Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

John M. Schanck

dblp:138/8980 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
1since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 2 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Cryptographic primitives and cryptanalysis · 63% Cryptographic protocols and secure computation · 37%
Theoretical computer science
3 papers
Quantum computing and quantum information · 76% Computational complexity · 24%

Topics — the 10 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic primitives and cryptanalysis
post-quantum cryptography
1.132020
Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020
Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019
High-Speed Key Encapsulation from NTRU · CHES 2017
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate revocation
0.912025
Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025
Cryptographic protocols and secure computation › key management
public key infrastructure
0.912025
Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025
Cryptographic primitives and cryptanalysis › post-quantum cryptography
lattice-based cryptography
0.722020
Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020
High-Speed Key Encapsulation from NTRU · CHES 2017
Cryptographic primitives and cryptanalysis › post-quantum cryptography › lattice-based cryptography › shortest vector problem
lattice sieving
0.412020
Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020
Quantum computing and quantum information
quantum algorithms
0.412020
Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020
Cryptographic primitives and cryptanalysis › post-quantum cryptography
isogeny-based cryptography
0.412019
Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019
Cryptographic primitives and cryptanalysis › post-quantum cryptography › isogeny-based cryptography
SIKE
0.412019
Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019
Quantum computing and quantum information
quantum cryptanalysis
0.412019
Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019
Computational complexity › decision problems
membership problem
0.312025
Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025

Methods — techniques the papers use, named apart from their topics

data structure design · 1.7compression · 1.7quantum walks · 0.4quantum walk · 0.4claw-finding · 0.4claw finding · 0.4
YearPublicationVenuePosition
2025 Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice
abstract
CRLite is a low-bandwidth, low-latency, privacy-preserving mechanism for distributing certificate revocation data. A CRLite aggregator periodically encodes revocation data into a compact static hash set, or membership test, which can can be downloaded by clients and queried privately. We present a novel data-structure for membership tests, which we call a clubcard, and we evaluate the encoding efficiency of clubcards using data from Mozilla's CRLite infrastructure. As of November 2024, the WebPKI contains over 900 million valid certificates and over 8 million revoked certificates. We describe an instantiation of CRLite that encodes the revocation status of these certificates in a 6.7 MB package. This is 54% smaller than the original instantiation of CRLite presented at the 2017 IEEE Symposium on Security and Privacy, and it is 21% smaller than the lower bound claimed in that work. A sequence of clubcards can encode a dynamic dataset like the WebPKI revocation set. Using data from late 2024 again, we find that clubcards encoding 6 hour delta updates to the WebPKI can be compressed to 26.8 kB on average-a size that makes CRLite truly practical. We have extended Mozilla's CRLite infrastructure so that it can generate clubcards, and we have added client-side support for this system to Firefox. We report on some performance aspects of our implementation, which is currently the default revocation checking mechanism in Firefox Nightly, and we propose strategies for further reducing the bandwidth requirements of CRLite.
John M. Schanck
SP1
2020 Estimating Quantum Speedups for Lattice Sieves
Martin R. Albrecht, Vlad Gheorghiu, Eamonn W. Postlethwaite, John M. Schanck
ASIACRYPT (2)4
2020 Decryption Failure Is More Likely After Success
Nina Bindel, John M. Schanck
PQCrypto2
2019 Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE
Samuel Jaques, John M. Schanck
CRYPTO (1)2
2018 CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM
abstract
Rapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security.
Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé
EuroS&P6
2017 High-Speed Key Encapsulation from NTRU
Andreas Hülsing, Joost Rijneveld, John M. Schanck, Peter Schwabe
CHES3
2017 Choosing Parameters for NTRUEncrypt
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte, Zhenfei Zhang
CT-RSA3
2016 Estimating the Cost of Generic Quantum Pre-image Attacks on SHA-2 and SHA-3
Matthew Amy, Olivia Di Matteo, Vlad Gheorghiu, Michele Mosca, Alex Parent, John M. Schanck
SAC6
2016 Circuit-extension handshakes for Tor achieving forward secrecy in a quantum world
abstract
Abstract We propose a circuit extension handshake for Tor that is forward secure against adversaries who gain quantum computing capabilities after session negotiation. In doing so, we refine the notion of an authenticated and confidential channel establishment (ACCE) protocol and define pre-quantum, transitional, and post-quantum ACCE security. These new definitions reflect the types of adversaries that a protocol might be designed to resist. We prove that, with some small modifications, the currently deployed Tor circuit extension handshake, ntor, provides pre-quantum ACCE security. We then prove that our new protocol, when instantiated with a post-quantum key encapsulation mechanism, achieves the stronger notion of transitional ACCE security. Finally, we instantiate our protocol with NTRU-Encrypt and provide a performance comparison between ntor, our proposal, and the recent design of Ghosh and Kate.
John M. Schanck, William Whyte, Zhenfei Zhang
Proc. Priv. Enhancing Technol.1
2014 Practical Signatures from the Partial Fourier Recovery Problem
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte
ACNS3
2014 Transcript Secure Signatures Based on Modular Lattices
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte
PQCrypto3