Co-located with the CIFRIS26 conference
Rome, Italy, October 5, 2026
Scope & Topics
Topics in Applied Cryptography 2026 (TAC2026) is a workshop dedicated to cryptography with a specific application, scenario and/or technology in mind, including performance evaluation, libraries and implementation issues, hardware and IoT, attacks and vulnerabilities, and requirements for unusual application scenarios; purely theoretical results are out of scope. Topics of interest include privacy enhancing cryptography, homomorphic encryption, secure multi-party computation, quantum key distribution, and quantum-safe cryptography.
Registration
To participate it is necessary to register on the conference page.
Program
All times are in Central European Summer Time (CEST).
| Monday 5th October 2026 | |
|
Invited Speaker |
|
|
On Delegation of Verifiable Presentations from mdoc and BBS Credentials Abstract: The interest in verifiable credential systems has gained traction as eIDAS 2.0 Regulation has been published. This regulation instructs EU member states to provide their citizens with digital identity wallets (EUDI Wallet) that must store the credentials and enable privacy-preserving presentation of identity information to relying parties. This new digital identity system requires defining new protocols and procedures to perform tasks involving the disclosure of identity information. One of such procedures is the delegation of attestation, as is reported in the EUDI Wallet Reference Implementation Roadmap. In this talk, we address the problem of constructing secure processes for the delegation of verifiable presentations derived from both verifiable and anonymous credentials. Our goal is to enable a credential holder (the delegator) to securely delegate another party (the delegatee) to present a credential on their behalf. We introduce the notion of a verifiable presentation delegation scheme, formalizing the core algorithms, namely delegation issuance, delegated presentation, and presentation verification, and defining the relevant security properties that such a scheme should satisfy: the correctness, the unforgeability, and, when the scheme is built on top of anonymous credentials, even the unlinkability. We present two concrete instantiations of delegation schemes: the first is built on top of mdoc verifiable credentials, while the second is built on top of BBS anonymous credentials. Finally, we discuss and analyze the security of our constructions in terms of the security properties we have introduced. Andrea Gangemi (ShunyaXifra) |
15:45-16:15 |
|
Tough cookies in the PQC migration: where current standards will have a hard time chewing Abstract: The ongoing transition to Post-Quantum Cryptography (PQC) requires to replace current factoring- and discrete logarithm based primitives with alternatives which rely on different computationally hard problems. The said problems often provide either less flexibility in the primitive design, or require a significantly higher (one- to two-orders of magnitude) more memory to encode their instances or their solutions, leading to an inflation in the cryptographic objects (keypairs, signatures, ciphertexts). While some relevant application scenarios can tolerate this increase in the requirements, there are concrete examples where we will need alternative ways to achieve the same confidentiality, integrity and origin authentication guarantees. Scenarios such as authentication in very low-bandwidth radio communication channels and encryption and authentication on severely memory limited devices (e.g., RFIDs) will require concrete engineering effort to complete the PQC transition. This talk will provide a survey of these scenarios, and highlight the open challenges. Alessandro Barenghi (PoliMI) |
16:15-16:45 |
|
The cost of quantum resistance: comparing classical and post-quantum cryptography Abstract: The transition to post-quantum cryptography implies long-term security against quantum adversaries, but this security comes with significant design and implementation trade-offs. This talk presents an in-depth technical examination of the challenges associated with replacing classical public-key cryptography with quantum-resistant alternatives. A thorough comparison between established schemes such as RSA and ECC and emerging post-quantum algorithms, including those standardized or currently being standardized by NIST, ISO, and the IETF, is essential to understand the scope and complexity of this transition. This discussion analyzes key encapsulation mechanisms and digital signature schemes, examining parameter selection, implementation complexity, memory requirements, computational efficiency, and communication overhead. Simone Dutto (ACN) |
16:45-17:15 |
|
Coffee Break |
17:15-17:30 |
|
Beyond the Algorithm: Hardware/Software Design for Post-Quantum Cryptography Abstract: Post-quantum cryptography is moving from standardization to deployment, but efficient implementation requires more than selecting secure algorithms. PQC schemes introduce new challenges in computation, memory footprint, data movement, and energy, particularly on embedded and IoT platforms. This talk provides a practical overview of how PQC workloads can be mapped to hardware, from custom instructions to tightly and loosely coupled accelerators, with a particular focus on RISC-V architectures. Through representative implementation examples, it discusses how algorithmic bottlenecks, communication overheads, and accelerator integration choices shape the final system performance, highlighting the need for a hardware/software co-design approach to practical PQC deployment.. Alessandra Dolmeta (PoliTO) |
17:30-18:00 |
Organizers
-
Chair Riccardo Longo, Fondazione Bruno Kessler (rlongo@fbk.eu).
-
Organizing Committee:
- Stefano Berlato, Fondazione Bruno Kessler (sberlato@fbk.eu);
- Veronica Cristiano, Telsy (veronica.cristiano@telsy.it);
- Marco Pedicini, Roma Tre University - Department of Mathematics and Physics (marco.pedicini@uniroma3.it);
- Silvio Ranise, University of Trento - Department of Mathematics and Fondazione Bruno Kessler (ranise@fbk.eu);
- Chiara Spadafora, University of Trento - Department of Mathematics (chiara.spadafora@unitn.it);
- Alessandro Tomasi, Fondazione Bruno Kessler (altomasi@fbk.eu).