The Next Generation

Talk by Mihir Bellare

2026-09-09
Location: TU Wien, FAV Hörsaal 1 Helmut Veith (Favoritenstraße 11, 1040 Wien) (HEEG02)
Date/Time: 2026-09-22 11:00 ‒ 11:40

Abstract: The first part of this talk, which is on the technical side, will critique the current definition of authenticated encryption (AE1 or AEAD), with regard, not to novel or advanced goals, but (perhaps surprisingly) to providing the most basic message privacy. It will then discuss alternatives (AE2, AE3, AE5), ultimately suggesting as a conclusion that a really good definition is still lacking and an open question. The second part of the talk, which is more on the social side, will explore how AI might impact our community.

Bio: Mihir Bellare is Professor of Computer Science and Engineering at UC San Diego. He received his BS from Caltech in 1986 and his PhD from MIT in 1991, and was a researcher at IBM from 1991 to 1995.

Together with Phillip Rogaway, Bellare pioneered the foundations of practice-oriented provable security, transforming cryptographic design through precise security definitions and concrete, quantitative reductions. He is a co-developer of widely deployed constructions including HMAC, RSA-OAEP, RSA-PSS, and OCB. His broader contributions span authenticated encryption, digital signatures, key derivation, the random-oracle methodology, and committing security, and have influenced major standards and protocols such as SSL/TLS, SSH, and IEEE 802.11.

Bellare is a Fellow of both the ACM and the IACR. His honors include the ACM Paris Kanellakis Theory and Practice Award, the RSA Conference Award in Mathematics, a Packard Fellowship, and an NSF CAREER Award.

The lecture is part of the 2nd Workshop on Generic Attacks and Proofs in Symmetric Cryptography (GAPS2), organized by Prof. Elena Andreeva.