Video summary
The second part of the Rump session focuses on a serious technical presentation regarding confidential ERC20 token transfers, developed through joint work between speakers and colleagues from various institutions. The proposed system enables private transactions on existing blockchain chains by utilizing an MPC (Multi-Party Computation) network to hide balances and transfer amounts while leveraging the underlying chain for integrity checks via commitments. By employing SNARKs within the MPC framework, the architecture ensures that even if all MPC servers collude, they cannot forge tokens or alter the state without detection. The system is designed with lightweight clients that do not require heavy on-device proving capabilities, achieving a performance metric of up to 300 private transfers per second in current demonstrations, with on-chain costs remaining under one cent per transaction due to efficient proof batching.
Following the technical deep dive, the session transitions into a more lighthearted segment comparing legendary Formula 1 drivers to cryptographic primitives and standards. This creative analogy draws parallels between historical racing icons and foundational crypto concepts: Ascari represents the one-time pad for its speed and security, Juan Manuel Fangio is likened to the Enigma machine due to their respective eras and statistical dominance, and Niki Lauda corresponds to homomorphic encryption for his resilience against adversity. The comparison continues through the golden era with Alain Prost as a reliable DSA device, Ayrton Senna as the legend of RSA, Michael Schumacher establishing a new era comparable to AES, Fernando Alonso representing the unique properties of Keccak, Lewis Hamilton associated with ECDSA and Bitcoin's financial success, Max Verstappen linked to lattice-based post-quantum standards like CRYSTALS-Kyber, and Andrea Bazzanella as a hopeful future champion akin to Poseidon.
The atmosphere shifts again to artistic and humorous interludes, including an announcement for a new center for theoretical computer science at IIT Madras named after a donor, with an advisory board featuring prominent cryptographers like Shafi Goldwasser. This is followed by a comedic "artistic companion" piece depicting the struggle of maintaining key secrecy against dictators using concepts like anamorphic encryption and robust cryptography, culminating in a satirical song about surveillance stripping away privacy. The session also celebrates the 25th anniversary of AES standardization with reenactments of inventor reactions and a workshop review involving Norwegian secret mountaineers, highlighting the community's enduring engagement with cryptographic history and future challenges like HQC side-channel analysis where message recovery is emphasized as critical for security implications.
The final segments of the transcript address practical applications and community initiatives, starting with a call to action from Swiss researchers inviting cryptographers to attack their internet voting system, which has successfully conducted 14 election events without being broken despite open-source specifications. The talk concludes with a challenge offering substantial monetary rewards for breaking specific cryptographic schemes based on heuristics, acknowledging the lack of formal reductions in current security proofs. Throughout these diverse topics, the speakers emphasize the importance of rigorous analysis, community collaboration, and the continuous evolution of cryptographic standards to address emerging threats such as quantum computing and side-channel attacks, all while maintaining a balance between serious research and the vibrant, often humorous culture of the Eurocrypt conference.
Read the full video transcript
Okay, welcome back to the second part of
the RAM session. Um,
>> and yeah, the next question is which
cryptographer had an idea for a cipher
and your talk is already half the time
is half up but okay. Okay. Hello
everyone. So I would have loved to have
the song after so that you remember me
as a musician but please try to keep
that mindset the previous picture of me
in your mind. Okay. Okay, so this is a
serious talk. So I want to talk to you
about Mercus private token transfers via
NPC and coarks joint work with my
colleagues Florian Lukestein, Christine
Rashberger from Tio Gratz and Tacio as
well, Verena from Tacio and Roman was
from Tacio.
Okay, so what's this uh work about? It's
a confidential ERC20 transfers on
existing chains, but they're private. So
we work in the accountbased model. We
hide the balances and the transfers
amounts. Um in our first version we leak
the addresses that are being
transferring from and to and we use an
NPC network that we hold shares of the
balances but for authentication or for
integrity we use the chain to hold
commitments.
So we use cosnarks or snarks running in
NPC to bridge the two we use NPC to
prove the correct state updates. Okay.
So we get privacy from the MPC
assumption from non-colision assumption
but integrity and this is very important
that is not being able to forge any
tokens we get them from the blockchain
itself even if all MPC servers collude
and this is a very important property we
have very lightweight clients uh there
is no client side snark proving or at
least it's super lightweight and in our
current demo we can support up to 300
private transfers per Second.
Okay. So this is roughly how the
architecture look like. Alice, Bob,
Charlie, they all can interact with the
system. They can request some
transactions to happen. They can encrypt
their cipher text. Not encrypt like
secret share. It's going to be put in an
action queue that is going to be read by
the NPC servers. The NPC servers are
going to read the queue. They're going
to execute an NPC protocol to perform
update on the secret state. And then
they're gonna again compute the new
commitments of the new state and also
the proof that this update was done
correctly.
Okay, so this is just u an overview of
the performance. So we believe we have a
pretty competitive runtimes. This is in
a three-party replicated secret sharing
setting. For the onchain cost, we are
talking about like less than less than a
cent for like um or about a cent for a
single transaction. So it's pretty cheap
and we what an important advantage we
have is that we can batch a lot of
proofs together. So a lot of clients can
come they can request a lot of transfers
and then they can they can all do it
together. Okay. [laughter]
So we have a demo. This is of course
just a screenshot of the demo but I'm
going to have a link afterwards.
And then okay and then and then for
future work we would like to hide the
sender and the receiver and we will go
we will move your transfers
>> please follow this and thank you.
>> I thought you were going to run for me.
Okay.
>> So the next question is which year did
these two cryptographers become fellows
and the hint is symmetric crypto.
>> Uh hi everyone. I want to quickly
announce uh a center for theoretical
computer science at IT Madras. Uh yeah
so it's called artfs. It's named after
uh the donor who uh donated uh a
significant amount of money. Uh so the
goal is to advance theoretical computer
science research. Uh uh it's the
advisory board has Shafi Goldwasher
who's a cryptographer and it's headed by
another cryptographer Shwatagar also
it's it's there's a big focus on
cryptography. Uh coming to the uh so one
of the focus areas the main focus area
is cryptography. Uh oh yeah my time has
been haled so I need to part through uh
the here's the website feel free to uh
look at it uh so the the main coming
coming to the coming to the main part we
want people to participate to it so uh
the yeah so the main slide please please
uh visit us or join us we have funding
for short-term visitors we we'll
organize uh some workshops uh and please
write to us write to me or write to
shetta if you're interested uh we We're
hiring like other assistant professors.
Uh we provide generous topups. Uh and
why we should come like the ID Madas
campus doesn't have lions but like we
have a beautiful campus that's a
national park and yeah in general we
guarantee warm.
[applause]
>> Thank you very much.
[laughter]
>> Next question. No.
>> What does this image represent?
Okay.
>> Okay.
>> Well, I'm going to talk about my
favorite sport, Formula 1, and how it
relates to cryptography. Formula 1 is a
very Italian sport, you will see. And
I'm going to compare each top Formula 1
driver in history with the some
cryptographic construction. First we
have Ascari the Italian two world
championships nine wins in a row. It's
comparable to the one time P that is
fast probably secure and it's also an
old method. Then we have the Argentinian
Ju Manuel Fio five world championships
the best of the century at least
statistically and it can be compared
with the nikma machine that is al it was
used during the second world war so
similar years and even there is a movie
about it.
Then we have when Formula 1 it gets
global the first global icon Nika
Austrian three world championships
continue racing after a very famous huge
crash and is comparable to the helman
which means ketography also like global
and is allows to continue against
adversaries or obstacles like Nicolo
did. Then we have the golden era first
Alen pros French the professor four
championships it can be it would have
been seven with the rules of last year
and it's comparable with DS standard
device and also like very reliable like
he was and then of course we have the
legend of Formula 1
Magic Arton Sennena Brazilian three
titers the legend I think is the most
important important and it's comparable
to RSA which is also the legend of
cryptography.
Then we come to the new era ' 90s 2000s
Michael Sumaker German seven titles the
golden years of Ferrari or Wibli and it
can be compared with AS which is also
established a new era of cryptography
standard by again. Then we have my
favorite Elano Fernando Spanish two
titles the king of the wind. Thank you.
[laughter]
And it can be compared with Keka because
everything that we have seen is like
encryption. This is different like
Alonso that is different. Then we have
for of course Hamilton British seven
championships the best statistics ever
and it can be compared with ECDSA
because it's using Bitcoin so it's more
or less the same era and it's also both
make a lot of money
then we have of course tappen the last
one Dutch
for for championships the wonder kid he
started very
And it can be compared with crystal
lithium one of the last standards by
it's latisbased postquantum which means
it has new characteristics like bstappen
and now there is a final bonus because
now there is the new hope Andrea Kinian
tonelli also Italian
fast and probably even if we are at the
start of the year probably the next
world champion and it can be compared
with posidon is fast and probably the
next Ethereum champion. And that's all.
Thank you.
[applause]
>> So this question is uh who are those
cryptographers and the hint very hard
hint is that they became fellows 10
years apart.
Next speaker
Hi. Hi. So, this is the com artistic
companion to my serious talk on Friday
in the foundation's first session. And
to understand the artistic content, I
need to introduce like two concepts.
Anamorphic encryption works where you
have citizens that no longer can keep
their keys secret and the dictators know
them. And what they do have is a double
key which allows them to secretly
communicate and this fact is not even
known by the dictator. And what the
dictator can do is to adversarily choose
an encryption scheme and then whatever
anamorphic encryption they use they
cannot communicate in a private way. For
more details
Thursday
robust crypto as hard as steel all PPT
adversaries kneel and in their hearts
they always feel that their attacks have
failed for real. I am the master of the
keys with mind that's never brought to
knees for easedroppers do all they
please and not a single bit they
squeeze.
Dictator stripped me of the key. All
that it took was one decree and when he
set up a
no double key could set me free.
And then
I had nothing to hide.
Surveillance straightened out my mind.
Before I simply was so blind. Now I
know.
Dictator is the light.
[applause]
>> Thank you very much. So the next
question is these three people are
members of
>> Thank you.
>> Good. So 25 years of ASMY review. So as
you all know AS has been standardized
about 25 years ago. So I wanted to give
a serious talk but then the lady
downstairs she gave maybe a little bit
too much kachaka on my kapirinia. So it
might not be so serious after all. Uh so
it's it's 25 years. So how can you
celebrate this and and how did it age?
So at uh K and I e they thought oh let's
have a plaque. So what was the reaction
of the inventors? Well they they were
quite happyish.
Um
and then NIST thought oh let's read the
rindal proposal again. And they realized
oh there's 25 versions and we only
standardized three. So let's standardize
a few more. And this is the erection of
uh
the inventors. And then uh in Norway
they have this Norwegian secret
mountaineers uh uh guys the NSM and they
thought let's review its security
discuss the needed adoptions let's have
a discussion on this um so they had this
workshop and you can see there is a
secret uh there there it is a secret so
how do you find the secret? Well, we all
know this. The best way to look for a
secret is to look for the plain text.
And if you actually look at the program
in a bit more detail,
there is a mountain there. What could
this possibly mean? Well, well, well.
There was a secret dining event.
Actually, you got there by by clicking
on the secret thing. This is also one
way of getting there. So, there's two
ominous figures. Uh, and it started very
well with a nice little tunnel. Uh, but
then uh well, there was an interview of
Y. You can see there's a bit of bottle
bottles behind him and he is I mean we
all love him but he is a bit naive. So
he started to talk about in this
interrogation about the need that
cryptographers needs to to do keep
whitening for secure ciphers and this
guy kind of misunderstood him and he
thought oh yeah you need the the key
point is that you need to whiten your
cryptographers and it very quickly got
out of hand. Um so this was then uh part
of the excursion the workshop excursion.
Um,
so here we see uh a familiar face.
Uh, so so this IS CHRISTINA.
UH, this is
and yeah.
[laughter]
So these are uh frozen parts reaction
broken knees. I mean they're
reenactments because I mean they look so
sad. that we didn't really dare to take
pictures while they were alive because I
think they would have killed us. Um, and
that's
so thank you to Son Reinium for an
unforgettable event and uh then
uh how do I play?
Well done.
Actually, let me see if I can take a
video. Probably not getting killed, but
Yes.
So, uh uh that's or Dunlman who is still
hiding in a desert to warm up. Uh
yes. So, so while the video plays, I
should mention that soon at Simla UIB,
if you like Norway, we will be hiring.
Uh so, if you're looking for kind of a
permanent position and you're quadly
senior, please come and see me.
President.
[applause]
So, next question. What did those people
become this year?
Please, next speaker.
Hello, my name is Jan and I'm from South
Korea. It is quite a serious top. I I I
[clears throat]
wanted to share my research and it will
be nice if I can make some convers good
conversation with about this topic. Let
me introduce about this one.
So
uh so the HQC become a standardization
in at the knees but the most people in
the side channel analysis most people
only concern about the recovering the
secret key as I as I highlight as a
green most people just want to reverse
the secret key but for me I for me I
want to recover the message part as
highlight highlighted as I read. So
some reviewers give me some feedback
that the message recovery is quite
trivial. So I I'm here how much it is
how it is important that recovering the
message.
So at the uh standardization of the HQC
need to mention that the HQC is a uh
very rare major and stable for about the
DFR analysis and then one of the most
reason why they their DFR is so is very
low because thanks to the concatenate
codes they they make some RS and RMD
decoding posture. So when we get some uh
side channel information about in the uh
very noisy tenor we can also use RS lead
solomon decoding procedure so we can
recover this message very easy.
So and then the conclusion is uh when we
uh when we recover the message very easy
then it means that message recovery
breaks the in CCA2 security in the
practice. So the
so it means that we build a perfect
plain text checking oracles. So the PCA
attack family is going to be more
feasible. So
yes,
I want to say message recovery is very
important. So let's Yeah, thank you.
[applause]
Thank you very much.
Whose collaboration graph is this?
No. So there was u there's a
presentation that has been skipped
because there was a technical problem.
So you you might see it next year. And
then there's an extra question now that
is uh where do these three
cryptographers work?
So hi everyone. I just want to quickly
draw your attention to a workshop I'm
organizing together with Simona and
Monica. It will be algebraic methods in
postquantum cryptography and it will be
in Macedonia. Uh coming August 10 to 14
August we will have uh invited talks. We
have room also for contributed talks and
we will have some workshops and most of
all we will also have sun probably and a
nice lake to come to. So hope to see you
there.
[applause]
So that's what who is missing.
>> Okay, so this is kind of a serious talk.
So it's our letter to Euro Crypt
attendees from Switzerland. So dear
cryptographers, engineers, usability
experts and ethnographers,
please attack our voting system. So
internet voting is clearly a terrible
idea as everyone thinks, but Switzerland
says, "Well, we'll try anyway." So we
tried and we ran 14 productive election
events without problems. So it was a win
and we published the source code, the
symbolic models, the cryptographic
specifications. So at this point, we
really did everything we could to break
it, but nobody has actually broken the
system. So please, we have a lot of
money. Help us reduce our reward budget
and scan the QR code. Join this post
evoting bug bounty and come to me or my
colleague a for questions in case.
Thanks.
Thank you. [applause]
>> So, next question. Which test of time
award did those fellows get? And the
hint is leakage.
Hello.
All right. So, these are things that I
do not do but uh uh some of you do.
Uh [sighs]
all right. So top 10. So first one. So
when you write things like it's it's
easy to see that
you do it after several hour of staring
at it.
Hard to show.
writing without loss of generality
and then um eventually losing it
standard assumptions
whatever you need it to be basically
we thank person one for the useful
conversation this usually is in the full
version and yeah you just hope that the
guide
doesn't understand you. I mean, we all
do. Like
what's wrong with that?
Yeah.
>> Yeah. Like
[cheering]
[applause]
All right. Okay. Let's go. Let's get
serious now. Okay.
Yeah. Unfortunately, prior work does not
satisfy propertics.
Yeah. When you're the author of two
like bashing your own work is the best
way, right? Isn't it?
All right. We thank the reviewer for the
useful comments.
They just don't read that paper like
it's don't they? So, nobody does it,
right? You ask AI to write the review.
It's very bad to do it and then some
people spend more time hiding.
They they use AI.
Yeah.
dilemma clearly follows from and wow
that's not really clear whether that is
true anyway okay last one
[applause]
which famous results were rejected ed
when first submitted.
>> All right. Uh thank you for the very
nice introduction.
So okay
uh this will be a very serious talk
about challenges cryptographic ones and
what better place is there to present
challenges than Rome. So Ben, we knew in
our arena, but it would be very like
boring if you have an empty arena
because we have to have some blood bot,
right? We want to see some action. So
this is our antagonist. It's a witness
encryption scheme essentially. Uh well,
this is a very brief workflow if you're
not familiar with that primitive. And
the nice thing is that we have currently
the most efficient uh scheme that that
fulfills that and that leads to the
paper. So, let's add this to the arena.
But it's still it's still boring
because [laughter] because we only have
one team, right? So, we need a second
team and these are the very brave brave
gladiators and that's actually you
cryptographers. So, let's get to the
serious part now because we're actually
giving away $100k for that. So, let's
see what we have. We're giving away
Yeah. real money. So, the condition is
very simple. You just have to solve some
very very simple loading equations like
you do this all the time right it's not
so hard so yeah we give around 30k for
like full breaks so these are small
scale instances of course but still the
full instances and we give away also
some additional num money for like
interesting observations what whatever
this means so yeah okay so why are we
doing this well unfortunately we base
the security on heristics and as far as
we know there are no reductions there.
So we did everything we could but we
invite more crypto analysis to this
scheme. So we have these concrete
challenges and yeah so this QR code
leads to the to the challenges actually.
So in Boca Loop which is English for
good luck. Thanks.
[applause]
>> Thank you Marcus.
Okay.