Keynote at CIFRIS26

The Fourth National Conference on Cryptography (CIFRIS26) is an international event promoted and organised by De Cifris together with Roma Tre University. The conference brings together researchers, practitioners, developers and users to discuss cryptography in its theoretical, applied, historical and societal dimensions, exchange methods and tools, and foster new scientific collaborations and research initiatives.

2026-10-07

Elena Andreeva was an invited speaker at CIFRIS26, where she delivered the talk “Expanding Primitives, Expanding Possibilities in Symmetric Cryptography.”

Abstract

Can expanding the output of a secret-key cryptographic primitive open up new “Swiss-Army-Knife”-like possibilities in symmetric cryptography? Expanding primitives map a single fixed-size input to multiple fixed-size output blocks under a secret key and, possibly, a public tweak. They can be seen as a Swiss-Army-Knife primitive, offering a unified interface for block ciphers, tweakable block ciphers, hash functions, and expanding functions.

Tunability, scalability, flexibility, security, and efficiency make this Swiss-Army-Knife approach especially attractive. Our design approach is tunable at several levels: the public tweak, the number of output blocks, and the type of operation used to expand the output. All of these can be chosen to fit the application and to bring the primitive closer to the higher-level protocol. This flexibility lets designers trade off security margin, output size, and cost without redesigning the primitive. The approach is also scalable: the cost of the shared computation is amortized across outputs, so efficiency grows with the demands of the application, from constrained IoT devices to high-throughput cloud services.

In this talk, I will explore how generic expanding primitives such as forkciphers (ForkSkinny, ASIACRYPT'19) and expanding pseudorandom functions (e.g. ButterKnife, ACNS'24) can improve security and efficiency in applications ranging from pseudorandom generation and key derivation to encryption, authenticated encryption, IoT-to-cloud Communication, and future-proof computation. Importantly, they support properties such as beyond-birthday-bound privacy and authenticity, committing security, security under release of unverified plaintext, and leakage resilience, among others. I will discuss the benefits of sharing and assigning computation across multiple outputs at the primitive, mode, and protocol levels, the challenges of designing, formalizing, and proving the security of tunable and scalable secret-keyed constructions, and the open questions shaping this research direction.

photo: James Case, CC BY 2.0, via Wikimedia Commons