Real World Cryptography in Paris!

Our 5th meetup. Five talks on homomorphic encryption, key-based identity, anonymous auctions, and protocol verification.

I. About

A Paris meetup for real-world cryptography!

RWC Paris is a meetup for people who work on, or are interested in, real-world cryptography. We get a mix of cryptographers, engineers, students, and researchers.

We meet a few times a year. Talks are short and technical. Sponsors cover the venue and food.

II. Schedule

Five talks, one evening.

Doors open at 19:00. Talks start at 19:15, with a break in the middle, and we finish around 21:15. Then drinks and conversation until 22:30.

Every slot includes a few minutes for questions.

  1. Doors open

    Food, drinks, and a few announcements.

  2. 20 min

    Poulpy: A backend agnostic modular FHE library over the Torus using bivariate polynomial representation

    Jean-Philippe Bossuat Ideal Rings Lab

    Abstract

    Poulpy is the first FHE library to depart from the standard RNS-centric design by building its core around the bivariate representation of Torus polynomials. This talk introduces the engineering and cryptographic motivations behind this choice and presents Poulpy’s unique modular, backend-agnostic architecture, designed to keep the open cryptographic core fully open-source, auditable and reusable while enabling independent proprietary backends.

  3. 20 min

    When FHE Isn’t Enough: Running Encrypted Programs on Encrypted Data with HEGIDE

    Pierre-Emmanuel Clet CEA-List, Université Paris-Saclay

    Abstract

    Fully Homomorphic Encryption lets a server compute on encrypted data, but the program itself stays in the clear, and its circuit shape leaks the logic. For proprietary algorithms, like trading strategies, fraud heuristics or AI models, that’s a dealbreaker, and classic Private Function Evaluation has been too slow or too limited to scale to fix it in practice. HEGIDE closes this gap. It is an oblivious processor over CKKS that hides both the data and the program by treating the function as just more encrypted data: the server runs a fixed, public processor over an encrypted instruction stream and cannot tell an Add from a Mul, or one memory access from another. It can obliviously read from and write to an encrypted memory, and execute instructions on words between 16 and 256 bits. CKKS packing drives thousands of program threads in parallel, bringing amortized cycle times down to a few milliseconds, two orders of magnitude faster in throughput than comparable encrypted processors.

  4. 15 min

    Break

  5. 5 min

    Public Keys as User Identity for Censorship-⁠Resistant Apps

    Marcos Carlomagno Tether

    Abstract

    Pubky is an open protocol where a user’s public key becomes their identity. This talk introduces how Pubky enables portable identity, user-owned data, and censorship resistant applications, while exploring the real world tradeoffs around key management, discovery, usability, and trust. More info at pubky.org.

  6. 15 min

    Large Scale Anonymous Sealed-⁠Bid Auctions with Tunable Privacy

    Özgür Kesim FU Berlin, Code Blau GmbH

    Abstract

    SEAL is an existing anonymous sealed-bid auction protocol, without auctioneer. It uses an anonymous veto-protocol to calculate the winning price bit-by-bit. The computational and bandwidth costs for a bidder scale with O(cN), where c is the number of encoding bits for the price and N the number of bidders. For large auctions (think: tickets to the world cup), these costs are prohibitive. We propose a divide-and-conquer approach to parallelize the auction, and introduce two knobs that allow us to tune a) the sizes of the anonymity sets and b) the coverage of verification’s of NIZK proofs, both for efficiency.

  7. 20 min

    From Toy to Instrument: Seven Years of Verifpal

    Nadim Kobeissi Symbolic Software

    Abstract

    Protocol verification tools have grown more expressive with every paper, and harder to pick up with every release. Most end up used by the group that built them and almost nobody else. Verifpal goes the other way: it is built around the person writing the model, with a small language you can read out loud, an active attacker, and output that names the attack instead of leaving you to reconstruct it. When I published it in 2019, that choice was expensive: its paper called its own soundness argument “an incomplete, semi-formal, in-progress set of results,” and the fair verdict was that Verifpal was a teaching aid resembling a verification tool. That verdict was correct. People used it anyway, on Signal, TLS 1.3, MTProto, ProtonMail, and during the design of Zoom’s end-to-end encryption.

    Seven years later, Verifpal has matured from toy to instrument. While the 2019 engine searched forward, the current engine starts from an unresolved query and searches backward through the conditions needed to violate it. Before reporting an attack, a separate validator checks that the attacker controls every modified slot and can derive every injected term, re-executes the protocol, and evaluates the query again. We prove that every reported attack is reachable in the bounded sequential-replay semantics defined here, independently of solver correctness. Because this semantics reuses a clone’s fresh values across sequential replays, it can admit witnesses that replication would exclude; the output labels such witnesses.

    The language now supports key encapsulation, explicit weakening assumptions, concurrent sessions, and multiple peer configurations. We compare Verifpal’s results and counterexamples with those of ProVerif, Tamarin, and Scyther on a corpus of classical protocols. Verifpal provides bounded counterexample search rather than unbounded proofs: it complements these tools, but does not replace them.

    This talk will also cover a critique against the entire field of protocol modeling and analysis tools, Verifpal included: symbolic verifiers are exploratory instruments, much closer to an interactive notebook for reasoning about a protocol than to any real assurance or proof tool, and reading a verdict from Tamarin, ProVerif or Verifpal as more than that has always been presumptuous. In order to truly advance the field of protocol modeling, it must be reframed for what it really is. Only then will we be able to realign our incentives on priorities to focus on who it can really benefit: real-world industry practitioners, not academics.

  8. Drinks and conversation

  9. Doors close

III. Registration Open

Register to attend Meetup 5!

Attending

Free, but please register so we can plan food and drinks. Doors open at 19:00 and the first talk starts at 19:15.

Venue

EPITA in Le Kremlin-Bicêtre, a few minutes on foot from Métro 7. Directions are below.

Call for talks

Closed. Thanks to everyone who sent in a proposal. The five talks we selected are in the schedule above.

Want to speak at a future meetup? Email us and we will keep you in mind for the next one.

IV. Venue

EPITA, Le Kremlin-Bicêtre.

Métro 7 to Le Kremlin-Bicêtre station, then a few minutes on foot.

Open in Google Maps
Place
EPITA
Street
14–16 Rue Voltaire
Postal
94270 Le Kremlin-Bicêtre
Country
France
Métro
Le Kremlin-Bicêtre (M7)
Coordinates
48.8104° N · 2.3527° E
V. Sponsors

Sponsors.

Sponsors organize the meetup, provide the venue, and cover food and drinks.

VI. Code of Conduct

We want RWC Paris to be a place where anyone curious about real-world cryptography feels welcome, no matter how much of it they already know. If you come, treat the people around you with respect and listen to views you disagree with. That goes for the group chat and email too, not just the room.

VII. Contact
Meetup 5

November 6, 2026.

Doors at 19:00 at EPITA in Le Kremlin-Bicêtre. Moved from September 4, so please update your calendar.