<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cryspen</title><link>https://cryspen.com/</link><description>Recent content on Cryspen</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 04 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cryspen.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Contact us</title><link>https://cryspen.com/contact/</link><pubDate>Sat, 04 Jul 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/contact/</guid><description>&lt;div class="text-center"&gt;
 &lt;div class="d-flex flex-column flex-sm-row align-items-center justify-content-center gap-3 py-3"&gt;
 &lt;a id="contact-email" class="fs-5 fw-semibold text-primary user-select-all" href="mailto:info@cryspen.com"&gt;info@cryspen.com&lt;/a&gt;
 &lt;button id="copy-email-btn" type="button" class="btn btn-primary text-light px-4"&gt;Copy address&lt;/button&gt;
 &lt;/div&gt;
 &lt;p class="text-black-61 pt-5 pb-2"&gt;You can also find us here:&lt;/p&gt;
 &lt;ul class="d-flex justify-content-center list-unstyled gap-2 pt-2 mb-0"&gt;
 
 &lt;li class="rounded-circle bg-red-16 p-2"&gt;
 &lt;a class="d-flex align-items-center justify-content-center size-16 text-primary" href="https://www.linkedin.com/company/cryspen" aria-label="LinkedIn"&gt;&lt;svg
 xmlns="http://www.w3.org/2000/svg"
 width="16"
 height="16"
 fill="currentColor"
 class="bi bi-linkedin"
 viewBox="0 0 448 512"
 &gt;
 &lt;path
 d="M416 32H31.9C14.3 32 0 46.5 0 64.3v383.4C0 465.5 14.3 480 31.9 480H416c17.6 0 32-14.5 32-32.3V64.3c0-17.8-14.4-32.3-32-32.3zM135.4 416H69V202.2h66.5V416zm-33.2-243c-21.3 0-38.5-17.3-38.5-38.5S80.9 96 102.2 96c21.2 0 38.5 17.3 38.5 38.5 0 21.3-17.2 38.5-38.5 38.5zm282.1 243h-66.4V312c0-24.8-.5-56.7-34.5-56.7-34.6 0-39.9 27-39.9 54.9V416h-66.4V202.2h63.7v29.2h.9c8.9-16.8 30.6-34.5 62.9-34.5 67.2 0 79.7 44.3 79.7 101.9V416z"
 /&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
 &lt;/li&gt;
 
 
 &lt;li class="rounded-circle bg-red-16 p-2"&gt;
 &lt;a class="d-flex align-items-center justify-content-center size-16 text-primary" href="https://github.com/cryspen" aria-label="GitHub"&gt;&lt;svg
 xmlns="http://www.w3.org/2000/svg"
 width="16"
 height="16"
 fill="currentColor"
 viewBox="0 0 496 512"
 &gt;
 &lt;path
 d="M165.9 397.4c0 2-2.3 3.6-5.2 3.6-3.3.3-5.6-1.3-5.6-3.6 0-2 2.3-3.6 5.2-3.6 3-.3 5.6 1.3 5.6 3.6zm-31.1-4.5c-.7 2 1.3 4.3 4.3 4.9 2.6 1 5.6 0 6.2-2s-1.3-4.3-4.3-5.2c-2.6-.7-5.5.3-6.2 2.3zm44.2-1.7c-2.9.7-4.9 2.6-4.6 4.9.3 2 2.9 3.3 5.9 2.6 2.9-.7 4.9-2.6 4.6-4.6-.3-1.9-3-3.2-5.9-2.9zM244.8 8C106.1 8 0 113.3 0 252c0 110.9 69.8 205.8 169.5 239.2 12.8 2.3 17.3-5.6 17.3-12.1 0-6.2-.3-40.4-.3-61.4 0 0-70 15-84.7-29.8 0 0-11.4-29.1-27.8-36.6 0 0-22.9-15.7 1.6-15.4 0 0 24.9 2 38.6 25.8 21.9 38.6 58.6 27.5 72.9 20.9 2.3-16 8.8-27.1 16-33.7-55.9-6.2-112.3-14.3-112.3-110.5 0-27.5 7.6-41.3 23.6-58.9-2.6-6.5-11.1-33.3 2.6-67.9 20.9-6.5 69 27 69 27 20-5.6 41.5-8.5 62.8-8.5s42.8 2.9 62.8 8.5c0 0 48.1-33.6 69-27 13.7 34.7 5.2 61.4 2.6 67.9 16 17.7 25.8 31.5 25.8 58.9 0 96.5-58.9 104.2-114.8 110.5 9.2 7.9 17 22.9 17 46.4 0 33.7-.3 75.4-.3 83.6 0 6.5 4.6 14.4 17.3 12.1C428.2 457.8 496 362.9 496 252 496 113.3 383.5 8 244.8 8zM97.2 352.9c-1.3 1-1 3.3.7 5.2 1.6 1.6 3.9 2.3 5.2 1 1.3-1 1-3.3-.7-5.2-1.6-1.6-3.9-2.3-5.2-1zm-10.8-8.1c-.7 1.3.3 2.9 2.3 3.9 1.6 1 3.6.7 4.3-.7.7-1.3-.3-2.9-2.3-3.9-2-.6-3.6-.3-4.3.7zm32.4 35.6c-1.6 1.3-1 4.3 1.3 6.2 2.3 2.3 5.2 2.6 6.5 1 1.3-1.3.7-4.3-1.3-6.2-2.2-2.3-5.2-2.6-6.5-1zm-11.4-14.7c-1.6 1-1.6 3.6 0 5.9 1.6 2.3 4.3 3.3 5.6 2.3 1.6-1.3 1.6-3.9 0-6.2-1.4-2.3-4-3.3-5.6-2z"
 /&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
 &lt;/li&gt;
 
 
 &lt;li class="rounded-circle bg-red-16 p-2"&gt;
 &lt;a class="d-flex align-items-center justify-content-center size-16 text-primary" href="https://bsky.app/profile/cryspen.bsky.social" aria-label="Bluesky"&gt;&lt;svg
 width="568"
 height="501"
 viewBox="0 0 568 501"
 fill="currentColor"
 xmlns="http://www.w3.org/2000/svg"
 &gt;
 &lt;path
 d="M123.121 33.6637C188.241 82.5526 258.281 181.681 284 234.873C309.719 181.681 379.759 82.5526 444.879 33.6637C491.866 -1.61183 568 -28.9064 568 57.9464C568 75.2916 558.055 203.659 552.222 224.501C531.947 296.954 458.067 315.434 392.347 304.249C507.222 323.8 536.444 388.56 473.333 453.32C353.473 576.312 301.061 422.461 287.631 383.039C285.169 375.812 284.017 372.431 284 375.306C283.983 372.431 282.831 375.812 280.369 383.039C266.939 422.461 214.527 576.312 94.6667 453.32C31.5556 388.56 60.7778 323.8 175.653 304.249C109.933 315.434 36.0535 296.954 15.7778 224.501C9.94525 203.659 0 75.2916 0 57.9464C0 -28.9064 76.1345 -1.61183 123.121 33.6637Z"
 /&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
 &lt;/li&gt;
 
 
 &lt;li class="rounded-circle bg-red-16 p-2"&gt;
 &lt;a class="d-flex align-items-center justify-content-center size-16 text-primary" href="https://ioc.exchange/@cryspen" aria-label="Mastodon"&gt;&lt;svg
 xmlns="http://www.w3.org/2000/svg"
 width="16"
 height="16"
 fill="currentColor"
 class="bi bi-mastodon"
 viewBox="0 0 16 16"
 &gt;
 &lt;path
 d="M11.19 12.195c2.016-.24 3.77-1.475 3.99-2.603.348-1.778.32-4.339.32-4.339 0-3.47-2.286-4.488-2.286-4.488C12.062.238 10.083.017 8.027 0h-.05C5.92.017 3.942.238 2.79.765c0 0-2.285 1.017-2.285 4.488l-.002.662c-.004.64-.007 1.35.011 2.091.083 3.394.626 6.74 3.78 7.57 1.454.383 2.703.463 3.709.408 1.823-.1 2.847-.647 2.847-.647l-.06-1.317s-1.303.41-2.767.36c-1.45-.05-2.98-.156-3.215-1.928a4 4 0 0 1-.033-.496s1.424.346 3.228.428c1.103.05 2.137-.064 3.188-.189zm1.613-2.47H11.13v-4.08c0-.859-.364-1.295-1.091-1.295-.804 0-1.207.517-1.207 1.541v2.233H7.168V5.89c0-1.024-.403-1.541-1.207-1.541-.727 0-1.091.436-1.091 1.296v4.079H3.197V5.522q0-1.288.66-2.046c.456-.505 1.052-.764 1.793-.764.856 0 1.504.328 1.933.983L8 4.39l.417-.695c.429-.655 1.077-.983 1.934-.983.74 0 1.336.259 1.791.764q.662.757.661 2.046z"
 /&gt;
 &lt;/svg&gt;
 &lt;/a&gt;
 &lt;/li&gt;
 
 &lt;/ul&gt;

&lt;/div&gt;
&lt;script&gt;
(function () {
 var btn = document.getElementById('copy-email-btn');
 if (!btn) return;
 var email = 'info@cryspen.com';
 function flash() {
 btn.textContent = 'Copied!';
 btn.disabled = true;
 setTimeout(function () { btn.textContent = 'Copy address'; btn.disabled = false; }, 2000);
 }
 function legacyCopy() {
 var ta = document.createElement('textarea');
 ta.value = email;
 ta.setAttribute('readonly', '');
 ta.style.position = 'fixed';
 ta.style.left = '-9999px';
 document.body.appendChild(ta);
 ta.select();
 try { document.execCommand('copy'); flash(); } catch (e) {}
 document.body.removeChild(ta);
 }
 btn.addEventListener('click', function () {
 if (navigator.clipboard &amp;&amp; navigator.clipboard.writeText) {
 navigator.clipboard.writeText(email).then(flash, legacyCopy);
 } else {
 legacyCopy();
 }
 });
})();
&lt;/script&gt;</description></item><item><title>Announcing CE Labs</title><link>https://cryspen.com/post/announcing-ce-labs/</link><pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/announcing-ce-labs/</guid><description>&lt;p&gt;Today, we are announcing the launch of &lt;a href="https://celabs.eu/"&gt;CE Labs&lt;/a&gt;, a Cryspen spin-off dedicated to Cryptographic Engineering, under the leadership of Franziskus Kiefer. Learn more about CE Labs &lt;a href="https://celabs.eu/blog/ce-labs-announcement/"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Going forward, Cryspen will be led by Karthik Bhargavan and will focus on building usable formal verification tools, helping users apply them on real-world software, and working towards a new product funded by an &lt;a href="https://eic.ec.europa.eu/eic-funding-opportunities/eic-transition_en"&gt;EIC Transition Grant&lt;/a&gt; called &lt;a href="https://cryspen.com/post/eic-transition-spectrum/"&gt;Spectrum&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Cryspen and CE Labs are continuing their close collaboration at the intersection of formal verification and cryptography. This partnership allows CE Labs to build high-assurance software using Cryspen&amp;rsquo;s tools, while Cryspen uses CE Labs&amp;rsquo; production code to refine and optimize its verification suite.&lt;/p&gt;</description></item><item><title>EIC Transition: Spectrum</title><link>https://cryspen.com/post/eic-transition-spectrum/</link><pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/eic-transition-spectrum/</guid><description>&lt;p&gt;We are excited to have been awarded a Transition Grant from the European Innovation Council to build a specification and verification toolkit that developers can use to build and deploy provably-secure software. The project is called &lt;a href="https://cryspen.com/spectrum/"&gt;Spectrum&lt;/a&gt; and it builds on our &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt; open-source framework.&lt;/p&gt;
&lt;p&gt;In the coming months, we will describe how we and our customers use the Spectrum tools on a daily basis to design and implement security-critical systems. If you would like to know how Spectrum can help you, get in touch.&lt;/p&gt;</description></item><item><title>Spectrum</title><link>https://cryspen.com/spectrum/</link><pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/spectrum/</guid><description>&lt;p&gt;Does your team use AI coding agents to write your software? How confident are you that the agent built what you actually intended, and that it didn&amp;rsquo;t introduce security vulnerabilities along the way? How can you check that the generated code complies with your security and privacy policies?&lt;/p&gt;
&lt;p&gt;&lt;a href="https://dora.dev/dora-report-2025/"&gt;More and more developer teams&lt;/a&gt; now use AI agents to build complex software at scale and at speed. The bottleneck is specification and review, which requires domain expertise and is error-prone, allowing correctness bugs and security flaws to slip into the codebase. As frontier AI models get better at &lt;a href="https://www.anthropic.com/glasswing"&gt;finding and exploiting vulnerabilities&lt;/a&gt;, there is a pressing need for methodologies to develop software systems that are secure-by-design and secure-by-default.&lt;/p&gt;</description></item><item><title>Software Verification in Lean</title><link>https://cryspen.com/post/software-verification-in-lean-2026/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/software-verification-in-lean-2026/</guid><description>&lt;p&gt;This week in Paris, Cryspen is delighted to be co-hosting
&lt;a href="https://beneficial-ai-foundation.github.io/SVIL2026/"&gt;Software Verification in Lean 2026&lt;/a&gt;, a
workshop and associated hackathon organized by the
&lt;a href="https://www.beneficialaifoundation.org/"&gt;Beneficial AI Foundation&lt;/a&gt; and the
&lt;a href="https://lean-lang.org/fro/"&gt;Lean FRO&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;SVIL 2026 brings together leading researchers and practitioners
working on using the &lt;a href="https://lean-lang.org/"&gt;Lean proof assistant&lt;/a&gt; to
formalize and verify real-world software. On Monday, I gave a talk on
the challenges of verifying cryptographic applications, and the
opportunities that are being opened up by the rapid innovations
in Lean and by the emergence of AI-assisted formal proofs.&lt;/p&gt;</description></item><item><title>The strengths and limits of formal verification</title><link>https://cryspen.com/post/strengths-and-limitations/</link><pubDate>Thu, 12 Feb 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/strengths-and-limitations/</guid><description>&lt;p&gt;I have learned that it is important to be precise when
documenting the guarantees offered by formally
verified code, and to resist the temptation of simplifying things too
much in trying to reach a larger audience. In my talks, to my
students, and to our users and customers, we always clearly describe
our coding, testing, and verification methodologies, explain what we
verify and against what specifications, elaborate our trust
assumptions, and detail the limitations of our approach.&lt;/p&gt;</description></item><item><title>PSQ: Post-Quantum Shared Secrets Made Easy</title><link>https://cryspen.com/post/psq-announce/</link><pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/psq-announce/</guid><description>&lt;p&gt;We&amp;rsquo;re pleased to announce the &lt;a href="https://github.com/celabshq/libcrux/tree/main/libcrux-psq"&gt;PSQ protocol&lt;/a&gt; for establishing a hybrid post-quantum shared secret between two parties.&lt;/p&gt;
&lt;p&gt;Cryptographic protocols, which exclusively rely on classical public key cryptography for establishing shared secrets, may be vulnerable to &lt;a href="https://en.wikipedia.org/wiki/Harvest_now%2C_decrypt_later"&gt;harvest-now-decrypt-later&lt;/a&gt; (HNDL) quantum attacks.
However, many protocols in widespread use today allow injecting a previously established pre-shared key (PSK) into the computation of the shared secret. If we can establish this pre-shared key in a way that is secure against HNDL attackers, we can provide an easy way of protecting many applications without having to touch their internals.&lt;/p&gt;</description></item><item><title>Cryspen Welcomes Alex</title><link>https://cryspen.com/post/welcome_alex/</link><pubDate>Mon, 10 Nov 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_alex/</guid><description>&lt;p&gt;This month, we welcome Alexander Bentkamp (Alex) as the newest member of our team.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://abentkamp.github.io/"&gt;Alex&lt;/a&gt; joins us with a strong background in automated and
interactive theorem proving, where his passion for formal proofs has
driven a series of influential contributions. He completed his PhD at
the Vrije Universiteit Amsterdam under the supervision of Jasmin
Blanchette, Uwe Waldmann, and Wan Fokkink, developing a novel proof
automation method for higher-order logic. The prover he co-developed
based on this method went on to win the annual CASC competition
multiple times and is now integrated into the Isabelle/HOL proof
assistant.&lt;/p&gt;</description></item><item><title>Formally Specifying and Testing the Rust Standard Library</title><link>https://cryspen.com/post/specify-rust-simd/</link><pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/specify-rust-simd/</guid><description>&lt;p&gt;Modern programming languages typically come with a large standard
library that implements essential language features like machine
arithmetic and I/O, offers efficient data structures, provides
interfaces to system libraries, etc. Although it is often overlooked,
this standard library should be considered as much part of the trusted
computing base (TCB) as the language compiler. Indeed, any bug in the standard
library is likely to break applications and could result in security vulnerabilities.&lt;/p&gt;</description></item><item><title>Helping Secure Signal's Post-Quantum Transition</title><link>https://cryspen.com/post/signal-spqr-verification/</link><pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/signal-spqr-verification/</guid><description>&lt;p&gt;Signal just &lt;a href="https://signal.org/blog/spqr/"&gt;announced&lt;/a&gt; the deployment
of their new post-quantum ratcheting protocol, called the Sparse
Post-Quantum Ratchet (SPQR), and Cryspen is proud to have contributed
to the formal analysis of the design and implementation of this new
Signal feature.&lt;/p&gt;
&lt;p&gt;The seeds of our collaboration with Signal reach back to 2023, when
Signal first published PQXDH, the post-quantum key establishment
protocol that marked the beginning of Signal&amp;rsquo;s post-quantum
transition. We helped Signal to &lt;a href="https://cryspen.com/post/pqxdh/"&gt;formally analyze and improve
PQXDH&lt;/a&gt;, resulting in a &lt;a href="https://www.usenix.org/conference/usenixsecurity24/presentation/bhargavan"&gt;paper at
Usenix Security&lt;/a&gt;.
This time, Cryspen and Signal agreed to collaborate from the very
beginning of the design process for SPQR all the way through to its
implementation.&lt;/p&gt;</description></item><item><title>PQC Support for JZLint</title><link>https://cryspen.com/post/pqc-jzlint/</link><pubDate>Mon, 11 Aug 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pqc-jzlint/</guid><description>&lt;p&gt;We joined forces with &lt;a href="https://mtg.de/"&gt;MTG AG&lt;/a&gt;, a leader in public key infrastructures, to release &lt;a href="https://github.com/MTG-AG/jzlint"&gt;JZLint 2.0&lt;/a&gt; with support for analyzing post-quantum (PQC) certificates and their public keys.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;JZLint 2.0&lt;/strong&gt; is a certificate linter that plays a crucial role in the issuance of digital certificates. Linting involves checking certificates for errors and ensuring their conformance to relevant specifications. This vital step is performed by public certificate authorities (CAs) to ensure compliance with technical standards and security requirements before the certificates are issued. Tools like JZLint play an essential role in the &lt;a href="https://celabs.eu/"&gt;transition to post-quantum secure cryptography&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Research</title><link>https://cryspen.com/research/</link><pubDate>Mon, 14 Jul 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/research/</guid><description>&lt;p&gt;We work with our colleagues in academia and industry to extend the
state-of-the-art in software verification and security analysis. We
regularly publish and present our research in peer-reviewed conferences
and workshops.&lt;/p&gt;
&lt;h2 id="presentations"&gt;Presentations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Real World Crypto 2025: &lt;em&gt;Using Formally Verified Post-Quantum Algorithms at Scale&lt;/em&gt;. Lucas Franceschino with Andres Erbsen.
(&lt;a href="https://cryspen.com/post/rwc-2025/RWC_2025_Slides.pdf"&gt;Slides&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=DBXb2uJDB5w&amp;amp;ab_channel=IACR"&gt;Video&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;VSTTE 2024: &lt;em&gt;High Assurance Post Quantum Cryptography&lt;/em&gt; (Invited Talk). Karthikeyan Bhargavan.
(&lt;a href="https://cryspen.com/post/vstte2024/VSTTE2024-slides.pdf"&gt;Slides&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;CRYPTO 2024: &lt;em&gt;Formal Methods for Cryptography: protocols, standards, implementations&lt;/em&gt; (Invited Talk). Karthikeyan Bhargavan.
(&lt;a href="https://cryspen.com/post/crypto2024/Crypto24Slides.pdf"&gt;Slides&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=PImanht0KoA&amp;amp;ab_channel=IACR"&gt;Video&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Real World Crypto 2024: &lt;em&gt;An Analysis of Signal&amp;rsquo;s PQXDH&lt;/em&gt;. Karthikeyan Bhargavan with Rolfe Schmidt.
(&lt;a href="https://iacr.org/submit/files/slides/2024/rwc/rwc2024/86/slides.pdf"&gt;Slides&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=Zevny4ePKCk&amp;amp;ab_channel=IACR"&gt;Video&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;NIST Workshop on Formal Methods within Certification Programs 2024: &lt;em&gt;Formal Specifications for Certifiable Cryptography&lt;/em&gt;. Karthikeyan Bhargavan.
(&lt;a href="https://cryspen.com/post/fmcp/Formal-Specifications-for-Certifiable-Cryptography-FMCP-2024.pdf"&gt;Slides&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;RustVerify 2024: &lt;em&gt;Enabling High Assurance Cryptographic Software&lt;/em&gt;. Jonas Schneider-Bensch.
(&lt;a href="https://cryspen.com/documents-and-slides/RustVerify2024.pdf"&gt;Slides&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Real World Post Quantum Cryptography 2024: &lt;em&gt;Verified ML-KEM in Rust and C using hax&lt;/em&gt;. Franziskus Kiefer.
(&lt;a href="https://na-prod-aventri-files.s3.amazonaws.com/html_file_uploads/d5b2efd4c301030c25549d2c57426e78_FranzikusKiefer_VerifiedML-KEMinRustandC_RWPQC2024.pdf?response-content-disposition=inline%3Bfilename%3D%22Franzikus%20Kiefer_Verified%20ML-KEM%20in%20Rust%20and%20C%20_%20RWPQC%202024.pdf%22&amp;amp;response-content-type=application%2Fpdf&amp;amp;AWSAccessKeyId=AKIA3OQUANZMGCIZWZ6F&amp;amp;Expires=1752632364&amp;amp;Signature=EoUJuZN3IKbX28LWrSuz0tRXjMU%3D"&gt;Slides&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Open Source Crypto Workshop 2024: &lt;em&gt;Cryptography with Formal Guarantees using hax&lt;/em&gt;. Franziskus Kiefer.
(&lt;a href="https://opensourcecryptowork.shop/2024/Cryptography%20with%20Formal%20Guarantees%20using%20Hax.pdf"&gt;Slides&lt;/a&gt;, &lt;a href="https://archive.org/details/oscw-2024-franziskus-kiefer-hax"&gt;Video&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;MatchPoints 2024: &lt;em&gt;High Assurance Post Quantum Cryptography&lt;/em&gt;. Karthikeyan Bhargavan.
(&lt;a href="https://cryspen.com/documents-and-slides/MatchPoints%E2%80%93High-Assurance_Post-Quantum_Cryptography.pdf"&gt;Slides&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="papers"&gt;Papers&lt;/h2&gt;
&lt;h4 id="2026"&gt;2026&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Project Everest: Perspectives from Developing Industrial-Grade High-Assurance Software&lt;/em&gt;.
Danel Ahman, Karthikeyan Bhargavan, Barry Bond, Jay Bosamiya, Christopher Brzuska, Antoine Delignat-Lavaud, Cédric Fournet, Aymeric Fromherz, Sydney Gibson, Chris Hawblitzel, Cătălin Hrițcu, Markulf Kohlweiss, Guido Martínez, Haobin Ni, Bryan Parno, Jonathan Protzenko, Tahina Ramananandro, Aseem Rastogi, Exequiel Rivas, Nikhil Swamy and Santiago Zanella-Béguelin. ACM Transactions on Programming Languages and SystemsVolume 48, Issue 2. June 2026.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="2025"&gt;2025&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Functional Verification of Cryptographic Protocol Implementations in Rust&lt;/em&gt;.
Karthikeyan Bhargavan, Lasse Letager Hansen, Franziskus Kiefer, Jonas Schneider-Bensch, Bas Spitters.
ACM SIGSAC Conference on Computer and Communications Security (CCS) 2025
(&lt;a href="https://eprint.iacr.org/2025/980"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;A Mechanically Verified Garbage Collector for OCaml&lt;/em&gt;.
Sheera Shamsu, Dipesh Kafle, Dhruv Maroo, Kartik Nagar, Karthikeyan Bhargavan, K. C. Sivaramakrishnan.
Journal of Automated Reasoning. 69(2): 11 (2025).
(&lt;a href="https://link.springer.com/article/10.1007/s10817-025-09721-0"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;KyberSlash: Exploiting secret-dependent division timings in Kyber implementations.&lt;/em&gt; &lt;br&gt;
Daniel J. Bernstein, Karthikeyan Bhargavan, Shivam Bhasin, Anupam Chattopadhyay, Tee Kiah Chia, Matthias J. Kannwischer, Franziskus Kiefer, Thales B. Paiva, Prasanna Ravi, Goutam Tamvada.
IACR Transactions on Cryptographic Hardware and Embedded Systems. 2025(2): 209-234 (2025)
(&lt;a href="https://eprint.iacr.org/2024/1049"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;TreeKEM: A Modular Machine-Checked Symbolic Security Analysis of Group Key Agreement in Messaging Layer Security&lt;/em&gt;.
Theophile Wallez, Jonathan Protzenko, Karthikeyan Bhargavan.
Symposium on Security and Privacy: 4375-4390 (2025)
(&lt;a href="https://eprint.iacr.org/2025/410"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Public Key Linting for ML-KEM and ML-DSA&lt;/em&gt;.
Evangelos Karatsiolis, Franziskus Kiefer, Juliane Krämer, Mirjam Loiero, Christian Tobias, Maximiliane Weishäupl.
Workshop on Secure Protocol Implementations in the Quantum Era (2025)
(&lt;a href="https://eprint.iacr.org/2025/1241"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="2024"&gt;2024&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;hax: Verifying Security-Critical Rust Software Using Multiple Provers&lt;/em&gt;.
Karthikeyan Bhargavan, Maxime Buyse, Lucas Franceschino, Lasse Letager Hansen, Franziskus Kiefer, Jonas Schneider-Bensch, Bas Spitters.
Verified Software. Theories, Tools and Experiments (VSTTE) 2024: 96-119.
(&lt;a href="https://eprint.iacr.org/2025/142"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messaging&lt;/em&gt;.
Karthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe Schmidt:
USENIX Security Symposium 2024
(&lt;a href="https://www.usenix.org/conference/usenixsecurity24/presentation/bhargavan"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="2023"&gt;2023&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Comparse: Provably Secure Formats for Cryptographic Protocols&lt;/em&gt;.
Theophile Wallez, Jonathan Protzenko, Karthikeyan Bhargavan.
ACM SIGSAC Conference on Computer and Communications Security (CCS) 2023: 564-578.
(&lt;a href="https://eprint.iacr.org/2023/1390"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Layered Symbolic Security Analysis in DY&lt;/em&gt;*
Karthikeyan Bhargavan, Abhishek Bichhawat, Pedram Hosseyni, Ralf Kuesters, Klaas Pruiksma, Guido Schmitz, Clara Waldmann, Tim Wuertele.
ESORICS (3) 2023: 3-21
(&lt;a href="https://eprint.iacr.org/2023/1329"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;From Dragondoom to Dragonstar: Side-channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake&lt;/em&gt;.
Daniel De Almeida Braga, Natalia Kulatova, Mohamed Sabt, Pierre-Alain Fouque, Karthikeyan Bhargavan.
IEEE European Symposium on Security and Privacy (EuroS&amp;amp;P) 2023: 707-723.
(&lt;a href="https://arxiv.org/abs/2307.09243"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;TreeSync: Authenticated Group Management for Messaging Layer Security&lt;/em&gt;.
Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan Bhargavan.
USENIX Security Symposium 2023: 1217-1233.
&lt;strong&gt;Awarded the Internet Defense Prize and a Distinguished Paper Award.&lt;/strong&gt;
(&lt;a href="https://www.usenix.org/conference/usenixsecurity23/presentation/wallez"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="2022"&gt;2022&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;A Symbolic Analysis of Privacy for TLS 1.3 with Encrypted Client Hello&lt;/em&gt;.
Karthikeyan Bhargavan, Vincent Cheval, Christopher A. Wood.
ACM SIGSAC Conference on Computer and Communications Security (CCS) 2022: 365-379.
(&lt;a href="https://inria.hal.science/hal-03922516"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Hybrid Public Key Encryption&lt;/em&gt;.
Richard L. Barnes, Karthikeyan Bhargavan, Benjamin Lipp, Christopher A. Wood.
IETF RFC 9180: 1-107 (2022)
(&lt;a href="https://www.rfc-editor.org/rfc/rfc9180.html"&gt;Standard&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Noise*: A Library of Verified High-Performance Secure Channel Protocol Implementations.&lt;/em&gt;
Son Ho, Jonathan Protzenko, Abhishek Bichhawat, Karthikeyan Bhargavan.
IEEE Symposium on Security and Privacy (S&amp;amp;P) 2022: 107-124.
(&lt;a href="https://eprint.iacr.org/2022/607"&gt;Paper&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/br&gt;
&lt;a class="btn btn-outline-primary px-4" href="mailto:info@cryspen.com"&gt;Get in touch&lt;/a&gt;</description></item><item><title>Tooling for Automated Benchmarking and Visualization</title><link>https://cryspen.com/post/benchmarking-07-25/</link><pubDate>Tue, 08 Jul 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/benchmarking-07-25/</guid><description>&lt;p&gt;Maintaining peak software performance is a critical aspect of our development process, and early regression detection is non-negotiable. At Cryspen, we&amp;rsquo;ve addressed this by implementing an automated, multi-platform benchmarking system. This post will detail the enhancements we&amp;rsquo;ve made to our workflows, allowing us to preemptively identify performance issues. Besides focusing on algorithm benchmarks, we utilize a tracing strategy for our protocol code. This method allows us to measure performance on live code. In addition, we will explore the tools and methods designed for creating comprehensive, informative visualizations of benchmark data, applicable to our wide range of projects and repositories.&lt;/p&gt;</description></item><item><title>Cryspen Welcomes Clement</title><link>https://cryspen.com/post/welcome_clement/</link><pubDate>Tue, 13 May 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_clement/</guid><description>&lt;p&gt;The team here at Cryspen is thrilled to welcome to our newest member, Clement!&lt;/p&gt;
&lt;p&gt;&lt;a href="https://clement.blaudeau.net/"&gt;Clement&lt;/a&gt; joins us fresh from his impressive
journey as a PhD student at Inria Paris, where he was part of the &lt;a href="https://cambium.inria.fr/"&gt;Cambium
team&lt;/a&gt;. His doctoral work focused on the
formalization of the powerful but intricate typing system of OCaml modules.
Under the supervision of Didier Rémy and Gabriel Radanne, Clement delved deep
into the theoretical underpinnings of this masterpiece of language design.&lt;/p&gt;</description></item><item><title>MLS Group State Forks: What, Why, How</title><link>https://cryspen.com/post/mls-fork-resolution/</link><pubDate>Thu, 03 Apr 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/mls-fork-resolution/</guid><description>&lt;p&gt;Group state forks are faulty states that MLS groups can end up in. This article looks at what they are exactly, how that happens and how to resolve them. We also look at a new OpenMLS feature that makes fork resolutions a little easier.&lt;/p&gt;
&lt;p&gt;Over time, an MLS group evolves its group state. Whenever a new member is added, or another is removed, or a group extension is added or someone updates their encryption keys, the state must be changed. The versions that a group evolves throughout its lifetime are called epochs and identified by a counter value.The way this works is that first a number of requested state changes (&lt;em&gt;proposals&lt;/em&gt; in MLS terminology) are collected (“Add Dora”, “This is my new key”, &amp;hellip;) and then applied in a big update (called &lt;em&gt;commit&lt;/em&gt; in MLS). Once a commit is applied, the group state is changed and the group epoch counter is incremented.&lt;/p&gt;</description></item><item><title>Cryspen @ RWC 2025</title><link>https://cryspen.com/post/rwc-2025/</link><pubDate>Thu, 27 Mar 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/rwc-2025/</guid><description>&lt;p&gt;&lt;a href="https://rwc.iacr.org/2025/"&gt;Real World Crypto 2025&lt;/a&gt; buzzed with energy as
the cutting edge of cryptography was presented to and discussed among an audience of leading
researchers and developers from academia and industry. Today, on the second day of the conference,
Cryspen teamed up with Google to showcase practical, scalable, verified solutions
for high-assurance software and post-quantum cryptography.&lt;/p&gt;
&lt;h4 id="verified-post-quantum-crypto-at-scale"&gt;Verified Post-Quantum Crypto at Scale&lt;/h4&gt;
&lt;p&gt;Our joint talk with Google described our collaboration on developing
an efficient, SIMD-optimized implementation of the &lt;a href="https://csrc.nist.gov/pubs/fips/203/final"&gt;ML-KEM standard&lt;/a&gt;
in Rust and C. This wasn&amp;rsquo;t just about writing code; it was about proving its correctness through
&lt;a href="https://cryspen.com/post/fospqc/"&gt;rigorous formal verification&lt;/a&gt;.
We demonstrated how verified cryptography can be implemented at scale, a critical
advancement for securing our digital infrastructure.
Our verified implementations are already powering security-critical software projects
like OpenSSH, Firefox, and Signal.&lt;/p&gt;</description></item><item><title>Control flow analysis with hax</title><link>https://cryspen.com/post/control-flow-analysis/</link><pubDate>Wed, 26 Mar 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/control-flow-analysis/</guid><description>&lt;p&gt;A difficulty of formal verification is that specifying programs can be hard.
Certain kinds of programs can end up having a specification that is as complex
as the code itself.
In this case it is better to focus on more interesting and
understandable properties rather than an equivalence proof with a specification.&lt;/p&gt;
&lt;p&gt;For example, showing that before calling one function you always call another
function (imagine a validation function).
Indeed, forgetting a validation step can lead to severe vulnerabilities
(see &lt;a href="https://nvd.nist.gov/vuln/detail/cve-2014-1266"&gt;this example&lt;/a&gt; of a
vulnerability because of a missing signature check).&lt;/p&gt;</description></item><item><title>Cryspen Welcomes Clara</title><link>https://cryspen.com/post/welcome_clara/</link><pubDate>Mon, 10 Feb 2025 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_clara/</guid><description>&lt;p&gt;We&amp;rsquo;re thrilled to officially welcome Clara to the Cryspen team!
Clara brings a fantastic blend of experiences and a passion for open-source that aligns perfectly with our mission.
Let&amp;rsquo;s get to know her a little better.&lt;/p&gt;
&lt;p&gt;Clara recently graduated from TU Berlin with a B.Sc. in Computer Science.
She&amp;rsquo;s gained valuable experience porting C code and Linux systems software to Rust, including porting libxkbcommon to safe Rust.
She&amp;rsquo;s also explored game emulator development and low-level programming.&lt;/p&gt;</description></item><item><title>X25519MLKEM768 TLS-Handshake in Bertie</title><link>https://cryspen.com/post/pq-bertie-server/</link><pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pq-bertie-server/</guid><description>&lt;p&gt;Summer is over for some months on the northern hemisphere, and &lt;a href="https://cryspen.com/post/fospqc/"&gt;so is&lt;/a&gt; the draft phase of NISTs post-quantum cryptographic standards. Since August 13, 2024, FIPS has standardized Kyber as ML-KEM in &lt;a href="https://csrc.nist.gov/pubs/fips/203/final"&gt;FIPS 203&lt;/a&gt; for PQ encryption, Dilithium as ML-DSA and SPHINCS+ as SLH-DSA in &lt;a href="https://csrc.nist.gov/pubs/fips/204/final"&gt;FIPS 204&lt;/a&gt; and &lt;a href="https://csrc.nist.gov/pubs/fips/205/final"&gt;FIPS 205&lt;/a&gt;, respectively, for PQ digital signatures. Read more on how we at Cryspen are building formally verified implementations of these standards, &lt;a href="https://cryspen.com/post/fospqc/"&gt;previously on this blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In parallel, the IETF has worked on integrating the new standards, in particular ML-KEM into existing Internet standards. Part of that is standardizing hybrid post-quantum key agreements that can be used in the TLS 1.3 handshake.&lt;/p&gt;</description></item><item><title>Cryspen @ VSTTE 2024</title><link>https://cryspen.com/post/vstte2024/</link><pubDate>Mon, 14 Oct 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/vstte2024/</guid><description>&lt;p&gt;&lt;a href="https://www.soundandcomplete.org/vstte2024.html"&gt;Verified Software: Theories, Tools, and Experiments&lt;/a&gt;
is a conference that aims to advance the state of the art in software verification.&lt;/p&gt;
&lt;p&gt;At VSTTE 2024 in Prague, Karthik spoke about how formal verification can be used
to speed up software development and clarify the security of real-world cryptography from design to implementation.
In particular, he showed how these techniques are crucial for the post-quantum transition,
using examples from our analysis of post-quantum protocols like &lt;a href="https://cryspen.com/post/pqxdh/"&gt;PQXDH&lt;/a&gt;
and our &lt;a href="https://cryspen.com/post/ml-kem-verification/"&gt;verified ML-KEM implementation&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Cryspen @ Crypto 2024</title><link>https://cryspen.com/post/crypto2024/</link><pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/crypto2024/</guid><description>&lt;p&gt;&lt;a href="https://crypto.iacr.org/"&gt;Crypto&lt;/a&gt; is the top international conference on cryptography
and is held every year (since 1981) in Santa Barbara, California. This year,
Crypto invited Karthikeyan Bhargavan, our Chief Research Scientist, to give
a talk on the use of formal methods in cryptography.&lt;/p&gt;
&lt;p&gt;Karthik spoke about the state of the art in formal analysis techniques for crypto,
and how we can use them to increase confidence in important
protocols like &lt;a href="https://cryspen.com/post/pqxdh/"&gt;PQXDH&lt;/a&gt;, &lt;a href="https://cryspen.com/post/pq-bertie/"&gt;TLS&lt;/a&gt;, and &lt;a href="https://cryspen.com/post/pq-openmls/"&gt;MLS&lt;/a&gt;.
He also spoke about how we at Cryspen use &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt; to build verified post-quantum cryptographic libraries like
&lt;a href="https://github.com/celabshq/libcrux"&gt;libcrux&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Formally Verified Post-Quantum Cryptography</title><link>https://cryspen.com/post/fospqc/</link><pubDate>Mon, 19 Aug 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/fospqc/</guid><description>&lt;p&gt;The US National Institute of Standards and Technology (NIST) &lt;a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards"&gt;just released&lt;/a&gt; the first three standards for Post-Quantum KEMs (&lt;a href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.203.pdf"&gt;ML-KEM&lt;/a&gt;) and Signatures (&lt;a href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.204.pdf"&gt;ML-DSA&lt;/a&gt;, &lt;a href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.205.pdf"&gt;SLH-DSA&lt;/a&gt;). This first official publication of Post-Quantum Cryptography (PQC) standards represents a significant step forward in securing the Internet, and organizations across the globe, against the future threat of quantum computers.&lt;/p&gt;
&lt;p&gt;At Cryspen, we have been developing formally verified open-source implementations of post-quantum cryptographic algorithms in Rust using the &lt;a href="https://hax.cryspen.com"&gt;hax toolchain&lt;/a&gt;. Our implementations are verified to be &lt;a href="https://cryspen.com/post/ml-kem-verification/"&gt;panic free, functionally correct, and secret independent&lt;/a&gt;. Indeed, our verification of Kyber already &lt;a href="https://cryspen.com/post/ml-kem-implementation/"&gt;uncovered vulnerabilities&lt;/a&gt; that were found to be present and &lt;a href="https://eprint.iacr.org/2024/1049"&gt;exploitable&lt;/a&gt; in multiple Kyber implementations.&lt;/p&gt;</description></item><item><title>Announcing the hax Playground</title><link>https://cryspen.com/post/announcement-playground/</link><pubDate>Wed, 14 Aug 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/announcement-playground/</guid><description>&lt;p&gt;We&amp;rsquo;re proud to announce the &lt;a href="https://hax-playground.cryspen.com/"&gt;hax
playground&lt;/a&gt;! Inspired by the
&lt;a href="https://play.rust-lang.org/"&gt;Rust Playground&lt;/a&gt;, the hax playground
allows you to play with hax directly in your web browser!&lt;/p&gt;
&lt;p&gt;
 &lt;div class="alert alert-primary text-center my-4" role="alert"&gt;
 Try it now on &lt;a href="https://hax-playground.cryspen.com/"&gt;https://hax-playground.cryspen.com&lt;/a&gt; 🚀
 &lt;/div&gt;
&lt;/p&gt;

&lt;p&gt;The hax playground provides a first glimpse at Cryspen&amp;rsquo;s upcoming
verification workbench!
From the playground, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Run the hax toolchain on your Rust code to see the F*, Coq or ProVerif output&lt;/li&gt;
&lt;li&gt;Run the F* typechecker to verify the generated F* code&lt;/li&gt;
&lt;li&gt;Inspect Rust internal ASTs interactively&lt;/li&gt;
&lt;li&gt;Share snippets with others&lt;/li&gt;
&lt;li&gt;Submit issues to the hax repository on GitHub&lt;/li&gt;
&lt;/ul&gt;
&lt;img src="diagram.png" class="py-4"&gt;
&lt;p&gt;We believe such a playground can be a great and useful tool, whether
it be for newcomers, for people that already use hax, for hax
developers, but also for people interested in Rust in general!&lt;/p&gt;</description></item><item><title>Cryspen Welcomes Maxime</title><link>https://cryspen.com/post/welcome_maxime/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_maxime/</guid><description>&lt;p&gt;We&amp;rsquo;re thrilled to announce that Maxime Buyse has joined the Cryspen team as a Formal Verification Engineer! 🎉&lt;/p&gt;
&lt;p&gt;Maxime is a whiz when it comes to formal methods, software verification, compilers, and functional programming.
His expertise will be instrumental in supercharging our tools like &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt; and making them even easier to use.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re excited to have someone of Maxime&amp;rsquo;s caliber join our team.
His passion for building top-notch software aligns perfectly with our mission.
With his help, we&amp;rsquo;re confident in pushing the boundaries of high assurance software.&lt;/p&gt;</description></item><item><title>High Assurance IoT PQC</title><link>https://cryspen.com/post/pqc-iot-announce/</link><pubDate>Mon, 05 Aug 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pqc-iot-announce/</guid><description>&lt;p&gt;Together with our sister-company &lt;a href="https://cryptoeng.de"&gt;CryptoEng&lt;/a&gt;, we extend our &lt;a href="https://github.com/celabshq/libcrux"&gt;libcrux&lt;/a&gt; cryptographic
library with support for resource constrained IoT devices.
Read &lt;a href="https://cryptoeng.de/blog/posts/iot-pqc-announce/"&gt;their announcement here&lt;/a&gt;.
The libcrux-iot library contains high performance, high assurance implementations of post-quantum, as well as classical, cryptographic primitives.&lt;/p&gt;
&lt;p&gt;&lt;a href="mailto:info@cryspen.com"&gt;Reach out&lt;/a&gt; if you are interested in licensing the libcrux-iot library to secure your connections with high-performance, high-assurance post-quantum cryptography.&lt;/p&gt;</description></item><item><title>Cryspen @ FMCP 2024</title><link>https://cryspen.com/post/fmcp/</link><pubDate>Sun, 28 Jul 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/fmcp/</guid><description>&lt;p&gt;The &lt;a href="https://www.nist.gov"&gt;US National Institute of Standards and
Technology&lt;/a&gt; (NIST) publishes a number of
important cryptographic standards (including upcoming ones for
post-quantum cryptography), and runs the &lt;a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program"&gt;cryptographic algorithm and
module validation
programs&lt;/a&gt;
that validate and issue certificates to cryptographic libraries.&lt;/p&gt;
&lt;p&gt;Last week, at the National CyberSecurity Center of Excellence in
Maryland, NIST hosted a workshop on &lt;a href="https://www.nist.gov/news-events/events/2024/07/nist-workshop-formal-methods-within-certification-programs-fmcp-2024"&gt;Formal Methods within
Certification
Programs&lt;/a&gt;.
The idea behind the workshop was to bring together formal methods
researchers and practitioners (like ourselves) with various
certification labs and the NIST validation teams, with the goal of
investigating how formal methods could be used to improve certification
processes.&lt;/p&gt;</description></item><item><title>Unlocking New Possibilities</title><link>https://cryspen.com/post/hax-sandbox/</link><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/hax-sandbox/</guid><description>&lt;p&gt;We have been developing the &lt;a href="https://hax.cryspen.com"&gt;hax toolchain&lt;/a&gt; over the last two years, in collaboration with research teams at &lt;a href="https://team.inria.fr/prosecco/"&gt;Inria&lt;/a&gt; and the &lt;a href="https://users-cs.au.dk/spitters/"&gt;University of Aarhus&lt;/a&gt;.
To showcase its capabilities we have successfully applied it to &lt;a href="https://cryspen.com/post/ml-kem-verification/"&gt;ML-KEM&lt;/a&gt; and &lt;a href="https://cryspen.com/post/hax-pv/"&gt;Bertie&lt;/a&gt;.
Others are using it to create new &lt;a href="https://eprint.iacr.org/2023/185"&gt;ground-breaking research results&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Key benefits of using hax:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Uncover potential bugs and vulnerabilities early: Hax’s rigorous formal analysis can identify potential errors and security flaws before they reach production, saving you time and resources.&lt;/li&gt;
&lt;li&gt;Reduce development time and costs: By formally verifying your code, you can reduce the need for manual testing and reduce the risk of regressions.&lt;/li&gt;
&lt;li&gt;Gain a competitive edge: Demonstrate the high quality and reliability of your software to your customers and partners.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Today, we&amp;rsquo;re announcing a collaboration with &lt;a href="https://www.sandboxaq.com/"&gt;SandboxAQ&lt;/a&gt; to help them verify their software using hax.
We are excited to see what new applications we come up with together and how we can evolve hax to be directly usable by software engineers.
Read SandboxAQ&amp;rsquo;s post on the collaboration &lt;a href="https://cryptographycaffe.sandboxaq.com/posts/formal-verification-overview/"&gt;here&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Post-Quantum TLS in Bertie</title><link>https://cryspen.com/post/pq-bertie/</link><pubDate>Wed, 03 Jul 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pq-bertie/</guid><description>&lt;p&gt;The prospect of quantum computers breaking most public key encryption in use today has created the need for new schemes that can resist classical and potential quantum attackers alike. Some of these schemes, such as ML-KEM and ML-DSA, are currently in the &lt;a href="https://csrc.nist.gov/Projects/post-quantum-cryptography"&gt;final stages of standardizations by NIST&lt;/a&gt;. Before fully transitioning to post-quantum secure cryptography, an important first step many organizations are taking is protecting against &lt;a href="https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later"&gt;Harvest Now Decrypt Later (HNDL) attacks&lt;/a&gt;, where data is collected and stored today, and later decrypted once cryptanalysis improves.
Signal recently introduced &lt;a href="https://cryspen.com/post/pqxdh/"&gt;PQXDH&lt;/a&gt;, which protects against these attacks.
&lt;a href="https://blog.chromium.org/2023/08/protecting-chrome-traffic-with-hybrid.html"&gt;Google&amp;rsquo;s Chrome browser is using&lt;/a&gt; the &lt;a href="https://www.ietf.org/archive/id/draft-tls-westerbaan-xyber768d00-02.html"&gt;&lt;code&gt;X25519Kyber768Draft00&lt;/code&gt;&lt;/a&gt; hybrid KEM cipher suite in TLS, which combines a post-quantum secure KEM with the classical key exchange. Cloudflare, which is serving a big chunk of the internet, &lt;a href="https://blog.cloudflare.com/post-quantum-for-all"&gt;supports it as well&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Cryptographic protocol verification with hax</title><link>https://cryspen.com/post/hax-pv/</link><pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/hax-pv/</guid><description>&lt;p&gt;This blog post details an example of how to use our &lt;a href="https://hax.cryspen.com"&gt;hax toolchain &lt;/a&gt; for verifying the security of cryptographic protocol implementations written in Rust.&lt;/p&gt;
&lt;p&gt;When building high-assurance software, we use different verification techniques with different goals.&lt;/p&gt;
&lt;p&gt;One goal is to prove implementation &lt;em&gt;correctness&lt;/em&gt;.
In this case the code in question is proven to be free of panics, or that the optimizations that it uses preserve conformance to a higher-level mathematical specification.
hax is well-suited to doing this type of verification, by extracting a model of the code in F*.
A recent example of this approach is our &lt;a href="https://cryspen.com/post/ml-kem-implementation/"&gt;verified implementation of ML-KEM (Kyber)&lt;/a&gt;. You can read more details about the verification effort in &lt;a href="https://cryspen.com/post/ml-kem-verification/"&gt;a separate blog post&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Conference Talks</title><link>https://cryspen.com/post/rwc2024/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/rwc2024/</guid><description>&lt;p&gt;Cryspen attended a number of conference in April and March. Here is a list of all slides and videos.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;We will update links when more resources become available.&lt;/em&gt;&lt;/p&gt;
&lt;h3 id="rwc"&gt;RWC&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://rwc.iacr.org/2024/program.php"&gt;RWC 2024&lt;/a&gt; took place in Toronto, Canada 🇨🇦 on March 25–27, 2024. RWC 2024 was organized by the International Association for Cryptologic Research (IACR).&lt;/p&gt;
&lt;p&gt;We presented together with Rolfe from &lt;a href="https://signal.org"&gt;Signal&lt;/a&gt; on &amp;ldquo;An Analysis of Signal&amp;rsquo;s PQXDH&amp;rdquo;.&lt;/p&gt;
&lt;!-- **Abstract:** In this talk, we describe PQXDH, a new post-quantum key agreement protocol deployed by Signal, its formal analysis using the ProVerif and CryptoVerif protocol analysis tools, and how this analysis influenced version 2 of PQXDH. We focus on the lessons learned in this process and how formal verification can be a powerful tool in an industrial setting. The talk will be given jointly by Rolfe Schmidt and Karthikeyan Bhargavan. --&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://iacr.org/submit/files/slides/2024/rwc/rwc2024/86/slides.pdf"&gt;Slides&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=Zevny4ePKCk"&gt;Video&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="rwpqc"&gt;RWPQC&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://na.eventscloud.com/website/65452/rwpqc2024-presentations/"&gt;Real World PQC (RWPQC) Workshop&lt;/a&gt; took place on Sunday, March 24, 2024 in Toronto, Canada 🇨🇦, colocated with RWC 2024 and in cooperation with IACR.&lt;/p&gt;</description></item><item><title>Post-Quantum OpenMLS</title><link>https://cryspen.com/post/pq-openmls/</link><pubDate>Thu, 11 Apr 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pq-openmls/</guid><description>&lt;p&gt;OpenMLS now offers security against harvest-now-decrypt-later (HNDL) quantum adversaries.&lt;/p&gt;
&lt;p&gt;In &lt;a href="https://github.com/openmls/openmls/pull/1546"&gt;#1546&lt;/a&gt; we merged support for the &lt;a href="https://www.ietf.org/archive/id/draft-connolly-cfrg-xwing-kem-02.html"&gt;X-Wing KEM draft&lt;/a&gt;, which is an early draft for securely combining elliptic-curve-based Diffie-Hellman with ML-KEM. In particular, OpenMLS now supports the ciphersuite MLS_256_XWING_CHACHA20POLY1305_SHA256_Ed25519 with ciphersuite 0x004D. There is no IANA code-point for this ciphersuite yet, such that interoperability may not be guaranteed. We work with other implementers towards interoperability of this ciphersuite.&lt;/p&gt;
&lt;p&gt;The implementation uses Cryspen’s &lt;a href="https://cryspen.com/post/ml-kem-verification/"&gt;formally verified ML-KEM&lt;/a&gt; and x25519 implementations from &lt;a href="https://github.com/celabshq/libcrux/"&gt;libcrux&lt;/a&gt;. The implementations are not only formally verified for correctness, secret independence, and memory safety, but also amongst the fastest implementations. Users should not notice any significant performance differences when using this new ciphersuite.
The threat of HNDL attackers requires applications to switch to post-quantum secure mechanisms now, just like &lt;a href="https://signal.org/blog/pqxdh/"&gt;Signal&lt;/a&gt; and &lt;a href="https://security.apple.com/blog/imessage-pq3/"&gt;iMessage&lt;/a&gt; did already. OpenMLS offers a simple way to achieve security against HNDL attackers and is ready to use.&lt;/p&gt;</description></item><item><title>Post-Quantum Group Messaging</title><link>https://cryspen.com/post/pq-mls/</link><pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pq-mls/</guid><description>&lt;p&gt;With multiple post-quantum cryptographic algorithms (&lt;a href="https://csrc.nist.gov/pubs/fips/203/ipd"&gt;ML-KEM&lt;/a&gt;, &lt;a href="https://csrc.nist.gov/pubs/fips/204/ipd"&gt;ML-DSA&lt;/a&gt;) nearing standardization, enterprises, research groups, and standards bodies have started investigating what post-quantum secure protocols should look like and what properties they should satisfy.&lt;/p&gt;
&lt;p&gt;In this post, we discuss a few new post-quantum protocol designs being proposed for use in end-to-end encrypted messaging protocols like Signal and MLS.&lt;/p&gt;
&lt;h2 id="secure-two-party-messaging"&gt;Secure Two-Party Messaging&lt;/h2&gt;
&lt;p&gt;At Real World Crypto 2024, Rolfe Schmidt and I presented our work (&lt;a href="https://iacr.org/submit/files/slides/2024/rwc/rwc2024/86/slides.pdf"&gt;slides&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=Zevny4ePKCk&amp;amp;ab_channel=IACR"&gt;video&lt;/a&gt;, &lt;a href="https://cryspen.com/post/pqxdh/"&gt;blog post&lt;/a&gt;), a collaboration between Cryspen, Inria, and Signal, on analyzing the &lt;a href="https://signal.org/docs/specifications/pqxdh/"&gt;PQXDH protocol&lt;/a&gt; which is currently being deployed in the Signal app. In the same session, Apple presented its own &lt;a href="https://security.apple.com/blog/imessage-pq3/"&gt;PQ3 protocol&lt;/a&gt; which is being deployed in iMessage.&lt;/p&gt;</description></item><item><title>Verifying Libcrux's ML-KEM</title><link>https://cryspen.com/post/ml-kem-verification/</link><pubDate>Tue, 30 Jan 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/ml-kem-verification/</guid><description>&lt;p&gt;In a &lt;a href="../ml-kem-implementation/"&gt;recent blog post&lt;/a&gt;, we described Cryspen&amp;rsquo;s new Rust
implementation of ML-KEM in Rust, and talked about how our
high-assurance development methodology helped us find a &lt;a href="https://github.com/pq-crystals/kyber/commit/dda29cc63af721981ee2c831cf00822e69be3220"&gt;new timing
bug&lt;/a&gt;
in various other Kyber implementations.&lt;/p&gt;
&lt;p&gt;In this post, we will go into
some more detail on how we use the &lt;a href="https://github.com/hacspec/hax"&gt;hax verification toolchain&lt;/a&gt; to
formally prove that our code is panic free and functionally correct.&lt;/p&gt;
&lt;div class="blog-content fs-6 pb-3"&gt;
 &lt;details&gt;
 
 &lt;summary&gt;Background on High-Assurance Cryptography&lt;/summary&gt;
 &lt;p&gt; &lt;p&gt;Cryptographic libraries lie at the heart of the trusted computing base
of all networked applications and, consequently, programming bugs in
these libraries are always treated as security vulnerabilities,
sometimes with high-profile acronyms and news articles. In the past
decade, a number of companies and research groups have made a
concerted attempt to improve confidence in cryptographic libraries by
using techniques from formal verification. This research area, called
computer-aided cryptography or high-assurance cryptography, is
surveyed in &lt;a href="https://eprint.iacr.org/2019/1393"&gt;this paper&lt;/a&gt;
and even has a &lt;a href="https://hacs-workshop.org"&gt;dedicated workshop&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Verified ML-KEM (Kyber) in Rust</title><link>https://cryspen.com/post/ml-kem-implementation/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/ml-kem-implementation/</guid><description>&lt;p&gt;ML-KEM, previously known as &lt;a href="https://pq-crystals.org/kyber/"&gt;Kyber&lt;/a&gt;, is the first post-quantum secure key-encapsulation mechanism (KEM) to get standardised by NIST in &lt;a href="https://csrc.nist.gov/pubs/fips/203/ipd"&gt;FIPS 203&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Cryspen has built &lt;a href="https://github.com/celabshq/libcrux/tree/main/libcrux-kem"&gt;a new high assurance Rust implementation of ML-KEM&lt;/a&gt;, using our verification framework &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt; and &lt;a href="https://fstar-lang.org"&gt;F*&lt;/a&gt;. Our implementation is among the fastest portable implementations that we know of (see &lt;a href="#performance-comparison"&gt;Performance comparison&lt;/a&gt;), and helped uncover a &lt;a href="https://github.com/pq-crystals/kyber/commit/dda29cc63af721981ee2c831cf00822e69be3220"&gt;timing bug&lt;/a&gt; (also called &lt;a href="https://kyberslash.cr.yp.to/"&gt;KyberSlash&lt;/a&gt;) in various Kyber implementations that would allow an attacker to &lt;a href="https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/ldX0ThYJuBo/m/uIOqRF5BAwAJ"&gt;recover the private key&lt;/a&gt;.&lt;/p&gt;
&lt;div class="blog-content fs-6 pb-3"&gt;
 &lt;details&gt;
 
 &lt;summary&gt;Background on Post Quantum Cryptography&lt;/summary&gt;
 &lt;p&gt; &lt;p&gt;The rise of quantum computing poses a significant threat to current cryptographic systems and protocols.
In particular, encrypted network traffic may be subjected to store-now-decrypt-later attacks, where encrypted data is collected by the adversary now so that it can be decrypted later,
maybe in several years, when quantum computers become powerful enough to break the public key cryptographic schemes we currently use to establish encryption keys.&lt;/p&gt;</description></item><item><title>Welcome Jan &amp; Lucas</title><link>https://cryspen.com/post/welcome_jan_lucas/</link><pubDate>Mon, 08 Jan 2024 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_jan_lucas/</guid><description>&lt;p&gt;📢 Exciting News! Cryspen is thrilled to announce the addition of two exceptional minds to our team: &lt;a href="https://lucas.franceschino.fr/"&gt;Dr. Lucas Franceschino&lt;/a&gt; and &lt;a href="https://github.com/keks"&gt;Jan Winkelmann&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;🎓 Lucas, our new R&amp;amp;D Proof &amp;amp; Tool Engineer, brings a remarkable background in formal verification, dependently typed languages, and abstract interpretation techniques. His expertise in functional programming, evident in his work with languages like Haskell, PureScript, OCaml, Coq, Idris, and F*, is complemented by his proficiency in NixOS and Emacs. Notably, Lucas is the main author of &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt;, our groundbreaking tool for formally verifying Rust code.&lt;/p&gt;</description></item><item><title>An Analysis of Signal's PQXDH</title><link>https://cryspen.com/post/pqxdh/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/pqxdh/</guid><description>&lt;!-- _Karthikeyan Bhargavan ([Cryspen]), Charlie Jacomme ([Inria Paris](https://www.inria.fr/en/inria-paris-centre)), Franziskus Kiefer ([Cryspen]) and Rolfe Schmidt ([Signal](https://signal.org/))_ --&gt;
&lt;p&gt;Signal recently &lt;a href="https://signal.org/docs/specifications/pqxdh/"&gt;published&lt;/a&gt; a new, post-quantum secure, version of their &lt;a href="https://signal.org/docs/specifications/x3dh/"&gt;X3DH&lt;/a&gt; protocol called &lt;a href="https://signal.org/docs/specifications/pqxdh/"&gt;PQXDH&lt;/a&gt;. As with any new cryptographic protocol, it is important to precisely analyse its security properties, especially for something as important as Signal.&lt;/p&gt;
&lt;p&gt;In this blog post we give an overview of PQXDH and describe how we modeled its security using two formal verification tools (&lt;a href="https://bblanche.gitlabpages.inria.fr/proverif/"&gt;ProVerif&lt;/a&gt; and &lt;a href="https://bblanche.gitlabpages.inria.fr/CryptoVerif/"&gt;CryptoVerif&lt;/a&gt;). We detail some issues we found, and how we, a mix of Inria researchers, Cryspen researchers and Signal developers, worked together to improve the PQXDH specification.&lt;/p&gt;</description></item><item><title>Announcing Campus Cyber Circus Project</title><link>https://cryspen.com/post/cyber-campus-hax/</link><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/cyber-campus-hax/</guid><description>&lt;p&gt;🎉 We&amp;rsquo;re excited to announce that Cryspen &lt;a href="https://ptcc.fr/projets/circus-2/"&gt;partnered&lt;/a&gt; with &lt;a href="https://www.inria.fr/fr"&gt;Inria&lt;/a&gt; on a transfer project to build a new integrated development and verification environment (IDVE). The project is part of the transfer program at &lt;a href="https://campuscyber.fr/"&gt;Campus Cyber&lt;/a&gt;, which brings together France&amp;rsquo;s top cybersecurity experts.&lt;/p&gt;
&lt;p&gt;The goal of this project is to advocate the commercial use of automated reasoning in security critical solutions in software engineering processes. We plan to make the IDVE, based on &lt;a href="https://hax.cryspen.com"&gt;hax&lt;/a&gt;, usable by any developer, even if they don&amp;rsquo;t have formal verification knowledge. We will apply hax to &lt;a href="https://github.com/cryspen/bertie"&gt;Bertie&lt;/a&gt;, the first formally verified, high-performance, implementation of TLS 1.3. &lt;/p&gt;</description></item><item><title>Specifying Oblivious Pseudonymization</title><link>https://cryspen.com/post/scrambledb/</link><pubDate>Mon, 18 Sep 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/scrambledb/</guid><description>&lt;p&gt;In this blog post we announce an executable specification in the
&lt;code&gt;hacspec&lt;/code&gt; specification language for the &lt;code&gt;ScrambleDB&lt;/code&gt; pseudonymization
system, developed by Cryspen as part of the &lt;a href="https://www.forschung-it-sicherheit-kommunikationssysteme.de/projekte/atlas"&gt;BMBF ATLAS project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Find the specification at our &lt;a href="https://github.com/cryspen/atlas/"&gt;GitHub
repository&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;First, we will motivate the need for utility-preserving
pseudonymization. Then we will describe how &lt;code&gt;ScrambleDB&lt;/code&gt; addresses the
issues found with conventional pseudonymization approaches. We
conclude with a demo of our executable specification that takes you
through a full protocol flow running right here in your browser.&lt;/p&gt;</description></item><item><title>Internet Defense Prize 2023</title><link>https://cryspen.com/post/internet-defense-prize-2023/</link><pubDate>Mon, 14 Aug 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/internet-defense-prize-2023/</guid><description>&lt;p&gt;At the &lt;a href="https://www.usenix.org/conference/usenixsecurity23"&gt;32nd Usenix Security Symposium&lt;/a&gt; in Anaheim CA, a paper on the &lt;a href="https://cryspen.com/post/mls-introduction/"&gt;Messaging Layer Security Protocol&lt;/a&gt;, co-authored by our founders Jonathan Protzenko and Karthikeyan Bhargavan, was awarded both the Distinguished Paper Award and the prestigious &lt;a href="https://www.usenix.org/blog/usenix-announces-winners-2023-internet-defense-prize"&gt;Internet Defense Prize&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The paper, titled &lt;a href="https://eprint.iacr.org/2022/1732"&gt;“TreeSync: Authenticated Group Management for Messaging Layer Security”&lt;/a&gt;, is authored by Théophile Wallez, Jonathan, Benjamin Beurdouche, and Karthik. It presents a precise, executable, machine-checked formal specification of &lt;a href="https://www.rfc-editor.org/rfc/rfc9420.html"&gt;MLS&lt;/a&gt; that shows how MLS can be cleanly decomposed into three components: TreeSync, TreeKEM, and TreeDEM. It then presents a formal security definition for TreeSync and a security proof for this sub-protocol in the Dolev-Yao model.&lt;/p&gt;</description></item><item><title>Prairie and Atlas</title><link>https://cryspen.com/post/prarie-and-atlas/</link><pubDate>Wed, 09 Aug 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/prarie-and-atlas/</guid><description>&lt;p&gt;With the widespread adoption and deployment of machine learning across enterprises,
ever-increasing amounts of data are being collected, stored, communicated,
combined, and computed over by sophisticated algorithms.
In parallel, new governmental regulations and rising concerns about privacy are
giving impetus to new research on how to protect the confidentiality, integrity
and privacy of all this data.&lt;/p&gt;
&lt;p&gt;At Cryspen, we are engaged in multiple R&amp;amp;D projects around these topics.
We help design new encryption standards, such as &lt;a href="https://www.rfc-editor.org/rfc/rfc9180.html"&gt;HPKE&lt;/a&gt;, for protecting data at
rest; we implement high-assurance cryptographic libraries, such as &lt;a href="https://github.com/celabshq/libcrux"&gt;libcrux&lt;/a&gt;;
we design and implement new protocols, such as &lt;a href="https://www.rfc-editor.org/rfc/rfc9420.html"&gt;MLS&lt;/a&gt;, for communicating sensitive data between a large number of endpoints; and we investigate state-of-the-art constructions, such as multi-party computation, for privacy-preserving analysis over distributed data.&lt;/p&gt;</description></item><item><title>Three (thousand) may keep a secret</title><link>https://cryspen.com/post/mls-introduction/</link><pubDate>Mon, 31 Jul 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/mls-introduction/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“Three may keep a secret, if two of them are dead.”&lt;/em&gt; - Benjamin Franklin (1735)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;However skeptical we may be of our human ability to keep secrets, we still routinely participate in group conversations that we would like to keep away from prying eyes. We exchange confidential work emails through corporate mail servers, discuss project internals on private Slacks, and exchange deeply personal information with family and friends on WhatsApp groups. The loss of this private data to malicious outsiders can result in public embarrassment, financial loss, and for vulnerable persons like journalists or activists, even threats to life and liberty.&lt;/p&gt;</description></item><item><title>MLS - RFC 9420</title><link>https://cryspen.com/post/mls-rfc-announcement/</link><pubDate>Tue, 18 Jul 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/mls-rfc-announcement/</guid><description>&lt;p&gt;&lt;strong&gt;✨ We are thrilled to announce the release of the MLS specification as &lt;a href="https://datatracker.ietf.org/doc/html/rfc9420"&gt;RFC 9420&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://datatracker.ietf.org/doc/html/rfc9420"&gt;RFC 9420&lt;/a&gt; is a comprehensive description of the first standardised, efficient, asynchronous, key establishment protocol with forward secrecy and post-compromise security for groups in size ranging from two to thousands. While Cryspen didn&amp;rsquo;t exist back when the MLS working group was established, our co-founder Karthik played a pivotal role in designing MLS from the beginning by contributing to the original design of &lt;a href="https://inria.hal.science/hal-02425247/file/treekem+(1).pdf"&gt;TreeKEM&lt;/a&gt;, the basis of MLS today.&lt;/p&gt;</description></item><item><title>Welcome Jonas</title><link>https://cryspen.com/post/welcome_jonas/</link><pubDate>Mon, 10 Jul 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/welcome_jonas/</guid><description>&lt;p&gt;📢 Exciting News! 🚀 We are thrilled to welcome Dr. Jonas Schneider-Bensch, to the Cryspen family as our newest R&amp;amp;D Cryptography Engineer!&lt;/p&gt;
&lt;p&gt;🎓 Jonas brings a wealth of knowledge and expertise, with a special focus on privacy-preserving technologies. His groundbreaking research and dedication to advancing cryptographic techniques have earned him a prominent reputation in the field.&lt;/p&gt;
&lt;p&gt;📚 With a remarkable PhD thesis titled &amp;ldquo;New Approaches to Privacy Preserving Signatures,&amp;rdquo; Jonas has demonstrated his deep understanding and innovative thinking in safeguarding privacy in digital transactions. His work has set new benchmarks for ensuring confidentiality and authenticity in cryptographic protocols.&lt;/p&gt;</description></item><item><title>Cryspen @ RWC 2023</title><link>https://cryspen.com/post/rwc-2023/</link><pubDate>Mon, 12 Jun 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/rwc-2023/</guid><description>&lt;p&gt;At Real World Crypto 2023 in Tokyo, we gave a talk on the hacspec language, the hax tool, and the libcrux crypto library.&lt;/p&gt;
&lt;p&gt;Designing and implementing cryptographic software is a perilous
endeavor. Experts (like us) will tell you not to “roll your own
crypto” and instead rely on standard mechanisms and well-vetted
open-source implementations. Or else you take the risk of falling prey
to embarrassing attacks, with &lt;a href="https://en.wikipedia.org/wiki/Heartbleed"&gt;dedicated
logos&lt;/a&gt;,
&lt;a href="https://en.wikipedia.org/wiki/FREAK"&gt;backronyms&lt;/a&gt;, and &lt;a href="https://breakingthe3ma.app/"&gt;long-lived
websites&lt;/a&gt; listing your design flaws and
coding bugs. Of course, &lt;a href="https://mitls.org/pages/attacks"&gt;published
standards&lt;/a&gt; and &lt;a href="https://www.openssl.org/news/vulnerabilities.html"&gt;popular crypto
libraries&lt;/a&gt; are not
infallible, but the argument goes that at least you share their
vulnerabilities and subsequent patches with a larger community of
users.&lt;/p&gt;</description></item><item><title>About us</title><link>https://cryspen.com/about/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/about/</guid><description>&lt;p&gt;Cryspen was founded in December 2021 by &lt;a href="https://bhargavan.info/"&gt;Karthik Bhargavan&lt;/a&gt;, &lt;a href="https://franziskuskiefer.de"&gt;Franziskus Kiefer&lt;/a&gt;, and &lt;a href="https://jonathan.protzenko.fr/"&gt;Jonathan Protzenko&lt;/a&gt;, with the goal of adapting and extending cutting-edge formal verification tools developed at research labs like &lt;a href="https://www.inria.fr/"&gt;Inria&lt;/a&gt; and applying them to commercial software development.&lt;/p&gt;
&lt;p&gt;In June 2026, Cryspen spun off &lt;a href="https://celabs.eu"&gt;CE Labs&lt;/a&gt; under the leadership of Franziskus to continue our work on Cryptographic Engineering. Cryspen itself pivoted to focus on developing formal verification tools for real-world security-critical software, funded by a new &lt;a href="https://eic.ec.europa.eu/eic-funding-opportunities/eic-transition_en"&gt;EIC Transition&lt;/a&gt; project called &lt;a href="https://cryspen.com/spectrum/"&gt;Spectrum&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Diversity, Equity, and Inclusion</title><link>https://cryspen.com/company/dei/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/company/dei/</guid><description>&lt;p&gt;Cryspen is committed to creating a diverse, equitable, and inclusive workplace
where all employees feel valued, respected, and empowered.
This policy outlines our commitment to fostering a positive and productive work
environment that celebrates differences and promotes equal opportunities for all.&lt;/p&gt;
&lt;h2 id="principles"&gt;Principles&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Diversity: We value and embrace the diverse backgrounds, experiences,
perspectives, and identities of our employees.&lt;/li&gt;
&lt;li&gt;Equity: We strive to ensure fair treatment and equal opportunities for all
employees, regardless of their background or characteristics.&lt;/li&gt;
&lt;li&gt;Inclusion: We create a welcoming and inclusive environment where everyone feels
valued, respected, and able to contribute their best.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="commitment"&gt;Commitment&lt;/h2&gt;
&lt;p&gt;Cryspen is committed to:&lt;/p&gt;</description></item><item><title>Impressum</title><link>https://cryspen.com/imprint/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/imprint/</guid><description>&lt;p&gt;Company Name: Cryspen Sarl&lt;/p&gt;
&lt;p&gt;Registered Office: 149 Avenue du Maine, 75014 Paris, France&lt;/p&gt;
&lt;p&gt;Email: &lt;a href="info@cryspen.com"&gt;info@cryspen.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Managing Director: Franziskus Kiefer&lt;/p&gt;
&lt;p&gt;Registration Number: &lt;a href="https://annuaire-entreprises.data.gouv.fr/entreprise/cryspen-908684848"&gt;908 684 848 R.C.S. Paris&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Social capital: &lt;a href="https://annuaire-entreprises.data.gouv.fr/entreprise/cryspen-908684848"&gt;€1500&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;VAT Number: &lt;a href="https://annuaire-entreprises.data.gouv.fr/entreprise/cryspen-908684848"&gt;FR21908684848&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Hosting: &lt;a href="https://pages.github.com/"&gt;Github&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="image-credits"&gt;Image Credits&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.freepik.com/free-vector/maintenance-concept-illustration_5421740.htm#query=illustrations%20engineering&amp;amp;position=7&amp;amp;from_view=search&amp;amp;track=ais"&gt;Hero based on Image by storyset on Freepik&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.freepik.com/free-vector/ecology-concept-enviroment_6930130.htm#query=tree%20cyber&amp;amp;position=4&amp;amp;from_view=search&amp;amp;track=locales"&gt;MLS tree image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.freepik.com/free-vector/abstract-vector-colorful-mesh-dark-background-futuristic-style-card-elegant-background-business-presentations-corrupted-point-sphere-chaos-aesthetics_22421018.htm#query=ai&amp;amp;position=1&amp;amp;from_view=search&amp;amp;track=sph"&gt;abstract vector colorful mesh image by GarryKillian on Freepik&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.freepik.com/free-vector/ring-glowing-points-black_6538788.htm#query=illustrations%20quantum%20bits&amp;amp;position=1&amp;amp;from_view=search&amp;amp;track=ais"&gt;vector ring of glowing points image by GarryKillian on Freepik&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Jobs</title><link>https://cryspen.com/jobs/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://cryspen.com/jobs/</guid><description>&lt;div id="join-widget"&gt;
 &lt;script
 defer
 type="text/javascript"
 data-mount-in="#join-widget"
 src="https://join.com/api/widget/bundle/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXR0aW5ncyI6eyJzaG93Q2F0ZWdvcnlGaWx0ZXIiOnRydWUsInNob3dMb2NhdGlvbkZpbHRlciI6dHJ1ZSwic2hvd0VtcGxveW1lbnRUeXBlRmlsdGVyIjp0cnVlLCJsYW5ndWFnZSI6ImVuIiwiam9ic1BlclBhZ2UiOjI1fSwiam9icyI6e30sImRlc2lnbiI6eyJzaG93TG9nbyI6dHJ1ZSwic2hvd0xvY2F0aW9uIjp0cnVlLCJzaG93RW1wbG95bWVudFR5cGUiOnRydWUsInNob3dDYXRlZ29yeSI6dHJ1ZSwiY29sb3JzIjp7IndpZGdldCI6eyJiYWNrZ3JvdW5kIjoiI0ZGRkZGRiIsImZpbHRlckJvcmRlciI6IiNENEQ0RDgiLCJwYWdpbmF0aW9uIjoiIzk5MDAwMCJ9LCJqb2JDYXJkIjp7InNoYWRvdyI6IiNGRkRCREIiLCJiYWNrZ3JvdW5kIjoiI0ZGRkZGRiIsInByaW1hcnlUZXh0IjoiIzNGM0Y0NiIsInNlY29uZGFyeVRleHQiOiIjNTI1MjVCIn19fSwidmVyc2lvbiI6MiwiY29tcGFueVB1YmxpY0lkIjoiNzUyMjA2YjVmYmM2ZmI5ZjA2YmM3NDEzM2JhMjdmYzciLCJpYXQiOjE2NzYxOTc0NTYsImp0aSI6ImVjZDJjYzA0LWEzYWUtNGI2ZC04ZWNlLTRiOTRjODhkYzlmOSJ9.x-Zdbbs8_ht6hYNS3DQs6UcLlN2mVps_eFaPGJU4vwU"
 &gt;&lt;/script&gt;
 &lt;/div&gt;</description></item><item><title>HACL Packages v0.6</title><link>https://cryspen.com/post/hacl-0_6/</link><pubDate>Mon, 07 Nov 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/hacl-0_6/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Today, we announce the first release of the HACL Packages libraries. 🎉&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This release of HACL packages includes the first release of the &lt;a href="https://github.com/cryspen/hacl-packages/releases/tag/c-v0.6.0"&gt;HACL C library&lt;/a&gt;
and a new release of the &lt;a href="https://opam.ocaml.org/packages/hacl-star/"&gt;hacl-star OCaml&lt;/a&gt; bindings.&lt;/p&gt;
&lt;p&gt;Together with this first release of the C library, we publish a first, work in
progress, version of the &lt;a href="https://tech.cryspen.com/hacl-packages/c/main/index.html"&gt;documentation&lt;/a&gt; for the library.
The &lt;a href="https://tech.cryspen.com/hacl-packages/"&gt;HACL Packages documentation&lt;/a&gt; is the main entry point for all information
about the HACL Packages.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Please &lt;a href="https://github.com/cryspen/hacl-packages/issues/new"&gt;file an issue&lt;/a&gt; or &lt;a href="https://github.com/cryspen/hacl-packages/discussions/new"&gt;open a discussion&lt;/a&gt; if you have trouble with anything in this tutorial.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>OpenMLS</title><link>https://cryspen.com/post/hello-openmls/</link><pubDate>Wed, 19 Oct 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/hello-openmls/</guid><description>&lt;p&gt;We have joined forces with our friends from &lt;a href="https://phnx.im/"&gt;Phoenix R&amp;amp;D&lt;/a&gt; to improve OpenMLS.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://messaginglayersecurity.rocks/mls-protocol/draft-ietf-mls-protocol.html"&gt;MLS protocol&lt;/a&gt; draft is in the IETF working group&amp;rsquo;s &lt;a href="https://mailarchive.ietf.org/arch/msg/mls/bOhxmpo70T-ikDd40OqQfst64gE/"&gt;last call&lt;/a&gt; and is thus
on track to become an RFC soon.
We want to make sure that OpenMLS is ready for wider adoption by the time the
RFC is ready.
To achieve this we start by catching up with all the changes to the protocol
(up to the current draft-16), improving test coverage of the code, and working
towards a more comprehensive test framework for interoperability.&lt;/p&gt;</description></item><item><title>HACL Packages</title><link>https://cryspen.com/post/introducing-hacl-packages/</link><pubDate>Tue, 07 Jun 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/introducing-hacl-packages/</guid><description>&lt;p&gt;Earlier this year, &lt;a href="https://tezos.foundation/"&gt;Tezos&lt;/a&gt; and &lt;a href="https://www.nomadic-labs.com/"&gt;Nomadic Labs&lt;/a&gt; started to work with Cryspen to
improve &lt;a href="https://hacl-star.github.io/"&gt;HACL*&lt;/a&gt; and ensure that it is a viable long-term solution for Tezos'
cryptographic needs.
HACL is a set of high assurance cryptographic primitives used by Tezos for most
of its cryptography.&lt;/p&gt;
&lt;p&gt;The original &lt;a href="https://hacl-star.github.io/"&gt;HACL*&lt;/a&gt; has been developed as part of &lt;a href="https://project-everest.github.io/"&gt;Project Everest&lt;/a&gt; and is a
collection of high-assurance cryptographic algorithms.
Its source is written in &lt;a href="https://www.fstar-lang.org/"&gt;F*&lt;/a&gt;, which is used to generate C code.
It also contains verified assembly code from the &lt;a href="https://hacl-star.github.io/HaclValeEverCrypt.html"&gt;Vale&lt;/a&gt; project and an agile
multiplexed cryptographic provider called &lt;a href="https://www.microsoft.com/en-us/research/publication/evercrypt-a-fast-veri%EF%AC%81ed-cross-platform-cryptographic-provider/"&gt;EverCrypt&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>What is High Assurance Cryptography?</title><link>https://cryspen.com/post/high-assurance-cryptography-1/</link><pubDate>Mon, 02 May 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/high-assurance-cryptography-1/</guid><description>&lt;p&gt;&lt;a href="https://www.cryspen.com"&gt;Cryspen&lt;/a&gt; builds high assurance cryptography.
But what does this actually mean?&lt;/p&gt;
&lt;p&gt;Before focusing on cryptography it is interesting to look at high assurance
software in general.
How is high assurance software different from other software?&lt;/p&gt;
&lt;p&gt;High assurance software is usually seen as being more trustworthy than other
software.
This is especially interesting in high-risk/high-stakes environments such as
financial institutions or governments.
There are different ways to achieve better guarantees for software.
Today the most commonly used technique to increase trust into software is using
certifications like &lt;a href="https://en.wikipedia.org/wiki/Common_Criteria"&gt;common criteria&lt;/a&gt;
or &lt;a href="https://en.wikipedia.org/wiki/FIPS_140-2"&gt;FIPS&lt;/a&gt;.
While these certifications offer a certain level of additional guarantees, only
the highest levels require some form of formal verification of the production
source code.
As such certification usually reaches only up to a certain level of high assurance.&lt;/p&gt;</description></item><item><title>An Executable HPKE Specification</title><link>https://cryspen.com/post/hpke_spec/</link><pubDate>Thu, 24 Feb 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/hpke_spec/</guid><description>&lt;p&gt;&lt;a href="https://datatracker.ietf.org/doc/draft-irtf-cfrg-hpke/"&gt;HPKE&lt;/a&gt;, published as &lt;a href="https://datatracker.ietf.org/doc/draft-irtf-cfrg-hpke/"&gt;RFC 9180&lt;/a&gt;, describes a scheme for hybrid public key encryption.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;📚 Read our &lt;a href="https://cryspen.com/post/tldr-hpke/"&gt;TL;DR on HPKE&lt;/a&gt; if you need more background on HPKE.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In this post, I describe the first executable HPKE specification using &lt;a href="https://hacspec.org"&gt;hacspec&lt;/a&gt;. It is not only an executable specification of &lt;a href="https://datatracker.ietf.org/doc/draft-irtf-cfrg-hpke/"&gt;HPKE&lt;/a&gt;, it is also an annotated version
of the RFC that can be read instead of (or in addition to) the RFC.
While the &lt;a href="https://cryspen.com/post/tldr-hpke/"&gt;TL;DR on HPKE&lt;/a&gt; was intended for consumers or potential users of HPKE,
this blog post is aimed at implementators that want to implement HPKE or understand
it better.&lt;/p&gt;</description></item><item><title>TL;DR - Hybrid Public Key Encryption</title><link>https://cryspen.com/post/tldr-hpke/</link><pubDate>Thu, 24 Feb 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/tldr-hpke/</guid><description>&lt;p&gt;&lt;a href="https://datatracker.ietf.org/doc/draft-irtf-cfrg-hpke/"&gt;HPKE&lt;/a&gt;, defined in &lt;a href="https://www.rfc-editor.org/rfc/rfc9180.html"&gt;RFC 9180&lt;/a&gt;, is a &lt;a href="https://datatracker.ietf.org/rg/cfrg/about/"&gt;CFRG&lt;/a&gt; standard that describes a scheme for hybrid public key encryption.
It is co-authored by my &lt;a href="https://www.cryspen.com"&gt;Cryspen&lt;/a&gt; co-founder &lt;a href="https://bhargavan.info/index.html"&gt;Karthikeyan Bhargavan&lt;/a&gt; and one of
his PhD students &lt;a href="https://www.benjaminlipp.de"&gt;Benjamin Lipp&lt;/a&gt; as part of his research at &lt;a href="https://team.inria.fr/prosecco"&gt;Inria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This blog post will give a brief overview of the specification and describes some use cases.&lt;/p&gt;
&lt;p&gt;If you want to learn more about the security proofs behind HPKE and the RFC process,
Benjamin wrote an &lt;a href="https://www.benjaminlipp.de/p/hpke-cryptographic-standard/"&gt;excellent blog post&lt;/a&gt; about it.&lt;/p&gt;</description></item><item><title>Cryspen ERC PoC Grant</title><link>https://cryspen.com/post/erc-poc/</link><pubDate>Thu, 10 Feb 2022 00:00:00 +0000</pubDate><guid>https://cryspen.com/post/erc-poc/</guid><description>&lt;p&gt;Cryspen co-founder &lt;a href="https://bhargavan.info/"&gt;Karthik Bhargavan&lt;/a&gt; got awarded an &lt;a href="https://erc.europa.eu/funding/proof-concept"&gt;ERC Proof of Concept grant&lt;/a&gt; for
commercialising the know-how and landmark research results from his Inria
research group &lt;a href="https://team.inria.fr/prosecco/"&gt;PROSECCO&lt;/a&gt; through Cryspen.&lt;/p&gt;
&lt;h2 id="announcement"&gt;Announcement&lt;/h2&gt;
&lt;p&gt;Cryptographic mechanisms are crucial to the security of our digital lives but their design and implementation remains notoriously difficult and error-prone. With the help of two ERC Grants, Karthikeyan Bhargavan and the Prosecco team at Inria have developed state-of-the-art formal verification techniques that can be applied to real-world cryptographic software. In particular, they used these techniques to help design and analyze the TLS 1.3 protocol standard, as well to build the HACL* verified cryptographic library, code from which has been incorporated in mainstream software projects including Mozilla Firefox, the Linux Kernel, the Tezos Blockchain, the WireGuard VPN, and the ElectionGuard voting system.&lt;/p&gt;</description></item></channel></rss>