Thomas Prest

dblp:50/11102 · DBLP profile ↗
← Back
25ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0003-1445-6212ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 2 first-author · 14 since 2021Theory of computation · 2 · 1 first-author
YearPublicationVenuePosition
2026 Toward a Secure Fixed-Point Implementation of the Falcon Signature Scheme
Daniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas Prest
CRYPTO (3)4
2026 IND-CCA Lattice Threshold KEM Under 30 KiB
Katharina Boudgoust, Rafaël Del Pino, Oleksandra Lapiha, Thomas Prest
PKC (1)4
2025 A Lattice-Based IND-CCA Threshold KEM from the BCHK+ Transform
Oleksandra Lapiha, Thomas Prest
ASIACRYPT (3)2
2025 Poster: Efficient Threshold ML-DSA up to 6 Parties
abstract
Threshold signature schemes enable a group of users to collaboratively produce digital signatures without revealing any individual share. With the current NIST post-quantum standardization underway, the lack of efficient and practical threshold variants of standardized schemes hinders adoption. We introduce the first threshold signature scheme compatible with the ML-DSA standard (Module-Lattice-based Digital Signature Algorithm), supporting up to 6 parties, while retaining efficient signing. Our work uses advanced short secret sharing techniques and optimized rejection sampling to balance communication and correctness in distributed settings. We implement our construction in Go and benchmark it in local, LAN, and WAN deployments. Results show that our threshold ML-DSA is both practical and compatible with real-world applications such as multi-device cryptocurrency wallets, threshold TLS, and Tor's directory authorities.
Sofía Celi, Rafaël Del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest
CCS5
2025 Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal Protocol
Yevgeniy Dodis, Daniel Jost 0001, Shuichi Katsumata, Thomas Prest, Rolfe Schmidt
EUROCRYPT (8)4
2024 Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices
Thomas Espitau, Guilhem Niot, Thomas Prest
CRYPTO (7)3
2024 Raccoon: A Masking-Friendly Signature Proven in the Probing Model
Rafaël Del Pino, Shuichi Katsumata, Thomas Prest, Melissa Rossi
CRYPTO (1)3
2024 Plover: Masking-Friendly Hash-and-Sign Lattice Signatures
Muhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest, Amin Sakzad, Ron Steinfeld
EUROCRYPT (6)4
2024 Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions
Rafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem, Thomas Prest, Markku-Juhani O. Saarinen
EUROCRYPT (2)5
2023 High-Order Masking of Lattice Signatures in Quasilinear Time
abstract
In recent years, lattice-based signature schemes have emerged as the most prominent post-quantum solutions, as illustrated by NIST’s selection of Falcon and Dilithium for standardization. Both schemes enjoy good performance characteristics. However, their efficiency dwindles in the presence of side-channel protections, particularly masking – perhaps the strongest generic side-channel countermeasure. Masking at order d-1 requires randomizing all sensitive intermediate variables into d shares. With existing schemes, signature generation complexity grows quadratically with the number of shares, making high-order masking prohibitively slow.In this paper, we turn the problem upside-down: We design a lattice-based signature scheme specifically for side-channel resistance and optimize the masked efficiency as a function of the number of shares. Our design avoids costly operations such as conversions between arithmetic and boolean encodings (A2B/B2A), masked rejection sampling, and does not require a masked SHAKE implementation or other symmetric primitives. The resulting scheme is called Raccoon and belongs to the family of Fiat-Shamir with aborts lattice-based signatures. Raccoon is the first lattice-based signature whose key generation and signing running time has only an O(d log(d)) overhead, with d being the number of shares.Our Reference C implementation confirms that Raccoon’s performance is comparable to other state-of-the-art signature schemes, except that increasing the number of shares has a near-linear effect on its latency. We also present an FPGA implementation and perform a physical leakage assessment to verify its basic security properties.
Rafaël Del Pino, Thomas Prest, Melissa Rossi, Markku-Juhani O. Saarinen
SP2
2022 How to Hide MetaData in MLS-Like Secure Group Messaging: Simple, Modular, and Post-Quantum
abstract
Secure group messaging (SGM) protocols allow large groups of users to communicate in a secure and asynchronous manner. In recent years, continuous group key agreements (CGKAs) have provided a powerful abstraction to reason on the security properties we expect from SGM protocols. While robust techniques have been developed to protect the contents of conversations in this context, it is in general more challenging to protect metadata (e.g. the identity and social relationships of group members), since their knowledge is often needed by the server in order to ensure the proper function of the SGM protocol.
Keitaro Hashimoto, Shuichi Katsumata, Thomas Prest
CCS3
2022 An Efficient and Generic Construction for Signal's Handshake (X3DH): Post-quantum, State Leakage Secure, and Deniable
Keitaro Hashimoto, Shuichi Katsumata, Kris Kwiatkowski, Thomas Prest
J. Cryptol.4
2021 A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEs
abstract
Continuous group key agreements (CGKAs) are a class of protocols that can provide strong security guarantees to secure group messaging protocols such as Signal and MLS. Protection against device compromise is provided by commit messages: at a regular rate, each group member may refresh their key material by uploading a commit message, which is then downloaded and processed by all the other members. In practice, propagating commit messages dominates the bandwidth consumption of existing CGKAs.
Keitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest, Bas Westerbaan
CCS4
2021 SoK: How (not) to Design and Implement Post-quantum Cryptography
James Howe, Thomas Prest, Daniel Apon
CT-RSA2
2020 Scalable Ciphertext Compression Techniques for Post-quantum KEMs and Their Applications
Shuichi Katsumata, Kris Kwiatkowski, Federico Pintore, Thomas Prest
ASIACRYPT (1)4
2020 ModFalcon: Compact Signatures Based On Module-NTRU Lattices
abstract
Lattices lead to promising practical post-quantum digital signatures, combining asymptotic efficiency with strong theoretical security guarantees. However, tuning their parameters into practical instantiations is a delicate task. On the one hand, NIST round~2 candidates based on Lyubashevsky's design (such as dilithium and qtesla) allow several tradeoffs between security and efficiency, but at the expense of a large bandwidth consumption. On the other hand, the hash-and-sign falcon signature is much more compact and is still very efficient, but it allows only two security levels, with large compactness and security gaps between them. We introduce a new family of signature schemes based on the falcon design, which relies on module lattices. Our concrete instantiation enjoys the compactness and efficiency of falcon, and allows an intermediate security level. It leads to the most compact lattice-based signature achieving a quantum security above 128 bits.
Chitchanok Chuengsatiansup, Thomas Prest, Damien Stehlé, Alexandre Wallet, Keita Xagawa
AsiaCCS2
2020 Integral Matrix Gram Root and Lattice Gaussian Sampling Without Floats
Léo Ducas, Steven D. Galbraith, Thomas Prest, Yang Yu 0008
EUROCRYPT (2)3
2020 Isochronous Gaussian Sampling: From Inception to Implementation
James Howe, Thomas Prest, Thomas Ricosset, Melissa Rossi
PQCrypto2
2019 Unifying Leakage Models on a Rényi Day
Thomas Prest, Dahmun Goudarzi, Ange Martinelli, Alain Passelègue
CRYPTO (1)1
2018 Grafting Trees: A Fault Attack Against the SPHINCS Framework
Laurent Castelnovi, Ange Martinelli, Thomas Prest
PQCrypto3
2017 Sharper Bounds in Lattice-Based Cryptography Using the Rényi Divergence
Thomas Prest
ASIACRYPT (1)1
2016 Fast Fourier Orthogonalization
abstract
The classical fast Fourier transform (FFT) allows to compute in quasi-linear time the product of two polynomials, in the circular convolution ring R[x]/(xd -1) --- a task that naively requires quadratic time. Equivalently, it allows to accelerate matrix-vector products when the matrix is circulant. In this work, we discover that the ideas of the FFT can be applied to speed up the orthogonalization process of matrices with circulant blocks of size d x d. We show that, when d is composite, it is possible to proceed to the orthogonalization in an inductive way ---up to an appropriate re-indexation of rows and columns. This leads to a structured Gram-Schmidt decomposition. In turn, this structured Gram-Schmidt decomposition accelerates a cornerstone lattice algorithm: the nearest plane algorithm. The complexity of both algorithms may be brought down to Θ(d log d).
Léo Ducas, Thomas Prest
ISSAC2
2015 Quadratic Time, Linear Space Algorithms for Gram-Schmidt Orthogonalization and Gaussian Sampling in Structured Lattices
Vadim Lyubashevsky, Thomas Prest
EUROCRYPT (1)2
2014 Efficient Identity-Based Encryption over NTRU Lattices
Léo Ducas, Vadim Lyubashevsky, Thomas Prest
ASIACRYPT (2)3
2012 Non-linear polynomial selection for the number field sieve
Thomas Prest, Paul Zimmermann 0001
J. Symb. Comput.1