The 2nd Workshop on
Generic Attacks and Proofs in Symmetric Cryptography
September 21-24, 2026
Vienna, Austria
About the Workshop

Over the past decades, the field of provable security for symmetric cryptographic primitives has evolved significantly. Since the seminal works of Goldreich-Goldwasser-Micali, Luby-Rackoff, and Bellare-Rogaway, we have made tremendous progress on multiple fronts: new primitives and security notions capturing the evolving landscape of real-world protocols, sophisticated proof techniques, and tighter security bounds.

Through the GAPS workshop, we aim to bring together leading experts and early-career researchers to reflect on these developments, revisit long-standing open questions, and identify new avenues for future research. This year's event marks a legacy spanning three decades of Practice-Oriented Provable Security, which has been fundamental in bridging the gap between theoretical cryptography and real-world deployment.

The workshop will follow a Dagstuhl- and ASK-style format, with invited talks in the morning sessions, and group discussions in the afternoon sessions focusing on the following high-level topics:

  1. Fine-tuning security bounds by bridging the gap between proofs and attacks.
  2. Exploring general proof techniques and foundational issues.
  3. Formulating new notions to capture novel threats to real-world applications of symmetric cryptography.
  4. Security against (post-)quantum adversaries.
  5. SK cryptography under new proof-driven security notions specific to ZKP, MPC, Tor, PQ settings.
  6. Provably secure and efficient modes for Arithmetization-Oriented applications.
  7. Security in the presence of leakage and fault.
  8. Automated tools for security proof verification.
Confirmed Speakers
  • Mihir Bellare (UC San Diego)
  • Phillip Rogaway (Formerly UC Davis)
  • Kazuhiko Minematsu (NEC Corporation)
  • Ashwin Jha (University of Wuppertal)
  • Bart Mennink (Maastricht University)
  • Christian Majenz (Technical University of Denmark)
  • Julia Len (UNC Chapel Hill)
  • Jean Paul Degabriele (Technology Innovation Institute)
  • Hrithik Nandi (Institute for Advancing Intelligence TCG CREST)
  • Stefano Trevisani (TU Wien)
Participants (TBD)
Venue and Travel

The GAPS 2026 workshop will be held at TU Wien, in Vienna, Austria.

The invited talks and discussions will be held at the Campus Favoritenstraße of TU Wien Informatics.

How to reach the venue?

The main building of TU Wien is located in Karlsplatz, in the hearth of Vienna. Campus Favoritenstraße is just a few hundred meters south, and less than a kilometer away from the Vienna central train station. Using the excellent Vienna's public transportation system, the fastest way to get there from the train station is either on foot or by taking the U1 metro line at the Südtiroler Platz stop, direction Leopoldau, and leaving at the Taubstummengasse stop. Vienna's main train station can in turn be easily reached in less than 30 minutes from Vienna's airport via the train line.
Tickets for local transportation (metro, trams, buses) can be bought from the WienMobil app, while train tickets can be bought from the ÖBB Tickets app.
Address:
Campus Favoritenstraße
TU Wien Informatics
1040 Vienna, Favoritenstraße 9-11

Visa

Citizens of EU member states, European Economic Area (EEA) and Switzerland do not need a visa for entering the Republic of Austria. Otherwise, please refer to the BMEIA website for detailed information.
If you need a visa and require an invitation letter for your application, please reach out to us with timely advance.

Accommodation

Hotel rooms and apartments in Vienna can be booked/rented via several travel agencies and rental service providers, such as Booking.com or Airbnb. Since underground lines are the fastest way to move around the city, we suggest participants to keep this into account when looking for apartments further away from the venue.

Program
Early Morning session
  • 09:00 - 09:15
    Welcome Words @ HHEG01 - FAV Hörsaal 3 Zemanek
  • 09:15 - 10:30
    Presentation and Discussion of Potential Group Topics @ HHEG01 - FAV Hörsaal 3 Zemanek
  • 10:30 - 11:00
    Coffee break @ HHEG07 - Foyer
Late Morning session
  • 11:00 - 11:40
    Discussion & Group Selection @ HHEG01 - FAV Hörsaal 3 Zemanek
  • 12:00 - 12:40
    Three Unwritten Papers in Symmetric Cryptography @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Phillip Rogaway
    People usually give talks about papers they've written. I thought it would be fun to turn that around and talk about papers that I didn't write. I'll reach into the distant recesses of memory to identify three problems in symmetric cryptography that I once thought would make for good papers, but that I never pursued. They failed to materialize not because I got stuck, but just because, you know, we don't do everything we think of doing. I won't tell you here what the three non-papers are about, because that would spoil the surprise.
  • 12:50 - 12:55
    Group Photograph @ HHEG07 - Foyer
  • 12:30 - 14:00
    Lunch @ HHEG07 - Foyer
Early Afternoon session
  • 14:00 - 15:30
    Group Discussion @ HHEG01 - FAV Hörsaal 3 Zemanek
  • 15:30 - 16:00
    Coffee break @ HHEG07 - Foyer
Late Afternoon session
  • 16:00 - 17:30
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
Early Morning session
  • 09:00 - 09:40
    Directions in Advanced Authenticated Encryption @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Kazuhiko Minematsu
    In this talk, I will briefly describe my involvement in two advanced forms of authenticated encryption (AE), especially leakage-resilient AE (LRAE) and committing AE (ComAE). Both classes have received great attention from the community. For LRAE, I will discuss two orthogonal approaches, i.e., everything is equally protected and "leveled" implementation, and show research progress on each of them. For ComAE, I will discuss an issue that arises when composing a black-box AE and a transform to make the transformed AE committing.
  • 09:50 - 10:30
    An alternative to the H-coefficient technique for post-quantum security proofs @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Christian Majenz
    The H-coefficient technique is as close as it gets to a universal tool for provable symmetric-key cryptography in idealized models. In this talk, I will first discuss what makes the H-coefficient technique so successful, and discuss why extending it to quantum adversaries seems hard. I will then present a different much more pedestrian approach: hybridizing across an adversary's queries to a keyed oracle (which remains classical/non-quantum in the post-quantum security setting). I will exemplify the technique using Even Mansour, the cipher we developed it for (together with Gorjan Alagic, Chen Bai, and Jonathan Katz). I will show a list of constructions the technique has been applied to, and describe prospects and obstacles to further applications.
  • 10:30 - 11:00
    Coffee break @ HHEG07 - Foyer
Late Morning session
  • 11:00 - 11:40
    The Next Generation @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Mihir Bellare
    The first part of this talk, which is on the technical side, will critique the current definition of authenticated encryption (AE1 or AEAD), with regard, not to novel or advanced goals, but (perhaps surprisingly) to providing the most basic message privacy. It will then discuss alternatives (AE2, AE3, AE5), ultimately suggesting as a conclusion that a really good definition is still lacking and an open question. The second part of the talk, which is more on the social side, will explore how AI might impact our community.
  • 11:40 - 12:30
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
  • 12:30 - 14:00
    Lunch @ HHEG07 - Foyer
Early Afternoon session
  • 14:00 - 15:30
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
  • 15:30 - 16:00
    Coffee break @ HHEG07 - Foyer
Late Afternoon session
  • 16:00 - 17:00
    Work in Groups (Midterm results) @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
Early Evening session
  • 17:30 - 18:30
    Social Event: Scenic Tram Ride @ Karlsplatz tram stop, front of Otto Wagner Pavilion
    Departure is at 17:30 sharp, if you plan to attend be there a bit earlier. See the attached document for more precise instructions.
Late Evening session
  • 18:30 - onwards
    Social Dinner @ Heuriger "Zum Martin Sepp", Cobenzlgasse 34, 1190 Wien
Early Morning session
  • 09:00 - 09:40
    This SuKS @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Bart Mennink
    The suffix keyed sponge (SuKS) is a variant of the keyed sponge that processes the key after the data instead of before the data. In 2019, Dobraunig and Mennink proved that this construction is a secure pseudorandom function and also achieves a certain level of leakage resilience. In this presentation, we take a fresh look at SuKS: we consider its advantages over the full-state keyed sponge, its disadvantages, and present a new generalization. We also discuss various applications of this generalized construction.
  • 09:50 - 10:30
    FLOE: Random-Access AEAD for Fast Lightweight Online Encryption @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Julia Len
    An ubiquitous problem in large-scale production environments is online encryption of large messages (e.g., databases, video streams, etc.), that is, encryption while using a small amount of memory. While straightforward when only (unauthenticated) encryption is required---say, by encrypting/decrypting in chunks, using a standard encryption scheme---this is more challenging in the presence of active attackers, who may drop or reorganize ciphertext segments arbitrarily. Moreover, many use cases additionally require both encryption and decryption to be random access, meaning that messages (resp., ciphertexts) can be encrypted (resp., decrypted) in any order. The purpose of this talk is to present the design of FLOE (Fast Lightweight Online Encryption), a new random-access online AEAD scheme. FLOE was designed in close collaboration with Snowflake, a leading cloud company, where it is slated to be deployed in production to protect sensitive user data. Requiring online encryption of large files, Snowflake encountered a number of real-world challenges with existing schemes, which motivated the design of a new construction.
  • 10:30 - 11:00
    Coffee break @ HHEG07 - Foyer
Late Morning session
  • 11:00 - 11:40
    Counter Galois Onion (CGO): Fast Non-Malleable Onion Encryption for Tor @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Jean Paul Degabriele
    In 2012 the Tor project expressed the need to upgrade Tor's onion encryption scheme to protect against tagging attacks and thereby strengthen its end-to-end integrity protection. In 2016 Nick Matthewson described a concrete onion encryption in Tor proposal 261, where each encryption layer is processed by a strongly secure, yet relatively expensive, tweakable wide-block cipher. Shortly after, Ashur, Dunkelman, and Luykx argued that replacing Tor's Counter-mode encryption with an tweakable wide-block cipher would be an overkill and replacing it instead with the RUP-secure AEAD scheme should suffice. Their intuition turned out to be fairly correct, however, translating said intuition into a secure onion encryption scheme for Tor is far from straightforward. In fact, several unsuccesful attempts followed at describing a concrete scheme for Tor in proposal 295. Currently, CGO (described in proposal 359) is the main candidate to become the new onion encryption scheme for Tor and it is already being integrated in Arti, Tor's next-generation implementation in Rust, with plans to be deployed in the near future. Proposal 359 does not describe the design rationale of Counter Galois Onion (CGO), but rather refers to our work instead (eprint 2025/583), where we identify the functionality and security desiderata for Tor's onion encryption, and propose CGO, an alternative onion encryption scheme that follows a minimalistic, modular design and includes several improvements over proposals 261 and 295. In this talk, we will explain the design rationale behind CGO and the challenges that need to be overcome for successful deployment in the real world. We will concentrate on the technical side, where we discuss how to turn a relatively simple underlying primitive (think wide blockcipher) into a fully-fledged onion encryption scheme, but we will also detail our interactions with Mathewson to ensure that CGO would actually solve the problems the Tor community cares most about. For instance, for Tor latency is key, requiring an efficient onion encryption scheme. In CGO's case, we use as underlying primitive an updatable tweakable split-domain cipher, which is an augmentation of the recently introduced rugged pseudorandom permutation (Degabriele and Karadzic, CRYPTO 2022) that allows for more efficient designs than the tweakable wide-block cipher suggested in proposal 261. We will also address the choices behind our concrete instantiation for the updatable tweakable split-domain cipher, called UIV+ and use it to benchmark our full CGO scheme against Tor's existing onion encryption scheme, demonstrating a clear performance gain at the proxy and at exit and entry routers, at the expense of a mild slowdown at intermediate routers. Both CGO and UIV+ are accompanied by formal security proofs that solidify the informal security claims. For this talk, we will concentrate on the informal, intuitive security that is provided by CGO.
  • 11:40 - 12:30
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
  • 12:30 - 14:00
    Lunch @ HHEG07 - Foyer
Early Afternoon session
  • 14:00 - 15:30
    Initial Group Presentations @ HEEG02 - FAV Hörsaal 1 Helmut Veith
  • 15:30 - 16:00
    Coffee break @ HHEG07 - Foyer
Late Afternoon session
  • 16:00 - 18:00
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
Early Morning session
  • 09:00 - 09:40
    Minimising the Minimised --- How Much Key Material Do Key-Alternating Ciphers Really Need? @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Ashwin Jha
    The Even-Mansour construction, and its generalisation to key-alternating ciphers, have long been studied as high-level provable security abstractions of the modern block cipher design philosophy. Starting from the seminal work of Even and Mansour, a substantial line of work has explored how far these constructions can be minimised along different dimensions, including the number of keys, the number of permutations, and the required independence assumptions. Following this line of work, we ask a complementary question: how large do the key spaces themselves need to be? We show that this question has deep connections with additive combinatorics, with different additive notions influencing different keying scenarios. These connections lead to substantially reduced key material while yielding near-optimal information-theoretic security bounds.
  • 09:50 - 10:30
    Generic Committing Attacks: Zero-Padded Ascon is Less Secure than Expected @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Hrithik Nandi
    In this talk, we study generic committing attacks against sponge-based authenticated encryption. We examine existing attack strategies for generic sponge constructions and study how various design features, including key blinding and zero-padding, affect their committing security. Finally, we present three new committing attacks that improve upon previously known attacks. In particular, one of our attacks provides a counterexample to the existing security analysis of Ascon-like schemes with zero-padding, showing that the claimed security does not hold for all parameter choices. For the case of 128-bit tags and 256-bit zero-padding, the previous analysis claims 192-bit committing security, whereas our attack reduces this to 130 bits.
  • 10:30 - 11:00
    Coffee break @ HHEG07 - Foyer
Late Morning session
  • 11:00 - 11:40
    Provably Secure and Efficient Arithmetization-Oriented Compression Functions @ HEEG02 - FAV Hörsaal 1 Helmut Veith
    Stefano Trevisani
    Modern ZK-SNARKs and ZK-STARKs, and many of their applications, require on cryptographic compression and hash functions. In this setting, efficiency is dictated by arithmetization requirements, where classical designs typically fall short. In this talk, we will explore the design of provably secure arithmetization-oriented compression functions, based on either block ciphers or cryptographic permutations, and compare their efficiency to existing constructions in the literature.
  • 11:40 - 12:30
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
  • 12:30 - 14:00
    Lunch @ HHEG07 - Foyer
Early Afternoon session
  • 14:00 - 16:00
    Work in Groups @ Seminarraum FAV EG A/B/C; FAV Hörsaal 2/3
  • 16:00 - 16:30
    Coffee break @ HHEG07 - Foyer
Late Afternoon session
  • 16:30 - 18:00
    Final Group Presentations and Closing Remarks @ HEEG02 - FAV Hörsaal 1 Helmut Veith
Contact
The workshop organizers can be contacted by email at gaps2vienna@gmail.com.

Elena Andreeva Security and Privacy Research Unit
Institute of Logic and Computation
TU Wien Informatics
Favoritenstraße 9-11
1040 Vienna, Austria

Stefan Lucks Computer Science and Media
Faculty of Media
Bauhaus-Universität Weimar
Bauhausstraße 11
99423 Weimar

Sponsors

The workshop is generously supported by our sponsors: