// Series
Research,
in sequence.
Follow connected investigations from first principles to implementation consequences—or search the complete archive by topic, format and evidence.
// Read in order
Explore the series.
Each series gathers articles that develop one question across several layers: concept, mechanism, evidence and operational consequence.
Authentication Ceremonies
How authentication succeeds or fails across credentials, recovery paths and session creation.
- Part 1Six digits are not the authentication ceremony.
- Part 2SMS OTP is now a restricted authenticator. The hard part is what replaces it.
Biometrics in 2D Barcodes
What survives when biometric information is compressed, printed, scanned and recovered from two-dimensional symbols.
- Part 1A face fits in 960 bytes.
- Part 2What survives the print, the scan and the phone.
- Part 3Colour buys capacity in exchange for illumination.
Cryptography Education
How cryptographic properties can be taught before the underlying algebra, and where current educational materials leave gaps.
Open this seriesFormat-Preserving Encryption
What format-preserving encryption reveals, how its modes differ and why migration is hard to infer from ciphertext alone.
- Part 1Preserving the format preserves the leakage.
- Part 2The ciphertext does not say which mode produced it.
Key Containers on Mobile Devices
A verifiability-first guide to mobile key custody across software, TEE, StrongBox and Secure Enclave environments.
- Part 1What “hardware-backed” means on Android.
- Part 2The certificate has two lists.
- Part 3Seven containers, ranked by what you can prove.
Offline Visual Exchange
Protocol, optical and replay-control decisions for encrypted exchanges between fully offline mobile devices and disconnected verifiers.
- Part 1A one-way QR can establish a key, but not a conversation.
- Part 2Three hundred milliseconds is an operating envelope.
- Part 3A secure key cannot make a photographed QR fresh.
PKCS #11 Key Policy
How handles, attributes and mechanisms determine what a token-held key can actually do.
Open this seriesSignature Footprint Engineering
Key, signature and proof-size trade-offs for cryptographic systems operating across storage and constrained transports.
- Part 1The signature is not the key.
- Part 2A selective proof is not automatically smaller.
- Part 3The payload must fit the channel.
Signature Nonces
Why nonce generation determines signature safety and how repeated signing exposes implementation failures.
Open this seriesSigned Bytes and Parser Differentials
How signatures over bytes fail as a security boundary when verifiers and applications resolve different meanings.
Open this series// Complete archive
Find an article.
Combine filters to move across research, field notes and marginalia. Selecting a series restores its intended reading order.
A COSE_Sign1 object is not its signing input.
Four transmitted fields become a different CBOR structure before signature verification.
Verification is not authorization.
A valid signature answers a narrower question than most applications need to decide.
127 bytes.
An IEEE 802.15.4 calculation begins with 127 octets. After framing and link security, only 81 may remain.
Random-looking is not unpredictable.
Statistical appearance cannot establish cryptographic unpredictability when generator state is small, duplicated or recoverable.
The other three questions.
Most cryptography education for children begins and ends with confidentiality. Integrity, authentication and credentials can be modelled with simple roles and objects, even as…
Cryptography can start before algebra.
Children can learn the questions cryptography answers before they can learn the mathematics behind its algorithms. Existing school materials teach secrecy well, but leave…
The payload must fit the channel.
A compact signed object needs one deterministic binary form and three explicit transport profiles. QR, NFC and Bluetooth LE fail in different ways when…
A selective proof is not automatically smaller.
When attributes require independent signatures, BBS can replace N signatures with one multi-message signature, but its selective-disclosure proof grows with every hidden message. The…
The signature is not the key.
A byte-level comparison of RSA, elliptic-curve, pairing-based and post-quantum signatures shows when recurring signature traffic overtakes key provisioning and storage.
Seven containers, ranked by what you can prove.
Mobile key containers form a degradation ladder ordered by what an issuer can prove, not only by resistance to attack. Below the policy cut…
The certificate has two lists.
Android key attestation records a key's security level and separates authorizations enforced by hardware from those enforced by software. A verifier must validate the…
What “hardware-backed” means on Android.
Android exposes software, TEE-backed and StrongBox-backed keys through one keystore API. The effective security level, mandated algorithm set and available attestation evidence vary by…
Colour buys capacity in exchange for illumination.
Polychrome barcodes can multiply payload density, but they exchange binary contrast for dependence on inks, cameras and uncontrolled light.
What survives the print, the scan and the phone.
Error correction can recover exact codewords from a damaged symbol. It cannot recover biometric detail removed before the credential was printed.
A face fits in 960 bytes.
A signed QR can carry an offline face credential, but signature, encoding and card geometry leave roughly one kilobyte for the image.
SMS OTP is now a restricted authenticator. The hard part is what replaces it.
Leaving SMS removes the telephony channel, but phishing resistance depends on origin binding and on every recovery path that can create a session.
Six digits are not the authentication ceremony.
An OTP output is short and temporary. Its real security depends on seed custody, moving-factor state, verification policy, session binding and recovery.
The verifier and the parser disagree.
Signature verification fails as a security boundary when the verifier and the application resolve different meanings from the same document.
Signatures are over bytes, not meaning.
Two messages can express the same data and still produce different signatures. Verification begins with the exact bytes a protocol chooses to protect.
Audit the attributes, not the datasheet.
PKCS #11 key policy is expressed through attributes and mechanisms inside the token. An inventory can reveal permissions that a product datasheet cannot.
The handle is not the key.
PKCS #11 gives applications a common view of cryptographic devices. The key's policy, lifecycle and operational meaning still depend on what lies behind the…
Entropy arrives late.
Correct algorithms can still generate related keys when identical devices ask for randomness before their environments have diverged.
Twenty-six years from break to scheduled retirement.
SHA-1's long retirement measures inventory, artifact lifetime and the unreachable tail of deployed systems more than cryptanalysis.
The handshake has a budget of fourteen kilobytes.
Post-quantum authentication can cross transport limits before application data begins. The real budget is measured in bytes, flights, fragments and buffers.
A random output can carry a proof.
A verifiable random function produces a unique, random-looking output and evidence anyone can check. It proves origin and uniqueness, not fairness in deciding which…
Removing a member creates a new epoch.
Messaging Layer Security makes membership part of shared cryptographic state. A removal takes effect when the remaining group commits and derives a new epoch.
The ciphertext does not say which mode produced it.
Format-preserving ciphertext carries no mode, key or tweak metadata. That convenience makes FF1 and FF3 migration difficult to scope from the data alone.
Preserving the format preserves the leakage.
Format-preserving encryption keeps ciphertext compatible with narrow legacy fields. It also keeps domain size, length, structure and often equality visible.
A compact handshake still has a transcript.
EDHOC compresses authenticated key exchange into three concise CBOR messages. Its efficiency still depends on exact transcript bytes, credential profiles and state transitions.
Two key exchanges still make one protocol.
A hybrid key exchange combines a traditional contribution with a post-quantum one. Its guarantee depends on the combiner, transcript, negotiation and every failure path…
Sign the same message twice.
Repeated signing reveals whether output varies. Across a population, repeated ECDSA values can expose nonce reuse, compromise and implementation anomalies.
Determinism is not a substitute for entropy.
Deterministic signing prevents catastrophic dependence on fresh random nonces. Hedged signatures add new randomness to reduce repeated traces and faults without trusting that randomness…
No intermediary should see the whole request.
Oblivious HTTP partitions network identity and request contents between a relay and a gateway. Padding, discovery, metadata and collusion still determine the privacy of…
Evidence is not a verdict.
Remote attestation authenticates evidence about a target environment. Endorsements, reference values and appraisal policy are what turn that evidence into a decision.
A key directory should be accountable.
Key transparency gives public-key distribution a consistent, auditable history. Its proofs expose silent substitution only when clients, monitors or witnesses compare committed views.
The aggregate can be known without collecting each value.
VDAFs let several aggregators verify and combine hidden client measurements. The result protects individual values only when non-collusion, batching and query policy hold.
Authorization does not require identity.
Privacy Pass separates token issuance from token redemption. The token can prove prior authorization without carrying a stable client identity.
The server does not need the password.
OPAQUE lets a client and server establish a mutually authenticated key without disclosing the password to the server. Registration, recovery and server-key custody still…
The signature is ordinary. The ceremony is not.
FROST turns distributed authority into one ordinary Schnorr signature. The difficult security work remains in share generation, nonce state, participant coordination and recovery.
The statement must enter the hash.
A zero-knowledge proof can verify correctly while authorizing the wrong statement. Fiat-Shamir security begins with the exact public instance, transcript order and domain separation…
Selective disclosure is not unlinkability.
BBS signatures support selective disclosure and randomized derived proofs. Unlinkability still depends on disclosed values, proof context, revocation and the surrounding protocol.
A blockchain can preserve a claim. It cannot make it true.
Hashes, signatures and consensus can preserve an ordered claim. They cannot establish the external truth, authority or intent behind it.
Toward an open cryptographic workbench.
Cryptographic tools explain algorithms, transform data and visualise workflows. A protocol workbench could connect those strengths while keeping exact bytes visible.
A secure key cannot make a photographed QR fresh.
Hardware-backed signing can prove which mobile key produced an offline QR. It cannot, by itself, prove that the image was created for this verifier,…
Three hundred milliseconds is an operating envelope.
Encrypted QR decoding is governed less by cipher choice than by symbol density, module sampling, optics, motion, exposure and the scanner pipeline. A byte…
A one-way QR can establish a key, but not a conversation.
An ephemeral X25519 key can protect an offline QR for a pre-provisioned verifier, but freshness, replay resistance and sender authentication still require explicit protocol…
What post-quantum migration costs at the edge.
Post-quantum algorithms change the size and shape of protocols. At the edge, bytes, memory, latency and update paths become part of the cryptographic decision.
Algorithm agility is an operational property.
Supporting a second algorithm is easy. Moving a running system from one cryptographic regime to another is the real test of agility.
The transcript is the protocol.
A secure session depends on more than fresh keys. The negotiation, participants and intended operation must be bound to the same cryptographic result.
A nonce is not a footnote.
A secure cipher can fail when nonce state does not survive writers, restarts and rollbacks. Uniqueness is a property of the operating system around…
The curve is only part of the choice.
P-256, secp256k1, Ed25519 and X25519 name different layers, purposes and ecosystems. Selecting a curve never selects the complete construction.
Putting the trust boundary beside the reader.
A SAM can keep master keys out of reader firmware and perform card protocols locally. The security result still depends on permissions, host integration…
A card migration is a state machine.
Moving a live fare system from MIFARE Classic to MIFARE Plus is not a card replacement exercise. It is a controlled transition across credentials,…
Designing a fare token for intermittent connectivity.
When balance and fare rules remain in a central account, a QR code is not the ticket. It is a compact claim whose meaning…
The SIM as a cryptographic computer.
Long before the secure element became a general platform, SIM and UICC applets provided a small governed environment for keys, authentication and digital signatures.
The token is the easy part.
A token can replace a sensitive value. The difficult work is defining what the replacement means, who may reverse it and how the system…
Keys without a secure boundary.
When cryptographic operations must run without an HSM, software can reduce the exposure of key material—but it cannot make a hostile host trustworthy.
When a QR code was not a format.
During the pandemic, visually similar QR codes carried incompatible data models, encodings and trust assumptions. A contribution from Uruguay to PathCheck’s Universal Verifier made…
