// Series

Research,
in sequence.

Follow connected investigations from first principles to implementation consequences—or search the complete archive by topic, format and evidence.

10public series
24articles in series
58published articles

// Read in order

Explore the series.

Each series gathers articles that develop one question across several layers: concept, mechanism, evidence and operational consequence.

// Complete archive

Find an article.

Combine filters to move across research, field notes and marginalia. Selecting a series restores its intended reading order.

127 bytes.

An IEEE 802.15.4 calculation begins with 127 octets. After framing and link security, only 81 may remain.

Random-looking is not unpredictable.

Statistical appearance cannot establish cryptographic unpredictability when generator state is small, duplicated or recoverable.

The other three questions.

Most cryptography education for children begins and ends with confidentiality. Integrity, authentication and credentials can be modelled with simple roles and objects, even as…

Cryptography can start before algebra.

Children can learn the questions cryptography answers before they can learn the mathematics behind its algorithms. Existing school materials teach secrecy well, but leave…

The payload must fit the channel.

A compact signed object needs one deterministic binary form and three explicit transport profiles. QR, NFC and Bluetooth LE fail in different ways when…

A selective proof is not automatically smaller.

When attributes require independent signatures, BBS can replace N signatures with one multi-message signature, but its selective-disclosure proof grows with every hidden message. The…

The signature is not the key.

A byte-level comparison of RSA, elliptic-curve, pairing-based and post-quantum signatures shows when recurring signature traffic overtakes key provisioning and storage.

Seven containers, ranked by what you can prove.

Mobile key containers form a degradation ladder ordered by what an issuer can prove, not only by resistance to attack. Below the policy cut…

The certificate has two lists.

Android key attestation records a key's security level and separates authorizations enforced by hardware from those enforced by software. A verifier must validate the…

What “hardware-backed” means on Android.

Android exposes software, TEE-backed and StrongBox-backed keys through one keystore API. The effective security level, mandated algorithm set and available attestation evidence vary by…

What survives the print, the scan and the phone.

Error correction can recover exact codewords from a damaged symbol. It cannot recover biometric detail removed before the credential was printed.

A face fits in 960 bytes.

A signed QR can carry an offline face credential, but signature, encoding and card geometry leave roughly one kilobyte for the image.

Six digits are not the authentication ceremony.

An OTP output is short and temporary. Its real security depends on seed custody, moving-factor state, verification policy, session binding and recovery.

The verifier and the parser disagree.

Signature verification fails as a security boundary when the verifier and the application resolve different meanings from the same document.

Signatures are over bytes, not meaning.

Two messages can express the same data and still produce different signatures. Verification begins with the exact bytes a protocol chooses to protect.

Audit the attributes, not the datasheet.

PKCS #11 key policy is expressed through attributes and mechanisms inside the token. An inventory can reveal permissions that a product datasheet cannot.

The handle is not the key.

PKCS #11 gives applications a common view of cryptographic devices. The key's policy, lifecycle and operational meaning still depend on what lies behind the…

Entropy arrives late.

Correct algorithms can still generate related keys when identical devices ask for randomness before their environments have diverged.

A random output can carry a proof.

A verifiable random function produces a unique, random-looking output and evidence anyone can check. It proves origin and uniqueness, not fairness in deciding which…

Removing a member creates a new epoch.

Messaging Layer Security makes membership part of shared cryptographic state. A removal takes effect when the remaining group commits and derives a new epoch.

The ciphertext does not say which mode produced it.

Format-preserving ciphertext carries no mode, key or tweak metadata. That convenience makes FF1 and FF3 migration difficult to scope from the data alone.

Preserving the format preserves the leakage.

Format-preserving encryption keeps ciphertext compatible with narrow legacy fields. It also keeps domain size, length, structure and often equality visible.

A compact handshake still has a transcript.

EDHOC compresses authenticated key exchange into three concise CBOR messages. Its efficiency still depends on exact transcript bytes, credential profiles and state transitions.

Two key exchanges still make one protocol.

A hybrid key exchange combines a traditional contribution with a post-quantum one. Its guarantee depends on the combiner, transcript, negotiation and every failure path…

Sign the same message twice.

Repeated signing reveals whether output varies. Across a population, repeated ECDSA values can expose nonce reuse, compromise and implementation anomalies.

Determinism is not a substitute for entropy.

Deterministic signing prevents catastrophic dependence on fresh random nonces. Hedged signatures add new randomness to reduce repeated traces and faults without trusting that randomness…

No intermediary should see the whole request.

Oblivious HTTP partitions network identity and request contents between a relay and a gateway. Padding, discovery, metadata and collusion still determine the privacy of…

Evidence is not a verdict.

Remote attestation authenticates evidence about a target environment. Endorsements, reference values and appraisal policy are what turn that evidence into a decision.

A key directory should be accountable.

Key transparency gives public-key distribution a consistent, auditable history. Its proofs expose silent substitution only when clients, monitors or witnesses compare committed views.

Authorization does not require identity.

Privacy Pass separates token issuance from token redemption. The token can prove prior authorization without carrying a stable client identity.

The server does not need the password.

OPAQUE lets a client and server establish a mutually authenticated key without disclosing the password to the server. Registration, recovery and server-key custody still…

The signature is ordinary. The ceremony is not.

FROST turns distributed authority into one ordinary Schnorr signature. The difficult security work remains in share generation, nonce state, participant coordination and recovery.

The statement must enter the hash.

A zero-knowledge proof can verify correctly while authorizing the wrong statement. Fiat-Shamir security begins with the exact public instance, transcript order and domain separation…

Selective disclosure is not unlinkability.

BBS signatures support selective disclosure and randomized derived proofs. Unlinkability still depends on disclosed values, proof context, revocation and the surrounding protocol.

Toward an open cryptographic workbench.

Cryptographic tools explain algorithms, transform data and visualise workflows. A protocol workbench could connect those strengths while keeping exact bytes visible.

A secure key cannot make a photographed QR fresh.

Hardware-backed signing can prove which mobile key produced an offline QR. It cannot, by itself, prove that the image was created for this verifier,…

The transcript is the protocol.

A secure session depends on more than fresh keys. The negotiation, participants and intended operation must be bound to the same cryptographic result.

A nonce is not a footnote.

A secure cipher can fail when nonce state does not survive writers, restarts and rollbacks. Uniqueness is a property of the operating system around…

The curve is only part of the choice.

P-256, secp256k1, Ed25519 and X25519 name different layers, purposes and ecosystems. Selecting a curve never selects the complete construction.

Putting the trust boundary beside the reader.

A SAM can keep master keys out of reader firmware and perform card protocols locally. The security result still depends on permissions, host integration…

A card migration is a state machine.

Moving a live fare system from MIFARE Classic to MIFARE Plus is not a card replacement exercise. It is a controlled transition across credentials,…

The SIM as a cryptographic computer.

Long before the secure element became a general platform, SIM and UICC applets provided a small governed environment for keys, authentication and digital signatures.

The token is the easy part.

A token can replace a sensitive value. The difficult work is defining what the replacement means, who may reverse it and how the system…

Keys without a secure boundary.

When cryptographic operations must run without an HSM, software can reduce the exposure of key material—but it cannot make a hostile host trustworthy.

When a QR code was not a format.

During the pandemic, visually similar QR codes carried incompatible data models, encodings and trust assumptions. A contribution from Uruguay to PathCheck’s Universal Verifier made…

No articles match this combination. Try removing one of the filters.