EDBT 2026 Demo / reviewers in the wild / expert
Emmanuel Thomé
dblp:44/5777
· DBLP profile ↗
20ranked-venue papers
4as first author
1since 2021 · last 2026
0000-0002-5669-2195ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 1 first-author · 1 since 2021Theory of computation · 6 · 3 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
9 papers |
Cryptographic primitives and cryptanalysis · 90% Network security · 10% |
Topics — the 11 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic primitives and cryptanalysis
discrete logarithm |
0.8 | 4 | 2020 | A Kilobit Hidden SNFS Discrete Logarithm Computation · EUROCRYPT (1) 2017 Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015 Comparing the Difficulty of Factorization and Discrete Logarithm: A 240-Digit Experiment · CRYPTO (2) 2020 |
Cryptographic primitives and cryptanalysis › integer factorization
number field sieve |
0.2 | 1 | 2015 | Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015 |
Network security › secure communication › secure communication protocol
TLS |
0.2 | 1 | 2015 | Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015 |
Cryptographic primitives and cryptanalysis
discrete logarithm problem |
0.2 | 1 | 2014 | A Heuristic Quasi-Polynomial Algorithm for Discrete Logarithm in Finite Fields of Small Characteristic · EUROCRYPT 2014 |
Cryptographic primitives and cryptanalysis › public-key cryptography
RSA |
0.2 | 2 | 2010 | Factorization of a 768-Bit RSA Modulus · CRYPTO 2010 When e-th Roots Become Easier Than Factoring · ASIACRYPT 2007 |
Cryptographic primitives and cryptanalysis
integer factorization |
0.1 | 1 | 2010 | Factorization of a 768-Bit RSA Modulus · CRYPTO 2010 |
Cryptographic primitives and cryptanalysis › public-key cryptography
public-key cryptanalysis |
0.1 | 1 | 2010 | Factorization of a 768-Bit RSA Modulus · CRYPTO 2010 |
Cryptographic primitives and cryptanalysis
public-key cryptography |
0.1 | 2 | 2007 | When e-th Roots Become Easier Than Factoring · ASIACRYPT 2007 Computation of Discrete Logarithms in F2607 · ASIACRYPT 2001 |
Cryptographic primitives and cryptanalysis › public-key cryptography
elliptic curve cryptography |
0.1 | 1 | 2008 | Index Calculus in Class Groups of Non-hyperelliptic Curves of Genus Three · J. Cryptol. 2008 |
Cryptographic primitives and cryptanalysis › public-key cryptography › elliptic curve cryptography
hyperelliptic curve cryptography |
0.1 | 1 | 2008 | Index Calculus in Class Groups of Non-hyperelliptic Curves of Genus Three · J. Cryptol. 2008 |
Cryptographic primitives and cryptanalysis
index calculus |
0.1 | 1 | 2008 | Index Calculus in Class Groups of Non-hyperelliptic Curves of Genus Three · J. Cryptol. 2008 |
Methods — techniques the papers use, named apart from their topics
number field sieve · 0.4number field sieve discrete log · 0.2man-in-the-middle attack · 0.2index calculus · 0.1number-theoretic algorithms · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | High-Order Galois Automorphisms for TNFS Linear Algebra
Haetham Al Aswad, Cécile Pierrot, Emmanuel Thomé |
CRYPTO (4) | 3 |
| 2020 | Comparing the Difficulty of Factorization and Discrete Logarithm: A 240-Digit Experiment
Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé, Paul Zimmermann 0001 |
CRYPTO (2) | 5 |
| 2020 | Cocks-Pinch curves of embedding degrees five to eight and optimal ate pairing computation
Aurore Guillevic, Simon Masson, Emmanuel Thomé |
Des. Codes Cryptogr. | 3 |
| 2017 | A Kilobit Hidden SNFS Discrete Logarithm Computation
Joshua Fried, Pierrick Gaudry, Nadia Heninger, Emmanuel Thomé |
EUROCRYPT (1) | 4 |
| 2017 | Computing Discrete Logarithms in 𝔽p6
Laurent Grémy, Aurore Guillevic, François Morain, Emmanuel Thomé |
SAC | 4 |
| 2016 | Linear Time Interactive Certificates for the Minimal Polynomial and the Determinant of a Sparse MatrixabstractComputational problem certificates are additional data structures for each output, which can be used by a---possibly randomized---verification algorithm that proves the correctness of each output. In this paper, we give an algorithm that computes a certificate for the minimal polynomial of sparse or structured matrices over an abstract field, of sufficiently large cardinality, whose Monte Carlo verification complexity requires a single matrix-vector multiplication and a linear number of extra field operations. We also propose a novel preconditioner that ensures irreducibility of the characteristic polynomial of the generically preconditioned matrix. This preconditioner takes linear time to be applied and uses only two random entries. We then combine these two techniques to give algorithms that compute certificates for the determinant, and thus for the characteristic polynomial, whose Monte Carlo verification complexity is therefore also linear. Jean-Guillaume Dumas, Erich L. Kaltofen, Emmanuel Thomé, Gilles Villard |
ISSAC | 3 |
| 2016 | Solving Discrete Logarithms on a 170-Bit MNT Curve by Pairing Reduction
Aurore Guillevic, François Morain, Emmanuel Thomé |
SAC | 3 |
| 2015 | Imperfect Forward Secrecy: How Diffie-Hellman Fails in PracticeabstractWe investigate the security of Diffie-Hellman key exchange as used in popular Internet protocols and find it to be less secure than widely believed. First, we present Logjam, a novel flaw in TLS that lets a man-in-the-middle downgrade connections to "export-grade" Diffie-Hellman. To carry out this attack, we implement the number field sieve discrete log algorithm. After a week-long precomputation for a specified 512-bit group, we can compute arbitrary discrete logs in that group in about a minute. We find that 82% of vulnerable servers use a single 512-bit group, allowing us to compromise connections to 7% of Alexa Top Million HTTPS sites. In response, major browsers are being changed to reject short groups. We go on to consider Diffie-Hellman with 768- and 1024-bit groups. We estimate that even in the 1024-bit case, the computations are plausible given nation-state resources. A small number of fixed or standardized groups are used by millions of servers; performing precomputation for a single 1024-bit group would allow passive eavesdropping on 18% of popular HTTPS sites, and a second group would allow decryption of traffic to 66% of IPsec VPNs and 26% of SSH servers. A close reading of published NSA leaks shows that the agency's attacks on VPNs are consistent with having achieved such a break. We conclude that moving to stronger key exchange methods should be a priority for the Internet community. David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green 0001, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, Paul Zimmermann 0001 |
CCS | 9 |
| 2014 | A Heuristic Quasi-Polynomial Algorithm for Discrete Logarithm in Finite Fields of Small Characteristic
Razvan Barbulescu, Pierrick Gaudry, Antoine Joux, Emmanuel Thomé |
EUROCRYPT | 4 |
| 2012 | Square Root Algorithms for the Number Field Sieve
Emmanuel Thomé |
WAIFI | 1 |
| 2011 | An L(1/3) Discrete Logarithm Algorithm for Low Degree Curves
Andreas Enge, Pierrick Gaudry, Emmanuel Thomé |
J. Cryptol. | 3 |
| 2010 | Factorization of a 768-Bit RSA Modulus
Thorsten Kleinjung, Kazumaro Aoki, Jens Franke, Arjen K. Lenstra, Emmanuel Thomé, Joppe W. Bos, Pierrick Gaudry, Alexander Kruppa, Peter L. Montgomery, Dag Arne Osvik, Herman J. J. te Riele, Andrey Timofeev, Paul Zimmermann 0001 |
CRYPTO | 5 |
| 2009 | Oracle-Assisted Static Diffie-Hellman Is Easier Than Discrete Logarithms
Antoine Joux, Reynald Lercier, David Naccache, Emmanuel Thomé |
IMACC | 4 |
| 2009 | Mapping Computation with No Memory
Serge Burckel, Emeric Gioan, Emmanuel Thomé |
UC | 3 |
| 2008 | Index Calculus in Class Groups of Non-hyperelliptic Curves of Genus Three
Claus Diem, Emmanuel Thomé |
J. Cryptol. | 2 |
| 2007 | When e-th Roots Become Easier Than Factoring
Antoine Joux, David Naccache, Emmanuel Thomé |
ASIACRYPT | 3 |
| 2007 | Time-and space-efficient evaluation of some hypergeometric constantsabstractHAL is a multi-disciplinary open access archive for the deposit and dissemination of sci-entific research documents, whether they are pub-lished or not. The documents may come from teaching and research institutions in France or abroad, or from public or private research centers. L’archive ouverte pluridisciplinaire HAL, est destinée au dépôt et a ̀ la diffusion de documents scientifiques de niveau recherche, publiés ou non, émanant des établissements d’enseignement et de recherche français ou étrangers, des laboratoires publics ou privés. Howard Cheng, Guillaume Hanrot, Emmanuel Thomé, Paul Zimmermann 0001, Eugene V. Zima |
ISSAC | 3 |
| 2002 | Subquadratic Computation of Vector Generating Polynomials and Improvement of the Block Wiedemann Algorithm
Emmanuel Thomé |
J. Symb. Comput. | 1 |
| 2001 | Computation of Discrete Logarithms in F2607
Emmanuel Thomé |
ASIACRYPT | 1 |
| 2001 | Fast computation of linear generators for matrix sequences and application to the block Wiedemann algorithmabstractIn this paper we describe how the half-gcd algorithm can be adapted in order to speed up the sequential stage of Coppersmith's block Wiedemann algorithm for solving large sparse linear systems over any finite field. This very stage solves a sub-problem than can be seen as the computation of a linear generator for a matrix sequence. Our primary realm of interest is the field Fq for large prime power q. For the solution of a N × N system, the complexity of this sequential part drops from Ο(N2) to Ο(M(N) log N) where M(d) is the cost for multiplying two polynomials of degree d. We discuss the implications of this improvement for the overall cost of the block Wiedemann algorithm and how its parameters should be chosen for best efficiency. Emmanuel Thomé |
ISSAC | 1 |