Elena Kirshanova

dblp:141/8674 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0001-8924-7605ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 8 first-author · 12 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Cool + Cruel = Dual, and New Benchmarks for Sparse LWE
Alexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite, Ludo N. Pulles, Fernando Virdia, Paul Vié
EUROCRYPT (4)2
2025 Fast Slicer for Batch-CVP: Making Lattice Hybrid Attacks Practical
Alexander Karenin, Elena Kirshanova, Julian Nowakowski, Alexander May 0001
ASIACRYPT (3)2
2025 A Quasi-polynomial Time Algorithm for the Extrapolated Dihedral Coset Problem over Power-of-Two Moduli
Shi Bai 0001, Hansraj Jangir, Elena Kirshanova, Tran Ngo, William Youmans
CRYPTO (2)3
2025 How to lose some weight: a practical template syndrome decoding attack
abstract
Abstract We study the hardness of the Syndrome Decoding problem, the base of most code-based cryptographic schemes, such as Classic McEliece, in the presence of side-channel information. We use ChipWhisperer equipment to perform a template attack on Classic McEliece running on an ARM Cortex-M4, and accurately classify the Hamming weights of consecutive 32-bit blocks of the secret error vector $$\textbf{e}\in {{\mathbb {F}}}_2^n$$ e ∈ F 2 n . With these weights at hand, we optimize Information Set Decoding algorithms. Technically, we demonstrate how to speed up information set decoding via a dimension reduction, additional parity-check equations, and an improved information set search, all derived from the Hamming-weight information. Consequently, using our template attack, we can practically recover an error vector $$\textbf{e}\in {{\mathbb {F}}}_2^n$$ e ∈ F 2 n in dimension $$n=2197$$ n = 2197 in a matter of seconds. Without side-channel information, such an instance has a complexity of around 88 bit. We also estimate how our template attack affects the security of the proposed McEliece parameter sets. Roughly speaking, even an error-prone leak of our Hamming weight information leads for $$n=3488$$ n = 3488 to a security drop of 89 bits.
Sebastian Bitzer, Jeroen Delvaux, Elena Kirshanova, Sebastian Maaßen, Alexander May 0001, Antonia Wachter-Zeh
Des. Codes Cryptogr.3
2024 Asymptotics and Improvements of Sieving for Codes
Léo Ducas, Andre Esser 0001, Simona Etinski, Elena Kirshanova
EUROCRYPT (6)4
2024 Construction-D lattice from Garcia-Stichtenoth tower code
Elena Kirshanova, Ekaterina Malygina
Des. Codes Cryptogr.1
2023 New NTRU Records with Improved Lattice Bases
Elena Kirshanova, Alexander May 0001, Julian Nowakowski
PQCrypto1
2023 Breaking Goppa-based McEliece with hints
Elena Kirshanova, Alexander May 0001
Inf. Comput.1
2023 Quantum algorithms for attacking hardness assumptions in classical and post-quantum cryptography
abstract
Abstract In this survey, the authors review the main quantum algorithms for solving the computational problems that serve as hardness assumptions for cryptosystem. To this end, the authors consider both the currently most widely used classically secure cryptosystems, and the most promising candidates for post‐quantum secure cryptosystems. The authors provide details on the cost of the quantum algorithms presented in this survey. The authors furthermore discuss ongoing research directions that can impact quantum cryptanalysis in the future.
Jean-François Biasse, Xavier Bonnetain, Elena Kirshanova, André Schrottenloher, Fang Song 0001
IET Inf. Secur.3
2022 Practical, Round-Optimal Lattice-Based Blind Signatures
abstract
Blind signatures are a fundamental cryptographic primitive with numerous practical applications. While there exist many practical blind signatures from number-theoretic assumptions, the situation is far less satisfactory from post-quantum assumptions. In this work, we provide the first overall practical, lattice-based blind signature, supporting an unbounded number of signature queries and additionally enjoying optimal round complexity. We provide a detailed estimate of parameters achieved -- we obtain a signature of size slightly above 45KB, for a core-SVP hardness of 109 bits. The run-times of the signer, user and verifier are also very small.
Shweta Agrawal 0001, Elena Kirshanova, Damien Stehlé, Anshu Yadav
CCS2
2021 Lower Bounds on Lattice Sieving and Information Set Decoding
Elena Kirshanova, Thijs Laarhoven
CRYPTO (2)1
2021 How to Find Ternary LWE Keys Using Locality Sensitive Hashing
Elena Kirshanova, Alexander May 0001
IMACC1
2021 Quantum Key Search for Ternary LWE
Maya-Iggy van Hoof, Elena Kirshanova, Alexander May 0001
PQCrypto2
2020 On the smoothing parameter and last minimum of random orthogonal lattices
Elena Kirshanova, Damien Stehlé, Alexandre Wallet
Des. Codes Cryptogr.1
2019 Quantum Algorithms for the Approximate k-List Problem and Their Application to Lattice Sieving
Elena Kirshanova, Erik Mårtensson, Eamonn W. Postlethwaite, Subhayan Roy Moulik
ASIACRYPT (1)1
2019 The General Sieve Kernel and New Records in Lattice Reduction
Martin R. Albrecht, Léo Ducas, Gottfried Herold, Elena Kirshanova, Eamonn W. Postlethwaite, Marc Stevens 0001
EUROCRYPT (2)4
2018 Improved Quantum Information Set Decoding
Elena Kirshanova
PQCrypto1
2018 On the asymptotic complexity of solving LWE
Gottfried Herold, Elena Kirshanova, Alexander May 0001
Des. Codes Cryptogr.2
2016 Parallel Implementation of BDD Enumeration for LWE
Elena Kirshanova, Alexander May 0001, Friedrich Wiemer
ACNS1