Description
Le but de cet exposé est de présenter très grossièrement deux aspects de la recherche en sécurité menée au LSV (laboratoire spécification et vérification, ENS Cachan et CNRS UMR 8643) et dans le projet INRIA SECSI.<br/> Un premier aspect est la vérification automatique de protocoles cryptographiques. L'idée est au départ de vérifier qu'un protocole est sûr sous des hypothèses simplificatrices assez radicales (chiffrement parfait et modèle de Dolev-Yao sont les deux mots-clés). Les méthodes typiques utilisées au LSV sont fondées sur la logique, la démonstration automatique de théorèmes et la théorie des automates. J'expliquerai rapidement quelques-unes de nos réussites dans ce domaine en 2003, et parlerai des affaiblissements des hypothèses simplificatrices que nous sommes de plus en plus capables de considérer.<br/> D'un autre côté, on aura beau sécuriser les protocoles cryptographiques, les systèmes informatiques réels seront toujours vulnérables. Un cas typique est formé par les attaques dites par buffer-overflow. Je donnerai un aperçu de quelques-unes des attaques les plus subtiles que l'on a vu fleurir récemment, et montrerai comment on peut les détecter et les contrer en temps réel à l'aide d'un outil de détection d'intrusions fondé sur des techniques innovantes de model-checking temps réel, ORCHIDS, développé au LSV.
Next sessions
-
Dissecting CRAFT, a full-round attack
Speaker : Eran Lambooij - Inria
I will present the first full-round key recovery attack on CRAFT, a block cipher introduced at ToSC 2019. The attack builds on the previous observation (ToSC 2026) that the state of CRAFT can be decomposed into two parts that barely exchange information. We transform this property into a dissection attack on the full-round cipher. This shows that in some cases we can elevate the dissection attack[…]-
Cryptography
-
-
Key Attack on the ACDGV Matrix Encryption Scheme
Speaker : Anmoal Porwal - Technical University of Munich
I will present our key-recovery attack on the ACDGV public-key encryption scheme proposed at ASIACRYPT 2024 by Aragon, Couvreur, Dyseryn, Gaborit, and Vinçotte. The secret key is a Gabidulin code hidden by appending random rows and columns and by left- and right-multiplication with invertible matrices. Our attack exploits the resulting algebraic structure to recover an equivalent secret key. It[…]-
Cryptography
-
Asymmetric primitive
-
-
Module Learning With Errors and Structured Extrapolated Dihedral Cosets
Speaker : Jinwei Zheng - Télécom Paris
The Module Learning With Errors (MLWE) problem is the fundamental hardness assumption underlying the key encapsulation and signature schemes ML-KEM and ML-DSA, which have been selected by NIST for post-quantum cryptography standardization. Understanding its quantum hardness is crucial for assessing the security of these standardized schemes. Inspired by the equivalence between LWE and[…]-
Cryptography
-