Submind YouTube summaries
Thumbnail for Rump session part II (Eurocrypt 2026)

Rump session part II (Eurocrypt 2026)

Watch on YouTube

Video summary

The second part of the Rump session focuses on a serious technical presentation regarding confidential ERC20 token transfers, developed through joint work between speakers and colleagues from various institutions. The proposed system enables private transactions on existing blockchain chains by utilizing an MPC (Multi-Party Computation) network to hide balances and transfer amounts while leveraging the underlying chain for integrity checks via commitments. By employing SNARKs within the MPC framework, the architecture ensures that even if all MPC servers collude, they cannot forge tokens or alter the state without detection. The system is designed with lightweight clients that do not require heavy on-device proving capabilities, achieving a performance metric of up to 300 private transfers per second in current demonstrations, with on-chain costs remaining under one cent per transaction due to efficient proof batching. Following the technical deep dive, the session transitions into a more lighthearted segment comparing legendary Formula 1 drivers to cryptographic primitives and standards. This creative analogy draws parallels between historical racing icons and foundational crypto concepts: Ascari represents the one-time pad for its speed and security, Juan Manuel Fangio is likened to the Enigma machine due to their respective eras and statistical dominance, and Niki Lauda corresponds to homomorphic encryption for his resilience against adversity. The comparison continues through the golden era with Alain Prost as a reliable DSA device, Ayrton Senna as the legend of RSA, Michael Schumacher establishing a new era comparable to AES, Fernando Alonso representing the unique properties of Keccak, Lewis Hamilton associated with ECDSA and Bitcoin's financial success, Max Verstappen linked to lattice-based post-quantum standards like CRYSTALS-Kyber, and Andrea Bazzanella as a hopeful future champion akin to Poseidon. The atmosphere shifts again to artistic and humorous interludes, including an announcement for a new center for theoretical computer science at IIT Madras named after a donor, with an advisory board featuring prominent cryptographers like Shafi Goldwasser. This is followed by a comedic "artistic companion" piece depicting the struggle of maintaining key secrecy against dictators using concepts like anamorphic encryption and robust cryptography, culminating in a satirical song about surveillance stripping away privacy. The session also celebrates the 25th anniversary of AES standardization with reenactments of inventor reactions and a workshop review involving Norwegian secret mountaineers, highlighting the community's enduring engagement with cryptographic history and future challenges like HQC side-channel analysis where message recovery is emphasized as critical for security implications. The final segments of the transcript address practical applications and community initiatives, starting with a call to action from Swiss researchers inviting cryptographers to attack their internet voting system, which has successfully conducted 14 election events without being broken despite open-source specifications. The talk concludes with a challenge offering substantial monetary rewards for breaking specific cryptographic schemes based on heuristics, acknowledging the lack of formal reductions in current security proofs. Throughout these diverse topics, the speakers emphasize the importance of rigorous analysis, community collaboration, and the continuous evolution of cryptographic standards to address emerging threats such as quantum computing and side-channel attacks, all while maintaining a balance between serious research and the vibrant, often humorous culture of the Eurocrypt conference.
Read the full video transcript
Okay, welcome back to the second part of the RAM session. Um, >> and yeah, the next question is which cryptographer had an idea for a cipher and your talk is already half the time is half up but okay. Okay. Hello everyone. So I would have loved to have the song after so that you remember me as a musician but please try to keep that mindset the previous picture of me in your mind. Okay. Okay, so this is a serious talk. So I want to talk to you about Mercus private token transfers via NPC and coarks joint work with my colleagues Florian Lukestein, Christine Rashberger from Tio Gratz and Tacio as well, Verena from Tacio and Roman was from Tacio. Okay, so what's this uh work about? It's a confidential ERC20 transfers on existing chains, but they're private. So we work in the accountbased model. We hide the balances and the transfers amounts. Um in our first version we leak the addresses that are being transferring from and to and we use an NPC network that we hold shares of the balances but for authentication or for integrity we use the chain to hold commitments. So we use cosnarks or snarks running in NPC to bridge the two we use NPC to prove the correct state updates. Okay. So we get privacy from the MPC assumption from non-colision assumption but integrity and this is very important that is not being able to forge any tokens we get them from the blockchain itself even if all MPC servers collude and this is a very important property we have very lightweight clients uh there is no client side snark proving or at least it's super lightweight and in our current demo we can support up to 300 private transfers per Second. Okay. So this is roughly how the architecture look like. Alice, Bob, Charlie, they all can interact with the system. They can request some transactions to happen. They can encrypt their cipher text. Not encrypt like secret share. It's going to be put in an action queue that is going to be read by the NPC servers. The NPC servers are going to read the queue. They're going to execute an NPC protocol to perform update on the secret state. And then they're gonna again compute the new commitments of the new state and also the proof that this update was done correctly. Okay, so this is just u an overview of the performance. So we believe we have a pretty competitive runtimes. This is in a three-party replicated secret sharing setting. For the onchain cost, we are talking about like less than less than a cent for like um or about a cent for a single transaction. So it's pretty cheap and we what an important advantage we have is that we can batch a lot of proofs together. So a lot of clients can come they can request a lot of transfers and then they can they can all do it together. Okay. [laughter] So we have a demo. This is of course just a screenshot of the demo but I'm going to have a link afterwards. And then okay and then and then for future work we would like to hide the sender and the receiver and we will go we will move your transfers >> please follow this and thank you. >> I thought you were going to run for me. Okay. >> So the next question is which year did these two cryptographers become fellows and the hint is symmetric crypto. >> Uh hi everyone. I want to quickly announce uh a center for theoretical computer science at IT Madras. Uh yeah so it's called artfs. It's named after uh the donor who uh donated uh a significant amount of money. Uh so the goal is to advance theoretical computer science research. Uh uh it's the advisory board has Shafi Goldwasher who's a cryptographer and it's headed by another cryptographer Shwatagar also it's it's there's a big focus on cryptography. Uh coming to the uh so one of the focus areas the main focus area is cryptography. Uh oh yeah my time has been haled so I need to part through uh the here's the website feel free to uh look at it uh so the the main coming coming to the coming to the main part we want people to participate to it so uh the yeah so the main slide please please uh visit us or join us we have funding for short-term visitors we we'll organize uh some workshops uh and please write to us write to me or write to shetta if you're interested uh we We're hiring like other assistant professors. Uh we provide generous topups. Uh and why we should come like the ID Madas campus doesn't have lions but like we have a beautiful campus that's a national park and yeah in general we guarantee warm. [applause] >> Thank you very much. [laughter] >> Next question. No. >> What does this image represent? Okay. >> Okay. >> Well, I'm going to talk about my favorite sport, Formula 1, and how it relates to cryptography. Formula 1 is a very Italian sport, you will see. And I'm going to compare each top Formula 1 driver in history with the some cryptographic construction. First we have Ascari the Italian two world championships nine wins in a row. It's comparable to the one time P that is fast probably secure and it's also an old method. Then we have the Argentinian Ju Manuel Fio five world championships the best of the century at least statistically and it can be compared with the nikma machine that is al it was used during the second world war so similar years and even there is a movie about it. Then we have when Formula 1 it gets global the first global icon Nika Austrian three world championships continue racing after a very famous huge crash and is comparable to the helman which means ketography also like global and is allows to continue against adversaries or obstacles like Nicolo did. Then we have the golden era first Alen pros French the professor four championships it can be it would have been seven with the rules of last year and it's comparable with DS standard device and also like very reliable like he was and then of course we have the legend of Formula 1 Magic Arton Sennena Brazilian three titers the legend I think is the most important important and it's comparable to RSA which is also the legend of cryptography. Then we come to the new era ' 90s 2000s Michael Sumaker German seven titles the golden years of Ferrari or Wibli and it can be compared with AS which is also established a new era of cryptography standard by again. Then we have my favorite Elano Fernando Spanish two titles the king of the wind. Thank you. [laughter] And it can be compared with Keka because everything that we have seen is like encryption. This is different like Alonso that is different. Then we have for of course Hamilton British seven championships the best statistics ever and it can be compared with ECDSA because it's using Bitcoin so it's more or less the same era and it's also both make a lot of money then we have of course tappen the last one Dutch for for championships the wonder kid he started very And it can be compared with crystal lithium one of the last standards by it's latisbased postquantum which means it has new characteristics like bstappen and now there is a final bonus because now there is the new hope Andrea Kinian tonelli also Italian fast and probably even if we are at the start of the year probably the next world champion and it can be compared with posidon is fast and probably the next Ethereum champion. And that's all. Thank you. [applause] >> So this question is uh who are those cryptographers and the hint very hard hint is that they became fellows 10 years apart. Next speaker Hi. Hi. So, this is the com artistic companion to my serious talk on Friday in the foundation's first session. And to understand the artistic content, I need to introduce like two concepts. Anamorphic encryption works where you have citizens that no longer can keep their keys secret and the dictators know them. And what they do have is a double key which allows them to secretly communicate and this fact is not even known by the dictator. And what the dictator can do is to adversarily choose an encryption scheme and then whatever anamorphic encryption they use they cannot communicate in a private way. For more details Thursday robust crypto as hard as steel all PPT adversaries kneel and in their hearts they always feel that their attacks have failed for real. I am the master of the keys with mind that's never brought to knees for easedroppers do all they please and not a single bit they squeeze. Dictator stripped me of the key. All that it took was one decree and when he set up a no double key could set me free. And then I had nothing to hide. Surveillance straightened out my mind. Before I simply was so blind. Now I know. Dictator is the light. [applause] >> Thank you very much. So the next question is these three people are members of >> Thank you. >> Good. So 25 years of ASMY review. So as you all know AS has been standardized about 25 years ago. So I wanted to give a serious talk but then the lady downstairs she gave maybe a little bit too much kachaka on my kapirinia. So it might not be so serious after all. Uh so it's it's 25 years. So how can you celebrate this and and how did it age? So at uh K and I e they thought oh let's have a plaque. So what was the reaction of the inventors? Well they they were quite happyish. Um and then NIST thought oh let's read the rindal proposal again. And they realized oh there's 25 versions and we only standardized three. So let's standardize a few more. And this is the erection of uh the inventors. And then uh in Norway they have this Norwegian secret mountaineers uh uh guys the NSM and they thought let's review its security discuss the needed adoptions let's have a discussion on this um so they had this workshop and you can see there is a secret uh there there it is a secret so how do you find the secret? Well, we all know this. The best way to look for a secret is to look for the plain text. And if you actually look at the program in a bit more detail, there is a mountain there. What could this possibly mean? Well, well, well. There was a secret dining event. Actually, you got there by by clicking on the secret thing. This is also one way of getting there. So, there's two ominous figures. Uh, and it started very well with a nice little tunnel. Uh, but then uh well, there was an interview of Y. You can see there's a bit of bottle bottles behind him and he is I mean we all love him but he is a bit naive. So he started to talk about in this interrogation about the need that cryptographers needs to to do keep whitening for secure ciphers and this guy kind of misunderstood him and he thought oh yeah you need the the key point is that you need to whiten your cryptographers and it very quickly got out of hand. Um so this was then uh part of the excursion the workshop excursion. Um, so here we see uh a familiar face. Uh, so so this IS CHRISTINA. UH, this is and yeah. [laughter] So these are uh frozen parts reaction broken knees. I mean they're reenactments because I mean they look so sad. that we didn't really dare to take pictures while they were alive because I think they would have killed us. Um, and that's so thank you to Son Reinium for an unforgettable event and uh then uh how do I play? Well done. Actually, let me see if I can take a video. Probably not getting killed, but Yes. So, uh uh that's or Dunlman who is still hiding in a desert to warm up. Uh yes. So, so while the video plays, I should mention that soon at Simla UIB, if you like Norway, we will be hiring. Uh so, if you're looking for kind of a permanent position and you're quadly senior, please come and see me. President. [applause] So, next question. What did those people become this year? Please, next speaker. Hello, my name is Jan and I'm from South Korea. It is quite a serious top. I I I [clears throat] wanted to share my research and it will be nice if I can make some convers good conversation with about this topic. Let me introduce about this one. So uh so the HQC become a standardization in at the knees but the most people in the side channel analysis most people only concern about the recovering the secret key as I as I highlight as a green most people just want to reverse the secret key but for me I for me I want to recover the message part as highlight highlighted as I read. So some reviewers give me some feedback that the message recovery is quite trivial. So I I'm here how much it is how it is important that recovering the message. So at the uh standardization of the HQC need to mention that the HQC is a uh very rare major and stable for about the DFR analysis and then one of the most reason why they their DFR is so is very low because thanks to the concatenate codes they they make some RS and RMD decoding posture. So when we get some uh side channel information about in the uh very noisy tenor we can also use RS lead solomon decoding procedure so we can recover this message very easy. So and then the conclusion is uh when we uh when we recover the message very easy then it means that message recovery breaks the in CCA2 security in the practice. So the so it means that we build a perfect plain text checking oracles. So the PCA attack family is going to be more feasible. So yes, I want to say message recovery is very important. So let's Yeah, thank you. [applause] Thank you very much. Whose collaboration graph is this? No. So there was u there's a presentation that has been skipped because there was a technical problem. So you you might see it next year. And then there's an extra question now that is uh where do these three cryptographers work? So hi everyone. I just want to quickly draw your attention to a workshop I'm organizing together with Simona and Monica. It will be algebraic methods in postquantum cryptography and it will be in Macedonia. Uh coming August 10 to 14 August we will have uh invited talks. We have room also for contributed talks and we will have some workshops and most of all we will also have sun probably and a nice lake to come to. So hope to see you there. [applause] So that's what who is missing. >> Okay, so this is kind of a serious talk. So it's our letter to Euro Crypt attendees from Switzerland. So dear cryptographers, engineers, usability experts and ethnographers, please attack our voting system. So internet voting is clearly a terrible idea as everyone thinks, but Switzerland says, "Well, we'll try anyway." So we tried and we ran 14 productive election events without problems. So it was a win and we published the source code, the symbolic models, the cryptographic specifications. So at this point, we really did everything we could to break it, but nobody has actually broken the system. So please, we have a lot of money. Help us reduce our reward budget and scan the QR code. Join this post evoting bug bounty and come to me or my colleague a for questions in case. Thanks. Thank you. [applause] >> So, next question. Which test of time award did those fellows get? And the hint is leakage. Hello. All right. So, these are things that I do not do but uh uh some of you do. Uh [sighs] all right. So top 10. So first one. So when you write things like it's it's easy to see that you do it after several hour of staring at it. Hard to show. writing without loss of generality and then um eventually losing it standard assumptions whatever you need it to be basically we thank person one for the useful conversation this usually is in the full version and yeah you just hope that the guide doesn't understand you. I mean, we all do. Like what's wrong with that? Yeah. >> Yeah. Like [cheering] [applause] All right. Okay. Let's go. Let's get serious now. Okay. Yeah. Unfortunately, prior work does not satisfy propertics. Yeah. When you're the author of two like bashing your own work is the best way, right? Isn't it? All right. We thank the reviewer for the useful comments. They just don't read that paper like it's don't they? So, nobody does it, right? You ask AI to write the review. It's very bad to do it and then some people spend more time hiding. They they use AI. Yeah. dilemma clearly follows from and wow that's not really clear whether that is true anyway okay last one [applause] which famous results were rejected ed when first submitted. >> All right. Uh thank you for the very nice introduction. So okay uh this will be a very serious talk about challenges cryptographic ones and what better place is there to present challenges than Rome. So Ben, we knew in our arena, but it would be very like boring if you have an empty arena because we have to have some blood bot, right? We want to see some action. So this is our antagonist. It's a witness encryption scheme essentially. Uh well, this is a very brief workflow if you're not familiar with that primitive. And the nice thing is that we have currently the most efficient uh scheme that that fulfills that and that leads to the paper. So, let's add this to the arena. But it's still it's still boring because [laughter] because we only have one team, right? So, we need a second team and these are the very brave brave gladiators and that's actually you cryptographers. So, let's get to the serious part now because we're actually giving away $100k for that. So, let's see what we have. We're giving away Yeah. real money. So, the condition is very simple. You just have to solve some very very simple loading equations like you do this all the time right it's not so hard so yeah we give around 30k for like full breaks so these are small scale instances of course but still the full instances and we give away also some additional num money for like interesting observations what whatever this means so yeah okay so why are we doing this well unfortunately we base the security on heristics and as far as we know there are no reductions there. So we did everything we could but we invite more crypto analysis to this scheme. So we have these concrete challenges and yeah so this QR code leads to the to the challenges actually. So in Boca Loop which is English for good luck. Thanks. [applause] >> Thank you Marcus. Okay.