Antoine Joux

dblp:j/AntoineJoux · DBLP profile ↗
← Back
79ranked-venue papers
36as first author
19since 2021 · last 2026
0000-0003-2682-6508ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 70 · 31 first-author · 16 since 2021Theory of computation · 11 · 6 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Chosen Ciphertext Secure Pseudorandom Codes in the Standard Model
Nico Döttling, Antoine Joux, Venkata Koppula, Mahesh Sreekumar Rajasree, Hendrik Waldner
CRYPTO (1)2
2026 Improving Lagarias-Odlyzko Algorithm for Average-Case Subset Sum: Modular Arithmetic Approach
abstract
Lagarias and Odlyzko (J.~ACM~1985) proposed a polynomial time algorithm for solving ``\emph{almost all}'' instances of the Subset Sum problem with $n$ integers of size $Ω(Γ_{\text{LO}})$, where $\log_2(Γ_{\text{LO}}) > n^2 \log_2(γ)$ and $γ$ is a parameter of the lattice basis reduction ($γ> \sqrt{4/3}$ for LLL). The algorithm of Lagarias and Odlyzko is a cornerstone result in cryptography. However, the theoretical guarantee on the density of feasible instances has remained unimproved for almost 40 years. In this paper, we propose an algorithm to solve ``almost all'' instances of Subset Sum with integers of size $Ω(\sqrt{Γ_{\text{LO}}})$ after a single call to the lattice reduction. Additionally, our argument allows us to solve the Subset Sum problem for multiple targets while the previous approach could only answer one target per call to lattice basis reduction. We introduce a modular arithmetic approach to the Subset Sum problem. The idea is to use the lattice reduction to solve a linear system modulo a suitably large prime. We show that density guarantees can be improved, by analysing the lengths of the LLL reduced basis vectors, of both the primal and the dual lattices simultaneously.
Antoine Joux, Karol Wegrzycki
STACS1
2025 VOLE-in-the-Head Signatures from Subfield Bilinear Collisions
Janik Huth, Antoine Joux
ASIACRYPT (4)2
2025 A High Dimensional Cramer's Rule Connecting Homogeneous Multilinear Equations to Hyperdeterminants
Antoine Joux, Anand Kumar Narayanan
ITCS1
2025 Kleptographic Attacks Against Implicit Rejection
Antoine Joux, Julian Loss, Benedikt Wagner
PKC (4)1
2025 Dimensional esfROSion: Improving the sfROS Attack with Decomposition in Higher Bases
Antoine Joux, Julian Loss, Giacomo Santato
TCC (3)1
2025 RYDE: a digital signature scheme based on rank syndrome decoding problem with MPC-in-the-Head paradigm
Loïc Bidoux, Jesús-Javier Chi-Domínguez, Thibauld Feneuil, Philippe Gaborit, Antoine Joux, Matthieu Rivain, Adrien Vinçotte
Des. Codes Cryptogr.5
2025 The regular multivariate quadratic problem
abstract
Abstract In this work, we introduce a novel variant of the multivariate quadratic problem, which is at the core of one of the most promising post-quantum alternatives: multivariate cryptography. In this variant, the solution of a given multivariate quadratic system must also be regular, i.e. each fixed-length block of consecutive entries has only one nonzero entry. We prove the NP-completeness of this variant and show similarities and differences with other computational problems used in cryptography. Then we analyze its hardness by reviewing the most common solvers for polynomial systems over finite fields, derive asymptotic formulas for the corresponding complexities and compare the different approaches.
Antoine Joux, Rocco Mora
Des. Codes Cryptogr.1
2024 Faster Signatures from MPC-in-the-Head
Dung Bui, Eliana Carozza, Geoffroy Couteau, Dahmun Goudarzi, Antoine Joux
ASIACRYPT (1)5
2024 MPC in the Head Using the Subfield Bilinear Collision Problem
Janik Huth, Antoine Joux
CRYPTO (1)2
2024 Key Recovery Attack on the Partial Vandermonde Knapsack Problem
Dipayan Das 0001, Antoine Joux
EUROCRYPT (6)2
2024 On Digital Signatures Based on Group Actions: QROM Security and Ring Signatures
Markus Bläser, Dung Hoang Duong, Antoine Joux, Tuong Ngoc Nguyen, Thomas Plantard, Youming Qiao, Willy Susilo
PQCrypto (1)4
2024 Space-Lock Puzzles and Verifiable Space-Hard Functions from Root-Finding in Sparse Polynomials
Nico Döttling, Jesko Dujmovic, Antoine Joux
TCC (3)3
2023 Short Signatures from Regular Syndrome Decoding in the Head
Eliana Carozza, Geoffroy Couteau, Antoine Joux
EUROCRYPT (5)3
2023 On the Hardness of the Finite Field Isomorphism Problem
Dipayan Das 0001, Antoine Joux
EUROCRYPT (5)2
2023 Shared permutation for syndrome decoding: new zero-knowledge protocol and code-based signature
Thibauld Feneuil, Antoine Joux, Matthieu Rivain
Des. Codes Cryptogr.2
2022 Syndrome Decoding in the Head: Shorter Signatures from Zero-Knowledge Proofs
Thibauld Feneuil, Antoine Joux, Matthieu Rivain
CRYPTO (2)2
2022 Classical and Quantum Algorithms for Variants of Subset-Sum via Dynamic Programming
abstract
International audience
Jonathan Allcock, Yassine Hamoudi, Antoine Joux, Felix Klingelhöfer, Miklos Santha
ESA3
2022 Practical Post-Quantum Signature Schemes from Isomorphism Problems of Trilinear Forms
Dung Hoang Duong, Antoine Joux, Thomas Plantard, Youming Qiao, Willy Susilo
EUROCRYPT (3)3
2018 How to Securely Compute with Noisy Leakage in Quasilinear Complexity
Dahmun Goudarzi, Antoine Joux, Matthieu Rivain
ASIACRYPT (2)2
2018 A New Public-Key Cryptosystem via Mersenne Numbers
Divesh Aggarwal, Antoine Joux, Anupam Prakash, Miklos Santha
CRYPTO (3)2
2017 Discrete Logarithms in Small Characteristic Finite Fields: a Survey of Recent Advances (Invited Talk)
abstract
The discrete logarithm problem is one of the few hard problems on which public-key cryptography can be based. It was introduced in the field by the famous Diffie-Hellman key exchange protocol. Initially, the cryptographic use of the problem was considered in prime fields, but was readily generalized to arbitrary finite fields and, later, to elliptic or higher genus curves. In this talk, we survey the key technical ideas that can be used to compute discrete logarithms, especially in the case of small characteristic finite fields. These ideas stem from about 40 years of research on the topic. They appeared along the long road that leads from the initial belief that this problem was hard enough for cryptographic purpose to the current state of the art where it can no longer be considered for cryptographic use. Indeed, after the recent developments started in 2012, we now have some very efficient practical algorithms to solve this problem. Unfortunately, these algorithms remain heuristic and one important direction for future research is to lift the remaining heuristic assumptions.
Antoine Joux
STACS1
2016 Technical history of discrete logarithms in small characteristic finite fields - The road from subexponential to quasi-polynomial complexity
Antoine Joux, Cécile Pierrot
Des. Codes Cryptogr.1
2015 Cryptanalysis of SHA-0 and Reduced SHA-1
Eli Biham, Rafi Chen, Antoine Joux
J. Cryptol.3
2014 Multi-user Collisions: Applications to Discrete Logarithm, Even-Mansour and PRINCE
Pierre-Alain Fouque, Antoine Joux, Chrysanthi Mavromati
ASIACRYPT (1)2
2014 Improving the Polynomial time Precomputation of Frobenius Representation Discrete Logarithm Algorithms - Simplified Setting for Small Characteristic Finite Fields
Antoine Joux, Cécile Pierrot
ASIACRYPT (1)1
2014 A Heuristic Quasi-Polynomial Algorithm for Discrete Logarithm in Finite Fields of Small Characteristic
Razvan Barbulescu, Pierrick Gaudry, Antoine Joux, Emmanuel Thomé
EUROCRYPT3
2014 Symmetrized Summation Polynomials: Using Small Order Torsion Points to Speed Up Elliptic Curve Index Calculus
Jean-Charles Faugère, Louise Huot, Antoine Joux, Guénaël Renault, Vanessa Vitse
EUROCRYPT3
2014 Recovering a sum of two squares decomposition
Jaime Gutierrez 0001, Álvar Ibeas, Antoine Joux
J. Symb. Comput.3
2013 Injective Encodings to Elliptic Curves
Pierre-Alain Fouque, Antoine Joux, Mehdi Tibouchi
ACISP2
2013 Faster Index Calculus for the Medium Prime Case Application to 1175-bit and 1425-bit Finite Fields
Antoine Joux
EUROCRYPT1
2013 Security Ranking Among Assumptions Within the Uber Assumption Framework
Antoine Joux, Antoine Rojat
ISC1
2013 The Special Number Field Sieve in 𝔽pn - Application to Pairing-Friendly Constructions
Antoine Joux, Cécile Pierrot
Pairing1
2013 A New Index Calculus Algorithm with Complexity $$L(1/4+o(1))$$ in Small Characteristic
Antoine Joux
Selected Areas in Cryptography1
2013 Elliptic Curve Discrete Logarithm Problem over Small Degree Extension Fields - Application to the Static Diffie-Hellman Problem on $E(\mathbb{F}_{q^{5}})$
Antoine Joux, Vanessa Vitse
J. Cryptol.1
2012 Towards Super-Exponential Side-Channel Security with Efficient Leakage-Resilient PRFs
Marcel Medwed, François-Xavier Standaert, Antoine Joux
CHES3
2012 Decoding Random Binary Linear Codes in 2 n/20: How 1 + 1 = 0 Improves Information Set Decoding
Anja Becker 0001, Antoine Joux, Alexander May 0001, Alexander Meurer
EUROCRYPT2
2012 A Tutorial on High Performance Computing Applied to Cryptanalysis - (Invited Talk Abstract)
Antoine Joux
EUROCRYPT1
2012 Cover and Decomposition Index Calculus on Elliptic Curves Made Practical - Application to a Previously Unreachable Curve over $\mathbb{F}_{p^6}$
Antoine Joux, Vanessa Vitse
EUROCRYPT1
2011 A Variant of the F4 Algorithm
Antoine Joux, Vanessa Vitse
CT-RSA1
2011 Improved Generic Algorithms for Hard Knapsacks
Anja Becker 0001, Jean-Sébastien Coron, Antoine Joux
EUROCRYPT3
2010 New Generic Algorithms for Hard Knapsacks
Nick Howgrave-Graham, Antoine Joux
EUROCRYPT2
2010 Pairing Computation on Elliptic Curves with Efficiently Computable Endomorphism and Small Embedding Degree
Sorina Ionica, Antoine Joux
Pairing2
2010 On the security of blockwise secure modes of operation beyond the birthday bound
abstract
We study the nonlinearity of the exponential Welch Costas functions, using the Fourier transform onZm. These functions have been proposed for use in nonbinary cryptosystems. High nonlinearity is required to ensure resistance to linear cryptanalysis. We prove some properties of the nonlinearity of these functions, and we suggest a plausible connection of the nonlinearity to the class number of a quadratic field.
Antoine Joux
IEEE Trans. Inf. Theory1
2009 Factoring pq2 with Quadratic Forms: Nice Cryptanalyses
Guilhem Castagnos, Antoine Joux, Fabien Laguillaumie, Phong Q. Nguyen
ASIACRYPT2
2009 Improved Generic Algorithms for 3-Collisions
Antoine Joux, Stefan Lucks
ASIACRYPT1
2009 Fault Attacks on RSA Signatures with Partially Unknown Messages
Jean-Sébastien Coron, Antoine Joux, Ilya Kizhvatov, David Naccache, Pascal Paillier
CHES2
2009 Oracle-Assisted Static Diffie-Hellman Is Easier Than Discrete Logarithms
Antoine Joux, Reynald Lercier, David Naccache, Emmanuel Thomé
IMACC1
2007 When e-th Roots Become Easier Than Factoring
Antoine Joux, David Naccache, Emmanuel Thomé
ASIACRYPT1
2007 Hash Functions and the (Amplified) Boomerang Attack
Antoine Joux, Thomas Peyrin
CRYPTO1
2007 Toward a Rigorous Variation of Coppersmith's Algorithm on Three Variables
Aurélie Bauer, Antoine Joux
EUROCRYPT2
2007 Overtaking VEST
Antoine Joux, Jean-René Reinhard
FSE1
2006 Inverting HFE Is Quasipolynomial
Louis Granboulan, Antoine Joux, Jacques Stern
CRYPTO2
2006 The Number Field Sieve in the Medium Prime Case
Antoine Joux, Reynald Lercier, Nigel P. Smart, Frederik Vercauteren
CRYPTO1
2006 The Function Field Sieve in the Medium Prime Case
Antoine Joux, Reynald Lercier
EUROCRYPT1
2006 Chosen-Ciphertext Attacks Against MOSQUITO
Antoine Joux, Frédéric Muller
FSE1
2005 Collisions of SHA-0 and Reduced SHA-1
Eli Biham, Rafi Chen, Antoine Joux, Patrick Carribault, Christophe Lemuet, William Jalby
EUROCRYPT3
2005 Two Attacks Against the HBB Stream Cipher
Antoine Joux, Frédéric Muller
FSE1
2004 Multicollisions in Iterated Hash Functions. Application to Cascaded Constructions
Antoine Joux
CRYPTO1
2004 A One Round Protocol for Tripartite Diffie-Hellman
Antoine Joux
J. Cryptol.1
2003 Algebraic Cryptanalysis of Hidden Field Equation (HFE) Cryptosystems Using Gröbner Bases
Jean-Charles Faugère, Antoine Joux
CRYPTO2
2003 Cryptanalysis of the EMD Mode of Operation
abstract
In this paper, we study the security of the Encrypt-Mask-Decrypt mode of operation, also called EMD, which was recently proposed for applications such as disk-sector encryption. The EMD mode transforms an ordinary block cipher operating on n -bit blocks into a tweakable block cipher operating on large blocks of size nm bits. We first show that EMD is not a secure tweakable block cipher and then describe efficient attacks in the context of disk-sector encryption. We note that the parallelizable variant of EMD, called EME that was proposed at the same time is also subject to these attacks. In the course of developing one of the attacks, we revisit Wagner’s generalized birthday algorithm and show that in some special cases it performs much more efficiently than in the general case. Due to the large scope of applicability of this algorithm, even when restricted to these special cases, we believe that this result is of independent interest. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Antoine Joux
EUROCRYPT1
2003 Loosening the KNOT
Antoine Joux, Frédéric Muller
FSE1
2003 New Attacks against Standardized MACs
Antoine Joux, Guillaume Poupard, Jacques Stern
FSE1
2003 Separating Decision Diffie-Hellman from Computational Diffie-Hellman in Cryptographic Groups
Antoine Joux
J. Cryptol.1
2002 Blockwise-Adaptive Attackers: Revisiting the (In)Security of Some Provably Secure Encryption Models: CBC, GEM, IACBC
Antoine Joux, Gwenaëlle Martinet, Frédéric Valette
CRYPTO1
2002 Fast Correlation Attacks: An Algorithmic Point of View
Philippe Chose, Antoine Joux, Michel Mitton
EUROCRYPT2
2002 On the Security of Randomized CBC-MAC Beyond the Birthday Paradox Limit: A New Construction
Éliane Jaulmes, Antoine Joux, Frédéric Valette
FSE2
2000 Why Textbook ElGamal and RSA Encryption Are Insecure
Dan Boneh, Antoine Joux, Phong Q. Nguyen
ASIACRYPT2
2000 A Chosen-Ciphertext Attack against NTRU
Éliane Jaulmes, Antoine Joux
CRYPTO2
2000 A NICE Cryptanalysis
Éliane Jaulmes, Antoine Joux
EUROCRYPT2
2000 A Statistical Attack on RC6
Henri Gilbert, Helena Handschuh, Antoine Joux, Serge Vaudenay
FSE3
1998 Differential Collisions in SHA-0
Florent Chabaud, Antoine Joux
CRYPTO2
1998 Lattice Reduction: A Toolbox for the Cryptanalyst
Antoine Joux, Jacques Stern
J. Cryptol.1
1996 The Action of a Few Random Permutations on r-Tuples and an Application to Cryptography
Joel Friedman, Antoine Joux, Yuval Roichman, Jacques Stern, Jean-Pierre Tillich
STACS2
1992 Improved Low-Density Subset Sum Algorithms
Matthijs J. Coster, Antoine Joux, Brian A. LaMacchia, Andrew M. Odlyzko, Claus-Peter Schnorr, Jacques Stern
Comput. Complex.2
1991 Cryptanalysis of Another Knapsack Cryptosystem
Antoine Joux, Jacques Stern
ASIACRYPT1
1991 The Cryptanalysis of a New Public-Key Cryptosystem Based on Modular Knapsacks
Yeow Meng Chee, Antoine Joux, Jacques Stern
CRYPTO2
1991 Improving the Critical Density of the Lagarias-Odlyzko Attack Against Subset Sum Problems
Antoine Joux, Jacques Stern
FCT1