The 2nd Workshop on
Generic Attacks and Proofs in Symmetric Cryptography
September 21-24, 2026
Vienna, Austria
About the Workshop

Over the past decades, the field of provable security for symmetric cryptographic primitives has evolved significantly. Since the seminal works of Goldreich-Goldwasser-Micali, Luby-Rackoff, and Bellare-Rogaway, we have made tremendous progress on multiple fronts: new primitives and security notions capturing the evolving landscape of real-world protocols, sophisticated proof techniques, and tighter security bounds.

Through the GAPS workshop, we aim to bring together leading experts and early-career researchers to reflect on these developments, revisit long-standing open questions, and identify new avenues for future research. This year's event marks a legacy spanning three decades of Practice-Oriented Provable Security, which has been fundamental in bridging the gap between theoretical cryptography and real-world deployment.

The workshop will follow a Dagstuhl- and ASK-style format, with invited talks in the morning sessions, and group discussions in the afternoon sessions focusing on the following high-level topics:

  1. Fine-tuning security bounds by bridging the gap between proofs and attacks.
  2. Exploring general proof techniques and foundational issues.
  3. Formulating new notions to capture novel threats to real-world applications of symmetric cryptography.
  4. Security against (post-)quantum adversaries.
  5. SK cryptography under new proof-driven security notions specific to ZKP, MPC, Tor, PQ settings.
  6. Provably secure and efficient modes for Arithmetization-Oriented applications.
  7. Security in the presence of leakage and fault.
  8. Automated tools for security proof verification.
Confirmed Speakers
  • Mihir Bellare (UC San Diego)
  • Phillip Rogaway (Formerly UC Davis)
  • Kazuhiko Minematsu (NEC Corporation)
  • Ashwin Jha (University of Wuppertal)
  • Bart Mennink (Maastricht University)
  • Christian Majenz (Technical University of Denmark)
  • Julia Len (UNC Chapel Hill)
  • Jean Paul Degabriele (Technology Innovation Institute)
  • Hrithik Nandi (Institute for Advancing Intelligence TCG CREST)
Participants (TBD)
  • TBD
Venue and Travel

The GAPS 2026 workshop will be held at TU Wien, in Vienna, Austria.

The invited talks and discussions will be held at the Campus Favoritenstraße of TU Wien Informatics.

How to reach the venue?

The main building of TU Wien is located in Karlsplatz, in the hearth of Vienna. Campus Favoritenstraße is just a few hundred meters south, and less than a kilometer away from the Vienna central train station. Using the excellent Vienna's public transportation system, the fastest way to get there from the train station is either on foot or by taking the U1 metro line at the Südtiroler Platz stop, direction Leopoldau, and leaving at the Taubstummengasse stop. Vienna's main train station can in turn be easily reached in less than 30 minutes from Vienna's airport via the train line.
Tickets for local transportation (metro, trams, buses) can be bought from the WienMobil app, while train tickets can be bought from the ÖBB Tickets app.
Address:
Campus Favoritenstraße
TU Wien Informatics
1040 Vienna, Favoritenstraße 9-11

Visa

Citizens of EU member states, European Economic Area (EEA) and Switzerland do not need a visa for entering the Republic of Austria. Otherwise, please refer to the BMEIA website for detailed information.
If you need a visa and require an invitation letter for your application, please reach out to us with timely advance.

Accommodation

Hotel rooms and apartments in Vienna can be booked/rented via several travel agencies and rental service providers, such as Booking.com or Airbnb. Since underground lines are the fastest way to move around the city, we suggest participants to keep this into account when looking for apartments further away from the venue.

Program
Early Morning session
  • 09:00 - 09:15
    Welcome Words
  • 09:15 - 10:30
    Presentation and Discussion of Potential Group Topics
  • 10:30 - 11:00
    Coffee break @ Foyer HHEG07
Late Morning session
  • 11:00 - 11:40
    Discussion & Group Selection
  • 11:50 - 12:30
    Three Unwritten Papers in Symmetric Cryptography
    Phillip Rogaway (People usually give talks about papers they've written. I thought it would be fun to turn that around and talk about papers that I didn't write. I'll reach into the distant recesses of memory to identify three problems in symmetric cryptography that I once thought would make for good papers, but that I never pursued. They failed to materialize not because I got stuck, but just because, you know, we don't do everything we think of doing. I won't tell you here what the three non-papers are about, because that would spoil the surprise.)
  • 12:30 - 14:00
    Lunch @
Early Afternoon session
  • 14:00 - 15:30
    Group Discussion
  • 15:30 - 16:00
    Coffee break @ Foyer HHEG07
Late Afternoon session
  • 16:00 - 17:30
    Work in Groups
Early Morning session
  • 09:00 - 09:40
    Directions in Advanced Authenticated Encryption
    Kazuhiko Minematsu (In this talk, I will briefly describe my involvement in two advanced forms of authenticated encryption (AE), especially leakage-resilient AE (LRAE) and committing AE (ComAE). Both classes have received great attention from the community. For LRAE, I will discuss two orthogonal approaches, i.e., everything is equally protected and "leveled" implementation, and show research progress on each of them. For ComAE, I will discuss an issue that arises when composing a black-box AE and a transform to make the transformed AE committing.)
  • 09:50 - 10:30
    An alternative to the H-coefficient technique for post-quantum security proofs
    Christian Majenz (The H-coefficient technique is as close as it gets to a universal tool for provable symmetric-key cryptography in idealized models. In this talk, I will first discuss what makes the H-coefficient technique so successful, and discuss why extending it to quantum adversaries seems hard. I will then present a different much more pedestrian approach: hybridizing across an adversary's queries to a keyed oracle (which remains classical/non-quantum in the post-quantum security setting). I will exemplify the technique using Even Mansour, the cipher we developed it for (together with Gorjan Alagic, Chen Bai, and Jonathan Katz). I will show a list of constructions the technique has been applied to, and describe prospects and obstacles to further applications.)
  • 10:30 - 11:00
    Coffee break @ Foyer HHEG07
Late Morning session
  • 11:00 - 11:40
    The Next Generation
    Mihir Bellare (The first part of this talk, which is on the technical side, will critique the current definition of authenticated encryption (AE1 or AEAD), with regard, not to novel or advanced goals, but (perhaps surprisingly) to providing the most basic message privacy. It will then discuss alternatives (AE2, AE3, AE5), ultimately suggesting as a conclusion that a really good definition is still lacking and an open question. The second part of the talk, which is more on the social side, will explore how AI might impact our community.)
  • 11:40 - 12:30
    Work in Groups
  • 12:30 - 14:00
    Lunch @
Early Afternoon session
  • 14:00 - 15:30
    Work in Groups
  • 15:30 - 16:00
    Coffee break @ Foyer HHEG07
Late Afternoon session
  • 16:00 - 17:00
    Work in Groups (Midterm results)
Early Evening session
  • 17:30 - 18:30
    Social Event
Late Evening session
  • 18:30 - onwards
    Social Dinner
Early Morning session
  • 09:00 - 09:40
    Invited Talk
    Bart Mennink
  • 09:50 - 10:30
    FLOE: Random-Access AEAD for Fast Lightweight Online Encryption
    Julia Len (An ubiquitous problem in large-scale production environments is online encryption of large messages (e.g., databases, video streams, etc.), that is, encryption while using a small amount of memory. While straightforward when only (unauthenticated) encryption is required---say, by encrypting/decrypting in chunks, using a standard encryption scheme---this is more challenging in the presence of active attackers, who may drop or reorganize ciphertext segments arbitrarily. Moreover, many use cases additionally require both encryption and decryption to be random access, meaning that messages (resp., ciphertexts) can be encrypted (resp., decrypted) in any order. The purpose of this talk is to present the design of FLOE (Fast Lightweight Online Encryption), a new random-access online AEAD scheme. FLOE was designed in close collaboration with Snowflake, a leading cloud company, where it is slated to be deployed in production to protect sensitive user data. Requiring online encryption of large files, Snowflake encountered a number of real-world challenges with existing schemes, which motivated the design of a new construction.)
  • 10:30 - 11:00
    Coffee break @ Foyer HHEG07
Late Morning session
  • 11:00 - 11:40
    Invited Talk
    Jean Paul Degabriele
  • 11:40 - 12:30
    Work in Groups
  • 12:30 - 14:00
    Lunch @
Early Afternoon session
  • 14:00 - 15:30
    Initial Group Presentations
  • 15:30 - 16:00
    Coffee break @ Foyer HHEG07
Late Afternoon session
  • 16:00 - 18:00
    Work in Groups
Early Morning session
  • 09:00 - 09:40
    Minimising the Minimised --- How Much Key Material Do Key-Alternating Ciphers Really Need?
    Ashwin Jha (The Even-Mansour construction, and its generalisation to key-alternating ciphers, have long been studied as high-level provable security abstractions of the modern block cipher design philosophy. Starting from the seminal work of Even and Mansour, a substantial line of work has explored how far these constructions can be minimised along different dimensions, including the number of keys, the number of permutations, and the required independence assumptions. Following this line of work, we ask a complementary question: how large do the key spaces themselves need to be? We show that this question has deep connections with additive combinatorics, with different additive notions influencing different keying scenarios. These connections lead to substantially reduced key material while yielding near-optimal information-theoretic security bounds.)
  • 09:50 - 10:30
    Invited Talk
    Hrithik Nandi
  • 10:30 - 11:00
    Coffee break @ Foyer HHEG07
Late Morning session
  • 11:00 - 12:30
    Work in Groups
  • 12:30 - 14:00
    Lunch @
Early Afternoon session
  • 14:00 - 15:30
    Work in Groups
  • 15:30 - 16:00
    Coffee break @ Foyer HHEG07
Late Afternoon session
  • 16:00 - 18:00
    Final Group Presentations and Closing Remarks
Contact
The workshop organizers can be contacted by email at gapsworkshop@gmail.com.

Elena Andreeva Security and Privacy Research Unit
Institute of Logic and Computation
TU Wien Informatics
Favoritenstraße 9-11
1040 Vienna, Austria

Stefan Lucks Computer Science and Media
Faculty of Media
Bauhaus-Universität Weimar
Bauhausstraße 11
99423 Weimar

Sponsors

The workshop is generously supported by our sponsors: