EDBT 2026 Demo / reviewers in the wild / expert
Joost Renes
dblp:170/3652
· DBLP profile ↗
12ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0003-1884-6330ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Using Learning with Rounding to Instantiate Post-Quantum Cryptographic AlgorithmsabstractThe Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) article presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This article systematically reviews existing LWR-based schemes — including Saber, Lizard, Florete, Espada, Sable, and SMAUG — analyzing their design choices, parameter sets, and performance tradeoffs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims at guiding future cryptographic design and standardization efforts leveraging LWR. Andrea Basso 0002, Joppe W. Bos, Jan-Pieter D'Anvers, Angshuman Karmakar, Jose Maria Bermudo Mera, Joost Renes, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang 0009, Yuewu Wang, Shicong Zhang, Chenxin Zhong |
ACM Trans. Embed. Comput. Syst. | 6 |
| 2023 | PQ.V.ALU.E: Post-quantum RISC-V Custom ALU Extensions on Dilithium and Kyber
Konstantina Miteloudi, Joppe W. Bos, Olivier Bronchain, Björn Fay, Joost Renes |
CARDIS | 5 |
| 2022 | Post-Quantum Cryptography with Contemporary Co-Processors: Beyond Kronecker, Schönhage-Strassen & Nussbaumer
Joppe W. Bos, Joost Renes, Christine van Vredendaal |
USENIX Security Symposium | 2 |
| 2021 | The Matrix Reloaded: Multiplication Strategies in FrodoKEM
Joppe W. Bos, Maximilian Ofner, Joost Renes, Tobias Schneider 0002, Christine van Vredendaal |
CANS | 3 |
| 2019 | Dual Isogenies and Their Application to Public-Key Compression for Isogeny-Based Cryptography
Michael Naehrig, Joost Renes |
ASIACRYPT (2) | 2 |
| 2019 | On Kummer Lines with Full Rational 2-torsion and Their Usage in CryptographyabstractA paper by Karati and Sarkar at Asiacrypt’17 has pointed out the potential for Kummer lines in genus 1, by observing that their SIMD-friendly arithmetic is competitive with the status quo. A more recent preprint explores the connection with (twisted) Edwards curves. In this article, we extend this work and significantly simplify the treatment of Karati and Sarkar. We show that their Kummer line is the x -line of a Montgomery curve translated by a point of order two, and exhibit a natural isomorphism to the y -line of a twisted Edwards curve. Moreover, we show that the Kummer line presented by Gaudry and Lubicz can be obtained via the action of a point of order two on the y -line of an Edwards curve. The maps connecting these curves and lines are all very simple. As a result, a cryptographic implementation can use the arithmetic that is optimal for its instruction set at negligible cost. Hüseyin Hisil, Joost Renes |
ACM Trans. Math. Softw. | 2 |
| 2018 | CSIDH: An Efficient Post-Quantum Commutative Group ActionabstractWe propose an efficient commutative group action suitable for non-interactive key exchange in a post-quantum setting. Our construction follows the layout of the Couveignes–Rostovtsev–Stolbunov cryptosystem, but we apply it to supersingular elliptic curves defined over a large prime field $$\mathbb F_p$$ , rather than to ordinary elliptic curves. The Diffie–Hellman scheme resulting from the group action allows for public-key validation at very little cost, runs reasonably fast in practice, and has public keys of only 64 bytes at a conjectured AES-128 security level, matching NIST’s post-quantum security category I. Wouter Castryck, Tanja Lange 0001, Chloe Martindale, Lorenz Panny, Joost Renes |
ASIACRYPT (3) | 5 |
| 2018 | Computing Isogenies Between Montgomery Curves Using the Action of (0, 0)
Joost Renes |
PQCrypto | 1 |
| 2017 | qDSA: Small and Secure Digital Signatures with Curve-Based Diffie-Hellman Key Pairs
Joost Renes, Benjamin Smith 0003 |
ASIACRYPT (2) | 1 |
| 2017 | Efficient Compression of SIDH Public Keys
Craig Costello, David Jao, Patrick Longa, Michael Naehrig, Joost Renes, David Urbanik |
EUROCRYPT (1) | 5 |
| 2016 | \mu Kummer: Efficient Hyperelliptic Signatures and Key Exchange on Microcontrollers
Joost Renes, Peter Schwabe, Benjamin Smith 0003, Lejla Batina |
CHES | 1 |
| 2016 | Complete Addition Formulas for Prime Order Elliptic Curves
Joost Renes, Craig Costello, Lejla Batina |
EUROCRYPT (1) | 1 |