on Sboxes</title>
        <author>
          <persName key="secret-2018-idp134320">
            <foreName>Christina</foreName>
            <surname>Boura</surname>
            <initial>C.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Jérémy</foreName>
            <surname>Jean</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Valentin</foreName>
            <surname>Suder</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00462">
        <idno type="issn">0925-1022</idno>
        <title level="j">Designs, Codes and Cryptography</title>
        <imprint>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01944565" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944565</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid2" type="article" rend="year" n="cite:boura:hal-01953916">
      <identifiant type="doi" value="10.1007/s00145-016-9251-7"/>
      <identifiant type="hal" value="hal-01953916"/>
      <analytic>
        <title level="a">Making the Impossible Possible</title>
        <author>
          <persName key="secret-2018-idp134320">
            <foreName>Christina</foreName>
            <surname>Boura</surname>
            <initial>C.</initial>
          </persName>
          <persName key="caramba-2018-idp153040">
            <foreName>Virginie</foreName>
            <surname>Lallemand</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Valentin</foreName>
            <surname>Suder</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01113">
        <idno type="issn">0933-2790</idno>
        <title level="j">Journal of Cryptology</title>
        <imprint>
          <biblScope type="volume">31</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">101-133</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953916" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953916</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid5" type="article" rend="year" n="cite:canteaut:hal-01650012">
      <identifiant type="doi" value="10.1007/s00145-017-9273-9"/>
      <identifiant type="hal" value="hal-01650012"/>
      <analytic>
        <title level="a">Stream Ciphers: A Practical Solution for Efficient Homomorphic-Ciphertext Compression</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Sergiu</foreName>
            <surname>Carpov</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Caroline</foreName>
            <surname>Fontaine</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Tancrède</foreName>
            <surname>Lepoint</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Pascal</foreName>
            <surname>Paillier</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Renaud</foreName>
            <surname>Sirdey</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01113">
        <idno type="issn">0933-2790</idno>
        <title level="j">Journal of Cryptology</title>
        <imprint>
          <biblScope type="volume">31</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">885-916</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01650012" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01650012</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid13" type="article" rend="year" n="cite:canteaut:hal-01953353">
      <identifiant type="doi" value="10.1016/j.ffa.2018.11.008"/>
      <identifiant type="hal" value="hal-01953353"/>
      <analytic>
        <title level="a">On CCZ-Equivalence, Extended-Affine Equivalence, and Function Twisting</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00597">
        <idno type="issn">1071-5797</idno>
        <title level="j">Finite Fields and Their Applications</title>
        <imprint>
          <biblScope type="volume">56</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2019</year>
          </dateStruct>
          <biblScope type="pages">209-246</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953353" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953353</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid51" type="article" rend="year" n="cite:chailloux:hal-01827601">
      <identifiant type="hal" value="hal-01827601"/>
      <analytic>
        <title level="a">L'algorithme quantique de Shor</title>
        <author>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="yes" x-editorial-board="no" x-international-audience="no" id="rid01010">
        <title level="j">Interstices</title>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01827601" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01827601</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid15" type="article" rend="year" n="cite:charpin:hal-01907499">
      <identifiant type="doi" value="10.1016/j.ffa.2018.12.001"/>
      <identifiant type="hal" value="hal-01907499"/>
      <analytic>
        <title level="a">New links between nonlinearity and differential uniformity</title>
        <author>
          <persName key="secret-2018-idp117600">
            <foreName>Pascale</foreName>
            <surname>Charpin</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Jie</foreName>
            <surname>Peng</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00597">
        <idno type="issn">1071-5797</idno>
        <title level="j">Finite Fields and Their Applications</title>
        <imprint>
          <biblScope type="volume">56</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2019</year>
          </dateStruct>
          <biblScope type="pages">188-208</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01907499" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01907499</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid3" type="article" rend="year" n="cite:duval:hal-01944495">
      <identifiant type="doi" value="10.13154/tosc.v2018.i2.48-78"/>
      <identifiant type="hal" value="hal-01944495"/>
      <analytic>
        <title level="a">MDS Matrices with Lightweight Circuits</title>
        <author>
          <persName key="secret-2018-idp154288">
            <foreName>Sébastien</foreName>
            <surname>Duval</surname>
            <initial>S.</initial>
          </persName>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03115">
        <idno type="issn">I-NtFnd</idno>
        <title level="j">IACR Transactions on Symmetric Cryptology</title>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01944495" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944495</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid7" type="article" rend="year" n="cite:fuhr:hal-01944785">
      <identifiant type="doi" value="10.13154/tosc.v2018.i1.29-56"/>
      <identifiant type="hal" value="hal-01944785"/>
      <analytic>
        <title level="a">State-Recovery Attacks on modified Ketje Jr</title>
        <author>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Fuhr</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid03115">
        <idno type="issn">I-NtFnd</idno>
        <title level="j">IACR Transactions on Symmetric Cryptology</title>
        <imprint>
          <biblScope type="volume">2018</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">29-56</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944785" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944785</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid31" type="article" rend="year" n="cite:ghorai:hal-01951932">
      <identifiant type="doi" value="10.1103/PhysRevA.99.012311"/>
      <identifiant type="hal" value="hal-01951932"/>
      <analytic>
        <title level="a">Composable security of two-way continuous-variable quantum key distribution without active symmetrization</title>
        <author>
          <persName key="secret-2018-idp156784">
            <foreName>Shouvik</foreName>
            <surname>Ghorai</surname>
            <initial>S.</initial>
          </persName>
          <persName>
            <foreName>Eleni</foreName>
            <surname>Diamanti</surname>
            <initial>E.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01584">
        <idno type="issn">1050-2947</idno>
        <title level="j">Physical Review A</title>
        <imprint>
          <dateStruct>
            <year>2019</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01951932" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01951932</ref>
        </imprint>
      </monogr>
      <note type="bnote">
        <ref xlink:href="https://arxiv.org/abs/1806.11356" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1806.<allowbreak/>11356</ref>
      </note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid53" type="article" rend="year" n="cite:leurent:hal-01953448">
      <identifiant type="hal" value="hal-01953448"/>
      <analytic>
        <title level="a">La fragilité inattendue du chiffrement symétrique</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="yes" x-editorial-board="yes" x-international-audience="no" id="rid01324">
        <idno type="issn">0029-5671</idno>
        <title level="j">La Recherche : l'actualité des sciences</title>
        <imprint>
          <biblScope type="volume">Novembre 2018</biblScope>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953448" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953448</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid83" type="article" rend="year" n="cite:leverrier:hal-01652084">
      <identifiant type="doi" value="10.1063/1.5007334"/>
      <identifiant type="hal" value="hal-01652084"/>
      <analytic>
        <title level="a"><formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>S</mi><mi>U</mi><mo>(</mo><mi>p</mi><mo>,</mo><mi>q</mi><mo>)</mo></mrow></math></formula> coherent states and a Gaussian de Finetti theorem</title>
        <author>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01198">
        <idno type="issn">0022-2488</idno>
        <title level="j">Journal of Mathematical Physics</title>
        <imprint>
          <biblScope type="volume">59</biblScope>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">042202</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01652084" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01652084</ref>
        </imprint>
      </monogr>
      <note type="bnote">
        <ref xlink:href="https://arxiv.org/abs/1612.05080" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1612.<allowbreak/>05080</ref>
      </note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid32" type="article" rend="year" n="cite:olivo:hal-01951361">
      <identifiant type="doi" value="10.1103/PhysRevA.98.042323"/>
      <identifiant type="hal" value="hal-01951361"/>
      <analytic>
        <title level="a">Ancilla-assisted linear optical Bell measurements and their optimality</title>
        <author>
          <persName key="secret-2018-idp166608">
            <foreName>Andrea</foreName>
            <surname>Olivo</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Frédéric</foreName>
            <surname>Grosshans</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid01584">
        <idno type="issn">1050-2947</idno>
        <title level="j">Physical Review A</title>
        <imprint>
          <biblScope type="volume">98</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">042323</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01951361" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01951361</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid20" type="inproceedings" rend="year" n="cite:aragon:hal-01957179">
      <identifiant type="doi" value="10.1109/ISIT.2018.8437464"/>
      <identifiant type="hal" value="hal-01957179"/>
      <analytic>
        <title level="a">A New Algorithm for Solving the Rank Syndrome Decoding Problem</title>
        <author>
          <persName>
            <foreName>Nicolas</foreName>
            <surname>Aragon</surname>
            <initial>N.</initial>
          </persName>
          <persName>
            <foreName>Philippe</foreName>
            <surname>Gaborit</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Adrien</foreName>
            <surname>Hauteville</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISIT 2018 - IEEE International Symposium on Information Theory</title>
        <loc>Vail, United States</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">2421-2425</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01957179" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01957179</ref>
        </imprint>
        <meeting id="cid89373">
          <title>IEEE International Symposium on Information Theory</title>
          <num>2018</num>
          <abbr type="sigle">ISIT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid9" type="inproceedings" rend="year" n="cite:ashur:hal-01944776">
      <identifiant type="doi" value="10.1007/978-3-030-03329-3_2"/>
      <identifiant type="hal" value="hal-01944776"/>
      <analytic>
        <title level="a">Cryptanalysis of MORUS</title>
        <author>
          <persName>
            <foreName>Tomer</foreName>
            <surname>Ashur</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Maria</foreName>
            <surname>Eichlseder</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Martin M</foreName>
            <surname>Lauridsen</surname>
            <initial>M. M.</initial>
          </persName>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName key="cascade-2018-idp120960">
            <foreName>Brice</foreName>
            <surname>Minaud</surname>
            <initial>B.</initial>
          </persName>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
          <persName>
            <foreName>Yu</foreName>
            <surname>Sasaki</surname>
            <initial>Y.</initial>
          </persName>
          <persName>
            <foreName>Benoît</foreName>
            <surname>Viguier</surname>
            <initial>B.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ASIACRYPT 2018 - 24th Annual International Conference on the Theory and Application of Cryptology and Information Security</title>
        <loc>Brisbane, Australia</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11273</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">35-64</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944776" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944776</ref>
        </imprint>
        <meeting id="cid305389">
          <title>International Conference on the Theory and Application of Cryptology and Information</title>
          <num>24</num>
          <abbr type="sigle">ASIACRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid34" type="inproceedings" rend="year" n="cite:bonnetain:hal-01953914">
      <identifiant type="doi" value="10.1007/978-3-030-03326-2_19"/>
      <identifiant type="hal" value="hal-01953914"/>
      <analytic>
        <title level="a">Hidden Shift Quantum Cryptanalysis and Implications</title>
        <author>
          <persName key="secret-2018-idp139568">
            <foreName>Xavier</foreName>
            <surname>Bonnetain</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ASIACRYPT 2018 - 24th Annual International Conference on the Theory and Application of Cryptology and Information Security</title>
        <loc>Brisbane, Australia</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11272</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">560-592</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953914" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953914</ref>
        </imprint>
        <meeting id="cid305389">
          <title>International Conference on the Theory and Application of Cryptology and Information</title>
          <num>24</num>
          <abbr type="sigle">ASIACRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid11" type="inproceedings" rend="year" n="cite:boura:hal-01955256">
      <identifiant type="doi" value="10.4230/DAGREP.8.1.1"/>
      <identifiant type="hal" value="hal-01955256"/>
      <analytic>
        <title level="a">On Sboxes sharing the same DDT</title>
        <author>
          <persName key="secret-2018-idp134320">
            <foreName>Christina</foreName>
            <surname>Boura</surname>
            <initial>C.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Jérémy</foreName>
            <surname>Jean</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Valentin</foreName>
            <surname>Suder</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">Dagstuhl Seminar 18021 Symmetric Cryptography</title>
        <loc>Dagstuhl, Germany</loc>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955256" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955256</ref>
        </imprint>
        <meeting id="cid58317">
          <title>Dagstuhl Seminar on Symmetric Cryptography</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid1" type="inproceedings" rend="year" n="cite:canteaut:hal-01955286">
      <identifiant type="hal" value="hal-01955286"/>
      <analytic>
        <title level="a">On nonlinear approximations and the linear hull effect</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Christof</foreName>
            <surname>Beierle</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Gregor</foreName>
            <surname>Leander</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">ASK 2018 - 8th Asian Workshop on Symmetric Key Cryptography</title>
        <loc>Kolkata, India</loc>
        <imprint>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955286" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955286</ref>
        </imprint>
        <meeting id="cid625094">
          <title>Asian Workshop on Symmetric Key Cryptography</title>
          <num>8</num>
          <abbr type="sigle">ASK</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid37" type="inproceedings" rend="year" n="cite:canteaut:hal-01955267">
      <identifiant type="hal" value="hal-01955267"/>
      <analytic>
        <title level="a">Chut ! On nous écoute</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no" x-editorial-board="no">
        <title level="m">Semaine des Maths 2018</title>
        <loc>Paris, France</loc>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955267" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955267</ref>
        </imprint>
        <meeting id="cid624268">
          <title>Semaine des mathématiques</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid38" type="inproceedings" rend="year" n="cite:canteaut:hal-01955273">
      <identifiant type="hal" value="hal-01955273"/>
      <analytic>
        <title level="a">Chut ! On nous écoute</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no" x-editorial-board="no">
        <title level="m">Conférence de clôture des Olympiades Nationales de Mathématiques 2018</title>
        <loc>Paris, France</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955273" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955273</ref>
        </imprint>
        <meeting id="cid626163">
          <title>Olympiades Nationales de Mathématiques</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid44" type="inproceedings" rend="year" n="cite:canteaut:hal-01944401">
      <identifiant type="hal" value="hal-01944401"/>
      <analytic>
        <title level="a">Desperately Seeking Sboxes</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">Eurocrypt 2018</title>
        <loc>Tel Aviv, Israel</loc>
        <imprint>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01944401" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944401</ref>
        </imprint>
        <meeting id="cid32774">
          <title>Annual International Conference on the Theory and Applications of Cryptographic Techniques</title>
          <num>37</num>
          <abbr type="sigle">EUROCRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid76" type="inproceedings" rend="year" n="cite:canteaut:hal-01955337">
      <identifiant type="hal" value="hal-01955337"/>
      <analytic>
        <title level="a">L'insoutenable légèreté du chiffrement</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="no" x-proceedings="no" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">Journées Scientifiques Inria 2018</title>
        <loc>Bordeaux, France</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955337" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955337</ref>
        </imprint>
        <meeting id="cid625261">
          <title>Journées Scientifiques Inria</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid14" type="inproceedings" rend="year" n="cite:canteaut:hal-01953349">
      <identifiant type="hal" value="hal-01953349"/>
      <analytic>
        <title level="a">On CCZ-Equivalence, Extended-Affine Equivalence and Function Twisting</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">BFA 2018 - 3rd International Workshop on Boolean Functions and their Applications</title>
        <loc>Loen, Norway</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953349" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953349</ref>
        </imprint>
        <meeting id="cid625775">
          <title>International Workshop on Boolean Functions and their Applications</title>
          <num>3</num>
          <abbr type="sigle">BFA</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid33" type="inproceedings" rend="year" n="cite:chailloux:hal-01950643">
      <identifiant type="hal" value="hal-01950643"/>
      <analytic>
        <title level="a">Relativistic commitment and zero-knowledge proofs</title>
        <author>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Seventeenth Bellairs Crypto-Workshop 2018</title>
        <loc>Holetown, Barbados</loc>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01950643" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01950643</ref>
        </imprint>
        <meeting id="cid626283">
          <title>Bellairs Crypto Workshop on Logical Foundations for Data Science</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid16" type="inproceedings" rend="year" n="cite:charpin:hal-01836184">
      <identifiant type="hal" value="hal-01836184"/>
      <analytic>
        <title level="a">New links between nonlinearity and differential uniformity</title>
        <author>
          <persName key="secret-2018-idp117600">
            <foreName>Pascale</foreName>
            <surname>Charpin</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Jie</foreName>
            <surname>Peng</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Sequences and Their Applications (SETA) 2018</title>
        <loc>Hong-Kong, China</loc>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01836184" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01836184</ref>
        </imprint>
        <meeting id="cid299856">
          <title>International Conference on Sequences and Their Applications</title>
          <num>2018</num>
          <abbr type="sigle">SETA</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid6" type="inproceedings" rend="year" n="cite:couteau:hal-01944772">
      <identifiant type="doi" value="10.1007/978-3-030-03329-3_4"/>
      <identifiant type="hal" value="hal-01944772"/>
      <analytic>
        <title level="a">On the Concrete Security of Goldreich’s Pseudorandom Generator</title>
        <author>
          <persName>
            <foreName>Geoffroy</foreName>
            <surname>Couteau</surname>
            <initial>G.</initial>
          </persName>
          <persName key="cascade-2018-idp133632">
            <foreName>Aurélien</foreName>
            <surname>Dupin</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Pierrick</foreName>
            <surname>Méaux</surname>
            <initial>P.</initial>
          </persName>
          <persName key="cascade-2018-idp160592">
            <foreName>Mélissa</foreName>
            <surname>Rossi</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ASIACRYPT 2018 - 24th Annual International Conference on the Theory and Application of Cryptology and Information Security</title>
        <loc>Brisbane, Australia</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11273</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">96-124</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944772" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944772</ref>
        </imprint>
        <meeting id="cid305389">
          <title>International Conference on the Theory and Application of Cryptology and Information</title>
          <num>24</num>
          <abbr type="sigle">ASIACRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid24" type="inproceedings" rend="year" n="cite:debrisalazard:hal-01957207">
      <identifiant type="doi" value="10.1007/978-3-030-03326-2_3"/>
      <identifiant type="hal" value="hal-01957207"/>
      <analytic>
        <title level="a">Two attacks on rank metric code-based schemes: RankSign and an IBE scheme</title>
        <author>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Debris-Alazard</surname>
            <initial>T.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ASIACRYPT 2018 - 24th International Conference on the Theory and Application of Cryptology and Information Security</title>
        <loc>Brisbane, Australia</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11272</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">62-92</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01957207" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01957207</ref>
        </imprint>
        <meeting id="cid305389">
          <title>International Conference on the Theory and Application of Cryptology and Information</title>
          <num>24</num>
          <abbr type="sigle">ASIACRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid22" type="inproceedings" rend="year" n="cite:eaton:hal-01949590">
      <identifiant type="doi" value="10.1007/978-3-319-79063-3_3"/>
      <identifiant type="hal" value="hal-01949590"/>
      <analytic>
        <title level="a">QC-MDPC: A Timing Attack and a CCA2 KEM</title>
        <author>
          <persName>
            <foreName>Edward</foreName>
            <surname>Eaton</surname>
            <initial>E.</initial>
          </persName>
          <persName key="secret-2018-idp161712">
            <foreName>Matthieu</foreName>
            <surname>Lequesne</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Alex</foreName>
            <surname>Parent</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp128592">
            <foreName>Nicolas</foreName>
            <surname>Sendrier</surname>
            <initial>N.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">PQCrypto 2018 - Ninth International Conference on Post-Quantum Cryptography</title>
        <loc>Fort Lauderdale, United States</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10786</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01949590" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01949590</ref>
        </imprint>
        <meeting id="cid332496">
          <title>International Workshop on Post-Quantum Cryptography</title>
          <num>9</num>
          <abbr type="sigle">PQCrypto</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid28" type="inproceedings" rend="year" n="cite:fawzi:hal-01895430">
      <identifiant type="doi" value="10.1109/FOCS.2018.00076"/>
      <identifiant type="hal" value="hal-01895430"/>
      <analytic>
        <title level="a">Constant overhead quantum fault-tolerance with quantum expander codes</title>
        <author>
          <persName>
            <foreName>Omar</foreName>
            <surname>Fawzi</surname>
            <initial>O.</initial>
          </persName>
          <persName key="secret-2018-idp159248">
            <foreName>Antoine</foreName>
            <surname>Grospellier</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">FOCS 2018 - 59th Annual IEEE Symposium on Foundations of Computer Science</title>
        <loc>Paris, France</loc>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">743-754</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01895430" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01895430</ref>
        </imprint>
        <meeting id="cid31179">
          <title>Annual IEEE Symposium on Foundations of Computer Science</title>
          <num>59</num>
          <abbr type="sigle">FOCS</abbr>
        </meeting>
      </monogr>
      <note type="bnote">
        <ref xlink:href="https://arxiv.org/abs/1808.03821" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1808.<allowbreak/>03821</ref>
      </note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid27" type="inproceedings" rend="year" n="cite:fawzi:hal-01895427">
      <identifiant type="doi" value="10.1145/3188745.3188886"/>
      <identifiant type="hal" value="hal-01895427"/>
      <analytic>
        <title level="a">Efficient decoding of random errors for quantum expander codes</title>
        <author>
          <persName>
            <foreName>Omar</foreName>
            <surname>Fawzi</surname>
            <initial>O.</initial>
          </persName>
          <persName key="secret-2018-idp159248">
            <foreName>Antoine</foreName>
            <surname>Grospellier</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">STOC 2018 - 50th Annual ACM Symposium on the Theory of Computing</title>
        <loc>Los Angeles, United States</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">521-534</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01895427" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01895427</ref>
        </imprint>
        <meeting id="cid25110">
          <title>ACM Symposium on Theory of Computing</title>
          <num>50</num>
          <abbr type="sigle">STOC</abbr>
        </meeting>
      </monogr>
      <note type="bnote">
        <ref xlink:href="https://arxiv.org/abs/1711.08351" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1711.<allowbreak/>08351</ref>
      </note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid29" type="inproceedings" rend="year" n="cite:fawzi:hal-01654670">
      <identifiant type="hal" value="hal-01654670"/>
      <analytic>
        <title level="a">Efficient decoding of random errors for quantum expander codes</title>
        <author>
          <persName>
            <foreName>Omar</foreName>
            <surname>Fawzi</surname>
            <initial>O.</initial>
          </persName>
          <persName key="secret-2018-idp159248">
            <foreName>Antoine</foreName>
            <surname>Grospellier</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">QIP 2018 - 21th Annual Conference on Quantum Information Processing</title>
        <loc>Delft, Netherlands</loc>
        <imprint>
          <publisher>
            <orgName type="organisation">QuTech</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-31</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01654670" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01654670</ref>
        </imprint>
        <meeting id="cid382980">
          <title>Workshop on Quantum Information Processing</title>
          <num>21</num>
          <abbr type="sigle">QIP</abbr>
        </meeting>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1711.08351" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1711.<allowbreak/>08351</ref> - 31 pages</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid35" type="inproceedings" rend="year" n="cite:grassi:hal-01896036">
      <identifiant type="doi" value="10.1007/978-3-030-03326-2_18"/>
      <identifiant type="hal" value="hal-01896036"/>
      <analytic>
        <title level="a">Quantum Algorithms for the k-xor Problem</title>
        <author>
          <persName>
            <foreName>Lorenzo</foreName>
            <surname>Grassi</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ASIACRYPT 2018 - 24th Annual International Conference on the Theory and Application of Cryptology and Information Security</title>
        <loc>Brisbane, Australia</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11272</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">527-559</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01896036" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01896036</ref>
        </imprint>
        <meeting id="cid305389">
          <title>International Conference on the Theory and Application of Cryptology and Information</title>
          <num>24</num>
          <abbr type="sigle">ASIACRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid17" type="inproceedings" rend="year" n="cite:lac:cea-01746138">
      <identifiant type="doi" value="10.1109/ISCAS.2018.8351693"/>
      <identifiant type="hal" value="cea-01746138"/>
      <analytic>
        <title level="a">Thwarting Fault Attacks against Lightweight Cryptography using SIMD Instructions</title>
        <author>
          <persName>
            <foreName>Benjamin</foreName>
            <surname>Lac</surname>
            <initial>B.</initial>
          </persName>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Jacques Jean-Alain</foreName>
            <surname>Fournier</surname>
            <initial>J. J.-A.</initial>
          </persName>
          <persName>
            <foreName>Renaud</foreName>
            <surname>Sirdey</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISCAS 2018 - IEEE International Symposium on Circuits and Systems</title>
        <loc>Florence, Italy</loc>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-5</biblScope>
          <ref xlink:href="https://hal-cea.archives-ouvertes.fr/cea-01746138" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal-cea.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>cea-01746138</ref>
        </imprint>
        <meeting id="cid88801">
          <title>IEEE International Symposium on Circuits and Systems</title>
          <num>2018</num>
          <abbr type="sigle">ISCAS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid25" type="inproceedings" rend="year" n="cite:lequesne:hal-01949569">
      <identifiant type="doi" value="10.1109/ISIT.2018.8437498"/>
      <identifiant type="hal" value="hal-01949569"/>
      <analytic>
        <title level="a">Attack on the Edon-K Key Encapsulation Mechanism</title>
        <author>
          <persName key="secret-2018-idp161712">
            <foreName>Matthieu</foreName>
            <surname>Lequesne</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISIT 2018 - IEEE International Symposium on Information Theory</title>
        <loc>Vail, United States</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">981-985</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01949569" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01949569</ref>
        </imprint>
        <meeting id="cid89373">
          <title>IEEE International Symposium on Information Theory</title>
          <num>2018</num>
          <abbr type="sigle">ISIT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid60" type="inproceedings" rend="year" n="cite:leurent:hal-01953383">
      <identifiant type="hal" value="hal-01953383"/>
      <analytic>
        <title level="a">MDS Matrices with Lightweight Circuits</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">The Challenges of Lightweight Cryptanalysis</title>
        <loc>Tel Aviv, Israel</loc>
        <imprint>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953383" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953383</ref>
        </imprint>
        <meeting id="cid626170">
          <title>The Challenges of Lightweight Cryptanalysis</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid66" type="inproceedings" rend="year" n="cite:leurent:hal-01966550">
      <identifiant type="hal" value="hal-01966550"/>
      <analytic>
        <title level="a">Security Issues with Small Block Sizes</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Lightweight Crypto Day 2018</title>
        <loc>Tel Aviv, Israel</loc>
        <imprint>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01966550" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01966550</ref>
        </imprint>
        <meeting id="cid626284">
          <title>Lightweight Crypto Day</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid59" type="inproceedings" rend="year" n="cite:leurent:hal-01953390">
      <identifiant type="hal" value="hal-01953390"/>
      <analytic>
        <title level="a">The Missing Difference Problem: And its Applications to Counter Mode Encryption</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Flexible Symmetric Cryptography</title>
        <loc>Leiden, Netherlands</loc>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953390" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953390</ref>
        </imprint>
        <meeting id="cid626156">
          <title>Lorentz Center Workhsop Flexible Symmetric Cryptography</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid19" type="inproceedings" rend="year" n="cite:leurent:hal-01944318">
      <identifiant type="doi" value="10.1007/978-3-319-96884-1_11"/>
      <identifiant type="hal" value="hal-01944318"/>
      <analytic>
        <title level="a">Generic Attacks Against Beyond-Birthday-Bound MACs</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Mridul</foreName>
            <surname>Nandi</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp173904">
            <foreName>Ferdinand</foreName>
            <surname>Sibleyras</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Crypto 2018 - 38th International Cryptology Conference</title>
        <loc>Santa Barbara, United States</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10991</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>August</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">306-336</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944318" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944318</ref>
        </imprint>
        <meeting id="cid306210">
          <title>International Cryptology Conference</title>
          <num>38</num>
          <abbr type="sigle">CRYPTO</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid18" type="inproceedings" rend="year" n="cite:leurent:hal-01944288">
      <identifiant type="doi" value="10.1007/978-3-319-78375-8_24"/>
      <identifiant type="hal" value="hal-01944288"/>
      <analytic>
        <title level="a">The Missing Difference Problem, and Its Applications to Counter Mode Encryption</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName key="secret-2018-idp173904">
            <foreName>Ferdinand</foreName>
            <surname>Sibleyras</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Eurocrypt 2018 - 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques</title>
        <loc>Tel Aviv, Israel</loc>
        <title level="s">LNCS - Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">10821</biblScope>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">745-770</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01944288" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01944288</ref>
        </imprint>
        <meeting id="cid32774">
          <title>Annual International Conference on the Theory and Applications of Cryptographic Techniques</title>
          <num>37</num>
          <abbr type="sigle">EUROCRYPT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid75" type="inproceedings" rend="year" n="cite:leverrier:hal-01955373">
      <identifiant type="hal" value="hal-01955373"/>
      <analytic>
        <title level="a">Introduction to quantum computing</title>
        <author>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="no" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Lecture series on Quantum Engineering at University Paris-Saclay</title>
        <loc>Palaiseau, France</loc>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955373" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955373</ref>
        </imprint>
        <meeting id="cid626288">
          <title>Lecture series on Quantum Engineering at University Paris-Saclay</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid8" type="inproceedings" rend="year" n="cite:nayaplasencia:hal-01953975">
      <identifiant type="doi" value="10.4230/DagRep.8.1.1"/>
      <identifiant type="hal" value="hal-01953975"/>
      <analytic>
        <title level="a">New Results on Modified Versions of Ketje Jr</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Fuhr</surname>
            <initial>T.</initial>
          </persName>
          <persName key="secret-2018-idp169040">
            <foreName>Yann</foreName>
            <surname>Rotella</surname>
            <initial>Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Dagstuhl Seminar 18021 Symmetric Cryptography</title>
        <loc>Dagstuhl, Germany</loc>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01953975" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01953975</ref>
        </imprint>
        <meeting id="cid58317">
          <title>Dagstuhl Seminar on Symmetric Cryptography</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid78" type="inproceedings" rend="year" n="cite:nayaplasencia:hal-01954618">
      <identifiant type="hal" value="hal-01954618"/>
      <analytic>
        <title level="a">New Results on Quantum Symmetric Cryptanalysis</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="no" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Journées Nationales 2018 du GDR Informatique Mathématique</title>
        <loc>Palaiseau, France</loc>
        <imprint>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01954618" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01954618</ref>
        </imprint>
        <meeting id="cid624602">
          <title>Journées Nationales du GDR Informatique Mathématique</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid72" type="inproceedings" rend="year" n="cite:nayaplasencia:hal-01953994">
      <identifiant type="hal" value="hal-01953994"/>
      <analytic>
        <title level="a">New results on symmetric quantum cryptanalysis (Keynote speaker)</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">QUANTALGO Quantum Algorithms and Applications</title>
        <loc>Paris, France</loc>
        <imprint>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953994" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953994</ref>
        </imprint>
        <meeting id="cid626164">
          <title>Project Workshop Quantum Algorithms and Applications</title>
          <num>1</num>
          <abbr type="sigle">QUANTALGO</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid48" type="inproceedings" rend="year" n="cite:nayaplasencia:hal-01953997">
      <identifiant type="hal" value="hal-01953997"/>
      <analytic>
        <title level="a">New results on symmetric quantum cryptanalysis</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Crossfyre 2018 - 8th international workshop on cryptography, robustness, and provably secure schemes for female young researchers</title>
        <loc>Surrey, United Kingdom</loc>
        <imprint>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953997" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953997</ref>
        </imprint>
        <meeting id="cid626161">
          <title>International workshop on cryptography, robustness, and provably secure schemes for female young researchers</title>
          <num>8</num>
          <abbr type="sigle">CROSSFYRE</abbr>
        </meeting>
      </monogr>
      <note type="bnote">Keynote speaker at Crossfyre 2018</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid50" type="inproceedings" rend="year" n="cite:nayaplasencia:hal-01953947">
      <identifiant type="hal" value="hal-01953947"/>
      <analytic>
        <title level="a">Symmetric lightweight primitives: (Design and) Cryptanalysis</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Lightweight Crypto Day 2018</title>
        <loc>Tel Aviv, Israel</loc>
        <imprint>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953947" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953947</ref>
        </imprint>
        <meeting id="cid626284">
          <title>Lightweight Crypto Day</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid56" type="inproceedings" rend="year" n="cite:olivo:hal-01951749">
      <identifiant type="hal" value="hal-01951749"/>
      <analytic>
        <title level="a">Optimality of linear optical Bell measurements. How much can ancillae help?</title>
        <author>
          <persName key="secret-2018-idp166608">
            <foreName>Andrea</foreName>
            <surname>Olivo</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Frédéric</foreName>
            <surname>Grosshans</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">GDR IQFA 9th Colloquium</title>
        <loc>Montpellier, France</loc>
        <imprint>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01951749" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01951749</ref>
        </imprint>
        <meeting id="cid625798">
          <title>Colloquium of the GDR IQFA - Ingénierie Quantique, des Aspects Fondamentaux aux Applications</title>
          <num>9</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid70" type="inproceedings" rend="year" n="cite:olivo:hal-01951728">
      <identifiant type="hal" value="hal-01951728"/>
      <analytic>
        <title level="a">Optimality of linear optical Bell measurements. How much can ancillae help?</title>
        <author>
          <persName key="secret-2018-idp166608">
            <foreName>Andrea</foreName>
            <surname>Olivo</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Frédéric</foreName>
            <surname>Grosshans</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ICIQP 2018 - International Conference on Integrated Quantum Photonics</title>
        <loc>Paris, France</loc>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01951728" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01951728</ref>
        </imprint>
        <meeting id="cid626162">
          <title>International Conference on Integrated Quantum Photonics</title>
          <num>2018</num>
          <abbr type="sigle">ICIQP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid71" type="inproceedings" rend="year" n="cite:olivo:hal-01951753">
      <identifiant type="hal" value="hal-01951753"/>
      <analytic>
        <title level="a">Optimality of linear optical Bell measurements. How much can ancillae help?</title>
        <author>
          <persName key="secret-2018-idp166608">
            <foreName>Andrea</foreName>
            <surname>Olivo</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Frédéric</foreName>
            <surname>Grosshans</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Q-Turn: changing paradigms in quantum science</title>
        <loc>Florianopolis, Brazil</loc>
        <imprint>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01951753" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01951753</ref>
        </imprint>
        <meeting id="cid626171">
          <title>Quantum information workshop</title>
          <num>2018</num>
          <abbr type="sigle">Q-turn</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid79" type="inproceedings" rend="year" n="cite:perrin:hal-01959751">
      <identifiant type="hal" value="hal-01959751"/>
      <analytic>
        <title level="a">Building Light but not Weak Protections for the IoT</title>
        <author>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no" x-editorial-board="no">
        <title level="m">PhD Graduation Ceremony of the University of Luxembourg (2018)</title>
        <loc>Belval, Luxembourg</loc>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01959751" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01959751</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid55" type="inproceedings" rend="year" n="cite:perrin:hal-01953351">
      <identifiant type="doi" value="10.4230/DAGREP.8.1.1"/>
      <identifiant type="hal" value="hal-01953351"/>
      <analytic>
        <title level="a">Generalized Feistel Networks with Optimal Diffusion</title>
        <author>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="no">
        <title level="m">Dagstuhl Seminar 18021 Symmetric Cryptography</title>
        <loc>Dagstuhl, Germany</loc>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953351" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953351</ref>
        </imprint>
        <meeting id="cid58317">
          <title>Dagstuhl Seminar on Symmetric Cryptography</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid49" type="inproceedings" rend="year" n="cite:perrin:hal-01953348">
      <identifiant type="hal" value="hal-01953348"/>
      <analytic>
        <title level="a">S-Box Reverse-Engineering: Boolean Functions, American/Russian Standards, and Butterflies</title>
        <author>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes" x-editorial-board="yes">
        <title level="m">CECC 2018 - Central European Conference on Cryptology</title>
        <loc>Smolenice, Slovakia</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-99</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953348" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953348</ref>
        </imprint>
        <meeting id="cid391349">
          <title>Central European Conference on Cryptology</title>
          <num>2018</num>
          <abbr type="sigle"/>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid21" type="inproceedings" rend="year" n="cite:tillich:hal-01957037">
      <identifiant type="doi" value="10.1109/ISIT.2018.8437843"/>
      <identifiant type="hal" value="hal-01957037"/>
      <analytic>
        <title level="a">The decoding failure probability of MDPC codes</title>
        <author>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">ISIT 2018 - IEEE International Symposium on Information Theory</title>
        <loc>Vail, United States</loc>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">941-945</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01957037" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01957037</ref>
        </imprint>
        <meeting id="cid89373">
          <title>IEEE International Symposium on Information Theory</title>
          <num>2018</num>
          <abbr type="sigle">ISIT</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid43" type="unpublished" rend="year" n="cite:bonnetain:hal-01946399">
      <identifiant type="hal" value="hal-01946399"/>
      <monogr>
        <title level="m">On Quantum Slide Attacks</title>
        <author>
          <persName key="secret-2018-idp139568">
            <foreName>Xavier</foreName>
            <surname>Bonnetain</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01946399" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01946399</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid67" type="misc" rend="year" n="cite:bonnetain:hal-01955534">
      <identifiant type="hal" value="hal-01955534"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes/no" x-proceedings="no" x-invited-conference="no">
        <title level="m">Quantum Cryptanalysis of AES</title>
        <author>
          <persName key="secret-2018-idp139568">
            <foreName>Xavier</foreName>
            <surname>Bonnetain</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955534" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955534</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid36" type="unpublished" rend="year" n="cite:bonnetain:hal-01896046">
      <identifiant type="hal" value="hal-01896046"/>
      <monogr>
        <title level="m">Quantum Security Analysis of CSIDH and Ordinary Isogeny-based Schemes</title>
        <author>
          <persName key="secret-2018-idp139568">
            <foreName>Xavier</foreName>
            <surname>Bonnetain</surname>
            <initial>X.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01896046" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01896046</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid63" type="misc" rend="year" n="cite:bonnetain:hal-01961633">
      <identifiant type="hal" value="hal-01961633"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no">
        <title level="m">Submerging CSIDH</title>
        <author>
          <persName key="secret-2018-idp139568">
            <foreName>Xavier</foreName>
            <surname>Bonnetain</surname>
            <initial>X.</initial>
          </persName>
          <persName key="secret-2018-idp171472">
            <foreName>André</foreName>
            <surname>Schrottenloher</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01961633" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01961633</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid46" type="misc" rend="year" n="cite:canteaut:hal-01955320">
      <identifiant type="hal" value="hal-01955320"/>
      <monogr x-scientific-popularization="no">
        <title level="m">Exploiting algebraic properties of block ciphers</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>February</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955320" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955320</ref>
        </imprint>
      </monogr>
      <note type="bnote">COST Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid47" type="misc" rend="year" n="cite:canteaut:hal-01955315">
      <identifiant type="hal" value="hal-01955315"/>
      <monogr x-scientific-popularization="no">
        <title level="m">Secure building-blocks against differential and linear attacks</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>February</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955315" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955315</ref>
        </imprint>
      </monogr>
      <note type="bnote">COST Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid82" type="misc" rend="year" n="cite:canteaut:hal-01959749">
      <identifiant type="hal" value="hal-01959749"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no">
        <title level="m">On CCZ-Equivalence, Extended-Affine Equivalence and Function Twisting</title>
        <author>
          <persName key="secret-2018-idp112224">
            <foreName>Anne</foreName>
            <surname>Canteaut</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp136960">
            <foreName>Léo</foreName>
            <surname>Perrin</surname>
            <initial>L.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01959749" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01959749</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid40" type="misc" rend="year" n="cite:kevin:hal-01959614">
      <identifiant type="hal" value="hal-01959614"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" x-proceedings="no" x-invited-conference="no">
        <title level="m">Near collisions search and generic decoding</title>
        <author>
          <persName key="secret-2018-idp146928">
            <foreName>Kevin</foreName>
            <surname>Carrier</surname>
            <initial>K.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01959614" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01959614</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid54" type="unpublished" rend="year" n="cite:chailloux:hal-01950650">
      <identifiant type="doi" value="10.01790"/>
      <identifiant type="hal" value="hal-01950650"/>
      <monogr>
        <title level="m">A note on the quantum query complexity of permutation symmetric functions</title>
        <author>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01950650" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01950650</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1810.01790" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1810.<allowbreak/>01790</ref> - 8 pages</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid58" type="misc" rend="year" n="cite:chailloux:hal-01950649">
      <identifiant type="hal" value="hal-01950649"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" x-proceedings="no" x-invited-conference="no">
        <title level="m">DEREC - Développement de la cryptographie relativiste</title>
        <author>
          <persName key="secret-2018-idp115136">
            <foreName>André</foreName>
            <surname>Chailloux</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01950649" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01950649</ref>
        </imprint>
      </monogr>
      <note type="howpublished">WISG 2018 - 12ème Workshop Interdisciplinaire sur la Sécurité Globale</note>
      <note type="bnote">Poster</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid68" type="unpublished" rend="year" n="cite:charpin:hal-01908336">
      <identifiant type="hal" value="hal-01908336"/>
      <monogr>
        <title level="m">Differential uniformity and the associated codes of cryptographic functions</title>
        <author>
          <persName key="secret-2018-idp117600">
            <foreName>Pascale</foreName>
            <surname>Charpin</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Jie</foreName>
            <surname>Peng</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01908336" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01908336</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid73" type="mastersthesis" rend="year" n="cite:coggia:hal-01955305">
      <identifiant type="hal" value="hal-01955305"/>
      <monogr x-international-audience="yes">
        <title level="m">On subspace trails cryptanalysis</title>
        <author>
          <persName key="secret-2018-idp149392">
            <foreName>Daniel</foreName>
            <surname>Coggia</surname>
            <initial>D.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université Paris Diderot (Paris 7)</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955305" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955305</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Masters thesis</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid80" type="misc" rend="year" n="cite:coggia:hal-01960306">
      <identifiant type="hal" value="hal-01960306"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes/no" x-proceedings="no" x-invited-conference="no">
        <title level="m">On subspace trails cryptanalysis</title>
        <author>
          <persName key="secret-2018-idp149392">
            <foreName>Daniel</foreName>
            <surname>Coggia</surname>
            <initial>D.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01960306" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01960306</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid84" type="misc" rend="year" n="cite:couvreur:hal-01959617">
      <identifiant type="hal" value="hal-01959617"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" x-proceedings="no" x-invited-conference="no">
        <title level="m">Recovering short secret keys of RLCE encryption scheme in polynomial time</title>
        <author>
          <persName key="grace-2018-idp118848">
            <foreName>Alain</foreName>
            <surname>Couvreur</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp161712">
            <foreName>Matthieu</foreName>
            <surname>Lequesne</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01959617" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01959617</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid26" type="unpublished" rend="year" n="cite:couvreur:hal-01803440">
      <identifiant type="hal" value="hal-01803440"/>
      <monogr>
        <title level="m">Recovering short secret keys of RLCE in polynomial time</title>
        <author>
          <persName key="grace-2018-idp118848">
            <foreName>Alain</foreName>
            <surname>Couvreur</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp161712">
            <foreName>Matthieu</foreName>
            <surname>Lequesne</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01803440" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01803440</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1805.11489" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1805.<allowbreak/>11489</ref> - working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid23" type="unpublished" rend="year" n="cite:debrisalazard:hal-01958175">
      <identifiant type="hal" value="hal-01958175"/>
      <monogr>
        <title level="m">Wave: A New Code-Based Signature Scheme</title>
        <author>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Debris-Alazard</surname>
            <initial>T.</initial>
          </persName>
          <persName key="secret-2018-idp128592">
            <foreName>Nicolas</foreName>
            <surname>Sendrier</surname>
            <initial>N.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01958175" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01958175</ref>
        </imprint>
      </monogr>
      <note type="bnote">preprint IACR disponible sur https://eprint.iacr.org/2018/996/20181022:154324</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid64" type="misc" rend="year" n="cite:debrisalazard:hal-01959613">
      <identifiant type="hal" value="hal-01959613"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" x-proceedings="no" x-invited-conference="no">
        <title level="m">Deux attaques contre des schémas se fondant sur les codes en métrique rang : Ranksign et un chiffrement basé sur l'identité</title>
        <author>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Debris-Alazard</surname>
            <initial>T.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01959613" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01959613</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid39" type="misc" rend="year" n="cite:grospellier:hal-01955453">
      <identifiant type="hal" value="hal-01955453"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="no" x-proceedings="no" x-invited-conference="no">
        <title level="m">Numerical estimate of the threshold for quantum expander codes</title>
        <author>
          <persName key="secret-2018-idp159248">
            <foreName>Antoine</foreName>
            <surname>Grospellier</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp183760">
            <foreName>Anirudh</foreName>
            <surname>Krishna</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01955453" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01955453</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid52" type="unpublished" rend="year" n="cite:grospellier:hal-01895436">
      <identifiant type="doi" value="10.03681"/>
      <identifiant type="hal" value="hal-01895436"/>
      <monogr>
        <title level="m">Numerical study of hypergraph product codes</title>
        <author>
          <persName key="secret-2018-idp159248">
            <foreName>Antoine</foreName>
            <surname>Grospellier</surname>
            <initial>A.</initial>
          </persName>
          <persName key="secret-2018-idp183760">
            <foreName>Anirudh</foreName>
            <surname>Krishna</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01895436" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01895436</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1810.03681" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1810.<allowbreak/>03681</ref> - 10 pages, 2 figures</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid65" type="unpublished" rend="year" n="cite:lequesne:hal-01925323">
      <identifiant type="hal" value="hal-01925323"/>
      <monogr>
        <title level="m">Attack on the EDON-K Key Encapsulation Mechanism</title>
        <author>
          <persName key="secret-2018-idp161712">
            <foreName>Matthieu</foreName>
            <surname>Lequesne</surname>
            <initial>M.</initial>
          </persName>
          <persName key="secret-2018-idp131456">
            <foreName>Jean-Pierre</foreName>
            <surname>Tillich</surname>
            <initial>J.-P.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.sorbonne-universite.fr/hal-01925323" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>sorbonne-universite.<allowbreak/>fr/<allowbreak/>hal-01925323</ref>
        </imprint>
      </monogr>
      <note type="bnote"><ref xlink:href="https://arxiv.org/abs/1802.06157" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>arxiv.<allowbreak/>org/<allowbreak/>abs/<allowbreak/>1802.<allowbreak/>06157</ref> - Submitted to ISIT 2018</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid45" type="misc" rend="year" n="cite:leurent:hal-01953398">
      <identifiant type="hal" value="hal-01953398"/>
      <monogr x-scientific-popularization="no">
        <title level="m">How Not to Use a Blockcipher</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>February</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953398" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953398</ref>
        </imprint>
      </monogr>
      <note type="bnote">COST Training School on Symmetric Cryptography and Blockchain, Torremolinos, Spain</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid81" type="misc" rend="year" n="cite:leurent:hal-01961739">
      <identifiant type="hal" value="hal-01961739"/>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes/no" x-proceedings="no" x-invited-conference="no">
        <title level="m">The Missing Difference Problem, and its Applications to Counter Mode Encryption</title>
        <author>
          <persName key="secret-2018-idp120448">
            <foreName>Gaëtan</foreName>
            <surname>Leurent</surname>
            <initial>G.</initial>
          </persName>
          <persName key="secret-2018-idp173904">
            <foreName>Ferdinand</foreName>
            <surname>Sibleyras</surname>
            <initial>F.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>October</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01961739" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01961739</ref>
        </imprint>
      </monogr>
      <note type="howpublished">JC2 2018 - Journées Codage et Cryptographie</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid30" type="misc" rend="year" n="cite:leverrier:hal-01955365">
      <identifiant type="hal" value="hal-01955365"/>
      <monogr x-scientific-popularization="no">
        <title level="m">Security of continuous-variable quantum key distribution</title>
        <author>
          <persName key="secret-2018-idp122880">
            <foreName>Anthony</foreName>
            <surname>Leverrier</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>May</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01955365" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01955365</ref>
        </imprint>
      </monogr>
      <note type="bnote">Secure Quantum Communications School, Baiona, Spain</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid57" type="misc" rend="year" n="cite:mendel:hal-01953923">
      <identifiant type="doi" value="10.13154/tosc.v2018.i1.1-4"/>
      <identifiant type="hal" value="hal-01953923"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes">
        <title level="m">Preface</title>
        <author>
          <persName>
            <foreName>Florian</foreName>
            <surname>Mendel</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="volume">2018</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1 - 4</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953923" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953923</ref>
        </imprint>
      </monogr>
      <note type="howpublished">IACR Transactions on Symmetric Cryptology (ToSC)</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid69" type="misc" rend="year" n="cite:nayaplasencia:hal-01953897">
      <identifiant type="hal" value="hal-01953897"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes">
        <title level="m">Introduction to Symmetric Cryptography</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953897" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953897</ref>
        </imprint>
      </monogr>
      <note type="howpublished">Summer School on real-world crypto and privacy</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid77" type="misc" rend="year" n="cite:nayaplasencia:hal-01953789">
      <identifiant type="hal" value="hal-01953789"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes">
        <title level="m">Lightweight Cryptography</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>June</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01953789" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953789</ref>
        </imprint>
      </monogr>
      <note type="howpublished">Summer School on real-world crypto and privacy</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid62" type="misc" rend="year" n="cite:nayaplasencia:hal-01954599">
      <identifiant type="hal" value="hal-01954599"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes">
        <title level="m">New results on symmetric quantum cryptanalysis</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01954599" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01954599</ref>
        </imprint>
      </monogr>
      <note type="howpublished">Keynote speaker at Flexible symmetric cryptography -Lorentz Center</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid74" type="misc" rend="year" n="cite:nayaplasencia:hal-01954616">
      <identifiant type="hal" value="hal-01954616"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="no" x-proceedings="no" x-invited-conference="yes">
        <title level="m">New results on symmetric quantum cryptanalysis</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01954616" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01954616</ref>
        </imprint>
      </monogr>
      <note type="howpublished">Seminaire CCA</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid61" type="misc" rend="year" n="cite:nayaplasencia:hal-01954612">
      <identifiant type="hal" value="hal-01954612"/>
      <monogr x-scientific-popularization="no" x-editorial-board="no" x-international-audience="yes" x-proceedings="no" x-invited-conference="yes">
        <title level="m">Symmetric Cryptanalysis: the Foundation of Trust</title>
        <author>
          <persName>
            <foreName>María</foreName>
            <surname>Naya-Plasencia</surname>
            <initial>M.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>March</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01954612" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01954612</ref>
        </imprint>
      </monogr>
      <note type="howpublished">Lorentz Center Highlights</note>
    </biblStruct>
    
    <biblStruct id="secret-2018-bid41" type="mastersthesis" rend="year" n="cite:querolcruz:hal-01893824">
      <identifiant type="hal" value="hal-01893824"/>
      <monogr x-international-audience="yes">
        <title level="m">Conditional Differential Cryptanalysis of the Post-Quantum ARX Symmetric Primitive Salsa20</title>
        <author>
          <persName key="secret-2018-idp186256">
            <foreName>Anaïs</foreName>
            <surname>Querol Cruz</surname>
            <initial>A.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Univeristé Denis Diderot Paris 7</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01893824" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01893824</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Masters thesis</note>
    </biblStruct>
  </biblio>
</raweb>
