EDBT 2026 Demo / reviewers in the wild / expert
Nicolas Aragon
dblp:224/9796
· DBLP profile ↗
17ranked-venue papers
11as first author
13since 2021 · last 2025
0000-0002-9446-8688ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 8 first-author · 11 since 2021Theory of computation · 2 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Single Trace Side-Channel Attack on the MPC-in-the-Head Framework
Julie Godard, Nicolas Aragon, Philippe Gaborit, Antoine Loiseau, Julien Maillard |
PQCrypto (2) | 2 |
| 2025 | Secret and shared keys recovery on hamming quasi-cyclic with SASCA
Chloé Baïsse, Antoine Moran, Guillaume Goy, Julien Maillard, Nicolas Aragon, Philippe Gaborit, Maxime Lecomte, Antoine Loiseau |
Des. Codes Cryptogr. | 5 |
| 2024 | MinRank Gabidulin Encryption Scheme on Matrix Codes
Nicolas Aragon, Alain Couvreur, Victor Dyseryn, Philippe Gaborit, Adrien Vinçotte |
ASIACRYPT (4) | 1 |
| 2024 | The Blockwise Rank Syndrome Learning Problem and Its Applications to Cryptography
Nicolas Aragon, Pierre Briaud, Victor Dyseryn, Philippe Gaborit, Adrien Vinçotte |
PQCrypto (1) | 1 |
| 2024 | LowMS: a new rank metric code-based KEM without ideal structure
Nicolas Aragon, Victor Dyseryn, Philippe Gaborit, Pierre Loidreau, Julian Renner, Antonia Wachter-Zeh |
Des. Codes Cryptogr. | 1 |
| 2024 | Efficient error-correcting codes for the HQC post-quantum cryptosystem
Carlos Aguilar Melchor, Nicolas Aragon, Jean-Christophe Deneuville, Philippe Gaborit, Jérôme Lacan, Gilles Zémor |
Des. Codes Cryptogr. | 2 |
| 2023 | BIKE Key-Recovery: Combining Power Consumption Analysis and Information-Set Decoding
Agathe Cheriere, Nicolas Aragon, Tania Richmond, Benoît Gérard |
ACNS (1) | 2 |
| 2023 | Analysis of the Security of the PSSI Problem and Cryptanalysis of the Durandal Signature Scheme
Nicolas Aragon, Victor Dyseryn, Philippe Gaborit |
CRYPTO (3) | 1 |
| 2022 | LRPC Codes with Multiple Syndromes: Near Ideal-Size KEMs Without Ideals
Carlos Aguilar Melchor, Nicolas Aragon, Victor Dyseryn, Philippe Gaborit, Gilles Zémor |
PQCrypto | 2 |
| 2022 | Ouroboros: An Efficient and Provably Secure KEM FamilyabstractIn this paper we introduce Ouroboros, a new family of Key Exchange protocols based on coding theory. The protocols propose a middle ground between the cryptosystems based on$\mathsf {QC}$-$\mathsf {MDPC}$codes, which feature small parameter sizes, but have a security reduction to two problems: the syndrome decoding problem and the indistinguishability of the code, and the HQC protocol, which features bigger parameters but has a security reduction to the syndrome decoding problem only. Ouroboros features a reduction to the syndrome decoding problem with only a small overhead compared to the$\mathsf {QC}$-$\mathsf {MDPC}$based cryptosystems. The approach is based on an ideal structure and also works for the rank metric. This yields a simple, secure and efficient approach for key exchange, the Ouroboros family of protocols. For the Hamming metric we obtain the same type of parameters (and almost the same simple decoding) as for$\mathsf {MDPC}$based cryptosystems, but with a security reduction to decoding random quasi-cyclic codes in the Random Oracle Model. This represents a reduction of up to 38% on the public key size compared to HQC, for the most secure parameters. For the rank metric, we obtain better parameters than for RQC, saving up to 31% on the public key for the most secure set of parameters, using non homogeneous errors in Ouroboros. In this full version, the protocol and decoding algorithm have been slightly improved, additional details are given in the security proof, and the protocol is fully described for the rank metric. Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Gilles Zémor |
IEEE Trans. Inf. Theory | 1 |
| 2021 | Cryptanalysis of the Rank Preserving Signature
Nicolas Aragon, Maxime Bros, Philippe Gaborit |
IMACC | 1 |
| 2021 | Fast and Secure Key Generation for Low Rank Parity Check Codes CryptosystemsabstractAmong the candidates for NIST's post-quantum cryptography standardization project, cryptosystems that rely on Low Rank Parity Check (LRPC) codes have interesting properties, such as a low public key size. However, the key generation phase for these cryptosystems is computationally expensive when done in constant-time, which is a security requirement on the standardization project, making it almost unusable for ephemeral key generation. We present a new constant-time algorithm for key generation on LRPC code-based cryptosystems, that divides the computational costs by four when compared to previous work over ROLLO, one of the NIST candidates. Our improvement consists in changing the way objects of a quotient ring are represented. By switching from a canonical basis to an optimal normal basis, we enable the full potential of the Itoh-Tsuiji algorithm for field inversion. Carlos Aguilar Melchor, Nicolas Aragon, Victor Dyseryn, Philippe Gaborit |
ISIT | 2 |
| 2021 | Cryptanalysis of a code-based full-time signature
Nicolas Aragon, Marco Baldi, Jean-Christophe Deneuville, Karan Khathuria, Edoardo Persichetti, Paolo Santini |
Des. Codes Cryptogr. | 1 |
| 2020 | Cryptanalysis of a rank-based signature with short public keys
Nicolas Aragon, Olivier Blazy, Jean-Christophe Deneuville, Philippe Gaborit, Terry Shue Chien Lau, Chik How Tan, Keita Xagawa |
Des. Codes Cryptogr. | 1 |
| 2019 | Durandal: A Rank Metric Based Signature Scheme
Nicolas Aragon, Olivier Blazy, Philippe Gaborit, Adrien Hauteville, Gilles Zémor |
EUROCRYPT (3) | 1 |
| 2019 | Low Rank Parity Check Codes: New Decoding Algorithms and Applications to CryptographyabstractWe introduce a new family of rank metric codes: Low Rank Parity Check codes (LRPC), for which we propose an efficient probabilistic decoding algorithm. This family of codes can be seen as the equivalent of classical LDPC codes for the rank metric. We then use these codes to design cryptosystems à la McEliece: more precisely we propose two schemes for key encapsulation mechanism (KEM) and public key encryption (PKE). Unlike rank metric codes used in previous encryption algorithms -notably Gabidulin codes - LRPC codes have a very weak algebraic structure. Our cryptosystems can be seen as an equivalent of the NTRU cryptosystem (and also to the more recent MDPC code-based cryptosystem) in a rank metric context, due to the similar form of the public keys. The present paper is an extended version of the article introducing LRPC codes, with important new contributions. We have improved the decoder thanks to a new approach which allows for decoding of errors of higher rank weight, namely up to$\frac {2}{3}(n-k)$when the previous decoding algorithm only decodes up to$\frac {n-k}{2}$errors. Our codes therefore outperform the classical Gabidulin code decoder which deals with weights up to$\frac {n-k}{2}$. This comes at the expense of probabilistic decoding, but the decoding error probability can be made arbitrarily small. The new approach can also be used to decrease the decoding error probability of previous schemes, which is especially useful for cryptography. Finally, we introduce ideal rank codes, which generalize double-circulant rank codes and allow us to avoid known structural attacks based on folding. To conclude, we propose different parameter sizes for our schemes and we obtain a public key of 3337 bits for key exchange and 5893 bits for public key encryption, both for 128 bits of security. Nicolas Aragon, Philippe Gaborit, Adrien Hauteville, Olivier Ruatta, Gilles Zémor |
IEEE Trans. Inf. Theory | 1 |
| 2018 | A New Algorithm for Solving the Rank Syndrome Decoding ProblemabstractIn this paper, we propose an improvement of the attack on the Rank Syndrome Decoding (RSD) problem found in [1], usually the best attack considered for evaluating the security of rank metric based cryptosystems. For H a full-rank (n-k)×n matrix over Fqmand e ∈ Fqnm of small norm r, the RSD problem consists in recovering e from s=HeT. In our case, the norm of a vector over Fqmis defined by the dimension of the Fq-subspace generated by its coordinates. This problem is very similar to the Syndrome Decoding problem in the Hamming metric (only the metric and the field of the coefficients are different) and the security of several cryptosystems relies on its hardness, like McEliece-based PKE [2], [3] or IBE [4]. Our attack is in O((n- k)3m3qw-⌈((k+1)m)/n]⌉-m) operations in Fqwhereas the previous best attacks are in O((n-k)3m3q(w-1)min(⌈((k+1)m)/n⌉,k+1)) [1], [5]. In particular in the case m ≤ n, our attack permits to obtain an exponential gain in qm(1-R)for R=k/n the rate of the code. We give examples of broken parameters for recently proposed cryptosystems based on LRPC codes or Gabidulin codes. Our attack does not fully break these cryptosystems but implies larger parameters for the same security levels. Nicolas Aragon, Philippe Gaborit, Adrien Hauteville, Jean-Pierre Tillich |
ISIT | 1 |