Dagstuhl Seminar 27441
Quantum Cryptanalysis
( Nov 01 – Nov 05, 2027 )
Permalink
Organizers
- Gorjan Alagic (University of Maryland - College Park, US)
- Martin Ekerå (KTH Royal Institute of Technology – Stockholm, SE and Swedish NCSA, Swedish Armed Forces – Stockholm, SE)
- Simona Etinski (TNO - Eindhoven, NL)
- Rainer Steinwandt (University of Alabama in Huntsville, US)
Contact
- Andreas Dolzmann (for scientific matters)
- Simone Schilke (for administrative matters)
The aim of this Dagstuhl Seminar is to stimulate and conduct cutting-edge quantum-cryptanalysis research on the security mechanisms that underpin our modern digital infrastructure. Emphasis will be placed on asymmetric cryptography with inherent structure making it susceptible to quantum attacks, and on cryptography which provides confidentiality, as it is susceptible to store-now-decrypt-later attacks.
The urgency of quantum-cryptanalysis research is underscored by recent rapid advances in quantum computing, and the associated ongoing standardization of and transition to asymmetric cryptography conjectured to be secure against quantum attacks, i.e., post-quantum cryptography. Timelines set, e.g., by the White House, by EU and US agencies, and by major industry players such as Google and Cloudflare, require the transition to be completed by 2029–2035. Quantum-cryptanalysis research crucially informs these timelines. It furthermore provides essential vetting of the cryptography that is believed to be post-quantum secure, and to which the world is currently transitioning.
Both the classical and quantum cryptanalysis of asymmetric schemes believed to be post-quantum secure are rapidly evolving, and this Dagstuhl Seminar will focus on asymmetric schemes that
(a) are, or have been, widely deployed (e.g., RSA, (EC-)DH and (EC-)DSA),
(b) are believed to be post-quantum secure, and are standardized (e.g., ML-KEM, ML-DSA), or
(c) are believed to be post-quantum secure, and are under consideration for standardization (e.g., FAEST).
This Dagstuhl Seminar has two thematic thrusts:
- Quantum-algorithmic innovations. This thrust focuses on new quantum-algorithmic techniques with cryptanalytic applications. For example, Shor’s seminal algorithms and the various derivatives thereof are all based on the idea of inducing a period in the quantum state and extracting it with the quantum Fourier transform. New techniques for implementing Shor-type algorithms in space- or depth-efficient ways have been proposed; any such ideas with quantum-cryptanalytic applications are within the scope of this thrust. This thrust also includes techniques aimed specifically at schemes that are conjectured to be post-quantum secure.
- Quantum resource estimation. This thrust focuses on logical and physical resource estimates for quantum attacks against schemes meeting one of the above criteria (a)–(c). Schemes of particular interest include those based on the discrete logarithm problem, some of which admit remarkably resource-efficient quantum attacks, and those based on lattice problems. Resource estimates for realistic quantum hardware or hybrid quantum-classical architectures are of key interest. This includes costing the quantum error correction, and tailoring circuits to a particular architecture, etc.
The seminar is intended to have presentations, but it will also use breakout working groups to conduct focused research on specific topics. The participants and topics for these groups will (largely) be determined by the seminar participants before the seminar takes place, as will the schedule.
Gorjan Alagic, Martin Ekerå, Simona Etinski, and Rainer Steinwandt
Related Seminars
- Dagstuhl Seminar 11381: Quantum Cryptanalysis (2011-09-18 - 2011-09-23) (Details)
- Dagstuhl Seminar 13371: Quantum Cryptanalysis (2013-09-08 - 2013-09-13) (Details)
- Dagstuhl Seminar 15371: Quantum Cryptanalysis (2015-09-06 - 2015-09-11) (Details)
- Dagstuhl Seminar 17401: Quantum Cryptanalysis (2017-10-01 - 2017-10-06) (Details)
- Dagstuhl Seminar 19421: Quantum Cryptanalysis (2019-10-13 - 2019-10-18) (Details)
- Dagstuhl Seminar 21421: Quantum Cryptanalysis (2021-10-17 - 2021-10-22) (Details)
- Dagstuhl Seminar 23421: Quantum Cryptanalysis (2023-10-15 - 2023-10-20) (Details)
- Dagstuhl Seminar 25431: Quantum Cryptanalysis (2025-10-19 - 2025-10-24) (Details)
Classification
- Cryptography and Security
- Data Structures and Algorithms
- Emerging Technologies
Keywords
- Cryptanalysis
- Quantum algorithms
- Quantum resource estimation
- Post-quantum cryptography
- Computational algebra

Creative Commons BY 4.0
