Selected Publications

The most important pre-quantum threat to AES-128 is the 1994 van Oorschot–Wiener parallel rho method, a low-communication parallel pre-quantum multi-target preimage-search algorithm. This algorithm uses a mesh of p small processors, each running for approximately $2^{128}/pt$ fast steps, to find one of $t$ independent AES keys $k_1$, …, $k_t$, given the ciphertexts AES_k_1(0), …,AES_k_t(0) for a shared plaintext $0$. NIST has claimed a high post-quantum security level for AES-128, starting from the following rationale: Grover’s algorithm requires a long-running serial computation, which is difficult to implement in practice. In a realistic attack, one has to run many smaller instances of the algorithm in parallel, which makes the quantum speedup less dramatic. NIST has also stated that resistance to multi-key attacks is desirable; but, in a realistic parallel setting, a straightforward multi-key application of Grover’s algorithm costs more than targeting one key at a time. This paper introduces a different quantum algorithm for multi-target preimage search. This algorithm shows, in the same realistic parallel setting, that quantum preimage search benefits asymptotically from having multiple targets. The new algorithm requires a revision of NIST’s AES-128, AES-192, and AES-256 security claims.
In SAC, 2017.

Recent Publications

. DAGS: Key Encapsulation using Dyadic GS Codes. NIST Submission, 2017.

PDF Code

Recent & Upcoming Talks

Preimage (and Kittens) search using Grover Algorithm
Oct 11, 2017
Low-communication parallel quantum multi-target preimage search
Sep 1, 2017
Introduction to Quantum Algorithms
Jun 1, 2016

Recent Posts

Report Starting one more surf «report» about Gran Canarias. It is middle of February, we find a nice place to surf. I mean, every video was with nice waves and happy people surfing. In the first day here, we went to «Playa de La Pared» and the waves weren’t the most exciting, it was 1 to 1.5 meters and it crashed direct. So, no walls to «play». However, it was a good


Report It was end of October, I went to proper surf, that is, I was staying more than one week in Peniche. I knew Portugal (I have surfed in Ribera d’Ilhas - Ericeira in June of 2016) and it is a nice place to surf. In the first day, we didn’t have great waves and it was something like 0.5m. However, when we reached the third day of the trip a massive swell arrived there.


Surf Trip to Portucal ERICEIRA


Report It was January 29th, I was going for a summerschool in Tenerife and I saw some videos about surfing. Unfortunately, I didn’t have much time to go to surf. I just surfed two days in Tenerife. It is possible to see that the wave is completely different from Brazil. In special, it is very different from Florianopolis However, it was a nice opportunity to surf fast waves. I think that the principal from waves from Tenerife is that it is more fast and deep than the waves in Brazil.


Surf in Florianopolis I have a special feeling for Florianopolis. It was the city that I learned to surf. Here, I am going to put the collection of pictures that I have from this awesome place. Florianopolis, Brazil .