EDBT 2026 Demo / reviewers in the wild / expert
Joppe W. Bos
dblp:02/7441
· DBLP profile ↗
34ranked-venue papers
22as first author
5since 2021 · last 2026
0000-0003-1010-8157ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 17 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Theory of computation · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Using Learning with Rounding to Instantiate Post-Quantum Cryptographic AlgorithmsabstractThe Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) article presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This article systematically reviews existing LWR-based schemes — including Saber, Lizard, Florete, Espada, Sable, and SMAUG — analyzing their design choices, parameter sets, and performance tradeoffs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims at guiding future cryptographic design and standardization efforts leveraging LWR. Andrea Basso 0002, Joppe W. Bos, Jan-Pieter D'Anvers, Angshuman Karmakar, Jose Maria Bermudo Mera, Joost Renes, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang 0009, Yuewu Wang, Shicong Zhang, Chenxin Zhong |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2024 | SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data SpaceabstractIn this paper, we present the SECURED project11Funded in part by the European Union (EU), Grant Agreement no. 10109571. Views and opinions expressed are those of the authors and do not necessarily reflect those of the EU or the Health and Digital Executive Agency. Neither the EU nor the granting authority are responsible for them., aimed at improving privacy-preserving processing of data in the health domain. The technologies developed in the project will be demonstrated in four health-related use cases and with the involvement of SME's selected through an open funding call. Francesco Regazzoni 0001, Gergely Ács, Albert Zoltan Aszalos, Christos Avgerinos, Nikolaos Bakalos, Josep Lluís Berral, Joppe W. Bos, Marco Brohet, Andrés G. Castillo, Gareth T. Davies, Stefanos Florescu, Pierre-Elisée Flory, Alberto Gutierrez-Torre, Evangelos Haleplidis, Alice Héliou, Sotiris Ioannidis, Alexander El-Kady, Katarzyna Kapusta, Konstantina Karagianni, Pieter Kruizinga, Kyrian Maat, Zoltán Ádám Mann, Kalliopi Mastoraki, SeoJeong Moon, Maja Nisevic, Balazs Pejo, Kostas Papagiannopoulos, Vassilis Paliouras, Paolo Palmieri 0001, Francesca Palumbo, Juan Carlos Pérez Baun, Péter Pollner, Eduard Porta-Pardo, Luca Pulina, Muhammad Ali Siddiqi, Daniela Spajic, Christos Strydis, George Tasopoulos, Vincent Thouvenot, Christos Tselios, Apostolos P. Fournaris |
DATE | 7 |
| 2023 | PQ.V.ALU.E: Post-quantum RISC-V Custom ALU Extensions on Dilithium and Kyber
Konstantina Miteloudi, Joppe W. Bos, Olivier Bronchain, Björn Fay, Joost Renes |
CARDIS | 2 |
| 2022 | Post-Quantum Cryptography with Contemporary Co-Processors: Beyond Kronecker, Schönhage-Strassen & Nussbaumer
Joppe W. Bos, Joost Renes, Christine van Vredendaal |
USENIX Security Symposium | 1 |
| 2021 | The Matrix Reloaded: Multiplication Strategies in FrodoKEM
Joppe W. Bos, Maximilian Ofner, Joost Renes, Tobias Schneider 0002, Christine van Vredendaal |
CANS | 1 |
| 2019 | Doubly Half-Injective PRGs for Incompressible White-Box Cryptography
Estuardo Alpirez Bock, Alessandro Amadori, Joppe W. Bos, Christopher Brzuska, Wil Michiels |
CT-RSA | 3 |
| 2019 | White-Box Cryptography: Don't Forget About Grey-Box Attacks
Estuardo Alpirez Bock, Joppe W. Bos, Christopher Brzuska, Charles Hubain, Wil Michiels, Cristofaro Mune, Eloi Sanfelix Gonzalez, Philippe Teuwen, Alexander Treff |
J. Cryptol. | 2 |
| 2019 | Arithmetic Considerations for Isogeny-Based CryptographyabstractIn this paper we investigate various arithmetic techniques which can be used to potentially enhance the performance in the supersingular isogeny Diffie-Hellman (SIDH) key-exchange protocol which is one of the more recent contenders in the post-quantum public-key arena. First, we give a systematic overview of techniques to compute efficient arithmetic modulo 2xpy± 1. Our overview shows that in the SIDH setting, where arithmetic over a quadratic extension field is required, the approaches based on the Montgomery reduction for such primes of a special shape are to be preferred. Moreover, the outcome of our investigation reveals that there exist moduli which allow even faster implementations. Second, we investigate if it is beneficial to use other curve models to speed up the elliptic curve scalar multiplication. The use of twisted Edwards curves allows one to search for efficient addition-subtraction chains for fixed scalars while this is not possible with the differential addition law when using Montgomery curves. Our preliminary results show that despite the fact that we found such efficient chains, using twisted Edwards curves does not result in faster scalar multiplication arithmetic in the setting of SIDH. Joppe W. Bos, Simon Friedberger |
IEEE Trans. Computers | 1 |
| 2018 | Differential Attacks on Deterministic Signatures
Christopher Ambrose, Joppe W. Bos, Björn Fay, Marc Joye, Manfred Lochter, Bruce Murray |
CT-RSA | 2 |
| 2018 | CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEMabstractRapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security. Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé |
EuroS&P | 1 |
| 2018 | Assessing the Feasibility of Single Trace Power Analysis of Frodo
Joppe W. Bos, Simon Friedberger, Marco Martinoli, Elisabeth Oswald, Martijn Stam |
SAC | 1 |
| 2017 | Fast Arithmetic Modulo 2x py ± 1abstractWe give a systematic overview of techniques to compute arithmetic modulo 2xpy± 1 and propose improvements. This is useful for computations in the supersingular isogeny Diffie-Hellman (SIDH) key-exchange protocol which is one of the more recent contenders in the post-quantum public-key arena. One of the main computational bottlenecks in this cryptographic key-exchange protocol is computing modular arithmetic in a finite field defined by a prime of this special shape. Recent implementations already use this special prime shape to speed up the cryptographic implementations but it remains unclear if the choices made are optimal or if one can do better. Our overview shows that in the SIDH setting, where arithmetic over a quadratic extension field is required, the approaches based on Montgomery multiplication are to be preferred. Based on our results, we give selection criteria for such moduli and the outcome of our search reveals that there exist moduli which result in even faster implementations. Joppe W. Bos, Simon Friedberger |
ARITH | 1 |
| 2017 | Faster Homomorphic Function Evaluation Using Non-integral Base Encoding
Charlotte Bonte, Carl Bootland, Joppe W. Bos, Wouter Castryck, Ilia Iliashenko, Frederik Vercauteren |
CHES | 3 |
| 2016 | Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEabstractLattice-based cryptography offers some of the most attractive primitives believed to be resistant to quantum computers. Following increasing interest from both companies and government agencies in building quantum computers, a number of works have proposed instantiations of practical post-quantum key exchange protocols based on hard problems in ideal lattices, mainly based on the Ring Learning With Errors (R-LWE) problem. While ideal lattices facilitate major efficiency and storage benefits over their non-ideal counterparts, the additional ring structure that enables these advantages also raises concerns about the assumed difficulty of the underlying problems. Thus, a question of significant interest to cryptographers, and especially to those currently placing bets on primitives that will withstand quantum adversaries, is how much of an advantage the additional ring structure actually gives in practice. Despite conventional wisdom that generic lattices might be too slow and unwieldy, we demonstrate that LWE-based key exchange is quite practical: our constant time implementation requires around 1.3ms computation time for each party; compared to the recent NewHope R-LWE scheme, communication sizes increase by a factor of 4.7x, but remain under 12 KiB in each direction. Our protocol is competitive when used for serving web pages over TLS; when partnered with ECDSA signatures, latencies increase by less than a factor of 1.6x, and (even under heavy load) server throughput only decreases by factors of 1.5x and 1.2x when serving typical 1 KiB and 100 KiB pages, respectively. To achieve these practical results, our protocol takes advantage of several innovations. These include techniques to optimize communication bandwidth, dynamic generation of public parameters (which also offers additional security against backdoors), carefully chosen error distributions, and tight security parameters. Joppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov, Michael Naehrig, Valeria Nikolaenko, Ananth Raghunathan, Douglas Stebila |
CCS | 1 |
| 2016 | Differential Computation Analysis: Hiding Your White-Box Designs is Not Enough
Joppe W. Bos, Charles Hubain, Wil Michiels, Philippe Teuwen |
CHES | 1 |
| 2016 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
J. Cryptol. | 1 |
| 2015 | Post-Quantum Key Exchange for the TLS Protocol from the Ring Learning with Errors ProblemabstractLattice-based cryptographic primitives are believed to offer resilience against attacks by quantum computers. We demonstrate the practicality of post-quantum key exchange by constructing cipher suites for the Transport Layer Security (TLS) protocol that provide key exchange based on the ring learning with errors (R-LWE) problem, we accompany these cipher suites with a rigorous proof of security. Our approach ties lattice-based key exchange together with traditional authentication using RSA or elliptic curve digital signatures: the post-quantum key exchange provides forward secrecy against future quantum attackers, while authentication can be provided using RSA keys that are issued by today's commercial certificate authorities, smoothing the path to adoption. Our cryptographically secure implementation, aimed at the 128-bit security level, reveals that the performance price when switching from non-quantum-safe key exchange is not too high. With our R-LWE cipher suites integrated into the Open SSL library and using the Apache web server on a 2-core desktop computer, we could serve 506 RLWE-ECDSA-AES128-GCM-SHA256 HTTPS connections per second for a 10 KiB payload. Compared to elliptic curve Diffie-Hellman, this means an 8 KiB increased handshake size and a reduction in throughput of only 21%. This demonstrates that provably secure post-quantum key-exchange can already be considered practical. Joppe W. Bos, Craig Costello, Michael Naehrig, Douglas Stebila |
IEEE Symposium on Security and Privacy | 1 |
| 2014 | Mersenne Factorization FactoryabstractWe present work in progress to completely factor seventeen Mersenne numbers using a variant of the special number field sieve where sieving on the algebraic side is shared among the numbers. It is expected that it reduces the overall factoring effort by more than 50%. As far as we know this is the first practical application of Coppersmith’s “factorization factory” idea. Most factorizations used a new double-product approach that led to additional savings in the matrix step. Thorsten Kleinjung, Joppe W. Bos, Arjen K. Lenstra |
ASIACRYPT (1) | 2 |
| 2014 | Cofactorization on Graphics Processing Units
Andrea Miele, Joppe W. Bos, Thorsten Kleinjung, Arjen K. Lenstra |
CHES | 2 |
| 2014 | Private predictive analysis on encrypted medical data
Joppe W. Bos, Kristin E. Lauter, Michael Naehrig |
J. Biomed. Informatics | 1 |
| 2013 | High-Performance Scalar Multiplication Using 8-Dimensional GLV/GLS Decomposition
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
CHES | 1 |
| 2013 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
EUROCRYPT | 1 |
| 2013 | Improved Security for a Ring-Based Fully Homomorphic Encryption Scheme
Joppe W. Bos, Kristin E. Lauter, Jake Loftus, Michael Naehrig |
IMACC | 1 |
| 2013 | Exponentiating in Pairing Groups
Joppe W. Bos, Craig Costello, Michael Naehrig |
Selected Areas in Cryptography | 1 |
| 2013 | Montgomery Multiplication Using Vector Instructions
Joppe W. Bos, Peter L. Montgomery, Daniel Shumow, Gregory M. Zaverucha |
Selected Areas in Cryptography | 1 |
| 2012 | ECM at Work
Joppe W. Bos, Thorsten Kleinjung |
ASIACRYPT | 1 |
| 2012 | Public Keys
Arjen K. Lenstra, James P. Hughes 0001, Maxime Augier, Joppe W. Bos, Thorsten Kleinjung, Christophe Wachter |
CRYPTO | 4 |
| 2011 | Efficient SIMD Arithmetic Modulo a Mersenne NumberabstractThis paper describes carry-less arithmetic operations modulo an integer 2^M-1 in the thousand-bit range, targeted at single instruction multiple data platforms and applications where overall throughput is the main performance criterion. Using an implementation on a cluster of PlayStation 3 game consoles a new record was set for the elliptic curve method for integer factorization. Joppe W. Bos, Thorsten Kleinjung, Arjen K. Lenstra, Peter L. Montgomery |
IEEE Symposium on Computer Arithmetic | 1 |
| 2011 | Efficient Hashing Using the AES Instruction Set
Joppe W. Bos, Onur Özen, Martijn Stam |
CHES | 1 |
| 2010 | Performance Analysis of the SHA-3 Candidates on Exotic Multi-core Architectures
Joppe W. Bos, Deian Stefan |
CHES | 1 |
| 2010 | Factorization of a 768-Bit RSA Modulus
Thorsten Kleinjung, Kazumaro Aoki, Jens Franke, Arjen K. Lenstra, Emmanuel Thomé, Joppe W. Bos, Pierrick Gaudry, Alexander Kruppa, Peter L. Montgomery, Dag Arne Osvik, Herman J. J. te Riele, Andrey Timofeev, Paul Zimmermann 0001 |
CRYPTO | 6 |
| 2010 | Fast Software AES Encryption
Dag Arne Osvik, Joppe W. Bos, Deian Stefan, David Canright |
FSE | 2 |
| 2010 | High-Performance Modular Multiplication on the Cell Processor
Joppe W. Bos |
WAIFI | 1 |
| 2009 | Analysis and Optimization of Cryptographically Generated Addresses
Joppe W. Bos, Onur Özen, Jean-Pierre Hubaux |
ISC | 1 |