EDBT 2026 Demo / reviewers in the wild / expert
Craig Costello
dblp:98/7227
· DBLP profile ↗
27ranked-venue papers
13as first author
5since 2021 · last 2026
0000-0001-5423-7714ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 12 first-author · 5 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Algorithms for the Detection of (N, N)-Splittings and Endomorphisms
Maria Corte-Real Santos, Craig Costello, Sam Frengley |
J. Cryptol. | 2 |
| 2024 | On Cycles of Pairing-Friendly Abelian Varieties
Maria Corte-Real Santos, Craig Costello, Michael Naehrig |
CRYPTO (9) | 2 |
| 2023 | Cryptographic Smooth Neighbors
Giacomo Bruno, Maria Corte-Real Santos, Craig Costello, Jonathan Komada Eriksen, Michael Meyer 0001, Michael Naehrig, Bruno Sterner |
ASIACRYPT (7) | 3 |
| 2022 | Accelerating the Delfs-Galbraith Algorithm with Fast Subfield Root Detection
Maria Corte-Real Santos, Craig Costello, Jia Shi 0010 |
CRYPTO (3) | 2 |
| 2021 | Sieving for Twin Smooth Integers with Solutions to the Prouhet-Tarry-Escott Problem
Craig Costello, Michael Meyer 0001, Michael Naehrig |
EUROCRYPT (1) | 1 |
| 2020 | B-SIDH: Supersingular Isogeny Diffie-Hellman Using Twisted Torsion
Craig Costello |
ASIACRYPT (2) | 1 |
| 2020 | The Supersingular Isogeny Problem in Genus 2 and Beyond
Craig Costello, Benjamin Smith 0003 |
PQCrypto | 1 |
| 2019 | Supersingular Isogeny Key Exchange for Beginners
Craig Costello |
SAC | 1 |
| 2018 | Computing Supersingular Isogenies on Kummer SurfacesabstractWe apply Scholten’s construction to give explicit isogenies between the Weil restriction of supersingular Montgomery curves with full rational 2-torsion over $$\mathbb {F}_{p^2}$$ and corresponding abelian surfaces over $$\mathbb {F}_{p}$$ . Subsequently, we show that isogeny-based public key cryptography can exploit the fast Kummer surface arithmetic that arises from the theory of theta functions. In particular, we show that chains of 2-isogenies between elliptic curves can instead be computed as chains of Richelot (2, 2)-isogenies between Kummer surfaces. This gives rise to new possibilities for efficient supersingular isogeny-based cryptography. Craig Costello |
ASIACRYPT (3) | 1 |
| 2017 | A Simple and Compact Algorithm for SIDH with Arbitrary Degree Isogenies
Craig Costello, Hüseyin Hisil |
ASIACRYPT (2) | 1 |
| 2017 | Efficient Compression of SIDH Public Keys
Craig Costello, David Jao, Patrick Longa, Michael Naehrig, Joost Renes, David Urbanik |
EUROCRYPT (1) | 1 |
| 2017 | Jacobian Coordinates on Genus 2 Curves
Hüseyin Hisil, Craig Costello |
J. Cryptol. | 2 |
| 2016 | Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEabstractLattice-based cryptography offers some of the most attractive primitives believed to be resistant to quantum computers. Following increasing interest from both companies and government agencies in building quantum computers, a number of works have proposed instantiations of practical post-quantum key exchange protocols based on hard problems in ideal lattices, mainly based on the Ring Learning With Errors (R-LWE) problem. While ideal lattices facilitate major efficiency and storage benefits over their non-ideal counterparts, the additional ring structure that enables these advantages also raises concerns about the assumed difficulty of the underlying problems. Thus, a question of significant interest to cryptographers, and especially to those currently placing bets on primitives that will withstand quantum adversaries, is how much of an advantage the additional ring structure actually gives in practice. Despite conventional wisdom that generic lattices might be too slow and unwieldy, we demonstrate that LWE-based key exchange is quite practical: our constant time implementation requires around 1.3ms computation time for each party; compared to the recent NewHope R-LWE scheme, communication sizes increase by a factor of 4.7x, but remain under 12 KiB in each direction. Our protocol is competitive when used for serving web pages over TLS; when partnered with ECDSA signatures, latencies increase by less than a factor of 1.6x, and (even under heavy load) server throughput only decreases by factors of 1.5x and 1.2x when serving typical 1 KiB and 100 KiB pages, respectively. To achieve these practical results, our protocol takes advantage of several innovations. These include techniques to optimize communication bandwidth, dynamic generation of public parameters (which also offers additional security against backdoors), carefully chosen error distributions, and tight security parameters. Joppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov, Michael Naehrig, Valeria Nikolaenko, Ananth Raghunathan, Douglas Stebila |
CCS | 2 |
| 2016 | Efficient Algorithms for Supersingular Isogeny Diffie-Hellman
Craig Costello, Patrick Longa, Michael Naehrig |
CRYPTO (1) | 1 |
| 2016 | Complete Addition Formulas for Prime Order Elliptic Curves
Joost Renes, Craig Costello, Lejla Batina |
EUROCRYPT (1) | 2 |
| 2016 | Fast, Uniform Scalar Multiplication for Genus 2 Jacobians with Fast Kummers
Ping Ngai Chung, Craig Costello, Benjamin Smith 0003 |
SAC | 2 |
| 2016 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
J. Cryptol. | 2 |
| 2015 | Fourℚ: Four-Dimensional Decompositions on a ℚ-curve over the Mersenne Prime
Craig Costello, Patrick Longa |
ASIACRYPT (1) | 1 |
| 2015 | Post-Quantum Key Exchange for the TLS Protocol from the Ring Learning with Errors ProblemabstractLattice-based cryptographic primitives are believed to offer resilience against attacks by quantum computers. We demonstrate the practicality of post-quantum key exchange by constructing cipher suites for the Transport Layer Security (TLS) protocol that provide key exchange based on the ring learning with errors (R-LWE) problem, we accompany these cipher suites with a rigorous proof of security. Our approach ties lattice-based key exchange together with traditional authentication using RSA or elliptic curve digital signatures: the post-quantum key exchange provides forward secrecy against future quantum attackers, while authentication can be provided using RSA keys that are issued by today's commercial certificate authorities, smoothing the path to adoption. Our cryptographically secure implementation, aimed at the 128-bit security level, reveals that the performance price when switching from non-quantum-safe key exchange is not too high. With our R-LWE cipher suites integrated into the Open SSL library and using the Apache web server on a 2-core desktop computer, we could serve 506 RLWE-ECDSA-AES128-GCM-SHA256 HTTPS connections per second for a 10 KiB payload. Compared to elliptic curve Diffie-Hellman, this means an 8 KiB increased handshake size and a reduction in throughput of only 21%. This demonstrates that provably secure post-quantum key-exchange can already be considered practical. Joppe W. Bos, Craig Costello, Michael Naehrig, Douglas Stebila |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | Geppetto: Versatile Verifiable ComputationabstractCloud computing sparked interest in Verifiable Computation protocols, which allow a weak client to securely outsource computations to remote parties. Recent work has dramatically reduced the client's cost to verify the correctness of their results, but the overhead to produce proofs remains largely impractical. Geppetto introduces complementary techniques for reducing prover overhead and increasing prover flexibility. With Multi QAPs, Geppetto reduces the cost of sharing state between computations (e.g, For MapReduce) or within a single computation by up to two orders of magnitude. Via a careful choice of cryptographic primitives, Geppetto's instantiation of bounded proof bootstrapping improves on prior bootstrapped systems by up to five orders of magnitude, albeit at some cost in universality. Geppetto also efficiently verifies the correct execution of proprietary (i.e, Secret) algorithms. Finally, Geppetto's use of energy-saving circuits brings the prover's costs more in line with the program's actual (rather than worst-case) execution time. Geppetto is implemented in a full-fledged, scalable compiler and runtime that consume LLVM code generated from a variety of source C programs and cryptographic libraries. Craig Costello, Cédric Fournet, Jon Howell, Markulf Kohlweiss, Ben Kreuter, Michael Naehrig, Bryan Parno, Samee Zahur |
IEEE Symposium on Security and Privacy | 1 |
| 2014 | Jacobian Coordinates on Genus 2 Curves
Hüseyin Hisil, Craig Costello |
ASIACRYPT (1) | 2 |
| 2014 | Faster Compact Diffie-Hellman: Endomorphisms on the x-line
Craig Costello, Hüseyin Hisil, Benjamin Smith 0003 |
EUROCRYPT | 1 |
| 2013 | High-Performance Scalar Multiplication Using 8-Dimensional GLV/GLS Decomposition
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
CHES | 2 |
| 2013 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
EUROCRYPT | 2 |
| 2013 | Exponentiating in Pairing Groups
Joppe W. Bos, Craig Costello, Michael Naehrig |
Selected Areas in Cryptography | 2 |
| 2010 | Delaying Mismatched Field Multiplications in Pairing Computations
Craig Costello, Colin Boyd, Juan Manuel González Nieto, Kenneth Koon-Ho Wong |
WAIFI | 1 |
| 2009 | Faster Pairings on Special Weierstrass Curves
Craig Costello, Hüseyin Hisil, Colin Boyd, Juan Manuel González Nieto, Kenneth Koon-Ho Wong |
Pairing | 1 |