EDBT 2026 Demo / reviewers in the wild / expert
John M. Schanck
dblp:138/8980
· DBLP profile ↗
11ranked-venue papers
2as first author
1since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Cryptographic primitives and cryptanalysis · 63% Cryptographic protocols and secure computation · 37% | |
| Theoretical computer science
3 papers |
Quantum computing and quantum information · 76% Computational complexity · 24% |
Topics — the 10 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic primitives and cryptanalysis
post-quantum cryptography |
1.1 | 3 | 2020 | Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020 Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019 High-Speed Key Encapsulation from NTRU · CHES 2017 |
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate revocation |
0.9 | 1 | 2025 | Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025 |
Cryptographic protocols and secure computation › key management
public key infrastructure |
0.9 | 1 | 2025 | Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025 |
Cryptographic primitives and cryptanalysis › post-quantum cryptography
lattice-based cryptography |
0.7 | 2 | 2020 | Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020 High-Speed Key Encapsulation from NTRU · CHES 2017 |
Cryptographic primitives and cryptanalysis › post-quantum cryptography › lattice-based cryptography › shortest vector problem
lattice sieving |
0.4 | 1 | 2020 | Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020 |
Quantum computing and quantum information
quantum algorithms |
0.4 | 1 | 2020 | Estimating Quantum Speedups for Lattice Sieves · ASIACRYPT (2) 2020 |
Cryptographic primitives and cryptanalysis › post-quantum cryptography
isogeny-based cryptography |
0.4 | 1 | 2019 | Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019 |
Cryptographic primitives and cryptanalysis › post-quantum cryptography › isogeny-based cryptography
SIKE |
0.4 | 1 | 2019 | Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019 |
Quantum computing and quantum information
quantum cryptanalysis |
0.4 | 1 | 2019 | Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE · CRYPTO (1) 2019 |
Computational complexity › decision problems
membership problem |
0.3 | 1 | 2025 | Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and Practice · SP 2025 |
Methods — techniques the papers use, named apart from their topics
data structure design · 1.7compression · 1.7quantum walks · 0.4quantum walk · 0.4claw-finding · 0.4claw finding · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and PracticeabstractCRLite is a low-bandwidth, low-latency, privacy-preserving mechanism for distributing certificate revocation data. A CRLite aggregator periodically encodes revocation data into a compact static hash set, or membership test, which can can be downloaded by clients and queried privately. We present a novel data-structure for membership tests, which we call a clubcard, and we evaluate the encoding efficiency of clubcards using data from Mozilla's CRLite infrastructure. As of November 2024, the WebPKI contains over 900 million valid certificates and over 8 million revoked certificates. We describe an instantiation of CRLite that encodes the revocation status of these certificates in a 6.7 MB package. This is 54% smaller than the original instantiation of CRLite presented at the 2017 IEEE Symposium on Security and Privacy, and it is 21% smaller than the lower bound claimed in that work. A sequence of clubcards can encode a dynamic dataset like the WebPKI revocation set. Using data from late 2024 again, we find that clubcards encoding 6 hour delta updates to the WebPKI can be compressed to 26.8 kB on average-a size that makes CRLite truly practical. We have extended Mozilla's CRLite infrastructure so that it can generate clubcards, and we have added client-side support for this system to Firefox. We report on some performance aspects of our implementation, which is currently the default revocation checking mechanism in Firefox Nightly, and we propose strategies for further reducing the bandwidth requirements of CRLite. John M. Schanck |
SP | 1 |
| 2020 | Estimating Quantum Speedups for Lattice Sieves
Martin R. Albrecht, Vlad Gheorghiu, Eamonn W. Postlethwaite, John M. Schanck |
ASIACRYPT (2) | 4 |
| 2020 | Decryption Failure Is More Likely After Success
Nina Bindel, John M. Schanck |
PQCrypto | 2 |
| 2019 | Quantum Cryptanalysis in the RAM Model: Claw-Finding Attacks on SIKE
Samuel Jaques, John M. Schanck |
CRYPTO (1) | 2 |
| 2018 | CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEMabstractRapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security. Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé |
EuroS&P | 6 |
| 2017 | High-Speed Key Encapsulation from NTRU
Andreas Hülsing, Joost Rijneveld, John M. Schanck, Peter Schwabe |
CHES | 3 |
| 2017 | Choosing Parameters for NTRUEncrypt
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte, Zhenfei Zhang |
CT-RSA | 3 |
| 2016 | Estimating the Cost of Generic Quantum Pre-image Attacks on SHA-2 and SHA-3
Matthew Amy, Olivia Di Matteo, Vlad Gheorghiu, Michele Mosca, Alex Parent, John M. Schanck |
SAC | 6 |
| 2016 | Circuit-extension handshakes for Tor achieving forward secrecy in a quantum worldabstractAbstract We propose a circuit extension handshake for Tor that is forward secure against adversaries who gain quantum computing capabilities after session negotiation. In doing so, we refine the notion of an authenticated and confidential channel establishment (ACCE) protocol and define pre-quantum, transitional, and post-quantum ACCE security. These new definitions reflect the types of adversaries that a protocol might be designed to resist. We prove that, with some small modifications, the currently deployed Tor circuit extension handshake, ntor, provides pre-quantum ACCE security. We then prove that our new protocol, when instantiated with a post-quantum key encapsulation mechanism, achieves the stronger notion of transitional ACCE security. Finally, we instantiate our protocol with NTRU-Encrypt and provide a performance comparison between ntor, our proposal, and the recent design of Ghosh and Kate. John M. Schanck, William Whyte, Zhenfei Zhang |
Proc. Priv. Enhancing Technol. | 1 |
| 2014 | Practical Signatures from the Partial Fourier Recovery Problem
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte |
ACNS | 3 |
| 2014 | Transcript Secure Signatures Based on Modular Lattices
Jeffrey Hoffstein, Jill Pipher, John M. Schanck, Joseph H. Silverman, William Whyte |
PQCrypto | 3 |