Dagstuhl Seminar 25431
Quantum Cryptanalysis
( Oct 19 – Oct 24, 2025 )
Permalink
Organizers
- Gorjan Alagic (University of Maryland - College Park, US)
- Simona Etinski (CWI - Amsterdam, NL)
- Stacey Jeffery (CWI - Amsterdam, NL)
- Rainer Steinwandt (University of Alabama in Huntsville, US)
Contact
- Marsha Kleinbauer (for scientific matters)
- Jutka Gasiorowski (for administrative matters)
Shared Documents
- Dagstuhl Materials Page (Use personal credentials as created in DOOR to log in)
Schedule
Motivation and technical scope
The past few years have been marked by rapid advances in quantum technologies, both from algorithmic and implementation perspectives, accompanied by a significant increase in resources devoted to the realization of fully capable quantum computers. In response to these developments, the cryptographic community has focused on designing cryptographic solutions that will remain secure and practical in the post-quantum era, once the full power of quantum computing is unleashed. A major milestone in this direction was the NIST post-quantum cryptography standardization effort, initiated in 2016 and concluded last year, which standardized several cryptographic schemes. Since the first edition – Dagstuhl Seminar “Quantum Cryptanalysis” (11381) in 2011 – in this series, we have closely followed this line of development by designing and analyzing mathematical tools to attack problems believed to be resistant to quantum attacks, intending to enable secure computation and communication in the era of large-scale quantum computers.
In this edition, the Dagstuhl Seminar “Quantum Cryptanalysis” (25431), we placed particular emphasis on several algorithms that have seen notable improvements in recent years and that offer promising directions for further progress. Among these, we analyzed Regev’s algorithm, as well as other closely related approaches. Going a step further, we also considered more exotic algorithms based on non-abelian group actions, which provide an additional promising research direction. Furthermore, we explored a more restrictive yet potentially impactful line of research within symmetric cryptography, focusing on approaches that rely on convolution-based attacks. Finally, to maintain a strong connection to practical feasibility, we examined implementation aspects by analyzing the computational and physical resources required to realize these algorithms.
One of the central goals of this seminar series was to bring together two research communities: the quantum computing community, primarily focused on the design of quantum algorithms, and the cryptographic community, which concentrates on the construction of cryptographic primitives and the analysis of their security. The aim was to bridge gaps in understanding quantum cryptanalysis from both perspectives and to establish a shared theoretical foundation that enables meaningful communication across communities. This objective was achieved through a series of shorter, ad hoc, and on-demand talks, which served as explanatory touchpoints for topics of particular interest to the participants.
Organization
To take full advantage of the unique opportunities offered by Schloss Dagstuhl, and in line with previous editions of the seminar, ample time was reserved for discussion and collaboration. A typical day, therefore, included only two to three presentations. Before the event, the organizers contacted participants to solicit potential topics and began forming working groups. Consequently, the first day of the seminar was largely devoted to establishing these working groups and defining their technical focus.
The working groups met regularly throughout the week to discuss their respective research topics and periodically reported their progress to the entire seminar. The participant-selected working group topics were:
- Quantum algorithms for codes and lattices based on Regev’s reduction,
- Quantum cryptanalysis of non-abelian group actions,
- Algorithms for syzygies and applications,
- Quantum algorithms for factoring and computing discrete logarithms, with a focus on Regev’s algorithm,
- Topics in convolution-based quantum symmetric cryptanalysis.
Following the Dagstuhl tradition and consistent with previous seminars in the “Quantum Cryptanalysis” series, no technical program was scheduled for Wednesday afternoon. This provided participants with an opportunity to explore the surrounding area or to devote additional time to collaborative research.
With 40 participants, Schloss Dagstuhl hosted a diverse group of leading experts from around the world. A substantial portion of the attendees were graduate students. These earlycareer researchers benefited from close interaction with established experts, contributing to cutting-edge research discussions while gaining valuable insights to support their professional development.
Gorjan Alagic, Simona Etinski, Stacey Jeffery, and Rainer Steinwandt
Located at the crossroad between quantum computing and cryptography, quantum cryptanalysis is the study of quantum attacks against cryptographic solutions. This is the eighth in a series of Dagstuhl Seminars on quantum cryptanalysis, focusing on algorithmic insights, as well as software tools, that support the quantum cryptanalyst. Given the relative stability of symmetric cryptosystems against quantum attacks, we plan to emphasize asymmetric cryptography in the 2025 edition of the seminar. (Note that it is not necessary to have attended previous editions to be able to fully be a part of the seminar.) We are especially interested in the quantum-resistance of asymmetric cryptographic solutions that are deployed, standardized, or considered for standardization. We welcome quantum cryptanalytic research on all established platforms, including isogenies and multivariate polynomials. However, given the emphasis of current standardization efforts, we expect the most impactful areas to be cryptanalysis of lattice-based and code-based designs as used in digital signature schemes and key encapsulation mechanisms. Accordingly, we currently anticipate two core themes for this Dagstuhl Seminar:
- Quantum-algorithmic innovations to attack various cryptographic building blocks, with an emphasis on lattice-based and code-based constructions; and
- Quantum resource estimation for attacks against deployed traditional and post-quantum cryptosystems.
In view of the fast-paced research in quantum cryptanalysis and to make effective use of the opportunities that Schloss Dagstuhl offers, we plan to determine the exact technical foci 2-3 months before the seminar based on feedback from the seminar participants, taking into account recent research developments. We plan for a small number of working groups that can spend a substantial part of the week on a specific problem domain within quantum cryptanalysis. The seminar schedule will also ensure regular exchange among the different working groups over the course of the week, and we plan to incorporate some introductory presentations that enable junior researchers to effectively collaborate with senior researchers in the working groups.
Currently anticipated focus areas include attacking lattice-based and code-based constructions, but participants may opt for alternate topics. A key goal is to maintain a strong seminar character, and not be confined to traditional presentations of completed results. As in prior editions, this seminar aims to bring together researchers from academia, government, and industry, including experts from quantum computing and experts in classical cryptography, as well as members of the new generation of native quantum cryptanalysts who are fluent in both disciplines.
Gorjan Alagic, Simona Etinski, Stacey Jeffery, and Rainer Steinwandt
Please log in to DOOR to see more details.
- Gorjan Alagic (University of Maryland - College Park, US) [dblp]
- Daniel C. Apon (Anduril Industries - Costa Mesa, US) [dblp]
- Kaveh Bashiri (BSI - Bonn, DE)
- Jean-François Biasse (University of South Florida - Tampa, US) [dblp]
- Xavier Bonnetain (LORIA & INRIA - Villers-lès-Nancy, FR) [dblp]
- Giacomo Borin (IBM Research Europe - Zürich, CH)
- Brennon Brimhall (Anduril Industries - Costa Mesa, US)
- André Chailloux (INRIA - Paris, FR) [dblp]
- Yanlin Chen (University of Maryland - College Park, US) [dblp]
- Thomas Debris-Alazard (Ecole Polytechnique - Palaiseau, FR & Inria Saclay - Palaiseau, FR) [dblp]
- Martin Ekerå (KTH Royal Institute of Technology - Stockholm, & Swedish NCSA, SE) [dblp]
- Lynn Engelberts (CWI - Amsterdam, NL)
- Thomas Espitau (PQShield - Paris, FR)
- Simona Etinski (CWI - Amsterdam, NL) [dblp]
- Joel Gärtner (KTH Royal Institute of Technology - Stockholm, SE) [dblp]
- Amin Shiraz Gilani (University of Maryland - College Park, US) [dblp]
- Sean Hallgren (Pennsylvania State University - University Park, US) [dblp]
- Kelsey Jackson (University of Maryland - College Park, US)
- Samuel E. Jaques (University of Waterloo, CA) [dblp]
- Stacey Jeffery (CWI - Amsterdam, NL) [dblp]
- Gregory Kahanamoku-Meyer (MIT - Cambridge, US) [dblp]
- Susanna Kirchhoff (Forschungszentrum Jülich, DE)
- Peter Kristel (Cyberagentur - Halle, DE)
- Johanna Loyer (INRIA Saclay - Palaiseau, FR) [dblp]
- Laura Maddison (University of Calgary, CA)
- Christian Majenz (Technical University of Denmark - Lyngby, DK) [dblp]
- Michele Mosca (University of Waterloo, CA) [dblp]
- Julian Nowakowski (Ruhr-Universität Bochum, DE)
- Alice Pellet-Mary (University of Bordeaux, FR) [dblp]
- Christophe Petit (UL - Brussels, BE) [dblp]
- Hugues Randriambololona (ANSSI - Paris, FR)
- Simona Samardjiska (Radboud University Nijmegen, NL) [dblp]
- André Schrottenloher (INRIA - Rennes, FR) [dblp]
- Yixin Shen (INRIA - Rennes, FR) [dblp]
- Manasi Shingane (University of Maryland - College Park, US) [dblp]
- Daniel C. Smith-Tone (NIST - Gaithersburg, US) [dblp]
- Jean-Pierre Tillich (INRIA - Paris, FR) [dblp]
- Wessel van Woerden (PQShield - Amsterdam, NL) [dblp]
- Alexandre Wallet (PQShield - Paris, FR)
- Bo-Yin Yang (Academia Sinica - Taipei, TW) [dblp]
Related Seminars
- Dagstuhl Seminar 11381: Quantum Cryptanalysis (2011-09-18 - 2011-09-23) (Details)
- Dagstuhl Seminar 13371: Quantum Cryptanalysis (2013-09-08 - 2013-09-13) (Details)
- Dagstuhl Seminar 15371: Quantum Cryptanalysis (2015-09-06 - 2015-09-11) (Details)
- Dagstuhl Seminar 17401: Quantum Cryptanalysis (2017-10-01 - 2017-10-06) (Details)
- Dagstuhl Seminar 19421: Quantum Cryptanalysis (2019-10-13 - 2019-10-18) (Details)
- Dagstuhl Seminar 21421: Quantum Cryptanalysis (2021-10-17 - 2021-10-22) (Details)
- Dagstuhl Seminar 23421: Quantum Cryptanalysis (2023-10-15 - 2023-10-20) (Details)
- Dagstuhl Seminar 27441: Quantum Cryptanalysis (2027-11-01 - 2027-11-05) (Details)
Classification
- Cryptography and Security
- Data Structures and Algorithms
Keywords
- cryptanalysis
- post-quantum cryptography
- quantum algorithms
- quantum resource estimation
- computational algebra

Creative Commons BY 4.0
